Privacy Policy
1. INTRODUCTION
1.1 This Privacy Policy explains how the Company collects, uses, processes, stores, discloses, and protects Personal Data in connection with a User's access to or use of the Platform and the Services, including the DocFlow platform available at https://www.docflow.ae/ and any related web or mobile applications.
1.2 By accessing or using the Platform, registering an Account, or otherwise engaging with the Services, the User acknowledges that it has read and understood this Privacy Policy. Where the User's consent is the applicable legal basis for a particular processing activity, such consent is obtained separately in accordance with Clause 5.
1.3 The Company does not sell or rent Personal Data to third parties.
1.4 Where a User does not provide certain Personal Data required for the operation of the Platform or the Services, the Company may be unable to provide the relevant functionality or Services to that User.
2. SCOPE OF THIS PRIVACY POLICY
2.1 This Privacy Policy applies to the Personal Data of:
Users who access or use the Platform, irrespective of whether they are Clients or Authorized Users;
individuals whose Personal Data is contained within E-Invoice Data processed through the Platform, including a Client's counterparties or their representatives; and
individuals whose Personal Data is otherwise provided to the Company in connection with the Services, including at the account registration or onboarding stage.
2.2 In respect of E-Invoice Data, the Company processes such data solely for the purpose of, and to the extent necessary for, providing the Services and performing the Company's functions as an accredited service provider described in Clause 2.8 of the Customer Agreement, including verification and transmission of E-Invoice data to the Competent Authority. The Client remains solely responsible for the accuracy, legality, and compliance of the Personal Data contained in the E-Invoices it issues, in
accordance with Clause 4.2 of the Customer Agreement.
2.3 This Privacy Policy does not apply to third-party websites or services that may be linked from the Platform, or to information processed by a Client independently of the Platform.
3. CATEGORIES OF PERSONAL DATA COLLECTED
3.1 Account and Contact Information. In connection with registration and use of an Account, theCompany may collect a User's name, email address, phone number, company name, job title or role, login credentials, and other contact information, processed for the purpose of providing the Services.
3.2 Technical and Usage Information. The Company may automatically collect technical information relating to use of the Platform, including IP address, browser type and version, device identifiers, access timestamps, session activity, and system diagnostic information.
3.3 E-Invoice Data. Where a Client uses the Platform to create, transmit, receive, or process E-Invoices, the Platform will process the Personal Data contained within such E-Invoices and related transaction documentation, including the names and contact details of the Client's counterparties or their representatives, in accordance with Clause 2.2.
3.4 Documentation Provided at Onboarding. Where required under Clause 3.2 of the Customer Agreement, the Company may collect copies of trade licences, constitutional documents, powers of attorney, or other documentation evidencing the authority of the individual accepting the Customer Agreement on behalf of a Client.
4. PURPOSES OF PROCESSING AND DATA RETENTION
4.1 The Company retains Personal Data for as long as necessary for the purposes for which it was collected, in accordance with this Clause 4 and Applicable Law.
4.2 Personal Data is processed for the following purposes:
providing and operating the Services, including enabling Authorized Users to access and use the Platform and facilitating the creation, processing, and management of E-Invoices;
account management and authentication, including verifying user identity during registration, login, and password reset;
performing the Company's functions as an accredited service provider, including the verification and transmission of E-Invoice data to the Competent Authority in accordance with Applicable Law;
processing transactions and communications, including sending invoices, notifications, confirmations, and administrative messages;
client support, including responding to inquiries and providing technical assistance;
improving and developing the Services, including maintaining and enhancing the functionality, reliability, and performance of the Platform;
security and fraud prevention, including detecting and addressing unauthorized access or misuse of the Platform;
monitoring and internal operations, including troubleshooting and system testing; and
compliance with legal obligations, including applicable laws, regulatory requirements, or lawful requests from a Competent Authority.
4.3 Personal Data is retained for as long as the relevant Account remains active and, thereafter, for such further period as is necessary to comply with Applicable Law, resolve disputes, or enforce the Company's agreements.
5. LEGAL BASIS FOR PROCESSING
5.1 The Company processes Personal Data on one or more of the following legal bases:
performance of a contract with the Client or the User, or to take steps at the User's request prior to entering into a contract;
compliance with a legal obligation, including obligations arising under the UAE electronic invoicing system;
the Company's legitimate interests in operating, securing, and improving the Platform and the Services, provided such interests are not overridden by the User's interests or fundamental rights; and
the User's consent, where required by Applicable Law, which the User may withdraw at any time in accordance with Clause 11.
5.2 Processing of Personal Data is carried out in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its implementing regulations.
6. COOKIES AND TRACKING TECHNOLOGIES
6.1 The Company uses cookies and similar tracking technologies, including beacons, tags, and scripts, to operate the Platform, recognize returning Users, and analyze use of the Platform.
6.2 A User may configure its browser to refuse cookies or to notify the User when a cookie is sent. If a User does not accept cookies, certain features of the Platform may not function correctly.
7. DISCLOSURE OF PERSONAL DATA
7.1 The Company may disclose Personal Data to trusted third-party service providers that support the operation of the Platform, including providers of:
cloud infrastructure and hosting services;
data storage and backup services;
security monitoring services;
analytics and diagnostic tools; and
technical support services.
7.2 Such service providers may access Personal Data only to the extent necessary to perform services on the Company's behalf and are subject to appropriate contractual confidentiality and data protection obligations.
7.3 The Company discloses E-Invoice Data to the Competent Authority to the extent required for the Company to perform its functions as an accredited service provider described in Clause 2.8 of the Customer Agreement.
7.4 The Company may also disclose Personal Data where necessary: (a) to comply with a legal obligation or a lawful request from a Competent Authority; (b) to protect the Company's rights, property, or legitimate interests; (c) to investigate suspected unlawful activity, fraud, or breach of Applicable Law or the terms governing the Platform; (d) to protect the safety of Users, Clients, or the
public; or (e) in connection with a corporate reorganization, merger, or sale of assets, subject to Clause 18.5 of the Customer Agreement.
8. INTERNATIONAL DATA TRANSFERS
8.1 Personal Data may be transferred to, or stored in, data centers located outside the United Arab Emirates where necessary for the operation of the Platform or the use of cloud infrastructure services.
8.2 Where such a transfer occurs, the Company takes reasonable steps to ensure that appropriate safeguards are implemented in accordance with Applicable Law to protect the Personal Data transferred.
9. DATA SECURITY
9.1 The Company maintains industry-standard technical and organizational measures appropriate to the nature and sensitivity of the Personal Data processed, consistent with the security measures described in Section 11 of the Customer Agreement.
9.2 The Company stores Personal Data in secure operating environments that are not accessible to the general public and implements measures designed to protect against loss, unauthorized access, misuse, or alteration of Personal Data. No method of transmission over the internet or electronic storage is entirely secure, and the Company cannot guarantee absolute security.
9.3 A User who believes its Account has been compromised should promptly notify the Company at info@docflow.ae. The Company will investigate reported incidents and, where appropriate, take further action, including notifying competent authorities in accordance with Applicable Law.
10. MARKETING COMMUNICATIONS
10.1 Where a User submits an inquiry, requests a demonstration, or subscribes to receive updates through the Platform, the Company may contact the User by email or other electronic means to provide the requested information and, with the User's consent, to inform the User of the Company's products, services, and offerings, consistent with Clause 11.1 of the Terms of Use and Clause 8.8 of the Customer Agreement.
10.2 The User may withdraw consent to marketing communications at any time using the unsubscribe mechanism specified in the relevant communication or by contacting the Company at info@docflow.ae.
11. DATA SUBJECT RIGHTS
11.1 Subject to Applicable Law, a User may have the right to:
access its Personal Data and request confirmation as to whether, and how, the Company processes it;
correct Personal Data that is inaccurate, incomplete, or out of date;
request erasure of Personal Data that is no longer necessary for the purposes for which it was collected, subject to the Company's legal obligations, including record-retention obligations described in Clause 4.3;
request that processing of some or all of its Personal Data be restricted in certain circumstances;
object to processing based on the Company's legitimate interests or carried out for direct marketing purposes;
request that its Personal Data be provided in a structured, commonly used, machine-readable format and, where technically feasible, transmitted to another organization; and
withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before such withdrawal or processing carried out on another lawful basis.
11.2 To exercise any of these rights, a User may contact the Company at info@docflow.ae. The Company may request additional information to verify the User's identity before responding and will make reasonable efforts to respond within a reasonable time, subject to Applicable Law.
11.3 Where a request relates to E-Invoice Data, the Company will, where appropriate, refer the request to the relevant Client, who remains responsible for such data in accordance with Clause 2.2.
12. COMPLIANCE WITH UAE DATA PROTECTION AND CYBERSECURITY LAWS
12.1 The Company conducts its operations in compliance with Applicable Law governing electronic transactions, cybersecurity, and the protection of Personal Data, including:
Applicable Law governing electronic transactions and digital trust services, which recognize the legal validity of electronic records and digital signatures used in online transactions;
Federal Decree-Law No. 34 of 2021 on Combatting Rumours and Cybercrimes; and
UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its implementing regulations.
12.2 The Company implements appropriate technical and organizational measures designed to safeguard Personal Data and ensure that it is processed in accordance with Applicable Law.
13. PERSONNEL ACCESS TO PERSONAL DATA
13.1 Access to Personal Data processed through the Platform is restricted to authorized personnel of the Company and, where necessary, personnel of trusted service providers supporting the Services, and is granted only to the extent reasonably necessary for purposes such as providing and maintaining the Services, customer support, system administration, security, and compliance with Applicable Law.
13.2 Personnel with access to Personal Data are subject to confidentiality obligations, consistent with Category IX of the Company's internal confidentiality policies applicable to ASP and e-invoicing platform data.
14. THIRD-PARTY LINKS
14.1 The Platform may contain links to third-party websites. The Company is not responsible for the privacy practices or content of such websites and encourages Users to review their privacy policies.
15. CHILDREN'S PRIVACY
15.1 The Platform is intended for business and professional use and is not directed to individuals under the age of eighteen (18), consistent with Clause 4.2 of the Terms of Use. The Company does not knowingly collect Personal Data from children.
16. CHANGES TO THIS PRIVACY POLICY
16.1 The Company may update this Privacy Policy from time to time by publishing an updated version on the Platform. The updated version takes effect upon publication, and continued use of the Platform or the Services following such publication constitutes acceptance of the updated Privacy Policy.
16.2 Users are encouraged to review this Privacy Policy periodically.
17. CONTACT INFORMATION
17.1 Questions regarding this Privacy Policy or the processing of Personal Data may be directed to the Company at info@docflow.ae.
Last updated: 07/08/2026