Bishop
← Legal

Privacy Policy

AIMES LAB FOR COMPUTER SYSTEMS & COMMUNICATION EQUIPMENT SOFTWARE DESIGN CO. L.L.C. Product: Bishop (https://bishop.aimestech.com)

Effective Date: 16 August 2026 Last Updated: 16 August 2026

1. Introduction

AIMES LAB FOR COMPUTER SYSTEMS & COMMUNICATION EQUIPMENT SOFTWARE DESIGN CO. L.L.C. (commercial license no. 1389208, issued by the Dubai Department of Economy and Tourism, United Arab Emirates) (“AIMES,” “Company,” “we,” “us,” or “our”) provides Bishop, an AI-assisted decision-support platform for financial analysis and modelling made available at https://bishop.aimestech.com (together with related websites, applications and support services, the “Services”).

This Privacy Policy explains how AIMES collects, uses, discloses, stores, and protects personal data in connection with the Services, and describes the rights available to individuals in the European Union/European Economic Area (“EU/EEA”) and United Kingdom, the United States, the United Arab Emirates, and other Middle Eastern jurisdictions where the Services are offered. It is written to comply with:

  • Regulation (EU) 2016/679 (the “GDPR”) and the UK GDPR/Data Protection Act 2018;
  • The UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, as implemented by its Executive Regulation (Cabinet Decision) in force since 2024 (“UAE PDPL”) (UAE Legislation);
  • Applicable comprehensive U.S. state privacy statutes, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”) and equivalent laws in Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws in force (20 U.S. states as of 2026) (Clym, 2026 State Privacy Law Guide); and
  • Regulation (EU) 2024/1689 (the “EU AI Act”) transparency requirements applicable to AI systems, to the extent relevant to the Services (EUR-Lex 32024R1689).

Bishop is a professional, business-to-business tool. It is intended solely for use by qualified professionals and entities in the course of their trade, business, or profession, and is not directed at, or intended for use by, consumers, retail customers, or individuals acting outside of a professional capacity. By using the Services, you confirm that you are accessing them in a professional capacity and agree to the terms of this Privacy Policy.

2. Who Is Responsible for Your Data (Controller/Processor Roles)

For account, billing, and administrative data relating to our business customers and their authorized users, AIMES acts as the data controller (or, under the UAE PDPL, the “Data Controller”).

For data that customers and their authorized users input into Bishop for modelling and analysis purposes (“Customer Content”), AIMES acts as a data processor/service provider on behalf of the business customer, who remains the controller of any personal data contained in that Customer Content. Customers are responsible for ensuring they have a lawful basis to submit personal data to Bishop and for complying with their own notice and consent obligations toward the individuals whose data they input.

Data Protection Contact: support@aimestech.com (Attn: Data Protection). EU/EEA and UK data subjects, and business customers seeking a Data Processing Agreement (including EU Standard Contractual Clauses), may also use this address.

3. Data We Collect

Account & Identity Data. Name, business email, job title, employer, phone number, physical address, billing/payment details. Source: provided directly by you or your organization.

Customer Content. Financial models, scenario data, datasets, assumptions, and other content you input into Bishop to obtain decision-support outputs (“Your Stuff”). Source: provided directly by you.

Usage Data. Feature usage, session logs, actions taken in-account, query and prompt metadata. Source: automatically collected.

Device & Technical Data. IP address, browser/device type, operating system, referring page, unique device identifiers, approximate location derived from IP. Source: automatically collected.

Cookies & Similar Technologies. Session and functional cookies, analytics identifiers, pixel tags. Source: automatically collected (see Section 9).

Employment-Related Data (AIMES personnel only). Residency status, Emirates ID, banking details, performance records. Source: provided directly by AIMES employees/contractors.

Communications Data. Support tickets, correspondence, marketing preferences. Source: provided directly by you.

AIMES does not knowingly collect special/sensitive categories of personal data (e.g., health, biometric, or genetic data) through Bishop, and customers must not submit such data through the Services unless expressly agreed in writing.

4. Use of Artificial Intelligence and Sub-Processors

Bishop uses third-party large language model (“LLM”) services provided by OpenAI (OpenAI, L.L.C. in the United States and, for EEA/UK/Swiss customers, OpenAI Ireland Limited) to power certain natural-language and analytical features (“AI Sub-Processor”). When you submit prompts, data, or Customer Content to features that rely on the AI Sub-Processor:

  • Data may be transmitted to and processed by OpenAI’s API infrastructure, which may process data in the United States or, where AIMES has enabled OpenAI’s EU data residency option, within the EU/EEA (OpenAI, Introducing Data Residency in Europe);
  • Such processing is governed by OpenAI’s Data Processing Addendum and, where applicable, the EU Standard Contractual Clauses (OpenAI DPA);
  • Consistent with OpenAI’s API terms, data submitted via the API is not used by OpenAI to train its models and is retained only as required for abuse monitoring and legal compliance, subject to OpenAI’s then-current policies;
  • AI-generated outputs are probabilistic and may be incomplete, outdated, or inaccurate — see the Bishop Disclaimer for further detail.

AI transparency notice (EU AI Act Article 50): Where you interact with Bishop features that are powered by an AI system, AIMES will make this reasonably clear in the product interface, consistent with Article 50 of the EU AI Act (artificialintelligenceact.eu). Bishop does not use AI to make solely automated decisions producing legal or similarly significant effects concerning natural persons without human involvement; Bishop outputs are decision-support only and require review by a qualified human user before being acted upon (see Section 12).

5. Purposes and Legal Bases for Processing

Providing and operating the Services (account creation, hosting Your Stuff, generating outputs) — Legal basis: performance of a contract.

Billing and account administration (invoicing, payment processing) — Legal basis: performance of a contract; legal obligation.

Security, fraud and abuse prevention (monitoring for anomalous activity, authentication) — Legal basis: legitimate interests; legal obligation.

Product improvement and support (troubleshooting, analytics on aggregated/de-identified usage) — Legal basis: legitimate interests.

Legal and regulatory compliance (responding to lawful requests, AML/CTF and sanctions screening, audit) — Legal basis: legal obligation.

Marketing communications (product updates, newsletters) — Legal basis: consent (EU/EEA, UK, UAE) or legitimate interests with opt-out (other regions), always subject to opt-out.

Where AIMES relies on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

6. Data Sharing and Disclosure

AIMES does not sell personal data, and does not “share” personal data for cross-context behavioral advertising as defined under the CCPA/CPRA. We may disclose personal data to:

  • Sub-processors and service providers, including cloud hosting providers, the AI Sub-Processor (OpenAI), customer support tooling, analytics, and payment processors, each bound by a data processing agreement requiring confidentiality and appropriate security;
  • AIMES group entities and affiliates, for legitimate internal business administration purposes;
  • Other authorized users within your organization’s Bishop workspace, to the extent needed for collaboration features you enable;
  • Professional advisers and auditors, including independent auditors and the relevant UAE regulatory authority where an audit is mandated;
  • Government or regulatory authorities, where required to comply with a legal obligation, court order, or lawful request, or to prevent fraud, money laundering, or harm;
  • A successor entity, in connection with a merger, acquisition, financing, or sale of assets, subject to this Privacy Policy (or a materially similar policy) continuing to apply.

A current list of sub-processors, including the AI Sub-Processor, is available on request at support@aimestech.com. Business customers with a Data Processing Agreement will receive advance notice of any new sub-processor and a reasonable opportunity to object.

7. International Data Transfers

Bishop’s production infrastructure and databases are hosted in data centers located in Finland, within the European Union/European Economic Area. Personal data may nonetheless be transferred to and processed in other countries, including the United States (via the AI Sub-Processor) and the United Arab Emirates (where AIMES is headquartered), in the following circumstances:

  • Transfers from the EU/EEA and UK: AIMES relies on the European Commission’s Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) or another valid transfer mechanism recognized under Chapter V GDPR for transfers outside the EU/EEA, including to the UAE and, via the AI Sub-Processor, to the United States (European Commission SCCs). Where the UK GDPR applies, the UK International Data Transfer Addendum is incorporated.
  • Transfers from the UAE: conducted in accordance with the cross-border transfer provisions of the UAE PDPL and its Executive Regulation, which permit transfer where the recipient jurisdiction ensures an adequate level of protection, appropriate safeguards are in place (such as standard contractual clauses), or a statutory derogation applies.
  • Transfers from U.S. states: made consistent with applicable state law requirements for service provider/processor agreements.

You may request a copy of the relevant safeguard (e.g., the executed SCCs) by contacting support@aimestech.com.

8. Data Security and Retention

AIMES maintains administrative, technical, and organizational measures designed to protect personal data, including encryption of data at rest and in transit, access controls and authentication, network segmentation, and continuous monitoring for abuse and vulnerabilities.

We retain Customer Content and account data for as long as your account remains active or as needed to provide the Services. Upon account closure, we will initiate deletion of your data within 30 days, subject to:

  • Backup and disaster-recovery systems purging data on a rolling schedule thereafter;
  • Retention required to comply with legal, tax, AML/CTF, or regulatory obligations (typically up to the statutory limitation period applicable in the UAE, EU member state, or U.S. state concerned);
  • Retention necessary to establish, exercise, or defend legal claims.

In the event of a personal data breach, AIMES will notify affected business customers without undue delay and, where legally required, will notify the competent supervisory authority (for the EU/EEA, this includes the Finnish Office of the Data Protection Ombudsman where relevant, or the supervisory authority of the customer’s establishment) within the timeframe required by applicable law (72 hours under GDPR Art. 33) and will notify affected individuals where required under the UAE PDPL, applicable U.S. state law, or GDPR Art. 34.

9. Cookies and Similar Technologies

Bishop uses strictly necessary cookies (e.g., session authentication) and, where permitted, functional and analytics cookies to improve the Services. You can control non-essential cookies through your browser settings or an in-product cookie preference tool where offered. EU/EEA and UK visitors will be presented with a cookie consent mechanism compliant with the ePrivacy Directive/GDPR before non-essential cookies are set.

10. Your Privacy Rights

EU/EEA, UK and Switzerland (GDPR/UK GDPR)

Subject to legal conditions and exemptions, you have the right to: access your personal data; rectify inaccurate data; request erasure; restrict or object to processing (including profiling); request data portability; and withdraw consent. You also have the right to lodge a complaint with your local supervisory authority, or with the Finnish Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) where AIMES’s processing infrastructure is located (tietosuoja.fi).

United States

Depending on your state of residence, you may have rights under the CCPA/CPRA (California), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, and comparable laws in other states with comprehensive privacy statutes in effect, including states whose laws took effect in 2026. These commonly include the right to: know/access; delete; correct; obtain a portable copy; opt out of the sale or “sharing” of personal data and of targeted advertising; opt out of profiling that produces legal or similarly significant effects; and not be discriminated against for exercising these rights. AIMES does not sell personal data and does not use personal data for cross-context behavioral advertising.

United Arab Emirates and Middle East

Under the UAE PDPL, you have the right to: obtain confirmation of and access to your data; request correction or erasure; object to and restrict processing; data portability; and withdraw consent for processing based on consent. Requests may be submitted to support@aimestech.com. Where you are located in another Middle Eastern jurisdiction with an applicable data protection law (e.g., Saudi Arabia’s Personal Data Protection Law, Qatar, or a UAE financial free zone such as the DIFC or ADGM), AIMES will honor equivalent rights to the extent required by that law.

To exercise any of the above rights, contact support@aimestech.com. We will respond within the timeframe required by the applicable law (e.g., 30 days under GDPR/UAE PDPL, subject to a permitted extension; 45 calendar days under CCPA/CPRA, subject to a permitted extension).

11. Automated Decision-Making and AI-Generated Outputs

Bishop is designed as a decision-support tool, not a decision-making tool. Outputs generated by Bishop (including any AI-assisted analysis) are intended to be reviewed and validated by a qualified human professional before being relied upon. AIMES does not use Bishop to make decisions producing legal or similarly significant effects about individuals based solely on automated processing without meaningful human review. If your organization configures Bishop to inform decisions that could have such effects (for example, creditworthiness assessments of natural persons), your organization is responsible, as data controller and/or “deployer” under the EU AI Act, for ensuring adequate human oversight, transparency to affected individuals, and compliance with Article 22 GDPR and applicable AI regulation.

12. Eligibility

The Services are intended for use by professionals acting in a business capacity and are not directed at children. AIMES does not knowingly collect personal data from individuals under the age of 18, or the applicable age of majority/digital consent in the relevant jurisdiction, and any such data will be deleted upon discovery.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Material changes will be notified via email or an in-product notice at least 30 days before taking effect, except where a shorter period is required by law. Continued use of the Services after the effective date constitutes acceptance of the revised policy.

14. Contact

AIMES LAB FOR COMPUTER SYSTEMS & COMMUNICATION EQUIPMENT SOFTWARE DESIGN CO. L.L.C. Dubai, United Arab Emirates (License No. 1389208) Email: support@aimestech.com Product: https://bishop.aimestech.com

Regulatory References

  • Regulation (EU) 2016/679 (GDPR)
  • UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data — https://uaelegislation.gov.ae/en/legislations/1972/download
  • Regulation (EU) 2024/1689 (EU AI Act) — https://eur-lex.europa.eu/legal-content/EN-FR/TXT/?from=EN&uri=CELEX:32024R1689
  • EU AI Act, Article 50 (transparency obligations) — https://artificialintelligenceact.eu/article/50/
  • European Commission Standard Contractual Clauses (Implementing Decision (EU) 2021/914) — https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en
  • Office of the Data Protection Ombudsman, Finland — https://tietosuoja.fi/en/home
  • U.S. State Comprehensive Privacy Laws overview (2026) — https://www.clym.io/blog/us-privacy-law-comparison-map
  • OpenAI Data Processing Addendum — https://openai.com/policies/data-processing-addendum/
  • OpenAI, Introducing Data Residency in Europe — https://openai.com/index/introducing-data-residency-in-europe/