Legal
Privacy notice
This notice explains which personal data are processed when you visit this website or write to the Initiative by email. It is an English translation of the German privacy notice; where the two differ, the German version prevails.
Controller
The controller responsible for processing personal data on this website, within the meaning of Article 4(7) of the General Data Protection Regulation (GDPR), is:
- Name and address
- M.B. Great Cyprus Holding Ltd, Grigori Afxentiou 59A, 4529 Pyrgos, Limassol, Cyprus; represented by its director, Mustapha Bazra
- info@arabian-service.com
- Data protection officer
- not appointed
The Al-Bazra Initiative for Heritage and AI is not a legal entity in its own right. The controller is therefore the person or body named above, not the Initiative itself.
No cookies, no tracking, no third-party content
- The website sets no cookies and uses no similar techniques, such as your browser's local storage, to store information on your device or read it from there. Consent under section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG) is therefore not required.
- There are no tools for analytics, audience measurement or tracking, and there is no advertising.
- No content is embedded from third-party servers: no font services, maps, videos, social media buttons or external scripts.
- Web fonts are served from this website's own server. Your browser does not connect to any third-party server while you view the pages.
Should content from other parties be embedded in future, for example manuscript images loaded directly from the server of the holding institution, this notice will be updated beforehand.
Hosting
The website is hosted on servers of Hetzner Online GmbH, which processes the server log files described below on behalf of the controller.
- Hosting provider
- Hetzner Online GmbH
- Data centre location
- Hetzner data centre in Nuremberg, Germany; hosting does not involve any transfer of data to a country outside the EU
- Data processing agreement (Article 28 GDPR)
- concluded
Server log files
Whenever you open a page, your browser necessarily transmits data to the server. The server stores the following in log files:
- the IP address of the requesting device;
- the date and time of the request;
- the request line, that is, the request method, the requested address (URL) and the protocol;
- the HTTP status code of the server's response;
- the amount of data transferred, in bytes;
- the referring address (referrer), that is, the page from which you arrived;
- the browser identifier (user agent), that is, information about your browser and operating system;
- the X-Forwarded-For header, which contains the original IP address when a request passes through an intermediate server and is empty for a direct request.
- Purpose
- Delivering the website, protecting its operation against attacks and misuse, and analysing faults
- Legal basis
- Article 6(1)(f) GDPR; the legitimate interest lies in operating the website securely and reliably
- Retention period
- 14 days; the log files are then deleted automatically
- Recipient
- Hetzner Online GmbH as processor
These data are not combined with other data sources and are not used to build profiles of visitors. Processing your IP address is technically necessary to transmit the pages to your device.
Contact by email
If you write to the Initiative by email, your email address, the time of sending, the content of your message and any details you choose to give, such as your name, are processed. These data are used solely to deal with your enquiry.
- Legal basis
- Article 6(1)(b) GDPR where your enquiry concerns entering into or performing a contract; otherwise Article 6(1)(f) GDPR, based on the legitimate interest in answering enquiries
- Retention period
- until your enquiry has been fully dealt with; the messages are then deleted unless statutory retention duties require them to be kept
- Email service
- united-domains GmbH, Starnberg, Germany, receives messages and forwards them to a mailbox with Google (Gmail); this may involve a transfer of data to the United States
Email is usually not encrypted end to end. Please do not use it to send particularly sensitive information, such as details of your health.
Comments on the Charter
The Ethics Charter for AI and Arabic and Islamic Heritage is to be open for public comment, and comments are to be sent by email. A comment is published only with your consent, with or without your name, as you prefer (Article 6(1)(a) GDPR). You may withdraw your consent at any time with effect for the future; the comment is then removed from the website.
In progress The public comment period runs from 15 September 2026 to 10 November 2026.
Links to other websites
This website contains links to websites run by others, such as sources and tools. You leave this website only when you follow such a link. From then on, the operator of that website is responsible for processing your data, and its own privacy notice applies.
Your rights
You have the following rights with regard to your personal data, which you can exercise against the controller:
- access (Article 15 GDPR);
- rectification of inaccurate data (Article 16 GDPR);
- erasure (Article 17 GDPR);
- restriction of processing (Article 18 GDPR);
- data portability (Article 20 GDPR);
- objection to processing (Article 21 GDPR).
Where data are rectified, erased or restricted, the recipients of those data are informed in accordance with Article 19 GDPR. An email to info@arabian-service.com is sufficient to exercise any of these rights.
Right to object
Where processing is based on Article 6(1)(f) GDPR, you may object to it at any time on grounds relating to your particular situation. Your data will then no longer be processed, unless the controller demonstrates compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
Withdrawing consent
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future (Article 7(3) GDPR). This does not affect the lawfulness of processing carried out before the withdrawal.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR), in particular in the EU member state where you live or work or where the alleged infringement took place. The authority responsible for the controller is: the Cypriot data protection authority (Office of the Commissioner for Personal Data Protection), 15 Kypranoros Street, 1061 Nicosia, Cyprus.
No automated decision-making
No decisions based solely on automated processing, including profiling, within the meaning of Article 22 GDPR are made about you.
Date of this notice and changes
Last updated: 13 September 2026. If the processing changes, for example because the website gains new functions, this notice will be updated beforehand.
This English version and the Arabic version are translations of the German privacy notice. The German version is authoritative.