LEGAL
Privacy Policy
Effective 1 July 2026
This policy explains how Scholarix Global Consultant FZE (trading as SGC Tech AI) handles personal data collected through sgctech.ai and related correspondence. We process data in line with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and its executive regulations.
What data we collect
We collect the minimum needed to operate the site and respond to enquiries. We do not buy or trade data.
Contact enquiries you send us
When you email info@sgctech.ai (or use a CTA that opens your mail client), we receive your name, email address, organisation, and the contents of your message. We use these only to reply.
Server logs
Our hosting provider records standard request metadata: IP address, user-agent, referrer, timestamp, and the resource requested. Logs are kept for 30 days for security and capacity planning, then deleted.
Aggregated analytics
We do not use third-party analytics, advertising pixels, or session-replay tools. We count page views from our own server logs only.
How we use it
Three purposes, narrowly defined.
- 01
To respond to your enquiry and provide the services you requested.
- 02
To operate, secure, and improve sgctech.ai (e.g. diagnosing outages, blocking abuse).
- 03
To comply with UAE law and respond to lawful requests from public authorities.
Lawful basis
We rely on one or more of the following PDPL grounds for each processing activity: your consent, performance of a contract you have asked us to perform, our legitimate interests in operating a secure service, or compliance with a legal obligation.
Where we rely on legitimate interests, we balance them against your rights and apply the minimum-data principle. You can ask us about the specific basis for any processing at any time.
Sharing and processors
We do not sell or rent personal data. We share it only with vetted processors who help us operate the site, and only as much as they need to do their job.
- Hosting & CDN — Vercel and a CDN provider host and serve sgctech.ai. They process request logs on our behalf under written processor terms.
- Email delivery — Outbound enquiry emails route through a transactional email provider for delivery. They receive the email content you send.
- Legal — If compelled by a lawful UAE order, we will disclose the minimum data required to comply.
Retention
We keep data only as long as we have a reason to keep it.
- Enquiry correspondence — up to 24 months from last contact, then archived or deleted.
- Server logs — 30 days, then deleted automatically.
- Engagement records — for the duration of the engagement plus the UAE statutory record-keeping window (typically 7 years for financial records).
Your rights under PDPL
You can exercise any of these at any time by emailing privacy@sgctech.ai.
Request a copy of the personal data we hold about you.
Request correction of inaccurate or incomplete data.
Request deletion of your data, subject to our record-keeping obligations.
Withdraw consent at any time, where processing is based on consent.
Lodge a complaint with the UAE Data Office.
International transfers
Some of our processors store data outside the UAE. Where we do, we rely on the PDPL transfer mechanisms and put contractual safeguards in place.
Hosting is delivered from regions we select for latency and redundancy. A current list of regions and safeguards is available on request.
Cookies and similar technologies
sgctech.ai does not set marketing, advertising, or analytics cookies. We use a single first-party session marker (a 32-byte opaque value) to remember that you have already seen the loading splash, so we don't re-flash it on every navigation.
You can clear it via your browser's site-data settings at any time. Clearing it just means you'll see the splash once on your next visit.
Google user data (app.sgctech.ai)
This section applies specifically to app.sgctech.ai, our Odoo-based workspace for team members and client-portal users. It does not apply to sgctech.ai, which does not request Google sign-in or any Google API access.
app.sgctech.ai offers "Sign in with Google" as one login option for its workspace, alongside email/password and passkey sign-in. Once signed in, app.sgctech.ai can also connect to Google Calendar, Google Meet, and Google Drive for the specific, narrow purposes below. We request only the following:
- Sign-in (name, email address, profile photo) — requested via the openid, userinfo.email, and userinfo.profile scopes, used only to create and authenticate your workspace account.
- Calendar (.../auth/calendar.events) — used to create, update, and cancel client meeting events on your Google Calendar on your behalf.
- Meet (.../auth/meetings.space.created) — used only to create and manage the Google Meet video-conferencing space attached to a scheduled event. We do not access, capture, or record meeting audio or video.
- Drive (.../auth/drive.file) — used only to store and retrieve automated database backup files that app.sgctech.ai itself creates in your Drive. This scope cannot see or touch any other file already in your Drive.
Storage and security — app.sgctech.ai is self-hosted on SGC Tech AI's own server infrastructure, not a third-party cloud platform. Your Google profile data and OAuth tokens are stored in the Odoo database on that infrastructure, and access is restricted to authorized SGC Tech AI administrators. Calendar events and Meet spaces created through the app live in your own Google Account, the same as if you created them yourself. Backup files created by the Drive integration are stored in your connected Google Drive, not on our servers.
Sharing — We do not sell Google user data or use it for advertising. Because app.sgctech.ai is self-hosted, no third-party platform processor handles this data on our behalf; it is not shared beyond SGC Tech AI, except if compelled by a lawful UAE order.
Retention and deletion — Google sign-in data is retained for as long as your workspace account is active. Calendar events and Meet spaces created through the app persist until you or we delete the underlying event — deleting it in either Odoo or Google Calendar removes it from both. Backup files in Drive are kept until superseded by a newer backup or manually deleted by an administrator. If you disconnect Google sign-in or your account is deleted, we stop creating new Calendar/Meet/Drive data on your behalf.
Your control — You can review or revoke app.sgctech.ai's access to your Google account at any time at myaccount.google.com/permissions. To request deletion of data already synced to app.sgctech.ai, email privacy@sgctech.ai.
Limited Use disclosure — SGC Tech AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Updates to this policy
When we change this policy in a material way, we will post a notice on sgctech.ai with the new effective date. The previous version is available on request.
Contact
Data controller: Scholarix Global Consultant FZE, Maseed Building Office No. 304, 119/12st, Al Rigga, Dubai (AE), United Arab Emirates.
Privacy enquiries: privacy@sgctech.ai
See also: Terms of Service