Legal

Privacy Policy

Smartbound – Athon L.L.C-FZ, Dubai, UAE

  1. 1. Information We Collect

    We collect information in three ways:

    • Information you give us directly — your name, email address, company, phone number, job title, and any message content, when you submit our contact form, register for a webinar, join a waitlist, or create a Client Portal account.
    • Information generated through using our services — if you are a client, this includes prospect and lead data processed on your behalf through our outbound engine (contact details, company information, engagement and reply history), and account activity within AthonBound Studio and the Client Portal.
    • Technical information — standard web server logs (IP address, browser type, pages visited, timestamps) collected automatically when you visit our website, and session identifiers needed to keep you logged in to AthonBound Studio or the Client Portal.
  2. 2. How We Use Your Information

    We use the information we collect to:

    • Respond to your inquiries and provide the services you request;
    • Create and administer your AthonBound Studio or Client Portal account, including authentication and access control;
    • Deliver the outbound and market-intelligence services you have engaged us for, on your behalf and under your instructions;
    • Send transactional communications (account notifications, invite and access emails, invoices, service updates);
    • Send marketing communications about our services, webinars, or content, where you have opted in or where permitted by applicable law, and always with an option to opt out;
    • Maintain the security, integrity, and proper functioning of our systems;
    • Comply with our legal, tax, and regulatory obligations.
  3. 3. Legal Basis for Processing (GDPR)

    Where the GDPR applies to our processing of your personal data, we rely on the following legal bases:

    • Contract — processing necessary to provide the services you or your organization have engaged us for, including operating your Client Portal or Studio account;
    • Consent — for marketing communications, webinar and waitlist sign-ups, and any non-essential cookies, which you can withdraw at any time;
    • Legitimate interest — for website security, service improvement, and B2B communications reasonably related to our services, balanced against your rights and expectations;
    • Legal obligation — for record-keeping required by tax, accounting, or other applicable law.
  4. 4. Data Retention

    We keep personal data only for as long as necessary for the purposes described in this policy, or as required by law. In practice, our systems apply the following retention rules:

    • Client documents (proposals, contracts) are subject to a configurable retention window (typically 90–365 days) after which they are automatically removed, unless retention is disabled by the client; invoices are retained without an automatic deletion window, as fiscal records;
    • Support and team chat messages are retained for 90 days;
    • Leads discarded during our review process have their personal details (name, email, phone, and message content) removed 30 days after the decision, while a minimal internal record (date, source campaign, and reason) is kept indefinitely for audit purposes;
    • Cancelled or ended billing schedules and discount records are permanently deleted 90 days after cancellation;
    • Contact form and webinar/waitlist submissions are retained for as long as reasonably necessary to respond to your inquiry or deliver the service requested, and are reviewed periodically.

    You may request earlier deletion of your data at any time — see “Your Rights” below.

  5. 5. Data Sharing

    We do not sell your personal data. We share personal data only with service providers who process it on our behalf, under contractual confidentiality and data-protection obligations, including:

    • Cloud hosting and database infrastructure providers (Supabase, Render);
    • Transactional and marketing email delivery providers (Resend);
    • Outbound engagement infrastructure used to run campaigns on behalf of clients (Smartlead), where you are a lead within a client’s campaign;
    • Payment and billing processors (Stripe), for invoicing and subscription management.

    We may also disclose personal data where required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets, subject to the same protections described here.

  6. 6. International Data Transfers

    AthonBound is based in Dubai, United Arab Emirates. Some of our service providers process data in other jurisdictions, including the European Union and the United States. Where personal data protected by the GDPR is transferred outside the European Economic Area, we rely on appropriate safeguards, such as Standard Contractual Clauses or equivalent mechanisms, to ensure it remains protected consistently with this policy.

  7. 7. Your Rights (GDPR)

    If the GDPR applies to you, you have the right to:

    • Access the personal data we hold about you;
    • Request correction of inaccurate or incomplete data;
    • Request deletion of your data, subject to our legal retention obligations;
    • Request restriction of, or object to, certain processing;
    • Request a portable copy of the data you provided to us;
    • Withdraw consent at any time, where processing is based on consent;
    • Lodge a complaint with your local data protection supervisory authority.

    To exercise any of these rights, contact us using the details in “Contact Information” below.

  8. 8. Cookies

    Our marketing website (athonbound.com) does not use analytics or advertising cookies. AthonBound Studio and the Client Portal use a single strictly-necessary session cookie to keep you signed in securely; without it, the service cannot function. We do not use this cookie for tracking or advertising, and it is never shared with third parties. If this changes in the future, we will update this policy and request consent where required.

  9. 9. Data Security

    We apply industry-standard technical and organizational measures to protect your data, including encryption of data in transit (HTTPS/TLS), hashed password storage, role-based access controls, and restricted internal access to personal data on a need-to-know basis. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security, but we work to keep these safeguards current and to respond promptly to any incident.

  10. 10. Changes to This Policy

    We may update this policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. When we make material changes, we will update the date below and, where appropriate, provide additional notice. We encourage you to review this page periodically.

    Last updated: 24 July 2026.

  11. 11. Contact Information

    If you have questions about this policy or wish to exercise your data protection rights, please contact us through our contact page, or write to:

    Smartbound – Athon L.L.C-FZ
    Dubai, United Arab Emirates