Data Protection Statement
The practical controls behind Sulook systems: scoped workflows, human approval gates, evidence-backed outputs, and accountable handling of operational information.
DIFC-aligned accountability
Sulook aims to operate in line with the DIFC Data Protection Law No. 5 of 2020 and related regulations and guidance where applicable. Our operating model is based on accountability, lawful and fair processing, transparency, security, purpose limitation, data minimisation, and respect for individual rights.
Governance by design
Sulook systems are designed around scoped workflows, human approval gates, evidence-backed outputs, role boundaries, and operational audit trails. Our goal is to help organisations gain leverage from AI without losing accountability or control.
Data minimisation and purpose limitation
We aim to collect and process only the information reasonably needed for discovery, scoping, implementation, support, and agreed service delivery. Client information is used for the purpose for which it was shared: assessing workflows, building approved systems, preparing deliverables, supporting deployed tools, or meeting administrative and legal obligations.
Human approval boundaries
For sensitive or irreversible actions, Sulook designs systems so AI agents assist rather than independently decide. External communications, pricing, payments, legal commitments, client-facing approvals, and similar actions should remain subject to human approval unless a client explicitly defines a safe and limited operating rule.
Evidence and auditability
Where appropriate, outputs can be linked to source documents, records, event logs, workflow state, approvals, or other evidence. This helps teams understand what information was used, what was decided, what was approved, and what remains blocked.
Access control and confidentiality
We seek to restrict access to client materials to people, systems, and service providers that need access for the relevant engagement. Role-based lanes can separate research, drafting, verification, approval, and execution responsibilities.
Client materials, operational details, workflow records, and non-public business information are handled as confidential unless they are already public, independently developed, or approved for disclosure.
Processors and third-party tools
Some engagements may involve hosting providers, communication platforms, model providers, automation tools, analytics services, document systems, or other third-party software. The specific tools used may depend on the agreed workflow, client requirements, security needs, lawful transfer requirements, and implementation scope.
International transfers
Where personal data is transferred outside the DIFC or UAE, Sulook aims to assess the transfer route and use appropriate contractual, organisational, or technical safeguards where required by applicable DIFC data protection rules.
Rights, requests, and complaints
Individuals may contact Sulook to request access, correction, deletion, restriction, objection, portability, withdrawal of consent where applicable, or review of relevant automated processing, subject to applicable law and legitimate business or legal requirements.
For privacy or data protection questions, contact hello@sulook.ae. Individuals may also have the right to contact or complain to the DIFC Commissioner of Data Protection.
Security incidents
If we become aware of a personal data breach, we will assess the incident and take appropriate steps, which may include containment, investigation, remediation, and notification to clients, affected individuals, or the DIFC Commissioner of Data Protection where required.
Last updated: 4 July 2026
This statement describes Sulook's operating posture for privacy-conscious AI and workflow systems. Specific contractual, regulatory, or sector requirements should be addressed in the relevant client agreement or data processing terms. This statement is not legal advice.