Privacy Policy
Draft, not yet in force
This policy explains how [LEGAL ENTITY NAME] handles personal data in connection with Trazer. Questions about it can be sent to [privacy@yourdomain].
Two different roles
This distinction matters, and getting it the wrong way round is the most common error in policies of this kind.
For data about our own customers, the people who sign up, sign in and pay, we are the controller: we decide why and how it is processed.
For data that a customer enters into their own workspace, their clients, contacts, deals and correspondence, we are a processor. The customer is the controller. We act on their instructions, and questions from their contacts should be directed to them.
Data we hold as controller
About the people who use the service directly:
- Identity and contact data: name, work email address, and the workspace they belong to
- Authentication data: one-time sign-in codes and session records. We do not store passwords because the service does not use them
- Usage data: aggregate counts such as number of members, deals, invoices and documents, used for support and billing
- Correspondence: messages sent to us for support or sales
Data we process on a customer's behalf
Whatever the customer chooses to enter into their workspace. Typically that includes contact details for their clients, deal and project records, documents such as proposals and NDAs, invoices, and email correspondence sent through the platform.
We do not use this data for our own purposes, do not sell it, and do not use it to train artificial intelligence models.
Why we process it
- To provide the service under our contract with the customer
- To authenticate users and keep accounts secure
- To provide support, which may require limited access to diagnose a specific reported issue
- To bill accurately, using aggregate usage counts
- To meet legal and regulatory obligations
Access by our staff
The platform is built so that operator access shows aggregate counts only, not the contents of a workspace. Our staff cannot browse a customer's deals, documents or correspondence through the ordinary operator tools.
Where diagnosing a specific reported problem requires deeper access, it is undertaken only with the customer's knowledge and is recorded.
Artificial intelligence
Where AI features are enabled for a workspace, the relevant text is sent to our AI sub-processor for the sole purpose of producing that response. It is not used to train models.
AI features can be disabled for a workspace on request.
Sharing
We share data with the sub-processors listed on the sub-processors page, each of which is engaged under terms requiring appropriate protection. We do not sell personal data.
We may disclose data where required by law or by a competent authority.
International transfers
Some of our sub-processors operate outside the UAE. Where data is transferred internationally we rely on the safeguards described in our agreements with them.
[CONFIRM WITH COUNSEL: the specific transfer mechanism and hosting regions must be stated accurately here, and customers in regulated sectors will ask for detail.]
Retention
Workspace data is retained for as long as the workspace is active. Following termination, data is retained for [RETENTION WINDOW] to allow export, then deleted.
Audit records may be retained longer where required for legal or security purposes.
Security
Access is governed by role and enforced at the database layer rather than only in the interface. Each workspace's records carry an immutable workspace tag, so one customer's data cannot be reached from another's workspace.
Sign-in uses one-time codes, so no passwords exist to be leaked or reused. Sensitive actions are written to an append-only audit log by the database itself.
Multi-factor authentication beyond the one-time code is not yet available. We state this plainly rather than implying a control we do not have.
Rights
Individuals have rights over their personal data, including access, correction, deletion and objection, subject to the limits of applicable law.
If we hold your data as controller, contact [privacy@yourdomain]. If your data is in a customer's workspace, contact that company directly, since they decide how it is used. We will assist them in responding.
Complaints
[INSERT the relevant UAE supervisory authority and its contact route, confirmed with counsel.]
Questions about this document can be sent to us through the contact form, and we will route them to the right place.
Back to all policies