Legal Document

Privacy Policy

Effective Date: 7 July 2026Version: 1.0Last Reviewed: 7 July 2026

1. Introduction

This Privacy Policy explains how OPZORA.AI & PR LLC, operating under the brand OPZORA, collects, uses, stores, shares and protects Personal Data when individuals and organizations use opzora.ai and the web-based services made available through it.

In this Privacy Policy, "OPZORA", "we", "us" and "our" refer to OPZORA.AI & PR LLC.

This Privacy Policy applies only to the OPZORA website and web-based services available through opzora.ai. It does not apply to independent websites, systems or services operated by third parties.

2. Who We Are

Legal entityOPZORA.AI & PR LLC
BrandOPZORA
LocationDubai, United Arab Emirates
Websiteopzora.ai
Privacy contactprivacy@opzora.ai
Support contactsupport@opzora.ai

OPZORA provides technology-assisted business setup analysis, reports, recommendations and related web-based services.

3. Our Roles as Controller and Processor

3.1 Direct users

For individuals who create or use an OPZORA account directly, OPZORA.AI & PR LLC generally acts as the Data Controller for account administration, authentication, service delivery, security, billing, support, compliance and platform management.

3.2 Organizational accounts

Where an organizational customer submits or manages Personal Data concerning its employees, customers, applicants, shareholders, directors, representatives or other persons, the organization will generally act as the Data Controller and OPZORA will generally process that data as a Data Processor on the organization's documented instructions.

OPZORA may remain an independent Data Controller for certain platform-level activities, including:

  • account and user administration;
  • authentication and access management;
  • platform security and fraud prevention;
  • billing and service administration;
  • compliance and audit records;
  • legal claims and dispute management; and
  • platform-level technical logs.

3.3 Business Setup Partners

The privacy role of a Business Setup Partner depends on the relevant service and contractual arrangement.

A Partner may act as:

  • an independent Controller when it provides its own business setup, licensing, visa, banking-support or corporate services;
  • a Processor when it acts only on documented instructions and does not determine independent processing purposes; or
  • a joint Controller where OPZORA and the Partner jointly determine the purposes and essential means of processing.

The applicable role should be explained in the relevant service, referral or contractual documentation.

4. Scope of This Policy

This Privacy Policy applies to Personal Data processed through or in connection with:

  • the OPZORA website;
  • individual and organizational accounts;
  • the web-based dashboard;
  • intake and assessment forms;
  • authentication and account verification;
  • business setup analysis;
  • report generation, delivery and storage;
  • document-upload functionality where enabled;
  • customer support and communications;
  • payments and invoicing where enabled; and
  • Partner referral or service-delivery workflows.

5. Who This Policy Covers

This Privacy Policy may apply to:

  • website visitors;
  • individual users;
  • founders, investors and business applicants;
  • organizational customers;
  • organization administrators and sub-users;
  • sales leads and marketing contacts;
  • support and WhatsApp contacts;
  • shareholders, directors, managers and ultimate beneficial owners;
  • employees and proposed employees;
  • authorized representatives;
  • family members or dependants whose information appears in submitted documents;
  • customers, suppliers or commercial counterparties identified in an application;
  • Business Setup Partner personnel;
  • vendors, contractors and professional advisers; and
  • job or collaboration applicants.

Users may be located inside or outside the United Arab Emirates. OPZORA may restrict services in jurisdictions that are prohibited, sanctioned, high-risk, unsupported or operationally unavailable.

6. Key Definitions

Personal Data
means information relating to an identified or identifiable natural person.
Authentication Data
means information used to create, verify, secure or access an account.
Google User Data
means information received through Google Sign-In.
Business Information
means information about a proposed or existing business, its activities, owners, operations, finances and requirements.
Uploaded Documents
means documents or files submitted through an enabled OPZORA upload workflow.
Partner
means a business setup company, corporate service provider, free-zone consultant, professional adviser or other service provider involved in delivering a requested service.
Processor
means a party that processes Personal Data for and on the documented instructions of a Controller.
Subprocessor
means a service provider engaged by a Processor to assist with processing Personal Data.

7. Personal Data We Collect

The categories collected in a particular application depend on the services used and the information required for that service.

7.1 Identity and contact information

We may collect:

  • name;
  • email address;
  • telephone number and country code;
  • nationality;
  • country, city or place of residence;
  • business location;
  • address information;
  • profile information;
  • profile photograph; and
  • identification information where required for a specific service.

7.2 Account and authentication information

We may process:

  • internal account identifiers;
  • authentication-provider identifiers;
  • authentication method;
  • email and telephone verification status;
  • account creation and login timestamps;
  • session identifiers;
  • successful and failed login records;
  • account recovery information;
  • organization membership;
  • roles and permissions; and
  • security and access events.

OPZORA does not store passwords in readable plaintext form.

7.3 Google User Data

When Google Sign-In is used, we may receive:

  • name;
  • email address;
  • profile image;
  • Google account identifier; and
  • authentication information associated with the approved openid, email and profile scopes.

We do not use Google Sign-In to access Google Drive, Google Calendar, Google Contacts, Gmail, Google Sheets or Google Workspace content.

7.4 Telephone and OTP information

When telephone authentication is used, we may process:

  • telephone number and country code;
  • time and purpose of the OTP request;
  • request, delivery or verification status;
  • verification result;
  • number of verification attempts;
  • technical transaction identifiers;
  • rate-limiting information; and
  • fraud, abuse or security signals.

Raw OTP content is not intended to be stored in ordinary application logs.

7.5 Business and investor information

Depending on the assessment requested, we may collect:

  • proposed business activities;
  • products and services;
  • target customers and markets;
  • countries of trade;
  • preferred jurisdiction and location;
  • ownership and management structure;
  • shareholder, director and manager details;
  • employee and visa requirements;
  • office or workspace requirements;
  • startup budget;
  • expected turnover and transaction profile;
  • banking expectations;
  • existing businesses and business history;
  • ultimate beneficial ownership;
  • source-of-funds or source-of-wealth information;
  • tax residence; and
  • the intended operational model.

7.6 Uploaded Documents

Where document upload is enabled and required for a service, documents may include:

  • passport, Emirates ID, visa or residence documents;
  • proof of address;
  • shareholder, director or ultimate beneficial owner documents;
  • corporate certificates and trade licences;
  • constitutional or ownership documents;
  • bank statements;
  • source-of-funds or source-of-wealth evidence;
  • income or asset evidence; and
  • supporting compliance or banking-related documents.

Users should not submit documents unless requested through an approved workflow.

7.7 Information about other people

Documents and applications may contain Personal Data relating to other people, including shareholders, directors, beneficial owners, employees, dependants, customers, suppliers and representatives.

You must only provide another person's Personal Data where you have the legal authority to do so and have given that person any notice required by applicable law.

7.8 Payment and billing information

Where payment functionality is enabled, we may process:

  • payment amount and currency;
  • transaction date and status;
  • transaction identifier;
  • invoice and receipt information;
  • billing information;
  • limited payer information; and
  • bank-transfer confirmation.

Card payments may be processed by an external payment provider.

OPZORA does not intend to collect or store card security codes, PINs, online banking passwords or full banking authentication credentials.

7.9 Technical, usage and security information

We may process:

  • IP address;
  • approximate IP-based location;
  • browser type and version;
  • device type;
  • operating system;
  • language and time zone;
  • date and time of access;
  • session identifiers;
  • pages and functions used;
  • error and diagnostic logs;
  • account and permission changes;
  • document upload, access, download, transfer or deletion events;
  • security events;
  • rate-limiting information; and
  • suspected fraud or misuse indicators.

We do not collect precise GPS location unless a specific feature requiring it is introduced with appropriate notice and, where required, consent.

7.10 Support and communication information

We may process:

  • support tickets;
  • emails;
  • WhatsApp communications;
  • messages and attachments;
  • complaint records;
  • meeting or call notes;
  • requests for human review; and
  • records of privacy or account-related requests.

Calls or meetings are not recorded or transcribed unless recording functionality is active and appropriate notice is provided.

7.11 Report and AI-processing information

We may process:

  • intake answers;
  • structured application information;
  • questions submitted by users;
  • relevant document text;
  • risk and suitability indicators;
  • generated analyses and reports;
  • confidence indicators;
  • reviewer comments;
  • corrections and disputed results;
  • model or workflow metadata;
  • application identifiers; and
  • technical audit information.

7.12 Cookies and similar technologies

Depending on the website configuration, we may use:

  • authentication and session cookies;
  • security cookies;
  • preference storage;
  • cookie-choice records;
  • local storage;
  • analytics identifiers; and
  • campaign or conversion information where non-essential technologies have been enabled lawfully.

8. Information We Ask You Not to Provide

Unless specifically requested through an approved secure process, do not provide:

  • passwords or online banking credentials;
  • PINs or card security codes;
  • private keys or API keys;
  • OTP content;
  • unnecessary medical information;
  • unnecessary religious or ethnic information;
  • biometric templates; or
  • unrelated confidential documents.

Where unnecessary or prohibited information is received, we may restrict access, redact, quarantine or delete it.

9. Sources of Personal Data

We may obtain Personal Data:

  • directly from you;
  • from an organization administrator or authorized user;
  • from documents submitted by you or an authorized person;
  • from Google or other authentication infrastructure;
  • from Business Setup Partners and professional advisers;
  • from official government, regulatory, licensing or free-zone sources;
  • from corporate registries and reputable public sources;
  • from compliance, sanctions, PEP or watchlist providers where applicable;
  • from payment, communications and support providers; and
  • automatically through security, authentication and technical logs.

10. How and Why We Use Personal Data

We may process Personal Data for the following purposes:

PurposeExamples of processing
Account creation and administrationCreating accounts, maintaining profiles, managing organizations, roles and permissions
Authentication and securityEmail/password login, Google Sign-In, telephone verification, OTP, account recovery and abuse prevention
Service deliveryCollecting requirements, analysing business setup options, producing reports and providing recommendations
Document processingReceiving, reviewing, extracting or validating information from documents where the relevant workflow is enabled
AI-assisted analysisStructuring information, classifying applications, generating risk or suitability indicators and drafting reports
Human reviewReviewing complex, disputed, flagged or higher-risk applications
Partner services and referralsIntroducing users to service providers and transferring necessary information for requested services
Payments and invoicingProcessing payments, bank transfers, receipts, refunds and organizational invoices
Customer supportResponding to questions, complaints, technical issues and data-rights requests
Platform operationsMaintaining logs, resolving errors, monitoring performance and improving service reliability
ComplianceMeeting legal, accounting, tax, regulatory, security and record-keeping obligations
Fraud and dispute managementInvestigating misuse, protecting rights and managing legal claims
MarketingSending permitted promotional communications and measuring campaigns where lawfully enabled
Product improvementImproving workflows and services using appropriately minimized, aggregated or anonymized information
Recruitment and contractor managementReviewing applications and administering potential working relationships

12. Google Sign-In and Google User Data

OPZORA offers Google Sign-In as an account creation and authentication method.

The approved scopes are:

  • openid;
  • email; and
  • profile.

Through those scopes, OPZORA may receive your name, email address, profile image and Google account identifier.

Google User Data is used for:

  • account creation;
  • authentication;
  • user identification;
  • account administration; and
  • account and platform security.

OPZORA does not use these scopes to access Google Drive, Google Calendar, Google Contacts, Gmail, Google Sheets or Google Workspace content.

We do not use Google User Data for unrelated advertising, unrelated profiling or unrestricted lead sales.

You may request that the Google sign-in association be disconnected by contacting support. Before disconnection, you may be required to establish an alternative login method. Disconnecting Google Sign-In does not automatically delete your OPZORA account, reports or other service records.

Account deletion must be requested separately.

13. Firebase Authentication, Telephone Authentication and OTP

OPZORA's supported authentication methods include:

  • email and password;
  • Google Sign-In; and
  • telephone number and OTP.

These methods are managed using Firebase Authentication.

When telephone authentication is selected:

  • you provide your telephone number;
  • an OTP is requested for account verification or login;
  • your telephone number and related technical information may be processed through Firebase or supporting communications infrastructure;
  • automated abuse-prevention controls may be applied;
  • the request is treated as your instruction to send an authentication message; and
  • mobile-network charges may apply depending on your operator and plan.

An OTP is a transactional security message, not a marketing message.

OPZORA may restrict certain countries, telephone ranges or operators for security, compliance, fraud-prevention or operational reasons.

Technical OTP records are retained only for an appropriate operational or security period, taking account of troubleshooting, fraud and abuse risks.

14. Business Information and Uploaded Documents

Business setup assessments may require detailed information concerning ownership, management, business activities, anticipated transactions, funding and operational requirements.

Where document upload is enabled:

  • only requested and relevant documents should be submitted;
  • access should be limited to personnel and providers that need the information;
  • sensitive documents should not be sent through ordinary or unapproved communication channels;
  • unnecessary information may be redacted or removed; and
  • documents may be shared with a Partner only where necessary for a requested service and supported by an appropriate legal ground.

OPZORA may require additional verification where a document or request presents a higher fraud, security or compliance risk.

15. OCR and Document Processing

Where document text-extraction or optical character recognition functionality is enabled, OPZORA may use document-processing services to extract information from an uploaded document.

Extracted information may be incomplete or inaccurate. Accordingly:

  • extracted information should be reviewed before material use;
  • users may correct inaccurate information;
  • low-confidence or inconsistent information may be flagged;
  • higher-risk documents or applications may be referred for human review; and
  • no significant adverse result should be based solely on unverified OCR output.

OPZORA does not use document-processing functionality for facial recognition, face matching, liveness testing or biometric-template creation unless a separate feature is introduced with an appropriate assessment and notice.

16. AI-Assisted Processing and Automated Analysis

OPZORA uses or may use approved AI and automated technologies to support business setup analysis.

These technologies may:

  • structure submitted information;
  • identify missing or inconsistent information;
  • classify and rank options;
  • generate risk and suitability indicators;
  • flag applications for additional review;
  • draft analyses or reports; and
  • identify situations requiring human attention.

Depending on the workflow, processing may involve business information, structured application information, user questions, relevant extracted text or limited document content.

OPZORA applies a data-minimization approach. Direct identifiers and irrelevant information should be removed or reduced where reasonably possible.

Sensitive identity, financial, KYC or compliance information should not be transferred to an external AI provider unless the relevant provider, service configuration, contractual terms, retention arrangements, security controls, processing locations and deletion capabilities have been appropriately assessed.

We do not state that every external AI service has identical retention or training rules. Those rules may differ by provider, account, model, feature and contract.

16.1 No final governmental, banking or licensing decision

AI-generated output does not itself constitute a final or binding decision concerning:

  • company registration;
  • licence approval;
  • visa issuance;
  • bank-account approval;
  • government approval;
  • acceptance by a Business Setup Partner; or
  • final legal eligibility.

Such decisions are made by the user, a qualified adviser, a Partner, a bank, a free zone, a licensing authority or another competent body.

16.2 Corrections and human review

You may:

  • correct submitted information;
  • report an error;
  • dispute a material result; and
  • request human review of a significant or higher-risk output.

Not every standard report is reviewed by a person before delivery. Complex, disputed, flagged or higher-risk applications may be escalated for human review.

17. Cookies, Analytics and Advertising Technologies

Necessary technologies may be used for:

  • authentication;
  • account and session management;
  • security;
  • fraud prevention;
  • language and preference settings;
  • cookie-choice storage; and
  • core website functionality.

Non-essential analytics or advertising technologies should only be activated in accordance with applicable consent requirements.

Where a consent-management tool is available, users should be able to:

  • accept or reject non-essential technologies;
  • make category-level choices;
  • change preferences; and
  • withdraw consent.

Where no separate Cookie Policy or preferences page is active, essential information about cookies remains governed by this Privacy Policy and the available website controls.

18. Payments

Payments may be made through a third-party gateway, bank transfer or organizational invoicing.

External payment providers may process payment information under their own privacy terms and regulatory obligations.

OPZORA may retain payment status, transaction identifiers, invoices, receipts, billing details and limited payer information for service, accounting, tax, refund, dispute and fraud-prevention purposes.

OPZORA does not intend to receive or store card security codes, PINs, online banking passwords or complete banking authentication credentials.

19. Communications, Support, WhatsApp and Chat

OPZORA may communicate through:

  • account and dashboard messages;
  • email;
  • support tickets;
  • telephone;
  • Google Workspace or Gmail;
  • WhatsApp Business; and
  • other approved communication tools.

WhatsApp should not be used as the primary storage location for passports, bank statements, KYC records or other high-risk documents.

Where sensitive information is sent through WhatsApp or another informal channel, OPZORA may:

  • restrict access;
  • move necessary content to an approved environment;
  • remove unnecessary copies; and
  • maintain an appropriate action record.

Where an AI chatbot is introduced, users should be informed that they are interacting with AI and should be offered an appropriate route to human support.

Users must not submit passwords, OTPs, complete card data, banking credentials or unnecessary sensitive documents through chat.

20. Business Setup Partners and Referrals

At your request, or where necessary to provide a service you requested, OPZORA may share relevant information with a Business Setup Partner.

Information shared may include:

  • identity and contact information;
  • business activities and requirements;
  • ownership and management information;
  • jurisdiction, visa and office requirements;
  • relevant application or report information; and
  • necessary supporting documents.

Sensitive documents should only be transferred where they are necessary for the requested service.

A Partner may process information under its own privacy policy and may act as an independent Data Controller.

OPZORA may receive a referral fee, introduction fee, commission or other commercial benefit where a user purchases or completes a Partner service. This commercial arrangement does not authorize unrestricted use of Personal Data.

Acceptance of this Privacy Policy alone is not permission for unlimited Partner transfers. Where consent or a separate instruction is required, it should be obtained at the relevant point.

OPZORA does not rent Personal Data for unrestricted, unrelated use. The meaning of a legal "sale" or "sharing" of Personal Data may differ between jurisdictions and will be assessed where such laws apply.

21. Other Service Providers and Recipients

We may use service providers for:

  • hosting and infrastructure;
  • database and storage;
  • authentication;
  • email and communications;
  • customer support;
  • document processing;
  • AI-assisted processing;
  • payments;
  • security and fraud prevention;
  • professional advice;
  • analytics where enabled; and
  • compliance screening where applicable.

Providers should receive only the information reasonably necessary for their function and should be subject to appropriate contractual, confidentiality, security and data-protection requirements.

We may also disclose Personal Data to:

  • professional advisers;
  • auditors and insurers;
  • courts, regulators and government authorities;
  • actual or prospective transaction parties in a business transfer; and
  • other parties where authorized by you or required by law.

22. International Data Transfers

OPZORA is located in the United Arab Emirates, but Personal Data may be processed in other countries.

International processing may occur because:

  • technology and hosting providers operate internationally;
  • authentication, communications or AI providers use international infrastructure;
  • approved contractors may work from other jurisdictions;
  • Partners may operate in different locations; or
  • technical support may be provided internationally.

Where required, OPZORA will use appropriate contractual, organizational and technical measures for international transfers. These may include contractual safeguards, access restrictions, data minimization, pseudonymization and security controls.

General acceptance of this Privacy Policy is not treated as the sole legal mechanism for every international transfer.

23. Data Retention

Retention depends on the data category, purpose, account status, legal requirements, security needs, contractual obligations and dispute risks.

Data categoryRetention criteria
Account and profile informationFor the duration of the account and a limited period after closure where required for administration, disputes, security or legal obligations
Authentication informationFor the period needed to manage account access, security and authentication records
Google Sign-In informationWhile the Google association or account remains active, subject to deletion, disconnection and legal-retention requirements
Telephone and OTP logsFor a short operational period for authentication and troubleshooting, or longer where linked to suspected fraud, abuse or a security event
Business intake informationFor the duration of the requested service and an appropriate post-service period for support, corrections, disputes and legal obligations
Uploaded documentsFor the duration required to provide the requested service, followed by deletion, anonymization or restricted retention where legally or contractually necessary
KYC, AML or compliance informationFor the applicable service period and any mandatory legal, regulatory, claims or audit period
ReportsWhile available through the account and for an appropriate period after closure or completion, subject to deletion requests and applicable exceptions
AI-processing and workflow logsFor the minimum period required for quality, security, troubleshooting and audit
Security and audit logsFor a risk-based period appropriate to detecting, investigating and evidencing misuse or security incidents
Payment, invoice and accounting recordsFor the period required by applicable accounting, tax, commercial or dispute requirements
Support and email recordsFor the period needed to resolve the request and maintain appropriate service, complaint or dispute records
WhatsApp and chat recordsFor the period necessary for the communication purpose, followed by deletion or restricted retention where appropriate
Marketing informationUntil consent is withdrawn or the relationship ends, subject to maintaining a suppression record to respect the opt-out
Cookie and consent choicesFor the period needed to demonstrate and apply the recorded preference and notice version
Data-rights and complaint recordsFor the period needed to complete the request and maintain appropriate compliance and dispute evidence
Recruitment informationFor the active recruitment process and an appropriate limited period thereafter, unless longer retention is authorized or required
Backup copiesUntil overwritten or removed under the verified backup lifecycle, with access restricted to recovery and continuity purposes

When a retention period ends, information is deleted, anonymized or placed in a restricted archive where continued retention is legally justified.

24. Account, Document and Report Deletion

You may request deletion of:

  • your account;
  • a specific application;
  • a document; or
  • a report.

Following a valid request, OPZORA will assess each relevant data category and may:

  • deactivate or restrict account access;
  • delete or anonymize operational information;
  • remove or disable the Firebase authentication user;
  • revoke relevant tokens or account connections;
  • review marketing and CRM records;
  • request deletion from relevant providers where available;
  • contact a relevant Partner where appropriate; and
  • allow backup copies to expire through the established backup lifecycle.

Some information may be retained in restricted form where necessary for:

  • accounting and tax;
  • legal or regulatory obligations;
  • fraud and security;
  • disputes or legal claims;
  • government requests; or
  • audit evidence.

Deletion from active systems does not necessarily result in immediate removal from every backup. If backup information is restored, applicable deletion restrictions should be reapplied.

25. Organizational Accounts

Organization administrators may be able to:

  • invite, manage and remove organization users;
  • assign roles and permissions;
  • access organization applications, documents and reports; and
  • manage organization workspace information.

An organization administrator should not have access to information outside the organization's authorized workspace.

When a user leaves an organization:

  • organization access should be removed or restricted;
  • relevant sessions or tokens should be revoked;
  • organization-owned records may remain under the organization's control; and
  • the access change may be recorded in an audit log.

When an organizational contract ends, data-return, export, deletion and transition arrangements may be governed by the relevant contract or data-processing agreement.

26. Security

OPZORA uses technical and organizational measures intended to be proportionate to the nature and risks of the processing.

Measures may include, where implemented and appropriate:

  • access restrictions;
  • role and permission controls;
  • authentication safeguards;
  • logging and monitoring;
  • secure communications;
  • encryption where supported and appropriate;
  • development and production separation;
  • backup and recovery arrangements;
  • confidentiality obligations;
  • provider-security requirements; and
  • access removal when personnel or contractors leave.

No online system is completely secure. OPZORA does not guarantee that a breach, loss or unauthorized access can never occur.

27. Data Subject Rights

Depending on applicable law and OPZORA's role, you may have rights to:

  • receive information about processing;
  • access your Personal Data;
  • correct incomplete or inaccurate information;
  • request deletion;
  • request restriction or cessation of processing;
  • object to certain processing;
  • withdraw consent;
  • opt out of direct marketing;
  • receive an available copy of your information;
  • request data portability where applicable;
  • dispute a screening or automated result;
  • request human review of a significant automated output; and
  • submit a complaint.

Rights may be subject to identity verification, legal exceptions and the rights of other people.

27.1 How to submit a request

Requests may be submitted through:

  • an available in-account request function;
  • privacy@opzora.ai; or
  • an authorized support channel.

Where OPZORA acts as a Processor for an organization, the request may need to be referred to that organization.

27.2 Identity verification

Verification will be proportionate to the sensitivity of the request and may include:

  • authenticated account access;
  • email verification;
  • OTP verification;
  • additional account information; or
  • an identification document where strictly necessary.

Verification documents should be deleted or restricted once no longer required.

27.3 Response target

OPZORA aims to respond to a valid request within 30 calendar days.

A shorter legal deadline will apply where required. A permitted extension may be used for a complex request, with an explanation provided where required.

27.4 Data export

Where appropriate, data may be provided in formats such as:

  • CSV or JSON for structured account and form information;
  • PDF or original report format;
  • original file format for uploaded documents; and
  • a secure, encrypted or expiring delivery method.

Information affecting third-party rights, trade secrets or platform security may be restricted or redacted.

28. Marketing Choices

Transactional or service communications may include:

  • account verification;
  • OTP;
  • security alerts;
  • report and application updates;
  • payment confirmation;
  • support responses; and
  • required legal notices.

These messages are separate from marketing.

Marketing communications may include newsletters, service announcements, Partner offers or promotional messages.

Where required, marketing is based on valid consent or another permitted legal ground. Each marketing message should provide an appropriate method to unsubscribe.

Withdrawing marketing consent does not prevent OPZORA from sending necessary account, service, security or legal communications.

Telephone numbers and OTP information are not used for marketing without a separate valid basis.

29. Children and Minimum Age

OPZORA services are intended for individuals aged 18 or older.

Individuals under 18 may not create an account.

OPZORA does not knowingly seek Personal Data from individuals under 18. If such information is identified, OPZORA may restrict the relevant account or record, investigate the circumstances and delete the information where appropriate.

30. Government and Legal Disclosures

OPZORA may disclose Personal Data where required by applicable law, a valid court order, a competent regulator or another lawful authority.

Before disclosure, OPZORA may assess:

  • the authority's identity and jurisdiction;
  • the legal basis of the request;
  • necessity and proportionality;
  • the minimum information required;
  • whether the request can lawfully be challenged or narrowed; and
  • whether the affected person may be notified.

OPZORA does not automatically provide all information requested without an appropriate legal assessment.

31. Business Transfers

If OPZORA or its business is involved in a merger, restructuring, financing, acquisition, sale, insolvency or transfer of assets, Personal Data may be reviewed or transferred as part of that transaction.

Appropriate confidentiality, due-diligence and data-protection measures should apply, and users will be informed where required by law.

32. Changes to This Privacy Policy

OPZORA may update this Privacy Policy to reflect changes in:

  • services and processing activities;
  • authentication or technology providers;
  • AI or document-processing workflows;
  • Partners;
  • applicable law;
  • international transfers;
  • user rights; or
  • security and operational requirements.

The Effective Date, Version Number and Last Reviewed Date will be updated when appropriate.

Material changes may be summarized or communicated through the website, account, email or another appropriate channel.

Previous versions should be retained in controlled internal records.

33. Contact and Complaints

For privacy questions, requests or complaints, contact:

OPZORA.AI & PR LLC

OPZORA

Dubai, United Arab Emirates

A privacy complaint may be registered, verified where necessary, reviewed by the internal Privacy Lead and answered with a reasoned response.

You may also have the right to complain to a competent data-protection authority or court under the law applicable to you.