Privacy Policy

Last Updated: August 2026

This policy explains what personal data we collect through sphinmedia.com, why we collect it, who we share it with, where it is processed, how long we keep it, and the rights you have over it. It is written to be plain and honest about what we do with your information. It sits alongside our Cookie and Consent Notice, which covers cookies in detail.

1. Who we are

Sphin Media is the studio brand operated by Assur Media, a UAE Free Zone Company registered under the Sharjah Research Technology and Innovation Park Free Zone Authority, Registration No. 9978. Assur Media is the contracting party, and all commercial and legal correspondence is issued under Assur Media.

In this policy, "we", "us", and "our" mean Assur Media, operating as Sphin Media. Assur Media is the controller of the personal data described here, which means we are the party that decides why and how your personal data is handled when you use sphinmedia.com.

Registered address Block B-B50-065, SRTIP, University City, Sharjah, United Arab Emirates, P.O. Box 66636
Privacy and data protection contact legal@assurmedia.com
General enquiries contact@sphinmedia.com
Pricing, packages, and new projects sales@sphinmedia.com
Something is not working: payments, files, or access support@sphinmedia.com
Cancelling an order, or requesting a refund support@sphinmedia.com
Invoices, receipts, and billing details admin@sphinmedia.com
Progress on work in hand designers@assurmedia.com

All privacy and data protection questions, requests, and complaints go to legal@assurmedia.com.

2. What this policy covers, and what it does not

This policy covers the personal data we collect when you visit sphinmedia.com, send us an enquiry, ask to talk, complete one of our forms, subscribe to our updates, or place an order.

This site is not a channel for patient or health data. We do not ask for, and you should not send us through this site, any patient records, medical information, or health data about identifiable people. Sphin Media does not collect, receive, store, or process patient or health data. If we ever receive such data by mistake, we will not use it, and we will return or securely delete it.

When we work for a client, we sometimes handle personal data on that client's behalf and on their instructions, for example audience or campaign data for a marketing project. That is a separate arrangement, governed by the data handling terms in the client's contract with us, and it is not covered by this policy.

3. The law that applies

Assur Media is established in the United Arab Emirates, so the main law that applies to how we handle your personal data is the United Arab Emirates Personal Data Protection Law (Federal Decree-Law No. 45 of 2021).

Where you are in Saudi Arabia or in Kuwait, the data protection rules of your own country may also apply to the personal data we hold about you. This policy is written to sit alongside those rules, and nothing in it removes a right you have under the law of your own country.

4. The personal data we collect through this site

What we collect depends on how you use the site.

What you do What we collect
Send an enquiry or ask to talk Your name, your business name, your email address, your WhatsApp or phone number, and what you tell us about what you need
Complete a scope or brief form The details of your brief, for example your sector, the package or project you are interested in, your goal in your own words, your timeline, your budget context where you give it, and whether you need a shoot
Share brand assets or account access with us The asset files and account details you choose to give us so that we can do the work. We do not ask for raw passwords
Place an order at checkout Your name, your billing and contact details, the items you order, and a record of the payment. The card payment itself is processed by Stripe or by PayPal
Subscribe to our email updates Your email address, your name where you give it, and a record of your consent, including when and how you gave it
Browse the site Your IP address, device and browser identifiers, the pages you view and the links you follow, the referring page, and server log data such as the date and time of your visit. Cookie and analytics data, where you have accepted the relevant cookies

We ask only for what we need in order to answer you, scope your work, take payment, and run the studio.

5. Why we collect it, and the lawful basis

An organisation needs a lawful basis for each use of personal data. The table below sets out the basis for each of our purposes.

Purpose Data used Lawful basis
Replying to your enquiry, and preparing a quote or a proposal Your contact details and what you tell us about your requirements Steps taken at your request before entering into a contract
Delivering a project or a retainer you have engaged us for Your contact details, your brief and project material, and the account access you give us Performance of our contract with you
Taking payment, issuing invoices, and managing your account Your name, billing and contact details, order details, and payment records Performance of our contract with you
Keeping tax and accounting records Invoice, payment, and contract records Compliance with a legal obligation
Sending email marketing, such as updates and offers Your email address, your name, and your consent record Your consent
Keeping the site secure and preventing abuse Your IP address, device and browser identifiers, and server log data Our legitimate interests in protecting the site and the people who use it
Measuring how the site is used Analytics data, page views, and cookie identifiers Our legitimate interests in understanding how the site is used. Analytics cookies are set only where you accept them
Improving our services and the way we scope and deliver work Enquiry, project, and analytics data, used in aggregate Our legitimate interests in improving what we offer
Answering a data protection request or a complaint Your contact details and the details of your request Compliance with a legal obligation

Where we rely on our legitimate interests, we weigh our interest against your interests and rights, and we do not use your data in a way that overrides them. You can object to that use, and section 15 explains how.

Where we rely on your consent, you can withdraw it at any time, and withdrawing it does not affect anything we did before you withdrew it.

6. Cookies and analytics

This site uses cookies and similar technologies. They fall into four categories: strictly necessary, functional, analytics, and marketing.

Strictly necessary cookies are on by default, because the site cannot work without them. Functional, analytics, and marketing cookies are not set unless you allow them in the consent banner. You can give, withhold, or change your choices at any time using the "Cookie preferences" link in the footer of every page, and you do not need to give a reason.

Your stored choice is refreshed every 6 months, after which the banner asks you again.

Analytics on this site are provided through Squarespace and Google Analytics. Advertising and conversion measurement are provided through Google Ads.

The full detail, including the cookies used and how long each one lasts, is in our Cookie and Consent Notice.

7. Who we share your data with

No personal data is sold. We share your personal data with the providers listed below only so far as they need it to provide their service to us. Beyond those providers, we share personal data only where we are required to do so by law, by a court, or by a regulator with authority over us, or where it is needed by our own professional advisers, such as our accountant or our lawyers, who are themselves under a duty of confidence.

Provider What we use it for
Squarespace Website hosting, forms, checkout, and cookie consent management
Stripe Card payment processing
PayPal Payment processing
Google Workspace Email and document storage
Google Analytics Website analytics
Google Ads Advertising and conversion measurement
Mailchimp Email marketing, where you have opted in
WhatsApp (Meta) Enquiries and client messaging
Notion Client content portal
Synology NAS and a separate company-owned backup device Encrypted file storage on company-owned equipment

The Notion client content portal holds personal information about you and your project, such as your contact details, your brief, and the material we produce for you. It is accessible only to you, your project manager, and Mohammed Elnahwy.

We use AI tools in our production work, for example for voice, music, image generation, and drafting. Client personal data is not entered into them.

8. Where your data is processed

We are based in the United Arab Emirates, and our team works from the United Arab Emirates and Kuwait. Personal data we hold ourselves is processed in those two countries.

Some of the providers listed in section 7 process personal data outside the United Arab Emirates. Squarespace, Stripe, PayPal, Google, Mailchimp, WhatsApp (Meta), and Notion are international services, and your personal data may be held and processed on their systems in other countries. We say so plainly, so that you know your data may cross a border when we use these tools.

Where a provider processes personal data outside the United Arab Emirates, the transfer is made on the basis of that provider's contractual data protection terms, which require the provider to protect the data and to use it only for the purposes we instruct.

9. How we protect your data

We take proportionate steps to protect the personal data we hold.

  • Encryption at rest is on by default for all client data held on our Synology NAS and on the separate company-owned backup device.

  • Access is limited to the people who need the data in order to do their work.

  • Multi-factor authentication is enabled on our key services, including email, document storage, and website administration.

  • A separate backup device holds a copy of client files, so that the failure of one device does not lose your material.

No system can be made completely secure, and we do not suggest otherwise. If something does go wrong, section 10 explains what we do.

10. Telling you about a personal data breach

We maintain a breach response process for identifying, containing, recording, and reviewing a personal data breach.

Where a breach is likely to result in a risk to your rights, we notify the relevant supervisory authority. Where the risk is high, we also notify you directly. In each case we do so without undue delay after becoming aware of the breach.

When we notify you, we tell you what happened, what data is affected, what we are doing about it, and what you can do.

11. Marketing, and your choices

If you contact us or start an order, we may follow up with you directly, one to one, about your enquiry. We do this only where you gave us your contact details and have not asked us to stop.

We send broader email marketing, such as updates and offers, only to people who have chosen to receive it. We manage this through Squarespace and, at times, Mailchimp, and we keep a record of your consent, including when and how you gave it.

You can opt out at any time, using the unsubscribe link in any marketing email or by writing to legal@assurmedia.com. We will stop, and we will not ask you for a reason. Opting out of marketing does not stop the messages we need to send you about a project or an order you have with us.

12. How long we keep your data

We keep personal data only for as long as we need it for the purpose we collected it for, or for as long as we are required to keep it.

Record How long we keep it
Enquiry and contact records 24 months from your last contact with us
Client project and contract records 10 years from the end of the engagement
Marketing consent records For as long as you remain subscribed, and for 24 months after that
Website analytics 26 months
Cookie consent records 24 months. Your stored choice is refreshed every 6 months

When a period ends, we delete the data or securely dispose of it.

13. Automated decision-making

We do not carry out automated decision-making that produces a legal effect for you, or that similarly significantly affects you. Decisions about your enquiry, your quote, and your project are made by people.

The analytics we use measure how the site is used. They are not used to make decisions about you as an individual.

14. Children and this site‍

This site is intended for a business audience and is not directed at children. We do not knowingly collect personal data from anyone under the age of 18 through this site, and we do not knowingly market to them.

If you believe that a person under the age of 18 has given us personal data, write to legal@assurmedia.com and we will delete it.

15. Your rights over your personal data

Depending on where you are and which law applies to you, you may have the right to:

  • ask us for a copy of the personal data we hold about you

  • ask us to correct data that is wrong or incomplete

  • ask us to delete data that we no longer need

  • ask us to restrict how we use your data, or object to a particular use

  • ask us to transfer your data to you, or to another provider, in a commonly used format

  • withdraw your consent, where our use of your data rests on your consent

  • ask us to stop sending you marketing

To make a request, write to legal@assurmedia.com and tell us what you would like us to do. We may need to check your identity before we act, so that we do not give your personal data to someone else.

We respond within 30 calendar days of receiving your request. Where a request is complex, or where you have made several requests together, we may extend that period once. If we do, we will tell you before the first 30 days are up, and we will explain why.

We do not charge you for making a request.

16. How to contact us, and how to complain

For any question or request about your personal data, write to legal@assurmedia.com. That address reaches the person responsible for data protection at Assur Media. You can also write to us at Block B-B50-065, SRTIP, University City, Sharjah, United Arab Emirates, P.O. Box 66636.

If you are not satisfied with how we have handled your personal data, or with how we have answered a request, tell us first at legal@assurmedia.com and we will try to put it right.

If we cannot resolve it with you, you have the right to complain to the data protection authority in your own country.

17. Governing law

This notice is governed by the law of the United Arab Emirates. If something goes wrong, please contact us first at legal@assurmedia.com and we will try to resolve it with you directly. If we cannot, the courts of the United Arab Emirates have jurisdiction. Nothing here removes a right you have to bring a claim in your own country where the law of that country gives you that right and it cannot be waived.

18. Changes to this policy

We may update this policy from time to time, for example when we add a provider, change a purpose, or respond to a change in the law.

When we do, we will change the "last updated" date at the foot of this page. Where a change is significant, we will make that clear on the site, and, where the law requires us to tell you directly, we will do so.

Last updated: August 2026

Sphin Media is the studio brand operated by Assur Media, a UAE Free Zone Company (Registration No. 9978). All commercial and legal correspondence is issued under Assur Media.