J
Juba
GTM operating system
TermsPrivacySupport

Data transparency

Privacy Notice

This notice explains how Juba handles personal information when people visit, create an account, join a workspace, connect tools, or use specialist workflows.

Customer versionLast updated July 24, 2026

Juba is operated by Juba Fourali in United Arab Emirates. Customer and legal notices may be sent to contact@getjuba.com.

1. Who controls personal information

Juba determines how account, website, billing, support, security, and product-usage information is processed and acts as controller for that information. For Customer Data submitted to a workspace, the customer normally determines the purposes and means of processing and Juba acts as its service provider or processor.

Juba Fourali, established in United Arab Emirates, operates Juba and is the controller for this information. Privacy questions and rights requests may be sent to contact@getjuba.com.

2. Information we collect

  • Account and workspace information: name, email, organisation, role, invitations, permissions, timezone, product profile, market, goals, and workspace settings.
  • Customer Data: evidence, research, contacts, prospects, messages, content, plans, campaigns, approvals, interviews, analytics, and other material submitted to or produced within a workspace.
  • Connected-provider information: provider identity, account identifiers, granted scopes, encrypted credentials or tokens, and permitted email, calendar, CRM, social, analytics, billing, app-store, advertising, or knowledge-source data.
  • Usage and security information: product events, action receipts, audit records, device and browser information, session records, timestamps, and privacy-preserving hashes derived from IP address and user-agent information.
  • Billing and support information: plan, subscription, invoice, transaction status, support correspondence, and service feedback. Payment-card details are handled by the selected billing provider and are not intended to be stored by Juba.

3. Where information comes from

We receive information directly from users and workspace administrators; from providers a user chooses to connect; from service providers supporting Juba; and from public sources when a workspace instructs a research workflow to use them. A workspace customer is responsible for providing required notices when it supplies information about other people.

4. Why we use information

  • provide, personalise, meter, and support the Service;
  • verify identity, isolate tenants, enforce roles, route approvals, and secure accounts;
  • operate specialist workflows and carry out permitted provider actions;
  • measure performance, reconcile provider outcomes, improve reliability, and prevent fraud or abuse;
  • process subscriptions, payments, and customer support;
  • comply with law and enforce agreements; and
  • send product or marketing communications where permitted, with available opt-out controls.

5. Legal bases

Where a legal basis is required, Juba relies on performance of a contract to provide requested services; legitimate interests in securing, operating, supporting, and improving the Service; consent for optional connections or communications where consent is required; and legal obligations. A customer acting as controller selects and documents the lawful basis for Customer Data it directs Juba to process.

6. AI-assisted processing and automated decisions

Juba uses AI models to analyse accepted workspace context and produce research, recommendations, drafts, classifications, and proposed actions. Relevant prompts, workspace evidence, instructions, and outputs may be sent to the configured AI provider. Juba's approval system is designed to keep material external actions within human-set permissions, scopes, budgets, and review routes.

Juba is not intended to make solely automated decisions that produce legal or similarly significant effects on individuals. Customers must not use it for that purpose without an independently lawful process, appropriate safeguards, and any required human review.

7. When information is disclosed

We disclose information only as needed to:

  • infrastructure, database, security, email, analytics, AI, support, and billing providers that process information for Juba;
  • providers a workspace chooses to connect and recipients of actions the workspace approves;
  • authorised workspace members according to their roles and permissions;
  • professional advisers, authorities, or other parties when required by law or necessary to protect rights and safety; and
  • a successor in a merger, financing, reorganisation, or sale, subject to appropriate confidentiality protections.

Juba does not sell personal information. Juba does not use Customer Data for cross-context behavioural advertising.

8. International processing and data region

Juba's primary production database is currently hosted with Turso in AWS Asia Pacific (Tokyo), region ap-northeast-1. Application delivery, AI, email, billing, and customer-connected providers may process information in other countries. Where required, Juba uses contractual or other recognised safeguards for restricted international transfers.

9. Retention

We retain account and workspace information while the account is active and afterward only as long as reasonably needed to provide exports, resolve disputes, enforce agreements, meet legal requirements, prevent abuse, and maintain reliable backups. Retention also depends on the data type, workspace instructions, plan, legal obligations, sensitivity, and operational recovery window.

Security and audit records may be retained longer where needed to protect the Service. Connected providers keep information according to their own policies. We delete or de-identify information when it is no longer needed, subject to backup rotation and lawful preservation requirements.

10. Security

Juba uses tenant isolation, role and approval enforcement, encrypted credentials, signed webhooks, restricted scopes, database-backed sessions, audit records, monitoring, and tested recovery controls. No method of storage or transmission is completely secure, so users should also apply least privilege and avoid submitting unnecessary secrets or personal information.

11. Your choices and rights

Depending on location and applicable law, people may request access, correction, deletion, restriction, portability, or objection; withdraw consent; opt out of certain sharing or targeted advertising; and appeal a denied request. They may also complain to the relevant data protection authority.

Send a request to contact@getjuba.com. We may verify identity and authority before acting. If Customer Data is controlled by a Juba customer, we may direct the request to that customer and support its response.

12. Cookies and similar technology

Juba uses essential cookies for secure authentication, session continuity, invitation handling, and fraud prevention. Product measurement may use first-party events or configured analytics tools. Optional analytics or marketing technology will be subject to applicable notice and consent requirements before use.

13. Children

Juba is a business service and is not directed to children. Accounts are limited to people aged 18 or older. Contact us if you believe a child has provided personal information.

14. Changes to this notice

We will update this notice when processing changes. The date above shows the latest revision. We will provide additional notice before a material change where required.

Juba · specialist GTM operations with governed executioncontact@getjuba.com