DXBComply

Privacy Policy

Last updated: May 5, 2026  ·  UAE Federal Decree-Law No. 45 of 2021 (PDPL)

1. Who We Are

DXBComply (also branded as DXBComply) is a UAE compliance SaaS that helps businesses track trade license renewals, compliance deadlines, and government document expiries.

We handle your data carefully because we know how sensitive compliance information is. This policy explains exactly what we collect, why we collect it, who we share it with, and what rights you have over your data.

For any data-related questions, email: ainagarkatti@gmail.com

2. What Data We Collect

We only collect data that is necessary to run the service.

DataWhy We Collect It
Full nameTo identify you as a user and personalise your account
Email addressTo send account notifications, renewal alerts, and login links. Also used as your login identifier.
Company nameTo associate your compliance records with your business entity
WhatsApp numberTo send renewal reminders and compliance alerts via WhatsApp
Emirates ID numbersTo track identity document expiries so you don't miss renewal deadlines
Trade license numbersTo track license renewal dates and send timely reminders
Document expiry datesCore function of the service — we store the expiry dates you enter or extract from uploaded documents
Uploaded document filesYou may upload PDFs or images of trade licenses, visas, Emirates IDs, and other compliance documents
We do NOT collect: payment card numbers (Stripe handles all payment processing), biometric data, location data, browsing history or analytics beyond basic page views, or any data not listed above.

3. How We Collect Your Data

  1. You give it to us directly — when you sign up, fill in your profile, upload documents, or enter compliance data
  2. We extract it from documents you upload — our OCR feature reads expiry dates from uploaded documents so you don't have to type them manually
  3. Service usage data — basic information about how you interact with the dashboard to improve the product

4. How Long We Keep Your Data

Data TypeRetention Period
Account information (name, email, company, WhatsApp number)Until you delete your account
Compliance data (license numbers, Emirates IDs, expiry dates)Until you delete your account
Uploaded documentsUntil you delete them or delete your account
Payment records5 years (UAE tax law requirement) — stored by Stripe, not by us
Usage analytics12 months, then anonymised

When you delete your account, all your personal data and uploaded documents are permanently deleted within 30 days. Backup copies are purged within 60 days.

5. Where Your Data Is Stored

Your data is stored on Supabase, hosted in Frankfurt, Germany (EU region).

Data residency: your data resides in Frankfurt, Germany. It does not leave the EU economic area except when processed by our third-party tools listed in Section 6, which may process data in other regions.

6. Third-Party Processors (Who We Share Data With)

We use the following services to run DXBComply. Each one has its own privacy and security measures. By creating an account you explicitly consent to these transfers under Article 22 of the UAE PDPL.

ServiceWhat It DoesWhere
SupabaseStores all your data (database + file storage)Frankfurt, Germany
ResendSends email notifications (renewal reminders, account emails)US / EU
Meta WhatsApp Cloud APISends WhatsApp renewal reminders (when this channel is enabled on your account)US / EU / Ireland
StripeProcesses subscription paymentsUS / EU
Anthropic (Claude)Powers AI features (document analysis, smart reminders)United States
We do NOT sell your data to anyone. We do not share your compliance data with any third party except as necessary to provide the service through the processors listed above.

7. Your Rights Under UAE PDPL

The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) gives you the following rights:

Right to Know

Ask us what data we hold about you at any time. We'll send a full copy within 5 business days.

Right to Access

Log into your dashboard to see all your data directly. For a machine-readable export (JSON/CSV), email us.

Right to Correct

Edit most of your data directly in the dashboard. For anything stuck, email us and we'll fix it within 2 business days.

Right to Delete

Delete your account from dashboard settings. This permanently removes your profile, all compliance data, all uploaded documents, and all expiry tracking records.

Right to Restrict Processing

If you believe your data is incorrect or being processed unlawfully, ask us to pause processing while we investigate.

Right to Data Portability

Request a copy of your data in CSV or JSON format within 5 business days.

Right to Object

If we're processing your data for a purpose you didn't agree to, you can object and we'll stop.

To exercise any right: ainagarkatti@gmail.com — we respond within 5 business days and may ask you to verify your identity.

8. How We Protect Your Data

MeasureWhat It Means
Encryption in transitAll data sent between your browser and our servers is encrypted with TLS 1.3
Encryption at restYour data is encrypted on Supabase's servers
Access controlsOnly you and authorised team members can access your data, with role-based permissions
Regular backupsYour data is backed up daily. Backups are encrypted and stored separately.
No third-party trackingWe don't use analytics scripts from Google, Facebook, or other ad networks

9. Cookies

We use only essential cookies:

  • Session cookie: keeps you logged in while you use the dashboard
  • CSRF token: prevents cross-site request forgery

We do not use tracking cookies, advertising cookies, or third-party analytics cookies. Blocking all cookies will prevent you from logging in.

10. Changes to This Policy

If we change this privacy policy, we will:

  1. Update the “Last updated” date at the top
  2. Email you at the address on your account
  3. Show a notice in the dashboard the next time you log in

Significant changes (new data collection, new third-party processors) will require your explicit consent. Minor changes take effect immediately.

11. Complaints

  1. First step: email ainagarkatti@gmail.com — we investigate within 5 business days
  2. Second step: if you're not satisfied, you can file a complaint with the UAE Data Office (the PDPL supervisory authority)

12. Legal Basis for Processing (PDPL Article 4)

Processing ActivityLegal Basis
Account creation and managementYour consent (you signed up and agreed to this policy)
Renewal remindersContractual necessity (this is the core service you signed up for)
AI document analysisYour consent (you choose which documents to analyse)
Payment processingContractual necessity (we can't provide the service without payment)
Legal compliance (tax records)Legal obligation (UAE tax law requires us to retain certain records)

13. Children's Privacy

DXBComply is a business-to-business service. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us with personal data, email ainagarkatti@gmail.com and we'll delete it immediately.

14. International Data Transfers

Your data is stored in Frankfurt, Germany (Supabase EU region). Some third-party processors (Anthropic, Resend, Stripe, Twilio) may process data in other countries, including the United States.

Where these countries have data protection laws that differ from UAE PDPL, we rely on:

  • Standard Contractual Clauses (SCCs) — for transfers to the US (Anthropic, Resend, Stripe, Meta)
  • Adequacy decisions — for transfers within the EU (Supabase)
  • Your explicit consent — where applicable

15. Data Protection Officer

In line with UAE PDPL Article 10, DXBComply has appointed a Data Protection Officer (DPO) responsible for monitoring our PDPL compliance, advising on data protection impact, acting as the contact point for the UAE Data Office, and handling all data-subject requests.

DPO: Asif Nagarkatti, Founder & CEO

Email: dpo@dxbcomply.ae  (or ainagarkatti@gmail.com)

Response time: Within 5 business days for general queries; within 72 hours for suspected data breaches.

Language: English or Arabic

If you believe your personal data has been mishandled or breached, contact the DPO immediately. We're also happy to explain anything in this policy in simpler terms — just ask.