Privacy Notice

How we protect, process and respect your information
Last updated: 1 August 2026

Who We Are

Leto App AI Services Ltd (“LetoApp”, “we”, “us” or “our”) provides an AI-assisted concierge service through our website and WhatsApp Business API, supported by human oversight.

We are incorporated in the Dubai International Financial Centre (DIFC) and are primarily subject to the DIFC Data Protection Law and Data Protection Regulations, including requirements relating to Personal Data processed through autonomous and semi-autonomous systems. Where applicable, other data protection laws may also apply, including the UAE Federal Personal Data Protection Law.

This Privacy Notice explains how we collect, use, share, transfer, protect and retain Personal Data when you use our services or interact with us. It applies to:
- users and prospective users of LetoApp;
- visitors to our website;
- individuals communicating with us through WhatsApp or other supported channels;
- vendors, contractors and business partners; and
- other individuals whose Personal Data we lawfully process.

Depending on the circumstances, LetoApp may act as a Controller where we determine why and how Personal Data is processed, or as a Processor where we process Personal Data on behalf of another organisation under documented instructions and contractual safeguards.

Personal Data We Collect

Identity and contact information: Name, email address, telephone number, delivery address and other contact details.

Concierge and task information: Requests, preferences, booking details, reminders, notes, scheduling information and other information needed to fulfil a requested service.

Communications: Messages and interactions through supported channels, including WhatsApp Business API and our website.

Transaction information: Payment confirmations, amounts and transaction details. Full payment card details are processed by authorised PCI DSS-compliant payment providers and are not stored by LetoApp.

Device and usage information: IP address, browser or device information, security logs and service interaction information.

Location information: Location or address information where necessary to provide a service you request, such as a delivery or reservation.

Special Category Personal Data

LetoApp does not actively seek Special Category Personal Data. However, because we provide a concierge service, such information may occasionally arise from a request you choose to make, for example information relating to a medical appointment or dietary requirement. Where this occurs, we process the information only where necessary and lawful, apply appropriate safeguards and, where required, obtain explicit consent.

How We Collect Personal Data

We may obtain Personal Data:

- directly from you through onboarding, forms, messages and service requests;
- through integrations you authorise, such as calendar, communication or payment services;
- from third parties you ask us to interact with; and
- through system-generated security, operational and service logs.

AI-Assisted Processing

LetoApp uses AI-enabled systems to support the concierge services you request. These systems may process Personal Data to:

- understand and structure your requests;
- generate recommendations;
- prepare or coordinate tasks;
- assist with scheduling, reservations and service fulfilment; and
- support communications relating to your request.

Our AI-enabled systems are designed to operate for defined, human-approved purposes and within established operational and access controls. They are not intended to independently determine unrelated purposes for the use of your Personal Data. Some low-risk recommendations or suggestions may be generated automatically. Where an action may have a legal, financial or other significant impact, appropriate human review or intervention is applied before execution.

You may request human review of an AI-generated recommendation or output at any time. We assess our AI-enabled systems and related processing for privacy, security, fairness and compliance risks and apply appropriate governance, monitoring and escalation controls.

Transparency and Human Oversight

When you interact with an applicable AI-enabled feature, we provide information about the use of AI and Personal Data through appropriate channels, which may include:

- website interfaces;
- onboarding;
- WhatsApp service interactions;
- feature-specific notices; and
- this Privacy Notice.

Depending on the service, this information may explain:
- why Personal Data is being processed;
- how AI supports the service;
- the types of recommendations or outputs that may be generated;
- how those outputs may be used;
- the availability of human oversight or intervention; and
- how you can exercise your rights.

Cookies and Similar Technologies

We use cookies and similar technologies for essential website operations and, where applicable, analytics or optional functionality. Essential cookies operate where necessary for the service. Optional cookies are used in accordance with applicable consent requirements. You can review our Cookies & Consent Policy for further information and manage available preferences through our consent controls.

You may also contact privacy@letoapp.com with questions about cookies or consent.

Sharing Personal Data

We share Personal Data only where necessary and lawful. Recipients may include:

- Service providers and processors: cloud hosting, communications, scheduling, customer support, analytics and payment providers.
- Third parties you ask us to engage: for example restaurants, hotels, transport providers, delivery providers or other businesses required to fulfil your request.
- Technology and integration partners: where necessary to operate integrations you have authorised or support our concierge service.
- Professional advisers: legal, compliance, accounting or technical advisers subject to appropriate confidentiality obligations.
- Public or regulatory authorities: where disclosure is required or permitted by applicable law.

We require our processors and service providers to process Personal Data only for authorised purposes and to maintain appropriate confidentiality and security safeguards.

Service Fulfilment and Third Parties

Where you ask LetoApp to arrange a service, we may provide limited Personal Data to the relevant third party. For example:

- a restaurant may receive your name and booking details;
- a delivery provider may receive your name, contact details and delivery location; or
- a travel or hospitality provider may receive information necessary to complete your reservation.

We seek to share only the information reasonably necessary to fulfil your request.

Payments

Payments are processed through authorised third-party payment providers. LetoApp may process transaction information such as payment status, amount and service details, but does not store full payment card numbers. Payment card information is handled through PCI DSS-compliant payment infrastructure.

International Transfers

LetoApp may process or transfer Personal Data outside the DIFC. Our primary hosting currently includes infrastructure located in the United States, and elements of AI development or operational support may take place in Colombia. Where Personal Data is transferred to a jurisdiction that does not benefit from an applicable DIFC adequacy decision, we apply appropriate transfer safeguards.

These may include:
- approved contractual safeguards;
- transfer risk assessments;
- vendor due diligence;
- encryption;
- access restrictions;
- data minimisation; and
- audit logging and monitoring.

Further information about applicable international transfer safeguards is available on request.

Security

We maintain organisational and technical measures designed to protect Personal Data against loss, misuse, unauthorised access, disclosure, alteration or destruction. These measures may include:

- role-based and least-privilege access controls;
- authentication controls;
- encryption in transit and at rest;
- audit logging and monitoring;
- secure software development and code review;
- vulnerability management and remediation;
- vendor security assessment and contractual safeguards;
- data minimisation and retention controls;
- human oversight of significant AI-assisted actions; and
- PCI DSS-compliant payment processing.

No technology environment can eliminate all risk, and we regularly review and improve our security and governance controls.

Personal Data Breaches

If a Personal Data Breach occurs, we assess its nature, scope and potential impact. Where notification to the DIFC Commissioner of Data Protection is required, we will notify the Commissioner as soon as practicable in the circumstances. Where a breach is likely to result in a high risk to affected individuals, we will also communicate with those individuals as required by applicable law.

Retention

We retain Personal Data only for as long as necessary for the purposes for which it was collected and to satisfy applicable legal, contractual, security and compliance requirements. Depending on the information involved, this may include:

- account information for the duration of the user relationship;
- task and booking records for the period necessary to complete the transaction and manage disputes or compliance obligations;
- security and support logs for appropriate operational and security periods; and
- payment and accounting records for applicable legal or tax retention periods.

When Personal Data is no longer required, we delete, anonymise or securely dispose of it in accordance with applicable requirements.

Your Rights

Subject to applicable law, you may have rights to:

- access your Personal Data;
- correct inaccurate information;
- request erasure;
- restrict processing;
- object to certain processing;
- request portability;
- withdraw consent where processing relies on consent; and
- raise a complaint regarding how your Personal Data is processed.

You may also have rights relating to automated processing and may request human review of relevant AI-generated outputs or decisions. Where Personal Data is processed through autonomous or semi-autonomous systems, you may also have rights to challenge relevant outcomes in accordance with applicable DIFC requirements.

We respond to valid requests in accordance with applicable legal requirements.

Children

LetoApp is not intended for individuals under 18 years of age, and we do not knowingly provide the service to children.

Governance and Accountability

LetoApp maintains governance arrangements designed to support responsible Personal Data processing and use of AI-enabled systems. Our governance framework includes appropriate oversight of:

- Personal Data processing;
- AI-enabled systems;
- privacy and security risks;
- third-party and international transfer risks;
- human oversight and escalation; and
- Data Subject rights.

We have appointed an external Data Protection Officer and AI Governance Officer to support oversight of our privacy and AI governance obligations.

- DPO / Governance Service Provider: GX1 AI Limited
- Contact: hello@gx1.ai

The DPO is the primary point of contact for privacy and data protection matters, including requests relating to your rights.

Changes to this Notice

We may update this Privacy Notice to reflect changes in our services, technology, legal obligations or governance practices. Where changes are material, we will take reasonable steps to notify affected users. The date at the top of this Notice indicates when it was last updated.

Contact Us

For privacy questions, rights requests or complaints:
Email: privacy@letoapp.com

For questions about AI-generated outputs or requests for human review:
Email: support@letoapp.com