Privacy Policy
Last Updated: August 2026
This policy explains what personal data we collect through sphinmedia.com, why we collect it, who we share it with, where it is processed, how long we keep it, and the rights you have over it. It is written to be plain and honest about what we do with your information. It sits alongside our Cookie and Consent Notice, which covers cookies in detail.
Table of Content
1. Who we are
Sphin Media is the studio brand operated by Assur Media, a UAE Free Zone Company registered under the Sharjah Research Technology and Innovation Park Free Zone Authority, Registration No. 9978. Assur Media is the contracting party, and all commercial and legal correspondence is issued under Assur Media.
In this policy, "we", "us", and "our" mean Assur Media, operating as Sphin Media. Assur Media is the controller of the personal data described here, which means we are the party that decides why and how your personal data is handled when you use sphinmedia.com.
| Registered address | Block B-B50-065, SRTIP, University City, Sharjah, United Arab Emirates, P.O. Box 66636 |
|---|---|
| Privacy and data protection contact | legal@assurmedia.com |
| General enquiries | contact@sphinmedia.com |
| Pricing, packages, and new projects | sales@sphinmedia.com |
| Something is not working: payments, files, or access | support@sphinmedia.com |
| Cancelling an order, or requesting a refund | support@sphinmedia.com |
| Invoices, receipts, and billing details | admin@sphinmedia.com |
| Progress on work in hand | designers@assurmedia.com |
All privacy and data protection questions, requests, and complaints go to legal@assurmedia.com.
2. What this policy covers, and what it does not
This policy covers the personal data we collect when you visit sphinmedia.com, send us an enquiry, ask to talk, complete one of our forms, subscribe to our updates, or place an order.
This site is not a channel for patient or health data. We do not ask for, and you should not send us through this site, any patient records, medical information, or health data about identifiable people. Sphin Media does not collect, receive, store, or process patient or health data. If we ever receive such data by mistake, we will not use it, and we will return or securely delete it.
When we work for a client, we sometimes handle personal data on that client's behalf and on their instructions, for example audience or campaign data for a marketing project. That is a separate arrangement, governed by the data handling terms in the client's contract with us, and it is not covered by this policy.
3. The law that applies
Assur Media is established in the United Arab Emirates, so the main law that applies to how we handle your personal data is the United Arab Emirates Personal Data Protection Law (Federal Decree-Law No. 45 of 2021).
Where you are in Saudi Arabia or in Kuwait, the data protection rules of your own country may also apply to the personal data we hold about you. This policy is written to sit alongside those rules, and nothing in it removes a right you have under the law of your own country.
4. The personal data we collect through this site
What we collect depends on how you use the site.
| What you do | What we collect |
|---|---|
| Send an enquiry or ask to talk | Your name, your business name, your email address, your WhatsApp or phone number, and what you tell us about what you need |
| Complete a scope or brief form | The details of your brief, for example your sector, the package or project you are interested in, your goal in your own words, your timeline, your budget context where you give it, and whether you need a shoot |
| Share brand assets or account access with us | The asset files and account details you choose to give us so that we can do the work. We do not ask for raw passwords |
| Place an order at checkout | Your name, your billing and contact details, the items you order, and a record of the payment. The card payment itself is processed by Stripe or by PayPal |
| Subscribe to our email updates | Your email address, your name where you give it, and a record of your consent, including when and how you gave it |
| Browse the site | Your IP address, device and browser identifiers, the pages you view and the links you follow, the referring page, and server log data such as the date and time of your visit. Cookie and analytics data, where you have accepted the relevant cookies |
We ask only for what we need in order to answer you, scope your work, take payment, and run the studio.
5. Why we collect it, and the lawful basis
An organisation needs a lawful basis for each use of personal data. The table below sets out the basis for each of our purposes.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Replying to your enquiry, and preparing a quote or a proposal | Your contact details and what you tell us about your requirements | Steps taken at your request before entering into a contract |
| Delivering a project or a retainer you have engaged us for | Your contact details, your brief and project material, and the account access you give us | Performance of our contract with you |
| Taking payment, issuing invoices, and managing your account | Your name, billing and contact details, order details, and payment records | Performance of our contract with you |
| Keeping tax and accounting records | Invoice, payment, and contract records | Compliance with a legal obligation |
| Sending email marketing, such as updates and offers | Your email address, your name, and your consent record | Your consent |
| Keeping the site secure and preventing abuse | Your IP address, device and browser identifiers, and server log data | Our legitimate interests in protecting the site and the people who use it |
| Measuring how the site is used | Analytics data, page views, and cookie identifiers | Our legitimate interests in understanding how the site is used. Analytics cookies are set only where you accept them |
| Improving our services and the way we scope and deliver work | Enquiry, project, and analytics data, used in aggregate | Our legitimate interests in improving what we offer |
| Answering a data protection request or a complaint | Your contact details and the details of your request | Compliance with a legal obligation |
Where we rely on our legitimate interests, we weigh our interest against your interests and rights, and we do not use your data in a way that overrides them. You can object to that use, and section 15 explains how.
Where we rely on your consent, you can withdraw it at any time, and withdrawing it does not affect anything we did before you withdrew it.
6. Cookies and analytics
This site uses cookies and similar technologies. They fall into four categories: strictly necessary, functional, analytics, and marketing.
Strictly necessary cookies are on by default, because the site cannot work without them. Functional, analytics, and marketing cookies are not set unless you allow them in the consent banner. You can give, withhold, or change your choices at any time using the "Cookie preferences" link in the footer of every page, and you do not need to give a reason.
Your stored choice is refreshed every 6 months, after which the banner asks you again.
Analytics on this site are provided through Squarespace and Google Analytics. Advertising and conversion measurement are provided through Google Ads.
The full detail, including the cookies used and how long each one lasts, is in our Cookie and Consent Notice.
7. Who we share your data with
No personal data is sold. We share your personal data with the providers listed below only so far as they need it to provide their service to us. Beyond those providers, we share personal data only where we are required to do so by law, by a court, or by a regulator with authority over us, or where it is needed by our own professional advisers, such as our accountant or our lawyers, who are themselves under a duty of confidence.
| Provider | What we use it for |
|---|---|
| Squarespace | Website hosting, forms, checkout, and cookie consent management |
| Stripe | Card payment processing |
| PayPal | Payment processing |
| Google Workspace | Email and document storage |
| Google Analytics | Website analytics |
| Google Ads | Advertising and conversion measurement |
| Mailchimp | Email marketing, where you have opted in |
| WhatsApp (Meta) | Enquiries and client messaging |
| Notion | Client content portal |
| Synology NAS and a separate company-owned backup device | Encrypted file storage on company-owned equipment |
The Notion client content portal holds personal information about you and your project, such as your contact details, your brief, and the material we produce for you. It is accessible only to you, your project manager, and Mohammed Elnahwy.
We use AI tools in our production work, for example for voice, music, image generation, and drafting. Client personal data is not entered into them.
8. Where your data is processed
We are based in the United Arab Emirates, and our team works from the United Arab Emirates and Kuwait. Personal data we hold ourselves is processed in those two countries.
Some of the providers listed in section 7 process personal data outside the United Arab Emirates. Squarespace, Stripe, PayPal, Google, Mailchimp, WhatsApp (Meta), and Notion are international services, and your personal data may be held and processed on their systems in other countries. We say so plainly, so that you know your data may cross a border when we use these tools.
Where a provider processes personal data outside the United Arab Emirates, the transfer is made on the basis of that provider's contractual data protection terms, which require the provider to protect the data and to use it only for the purposes we instruct.
9. How we protect your data
We take proportionate steps to protect the personal data we hold.
Encryption at rest is on by default for all client data held on our Synology NAS and on the separate company-owned backup device.
Access is limited to the people who need the data in order to do their work.
Multi-factor authentication is enabled on our key services, including email, document storage, and website administration.
A separate backup device holds a copy of client files, so that the failure of one device does not lose your material.
No system can be made completely secure, and we do not suggest otherwise. If something does go wrong, section 10 explains what we do.
10. Telling you about a personal data breach
We maintain a breach response process for identifying, containing, recording, and reviewing a personal data breach.
Where a breach is likely to result in a risk to your rights, we notify the relevant supervisory authority. Where the risk is high, we also notify you directly. In each case we do so without undue delay after becoming aware of the breach.
When we notify you, we tell you what happened, what data is affected, what we are doing about it, and what you can do.
11. Marketing, and your choices
If you contact us or start an order, we may follow up with you directly, one to one, about your enquiry. We do this only where you gave us your contact details and have not asked us to stop.
We send broader email marketing, such as updates and offers, only to people who have chosen to receive it. We manage this through Squarespace and, at times, Mailchimp, and we keep a record of your consent, including when and how you gave it.
You can opt out at any time, using the unsubscribe link in any marketing email or by writing to legal@assurmedia.com. We will stop, and we will not ask you for a reason. Opting out of marketing does not stop the messages we need to send you about a project or an order you have with us.
12. How long we keep your data
We keep personal data only for as long as we need it for the purpose we collected it for, or for as long as we are required to keep it.
| Record | How long we keep it |
|---|---|
| Enquiry and contact records | 24 months from your last contact with us |
| Client project and contract records | 10 years from the end of the engagement |
| Marketing consent records | For as long as you remain subscribed, and for 24 months after that |
| Website analytics | 26 months |
| Cookie consent records | 24 months. Your stored choice is refreshed every 6 months |
When a period ends, we delete the data or securely dispose of it.
13. Automated decision-making
We do not carry out automated decision-making that produces a legal effect for you, or that similarly significantly affects you. Decisions about your enquiry, your quote, and your project are made by people.
The analytics we use measure how the site is used. They are not used to make decisions about you as an individual.
14. Children and this site
This site is intended for a business audience and is not directed at children. We do not knowingly collect personal data from anyone under the age of 18 through this site, and we do not knowingly market to them.
If you believe that a person under the age of 18 has given us personal data, write to legal@assurmedia.com and we will delete it.
15. Your rights over your personal data
Depending on where you are and which law applies to you, you may have the right to:
ask us for a copy of the personal data we hold about you
ask us to correct data that is wrong or incomplete
ask us to delete data that we no longer need
ask us to restrict how we use your data, or object to a particular use
ask us to transfer your data to you, or to another provider, in a commonly used format
withdraw your consent, where our use of your data rests on your consent
ask us to stop sending you marketing
To make a request, write to legal@assurmedia.com and tell us what you would like us to do. We may need to check your identity before we act, so that we do not give your personal data to someone else.
We respond within 30 calendar days of receiving your request. Where a request is complex, or where you have made several requests together, we may extend that period once. If we do, we will tell you before the first 30 days are up, and we will explain why.
We do not charge you for making a request.
16. How to contact us, and how to complain
For any question or request about your personal data, write to legal@assurmedia.com. That address reaches the person responsible for data protection at Assur Media. You can also write to us at Block B-B50-065, SRTIP, University City, Sharjah, United Arab Emirates, P.O. Box 66636.
If you are not satisfied with how we have handled your personal data, or with how we have answered a request, tell us first at legal@assurmedia.com and we will try to put it right.
If we cannot resolve it with you, you have the right to complain to the data protection authority in your own country.
17. Governing law
This notice is governed by the law of the United Arab Emirates. If something goes wrong, please contact us first at legal@assurmedia.com and we will try to resolve it with you directly. If we cannot, the courts of the United Arab Emirates have jurisdiction. Nothing here removes a right you have to bring a claim in your own country where the law of that country gives you that right and it cannot be waived.
18. Changes to this policy
We may update this policy from time to time, for example when we add a provider, change a purpose, or respond to a change in the law.
When we do, we will change the "last updated" date at the foot of this page. Where a change is significant, we will make that clear on the site, and, where the law requires us to tell you directly, we will do so.
Last updated: August 2026
Sphin Media is the studio brand operated by Assur Media, a UAE Free Zone Company (Registration No. 9978). All commercial and legal correspondence is issued under Assur Media.

