This Privacy Policy explains how Local Knowledge FZE handles personal data when you visit brandsolomo.com, contact us, or use the Brand SoLoMo platform and managed services. We process personal data in line with the UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021 (the “PDPL”), and other applicable laws. This policy should be read together with our Terms of Service.
1. Who we are
Brand SoLoMo is operated by Local Knowledge FZE, a company licensed in the United Arab Emirates (“we”, “us” or “our”). We provide a digital local management platform and managed services that help businesses and agencies manage business listings, reviews, posts and performance across platforms such as Google Business Profile and Apple Business Connect.
2. Controller and processor roles
- We are the controller for personal data we collect for our own purposes: website enquiries, account registration and login, billing, customer support, security and improving our Services.
- We are a processor for personal data we handle on behalf of our customers inside the platform, such as the names and content of people who leave reviews on a customer’s listings, and details of a customer’s staff and clients. Our customer is the controller of that data, and we process it only on their documented instructions and under our Terms of Service.
If you are a reviewer or a customer of one of our clients and want to exercise your rights, please contact the relevant business directly. We will support them in responding.
3. Data we collect
When you contact us through the website
First and last name, business email address, company name, country, how you intend to use Brand SoLoMo, how you heard about us, your message, and the plan you are interested in. We also record your IP address, browser type and the time of submission to prevent spam and abuse.
When you use the platform
- Account data: name, email address, role, company or agency, profile details you choose to add, and your password (stored only as a secure hash).
- Security and usage data: login times, IP addresses, device and browser information, failed login attempts, and an activity log of actions taken in the platform (for example, publishing a post or replying to a review).
- Business and listing data: business names, addresses, phone numbers, opening hours, categories, descriptions, photos, videos, posts and similar content for the locations you manage.
- Review data: reviews received on connected platforms, including the reviewer’s public display name, profile image, rating and review text, and the replies you publish.
- Performance data: aggregated statistics from connected platforms, such as profile views, searches, calls, direction requests and search terms. This is not linked to identifiable individuals.
- Connection data: secure access tokens that allow us to act on your connected Google, Apple and other platform accounts (see section 6).
- Communications: support tickets, emails, report recipients and notification preferences, and questions you ask our in-app assistant.
- Billing data: company billing contacts, invoicing details and payment records. We do not store full payment card numbers.
4. How we use data
- To respond to enquiries, prepare proposals and onboard new customers.
- To provide the Services: managing and publishing listings, posts, photos and review replies, producing analytics and scheduled reports, and sending alerts you have set up.
- To provide managed “Done For You” services on your behalf.
- To secure the Services: authentication, fraud and spam prevention, detecting misuse, and keeping audit logs.
- To provide support and service communications, such as password resets, invitations, sync failures and billing notices.
- To maintain and improve the Services, including fixing problems and understanding how features are used in aggregate.
- To comply with legal, tax and regulatory obligations, and to establish or defend legal claims.
We do not sell personal data, and we do not use it for third-party advertising.
5. Legal basis
Under the PDPL, we process personal data on one or more of the following grounds:
- Contract: to take steps at your request before entering into an agreement, and to perform our agreement with you.
- Legal obligation: where processing is required by UAE law, such as tax and record-keeping rules.
- Legitimate interests: to secure and improve our Services and to respond to business enquiries, where these interests are not overridden by your rights.
- Consent: where we ask for it, for example when you tick the consent box on our enquiry form. You can withdraw consent at any time without affecting processing that happened before.
6. Google and Apple account data
When you connect a Google account, we request access to Google Business Profile data so we can import and manage your locations, reviews, posts, media and performance insights on your behalf. When you connect Apple Business Connect, we access your brand and location data in the same way.
- We use this data only to provide and improve the user-facing features of Brand SoLoMo that you have chosen to use.
- We do not sell it, use it for advertising, or transfer it to others except as needed to provide the Services, to comply with law, or as part of a merger or acquisition with notice to you.
- People at Local Knowledge do not read this data unless you ask us to (for example, for support or managed services), it is needed for security, or it is required by law.
- Access tokens are stored encrypted, and you can revoke access at any time from your Google or Apple account settings or by disconnecting the platform in Brand SoLoMo.
Brand SoLoMo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7. AI processing
Some features use AI models to draft review replies, write posts, analyse review sentiment and topics, check photos before publishing, and answer questions in our in-app assistant. To do this, relevant content (for example, review text, business details or your question) is sent to AI providers acting as our processors.
- We use business-grade APIs from providers such as OpenAI, Google (Gemini), OpenRouter and DeepSeek. The provider in use can vary with the feature and your settings.
- We do not use your data to train publicly available AI models. We send only the content a feature needs, through paid business APIs, and choose settings that opt out of provider training where the provider offers that option.
- AI output is a suggestion. You control whether it is published, unless you turn on automatic publishing.
9. International transfers
Our infrastructure providers operate data centres outside the UAE, currently in the United States (application hosting) and the European Union (file storage and backups). Connected platforms and AI providers may also process data in other countries.
When we transfer personal data outside the UAE, we do so in line with the PDPL, relying on adequate protection in the destination country or appropriate safeguards such as contractual data protection commitments with our providers.
10. How long we keep data
- Website enquiries: up to 24 months after our last contact, unless you become a customer.
- Account and platform data: for as long as your account is active, and for up to 30 days after termination so you can request an export, after which it is deleted or anonymised.
- In-app assistant conversations: up to 90 days.
- Database backups: kept on a rolling basis and overwritten automatically, typically within a few weeks.
- Billing and tax records: for the period required by UAE law.
- Security logs: for as long as needed to protect the Services and investigate incidents.
Content already published on connected platforms, such as a listing or review reply, stays there under the control of that platform and your account.
11. Security
We use appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS/TLS), encryption of stored access tokens and backups, role-based access controls, login protection against repeated failed attempts, activity logging, and regular automated backups. Access by our team is limited to people who need it to provide the Services.
No system is completely secure. If we become aware of a personal data breach that affects you, we will notify you and the relevant authority as required by the PDPL.
13. Your rights
Subject to the conditions in the PDPL, you have the right to:
- be informed about how your personal data is processed;
- access a copy of your personal data;
- have inaccurate data corrected or completed;
- have your data erased where it is no longer needed or processed unlawfully;
- restrict or object to certain processing, including direct marketing;
- receive your data in a structured, commonly used format and have it transferred (data portability); and
- withdraw consent at any time where processing is based on consent.
To make a request, email us at the address in section 17. We may need to verify your identity, and we will respond within the time required by law. You can update most account details yourself in the platform.
14. Marketing communications
If you contact us or become a customer, we may send you relevant updates about Brand SoLoMo. Every marketing email includes a way to unsubscribe, and you can opt out at any time by contacting us. Service messages, such as security or billing notices, are not marketing and will still be sent.
15. Children
Our Services are designed for businesses and are not intended for anyone under 18. We do not knowingly collect personal data from children.
16. Changes to this policy
We may update this policy from time to time. We will post the new version on this page and change the “Last updated” date. If changes are significant, we will notify customers by email or in the platform before they take effect.
17. Contact and complaints
For privacy questions or to exercise your rights, contact:
Local Knowledge FZE (Brand SoLoMo)
United Arab Emirates
Email: [email protected]
If you are not satisfied with our response, you may lodge a complaint with the UAE Data Office or another competent data protection authority.