This Privacy Policy explains how 4TRAITS LLC collects, uses, stores and shares personal data through the 4TRAITS website, protected tools, AI-enabled functions, document workflows, client and partner portals, communications and related services.
1. Who we are
4TRAITS LLC is a limited liability company established in Sharjah Media City Free Zone (Shams), Sharjah, United Arab Emirates, under licence number 2112716.01. Its tax registration number is 105420643600001.
For privacy questions or requests, contact:
4TRAITS LLC
Sharjah Media City Free Zone (Shams)
Sharjah, United Arab Emirates
Email: care@4traits.io
An in-app privacy request channel may also be available to signed-in users.
2. Scope
This Policy applies to personal data processed through:
- 4traits.io and related 4TRAITS websites or subdomains;
- protected tools, portals and applications;
- inquiry, onboarding, checkout and account forms;
- document creation, upload, signature, execution, delivery and workflow functions;
- AI-assisted content, analysis and automation;
- business lead research and governed outreach functions;
- calls, meetings, support and service communications; and
- professional services delivered through or supported by the platform.
A client agreement or Data Processing Agreement may provide additional privacy terms for a particular engagement.
3. Our role
4TRAITS generally acts as a data controller when it determines why and how personal data is processed for website operation, inquiries, account administration, billing, security, legal compliance, service management, business development and its own business activities.
When a business customer uploads or manages personal data through the Services and determines the purposes of processing, 4TRAITS will generally act as a data processor following that customer’s documented instructions. The customer remains responsible for its own privacy notices, lawful basis, instructions and data-subject relationships. A Data Processing Agreement may govern that processing.
The actual role depends on the facts and applicable law.
4. Personal data we collect
Depending on how you interact with us, we may collect the following categories.
Contact and identity information
- name, business email, telephone number and professional contact details;
- employer, organisation, role, job title and authority to act;
- account identifier, membership role and authentication details; and
- signature, typed name, verification data, consent and acceptance records.
Inquiry, client and project information
- preferred meeting date, time and time zone;
- messages, requests, instructions, proposals and service requirements;
- project files, contracts, forms, records and other uploaded content;
- client, supplier, employee, lead or other third-party data included in customer content; and
- generated documents, AI prompts, outputs, annotations, approvals and workflow records.
Document execution and delivery information
Where an authorised user uses an electronic document workflow, we may process the document and signed copy, signer name and title, account or actor identifier, verification evidence, execution time, document and integrity hashes, transaction or archive references, delivery address and delivery metadata.
Transaction and billing information
- billing contact, company details, invoices, payment status, subscription or order information;
- tax and accounting records; and
- limited payment transaction references received from payment providers.
4TRAITS does not intend to store complete payment-card numbers or card security codes.
Communications information
- emails, support messages and correspondence;
- service, verification, approval and document-delivery messages and related delivery metadata;
- call, meeting or support recordings and transcripts where clear notice and any required consent have been provided; and
- feedback, survey responses and service-history information.
Public professional, business and research information
For limited business-to-business research, we may process relevant professional information that you or your organisation has made public or that is lawfully available from company websites, professional profiles, public procurement or opportunity notices, business directories, public registers, public platforms or licensed data sources. This may include name, role, employer, business contact details, professional interests, opportunity information, source URL, source identifiers, timestamps, public evidence snapshots and source-version information.
Research workflows may also create operational metadata such as qualification or prioritisation outputs, disposition, attempt history, evidence fingerprints and owner-review or approval records. We do not intentionally collect sensitive or purely personal information for routine lead research.
Technical, usage and security information
- IP address, user agent, browser, device and operating-system information;
- session, authentication, invitation, one-time verification and security-event data;
- pages, functions, actions and timestamps;
- referral and integration information; and
- essential cookie or browser-storage identifiers.
5. How we obtain personal data
We may receive personal data:
- directly from you;
- from your employer, organisation, authorised representative or customer;
- from content uploaded by platform users;
- from connected third-party services at the user’s direction;
- automatically when you use the Services;
- from payment, communications, hosting, security and other providers; and
- from public or lawfully obtained professional sources for limited B2B research.
6. Why we process personal data
We process personal data for the following purposes:
- responding to inquiries and arranging calls;
- creating and administering accounts, invitations, access and permissions;
- preparing proposals, contracts, documents and deliverables;
- providing, supporting, maintaining and improving the Services;
- processing uploads, instructions, signatures, execution evidence and workflow actions;
- securely archiving and delivering executed documents where requested;
- generating AI-assisted drafts, analysis, classifications and recommendations;
- verifying public-source evidence, qualifying relevant business opportunities and supporting owner-controlled outreach;
- performing customer-authorised integrations and automation;
- handling orders, billing, accounting and tax obligations;
- communicating about services, security, verification, changes and support;
- conducting limited, relevant and compliant B2B research and outreach;
- protecting users, data and systems, preventing misuse and investigating incidents;
- establishing, exercising or defending legal rights;
- complying with legal, regulatory, court and government requirements; and
- creating genuinely aggregated or de-identified statistics and service insights.
7. Legal grounds
Where UAE personal data law applies, processing will be based on one or more legally recognised grounds, including:
- your specific, clear and withdrawable consent;
- taking requested steps before entering into a contract;
- performing, amending or terminating a contract with you;
- complying with legal or regulatory obligations;
- establishing, exercising or defending legal rights;
- protecting your interests or the rights of others where the law permits;
- processing professional information that you have made publicly available; or
- another ground permitted by applicable law.
Where processing relies on consent, you may withdraw it through the relevant control, the in-app privacy channel where available, or care@4traits.io. Withdrawal does not affect processing that was lawful before withdrawal and may not affect processing required for a contract, law or legal claim.
8. AI providers and automated processing
The Services may submit prompts, content, public-source evidence or relevant instructions to approved AI providers to generate, classify or analyse requested outputs. The provider used may vary according to the configured service, customer agreement, availability, security and performance requirements.
We seek to limit AI submissions to information necessary for the requested task and apply contractual, technical and organisational safeguards appropriate to the processing.
4TRAITS will not use customer content to train general-purpose public AI models without explicit consent. Third-party AI providers have their own service terms and data-handling commitments, which may differ according to the account or product used.
AI may support scoring, classification, research qualification, recommendations and workflow prioritisation. AI-generated research or outreach content is treated as a draft or decision-support input and may be subject to validation or human approval before external use. 4TRAITS does not intend to rely solely on automated processing for decisions that have a significant legal or similarly serious effect on an individual without a lawful basis, appropriate safeguards and meaningful human review. Where applicable, you may object and request human review.
9. Cookies and browser storage
4TRAITS currently uses only cookies or browser storage that are reasonably necessary for security, authentication, language or essential platform operation.
We will not activate optional analytics, advertising or behavioural tracking technologies without first implementing an appropriate consent mechanism where consent is required. You can restrict cookies through your browser, but blocking essential technologies may prevent parts of the Services from working.
10. How we share personal data
We may share personal data only as reasonably necessary with:
- hosting, database, storage and infrastructure providers;
- email, communications, calendar and support providers;
- payment and billing providers;
- AI and automation providers selected for a requested function;
- public-source research or collection providers where a configured workflow requires them;
- security, monitoring and technical-support providers;
- professional advisers, auditors, insurers and financing parties subject to appropriate duties;
- a buyer, investor, successor or transaction adviser in connection with a proposed or completed corporate transaction, subject to confidentiality and applicable law;
- a customer or organisation responsible for the relevant account or processing; and
- courts, regulators, law-enforcement bodies and other competent authorities where disclosure is legally required or necessary to protect rights and safety.
We require providers to process personal data only for authorised purposes and to apply appropriate safeguards. The separately maintained Subprocessor Register identifies principal providers used or supported for customer-data processing and distinguishes active, conditional and inactive providers.
11. No sale or third-party targeted advertising
4TRAITS does not sell or rent personal data and does not share it for third-party targeted advertising.
We may disclose information to authorised service providers, professional advisers, transaction counterparties and authorities for the purposes described in this Policy.
12. International transfers
Our providers and authorised recipients may process personal data in the UAE and other countries. Those countries may have different data-protection laws.
Where personal data is transferred outside the UAE, we will use an applicable lawful transfer mechanism and appropriate safeguards, which may include contractual protections, provider assessments, technical controls, encryption, access restrictions, explicit consent where appropriate, or transfer necessary to perform a contract or establish legal rights.
We do not promise UAE-only storage unless a specific signed agreement requires it.
13. Security
We use technical and organisational measures designed to protect personal data in a manner appropriate to the nature and risk of processing. Measures may include access controls, individual accounts, authentication and one-time verification, encryption, private storage, logging, integrity hashes, secure development practices, provider due diligence, backups, incident procedures, data minimisation and staff or contractor confidentiality obligations.
No system is completely secure. You must protect credentials, use authorised devices and promptly report suspected compromise to care@4traits.io.
14. Retention
We keep personal data only for as long as reasonably necessary for the stated purpose and applicable legal, contractual, security and dispute requirements. Our normal retention approach is:
- Inquiries and prospective-client records: up to 24 months after the last meaningful contact;
- B2B research and source evidence: normally up to 24 months after the last meaningful research activity, source observation or terminal disposition, unless the information remains linked to an active opportunity, legal hold, dispute or another documented need; stale source-candidate and observation records are subject to automated retention cleanup;
- Marketing records: until consent is withdrawn, an objection is made, the data becomes inactive or another lawful retention need ends; limited suppression information may be kept for as long as necessary to honour an opt-out or do-not-contact request;
- Account and security logs: normally up to 12 months;
- Client and project records: the service period plus 24 months, unless a contract, legal requirement or claim justifies longer retention;
- Temporary uploaded files: normally deleted within 90 days after the relevant task or engagement is completed, unless the user saves them, a contract provides otherwise or another retention need applies;
- Executed agreements and signature evidence: executed mutual NDAs and comparable executed records, signed copies, signer and verification evidence, integrity hashes and associated archive or delivery metadata are normally retained for approximately seven years from execution, unless a longer period is required by contract, law, legal hold, dispute or claim;
- Corporate, accounting and tax records: at least seven years where required;
- Terms and Privacy acceptance evidence: for the period reasonably necessary to establish acceptance, administer the relationship and defend legal rights;
- Recordings and transcripts: only for the notified purpose and an appropriate defined period;
- Backups: deleted information is normally overwritten within approximately 90 days, subject to technical cycles and legal holds; and
- Legal, fraud, incident and compliance records: for the applicable claim, investigation or statutory period.
We may anonymise information instead of deleting it where it can no longer reasonably identify an individual. Retention periods may be shortened where the information is no longer needed.
15. Your privacy rights
Subject to applicable law, verification and relevant exceptions, you may request:
- information about the personal data we process, its purposes, recipients, retention and transfer safeguards;
- access to your personal data;
- correction or completion of inaccurate data;
- deletion where the data is no longer needed or processing is unlawful;
- restriction of processing;
- objection to direct marketing and certain other processing;
- withdrawal of consent;
- transfer or portability of eligible data in a structured, machine-readable form;
- information about significant automated processing; and
- human review of an eligible automated decision.
Submit a request through the in-app privacy channel, where available, or email care@4traits.io.
We may request information needed to verify identity, authority and scope. We may refuse or limit a request where permitted by law, including where it is excessively repetitive, conflicts with judicial or regulatory procedures, would undermine information security, affects another person’s privacy, or conflicts with a legal retention obligation. We will explain the basis where legally required.
You may also submit a complaint to the competent UAE data-protection authority where that right is available.
16. Marketing communications
We may respond to your inquiry and send relevant service-related follow-ups. Promotional marketing will be sent only where we have consent or another lawful basis and will include or support an appropriate opt-out mechanism.
You may opt out through the unsubscribe method provided or by contacting care@4traits.io. We will keep limited suppression information where necessary to respect the opt-out.
Telephone, SMS and messaging-app marketing will be conducted only in accordance with applicable UAE telemarketing and communications rules. If promotional SMS is enabled for a UAE-linked campaign subject to TDRA requirements, it must use prior explicit consent, the permitted sending window and a free and effective unsubscribe mechanism.
17. Business lead research
4TRAITS may conduct limited B2B research using relevant public or lawfully obtained professional information for legitimate business outreach and service development.
Research workflows may preserve source URLs, public evidence, source-version information, timestamps, qualification outputs, disposition and attempt history so that findings can be verified, stale opportunities can be managed and external outreach remains controlled. Where configured, external outreach may require owner or authorised human approval before sending.
We seek to:
- record or preserve the source and evidence necessary to verify a research result;
- avoid sensitive and purely personal information;
- use professional contact details only for relevant outreach;
- respect objections, unsubscribe requests and applicable do-not-contact controls;
- avoid bypassing authentication, access controls, robots restrictions or platform restrictions;
- validate AI-generated research before relying on it for external action;
- apply the retention controls in section 14 to research evidence; and
- correct, suppress or delete inaccurate or unnecessary information.
18. Sensitive personal data
Do not upload government identification documents, health information, biometric data, criminal records, payment credentials or highly confidential third-party material unless it is genuinely necessary for an authorised service and appropriate safeguards and permissions are in place.
We may reject, restrict or securely delete unnecessary sensitive data. Where sensitive data processing is approved, additional contractual, access, security and retention controls may apply.
19. Children
The Services are intended for users aged 18 or older. We do not knowingly offer the Services directly to children or intentionally collect their personal data through ordinary website use.
If you believe a child has provided personal data, contact care@4traits.io so we can assess and take appropriate action.
20. Recordings and transcripts
We may record or transcribe calls, meetings or support sessions only after giving clear notice and obtaining consent where required. Recordings may be used for service delivery, documentation, quality, training or dispute resolution and will be subject to restricted access and purpose-based retention.
21. Security incidents
We investigate suspected personal-data breaches, take reasonable containment and remediation measures, document material incidents and notify affected customers, individuals or competent authorities where required by law.
Notification timing and content will depend on the nature, risk, available facts and applicable legal requirements.
22. Third-party sites and services
The Services may link to, query or integrate with third-party sites and services. Their independent privacy practices are governed by their own policies. Review those policies before providing information or enabling an integration.
Public platforms or public procurement sources are not necessarily 4TRAITS subprocessors merely because a lawful public or authorised interface is queried. The Subprocessor Register describes principal providers separately.
23. Changes to this Policy
We may update this Policy when laws, services, providers or processing practices change. The current version will display its version number, effective date and last-updated date.
We will provide reasonable notice of material changes through the platform, account email or another appropriate channel before they take effect where appropriate. We will seek fresh consent where legally required. Where the platform requires affirmative legal acceptance, a material version change may invalidate an existing platform session and require the current versions to be reviewed and accepted again.
24. Privacy governance and contact
4TRAITS assigns internal responsibility for privacy governance, including rights requests, incident coordination, retention reviews and provider oversight. This role may be described as the Privacy Lead and will not be represented as a statutory Data Protection Officer unless the applicable legal threshold and appointment requirements are met.
Privacy questions, requests and complaints may be sent to:
4TRAITS LLC
Sharjah Media City Free Zone (Shams)
Sharjah, United Arab Emirates
Email: care@4traits.io