Legal
Privacy Policy
Last updated: September 4, 2026
This Privacy Policy explains how Diojen Tech FZ-LLC(“Duqqan,” “we,” “us”), registered at VUPR0809 Compass Building, Al Hulaila Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates, collects, uses, and protects information when you use Duqqan at duqqan.app, the owner panel, and demos. We are the data controller for that information and we process personal data in line with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021).
1. Scope
This policy covers the data we process to run Duqqan. It does notcover the content or visitor data of the websites our customers publish — for a published customer site, the customer is the controller of its visitors’ data and we act as their processor. A data-processing agreement is available to customers on request.
2. What information we collect
- Account data — your name, email, and a securely hashed password.
- Business and site content — the business information, text, and media you provide or upload.
- Lead and prospect data — contact and business details, including information we gather about a business from public sources(Google Maps, public Instagram posts, and the business’s own website) to prepare a demo.
- Payment data — handled by Stripe. We receive billing status and details but never store full card numbers.
- Communications — messages you send us.
- Technical and usage data — IP address, browser/user agent, timestamps, and limited tracking of whether our emails were opened or clicked and whether a demo was viewed. On duqqan.app we also measure traffic with Google Analytics 4 — which pages are read and where visitors arrive from — and with Microsoft Clarity, which records how a visit moves through a page (scrolling, clicks) and aggregates those visits into heatmaps. Both load only after you accept them in the cookie banner, both are limited to our own marketing pages, and neither is an advertising tag (see our Cookie Notice).
- Your cookie choice — when you accept or reject analytics on duqqan.app, we keep a record of that decision: the date, which of the two categories you allowed, the version of the notice you were shown, and a random reference your browser generates. It holds no IP address and no analytics id. A refusal is recorded too, for the reason set out in the Cookie Notice— showing that we honoured a “no” requires having kept it.
3. How we collect it
We collect data directly from you, automatically as you use the Services (see our Cookie Notice), and — for the outbound demo flow — from publicly available sources about a business.
4. Why we process it (lawful basis)
Under the UAE PDPL we rely on: performance of our contract with you (to provide the Services); our legitimate interests (to prepare business demos, improve the product, and prevent fraud and abuse); your consent where it is required; and compliance with our legal obligations.
One case is worth naming because it is easy to get backwards. Analytics run on your consent. The record that you gave or refused that consent is kept under our legal obligation instead — we are required to be able to demonstrate it, and a record you could withdraw would be no evidence at all. That is why refusing analytics still leaves a record of the refusal.
5. How we use it
- to generate, host, and serve your website;
- to send account, billing, and service communications;
- to take payments and manage subscriptions;
- to improve and secure Duqqan and prevent abuse;
- to send you marketing about Duqqan, where permitted (see below);
- to demonstrate that you gave or refused consent to analytics, and when;
- to comply with our legal obligations.
We do not sell personal data.
6. AI processing
We use an enterprise AI provider — OpenAI, via the OpenAI API — to generate content from your inputs and publicly available information about your business. Your business content is not used to train third-party AI models; it is processed under enterprise data-protection terms that prohibit training on your data.
7. Automated decision-making
Duqqan uses AI to generate website content and suggestions, but we do not make decisions producing legal or similarly significant effects about you solely by automated means. You always review and control what is published.
8. Service providers (sub-processors)
We share data only with the providers we need to run Duqqan, and only the minimum necessary. Each is bound by confidentiality and data-protection terms.
| Provider | Contracting entity | Purpose | Region |
|---|---|---|---|
| OVHcloud | OVH SAS | Application and database hosting | Germany |
| Cloudflare | Cloudflare | DNS, CDN, media storage (R2), bot protection (Turnstile), custom domains | Global |
| Stripe | Stripe | Payment processing and subscription billing | EU / US |
| Telr | Telr PTE LTD | Card payments, for businesses that select it | UAE |
| Resend | Plus Five Five, Inc. (San Francisco, CA) | Transactional and notification email | USA |
| OpenAI | OpenAI | AI content generation, vision, and translation | US |
| Places / Maps data for business information | US | ||
| Google Analytics | Not yet confirmed — see below | Traffic and behaviour measurement on duqqan.app, after cookie consent | US |
| Microsoft Clarity | Not yet confirmed — see below | Session recordings and heatmaps on duqqan.app, after cookie consent | US |
| Bright Data | Bright Data | Fetching public Instagram posts | US / EU |
| WhatsApp (Meta) | WhatsApp LLC | WhatsApp Business messaging, for businesses that connect a number | US / EU |
| Openprovider | Hosting Concepts B.V. (Rotterdam) | Domain registration — registrant contact details are passed to the registry | Netherlands |
| Slack | Slack Technologies Limited (Dublin) | Operational alerting to our own team | Ireland |
- OVHcloud — OVHcloud contracts through per-country affiliates (OVH SAS, OVH GmbH, …). Which one signed OUR account is on our invoice, not on their site.
- Telr — Licensed by the Central Bank of the UAE and operating from Dubai Digital Park, but the policy does not say where cardholder data is stored.
- Google Analytics — Which Google entity signs for a RAK free-zone customer (Google LLC or Google Ireland Limited) is on our own Analytics account terms rather than a public page — and GA4 offers no data-residency control, so 'US' is where the data lands rather than somewhere we chose.
- Microsoft Clarity — Named as Microsoft Corporation everywhere Clarity is described, but which Microsoft entity contracts with a RAK free-zone company is not stated on a public page — and Clarity offers no data-residency choice, so 'US' is where the recordings land rather than somewhere we chose.
The list above is the processors we instruct — including Google Analytics and Microsoft Clarity, which measure traffic and record visits on duqqan.app itself once you accept the cookie banner. It does not include the analytics or advertising tags a business may switch on for its ownsite — Meta Pixel, Hotjar and the rest, and a business’s own Google Analytics or Clarity property too. There, that business chooses the vendor and is the controller for what it collects; we render what it configured, behind the consent banner on that site. Our Cookie Notice lists those separately, and Integrations shows which are available.
9. WhatsApp Business Platform data
A business using Duqqan can connect its own WhatsApp Business number so that orders, bookings, and enquiries reach it on WhatsApp. We are a Tech Provideron the WhatsApp Business Platform: we operate the connection on that business’s behalf and under its instructions. For the conversations between a business and its customers, the business is the controller and we are its processor. WhatsApp LLC (WhatsApp Ireland Limited for customers in the EEA and the UK) processes those messages as part of delivering WhatsApp, under Meta’s own terms.
When a business connects a number, we receive and store only what the feature needs (“Platform Data”):
- Account identifiers — the WhatsApp Business Account ID, phone number ID, the display phone number, and the access token that authorises us to send on its behalf.
- Message content and metadata— the text and media of messages sent to and from the business’s number, the customer’s phone number and WhatsApp profile name, message identifiers, timestamps, and delivery/read statuses.
- Message templates — the templates a business registers with Meta and their approval status.
We use Platform Data only to deliver the messaging feature to the business that connected the number: routing an incoming message to that business, sending its replies, showing its conversation history in its own panel, and reporting delivery failures. We do notsell it, use it for advertising or ad targeting, build profiles from it, use it to train AI models, or share it with any business other than the one it belongs to. Each business’s conversations are isolated at the database level, the same way the rest of its data is (see “How we keep it safe” below).
A business may disconnect its number at any time from its Duqqan settings, which revokes our access token and stops all further processing. We retain conversation history for as long as the business’s account is active, because it is the business’s own record of its customer enquiries; it is deleted when the account is deleted, or sooner on request. To have WhatsApp data deleted — whether you are a business or a customer who messaged one — see Data Deletion or email [email protected].
10. Shopify store data
A business using Duqqan can connect its own Shopify store so that its catalogue and orders appear alongside its conversations. As with WhatsApp above, the business is the controller and we are its processor: we read from that store on its instruction and only for as long as it keeps the connection. Shopify is the business’s own platform, not a sub-processor we instruct on our own behalf, which is why it does not appear in the table in section 8.
When a business connects a store, we receive and store only what the feature needs:
- Store identifiers — the
.myshopify.comdomain, the store identifier, the scopes granted, and the access and refresh tokens that authorise us to read on its behalf. Both tokens are encrypted with a key unique to that business. - Product data— title, handle, description, status, price range, variants and the address of the product image, which stays on Shopify’s servers rather than being copied to ours. None of this is personal data.
- Order data— order number, total, currency, payment and fulfilment status, the date it was placed, and the line items. Where the order carries them, we also store the customer’s name and phone number, each encrypted with that business’s own key.
We deliberately do notcopy the customer’s email address, billing or shipping address, or any payment detail — a Shopify order contains all of them, and none is needed for what this feature does.
We use this data onlyto deliver the feature to the business that connected the store: showing its catalogue and orders in its own panel, and matching an incoming WhatsApp conversation to that customer’s orders so the business can answer with context. The match is on an exact, per-business hash of the phone number, so the same customer is not identifiable across two businesses. We do not sell this data, use it for advertising, build profiles, or message a customer because their number arrived in an order — a phone number in a Shopify order is not consent to contact it, and nothing is sent unless the business confirms its own lawful basis and the customer has opted in on WhatsApp.
A business can disconnect at any time from its panel. When it does, or when it uninstalls the app, the store connection and everything mirrored from it is deleted. We also action Shopify’s own customer data requests and erasure requests when a merchant or a customer raises one through Shopify.
11. Demos from public information
For our outbound flow we may build a private demo site for a business using its publicly available information and email a link to it. If you are that business and would prefer we did not, email [email protected] and we will delete the lead and the demo.
12. Social logins
You register with email and password. If we offer the option to sign in through a third-party account in future, that provider would share basic profile information (such as your name and email) with us, which we would use only to create and run your account.
13. Sharing your information
Beyond the providers above, we share personal data only when required by law, to protect our rights, or as part of a business transfer (such as a merger or sale), in which case we will continue to protect it under this policy. We never sell your personal data.
14. International transfers
Some of our providers process data outside the UAE (for example in the EU or US). Where that happens, we rely on appropriate safeguards to protect your data.
This includes our own infrastructure, which is worth stating plainly rather than leaving it to be read out of the table below: our application and database are hosted in Germany (OVHcloud), and encrypted backups are held with Cloudflare. So data you give us is processed outside the UAE from the moment we receive it — not only when a third-party tool is involved.
15. How long we keep it
Demos expire after about seven (7) days, after which an automated job removes them. Abandoned leads and data that has reached the end of its retention period are deleted by scheduled jobs. We keep account and billing data while your account is active and for a reasonable period afterwards, then delete or anonymise it, subject to any legal obligation to retain records.
Records of your cookie choice (section 2) are kept for twenty-four (24) months from the date of the decision, then deleted by a daily job. The bound is measured from when you decided, not from when the record reached us, so a choice made long ago is not held longer because we learned of it late.
Orders mirrored from a connected Shopify store (section 10) have two fixed bounds, applied by a daily job. After twelve (12) monthsthe customer’s name and phone number are erased from the mirrored order while the order itself — amount, date, line items — remains, because that record belongs to the business and outlives our need to hold the person. After twenty-four (24) monthsthe order is deleted outright. Both bounds are measured from the date the order was placed, not from the date we received it, so a store’s existing history is subject to them from the moment it connects.
16. How we keep it safe
We protect data in transit with encryption, isolate each business’s data at the database level, and restrict internal access. Administrative access is separate from customer accounts and protected by two-factor authentication. No method of transmission or storage is 100% secure, but we work to protect your data using appropriate measures.
17. Data breaches
If a personal-data breach occurs that is likely to affect your rights, we will notify the relevant authority and affected users as required by the UAE PDPL.
18. Marketing communications
We may send you product news and marketing about Duqqan where permitted. You can opt out at any time using the unsubscribe link in those emails or by emailing [email protected]. We will still send essential service and billing messages.
19. Your privacy rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal data; object to or restrict certain processing; and withdraw consent. To exercise a right, email [email protected]. You may also complain to the UAE Data Office.
20. Do-Not-Track
Some browsers send a “Do-Not-Track” signal. As there is no agreed standard for it, we do not respond to it specifically. Instead, analytics cookies load only if you accept them, and you can change or withdraw that choice at any time using the Cookie settings link in the footer (see our Cookie Notice). Withdrawing stops the analytics; it does not erase the record that you had allowed them earlier, which is kept for the period in section 15 and is what shows the withdrawal was honoured.
21. Children
Duqqan is for businesses and is not directed at children. We do not knowingly collect data from anyone under 18; if we learn we have, we will delete it.
22. Reviewing, updating, or deleting your data
You can review and update most of your information from your account settings. To request a copy of your data, or to have it corrected or deleted, email [email protected] and we will respond within a reasonable time, subject to applicable law.
23. Changes and contact
We may update this policy and will revise the date above; for material changes we will give reasonable notice. Questions about this policy or your data? Email [email protected]. Diojen Tech FZ-LLC, VUPR0809 Compass Building, Al Hulaila Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates.