Privacy Notice
Effective: · Last updated:
1. Who we are
Limitls AI is an operating brand of Limitless Tech (FZE), a Free Zone Establishment licensed by Sharjah Research Technology and Innovation Park (SRTIP), license no. 11433.
Privacy contact: privacy@limitls.ai
For the website, business inquiries, and Limitls’s own commercial relationships, Limitless Tech (FZE) determines why and how personal information is used. When Limitls handles personal information only on a client’s documented instructions, the client may be the controller or business, and Limitls acts as a processor or service provider under the applicable agreement.
2. Scope
This notice explains how we handle personal information when you:
- visit
limitls.ai; - contact us, submit an inquiry, or schedule a meeting;
- communicate with us about a possible or current business relationship;
- participate in a supplier, partner or procurement process; or
- receive relevant business-to-business outreach from us.
Client-project information may also be governed by a signed agreement, SOW, DPA, client policy or project-specific privacy notice. If those documents impose a stronger commitment for the relevant processing, we follow that commitment.
3. Information we collect
Depending on the interaction, we may collect:
- name, work email, job title, organization, country or market and professional contact details;
- the service pressure and context you choose to submit;
- the industry or domain you optionally select;
- meeting details, calendar availability and business correspondence;
- proposal, contract, supplier-onboarding, billing and payment-administration information;
- limited technical information such as page, referrer, device class, approximate region and security logs;
- source, status, last-contact date and opt-out status for a business prospect; and
- information you provide while exercising a privacy right or reporting a concern.
For business prospects, information may come from the person or their organization, referrals, professional events, public organization websites and public professional profiles. Limitls does not use purchased, harvested or scraped contact lists.
Do not submit client-confidential material, credentials, regulated records, special-category information or other sensitive information through the public contact form or ordinary email unless we have agreed a secure channel and purpose.
4. How we use information
We use personal information to:
- respond to inquiries and schedule meetings;
- understand fit, prepare proposals and manage business relationships;
- provide contracted services and coordinate approved delivery parties;
- operate, secure, measure and improve the website;
- maintain records, invoices, contracts, tax and compliance evidence;
- perform conflict, fraud, sanctions, security and supplier checks where appropriate;
- send targeted business-to-business communications where permitted and honor opt-outs; and
- establish, exercise or defend legal rights and comply with law.
The legal basis depends on the law and context. It may include consent where required, steps requested before a contract, performance of a contract, compliance with law, protection of rights and safety, or a legitimate business interest recognized by applicable law. We do not rely on a lawful basis that the applicable jurisdiction does not recognize.
5. Website analytics and cookies
Two kinds of website analytics run here and they are treated differently. Vercel Web Analytics runs on every visit in its cookie-free, privacy-minimized mode: it sets no cookie, stores nothing on your device, and identifies a visit by a value derived from the request that Vercel discards within 24 hours. Google Analytics runs only if you accept it, and it sets two first-party cookies when it does.
You are asked once, in a banner at the bottom of the page, and you can accept or decline. Declining does not affect the website, the contact form or scheduling. Before you choose, and if you decline, no Google Analytics script is loaded, no request is made to Google and no Google cookie is set. You can change your choice at any time from Privacy preferences in the footer of any page.
No advertising pixel, session replay or live-chat tracking is configured. Analytics events must not contain names, email addresses, organization names, free-text form content or confidential information, and web addresses are filtered before they leave your browser so that only campaign parameters and the service you arrived from are kept.
If another non-essential analytics or advertising technology is later introduced, this notice and the Cookies & Analytics page must be updated, and the technology must not load before any consent required by applicable law is obtained.
See Cookies & Analytics for what each service sets and how to change your choice.
6. Service providers and delivery parties
We use these service providers to operate the business:
- website hosting and privacy-minimized analytics: Vercel;
- email, calendar and business productivity: Microsoft 365 supplied through GoDaddy;
- meeting scheduling: Calendly;
- source-code hosting and software delivery: GitHub;
- controlled business-file storage and collaboration: approved Microsoft services or a client-controlled workspace;
- contact-form delivery: Resend, sending from forms.limitls.ai; and
- approved delivery specialists, only when relevant to an opportunity or engagement.
Where you have already typed details into our contact form, those values may be passed to the scheduling interface so you do not re-enter them. They are held only in your browser until you choose to schedule, and are not placed in web addresses, analytics or stored on your device.
When you choose Schedule a call, we load Calendly within this page. Calendly processes the information you enter to arrange the meeting and provides its own cookie settings for the scheduling experience. You can decline optional cookies and continue booking.
Calendly loads its own analytics and advertising providers inside that scheduling area, under its own terms rather than ours. Nothing from Calendly loads, and no Calendly cookie is set, until you choose to schedule.
Calendly’s privacy notice (opens in a new tab) explains its processing. Our own analytics are the two services described in Cookies & Analytics: cookie-free measurement that runs for everyone, and Google Analytics only if you accept it.
We may disclose information to professional advisors, insurers, regulators, law enforcement, or counterparties where reasonably necessary and lawful. We do not sell personal information. We do not share it for cross-context behavioral advertising or use it for targeted advertising.
Delivery parties receive only the access required for their role and are disclosed and governed as required by the relevant agreement. Partner certifications and controls belong to the partner and are not represented as Limitls certifications.
7. International transfers
We are based in the United Arab Emirates and may use providers or delivery parties in other countries, including the United States. Personal information may therefore be stored or accessed outside the country where it was collected.
Transfers are subject to applicable data-protection requirements and any agreed restrictions on providers, locations and access. A client agreement or data-processing agreement may impose additional limits for client-project information.
Contact privacy@limitls.ai for information about the arrangements relevant to your information or engagement.
8. Retention
We keep personal information only for a defined business, contractual, security or legal purpose. The default schedule is:
| Record | Default retention |
|---|---|
| Unqualified inquiry with no active opportunity | 12 months after collection or the last inbound/outbound business contact, whichever is later |
| Qualified or active opportunity | While active and up to 24 months after closure |
| Unsuccessful proposal | 24 months after closure |
| Calendly meeting administration | 12 months unless incorporated into an active opportunity or client record |
| Client working information | Engagement plus up to 90 days, unless the contract requires a different return or deletion period |
| Contracts, invoices, tax and legally required business records | 7 years, or longer where law, audit or a legal hold requires it |
| Security and access logs | Normally at least 90 days where the service supports it; longer where risk or contract requires |
| Incident records | 7 years as an internal default, subject to legal review |
| Backup copies | Rolling lifecycle, normally up to 90 days where technically feasible |
| Marketing suppression record | The minimum identifier and date needed to honor the opt-out for as long as necessary |
We may retain information longer when required by law, contract, an investigation, a dispute or a documented legal hold. We may delete or anonymize it earlier when the purpose has ended and no exception applies.
9. Security
We use proportionate administrative, technical and organizational safeguards based on the information and risk involved. No method of transmission, storage or security control eliminates all risk. Do not send sensitive information through a channel that we have not approved for it.
Report a suspected issue through the security-reporting section of the Trust page.
10. Your choices and rights
Depending on applicable law and our role, you may be able to ask us to:
- confirm whether we hold personal information about you;
- provide access to or a copy of it;
- correct inaccurate information;
- delete information that no longer has a lawful purpose;
- restrict or object to certain uses;
- withdraw consent where processing depends on consent;
- provide portable information where the right applies; or
- stop business-to-business marketing communications.
These requests can cover information such as your contact details, organization, correspondence, meeting record, opportunity notes or lead-list entry. We may need to verify identity and authority. Some information may be retained where law, contract, tax, security, legal claims or another valid exception requires it.
Email privacy@limitls.ai. Our internal target is to acknowledge a request within five business days and respond within the period required by applicable law. If we need more information or time, we will explain why where the law permits.
To stop marketing email, use the stated opt-out method or reply with your request. We maintain the minimum suppression record needed to prevent future outreach.
11. United States disclosures
Where a United States state privacy law applies, we process verified requests and honor applicable rights and appeal mechanisms. We do not sell personal information, share it for cross-context behavioral advertising or use it for targeted advertising. Because laws differ by state and threshold, this statement does not imply that every state law applies to every Limitls interaction.
For United States commercial email, Limitls applies the CAN-SPAM requirements, including accurate sender information, a valid physical postal address, clear identification of the commercial message, a clear opt-out and timely suppression. No United States commercial outreach may begin until the address used has been confirmed as current, complete and able to receive mail. A United States address is not required merely because the recipient is in the United States.
12. Children
The website is directed to business and public-sector decision-makers and is not intended for children. We do not knowingly collect personal information from a child through the public site. If you believe a child has submitted information, contact us so we can review and delete it where appropriate.
13. Changes
We may update this notice when our services, providers or legal obligations change. We will change the “last updated” date and provide additional notice where a change materially affects how personal information is handled.
14. Contact and complaints
For privacy questions, requests or complaints, email privacy@limitls.ai. For postal correspondence or a formal notice, contact us for the appropriate delivery details.
You may also complain to the competent privacy or regulatory authority where applicable. You do not need to contact us first to exercise that right.