This UAE-oriented draft is product content for specialist review, not legal advice. Production remains blocked until the operator identity and document are approved.
Version: draft-2026-08-14 · Draft date: 14 August 2026
Scope and eligibility
Available exclusively to companies for company-owned or company-managed devices. Personal consumer repair requests are not accepted. Employee and representative contact details remain personal data even when submitted for a business.
Information handled
The service handles company and authorized-contact details, workplace address, device-batch descriptions, request and lifecycle records, quote decisions, payment and refund status, consent versions, security events, and communication history.
- Do not provide passwords, PINs, unlock codes, card details, ID documents, confidential files, or unnecessary device secrets.
- The first release does not provide public file upload.
Purposes and legal basis
Information is used to assess eligibility, create and perform a company-service request, coordinate pickup and return, diagnose devices, issue and record quotes, process payment or refunds, prevent abuse, meet recordkeeping duties, and respond to rights requests. The applicable basis must be confirmed by UAE-qualified counsel for the final operator.
Processors and recipients
Configured providers may include Firebase and Google Cloud for hosting, authentication, storage, functions, maps, and abuse protection; Ziina for hosted payments; Resend for transactional email; and separately enabled Google measurement services after applicable consent. Provider contracts, locations, and cross-border transfer safeguards require launch review.
Retention and security
Records are retained according to operational, financial, dispute, security, and legal needs, then deleted or anonymized under the approved schedule. Controls include access restrictions, encrypted transport, provider-supported encryption at rest, token hashing, audit records, redacted logs, rate limits, and tested restore procedures. No security measure is absolute.
Choices and requests
Subject to applicable law and verified identity, individuals may have routes to access, correct, delete, restrict, object, request portability, withdraw consent, or complain. The final operator must document the applicable process, exceptions, and authority before publication.
Operator and policy contact
The verified controller/operator identity is a launch-blocking configuration value. A verified privacy contact must be configured before publication.