Privacy Policy

Effective August 6, 2026Last updated August 6, 2026Outworx for Web-Design, trading as Underlayer

This Privacy Policy applies to underlayer.outworx.io, the Underlayer dashboard, the Underlayer REST API, and every embeddable component we ship (player, catalog, builder). It's written for two audiences at once — the businesses that run their training through Underlayer, and the Learners who end up completing a course inside someone else's product — because both show up in the data this Policy describes.

1. Who we are

"Underlayer" is a brand name used by Outworx for Web-Design, a sole establishment licensed in the Emirate of Dubai, United Arab Emirates under E-Trader (Professional) License No. 1556815, Commercial Register No. 1348414, issued by the Dubai Department of Economy and Tourism ("DET"). Outworx for Web-Design is the controller responsible for the personal data described in this Policy, and "Underlayer", "we", "us" and "our" refer to it throughout.

This Privacy Policy explains what personal data we collect through underlayer.outworx.io and the Underlayer API, embeddable components, and dashboard (together, the "Services"), why we collect it, and the rights available to you under applicable law — principally UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL") and its implementing regulations and decisions, as issued and in force from time to time.

Because Underlayer is used by teams outside the UAE and processes data about end users located in the EU, UK, and elsewhere, this Policy also describes how we honor rights available under the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act ("CCPA") where those laws apply, even though our primary legal basis and governing framework is UAE law.

2. Definitions

  • "Customer" — the business or individual that registers an Underlayer workspace and controls what content is generated and who it's shown to.
  • "Authorized User" — an employee or contractor of a Customer who accesses the Underlayer dashboard or API on the Customer's behalf.
  • "Learner" / "Identity" — an end user of a Customer's product who is provisioned an identity through the Underlayer Identities API in order to view, complete, and be tracked against courses.
  • "Personal Data" — any information relating to an identified or identifiable natural person, as defined in Article 1 of the PDPL.
  • "Processing" — any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
  • "Controller" and "Processor" carry the meanings given to them in the PDPL and, where applicable, the GDPR.

3. Our role: controller and processor

Underlayer wears two hats, and which one applies depends on whose data is involved.

3.1 As a data processor

When a Customer submits Learner data through the Identities API, uploads source material to generate a course, or configures webhooks and tracking, Underlayer processes that data as a processor acting on the Customer's documented instructions. The Customer is the controller of its Learners' Personal Data and is responsible for having a lawful basis to collect and share it with us. Our processing obligations to Customers are set out in our Data Processing Addendum ("DPA"), available on request, which forms part of our Terms of Service for any Customer subject to the PDPL, GDPR, or a similar regime.

3.2 As a data controller

We act as a controller for Personal Data relating to Customers and Authorized Users themselves — for example, account registration details, billing contacts, sandbox sign-ups, marketing preferences, and data we collect about visitors to underlayer.outworx.io. This Privacy Policy is written primarily from that perspective. If you are a Learner and have a question about a specific course or product, the Customer that operates that product is the right party to contact first — we act on their instructions and can direct you to them.

4. Personal data we collect

4.1 Account & workspace data

  • Name, work email address, and password (or SSO identifier) when you create an account.
  • Company or workspace name, billing address, and VAT/tax registration number where applicable.
  • Role and permissions within a workspace, and communications you send us for support.

4.2 Content you submit for generation

Documents, URLs, prompts, or other source material a Customer submits to generate a course, and the resulting course content, theme, and quiz data. This is Customer Content processed on the Customer's instructions; see Section 6 for how it's used.

4.3 Learner / Identity data

  • Identifiers a Customer provisions through the Identities API (typically a Customer-assigned user ID, and optionally a name or email address the Customer chooses to pass to us).
  • Progress, quiz answers, scores, view events, and completion events recorded as a Learner interacts with an embedded course.

4.4 Payment data

We do not store full payment card numbers. Billing is handled by our third-party payment processor (currently Stripe), which collects card or bank details directly and shares with us only what's needed to manage your subscription — such as the last four digits of a card, billing address, and transaction status.

4.5 Technical, usage & log data

  • API request logs, including endpoint, timestamp, response status, and the API key used (not the raw key itself after issuance).
  • IP address, browser and device type, and pages visited on underlayer.outworx.io, collected via standard server logs and privacy-respecting analytics.

4.6 Cookies

See Section 8 for the specific cookies we use on underlayer.outworx.io and the embedded player.

5. How we use personal data

We process Personal Data only where we have a lawful basis to do so under the PDPL — principally: performance of a contract (running your workspace and the Services you're subscribed to), legitimate interest (keeping the Services secure, improving reliability, and preventing abuse), legal obligation (tax, accounting, and regulatory record-keeping), and consent (marketing communications, and any optional analytics or cookies that require it).

  • Operating, maintaining, and securing the Services, including authenticating API requests and enforcing usage limits.
  • Generating, storing, and delivering courses on a Customer's instructions.
  • Recording and reporting Learner progress and completions back to the Customer via the Tracking API and webhooks.
  • Processing payments, issuing invoices, and complying with UAE tax and accounting obligations, including VAT record-keeping under Federal Decree-Law No. 8 of 2017.
  • Responding to support requests and sending service-related notices (renewal reminders, incident notices, security alerts).
  • With consent, sending product updates or marketing — you can opt out at any time.
  • Detecting, investigating, and preventing fraud, abuse, or violations of our Terms of Service.

6. AI course generation and your data

When a Customer generates a course, the source material and prompt are sent to a third-party AI model provider solely to produce that course, and are not retained by us for any purpose beyond generation, debugging that specific request, and abuse monitoring.

Your content and your Learners' data are never used to train, fine-tune, or improve any AI model — ours or a third party's. This is a contractual and policy commitment, not merely a marketing statement, and it's reflected in our agreements with the AI providers we use. Where a provider's standard terms would otherwise permit training on submitted data, we contract out of that provision or use an enterprise/API tier that excludes it by default.

Generated course content can be inaccurate, incomplete, or contextually wrong, in the same way any AI output can be. We encourage Customers to review generated content before publishing it, particularly for regulated or safety-critical training.

7. Cookies and similar technologies

7.1 Marketing site (underlayer.outworx.io)

  • Strictly necessary cookies — session, authentication, and CSRF protection. Always on; required for the site to function.
  • Nothing else. We run no analytics or advertising cookie and load no third-party script, which is why you have not been shown a consent banner: there is nothing on this site to consent to. If that changes, the banner arrives with it and this section is rewritten first.

7.2 Embedded player

The embedded course player uses a short-lived, signed session token (not a third-party tracking cookie) to associate a Learner's activity with the Identity a Customer provisioned. It does not set advertising or cross-site tracking cookies.

7.3 Managing cookies

There are currently no non-essential cookies to manage on underlayer.outworx.io. You can clear or block cookies through your browser settings, but blocking strictly necessary cookies will prevent the site or dashboard from functioning.

One exception is worth naming: a course can contain an embed block pointing at another company's page, and opening a course that has one loads that page in a frame, where it may set its own cookies. That is the third party's doing, on the site the author chose to embed.

8. How we share personal data

We do not sell Personal Data, and we do not share it with third parties for their own independent marketing purposes. We share Personal Data only in the following circumstances:

  • Sub-processors — infrastructure, hosting, database, AI generation, email delivery, and payment providers we rely on to run the Services, each bound by a written data processing agreement consistent with the PDPL and, where relevant, the GDPR's Article 28 requirements. The current list is published in full at underlayer.outworx.io/sub-processors, naming each one and what it receives; questions go to privacy@underlayer.outworx.io.
  • At a Customer's direction — Learner data is shared back to the relevant Customer via the API, dashboard, and webhooks, since that Customer is the controller of that data.
  • Legal and regulatory disclosure — where required by UAE law, a valid order of a UAE court or competent authority (including the UAE Data Office), or to establish, exercise, or defend a legal claim.
  • Corporate transactions — if Underlayer is involved in a merger, acquisition, financing, or sale of assets, Personal Data may be disclosed to the parties involved, subject to confidentiality obligations and this Policy.

9. International data transfers

Underlayer's infrastructure and sub-processors may be located outside the UAE. Where we transfer Personal Data outside the UAE, we do so only where the destination country is recognized by the UAE Data Office as providing an adequate level of protection, or, in the absence of such recognition, under appropriate safeguards such as standard contractual clauses, binding corporate rules, or another mechanism recognized under the PDPL and its implementing regulations. Where a transfer also involves Personal Data originating in the EU/UK, we rely on the European Commission's Standard Contractual Clauses or an equivalent UK mechanism as an additional safeguard.

10. Data retention

We retain Personal Data for as long as a workspace remains active, and for a limited period afterward to comply with legal obligations (including UAE tax and accounting record-keeping, which generally requires financial records to be retained for at least five years), resolve disputes, and enforce our agreements.

If a Customer closes its workspace, we delete or anonymize Personal Data within 90 days, except where retention is required by law. Customers can export their data, including Learner records, at any time before closure via the API or by request to our support team.

11. Security

We apply administrative, technical, and physical safeguards appropriate to the sensitivity of the data we process, including encryption of data in transit and at rest, role-based access controls, signed and scoped API keys, and webhook payload signing. No system is perfectly secure, and we cannot guarantee absolute security, but we continuously work to reduce risk and will notify affected parties as required by Section 13 if a breach occurs.

12. Your rights

Under the PDPL, you have the right to request access to, correction of, or erasure of your Personal Data, to object to or restrict certain processing, to request that we transfer your data to another provider (data portability), and to withdraw consent at any time where processing is based on consent. We aim to respond to verified requests within 30 days, and sooner where the law requires it.

If you are located in the European Economic Area or the United Kingdom, you have equivalent rights under the GDPR, including the right to lodge a complaint with your local supervisory authority. If you are a California resident, you have rights under the CCPA to know what Personal Data we hold about you, to request its deletion, and to opt out of any "sale" or "sharing" of Personal Data — we do not sell or share Personal Data as those terms are defined under the CCPA.

To exercise any of these rights, contact us at privacy@underlayer.outworx.io. If you are a Learner and your data was provided to us by a Customer, we may direct your request to that Customer where they are best placed to fulfill it, consistent with our role as a processor.

13. Children's privacy

The Services are designed for use by businesses and their employees or customers, and are not directed at children. We do not knowingly collect Personal Data from individuals under 18. If a Customer's use case involves Learners under 18 (for example, workplace-adjacent training for younger apprentices), the Customer is responsible for obtaining any consent required by applicable law before provisioning that Learner's Identity to us.

14. Data breach notification

If we become aware of a Personal Data breach that poses a risk to the rights and interests of data subjects, we will notify the UAE Data Office without undue delay, and in any event within 72 hours of becoming aware of it, as required by Article 9 of the PDPL. Where a breach is likely to result in a high risk to affected individuals, or where we act as a processor, we will notify the relevant Customer without undue delay so they can meet their own notification obligations.

15. Changes to this policy

We may update this Policy as the Services evolve or as UAE and international data protection law develops. We'll post the updated version here with a new "last updated" date, and for material changes that reduce your rights, we'll provide direct notice by email to workspace owners at least 14 days before the change takes effect.

16. Data protection contact & complaints

Questions, requests, or complaints about this Policy can be sent to our data protection contact at privacy@underlayer.outworx.io. As a sole establishment, Underlayer has not reached the scale of processing that requires appointment of a formal Data Protection Officer under Article 10 of the PDPL, but we will appoint one, and publish their details here, if our processing activities reach that threshold.

If you believe we have not adequately addressed your concern, you have the right to lodge a complaint directly with the UAE Data Office, the federal regulator responsible for PDPL enforcement.

17. Governing law

This Privacy Policy is governed by the federal laws of the United Arab Emirates, without regard to their conflict-of-law provisions, and interpreted alongside the Terms of Service.

Drafted for Underlayer under UAE law, including Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. Have counsel review it before it governs a live customer relationship.