Privacy Policy
Introduction
Last updated: May 25, 2026
NewVision Upstream FZ LLC (“NewVision,” “we,” “us,” “our”) is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what rights you have in relation to it. This Privacy Policy applies to personal data collected through our website at newvision.io and through our Software. It forms part of our Terms of Use.
Who We Are
The data controller responsible for your personal data is NewVision Upstream FZ LLC, Business Center 1, M Floor, The Meydan Hotel, Nad Al Sheba, Dubai, U.A.E. NewVision has not appointed a Data Protection Officer. For any privacy-related queries, please see the Contact section at the end of this Policy. As a company incorporated in the UAE, NewVision processes personal data in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) and its implementing regulations, as well as other applicable data protection laws including the EU General Data Protection Regulation (GDPR), UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA) where relevant.
What Data We Collect
Data you provide directly
- Identity data: name, job title, company name;
- Contact data: email address, phone number;
- Account data: username, password (stored in hashed form);
- Communication data: content of emails, support requests, and feedback you send us;
- Marketing preferences: whether you have consented to receive marketing communications;
Data we collect automatically
- Usage data: features used, actions taken within the Software, login timestamps, session duration;
- Technical data: browser type, operating system, device information, and approximate location derived from your IP address. We do not store your full IP address;
- Analytics data: website visitor behaviour collected through Google Analytics;
- Cookies and similar technologies: as described in the Cookies section below
Data collected for compliance purposes
We screen users and associated entities against applicable sanctions lists and Politically Exposed Persons (PEP) lists as part of our compliance obligations. This screening involves automated matching against third-party databases, and all results are reviewed by a member of our team before any action is taken.
How We Collect Your Data
We collect personal data:
- When you register for an account or subscribe to a plan
- When you use or interact with the Software or website
- When you contact our support team
- When you respond to surveys or provide feedback
- Through cookies and analytics tools when you visit our website
Why We Use Your Data and Our Legal Basis
We only process your personal data where we have a lawful basis to do so:
| Purpose | Legal basis |
|---|---|
| Creating and managing your account | Performance of a contract |
| Providing access to the Software | Performance of a contract |
| Processing payments via our payment provider | Performance of a contract |
| Providing technical support | Performance of a contract |
| Sending service notifications and updates | Performance of a contract |
| Sending marketing communications | Consent |
| Website analytics and improving our services | Legitimate interests |
| Security monitoring and fraud prevention | Legitimate interests |
| Sanctions and PEP screening | Legal obligation / legitimate interests |
| Complying with applicable law | Legal obligation |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You have the right to object to processing based on legitimate interests — see Your Rights below.
Who We Share Your Data With
We do not sell your personal data. We share it only with the following categories of recipients, all of whom process data on our behalf under appropriate agreements:
- Amazon Web Services — for hosting the Software and website in the Europe (Stockholm) region, Sweden (eu-north-1)
- Paddle - our authorized payment provider — for processing subscription payments
- DocuSign Inc. and Zoho Corporation Pvt. Ltd (ZohoSign) — for executing agreements
- Google Analytics — for website analytics
- Legal and regulatory authorities: where required by applicable law, court order, or regulatory obligation
International Data Transfers
NewVision is based in Dubai, UAE. Your personal data is hosted on Amazon Web Services infrastructure in the Europe (Stockholm) region, Sweden (eu-north-1).
Although our primary hosting infrastructure is located in the European Union, your personal data may be accessed from or processed in countries outside the EU/EEA or the United Kingdom, including the United Arab Emirates, where NewVision is established, and other jurisdictions where our service providers operate.
Where we transfer personal data from the EU/EEA to a country outside the EU/EEA that has not been recognised as providing an adequate level of data protection, we rely on appropriate safeguards, including the Standard Contractual Clauses approved by the European Commission, as incorporated into the Data Processing Agreements we have in place with our service providers.
Where we transfer personal data from the United Kingdom to a country outside the UK, we rely on appropriate safeguards under UK data protection law, including the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as applicable.
How Long We Keep Your Data
| Category | Retention period |
|---|---|
| Account, identity and contact data | Duration of subscription plus 3 years after account closure |
| Usage and log data | 12 months |
| Support communications | 3 years from last interaction |
| Billing and invoice records | 7 years |
| Marketing consent records | Duration of marketing activity plus 3 years after opt-out |
| Analytics and cookie data | 13 months |
After the applicable retention period, data is securely deleted or anonymised.
How We Protect Your Data
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption of data in transit (TLS) and at rest
- Role-based access controls and credential management
- Anonymisation of data where possible — for example, we derive location information from IP addresses and do not store full IP addresses
- Regular security monitoring and assessments
- Staff training on data protection
No method of transmission over the internet is completely secure. If you become aware of any security concern, please notify us as described in the Contact section below.
Children
Our Software and website are professional tools intended for use by adults in a business context. They are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, please contact us as described in the Contact section below and we will delete it promptly.
Your Rights
You have the following rights regarding your personal data:
- Right of access — you may request a copy of the personal data we hold about you.
- Right to rectification — you may request correction of inaccurate or incomplete data.
- Right to erasure — you may request deletion of your personal data where we no longer have a lawful basis to retain it.
- Right to restrict processing — you may request that we limit how we use your data in certain circumstances.
- Right to data portability — you may request that we provide your data to you or transfer it to another organisation in a structured, machine-readable format.
- Right to object — you may object to processing based on legitimate interests or for direct marketing purposes. Where you object to direct marketing, we will stop processing your data for that purpose immediately.
- Right to withdraw consent — where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint — you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction:
- UAE residents: UAE Data Office — uaedataoffice.ae;
- EU residents: your national Data Protection Authority — edpb.europa.eu/about-edpb/board/members;
- UK residents: Information Commissioner’s Office — ico.org.uk
To exercise any of these rights, please see the Contact section below. We will respond within one month. We may ask you to verify your identity before fulfilling a request.
Automated Decision-Making
We use automated tools to screen users and associated entities against sanctions lists and PEP databases as part of our compliance obligations. This screening uses automated matching, but all results are reviewed by a member of our team before any decision is made. No decision that significantly affects you is made solely by automated means without human involvement. We do not otherwise use automated decision-making or profiling in a way that produces legal or similarly significant effects on you.
Cookies
- Essential cookies — required for the website and Software to function, including session management and authentication. These do not require consent.
- Analytics cookies — used to understand how visitors use our website in order to improve it. These are only placed with your consent via our cookie banner.
You can manage your cookie preferences at any time through our cookie settings or by adjusting your browser settings. Withdrawing consent for analytics cookies will not affect your ability to use the Software.
Consent for analytics cookies is obtained through our cookie banner and recorded in our system.
Marketing Communications
If you consented to receive marketing communications at the time of registration, we may send you information about our products, services, and updates. You may withdraw your consent and opt out at any time by clicking the unsubscribe link in any marketing email or by contacting us as described in the Contact section below.
US Residents — Additional Rights
NewVision does not sell or share your personal data for cross-context behavioural advertising purposes. You have the right to non-discrimination for exercising any of your privacy rights. For all other rights, see the Your Rights section above. To exercise any such rights, please see the Contact section below.
Third Party Websites
Our website may contain links to third party websites. This Privacy Policy applies only to newvision.io. We are not responsible for the privacy practices of any third party website.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and by a notice presented upon your next login to your account. The date at the top of this page reflects the most recent update. Continued use of the website or Software after the effective date of any changes constitutes acceptance of the updated Policy.
Contact
For any privacy-related questions, requests, or complaints:
- Email: support@newvision.io
- Address: NewVision Upstream FZ LLC, Business Center 1, M Floor, The Meydan Hotel, Nad Al Sheba, Dubai, U.A.E.