Privacy Policy
How CodeLabs LLC collects, uses and protects personal data across UrbanHorn.
Effective date: 28 July 2026
Last updated: 7 August 2026
This Privacy Policy explains how CodeLabs LLC (“Codelabs”, “we”, “us”) collects, uses, shares and protects personal data in connection with urbanhorn.io, portal.urbanhorn.io and the UrbanHorn platform (the “Service”). UrbanHorn is a product of Codelabs.
CodeLabs LLC is a limited liability company licensed by the Sharjah Media City Free Zone Authority (SHAMS) under trade licence number 2541506.01 and formation number 2541506, with its registered office at Sharjah Media City, Sharjah, United Arab Emirates, and its principal place of business at Office 7, 17th Floor, Prime Tower, Business Bay, Dubai, United Arab Emirates. We also operate a group entity registered in Dover, Delaware, United States.
1. The two roles we play — please read this first#
This distinction determines your rights and who you should contact.
We are a controller for personal data about our own customers and website visitors: the person who signs up, billing contacts, support correspondence, and analytics about how urbanhorn.io is used. This policy governs that data.
We are a processor for the Customer Data our customers put into the platform — including the content of conversations between our customers’ Agents and their own End Users. In that case our customer is the controller. We process it on their documented instructions, and their own privacy notice governs it.
If you are an End User who has chatted with an Agent and you want to access or delete that conversation, contact the business you were dealing with. If you contact us, we will refer you to them and assist them in responding.
2. Personal data we collect#
2.1 Data you give us (as controller)
- Account data — name, work email, password credentials, organisation name, role, country.
- Billing data — billing name and address, VAT/TRN, plan, invoices, transaction history. We do not collect or store full payment card numbers; these go directly to our payment processor.
- Support and sales data — messages you send us, and records of correspondence.
2.2 Data we collect automatically (as controller)
- Usage data — features used, Agent and credit consumption, API call volumes, timestamps.
- Device and log data — IP address, browser and device type, operating system, referring pages, error logs.
- Cookies and similar technologies — see section 9.
2.3 Customer Data (as processor)
Knowledge sources you upload, Agent configurations, connected tool credentials, conversation transcripts, and any personal data of End Users contained in them. We process this only to provide the Service.
3. What we do not do#
- We do not use Customer Data to train foundation models for other customers or for general model improvement.
- We do not sell personal data, and we do not share it for cross-context behavioural advertising.
- We do not use conversation content for our own marketing.
4. Why we process it, and our legal bases#
For customers and visitors in the EEA and UK, the legal bases under the GDPR / UK GDPR are:
| Purpose | Legal basis |
|---|---|
| Providing the Service and administering your account | Performance of a contract |
| Billing, collections and tax records | Contract; legal obligation |
| Security, fraud and abuse prevention, service integrity | Legitimate interests |
| Product analytics and improvement | Legitimate interests (or consent where required) |
| Marketing emails to business contacts | Consent, or legitimate interests with opt-out |
| Non-essential cookies | Consent |
| Responding to legal requests and defending claims | Legal obligation; legitimate interests |
| Processing Customer Data on a customer’s behalf | Processor acting on controller’s instructions |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights, and you may object (section 8).
5. Who we share it with#
We share personal data with service providers (sub-processors) who help us run the Service, under contracts requiring appropriate protection and use only on our instructions. Categories include:
- Cloud hosting and infrastructure — running the platform and storing data.
- AI model providers — to generate Output. Inputs are sent to the model provider you or we route to.
- Messaging and channel providers — for example WhatsApp Business, to deliver messages on the channels you enable.
- Payment processing — to take payments and prevent fraud.
- Email, support and analytics tools — to communicate with you and understand product usage.
We also disclose data where required by law or valid legal process, to protect rights and safety, and in connection with a merger, acquisition or sale of assets (with notice where required).
Our current sub-processors are:
| Sub-processor | Purpose | Primary location |
|---|---|---|
| OpenAI | AI model inference — generating agent responses | United States |
| Anthropic | AI model inference — generating agent responses | United States |
| AI model inference — generating agent responses | United States / EU | |
| Google (Analytics) | Website analytics for urbanhorn.io | United States |
| Meta Platforms | AI model inference; WhatsApp Business message delivery where that channel is enabled | United States / Ireland |
| World Host Group (WHG Hosting Services Ltd) | Platform hosting and data storage | Mumbai, India (company registered in the United Kingdom) |
| Stripe | Payment processing and fraud prevention | United States / Ireland |
| Cloudflare | DNS resolution for urbanhorn.io | Global |
Inputs are sent to the model provider handling that task. We select which provider handles which use case; you do not need an account with any of them. We will give reasonable notice before adding or replacing a sub-processor, and you may raise an objection using the contact details below.
6. International transfers#
We are established in the United Arab Emirates, operate a group entity in the United States, and use service providers in multiple countries, so your personal data may be transferred outside your country, including outside the EEA and UK. Our platform is currently hosted in Mumbai, India, so Customer Data is stored there.
Where we transfer personal data from the EEA or UK to a country without an adequacy decision, we rely on appropriate safeguards — principally the European Commission’s Standard Contractual Clauses, and for the UK the International Data Transfer Addendum — together with transfer risk assessments and supplementary measures where needed. You may request a copy of the relevant safeguards using the contact details below.
7. How long we keep it#
- Account data — for the life of your account, then up to 24 months.
- Billing and tax records — as required by applicable law (typically 5 years in the UAE).
- Customer Data — for as long as your account is active. After termination it is available for export for 30 days and then deleted or anonymised. Scale plans support configurable retention for conversation history.
- Logs and security records — typically 12 months.
- Marketing contacts — until you opt out, then on a suppression list so we do not contact you again.
8. Your rights#
Subject to applicable law, you may have the right to: access your personal data; correct inaccurate data; erase data; restrict or object to processing (including direct marketing and profiling); data portability; and to withdraw consent at any time without affecting prior processing.
These rights arise under the EU GDPR and UK GDPR, and comparable rights exist under UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), which applies to us as a company licensed in the Sharjah Media City Free Zone.
To exercise a right, email talk@codelabs.ae. We will respond within the period required by law (one month under the GDPR, extendable where permitted). We may need to verify your identity.
You have the right to complain to a supervisory authority — in the EEA, your local data protection authority; in the UK, the Information Commissioner’s Office; and in the UAE, the UAE Data Office. We would appreciate the chance to address your concern first.
9. Cookies#
We use cookies and similar technologies to run the site, remember preferences, keep sessions secure, and understand usage. Strictly necessary cookies do not require consent; analytics and any marketing cookies are set only where you consent, in regions where consent is required. You can control cookies through your browser, though blocking some may affect functionality.
We use Google Analytics 4 on this website. It loads on every page view and sets first-party cookies (_ga and _ga_<id>, which expire after two years) to tell repeat visits apart. Through it, Google receives your IP address, the pages you view, your device and browser type, and an approximate location derived from your IP. We use this only to understand which pages are useful and where visitors arrive from. We do not run advertising, ad-targeting or cross-site tracking tags, we have not enabled Google Signals or advertising features, and we do not sell or share this data for advertising. Our webfonts are served from our own servers, so loading a page sends no request to a font provider.
We show a notice about this on your first visit. It is a notice rather than a choice: analytics loads for everyone. If you would rather not be measured, you can block cookies for this site in your browser, use Google’s opt-out browser add-on, or use your browser’s tracking protection — none of which affects your ability to use the site. You can also ask us to delete analytics data associated with you using the contact details below.
10. Security#
We maintain technical and organisational measures appropriate to the risk, including encryption in transit, access control on a least-privilege basis, logical separation between customers’ data, logging, and periodic review of our practices. No method of transmission or storage is completely secure. Where a personal data breach is likely to result in a risk to individuals, we will notify the relevant authority and affected parties as required by law, and we will notify affected customers without undue delay.
11. Automated decision-making#
We do not use your personal data to make decisions producing legal or similarly significant effects about you without human involvement. Our customers configure their own Agents; where a customer uses the Service in a way that involves automated decision-making about individuals, that customer is responsible for the lawfulness of that use and for any required disclosures, safeguards and human review.
12. Children#
The Service is for business use and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact us and we will delete it.
13. Changes to this policy#
We may update this policy. We will change the “last updated” date and, where the change is material, give notice by email or in-product before it takes effect.
14. Contact us#
CodeLabs LLC (trade licence 2541506.01, SHAMS)
Registered office: Sharjah Media City, Sharjah, United Arab Emirates
Correspondence: Office 7, 17th Floor, Prime Tower, Business Bay, Dubai, United Arab Emirates
Email: talk@codelabs.ae · Phone: +971 52 668 4165