This Privacy Policy explains how CHI M S DIGITAL MARKETING CO. L.L.C, trading as Chi Agency (“Chi”, “we”, “us”, or “our”), collects, uses, stores, shares, and protects personal information in connection with our website, business activities, agency services, digital services, and Mufeed (مفيد).
Mufeed is our AI-assisted customer communication application, including services operated through WhatsApp and other supported communication channels.
Effective date: 8 September 2026
Last updated: 8 September 2026
Legal entity: CHI M S DIGITAL MARKETING
CO. L.L.C
Trading name: Chi Agency
Business address:
Al Saqr Business Tower
27th Floor
Sheikh Zayed Road
Dubai, United Arab Emirates
Privacy contact: info@chiagency-ae.com
Our website is a company portfolio and business website through which prospective clients may contact us and submit enquiries.
Information submitted through our website may be retained as prospective-client or business lead records in our email systems, server-hosted database, and customer relationship management (“CRM”) systems.
This Privacy Policy applies, as relevant, to:
Additional privacy notices or contractual terms may apply to particular services, clients, projects, platforms, or jurisdictions.
Depending on the circumstances, Chi may act either for its own purposes or on behalf of a client.
When we determine why and how personal information is processed for purposes such as:
we act as the organisation responsible for that processing.
When a client appoints us to:
the client may determine the purposes and essential means of processing.
In those circumstances, Chi may process personal information on the client’s behalf and according to the client’s instructions, the applicable agreement, and applicable law.
For example, a restaurant using Mufeed may determine how its customers’ enquiries, reservations, product enquiries, or order requests should be handled.
The client’s own privacy notice may therefore also apply.
Where we process personal information on a client’s behalf, that engagement is also governed by a separate written data processing agreement between Chi and the client. That agreement sets out the subject matter, duration, nature and purpose of the processing, the categories of personal information and individuals involved, the security measures applied, the use of subprocessors, and the return or deletion of personal information once the engagement ends. This Privacy Policy describes our practices generally and does not replace that agreement.
If you submit a privacy request relating to a service that we operate for a client, we may refer the request to that client or coordinate with the client to handle it appropriately.
The information we process depends on how you interact with us and which services are enabled. It may include the following categories.
This may include:
This may include:
This may include:
We do not currently collect or store payment-card details through Mufeed or our website.
Where included in a commissioned service, we may process:
Where relevant to a commissioned project, information may include:
This may include:
When you communicate with a business through Mufeed, we may process information such as:
Depending on the capabilities enabled for a particular Mufeed service, information processed may also include:
Not all Mufeed deployments use all of these capabilities.
When you submit a contact form, we process the information you enter into the form, including any information you voluntarily include in free-text fields.
These submissions may be stored in:
Our website, servers, security services, communication platforms, and infrastructure providers may process technical information such as:
Please provide only information reasonably necessary for your enquiry or interaction.
Unless specifically requested through an appropriate secure process, you should not send:
A normal Mufeed conversation or website enquiry is not intended to be a secure channel for unnecessary sensitive information.
We may obtain personal information:
We do not treat information being publicly available as unlimited permission to use it for any purpose.
Depending on the circumstances, we may process information to:
We process personal information only where there is an appropriate basis under applicable law.
Depending on the circumstances, this may include:
Visiting our website or communicating with Mufeed does not by itself constitute consent to unrelated marketing.
Mufeed may use the Meta WhatsApp Business Platform and other authorised communication platforms to receive and send messages.
Mufeed also uses artificial-intelligence services to understand requests, generate responses, classify information, summarise conversations, assist business workflows, and perform other configured functions.
Depending on the service configuration, Mufeed may use one or more external artificial-intelligence providers.
The following list is illustrative rather than exhaustive, and reflects the providers available at the time of writing. Depending on configuration, these may include providers such as:
The provider used for a particular request may change.
Mufeed may select or route requests between AI providers based on factors such as:
A single conversation may therefore be processed using more than one technology provider where necessary for the configured service.
Depending on the requested functionality, information sent to an AI provider may include:
If multimedia capabilities are enabled, this may also include:
A telephone number is not necessarily sent to an AI provider as a dedicated field.
However, a telephone number or other personal information may be included if:
External AI providers operate their own infrastructure and process information according to the commercial terms, data-processing terms, security requirements, and retention arrangements applicable to the services we use.
Provider practices may differ.
Depending on the provider and service configuration, providers may retain limited information temporarily for purposes such as:
Where appropriate controls are available, we seek to use commercial or API configurations that minimise retention and limit the use of customer content for training general-purpose AI models.
We do not intentionally opt Mufeed customer conversations into optional general-purpose model-training programmes unless an appropriate legal basis exists and any required authorisation, notice, or consent has been obtained.
Artificial-intelligence systems can produce:
AI-generated responses should therefore not automatically be treated as authoritative.
Important information such as:
should be confirmed with the relevant business where appropriate.
A generated summary or acknowledgment does not necessarily mean that an order, reservation, or request has been formally accepted.
Mufeed is primarily intended to assist communication and operational workflows.
We do not currently use Mufeed to make solely automated decisions that produce significant legal or similarly significant effects on individuals.
If such functionality is introduced, we will assess the applicable legal requirements and provide any additional notices or safeguards required.
We may send our own promotional communications where permitted by applicable law and, where required, after obtaining consent.
You may ask us to stop marketing communications at any time.
Administrative, contractual, transactional, security, and other essential service communications may still be sent where necessary.
Submitting a website enquiry or having a customer-service conversation through Mufeed does not by itself authorise unrelated promotional messaging.
When we operate advertising or marketing activities for clients, processing is governed by:
A customer-service conversation should not automatically be treated as permission to add a person to an unrelated advertising audience.
Our website uses Google reCAPTCHA or related Google security technology to help:
reCAPTCHA may process technical information and may use cookies or similar technologies necessary for these purposes.
We may use Google Ads and related advertising or conversion-measurement technologies.
Where enabled, these technologies may process information about:
Google and other advertising providers may use cookies or similar technologies for advertising measurement and related functionality.
Where applicable law requires consent before enabling non-essential advertising or tracking technologies, we will use appropriate consent controls before enabling them.
You can use your browser settings to restrict or remove cookies.
However, browser settings may not control every type of similar technology, and restricting security-related cookies may affect website functionality.
We do not sell personal information.
We may disclose or provide access to information only as reasonably necessary for the purposes described in this Privacy Policy.
Recipients may include:
Technology providers currently or potentially used in connection with our services include:
Hosting and infrastructure
Our website and application infrastructure is hosted on
virtual private server infrastructure supplied by a
third-party hosting provider.
Meta
Meta provides the WhatsApp Business Platform used for
Mufeed integrations where WhatsApp functionality is
enabled.
Artificial-intelligence providers
AI services may include OpenAI, Anthropic, Google,
Moonshot AI, and other providers selected for the
relevant functionality.
Google
Google technologies may be used for reCAPTCHA,
advertising, conversion measurement, and related website
or marketing functionality.
Microsoft
Microsoft 365 provides our business email
infrastructure. Enquiries submitted through our website
contact form are transmitted through, and stored in,
mailboxes hosted on Microsoft 365.
CRM and business systems
Website enquiries and business communications may also
be processed through our CRM systems and related
business administration tools.
Providers may themselves use subprocessors as permitted under their applicable contracts and policies.
Chi is based in the United Arab Emirates.
Our suppliers, infrastructure providers, AI providers, communication platforms, email providers, CRM providers, and authorised technical teams may process information in countries outside the UAE. Our business email is hosted on Microsoft 365, and the location of processing depends on the region of our Microsoft tenant and Microsoft’s own infrastructure.
Our hosting infrastructure is currently supplied through a virtual private server operated by a third-party hosting provider.
We do not represent that all information processed through our website or services is necessarily stored physically within the United Arab Emirates.
The location of processing may depend on:
Where applicable law imposes requirements on international transfers of personal information, we will use the applicable lawful transfer arrangements, safeguards, contractual protections, or other mechanisms required by law.
We do not retain personal information indefinitely.
Retention depends on:
Our general retention periods are as follows.
We generally retain Mufeed operational conversation records for up to 30 days after the last relevant interaction.
Information may be retained for a longer or shorter period where:
Where only part of a conversation needs to become a business record, we may retain that necessary information separately while deleting the remaining operational conversation data.
Website enquiries and prospective-client records that do not develop into an active client relationship are generally retained for up to 24 months after the last meaningful business interaction.
After that period, they may be deleted or anonymised unless there is an appropriate reason to retain them for longer.
Operational client, project, and support information is generally retained for the duration of the relationship and for up to three years after the relationship or project ends.
Some records may need to be kept longer because of:
Contracts, invoices, accounting records, and records required for tax or statutory purposes are retained for the period required by the tax and statutory requirements in force at the relevant time.
Different categories of record carry different statutory minimum periods, and corporate tax records and VAT records are subject to their own rules. We therefore apply the retention period required for each category of record rather than a single fixed term for all of them.
Where no shorter period applies, our general practice is to retain such records for seven years after the end of the relevant tax period. We retain them for longer where a legal obligation, contractual requirement, dispute, or legal claim requires it.
Routine website, application, server, and security logs are generally retained for up to 90 days.
Relevant logs may be retained for longer if required to:
We do not currently maintain separate application-level backup archives for Mufeed as a standard independent data store.
Infrastructure providers may operate provider-level resilience, recovery, or backup systems under their own applicable terms.
If Chi introduces its own application-level backup system, we intend to use rolling backup retention of no more than 30 days unless operational, contractual, security, or legal requirements justify a different period.
Deletion from Chi’s active systems does not necessarily mean information is immediately deleted from every independent provider.
External providers may maintain limited information according to:
We use reasonable technical and organisational measures designed to protect personal information against:
Depending on the system, our controls may include:
Security controls are applied according to the deployed architecture and configuration of each system, rather than being determined by any particular technology choice.
No internet-based service, transmission mechanism, or storage system can be guaranteed to be completely secure.
Depending on the law applicable to the processing of your personal information, you may have rights such as the right to:
Withdrawal of consent does not invalidate processing that was lawfully carried out before consent was withdrawn.
Some rights may be subject to legal limitations or exceptions.
For example, we may be required to retain certain records despite a deletion request where retention is necessary to comply with a legal obligation or establish, exercise, or defend legal rights.
To exercise a privacy right or request deletion of personal information, contact info@chiagency-ae.com.
You may use a subject such as Privacy Request or Data Deletion Request.
Please explain:
For a request relating to WhatsApp, you may provide the relevant telephone number in international format.
Do not send us:
We may request proportionate information necessary to verify that the request relates to you.
When we process information on behalf of a client, we may coordinate the request with that client.
Where a valid deletion request applies, we will take reasonable steps to delete the applicable information from systems under our control, subject to lawful retention requirements and technical limitations.
Deletion from our systems does not automatically delete:
Information contained in backup or recovery systems, where applicable, may remain until the normal backup retention cycle expires.
Chi’s agency services and Mufeed are not specifically directed at children.
We do not intentionally design our general business services for the collection of children’s personal information.
A client-facing service, campaign, production, event, or project may nevertheless involve children.
Where this occurs, we will apply appropriate procedures and obtain parent or guardian authorisation where required by applicable law.
If you believe a child’s personal information has been collected, processed, or published inappropriately through one of our services, contact us at info@chiagency-ae.com.
We do not treat participation in a project as automatic permission to publish an identifiable person’s personal information.
Where we wish to publish identifiable individuals, testimonials, photographs, videos, or similar personal material in:
we will obtain appropriate permission where required.
Any permission will apply to the relevant intended use rather than serving as unlimited authorisation for unrelated future uses.
Our website, communications, Mufeed, and client services may contain links to or integrations with third-party websites, applications, platforms, and services.
These third parties may process information independently.
Their own:
apply to processing they independently control.
Chi is not responsible for the independent privacy practices of third-party services that we do not control.
We may update this Privacy Policy when necessary to reflect changes in:
When we update the policy, we will publish the revised version and update the Last updated date.
Where applicable law requires additional notice or consent for a material change, we will provide it.
Changing an AI model or provider does not necessarily require a new privacy notice where the new provider operates within the processing purposes and categories clearly described in this policy.
However, we will update this policy where a change materially affects how personal information is processed.
For questions, privacy requests, or data deletion requests relating to this Privacy Policy, contact:
CHI M S DIGITAL MARKETING CO. L.L.C