Privacy Policy
Last Updated: February 2026
Introduction
UMMRO ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our AI-compliance and robustness testing platform.
This policy is designed to comply with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws. By using the Service, you acknowledge that you have read and understood this Privacy Policy.
1. Information We Collect
Information You Provide
- Account information: name, email address, organization, and password
- Payment information: billing details processed securely by our payment providers
- Communications: messages, support requests, and feedback you send to us
- AI system information: model configurations, prompts, and evaluation settings you submit for testing
Automatically Collected Information
- Log data: IP address, browser type, pages visited, and timestamps
- Device information: operating system, device identifiers, and screen resolution
- Usage data: features used, evaluation runs, and interaction patterns
- Cookies and Tracking Technologies
Information from Third Parties
We may receive information about you from third-party services, such as authentication providers, payment processors, and analytics services, in accordance with their privacy policies and your settings with those services.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Process transactions and manage billing
- Send administrative communications, such as service updates and security notices
- Respond to your inquiries and provide customer support
- Monitor and analyze usage trends to improve performance and reliability
- Detect, prevent, and address fraud, abuse, and security incidents
- Comply with legal obligations and regulatory requirements
- Understand how the Service is used and develop new features
3. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, in line with GDPR Article 32.
Our security measures include:
- Encryption of data in transit using TLS
- Encryption of data at rest
- Regular security assessments and penetration testing
- Strict access controls based on the principle of least privilege
- Employee training on data protection and security practices
- Incident response procedures for detecting and handling security breaches
While we strive to protect your personal data, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
4. Data Sharing and Disclosure
We do not sell your personal data. We may share your information only in the following circumstances:
- Service Providers: We share data with trusted vendors who perform services on our behalf, such as hosting, payment processing, and analytics, under contractual obligations to protect your data.
- Legal Requirements: We may disclose your information if required to do so by law, court order, or governmental authority, or to protect our rights, safety, or property.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction, subject to equivalent protection.
- With Your Consent: We may share your information for other purposes with your explicit consent, which you may withdraw at any time.
5. Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal data. We will respond to valid requests within the timeframes required by applicable law.
GDPR Rights (EU/EEA Users)
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of your personal data where there is no legal basis for continued processing.
- Right to Restrict Processing: Request that we limit the processing of your personal data in certain circumstances.
- Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
- Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Withdraw your consent at any time where processing is based on consent.
California Privacy Rights (CCPA)
If you are a California resident, you may have additional rights under the California Consumer Privacy Act, including the right to know what personal information we collect, the right to request deletion, and the right not to be discriminated against for exercising your privacy rights.
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy. Retention periods depend on:
- The type and sensitivity of the data
- Legal and regulatory retention requirements
- Legitimate business purposes, such as security and audit needs
- The status of your relationship with us, such as whether your account is active
When data is no longer needed, it is securely deleted or irreversibly anonymized.
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to operate the Service, remember your preferences, and analyze usage. For full details, please see our Cookie Policy.
We use the following types of cookies:
- Essential: Required for the Service to function, such as authentication and security cookies.
- Analytics: Help us understand how the Service is used so we can improve it.
- Preference: Remember your settings, such as language and theme choices.
- Marketing: Used to measure the effectiveness of our communications and campaigns.
You can control cookies through your browser settings and our consent banner. Disabling certain cookies may affect the functionality of the Service.
8. Third-Party Links
The Service may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies.
9. Children's Privacy
The Service is not directed to individuals under the age of 16, and we do not knowingly collect personal data from children. If we become aware that we have collected data from a child without appropriate consent, we will delete it promptly.
10. International Data Transfers
Your personal data may be transferred to and processed in countries other than your own. Where we transfer data outside the European Economic Area, we ensure appropriate safeguards are in place, such as the European Commission's Standard Contractual Clauses or adequacy decisions.
By using the Service, you acknowledge that your data may be processed in these locations under such safeguards, and you may contact us for more information about the specific mechanisms used.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last Updated" date. For significant changes, we may also notify you by email.
12. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: privacy@ummro.dev
Data Protection Officer: Contact details available upon request
13. GDPR Data Processing Agreement
For customers processing personal data through the Service, UMMRO acts as a data processor under GDPR Article 28. We process personal data only on documented instructions from the customer and in accordance with our contractual commitments.
A Data Processing Agreement (DPA) covering our processing obligations, sub-processors, and security measures is available upon request at privacy@ummro.dev.
Entity Information
Service Provider: UMMRO by Ahmed Adel Bakr Alderai
Last Updated: February 2026