Effective Date: 24.11.2025
This Privacy Policy explains how Kiowa Mayfield Darlington (FZE) (“Innovisto”, “we”, “us”, or “our”) collects, uses, shares, and protects your personal data when you use the Innovisto platform and website. We are committed to safeguarding your privacy and ensuring that your personal information is handled lawfully, transparently, and securely.
This Policy applies to all data collected through the Innovisto website and application (collectively, the “Service”).
Innovisto is a brand owned and exclusively managed by Kiowa Mayfield Darlington (FZE), a Free Zone company registered at the Sharjah Research Technology and Innovation Park, Sharjah, United Arab Emirates.
For EU and UK users, Innovisto has appointed a GDPR Article 27 representative, reachable at legal@innovisto.com.
Innovisto complies with the General Data Protection Regulation (GDPR) and UAE Federal Law No. 45 of 2021 (Personal Data Protection Law).
We collect only the data necessary to operate and improve the Service. The types of data we process include:
Account Information
Usage Data
Support Data
Payment Metadata
Cookies and Tracking Data
| Purpose | Description | Legal Basis |
|---|---|---|
| Account setup and authentication | To create, verify, and maintain your account, including phone number verification and delivery of OTP codes | Contract performance (Art. 6(1)(b) GDPR) |
| Subscription and billing | To manage plans, renewals, and payments through Paddle | Contract performance; legal obligation for tax |
| Service operation | To provide access to the daily idea platform and maintain technical performance | Contract performance |
| Secure an Idea | To operate the Secure an Idea functionality and maintain internal delivery logic | Contract performance |
| Customer support | To respond to inquiries and resolve issues | Legitimate interests (Art. 6(1)(f)) |
| Security and abuse prevention | To detect fraud, prevent misuse, and protect the Service (Supabase logs, server logs, OTP verification) | Legitimate interests; legal obligation |
| Analytics and improvement | To evaluate usage trends and improve the Service | Consent (Art. 6(1)(a)) |
| Marketing communication | To send optional updates or promotional material | Consent (Art. 6(1)(a)) |
| Legal compliance | To meet regulatory and tax obligations | Legal obligation (Art. 6(1)(c)) |
Where we rely on consent, you may withdraw it at any time through the cookie settings or by unsubscribing from communications.
All payments and billing are handled exclusively by Paddle, which acts as the Merchant of Record. Paddle is an independent controller of your payment data and is responsible for collecting, storing, and processing financial information in accordance with its own privacy policy and applicable laws.
Innovisto only receives limited metadata from Paddle (such as customer ID, plan, and payment status) necessary to maintain your subscription access.
By completing checkout, you also agree to Paddle’s own Privacy Policy, which governs their handling of billing and financial information.
We use cookies and similar technologies to ensure the secure and proper operation of the Service.
Cookie categories:
Non essential cookies do not load unless you actively provide opt in consent through the cookie banner. Until consent is given, only strictly necessary cookies required for authentication and core functionality are used.
Strict opt-in: Analytics and marketing cookies (including Google Analytics, Google Ads, and Meta pixels) are disabled by default and activated only if you provide explicit consent through the cookie banner.
You can withdraw your consent or adjust cookie preferences anytime using the “Manage Cookies” link in the footer.
We also use server-side logging (Supabase logs, rate-limiting logs) for security, fraud prevention, and operational integrity. These logs do not track users for marketing purposes.
We share personal data only with trusted third parties under contractual safeguards. These include:
Twilio Specific Notice
Twilio delivers all OTP (one time passcode) messages. Twilio processes your phone number and message delivery metadata. Twilio operates under its own privacy policy and may process data in the EU, US, or other global regions. Innovisto is not liable for Twilio’s handling or storage of OTP-related data.
International Transfers
Supabase data is hosted in the European Union.
Paddle may process data in the UK and EU.
Twilio may process data in the US or other global regions.
Transfers occur with contractual safeguards, including Standard Contractual Clauses where required.
We do not sell, rent, or lease your personal data to any third parties.
No system is completely immune from risk, but we actively work to minimize exposure and respond promptly to any incidents.
| Data Category | Retention Period | Reason |
|---|---|---|
| Account data | Life of account + 24 months | Reactivation, support, audit |
| Billing data | 5 years | Accounting and legal compliance |
| Analytics data | 12 months | Product improvement |
| Support messages | 24 months | Customer service records |
| Secure an Idea data | Lifetime of subscription + 24 months | Service continuity and audit |
We respond to verified rights requests within 30 days. To exercise your rights, email support@innovisto.com with the subject line “Data Request.”
The Service is intended for adults only. We do not knowingly collect or process personal data from anyone under 18 years of age. If we learn that we have collected data from a minor, we will delete it promptly.
We may update this Privacy Policy to reflect changes in technology, law, or our practices. The latest version will always be available on our website. If material changes occur, we will notify users via email or prominent notice within the app. Your continued use of the Service after such changes constitutes acceptance of the updated policy.
For any privacy-related questions or rights requests, contact:
Email: support@innovisto.com
For EU and UK users: EU Representative (Article 27): legal@innovisto.com
If you believe we have not addressed your concern adequately, you may lodge a complaint with your local supervisory authority.
| Category | Example Data | Purpose | Legal Basis |
|---|---|---|---|
| Account data | Name, email, phone number, DOB, gender, timezone | Account creation, authentication | Contract |
| Subscription data | Plan, renewal date, Paddle ID | Manage billing and access | Contract |
| Analytics | Session data, interactions | Product improvement | Consent |
| Advertising | Pixel data, UTM tracking | Retargeting, campaign measurement | Consent |
| Support | Email, attachments | Respond to inquiries | Legitimate interest |
| Secure an Idea | Secured idea IDs | Feature operation | Contract |
| Legal/compliance | Invoices, records | Accounting, audits | Legal obligation |
Last updated: 24.11.2025