LEGAL
Privacy Policy
Last updated: 2 September 2026
Last updated: 2 September 2026
Who we are
Ishara is a deal-intelligence CRM operated by LISAN AI - FZE ("we", "us") as part of the Lisan platform. This privacy policy explains what personal data we process, where it comes from, why we process it, how long we keep it, and the rights available to individuals. Privacy questions go to support@lisan.com.
For account, website, support, and product-usage data, LISAN AI - FZE generally acts as the controller. For personal data a customer places in a workspace (CRM records, synced email, call recordings and transcripts), the customer generally decides why and how that data is used, and we process it to provide the service. If your details were added to a workspace by an Ishara customer, that customer may be the right first contact for a request about the record. For the public-source reference directories described below, we act as the controller.
Data we collect
- Account data. Your name, email address, and authentication details when you create an account or sign in.
- CRM records you enter. Companies, people, deals, and custom objects, along with notes, comments, files, and the fields your team fills in. Every stored value carries a provenance tag recording who or what wrote it: a user, an import, an automation, a formula, an AI suggestion, an enrichment, or the system.
- Connected mailboxes. If you connect a Gmail or Outlook account, you authorize it through the provider's own OAuth screen; we never see or store your mailbox password. Ishara syncs messages so threads appear on the records they concern, and stores sending data such as templates, scheduled sends, engagement events, and suppression lists kept per reason.
- Call recordings and transcripts. When someone in your workspace schedules a MeetriX bot into a meeting, the call is recorded and transcribed (in Arabic or English) with speaker labels, playback, and insights that cite the transcript. Who in the workspace can open each call is controlled per interaction.
- Public-source reference data. The investor directory and the government tender corpus, described in their own section below.
- Usage data. Application logs and diagnostic events (pages visited within the app, errors, timing) that help us keep the service running and improve it.
- Communications and commercial data. Messages you send to support, product enquiries, and subscription information. Payment providers process payment-card details; we do not store full card numbers.
Where the data comes from
We receive data directly from account holders and the teammates they invite; from imports you run (a whole Attio workspace in one click, a Pipedrive sync, or a CSV file); from mailboxes you connect; from calls your team schedules a bot into; from public sources for the reference directories; and from enrichment providers when you trigger enrichment (the built-in brand directory first, then Logo.dev, Brandfetch, or Apollo, under your workspace's write policy, which can route suggestions into a review queue instead of writing directly). Technical and usage data is generated when the service is used.
The reference directories
Ishara ships with reference data compiled from public sources, and we want to be plain about what that means for the people described in it.
The investor directory holds professional information about investors and investment firms: roles, firms, cheque sizes, stage and sector focus, track record, press, and similar career facts, compiled from publicly available sources. Every value is provenance-labelled so its origin is visible, and self-declared claims are kept separate from independently sourced facts rather than mixed into the same column. Photos are stored on our own infrastructure rather than hotlinked.
The tender corpus is drawn from official government procurement portals in the markets Ishara covers (Qatar end to end today, with other states as coverage lands). It mostly concerns companies and public bodies, though published bid tables can include the names of individuals acting for a company.
We process this reference data on the basis of our legitimate interest in providing market information that is already public, balanced against the interests of the people described. If you are listed in a directory and want a record corrected or removed, email support@lisan.com and we will act on it.
How we use your data
We process the data above to:
- provide the service: storing, displaying, and computing over your records, and matching synced email to the records it concerns;
- authenticate you and the people you invite;
- run features you explicitly trigger, such as AI research, enrichment, sends you compose, and call bots you schedule;
- enforce email suppression, so a recorded opt-out is honored on every future send of that kind;
- respond to support requests;
- monitor security, prevent abuse, and debug faults;
- improve the product based on aggregate usage patterns.
We do not use your workspace content for advertising, and we do not sell personal data.
Legal bases
Where a law such as the EU GDPR or UK GDPR requires a legal basis, we rely on the basis that fits the activity:
- Contract: to create accounts, provide requested product functions, administer subscriptions, and respond to service requests.
- Legitimate interests: to secure and improve the service, prevent abuse, diagnose faults, provide the public-source reference directories, and communicate about the product, balanced against the rights of affected individuals.
- Legal obligation: where records or disclosures are required by applicable law.
- Consent: where we specifically ask for it; consent can be withdrawn for future processing.
Where the Saudi Personal Data Protection Law (PDPL) or a similar regional law applies, the product's email rails are built to match its consent model: opt-outs are recorded by reason, a marketing opt-out is enforced separately from transactional messages such as sign-in codes and invitations, and suppression is checked before every send.
When we process workspace content for a customer, the customer is responsible for identifying its own lawful basis, for any notices owed to the people in its records, and for complying with the call-recording consent rules that apply where its meetings take place.
Service providers
We use a short list of providers to run Ishara: cloud infrastructure for hosting, Postgres databases, and file storage; email delivery for sign-in codes and notifications; MeetriX for meeting bots, recording, and transcription; AI model providers, routed per feature under your workspace's AI policy and used only for the features you or your workspace enable; and the enrichment providers named above, queried only when enrichment is triggered. Each provider is permitted to process data only for the services it supplies to us. The current list is available on request at support@lisan.com, and we will publish material changes before a new provider starts processing customer personal data. We may also disclose data when required by law, to protect the service and its users, or as part of a corporate transaction subject to appropriate safeguards.
International transfers
Depending on where you are, using Ishara can involve transferring personal data across borders between you, our infrastructure, and the providers above. Where a law such as the GDPR, UK GDPR, or the PDPL requires a transfer mechanism, we put appropriate safeguards in place and will document them in a data processing agreement on request via support@lisan.com.
Retention
We keep data while an account or workspace is active and for as long afterwards as reasonably needed to provide exports, resolve disputes, maintain security, meet contractual commitments, or comply with law. Deleting records in the app moves them into a trash with a retention window and a count-and-confirm step; destructive actions support undo, and changes are written to an audit trail so mistakes can be traced rather than silently lost. One deliberate exception: suppression records (who opted out of what) are kept even after other data about the person is deleted, because discarding an opt-out would cause the very messages the person refused.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing of personal data, receive portable data, or withdraw consent. These rights can be limited by law and by the rights of other people. Email support@lisan.com; we may need to verify your identity and, for customer-controlled workspace records, may refer the request to the workspace administrator. People listed in the reference directories can use the same address for corrections or removal.
You may also complain to the data-protection authority that applies where you live or work. We would appreciate the opportunity to address the concern first.
What we never do
We do not sell personal data, and we do not use workspace content for advertising. We disclose personal data only as described in this policy, on the instructions of the customer that controls a workspace, or where legally required.
Changes to this policy
If we make a material change, we will update the date at the top and provide additional notice where required. The current policy applies from the stated date; we do not treat silence as consent where consent is legally required.
Contact
Privacy questions, correction requests, or deletion requests: support@lisan.com. See also our Terms of Service and Security pages, or reach us via the contact page.