Legal

Privacy Policy

Last updated: 19 June 2026  ·  Effective: 19 June 2026

UAE Data Residency Guarantee. All invoice data, account data, and processing logs are stored exclusively on AWS UAE (me-central-1). No data ever leaves UAE jurisdiction. This is a hard architectural constraint required for FTA accreditation.

1

Information We Collect

When you register for Qavrin, we collect: company name, Tax Registration Number (TRN), legal entity details, authorised contact name, business email address, and billing information. This information is required to provision your account and establish your Peppol network identity.

Through normal use of the Service, we process invoice data you submit for clearance. This includes all fields required by the UAE FTA PINT AE standard: supplier and buyer TRN (BT-31, BT-48), invoice number (BT-1), issue and due dates (BT-2, BT-9), line item details, VAT amounts (BT-106), and VAT categories (BT-112).

We also collect technical usage data including API call logs, clearance status events, rejection reasons, and system performance metrics. This data is used solely for Service delivery, support, and compliance audit trail purposes.

2

How We Use Your Information

We use your information to: (a) provision and operate your Qavrin account; (b) connect your ERP to the UAE FTA via the Peppol 5-corner network; (c) validate invoices against the PINT AE standard; (d) transmit cleared invoice data to the FTA in real-time; (e) generate your compliance dashboard and analytics; and (f) issue FTA-compliant tax invoices for your Qavrin subscription.

We may use aggregated, anonymised data to improve the Service, train our AI Gap Analyzer, and publish industry compliance benchmarks. No individually identifiable data is used for these purposes.

We will never sell, rent, or share your company data or invoice data with third parties for marketing, advertising, or commercial purposes.

3

Data Storage - UAE Region

All invoice data, account data, and processing logs are stored exclusively on Amazon Web Services in the UAE region (me-central-1, Abu Dhabi). No data is replicated, backed up, or processed outside UAE jurisdiction. This is a hard architectural constraint, not a policy election.

Data storage in the UAE region ensures compliance with UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection, UAE Cabinet Resolution No. 33 of 2022, and the FTA's national data residency requirements for Accredited Service Providers.

Encryption at rest uses AES-256. Encryption in transit uses TLS 1.3. Database access is restricted to Qavrin backend services running within the same AWS UAE VPC. No Qavrin employee has standing access to production invoice data; access requires an audited break-glass procedure.

4

Data Sharing

Invoice data is shared with the following parties as required to deliver the Service: (a) UAE Federal Tax Authority (FTA) - for real-time clearance and VAT reporting as mandated by UAE law; (b) Peppol network - for routing cleared invoices to the Buyer's Access Point (Corner 4) and ultimately the buyer's ERP (Corner 5); (c) OpenPeppol - metadata for network participant registration via the Service Metadata Provider (SMP).

We engage sub-processors limited to: AWS UAE (infrastructure), Resend (transactional email), and Stripe (payment processing). Each sub-processor is bound by data processing agreements consistent with UAE data protection law. No sub-processor receives invoice content.

We may disclose information if required by UAE law, FTA directive, court order, or to protect the rights and safety of Qavrin, our customers, or the public. We will notify you of such disclosures where legally permitted.

5

Security

Qavrin operates on ISO 27001-certified AWS infrastructure within the UAE region. All API endpoints use TLS 1.3. Authentication uses industry-standard OAuth 2.0 with MFA support. Peppol AS4 message transmission uses mutual TLS and digital signatures on every invoice.

We conduct regular penetration testing and vulnerability assessments. Our infrastructure is monitored 24/7 for anomalous access, data exfiltration attempts, and service integrity. Critical security incidents are reported to the FTA within 2 business days as required by Cabinet Decision No. 106 of 2025.

In the event of a personal data breach that affects your data, we will notify you without undue delay and within the timeframes required by UAE Federal Decree-Law No. 45 of 2021.

6

Your Rights

Under UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection, you have the right to: access the personal data we hold about your account; request correction of inaccurate data; request deletion of data not required for FTA regulatory compliance; object to processing; and receive a copy of your data in a portable format.

To exercise these rights, contact us at privacy@Qavrin.ae. We will respond within 30 days. Note that certain invoice data cannot be deleted during the mandatory 7-year retention period required by UAE FTA regulations.

You have the right to lodge a complaint with the UAE Data Office if you believe your data protection rights have been violated.

7

Data Retention

Invoice data is retained for 7 years from the invoice date, in compliance with UAE FTA requirements and Cabinet Decision No. 106 of 2025. This retention is mandatory and cannot be reduced at your request.

Account data (company profile, user details, billing records) is retained for the duration of your subscription plus 7 years, consistent with UAE commercial record-keeping requirements.

Anonymised and aggregated analytics data may be retained indefinitely. Upon account termination, we provide a 30-day window for you to export your data before it is archived to cold storage.

8

Contact

For privacy enquiries, data subject requests, or to report a concern, contact our Data Protection function at: privacy@Qavrin.ae

Qavrin Technologies LLC, Dubai, United Arab Emirates.

This Privacy Policy was last updated on 19 June 2026. We will notify registered users of material changes by email.

This Privacy Policy is governed by UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection and UAE Cabinet Resolution No. 33 of 2022. This document is provided in English. In the event of any conflict with a translation, the English version shall prevail.