Privacy Notice
1. Controller
SITUS FZ L.L.C., Expo City Dubai Authority Service Licence No. 00134, Dubai, United Arab Emirates, is the controller of personal data it processes for website, account, billing and service-administration purposes, unless a different role is expressly stated for a feature.
2. Data we process
- Account data: name, business email, authentication identifiers and account status.
- Subscription and billing data: plan, entitlement, payment/customer identifiers, billing status and transaction metadata. Payment card details are handled by the payment processor rather than stored directly by SITUS.
- Technical data: browser/device information, security events, timestamps, error diagnostics and aggregate usage counts needed to enforce plan limits and operate the Service.
- Terms acceptance: the version accepted, timestamp, source and related checkout/account identifiers.
- Customer Content: vendor/supplier data, invoices, evidence, explanations and other compliance records entered by the customer. In the encrypted-vault architecture, this content is encrypted client-side before recoverable cloud backup.
- Support communications: messages and files voluntarily sent to SITUS for support.
3. Why we process data
We process data to provide and secure VAT Guard, authenticate users, administer subscriptions, enforce plan entitlements, provide encrypted backup/recovery, deliver transactional communications, detect abuse, maintain legal/security records, comply with law and improve reliability.
4. Customer-side encrypted content
Where the encrypted backup architecture is enabled, Customer Content is encrypted before it is uploaded for backup. SITUS does not need the customer’s vault passphrase or recovery key to administer subscriptions. Customers must protect their recovery credentials. If the encryption architecture makes recovery technically impossible without the key, SITUS may be unable to restore readable content when the key is lost.
5. Service providers
VAT Guard may use service providers for website hosting, application hosting/CDN, authentication, encrypted object storage, subscription payments, transactional email, monitoring and security. The planned launch stack may include Tilda for marketing pages, Stripe for subscription payments, Supabase for authentication/control-plane data and encrypted backup storage, and a CDN/static-hosting provider for the application/demo. The published subprocessor list should be updated if providers change.
6. International processing
Service providers may process data in jurisdictions outside the UAE. SITUS will use contractual, technical and organisational safeguards required by applicable UAE data-protection law where cross-border transfers occur.
7. Retention
Account, subscription, security, tax-invoice and legal records are retained for periods reasonably necessary for their purposes and applicable legal obligations. Encrypted Customer Content is retained according to the Service’s subscription/termination settings and published deletion process. Customers should export or recover records before any announced deletion deadline.
8. Security
SITUS uses reasonable technical and organisational measures appropriate to the Service. No internet, browser, encryption or cloud system is absolutely secure. Customers are responsible for authorised-user management, endpoint security, strong credentials and recovery-key custody.
9. Rights
Individuals may have rights under applicable UAE data-protection law, including rights relating to access, correction, deletion or other processing controls, subject to legal limitations and verification of identity. Requests should be sent through the privacy/contact channel published on the VAT Guard website.
10. Cookies and local storage
The application may use strictly necessary browser storage for authentication and the encrypted working vault. The marketing site may use Tilda or analytics cookies depending on the site configuration. If non-essential analytics or advertising cookies are enabled, a suitable cookie notice/consent mechanism should be displayed.
11. Changes
This Notice may be updated as the product architecture or law changes. Material changes will be identified by a new version/effective date and notified where appropriate.
12. Contact
Privacy questions and requests should be sent through the contact details published on the VAT Guard website.