AI Compass

Privacy Policy

Version 1.0 · Updated 30 September 2026 · Under legal review

1. About this policy

AI Compass (the Platform) is an internal intelligence platform operated by the Dubai Centre for AI, part of Dubai Future Foundation (DCAI or DFF). It is available only to nominated officers of participating Dubai government entities and to authorised DCAI staff. It is not open to the public.

This policy explains what personal data the Platform holds about you, why, and what we do with it. The Dubai Centre for AI (DCAI), part of Dubai Future Foundation, is responsible for the personal data described in this policy. When we refer to personal data, we mean any information about an individual from which that person can be identified.

2. What personal data we hold

The Platform holds very little personal data. The only personal data it stores is your account record:

  • your work email address;
  • your display name;
  • your role on the Platform (CAIO, Admin or Viewer);
  • the government entity you belong to (where applicable);
  • whether your account is active; and
  • the date and time you last signed in.

If your account uses the password sign-in route (see Clause 3), we also store your password as an irreversible cryptographic hash. The password itself is never stored and the hash cannot be read back or reversed.

Your account is set up by DCAI when your entity nominates you for access. Your work email address is provided as part of that nomination, and your display name is provided with your nomination. Each time you sign in with single sign-on, your organisation's sign-in service confirms your verified email address to the Platform. A small number of accounts that cannot use single sign-on sign in with a password instead (see Clause 3).

What we do not hold. The Platform has no place where you can save text, upload a document or record an entry, so it holds no content written or uploaded by you. It keeps no browsing history or page-by-page activity log, uses no analytics, advertising or marketing tools, and collects no special categories of personal data.

3. How you sign in

Most users sign in with single sign-on. You enter your work email address and are sent to your own organisation's Microsoft sign-in page, where you sign in against your employer's directory. Microsoft then confirms your verified email address to the Platform, which checks it against the list of approved accounts. The Platform never sees or handles your password in this process.

A password route exists for a small number of accounts that cannot use single sign-on. For those accounts only, the password is stored as described in Clause 2.

4. Cookies

The Platform uses one cookie: an encrypted session cookie that keeps you signed in. It is stored in your browser and is valid for 24 hours, after which you need to sign in again. It is strictly necessary for the Platform to work. The Platform sets no advertising, analytics or tracking cookies.

5. Questions you ask the AI features

Some parts of the Platform let you ask questions (for example, about a report or policy document, or about the Platform itself). When you do, your typed question and the material needed to answer it are sent to a third-party artificial intelligence service, through DFF's own systems hosted in the UAE, to produce the answer. Processing takes place in the United Arab Emirates.

The Platform does not attach your name, email address or entity to these requests.

  • The Platform does not store your questions or the answers. A conversation exists only while the question panel is open.
  • Anything you type into a question box is sent as part of the request. Please do not type personal data, or confidential, proprietary or classified information, into a question box.

6. News images loaded from other websites

The Worldwide AI News page shows thumbnail images published by the news outlets that wrote each article. These images load directly from each outlet's own website, so those outlets may be able to see that the news page has been opened and will receive the standard technical information your browser sends when loading an image (such as your IP address). This is the only place in the Platform where content is loaded from an outside website; logos, flags and fonts elsewhere are served from our own infrastructure.

7. How we use your personal data

We use your account record only to:

  • confirm who you are when you sign in;
  • decide what you can access, based on your role and entity; and
  • administer accounts, including activating and deactivating them.

We do not sell, rent or disclose your information to commercial third parties, and we do not use it for marketing.

8. Who can see your personal data

Your account record can be seen by DCAI administrators. Password hashes cannot be read by anyone.

The Platform is hosted on cloud infrastructure provided by a third-party provider and administered by DFF. DFF staff have access to the infrastructure for the purpose of operating it, and the cloud provider processes data only as needed to provide the hosting service.

We may also disclose your personal data to a competent law enforcement body, regulator, government agency or court where we believe disclosure is required by applicable law or regulation, or is necessary to establish, exercise or defend our legal rights.

9. Where your personal data is stored

Your account record is stored in a database within Dubai Future Foundation's cloud environment in the UAE. All connections to the database are encrypted in transit. The Platform does not use any separate or third-party database.

Generating answers to your questions also takes place within the United Arab Emirates. No personal data is processed outside the UAE.

10. How we protect your personal data

No online service can be guaranteed to be completely secure. Please take reasonable precautions to protect your account, including keeping any sign-in details confidential.

The Platform includes the following security measures:

  • Sign-in through your employer's Microsoft directory, so the Platform never handles your password in the single sign-on route.
  • An encrypted session cookie that expires after 24 hours.
  • Encrypted connections to the database.
  • A web application firewall that inspects every incoming request before it reaches the Platform.
  • Access restrictions by role, enforced on the server.
  • Irreversible hashing of passwords for accounts using the password route.

11. How long we keep your personal data

We keep your account record for as long as necessary to operate the Platform and administer your access to it, including to comply with our legal obligations. When you leave your post, or your entity leaves the programme, your account will be deactivated and your account record deleted within 30 days.

12. Your requests

You can contact us to ask what personal data we hold about you, or to ask us to correct or delete it. We will respond to requests in accordance with applicable data protection laws and government data policies. Please also let DFF know if you leave your post so that your account can be closed.

13. Changes to this policy

We may update this policy, for example if the Platform changes. The “last updated” date at the top will show when it was last changed, and we will tell you when you next sign in if we make a material change.

14. Contact

For questions about this policy, your personal data, or to exercise your rights, contact the Dubai Centre for AI at info@dub.ai.