Who We Serve

    Your sector. Your AI risks. Mapped to your applicable law.

    Generic compliance content gets ignored because it does not speak to your business. Find your industry below and see exactly where AI exposes you today - the specific tools, the specific laws, and what the audit puts in place to close each gap.

    Marketing Agency

    You move fast on AI - and you hold other companies' data while doing it.

    Client data pasted into ChatGPT, Jasper or Copilot without a DPAPDPPL Art. 7
    AI-generated or edited images of real, identifiable peopleLaw No.11/2025 Art.8(bis)
    No documented AI usage policy across a fast-moving creative teamPDPPL / NCSA
    Third-party data processed on behalf of clients with no safeguardsPDPPL / QFC DPR

    The audit delivers: An Approved Tool List and a Client-Facing AI Data Statement so you can win work - not lose it - on governance.

    Restaurant & F&B

    Loyalty, reservations and marketing now run through AI tools you never vetted.

    Customer contact lists loaded into AI marketing toolsPDPPL Art. 7
    Loyalty and reservation data shared with un-vetted vendorsPDPPL / Consumer Protection Law
    AI-driven promotions that mislead or misuse customer dataConsumer Protection Law No.8/2008

    The audit delivers: A practical tool register and data-handling guidelines your floor and marketing staff can actually follow.

    Medical Clinic

    Health data is the highest-sensitivity category under applicable GCC law.

    Patient health data in AI = maximum PDPPL exposure + DPIA strongly recommendedPDPPL (special-nature data)
    AI transcription or scribe tools with no Data Processing AgreementQFC DPR Art.12 / PDPPL
    AI-assisted diagnosis or imaging without documented human oversightPDPPL / NCSA

    The audit delivers: A Data Protection Impact Assessment framework and vendor DPAs that bring your AI tooling within legal bounds.

    Real Estate

    You handle identity and financial documents on every single deal.

    Buyer and tenant IDs and financial data entered into AI toolsPDPPL Art. 7
    AI-staged or AI-edited listing images featuring real, identifiable peopleLaw No.11/2025 Art.8(bis) / IP Law No.7/2021
    Cross-border transfer of client data to overseas AI vendors without safeguardsPDPPL transfer rules

    The audit delivers: A risk-ranked map of where personal and financial data flows - and how to close each gap.

    Professional Services

    Confidentiality is your product. AI quietly puts it at risk.

    Confidential client files pasted into public AI modelsPDPPL / professional duty of confidentiality
    No AI usage policy - undocumented, ungoverned decisionsPDPPL / NCSA
    Employee use of AI on sensitive client matters with no oversight or loggingLabour Law No.14/2004 / PDPPL

    The audit delivers: An AI Usage Policy and Employee Responsibility Agreement that protect client confidentiality and create a documented governance chain.

    Hotel & Hospitality

    Guest passports, payments and preferences flow through your systems daily.

    Guest passport and payment data processed through AI systems - high PDPPL exposurePDPPL (special-nature data)
    Cross-border data transfers to AI vendors without documented safeguardsPDPPL transfer rules
    AI concierge or chat tools collecting guest data with no privacy noticeE-Commerce Law No.16/2010 / PDPPL

    The audit delivers: A vendor risk assessment and incident response plan sized for a 24/7 operation.

    IT Consulting

    Your clients trust you with their data. AI quietly puts that trust at legal risk.

    Confidential client data pasted into ChatGPT or Copilot without a DPAPDPPL Art. 7
    No AI usage policy across development and delivery teamsPDPPL / NCSA
    Cross-border transfers via GitHub Copilot, ChatGPT or Claude to US serversPDPPL transfer rules
    AI-assisted decisions with no human oversight or audit trailPDPPL / NCSA

    The audit delivers: An AI Usage Policy and Client-Facing AI Data Statement - so when your clients ask how you handle their data with AI, you have a written answer ready.

    The next move is yours

    Most businesses using AI are not compliant. Most never know until it's too late.

    Free - receive your personalised risk feedback in under 48 hours. The cost of finding out later: everything.

    Not sure which you need?