LEGAL

Privacy Policy

Last Updated: 2026

Legal Notice

No part of this document may be reproduced or transmitted in any form or by any means, electronic or mechanical, for any purpose, without the express written permission of Defenix.ai. Under the law, reproducing includes translating into another language or format.

As between the parties, Defenix.ai retains title to and ownership of all proprietary rights with respect to the software contained within its products. The software is protected by UAE copyright laws and international treaty provision. Therefore, you must treat the software like any other copyrighted material (e.g., a book or sound recording).

Every effort has been made to ensure that the information in this document is accurate. Defenix.ai is not responsible for printing or clerical errors. Information in this document is subject to change without notice.

Introduction

Welcome to DefenGPT (“we,” “our,” or “us”). We are committed to protecting your privacy and ensuring the security of your data. This Privacy Policy outlines how we collect, use, disclose, and safeguard your information when you use our Software as a Service (SaaS) or on-premises deployment solutions. By using DefenGPT, you agree to the terms outlined in this policy.

The main modules of DefenGPT

Defenix's DefenGPT offers risk management and data protection for Generative AI, including two modules:

  • AI Firewall – Real-time control of AI services like ChatGPT/Copilot/Gemini by applying risk-based policies and classifying data sensitivity.
  • AI Suite – An end-to-end AI chatbot solution that delivers answers, data analytics, and direct search from your primary data sources while ensuring zero data exposure.

Note: When not specified otherwise, the policy covers both modules.

Information We Collect

a. Personal Information

  • User information: Name, email address, and username for account access via Single Sign-On (SSO). (Relevant for The Admin Centre Only)

b. Corporate Data

As the nature of the AI Suite module is to analyse your company data, it has access to any data you connect which includes:

  • Uploaded Documents: Files and documents you upload to DefenGPT.
  • Integrated Services: Access to your Google Drive, Gmail, SharePoint, Confluence and other integrated services.
  • Corporate Communications: Emails and other communications accessed through integrations.

The Private AI has all the content of the data you connect to be able to answer questions from your data. For users who use only the AI Firewall, the only data stored is the data involved in the AI interaction which includes the prompt text, any files sent with the prompt text and the response. The Firewall collects all data of the AI services configured which includes ChatGPT, Copilot and Gemini.

c. Technical Data

  • Usage Data: Information about how you interact with DefenGPT, including IP addresses, browser type, operating system, and device information.
  • Log Data: Server logs, error reports, and other diagnostic information.

How We Use Your Information

We utilize the collected data for the following purposes:

Service Provision

To operate, maintain, and improve DefenGPT services.

Personalization

To tailor the chatbot experience based on your corporate data and user interactions.

Management

To facilitate connections with integrated services like Google Drive and Gmail.

Security

To protect against unauthorized access, data breaches, and other security threats.

Compliance

To comply with legal obligations and enforce our terms and policies.

Communication

To send updates, notifications, and respond to inquiries.

We do not use your information to develop, improve, or train AI and/or ML models.

Data Storage and Security

a. Storage

  • SaaS Deployment: Data is stored on our secure cloud servers, utilizing industry standard encryption both in transit and at rest.
  • On-Premises Deployment:Data is stored on your organization's servers, with DefenGPT providing the necessary tools and guidelines to ensure data security. When choosing a self-hosted / on prem deployment, Defenix has no access to your data.

b. Security Measures

  • Encryption: All data transmitted between your systems and DefenGPT is encrypted using SSL/TLS protocols.
  • Access Controls: Strict access controls are in place to ensure that only authorized personnel can access your data.
  • Regular Audits: We conduct regular security audits and vulnerability assessments to maintain the integrity of our systems.

c. Securing Your Data

All data is encrypted in transit to and from the Internet, mitigating the risk of third parties accessing it. We store data in data centers around the globe in accordance with the needs of our customers. If needed, we offer a specific location for our SaaS depending on AWS availability in that country. We also offer an on-premises deployment that keeps our customers' data 100% secure and private according to their internal security guidelines.

Authentication and Access

Single Sign-On (SSO):DefenGPT utilizes Single Sign-On (SSO) for user authentication. We do not collect or store user passwords. Instead, authentication is managed through your organization's chosen SSO provider, ensuring secure and streamlined access to our services. Note that in the demo environment there is an option to create a local user in which we store the hash of your password.

Data Sharing and Third Parties

We do not share your personal or corporate data with any third parties. Your data is solely used to provide and enhance the DefenGPT services you have subscribed to. We do not sell, rent, or lease your data to any external entities.

Cookies and Similar Technologies

a. What Are Cookies? Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work more efficiently and to provide information to the owners of the site.

b. Types of Cookies We Use
Essential Cookies: These cookies are necessary for the basic functioning of DefenGPT. They enable core functionalities such as security, network management, and accessibility.
Functional Cookies: These cookies allow DefenGPT to remember choices you make (such as your language preference) and provide enhanced, more personalized features.

c. Managing Cookies: You have the right to decide whether to accept or reject cookies. You can adjust your browser settings to refuse all cookies or to indicate when a cookie is being sent. However, please note that some parts of DefenGPT may not function properly if cookies are disabled.

User Rights

You have the following rights regarding your data:

Access

Request access to the data we hold about you.

Rectification

Request corrections to inaccurate or incomplete data.

Deletion

Request the deletion of your data, subject to legal and contractual obligations.

Objection

Object to the processing of your data for certain purposes.

Please note that we do not offer data portability. This means you cannot request the transfer of your data to another service provider through our platform. To exercise these rights, please contact us using the information provided in the Contact Us section.

Data Retention

We retain your data for as long as necessary to provide DefenGPT services, comply with our legal obligations, resolve disputes, and enforce our agreements. Specifically, after 30 days of decommissioning the service, personal data will be deleted. The specific retention periods may vary based on the type of data and its intended use.

Children's Privacy

DefenGPT is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete such information promptly.

Choices of AI Engine

Organizations using DefenGPT can select between public AI engines (e.g., OpenAI) and private AI engines (e.g., Llama3.1).

  • Public AI Engines: If you choose to use a public AI engine, your data may be processed by the chosen AI provider. We ensure that such providers comply with relevant data protection regulations and that the use of your data is limited to the purposes disclosed in this Privacy Policy.
  • Private AI Engines: Selecting a private AI engine ensures that your data is processed solely within your infrastructure and is not shared with any third parties.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any significant changes by posting the new policy on our website and updating the “Last Updated” date.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Contact Us

Disclaimer

While Defenix uses reasonable efforts to include accurate and up-to-date information in this document, Defenix makes no warranties or representations as to its accuracy. Defenix assumes no liability or responsibility for any typographical or other errors or omissions in the content of this document.

Limitation of Liability

Defenix.ai and/or its respective suppliers make no representations about the suitability of the information contained in this document for any purpose. Information is provided “as is” without warranty of any kind and is subject to change without notice. The entire risk arising out of its use remains with the recipient. In no event shall Defenix.ai and/or its respective suppliers be liable for any direct, consequential, incidental, special, punitive, or other damages whatsoever (including without limitation, damages for loss of business profits, business interruption, or loss of business information), even if Defenix.ai has been advised of the possibility of such damages.