The fine print, in plain language.
How Laddershift Marketing Services collects data, delivers work, and keeps your revenue engine defensible. Written to global standards and anchored in UAE law, where we’re based.
Last updated 2 July 2026 · Laddershift Marketing Services, Dubai, UAE
Privacy Policy
Effective 2 July 2026
This Privacy Policy explains how Laddershift Marketing Services (“LadderShift”, “we”, “us”), a company based in Dubai, United Arab Emirates, collects, uses, discloses, and protects personal data. It is written to align with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (“PDPL”) and the EU/UK General Data Protection Regulation (“GDPR”).
1. Data we collect
- Contact & account data, name, business email, phone, company, and role, when you apply for an audit or engage us.
- Engagement data, information you share so we can build your system: your offer, ICP, playbooks, and access to the tools you ask us to connect.
- Lead & prospect data, personal data of your prospects and customers that flows through the systems we operate on your behalf, for which you are the controller and we act as processor.
- Technical data, IP address, device and browser type, and usage analytics collected via our website and dashboards.
2. How and why we use it
We process personal data to deliver and improve our services, to communicate with you, to meet legal and security obligations, and, only where permitted, for marketing you can opt out of at any time. Our lawful bases are: performance of a contract, our legitimate interests (balanced against your rights), your consent, and compliance with legal obligations.
3. Sharing & subprocessors
We share personal data only with vetted subprocessors who help us run the service (see the Subprocessor List), with your connected tools at your direction, and where required by law. We never sell personal data.
4. International transfers
Where data leaves the UAE, EU, or UK, we rely on adequacy decisions or Standard Contractual Clauses and apply appropriate safeguards, consistent with PDPL and GDPR cross-border transfer rules.
5. Retention & security
We keep personal data only as long as needed for the purposes above or as required by law, then delete or anonymise it. Data is encrypted in transit and at rest, with least-privilege, revocable access.
6. Your rights
Subject to the PDPL and GDPR, you may request access, correction, deletion, restriction, or portability of your personal data, object to certain processing, and withdraw consent. To exercise these rights, email privacy@laddershift.com. You may also lodge a complaint with the UAE Data Office or your local supervisory authority.
7. Cookies & contact
We use essential and analytics cookies; you can control non-essential cookies in your browser. Questions? Contact our data team at privacy@laddershift.com.
Terms of Service
Effective 2 July 2026
These Terms govern your use of the LadderShift website and the services provided by Laddershift Marketing Services. By engaging us or using our site, you agree to them.
1. Services & engagement
We design, build, and operate AI-assisted revenue systems as described in the applicable proposal or statement of work (“SOW”). The SOW controls scope, deliverables, timelines, and fees; these Terms cover everything else.
2. Your responsibilities
You are responsible for the accuracy of the materials you provide, for lawful use of the systems we build, for obtaining consent from the contacts you market to, and for maintaining your own tool subscriptions and credentials.
3. Intellectual property
You own your data, brand assets, and the content of your campaigns. We retain ownership of our underlying frameworks, templates, and tooling, and grant you a license to use the delivered system for your business.
4. Fees & payment
Fees, milestones, and payment terms are set in the SOW. Unless stated otherwise, invoices are due within the period specified, and late amounts may pause active work. See our Refund Policy.
5. Warranties & liability
We deliver services with reasonable skill and care. We do not guarantee specific revenue outcomes. To the maximum extent permitted by law, our aggregate liability is limited to the fees paid for the services giving rise to the claim, and we exclude indirect or consequential loss.
6. Term, termination & governing law
Either party may terminate as set out in the SOW. These Terms are governed by the laws of the United Arab Emirates as applied in the Emirate of Dubai, and disputes are subject to the exclusive jurisdiction of the Dubai courts, without prejudice to any applicable free-zone dispute mechanism.
Subprocessor List
Reviewed quarterly
We use a small set of trusted providers to deliver the service. Each is bound by data-processing terms consistent with PDPL and GDPR. Categories below reflect the types of subprocessor we engage; the specific vendors on your account are listed in your data-processing addendum.
Encrypted hosting for dashboards and operational data. Region-pinned where required.
Enterprise LLM APIs under zero-retention or no-training terms for message drafting and analysis.
The CRM, email, and messaging platforms you connect, used at your direction to deliver campaigns.
Privacy-respecting product analytics and error monitoring to keep systems reliable.
To receive advance notice of subprocessor changes, email privacy@laddershift.com.
Vulnerability Disclosure Policy
Safe harbor for good-faith research
We welcome reports from security researchers. If you believe you’ve found a vulnerability in our website or systems, tell us and we’ll work with you to confirm and fix it.
Scope & safe harbor
Testing must not access, modify, or exfiltrate data that isn’t yours, degrade our services, or affect other users. Good-faith research conducted within this policy will not lead to legal action from us.
How to report
Email security@laddershift.com with a description, reproduction steps, and impact. Please give us reasonable time to remediate before any public disclosure.
Our commitment
We aim to acknowledge reports within 3 business days, validate within 10, and keep you updated through remediation. We’re happy to credit researchers who wish to be named.
Refund Policy
Fair, and written down
The Revenue Leak Audit is free and carries no obligation. For paid engagements, the following applies alongside your SOW and UAE consumer-protection principles.
- Setup & build fees cover work performed. Once a build milestone is underway, fees for that milestone are non-refundable, but undelivered milestones can be cancelled for a pro-rata refund.
- Monthly management fees can be cancelled with the notice stated in your SOW; you’re billed only through the end of the notice period.
- Service issues. If we materially fail to deliver a contracted milestone and can’t remedy it within a reasonable period, you’re entitled to a refund of the fees for that milestone.
- Third-party costs (ad spend, tool subscriptions, data) are passed through and are not refundable by us.
To request a refund, email billing@laddershift.com. We aim to resolve requests within 14 days. Nothing here limits rights you may have under applicable UAE consumer-protection law.
AI Policy
How we use AI, responsibly
AI is core to what we build. We use it to draft messages, qualify leads, schedule, and surface insight, always under human oversight and never as an unaccountable black box.
Human-in-the-loop
Every outbound message an agent produces is reviewable and approved by a person before it sends. You set the guardrails; the system stays inside them.
Your data & model training
We use enterprise LLM providers under terms that prohibit training on your data. Your prospect and business data is used to run your system, not to train third-party models.
Accuracy & limits
AI systems can make mistakes. We test, monitor, and retrain, and we design workflows so a human catches errors before they reach your customers. AI output is a draft for your judgement, not legal, financial, or professional advice.
Prohibited uses
We won’t build systems for deceptive, discriminatory, or unlawful outreach, or anything that violates the terms of the platforms we operate on. If a request crosses that line, we’ll say no.