Trust

Trust and Security

What we commit to on security, data handling and contracts. Written for your legal and procurement review.

Last updated 30 Sep 2026

01Company

Legal entityScoremachine Software FZ-LLC
RegistrationFree Zone Limited Liability Company, Dubai Development Authority, licence 106701
Registered officeHD42B, First Floor, In5 Tech, Dubai Internet City, Dubai, UAE
HostingOVHcloud (platform and API) · Cloudflare (website)
ProgramsMember of the OVHcloud Startup Program
Governing lawUAE law as applied in Dubai. Disputes go to DIAC arbitration, seated in Dubai, in English

02How We Handle Your Data

Our clients control the contact data they submit. We process it as their processor, on their documented instructions only.

24 hoursQuery payloads, deleted after the request completes
30 daysOperational and billing logs, with identifiers hashed or truncated where feasible
30 daysEncrypted backups, deleted on a rolling basis
  • We never use your data for our own purposes, including model training. Irreversibly anonymized data is the one exception.
  • We notify you of a personal data breach within 48 hours of becoming aware of it.
  • When the agreement ends, we delete or return your data, at your choice. We confirm deletion in writing on request.
  • The services are not designed for sensitive personal data or data about children. Please do not submit it.

Privacy Policy →

03Security Measures

The measures in force today, as set out in Annex B of our DPA.

01

Access control

Role-based access on a need-to-know basis. Unique credentials, multi-factor authentication for admin access, and prompt revocation on role change.

02

Encryption

TLS 1.2 or higher on all API and web traffic. Stored payloads, logs and backups are encrypted at rest.

03

Transient processing

Query payloads are processed in memory or short-lived storage. They are purged within 24 hours.

04

Network and hosts

Firewalls, network segregation, hardened hosts and timely security patches.

05

Monitoring

Security event logging, monitoring for unauthorized access attempts and alerts on unusual activity.

06

Vulnerability management

Periodic vulnerability scans. Fixes are prioritized by severity.

07

Personnel

Confidentiality undertakings and security training for everyone with access. Background screening where the law permits.

08

Incident response

A documented procedure that supports the 48-hour breach notice.

09

Business continuity

Encrypted backups with rolling deletion, and documented recovery procedures.

04Sub-processors and Transfers

We run lookups through vetted telecom and data intelligence partners. Their identities are commercially confidential.

Categories we use

  1. 01Cloud hosting and infrastructure
  2. 02Numbering intelligence and number portability
  3. 03Carrier and line-status intelligence
  4. 04Digital activity and messenger presence
  5. 05Email verification

What we commit to

  • The full list gives each partner’s legal name, service, country and data categories. We send it within 10 business days of a written request, under the NDA or your agreement.
  • We give 14 days’ notice before adding or replacing a partner. You may object in that window.
  • Each partner signs data protection terms no less protective than our DPA. We stay liable for their performance.
  • Transfers outside the UAE, or outside the EEA and UK where the GDPR applies, rely on an adequacy decision or on contractual safeguards. Where the GDPR applies, those include the EU Standard Contractual Clauses or the UK equivalent.

05Legal Pack

Our standard documents, summarized. Request the full set and we will send it to your work email.

Signed first

Mutual NDA

  • Lets both sides discuss capabilities, pricing, volumes and use cases.
  • Mutual. It protects your information exactly as it protects ours.
  • Two-year term. Obligations last three years from each disclosure, and longer for trade secrets.
  • No recording of calls or demos without written consent.
  • Covers no personal data. Processing needs the MSA and DPA.

The framework

Master Services Agreement + Order Form

  • The MSA sets the terms. Each engagement is a short Order Form covering services, volumes, pricing and payment method.
  • Prepaid balance or postpaid invoicing, in USD, exclusive of VAT.
  • Prices are fixed for the Initial Term of each Order Form.
  • Either side may end the framework on 30 days’ notice. We never terminate for convenience during a live Initial Term.
  • Unused prepaid balance is refunded within 30 days of termination.
  • UAE law, and DIAC arbitration in Dubai after 30 days of good-faith negotiation.

Before any processing

Data Processing Agreement

  • Signed with the MSA, before any personal data is processed.
  • Reflects UAE Federal Decree-Law No. 45 of 2021 (PDPL) and, where it applies, Article 28 of the EU GDPR.
  • Prevails over the MSA on any data protection matter.
  • Covers instructions, security, sub-processors, transfers, breach notice, audits, and return or deletion.
  • One audit a year on 30 days’ notice, and more after a breach.

These summaries are for convenience. The signed agreements govern.

Request the legal pack

Documents

Your request goes to legal@scoremachine.ai. We use these details only to reply. See the Privacy Policy.

Legal and privacy

legal@scoremachine.ai

Technical and support

support@scoremachine.ai

Registered office

Scoremachine Software FZ-LLC, HD42B, First Floor, In5 Tech, Dubai Internet City, Dubai, UAE