Privacy Policy
Designed to align with UAE PDPL & GDPR

Privacy Policy

Effective date: 10 July 2026. Controller: Caelius Management L.L.C-FZ, trading as Haviqo, Dubai, United Arab Emirates.

Governing law. This policy is governed primarily by Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) and its implementing regulations. Where Haviqo processes personal data of individuals located in the European Economic Area or the United Kingdom, Regulation (EU) 2016/679 (GDPR) and the UK GDPR apply concurrently. In the event of conflict, the stricter standard applies.

1. Who We Are and How to Contact Us

Protected requests are authenticated and authorised. Important business operations are recorded in the audit trail.

For data protection enquiries, contact our Data Protection Officer at . We will respond within 15 calendar days as required by the UAE PDPL. privacy@haviqo.com.

2. Personal Data We Collect

We collect the following categories of personal data:

CategoryDetails
Account dataName, email address, role, login method, session tokens.
Company dataTrade name, TRN, CT registration number, trade licence number, registered address, emirate, free zone.
Employee recordsFull name, nationality, passport number, Emirates ID, visa number, visa expiry date, employment start date, basic salary, housing allowance, transport allowance, job title, department, IBAN.
Payroll dataMonthly salary, EOSB accrual, WPS SIF file content, payslip history.
Financial dataJournal entries, chart of accounts, transaction descriptions, VAT amounts, CT estimates.
Usage dataIP address, browser type, pages visited, timestamps (for security and audit purposes only).
Uploaded documentsCompany logo, any documents uploaded by users.

We do not collect biometric data, health data, or political/religious opinions unless you voluntarily upload documents containing such information.

3. How and Why We Use Your Data

  • Providing and operating the Haviqo platform (accounting, payroll, tax, HR, secretarial modules).
  • Generating compliance outputs: VAT201 returns, CT estimates, WPS SIF files, IFRS financial statements, FTA audit reports.
  • Sending compliance deadline reminders (visa expiry, VAT filing, CT filing, WPS deadlines) by email.
  • Maintaining immutable audit logs for regulatory and internal governance purposes.
  • Detecting and preventing fraud, unauthorised access, and security incidents.
  • Improving the platform through aggregated, anonymised analytics (no individual profiling).
  • Complying with UAE legal obligations (MOHRE, FTA, Ministry of Finance, Central Bank).

5. Sensitive and Special-Category Data

Employee records on the platform may include passport numbers, Emirates IDs, visa numbers, and nationality — categories that attract heightened protection under UAE PDPL Article 4 and GDPR Article 9. We process this data solely for the purpose of UAE labour law compliance (MOHRE, WPS, visa tracking). Access is restricted to users with the HR_MANAGER or OWNER role within your organisation.

Salary and financial data is encrypted at rest and in transit. We do not sell, license, or share this data with third parties for commercial purposes.

6. Sharing and Disclosure

We share personal data only in the following circumstances:

  • Within your organisation: Users you have invited to your Haviqo tenant, subject to their assigned role and RBAC permissions.
  • Infrastructure providers: Cloud infrastructure: Supabase (PostgreSQL database, authentication, and file storage; Frankfurt, EU), Render (backend/API hosting; Frankfurt, EU), and Vercel (frontend hosting; global edge). These providers act as data processors under written agreements.
  • Email delivery: Resend (transactional email) for compliance alerts and invitations. No marketing data is shared.
  • AI processing (Groq Inc., US): When you use the Haviqo AI assistant or the OCR receipt scanning feature, the data you submit (financial summaries, document images) is transmitted to Groq Inc. (United States) for processing. Groq acts as a data sub-processor. No employee PII (names, IDs, passport numbers) is intentionally included in AI prompts, but financial and commercial data of your company may be transmitted. Groq does not use your data to train its models, per its current terms of service.
  • Legal obligation: We will disclose data to UAE regulatory authorities (FTA, MOHRE, UAE Data Office) when required by law, court order, or regulatory demand.
  • Business transfer: In the event of a merger or acquisition, data may be transferred subject to equivalent protections and prior notice to you.

We do not sell personal data. We do not share data with advertising networks.

7. International Data Transfers

Primary data storage is in Frankfurt, Germany (Supabase eu-central-1 for database, authentication, and file storage; Render Frankfurt for the API backend). The frontend is served via Vercel's global CDN edge network. Some sub-processors are based in the United States: Resend (transactional email), Upstash (rate limiting), and Groq (AI processing). These transfers are governed by each provider's data processing terms. We are working to establish formal Data Processing Agreements (DPAs) with each US-based sub-processor.

Data is not currently stored within the UAE territory. We are evaluating migration to UAE-region infrastructure as it becomes available from our providers, in line with PDPL data residency expectations.

8. Retention Periods

CategoryDetails
Account and company dataDuration of the subscription plus 5 years (UAE commercial records obligation under Federal Law No. 2 of 2015).
Employee recordsDuration of employment plus 5 years (UAE Labour Law, Federal Decree-Law No. 33 of 2021).
Financial and accounting data10 years from the end of the relevant fiscal year (UAE CT Law, Federal Decree-Law No. 47 of 2022, Article 54).
Audit recordsActive audit metadata is retained while the tenant remains active. Each minimized retention event is retained for seven years from its event timestamp.
Session tokens24 hours (demo sessions) or 7 days (authenticated sessions), then purged.
Deleted account dataTenant content is eligible for secure purge 90 days after a deletion request, subject to an active legal hold and applicable retention obligations.

9. Your Rights

Under the UAE PDPL and, where applicable, the GDPR, you have the following rights. To exercise any right, email with proof of identity. We will respond within 15 days (UAE PDPL) or 30 days (GDPR). privacy@haviqo.com.

CategoryDetails
AccessObtain a copy of your personal data we hold.
RectificationCorrect inaccurate or incomplete data.
ErasureRequest deletion of your data, subject to legal retention obligations.
RestrictionRestrict processing while a dispute is resolved.
Portability (GDPR)Receive your data in a structured, machine-readable format.
ObjectionObject to processing based on legitimate interests.
Withdraw consentWithdraw consent at any time without affecting prior processing.
Lodge a complaintFile a complaint with the UAE Data Office (established under Federal Decree-Law No. 45 of 2021), or with your local data protection authority if you are in the EEA.

10. Security Measures

We implement the following technical and organisational measures:

  • HTTPS protection in transit under the active hosting-provider configuration.
  • Provider-managed protection for database and file storage at rest.
  • Role-based access control (RBAC) with five roles: OWNER, CFO, ACCOUNTANT, AUDITOR, HR_MANAGER.
  • Row-level tenant isolation: every database query is scoped to a tenantId; cross-tenant access is blocked at the application layer.
  • Immutable audit logs: journal entries and user actions cannot be edited or deleted after write.
  • Authentication sessions follow the active Supabase project configuration and supported invalidation flows.
  • No storage of plaintext passwords; password hashing is managed by Supabase Auth using a secure hashing algorithm. Haviqo does not store or have access to plaintext passwords.
  • Incident response: see our Security page for the current incident response plan.

We conduct periodic security reviews. We will notify affected customers and the UAE Data Office within 72 hours of discovering a personal data breach that poses a risk to individuals, as required by UAE PDPL Article 14.

11. Cookies and Tracking

We use strictly necessary cookies for session management (JWT stored as an HttpOnly, Secure cookie). We do not use advertising cookies, third-party tracking pixels, or behavioural profiling. A limited first-party landing-page funnel is disabled by default and records only consented, non-identifying events.

12. Children

The Haviqo platform is a B2B enterprise service intended for use by corporate entities and their authorised representatives. We do not knowingly collect personal data from individuals under 18. If you believe a minor has provided data through our platform, contact privacy@haviqo.com immediately.

13. Changes to This Policy

We will notify you of material changes to this policy by email and by a prominent notice within the platform at least 30 days before the change takes effect. Continued use of the platform after that date constitutes acceptance of the revised policy. The current version is always available at haviqo.com/privacy.

Data Protection Contact

For all data protection enquiries, erasure requests, or complaints: privacy@haviqo.com

Supervisory authority: UAE Data Office (established under Federal Decree-Law No. 45 of 2021).

Last updated: 10 July 2026. Version 1.0.