Legal

Privacy Policy

Smartbound – Athon L.L.C-FZ, Dubai, UAE

  1. 1. Information We Collect

    We collect information in three ways:

    • Information you give us directly: your name, email address, company, phone number, job title, and any message content, when you submit our contact form, register for a webinar, join a waitlist, or create a Client Portal account.
    • Information generated through using our services : if you are a client, this includes prospect and lead data processed on your behalf through our outbound engine (contact details, company information, engagement and reply history), and account activity within AthonBound Studio and the Client Portal.
    • Technical information: standard web server logs (IP address, browser type, pages visited, timestamps) collected automatically by the server that serves our website, and session identifiers needed to keep you logged in to AthonBound Studio or the Client Portal.
  2. 2. How We Use Your Information

    We use the information we collect to:

    • Respond to your inquiries and provide the services you request;
    • Create and administer your AthonBound Studio or Client Portal account, including authentication and access control;
    • Deliver the outbound and market-intelligence services you have engaged us for, on your behalf and under your instructions;
    • Send transactional communications (account notifications, invite and access emails, invoices, service updates);
    • Send marketing communications about our services, webinars, or content, where you have opted in or where permitted by applicable law, and always with an option to opt out;
    • Maintain the security, integrity, and proper functioning of our systems;
    • Comply with our legal, tax, and regulatory obligations.
  3. 3. Legal Basis for Processing (GDPR)

    Where the GDPR applies to our processing of your personal data, we rely on the following legal bases:

    • Contract: processing necessary to provide the services you or your organization have engaged us for, including operating your Client Portal or Studio account;
    • Consent: for marketing communications, webinar and waitlist sign-ups, and any non-essential cookies, which you can withdraw at any time;
    • Legitimate interest: for website security, service improvement, and B2B communications reasonably related to our services, balanced against your rights and expectations;
    • Legal obligation: for record-keeping required by tax, accounting, or other applicable law.
  4. 4. Data Retention

    We keep personal data only for as long as necessary for the purposes described in this policy, or as required by law. In practice, our systems apply the following retention rules:

    • Client documents (proposals, contracts) are subject to a configurable retention window (typically 90–365 days) after which they are automatically removed, unless retention is disabled by the client; invoices are retained without an automatic deletion window, as fiscal records;
    • Support and team chat messages are retained for 90 days;
    • Leads discarded during our review process have their personal details (name, email, phone, and message content) removed 30 days after the decision, while a minimal internal record (date, source campaign, and reason) is kept indefinitely for audit purposes;
    • Cancelled or ended billing schedules and discount records are permanently deleted 90 days after cancellation;
    • Contact form and webinar/waitlist submissions are retained for as long as reasonably necessary to respond to your inquiry or deliver the service requested, and are reviewed periodically.

    You may request earlier deletion of your data at any time: see “Your Rights” below.

  5. 5. Data Sharing

    We do not sell your personal data. We share personal data only with service providers who process it on our behalf, under contractual confidentiality and data-protection obligations, including:

    • Cloud hosting and database infrastructure providers (Supabase, Render);
    • Transactional and marketing email delivery providers (Resend);
    • Outbound engagement infrastructure used to run campaigns on behalf of clients (Smartlead), where you are a lead within a client’s campaign;
    • Payment and billing processors (Stripe), for invoicing and subscription management.

    There are no website statistics to share: we do not collect any.

    We may also disclose personal data where required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets, subject to the same protections described here.

  6. 6. International Data Transfers

    AthonBound is based in Dubai, United Arab Emirates. Some of our service providers process data in other jurisdictions, including the European Union and the United States. Where personal data protected by the GDPR is transferred outside the European Economic Area, we rely on appropriate safeguards, such as Standard Contractual Clauses or equivalent mechanisms, to ensure it remains protected consistently with this policy.

  7. 7. Cookies and local storage

    This website stores as little as possible on your device, and nothing at all for advertising or cross-site tracking:

    • Language preference (ab_lang): set when you pick a language, or answer the language prompt on your first visit. It stores only “en” or “it”, lasts twelve months, and exists so we stop asking. As a preference you asked for, it does not require consent.
    • Session cookie (Studio and Client Portal): a single strictly-necessary cookie that keeps you signed in securely. Without it, the service cannot function. It is never used for tracking or advertising, and never shared.
    • Webinar registration flag: if you register for a webinar, your browser remembers that locally so the page shows you the player instead of the form again.

    Analytics: none. We do not measure your visit. There is no analytics software on this site, no page-view counter, no event tracking and no advertising or tracking network of any kind. The server that serves the site keeps ordinary technical request logs, as any web server does, to run and protect it; they are not used to profile anyone.

    If we ever add analytics, advertising or other non-essential cookies, we will update this policy and ask for your consent first.

  8. 8. Your Rights (GDPR)

    If the GDPR applies to you, you have the right to:

    • Access the personal data we hold about you;
    • Request correction of inaccurate or incomplete data;
    • Request deletion of your data, subject to our legal retention obligations;
    • Request restriction of, or object to, certain processing;
    • Request a portable copy of the data you provided to us;
    • Withdraw consent at any time, where processing is based on consent;
    • Lodge a complaint with your local data protection supervisory authority.

    To exercise any of these rights, contact us using the details in “Contact Information” below. We answer within one month, as the GDPR requires.

  9. 9. Data Security

    We apply industry-standard technical and organizational measures to protect your data, including encryption of data in transit (HTTPS/TLS), hashed password storage, role-based access controls, and restricted internal access to personal data on a need-to-know basis. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security, but we work to keep these safeguards current and to respond promptly to any incident.

  10. 10. Changes to This Policy

    We may update this policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. When we make material changes, we will update the date below and, where appropriate, provide additional notice. We encourage you to review this page periodically.

    Last updated: 3 September 2026.

  11. 11. Contact Information

    If you have questions about this policy or wish to exercise your data protection rights, please contact us through our contact page, or write to:

    Smartbound – Athon L.L.C-FZ
    Dubai, United Arab Emirates