DigiCore
  • Home
  • Products
    • DigiSIgn
    • DigiVerify
    • DigiVouch
    • AI Fabric
    • DigiVouch Platform
  • Technology
  • About
  • Partners
AI Empowered
← Back to home

Privacy Policy

Last updated: 23 July 2026
Effective date: 22 July 2026

1. Introduction

This Privacy Policy explains how شركة اريزونا للبرمجة و الانظمة الذكية (Arizona for Programming and Intelligent Systems Co.) ("DigiCore", "AIS", "we", "us", or "our") collects, uses, discloses, and protects personal data when you visit www.aisdigicore.com (the "Website"), contact us through it, or download materials from it.

We are a financial technology provider serving banks and financial institutions across the Middle East. We treat the protection of personal data as a core professional obligation, not a formality.

Please read this Policy carefully. If you do not agree with it, please do not use the Website.

1.1 Scope of this Policy — please read

This Policy applies only to this Website and to direct business communications with us.

It does not apply to personal data that we process on behalf of our clients when our products — including DigiSign, DigiVouch, DigiVerify, DigiIntellect (AI Fabric), and the DigiVouch Platform — are deployed within a client's environment. In those engagements, our client (the financial institution) is the data controller and determines the purposes and means of processing. We act solely as a data processor under a written agreement, and the client's own privacy notice governs the relationship with its customers.

If you are a customer of a bank that uses our software and have a question about your personal data, please contact that bank directly.

Artificial intelligence and client data. Where our products include AI or machine-learning capabilities — DigiIntellect (AI Fabric) in particular — we do not use personal data belonging to a client, or to that client’s customers, to train, fine-tune, or otherwise improve any model for our own purposes or for the benefit of any other client. Client data is processed only within that client’s own environment and only on that client’s documented instructions, as its processor. Any model trained on a client’s data belongs to that engagement and is governed by the written agreement for it.

2. Who We Are and How to Contact Us

Data Controller: شركة اريزونا للبرمجة و الانظمة الذكية
English name: Arizona for Programming and Intelligent Systems Co.
Commercial Registration No.: 200160506
Place of registration: Hashemite Kingdom of Jordan
Registered Address: Office 31, AlKaradsheh Tower, Wadi Saqra, Amman, Jordan, 11195, P.O. Box 3028
Email: privacy@aisdigicore.com
General enquiries: Sales@aisdigicore.com
Telephone: +962 7 9907 8081

Data Protection Officer: Razan Arab, Legal Advisor
DPO email: dpo@aisdigicore.com

For any question, request, or complaint regarding this Policy or your personal data, contact us at privacy@aisdigicore.com. You may also contact our Data Protection Officer directly at dpo@aisdigicore.com or at the postal address above.

3. Personal Data We Collect

3.1 Information you provide directly

Contact Request form. When you submit a contact request, we collect:

DataRequiredPurpose
Full nameYesTo identify and address you
Mobile numberNoOnly if you would prefer us to telephone you rather than email. Leave it blank and we will reply by email
Email addressYesTo respond to your enquiry
Company nameNoTo understand the business context of your enquiry

Direct correspondence. If you email, call, or contact us via social media, we retain the content of that correspondence and your contact details.

Business and event interactions. If you meet us at a conference, request a demonstration, or exchange business cards, we may record your name, role, organisation, and business contact details.

We do not ask for and do not want sensitive personal data through this Website — including data revealing health, religious or philosophical beliefs, political opinions, biometric or genetic data, or financial account details. Please do not submit such information through the contact form or by email.

3.2 Information collected automatically

When you visit the Website, our servers and infrastructure providers automatically record technical information, including:

  • IP address
  • Browser type, version, and language settings
  • Operating system and device type
  • Pages viewed, time spent, and navigation paths
  • Referring website or search term
  • Date and time of access

This information is collected in server logs for security, fraud prevention, abuse detection, and performance monitoring.

3.3 Website usage measurement (our own analytics)

We measure how the Website is used, using our own software running on our own servers. No third-party analytics service is involved, and no measurement data is sent to anyone else. We do not use Google Analytics, Meta Pixel, or any comparable tool.

We record:

WhatDetail
Pages viewedThe page address and time of the request, whether the page loaded successfully, how long our server took to respond, the referring website or search engine, and any campaign tags contained in the link you followed
Which product you read aboutWhich product tab you opened in the products section, and approximately how long it remained on screen
Brochures downloadedWhich document was downloaded, and the page it was requested from
Video engagementWhich video was played, how much of it was watched, and how far through it you reached
Technical characteristicsDevice type (desktop, mobile, or tablet) and browser family

We do not store your IP address in this measurement data. Your IP address is combined with a secret value and the current date and put through a one-way cryptographic function (SHA-256); only a short extract of the result is stored. The secret is held separately from the measurement data and is not disclosed.

This is pseudonymisation, not anonymisation, and we describe it that way deliberately. The stored code is designed so that it cannot practicably be reversed to recover your IP address by anyone holding the measurement data alone. It is not a mathematical impossibility: the range of possible IP addresses is small enough that somebody who obtained our secret could work backwards from a code to an address. We therefore continue to treat these codes as personal data and protect them accordingly, rather than claiming they fall outside data protection law.

Because the date forms part of the input, the same visitor produces a different code the following day. This lets us count how many distinct people visited on a given day; it does not let us recognise you across days.

Where a web address contains a parameter whose name suggests a sensitive value — for example an email address, token, password, key, one-time code, telephone number, or national identification number — the value is replaced with [redacted] before anything is written to our records. We never record what you type into a form through this measurement.

Automated traffic — search engine crawlers and other robots — is identified and excluded from every figure.

This measurement produces aggregate statistics about how the Website is used. It does not create a profile of you, is not used for advertising, is not combined with any other data set, and is never shared or sold.

Measurement begins when you first open the Website, and you can switch it off at any time from the Cookie settings link in the footer of every page; it takes effect immediately and deletes both measurement cookies. Nothing else about the Website changes. See Section 9.2.

If your browser sends a recognised privacy signal — Global Privacy Control (Sec-GPC) or the older Do Not Track — none of this is recorded and no measurement cookie is set, so it never begins in the first place, and we do not show you the notice either. See Section 9.4.

Legal basis: our legitimate interests. We measure how the Website is used in order to understand and improve it. We rely on our legitimate interest in operating and improving a business website (Article 6(1)(f) GDPR and its equivalents), and we have designed the measurement to sit lightly on that interest: your IP address is never stored, no profile is built, the data is combined with nothing else and is never shared or sold, and one click stops it and deletes both cookies. We consider this a limited and reasonable use that a visitor to a business website would expect, and one that does not override your interests, rights, or freedoms.

This basis is not available everywhere. Where the law requires prior consent before analytics cookies may be stored on your device — the European Economic Area and the United Kingdom among them — legitimate interests cannot substitute for that consent. This Website is not currently operated on that footing; if that changes, we will ask for your consent before measuring anything and this Section will say so.

You have the right to object to this processing at any time. The Cookie settings link does exactly that in one click, with no detriment and no need to give a reason — see Sections 9.2 and 12.

3.4 Anti-abuse and security measures

Our contact form uses automated technical measures to detect and block automated submissions. These measures may process your IP address, browser characteristics, and the timing of your interaction with the form. This processing is necessary to protect the Website and our systems from abuse and is carried out on the basis of our legitimate interests in maintaining service security and availability.

3.5 Cookies and similar technologies

We use cookies and comparable technologies as described in Section 9.

4. Why We Process Your Personal Data, and Our Legal Basis

PurposeLegal basis
Responding to your contact request or enquirySteps taken at your request prior to entering into a contract; our legitimate interest in responding to business enquiries
Sending you requested materials such as product brochuresSteps taken at your request; legitimate interest
Business development and relationship management with corporate contactsOur legitimate interest in developing business relationships in the financial sector
Marketing communications about our products and servicesYour consent, where required by applicable law; otherwise our legitimate interest, subject always to your right to opt out
Operating, securing, and improving the WebsiteOur legitimate interest in maintaining a secure and functional website
Measuring how the Website is used — pages, products, brochures, and videos (Section 3.3)Our legitimate interest in operating and improving the Website (Section 3.3), which you may object to at any time from the Cookie settings link with immediate effect. Not carried out at all if your browser sends a recognised privacy signal (Global Privacy Control or Do Not Track)
Displaying the embedded Google map when you choose to load it (Section 7.1)Your consent, given by pressing Show map. The map is not loaded, and nothing is sent to Google, unless you press it
Detecting, preventing, and investigating fraud, abuse, or security incidentsOur legitimate interest in protecting our systems; compliance with legal obligations
Complying with legal, regulatory, tax, and accounting obligationsCompliance with a legal obligation
Establishing, exercising, or defending legal claimsOur legitimate interest in protecting our legal position

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your interests, rights, and freedoms. You may request further information about that assessment at any time.

We do not use the Website to make automated decisions producing legal or similarly significant effects concerning you, and we do not carry out profiling of Website visitors.

5. Marketing Communications

We may send you information about our products, services, events, and publications where you have requested it, where you have consented, or where permitted by applicable law in the context of an existing or prospective business relationship.

You may opt out at any time by using the unsubscribe link in any marketing email or by writing to privacy@aisdigicore.com. Opting out of marketing does not affect communications necessary to respond to a specific enquiry you have made, or to administer an existing contractual relationship.

6. Disclosure of Personal Data

We do not sell your personal data, and we do not rent, trade, or otherwise make it available for the independent marketing purposes of third parties.

We disclose personal data only in the following circumstances:

Service providers. We use third parties to operate our business. These providers process personal data only on our documented instructions, under written contracts imposing confidentiality and security obligations, and may not use it for their own purposes.

Our providers are:

CategoryProviderPurposeWhere processed
Website hosting and infrastructureContabo GmbH, Munich, GermanyServing the Website and storing contact-form submissionsUnited States
Email deliveryMicrosoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, IrelandDelivering enquiries submitted through the contact form to our staffEurope. Microsoft reports the current data location for our tenant as Europe but has given no contractual data residency commitment for it, so this may change
Customer relationship management, IT supportNone — enquiries are handled within Microsoft 365 by our own staff——

Website usage measurement (Section 3.3) uses no service provider: it runs on our own infrastructure and the data is not sent anywhere.

Group companies and affiliates. Where necessary for the purposes set out in this Policy, and subject to equivalent safeguards.

Business partners. Where you have engaged with us jointly with a named partner, and only with your knowledge.

Professional advisers. Lawyers, auditors, insurers, and accountants, where necessary and subject to duties of confidentiality.

Legal and regulatory disclosure. Where required by applicable law, court order, or a lawful request from a competent authority; or where necessary to establish, exercise, or defend legal claims, or to protect the rights, property, or safety of DigiCore, our clients, or others.

Corporate transactions. In connection with a merger, acquisition, restructuring, or sale of assets, subject to appropriate confidentiality protections and continued application of this Policy.

7. Third-Party Content Embedded in the Website

The Website can include content served by third parties. We do not load such content automatically: it is requested only if and when you choose to load it, and until then the third party receives nothing about you. When you do load it, the third party may receive your IP address and set its own cookies, its own privacy policy applies to that processing, and we do not control it.

7.1 Google Maps

The contact section of the Website can show an interactive map of our head office location. This map is provided by Google LLC and its affiliates ("Google").

The map does not load on its own. When you open the contact section you see a placeholder in its place, with our office address written out in text and a Show map button. Nothing is requested from Google, and Google receives nothing about you, unless and until you press that button. If you never press it, no connection to Google is ever made from this page.

Pressing "Show map" is your consent, and is what we rely on. When you press it — and only then — your browser establishes a direct connection to Google's servers to retrieve the map, and Google receives:

  • Your IP address
  • Information about your browser, operating system, device, and screen resolution
  • The address of the page on our Website on which the map appears
  • The date and time of access

Google may set cookies or use similar technologies in your browser at that point, and may associate this information with a Google account if you are signed in to one at the time. Google processes this data as an independent data controller for its own purposes, which may include operating and improving its services, security, and personalisation. We have no control over, and no access to, the data Google collects in this way, and we are not responsible for Google's processing of it.

Data collected by Google in this manner may be transferred to and processed in the United States and other countries outside your jurisdiction.

Legal basis: your consent (Article 6(1)(a) GDPR, together with your consent to the storing of and access to information on your device under the ePrivacy rules). Your click on Show map is that consent: the map is off until you ask for it, so the choice is freely made, and you are under no obligation to make it. Our full office address, telephone number, and email address are stated in text form in Section 2 of this Policy and in the contact section itself, so you lose no information or functionality by leaving the map unloaded. The consent applies only to that map, on that visit — the map does not persist, and the next page you open starts again with the placeholder.

Further information is available in Google's Privacy Policy at https://policies.google.com/privacy and in the Google Maps/Google Earth Additional Terms of Service at https://www.google.com/help/terms_maps/.

7.2 Social media

The Website contains links to our profiles on LinkedIn, Facebook, Instagram, YouTube, and X. These are ordinary hyperlinks only. No content, plug-in, or tracking element from those platforms is embedded in the Website, and they receive no data about you unless you actively choose to follow a link. Once you do, that platform's own terms and privacy policy govern.

7.3 Video, brochures, and other media

All video and media content on the Website is hosted on our own infrastructure and served directly from our domain. We do not use any third-party video hosting or streaming service — no YouTube, Vimeo, or comparable embed — and no third party receives your data when you view video content or download a brochure.

Videos and brochures are not stored in a publicly browsable folder. Each is served through an individual link generated by us, so the underlying file locations are not exposed. This is a protection for our materials and does not involve any additional processing of your personal data.

We measure engagement with videos and brochures ourselves, as described in Section 3.3.

8. International Transfers of Personal Data

We are established in the Hashemite Kingdom of Jordan. Our clients, partners, and service providers are located in a number of jurisdictions, including within the Gulf Cooperation Council region, and your personal data may therefore be processed in countries other than your own. Specifically:

DataWhere it is processed
Contact-form submissions, as stored by the WebsiteUnited States
Contact-form submissions, as delivered to our staff by emailEurope (current location; no contractual residency commitment)
Access to both by our staffJordan

Where we transfer personal data across borders, we implement the safeguards required by whichever law applies to that transfer. The mechanisms differ by jurisdiction, and we do not assume that one framework’s vocabulary covers another:

  • Jordan. Transfers to our hosting in the United States and to Microsoft 365 are made in accordance with the Personal Data Protection Law No. 24 of 2023 and the requirements of the Personal Data Protection Unit, including any approval or notification the Law requires for the destination concerned.
  • Saudi Arabia. Where a transfer is subject to the Saudi Personal Data Protection Law, it is made only on a basis that Law permits and in accordance with its Regulations on transfer outside the Kingdom, including any risk assessment and any condition imposed by SDAIA. Saudi transfer rules are not equivalent to the EU regime, and we do not rely on EU mechanisms to justify a Saudi transfer.
  • European Economic Area / United Kingdom. Where the GDPR or UK GDPR applies, transfers to our United States hosting are made under standard contractual clauses, together with the supplementary measures identified by our transfer impact assessment for that destination.
  • Other jurisdictions. The equivalent mechanism provided by the applicable local law.
  • Your explicit consent, where that is a lawful and appropriate basis for the particular transfer.

Where more than one regime applies to the same transfer, we satisfy each of them rather than the least demanding.

The embedded map is a transfer in its own right. If you press Show map, your IP address is sent to Google LLC in the United States (Section 7.1). That transfer rests on your consent — the same click that loads the map — and for visitors in the European Economic Area and the United Kingdom there is an additional route: Google LLC is certified under the EU–US Data Privacy Framework and its UK Extension, so the destination is covered by an adequacy decision as well as by your consent. If you do not load the map, no transfer takes place at all.

You may request further information about the safeguards applied to a specific transfer by contacting privacy@aisdigicore.com.

9. Cookies and Similar Technologies

9.1 What cookies are

Cookies are small text files placed on your device by a website. Similar technologies include local storage and comparable browser mechanisms. This Section uses "cookies" to refer to all of them.

9.2 Cookies we use

CookieSet byTypePurposeConsent required
ASP.NET Core antiforgery cookie (.AspNetCore.Antiforgery.*)Us (first party)Session cookie, HttpOnly, SameSite=StrictProtects the contact form against cross-site request forgery. Expires when you close your browser. Contains no personal data and is not used to identify or track you.No — strictly necessary
_aconsentUs (first party)2 years if you decline, 6 months if you agree; HttpOnly, Secure, SameSite=LaxRecords your answer to the choice in Section 9.2.1 — whether measurement is on or off for you — together with the date and the policy version it related to. We keep it so that we honour your answer and do not keep asking.No — strictly necessary. It is how we remember your choice, and without it we could not honour a refusal or avoid repeating the question
_asidUs (first party)30 minutes, HttpOnly, Secure, SameSite=LaxGroups the pages of a single visit together, so that ten pages read by one person are not counted as ten visitors. Contains a random value only. Renewed while you keep browsing; expires 30 minutes after your last page.Set under our legitimate interest, and not set at all if you have turned measurement off or your browser sends a recognised privacy signal
_avidUs (first party)395 days, HttpOnly, Secure, SameSite=LaxDistinguishes a first-time visitor from a returning one. Contains a random value only, is not linked to your name, email address, or any enquiry you send us, and is not used to build a profile or to target advertising.Set under our legitimate interest, and not set at all if you have turned measurement off or your browser sends a recognised privacy signal
Cookies set by GoogleGoogle LLC (third party)VariesGoogle may set cookies only if you press Show map to load the embedded map in the contact section, and then subject to your browser's third-party cookie settings. Until you do, none are set. These are set and read by Google for its own purposes, and we have no access to them. See Section 7.1.Set only with your consent (your click to load the map); also controllable through your browser settings

_asid and _avid support the usage measurement described in Section 3.3. They are first-party cookies, readable only by this Website, never transmitted to any third party, and marked HttpOnly so that no script — ours or anyone else's — can read them.

9.2.1 How we ask, and how to change your answer

On your first visit we show you a notice, with links to this Policy and to a settings page, telling you that we measure how the site is used and that you can turn it off. Measurement is already running as you read it: the notice informs you, it does not hold measurement back. We do not vary this by country, and we do not determine where you are.

One click turns measurement off at any time. The Cookie settings link in the footer of every page does it. When you use it: recording stops immediately, for that visit and every future one; _asid and _avid are deleted from your device; nothing else about the Website changes; and we keep only the fact of your choice, in _aconsent, so that we can honour it and not keep showing you the notice.

There is no penalty, no reduced functionality, and no need to give a reason or contact us. You can change your mind again from the same page.

The notice and the settings page both work without JavaScript, so they can be used even if scripts are blocked in your browser.

If you would prefer an opt-out that applies automatically on every website rather than only this one, use a browser or extension that sends Global Privacy Control — see Section 9.4. Note that the older "Do Not Track" setting is no longer sent by most browsers, so switching it on may achieve nothing.

We do not use advertising cookies, marketing or tracking pixels, or any cross-site tracking technology. We do not use Google Analytics, Meta Pixel, or any comparable third-party tool. We do not build advertising or behavioural profiles, we do not share cookie data with advertising networks or data brokers, and we do not sell it.

We do not use local storage, IndexedDB, or comparable browser storage mechanisms to store information about you.

Please note: the embedded Google map is not loaded unless you press Show map, so by default nothing is transmitted to Google and no Google cookie is set. If you do load it, blocking third-party cookies in your browser prevents Google from setting cookies but does not prevent your IP address reaching Google. The way to avoid that entirely is simply not to load the map. See Section 7.1.

9.3 Managing cookies

The antiforgery cookie is strictly necessary for the security of the contact form and cannot be disabled without affecting the correct operation of the Website. The _aconsent cookie is likewise necessary — it is the record of your own choice.

The simplest way to control the two measurement cookies is the Cookie settings link in the footer of every page (Section 9.2.1) — one button switches them off and deletes them, withdrawing the consent under which they were set. A browser that sends Global Privacy Control prevents them regardless of anything else (Section 9.4), as does the older Do Not Track where a browser still supports it; you can also block and delete cookies for this site in your browser settings. Nothing on the Website stops working in any of those cases — pages, videos, and brochure downloads all behave identically.

Any cookies set by Google in connection with the embedded map — which arise only if you choose to load it with Show map — are third-party cookies. You can control them, and the cookies above, through your browser settings:

  • Microsoft Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data
  • Google Chrome: Settings → Privacy and security → Third-party cookies
  • Mozilla Firefox: Settings → Privacy & Security → Enhanced Tracking Protection
  • Safari: Settings → Privacy → Prevent cross-site tracking

Most modern browsers block third-party cookies by default. You can also delete existing cookies at any time through your browser.

As explained in Section 7.1, the map loads only if you press Show map, and blocking third-party cookies does not by itself prevent your IP address reaching Google once it has loaded. The surest way to prevent that is not to load the map in the first place.

9.4 Browser privacy signals (Global Privacy Control and Do Not Track)

We honour machine-readable opt-out signals sent by your browser, automatically and without you having to do anything on this Website.

We recognise two:

SignalHeaderStatus
Global Privacy ControlSec-GPC: 1The current, actively supported signal. Sent by several browsers and by widely used privacy extensions, and legally binding in some jurisdictions, including California.
Do Not TrackDNT: 1The older signal. Its specification was discontinued in 2019 and most browsers no longer send it, but we continue to honour it for anyone whose browser still does.

If either is present, then for the whole of your visit:

  • no page view, product interest, brochure download, or video engagement is recorded;
  • the _asid and _avid cookies are not set;
  • you are not asked about measurement at all — you have already expressed a preference, and putting the question to you about measurement that is not going to happen would be noise;
  • the strictly necessary antiforgery cookie remains, because the contact form cannot be protected without it.

The signal is acted on by our servers, so it takes effect whether or not any script runs in your browser.

Please do not rely on Do Not Track alone. Because most browsers have removed it, switching it on may have no effect at the browser end — the setting exists but nothing is sent. If you want a browser-level opt-out that works, use a browser or extension that sends Global Privacy Control. Alternatively, the Cookie settings link on this Website switches measurement off for this site directly, and does not depend on any browser signal.

A privacy signal does not remove the Show map button. If you choose to load the map, Google receives your IP address as described in Section 7.1; the way to prevent that is not to load it. We treat your click as the more specific instruction — a browser signal tells us you do not want to be measured, whereas pressing a button labelled Show map is a deliberate request for that one thing. Nothing loads unless you press it.

10. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law.

DataRetention period
Contact form submissions that do not lead to a business relationship12 months from last contact
Business contact details for an active or prospective client relationshipDuration of the relationship, plus 12 months
Records relating to a contractual relationshipDuration of the contract, plus the applicable statutory limitation period
Server and security logs24 months
Your cookie choice (_aconsent)If you decline: 2 years, and always longer than the measurement cookies it prevents, so that we do not keep asking. If you agree: 6 months, after which you are asked again
Website usage measurement — detailed daily records (Section 3.3)100 days, then permanently deleted
Website usage measurement — monthly aggregate statistics, containing counts only and no identifier of any kind400 days, then permanently deleted
Marketing consent and opt-out recordsRetained for as long as necessary to demonstrate compliance
Records required for tax, accounting, or regulatory purposesAs prescribed by applicable law

When personal data is no longer required, we securely delete it or irreversibly anonymise it.

11. Information Security

We maintain technical and organisational security measures appropriate to the nature of the data we hold and the risks involved, including:

  • Encryption of data in transit using TLS 1.2 or above
  • Access control on a least-privilege, need-to-know basis
  • Network segmentation and perimeter protection
  • Logging, monitoring, and alerting for security events
  • Secure development practices and periodic security testing
  • Confidentiality obligations and security awareness training for personnel
  • Contractual security requirements imposed on service providers
  • A documented incident response process

No method of transmission or storage is entirely secure, and we cannot guarantee absolute security. However, we commit to maintaining controls proportionate to the sensitivity of the data we handle.

Personal data breaches. We maintain a documented incident response process and notify affected individuals and the competent authority where the applicable law requires it. The timeframes that bind us are short, and we work to them:

WhereNotifyWithin
Jordan (Law No. 24 of 2023)The affected individuals24 hours of becoming aware of the breach
Jordan (Law No. 24 of 2023)The Personal Data Protection Unit72 hours of becoming aware of the breach
Saudi Arabia (Personal Data Protection Law)The Saudi Data & AI Authority (SDAIA)72 hours of becoming aware of the breach
Saudi Arabia (Personal Data Protection Law)The affected individualsWithout undue delay, where the breach may cause them harm
EEA / UK, where the GDPR appliesThe supervisory authority72 hours of becoming aware of the breach

Where a breach affects data we process on behalf of a client, we notify that client without undue delay so that it can meet its own obligations as controller.

12. Your Rights

Subject to applicable law and to any conditions or exemptions that may apply, you have the following rights in relation to your personal data:

  • Access — to be informed whether we process your personal data and to obtain a copy of it
  • Rectification — to have inaccurate or incomplete data corrected
  • Erasure — to request deletion where there is no lawful ground for us to continue processing
  • Restriction — to request that we limit our processing in certain circumstances
  • Objection — to object to processing based on our legitimate interests, and to object to direct marketing at any time
  • Portability — to receive certain data in a structured, commonly used, machine-readable format
  • Withdrawal of consent — where processing is based on consent, to withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal
  • Complaint — to lodge a complaint with the competent data protection authority in your jurisdiction. In Jordan that is the Personal Data Protection Unit at the Ministry of Digital Economy and Entrepreneurship; in Saudi Arabia, SDAIA; in the EEA or UK, your national supervisory authority

How to exercise your rights

Write to privacy@aisdigicore.com. We will respond within the period required by applicable law and in any event without undue delay.

For the usage measurement described in Section 3.3 you do not need to write to us at all. Use the Cookie settings link in the footer of any page to withdraw your consent. Measurement stops immediately and both measurement cookies are deleted. A browser sending Global Privacy Control achieves the same automatically, on this and every other site (Section 9.4). Writing to us remains available if you prefer. We may need to verify your identity before acting on a request, and we will explain if any exemption applies to a particular request.

Exercising your rights is free of charge, save where a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act, and will explain our reasons.

13. Applicable Data Protection Laws

We process personal data in accordance with the data protection laws applicable to our activities. Depending on your location and the circumstances of processing, these may include:

  • The Personal Data Protection Law of the Hashemite Kingdom of Jordan (Law No. 24 of 2023) and its implementing regulations
  • The Personal Data Protection Law of the Kingdom of Saudi Arabia and its implementing regulations, where processing relates to individuals in Saudi Arabia
  • United Arab Emirates — Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, and the data protection regimes of the DIFC and ADGM where processing falls within those financial free zones
  • Qatar — Law No. 13 of 2016 concerning Personal Data Privacy Protection, and the QFC data protection regime where applicable
  • Bahrain — Law No. 30 of 2018 with respect to Personal Data Protection
  • Oman — the Personal Data Protection Law issued by Royal Decree No. 6/2022 and its executive regulations
  • Kuwait — the constitutional and sectoral privacy protections applicable there. Kuwait has not yet enacted a comprehensive cross-sector personal data protection law; where a sector-specific rule applies to a particular engagement, we comply with it
  • The EU General Data Protection Regulation and the UK GDPR, where they apply to our processing
  • Applicable data protection laws of any other jurisdiction in which we operate or in which our clients are established

Where more than one law applies, we apply the standard that provides the higher level of protection.

Registration and representation. Several of these regimes require a controller to register with a national authority, to appoint a data protection officer, or to appoint a local representative. We maintain the registrations and appointments required of us in the jurisdictions in which we operate.

14. Children

The Website is directed exclusively at businesses and business professionals. It is not intended for, and we do not knowingly collect personal data from, individuals under the age of 18. If you believe a minor has provided us with personal data, contact privacy@aisdigicore.com and we will delete it.

15. Links to Other Websites

The Website contains links to third-party websites, including those of our partners and our social media profiles. We are not responsible for the privacy practices or content of those websites. We encourage you to read the privacy policy of every website you visit.

16. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. The "Last updated" date at the top indicates when the current version took effect.

Where changes are material, we will provide prominent notice on the Website and, where required by applicable law, seek your consent. We encourage you to review this Policy periodically.

17. Contact and Complaints

For any question, request, or complaint about this Policy or our handling of personal data:

Email: privacy@aisdigicore.com
Post: شركة اريزونا للبرمجة و الانظمة الذكية
Arizona for Programming and Intelligent Systems Co.
Office 31, AlKaradsheh Tower, Wadi Saqra, Amman, Jordan, 11195, P.O. Box 3028
Telephone: +962 7 9907 8081

We take all concerns seriously and aim to resolve them directly. If you remain dissatisfied, you have the right to lodge a complaint with the competent data protection supervisory authority in your jurisdiction.

© 2026 شركة اريزونا للبرمجة و الانظمة الذكية — Arizona for Programming and Intelligent Systems Co. All rights reserved.

We measure how this site is used. Two cookies, our own servers, no IP addresses stored and nothing shared. You can turn it off at any time. Privacy · Details