Privacy Policy

Last updated: 2 August 2026

FlareFalcon respects your privacy and is committed to protecting the personal data that we collect and process.

This Privacy Policy explains how FlareFalcon collects, uses, stores and shares personal data when you visit flarefalcon.ai, submit a website for an AI-readiness snapshot, contact us or purchase services through the website.

1. About FlareFalcon

FlareFalcon is a generative engine optimisation agency based in Dubai, United Arab Emirates.

For the purposes of applicable data protection law, FlareFalcon is the controller of the personal data described in this Privacy Policy unless otherwise stated.

You can contact us about privacy or data protection matters at:

Email: [email protected]

Location: Dubai, United Arab Emirates

2. Laws Covered by This Policy

We process personal data in accordance with applicable data protection and privacy laws, which may include:

  • UAE Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data
  • The European Union General Data Protection Regulation, where it applies
  • The United Kingdom General Data Protection Regulation and Data Protection Act 2018, where they apply
  • Applicable electronic communications, direct marketing and cookie laws

The rights and legal requirements that apply in a particular case may depend on where you are located and the circumstances in which we process your data.

3. Personal Data We Collect

3.1 Information You Provide Directly

We may collect information that you submit through our website, including:

  • Your name
  • Your email address
  • Your telephone number
  • Your organisation or business name
  • Your job title
  • Your website address
  • The services you are interested in
  • Information included in an enquiry or message
  • Any files, documents or other information you choose to provide
  • Your communication preferences

You should not submit sensitive personal data through our website unless we specifically request it and there is a lawful reason for doing so.

3.2 AI-Readiness Snapshot Information

When you request a free AI-readiness snapshot or similar audit, we may collect:

  • The submitted website URL
  • The domain name and publicly accessible website content
  • Your name and contact details, where requested
  • Technical information about the submitted website
  • Website performance, crawlability and rendering information
  • robots.txt, sitemap and structured-data information
  • Machine-readable files and publishing resources
  • Business-clarity and AI-readiness signals
  • Audit scores, findings and generated reports
  • Information about when and how the audit was requested

The audit may process publicly available information from the submitted website and related public sources.

You must only submit a website where you are authorised to request the audit or have a legitimate reason to assess it.

3.3 Technical and Usage Information

When you use our website, we and our service providers may automatically collect information such as:

  • Internet Protocol address
  • Browser type and version
  • Device type
  • Operating system
  • General geographic location derived from an Internet Protocol address
  • Referral source
  • Pages viewed
  • Links and buttons selected
  • Session duration
  • Date and time of visits
  • Website errors and performance information
  • Cookie identifiers and similar online identifiers
  • Consent and cookie-preference records

3.4 Payment and Transaction Information

When online payments are introduced, payments will be processed by a third-party payment gateway.

We may collect or receive:

  • Your name
  • Billing address
  • Email address
  • Organisation details
  • Transaction amount
  • Currency
  • Payment status
  • Invoice details
  • Transaction or payment reference
  • Limited payment-method information, such as the card type and final digits

Complete payment-card details will normally be collected and processed directly by the payment provider rather than stored by FlareFalcon.

The payment provider will process personal data under its own privacy policy and legal obligations. We will update this Privacy Policy or provide additional information when a payment provider is selected.

4. How We Use Personal Data

We may use personal data to:

  • Respond to enquiries and communicate with prospective clients
  • Provide requested AI-readiness snapshots and reports
  • Analyse submitted websites and publicly accessible website information
  • Prepare proposals, quotations and service recommendations
  • Deliver GEO, technical, content, monitoring and public relations services
  • Create and manage client relationships
  • Process orders, payments, invoices and refunds
  • Provide support and respond to service-related questions
  • Operate, maintain and secure our website
  • Diagnose errors and improve website performance
  • Measure how visitors use the website
  • Improve our audits, reports, services and user experience
  • Maintain records of consent and communication preferences
  • Prevent fraud, misuse, security incidents and unlawful activity
  • Establish, exercise or defend legal claims
  • Meet legal, regulatory, accounting and tax obligations
  • Send marketing communications where permitted
  • Manage our suppliers, contractors and professional advisers

We will not use personal data for purposes that are incompatible with the purposes described in this policy unless permitted or required by law.

5. Legal Bases for Processing

Where GDPR or UK GDPR applies, we rely on one or more of the following legal bases.

5.1 Taking Steps Before Entering a Contract

We may process your information when you ask about our services, request an audit, request a quotation or take other steps before entering into an agreement with us.

This may apply when we:

  • Respond to a service enquiry
  • Prepare a proposal or quotation
  • Provide a requested AI-readiness snapshot
  • Discuss your requirements
  • Assess whether we can provide the requested services

5.2 Performance of a Contract

We process personal data where necessary to provide services under an agreement with you or your organisation.

This may include:

  • Delivering audits and reports
  • Providing technical or consulting services
  • Managing a client account
  • Processing payments and invoices
  • Providing customer support
  • Communicating about ongoing work

5.3 Legitimate Interests

We may process personal data where it is necessary for our legitimate business interests and those interests are not overridden by your rights and freedoms.

Our legitimate interests may include:

  • Operating and improving our business and website
  • Responding to business enquiries
  • Understanding demand for our services
  • Maintaining accurate business records
  • Measuring website performance
  • Securing our systems
  • Preventing fraud and misuse
  • Developing and improving audit processes
  • Managing professional relationships
  • Recovering debts
  • Establishing, exercising or defending legal claims

Where required, we assess the nature and impact of the processing before relying on legitimate interests.

5.4 Consent

We may rely on your consent where required, including for:

  • Non-essential analytics cookies
  • Certain marketing communications
  • Any optional processing that requires permission under applicable law

You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

5.5 Legal Obligations

We may process personal data where necessary to comply with legal or regulatory obligations, including:

  • Accounting and tax requirements
  • Responding to lawful requests from authorities
  • Maintaining required business records
  • Preventing or reporting unlawful activity
  • Complying with court orders and legal proceedings

5.6 Legal Claims and Vital Interests

Where appropriate and permitted by law, we may process personal data to protect a person's vital interests or to establish, exercise or defend legal claims.

6. Automated Audits and Decision-Making

Our free AI-readiness snapshot may use automated systems to inspect website and technical signals and calculate a proprietary readiness score.

The automated snapshot may analyse factors such as:

  • Website availability
  • Performance and page-quality signals
  • Crawlability
  • robots.txt and sitemap availability
  • Structured data
  • Machine-readable resources
  • Business-clarity signals
  • Technical and AI-readiness indicators

The automated score is an informational indicator. It does not determine your legal rights, access to essential services, creditworthiness or eligibility for employment.

The snapshot does not establish whether an organisation is currently cited, ranked or recommended by an AI platform. Important commercial or technical decisions should not be based solely on an automated snapshot without appropriate human review.

7. Google Analytics

We use Google Analytics to understand how visitors interact with our website.

Google Analytics may collect information such as:

  • Pages visited
  • Approximate location
  • Device and browser information
  • Referral source
  • Interactions with website features
  • Session timing and duration
  • Online identifiers
  • Internet Protocol address and information derived from it

Google may process this information on our behalf to provide analytics reports and related services.

Where legally required, Google Analytics will only be activated after you give consent through our cookie banner or preference tool.

Google may process information on servers located outside your country. Its processing is governed by its own terms, privacy documentation and applicable data-transfer safeguards.

You can manage non-essential analytics cookies through our website's cookie controls. You may also restrict cookies through your browser settings, although this may affect certain website features.

8. Cookies and Similar Technologies

Cookies are small files stored on your device when you visit a website. We may also use similar technologies, including tags, pixels, local storage and software development tools.

8.1 Strictly Necessary Cookies

These cookies are required for the website to function or to provide a feature you request.

They may be used to:

  • Maintain website security
  • Remember privacy preferences
  • Enable forms
  • Balance website traffic
  • Prevent fraud or misuse

Where permitted by law, strictly necessary cookies may be used without consent.

8.2 Analytics Cookies

Analytics cookies help us understand how visitors use the website and identify opportunities to improve it.

These cookies may measure:

  • Visitor numbers
  • Traffic sources
  • Page views
  • Website interactions
  • Session duration
  • Errors and performance

Where required by applicable law, analytics cookies will not be placed until you consent.

8.3 Payment Cookies

When online payments are introduced, the payment gateway may use cookies or similar technologies for:

  • Processing transactions
  • Fraud prevention
  • Security
  • Authentication
  • Remembering payment preferences

The payment provider may control some of these technologies and explain them in its own privacy and cookie documentation.

8.4 Managing Cookies

You can accept, reject or manage non-essential cookies through the cookie controls displayed on our website.

You can also delete or restrict cookies through your browser. Browser restrictions may prevent parts of the website from operating correctly.

9. Marketing Communications

We may send you information about our services where:

  • You have consented to receive it
  • You are an existing client and the communication is permitted by law
  • We otherwise have a lawful basis to contact you

You can unsubscribe at any time by:

Service messages, payment notices and other essential communications are not marketing and may still be sent where necessary.

We do not sell personal data to third parties for their own direct marketing.

10. How We Share Personal Data

We may share personal data with carefully selected third parties where necessary, including:

  • Website hosting and infrastructure providers
  • Cloud storage providers
  • Email and communication providers
  • Website analytics providers
  • Audit, automation and reporting technology providers
  • Customer relationship management providers
  • Payment gateways and payment processors
  • Accounting, banking and invoicing providers
  • IT support and cybersecurity providers
  • Contractors and professional service providers
  • Lawyers, accountants, insurers and other advisers
  • Regulators, law-enforcement bodies and public authorities
  • A buyer, investor or successor involved in a sale, merger, restructuring or transfer of the business

Service providers are permitted to use personal data only for the agreed purposes or as otherwise allowed by law.

We may disclose information where reasonably necessary to comply with law, enforce an agreement, protect our rights or investigate suspected fraud, abuse or security threats.

11. International Data Transfers

FlareFalcon is based in the United Arab Emirates, and personal data may be processed in the UAE and other countries where our service providers operate.

Some recipients may be located outside the country in which you live. Those countries may have different data protection laws.

Where required, we use appropriate measures to protect international transfers, which may include:

  • Contractual data-protection obligations
  • Standard contractual clauses
  • Transfers to countries recognised as providing adequate protection
  • Supplementary technical and organisational safeguards
  • Other lawful transfer mechanisms

By submitting information to a business based in the UAE, you acknowledge that your information may be processed in the UAE, subject to applicable legal safeguards.

12. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including legal, accounting, security and dispute-resolution requirements.

Our anticipated retention periods include:

  • Unsuccessful or general enquiries: Normally up to 24 months after the most recent substantive communication.
  • AI-readiness snapshot submissions and reports: Normally up to 24 months, unless a longer period is required for service delivery, security, benchmarking or legal purposes.
  • Client and contractual records: For the duration of the relationship and normally up to seven years afterwards.
  • Invoices, payments and accounting records: Normally up to seven years or for the period required by applicable tax and accounting law.
  • Analytics information: According to the retention settings configured within Google Analytics.
  • Cookie consent records: For as long as reasonably necessary to demonstrate and manage your preferences.
  • Marketing records: Until you unsubscribe or object, after which we may retain a limited suppression record to ensure that your preference is respected.
  • Security logs: For a period proportionate to the security risk and operational need.

We may retain information for longer where necessary to resolve a dispute, respond to a legal claim, comply with law or investigate fraud or security incidents.

We may retain anonymised information indefinitely because it no longer identifies an individual.

13. Data Security

We use reasonable technical and organisational measures designed to protect personal data against:

  • Unauthorised access
  • Accidental loss
  • Unlawful disclosure
  • Alteration
  • Destruction
  • Misuse

These measures may include access controls, authentication, encryption, secure hosting, backups, system monitoring, software updates and restrictions on staff and contractor access.

No online service or data-transmission method can be guaranteed to be completely secure. You are responsible for using appropriate care when sending information online.

14. Your Data Protection Rights

Depending on the law that applies to you, you may have the right to:

  • Request confirmation that we process your personal data
  • Request access to your personal data
  • Request correction of inaccurate or incomplete data
  • Request deletion of personal data
  • Request restriction of processing
  • Object to processing based on legitimate interests
  • Object to direct marketing
  • Withdraw consent
  • Request the transfer of data in a structured, commonly used and machine-readable format
  • Request information about international transfers
  • Request human review of certain automated decisions
  • Complain to an applicable data protection authority

These rights are not absolute. We may need to retain or continue processing certain information where permitted or required by law.

To exercise a right, contact [email protected].

We may need to verify your identity before fulfilling a request. We will respond within the period required by applicable law.

We normally do not charge a fee for a reasonable request. We may charge a reasonable fee or refuse a request where permitted by law, including where it is manifestly unfounded, excessive or repetitive.

15. Complaints

Please contact us first if you have a concern about how we use your personal data:

[email protected]

You may also have the right to complain to the data protection authority responsible for your jurisdiction.

For visitors in the United Kingdom, this may be the Information Commissioner's Office.

For visitors in the European Economic Area, this may be the supervisory authority in the country where you live, work or believe an infringement occurred.

For visitors in the UAE, complaints may be directed to the competent UAE data-protection authority where applicable.

16. Third-Party Websites and Services

Our website may link to third-party websites, platforms or services.

We do not control those third parties and are not responsible for their privacy practices. You should review the privacy policy of any external website or service before providing personal data.

17. Children's Privacy

Our website and services are intended for businesses and adults. They are not directed towards children.

We do not knowingly collect personal data directly from children. If you believe that a child has submitted personal data to us, contact [email protected] so that we can investigate and take appropriate action.

18. Changes to This Privacy Policy

We may update this Privacy Policy when:

  • Our services or data-processing practices change
  • We appoint new service providers
  • We introduce online payments or new website features
  • Applicable laws or regulatory guidance change

The latest version will be published on this page with an updated "Last updated" date.

Material changes may also be communicated through the website or directly to affected individuals where appropriate.

19. Contact Us

Questions, requests and complaints concerning this Privacy Policy or our use of personal data should be sent to:

FlareFalcon

Dubai, United Arab Emirates

Email: [email protected]

Website: https://flarefalcon.ai/

ChatGPT
Claude
Gemini
Microsoft Copilot
Perplexity
Grok
DeepSeek
Meta AI
Apple Intelligence