Policy basis
This page explains how the product handles account, document, and messaging data. When the text mentions legal obligations, verify them against the governing law and your own counsel.
Scope
Account and compliance data
Storage
Supabase in Frankfurt
Review rule
Legal text is informational
Dembri is a UAE compliance SaaS that helps businesses track trade license renewals, compliance deadlines, and government document expiries. The service is operated by Dembri Technologies Ltd, a company incorporated in the Dubai International Financial Centre (DIFC), registered number 13580.
We handle your data carefully because we know how sensitive compliance information is. This policy explains exactly what we collect, why we collect it, who we share it with, and what rights you have over your data.
For any data-related questions, email: privacy@dembri.com
We only collect data that is necessary to run the service.
| Data | Why We Collect It |
|---|---|
| Full name | To identify you as a user and personalise your account |
| Email address | To send account notifications, renewal alerts, and login links. Also used as your login identifier. |
| Company name | To associate your compliance records with your business entity |
| WhatsApp number | To send renewal reminders and compliance alerts via WhatsApp |
| Emirates ID numbers | To track identity document expiries so you don't miss renewal deadlines |
| Trade license numbers | To track license renewal dates and send timely reminders |
| Document expiry dates | Core function of the service — we store the expiry dates you enter or extract from uploaded documents |
| Uploaded document files | You may upload PDFs or images of trade licenses, visas, Emirates IDs, and other compliance documents |
| Data Type | Retention Period |
|---|---|
| Account information (name, email, company, WhatsApp number) | Until you delete your account |
| Compliance data (license numbers, Emirates IDs, expiry dates) | Until you delete your account |
| Uploaded documents | Until you delete them or delete your account |
| Payment records | 5 years (UAE tax law requirement) — stored by Stripe, not by us |
| Usage analytics | 12 months, then anonymised |
When you delete your account, all your personal data and uploaded documents are permanently deleted within 30 days. Backup copies are purged within 60 days.
We use the Meta WhatsApp Business Cloud API to send renewal reminders and (for Group-tier customers) two-way compliance chat. WhatsApp messaging requires explicit, per-recipient consent under both Meta's platform policy and UAE PDPL.
How we capture your consent. You opt in to WhatsApp messages from Dembri in one of two ways:
How we record your consent. For every opt-in, we store the phone number (in E.164 format), the timestamp, and the method (settings toggle or first inbound message). This record is retained for the lifetime of your account, plus 3 years after account deletion, as evidence of lawful processing under PDPL Article 4 and Meta's opt-in policy.
How to opt out. Two equivalent options:
Opt-out is immediate. We send a one-line confirmation and never message that number again from Dembri's WhatsApp Business Account until you opt back in via the settings toggle.
If you change your WhatsApp number. Opt-in is bound to a specific number. If you update the number in your settings, your previous opt-in record stays bound to the old number; you'll need to opt in again for the new one. This is intentional — it ensures consent always matches the number we send to.
For Group-tier customers using two-way chat. Messages you send to us and our AI agent's replies are stored in your chat history and used to improve your service experience. They are not used to train any AI model.
No marketing or promotional content is sent via WhatsApp. Messages are strictly transactional — renewal reminders, account alerts, and (for Group tier) your own compliance questions.
Your data is stored on Supabase, hosted in Frankfurt, Germany (EU region).
Data residency: your data resides in Frankfurt, Germany. It does not leave the EU economic area except when processed by our third-party tools listed in Section 6, which may process data in other regions.
We use the following services to run Dembri. Each one has its own privacy and security measures. By creating an account you explicitly consent to these transfers under Article 22 of the UAE PDPL.
| Service | What It Does | Where |
|---|---|---|
| Supabase | Stores all your data (database + file storage) | Frankfurt, Germany |
| Resend | Sends email notifications (renewal reminders, account emails) | US / EU |
| Meta WhatsApp Cloud API | Sends WhatsApp renewal reminders (when this channel is enabled on your account) | US / EU / Ireland |
| Stripe | Processes subscription payments | US / EU |
| Anthropic (Claude) | Powers AI features (document analysis, smart reminders) | United States |
| Perplexity (Sonar API) | Powers live government-policy research — only when you explicitly click the "Look up live →" button in chat (see Section 6b) | United States |
When you chat with Dembri's AI agent about your own documents, compliance status, or UAE regulatory questions, the conversation is processed by Anthropic (USA) under our zero-retention Data Processing Addendum.
What is sent. Your question text, with personal identifiers (Emirates ID, UAE and international phone numbers, email addresses, passport numbers, visa file numbers, payment card numbers) automatically scrubbed before transmission. A summary of the documents relevant to answering — document name, type, issuing authority, status, and expiry date — is included as context. We do not send document numbers, file contents, scanned images, payment information, or your account profile.
Where it goes. Anthropic (USA), our AI sub-processor under PDPL Article 21(3)(c). Anthropic processes the text transiently under a zero-retention policy: your data is not used to train any model, is not retained beyond the response, and is not combined with data from any other source.
How to opt out. Don't use the chat feature. All other Dembri functionality — document vault, expiry calendar, reminders, playbooks — works without the AI agent.
When you ask the AI agent a question about UAE government policy (for example, “What does MOHRE require for X?” or “Cabinet Decision 106/2025 — does this still apply?”), the agent may offer a “Research this live” button. Clicking this button is the only way that any part of your question is sent to a research provider outside Dembri.
What is sent. Only the text of the specific question, with personal data (Emirates ID, passport, visa numbers, phone, email) automatically removed before transmission. We do not send your account information, document contents, license records, reminder schedules, or chat history.
Where it goes. Perplexity (USA), our research sub-processor under PDPL Article 21(3)(c). Perplexity uses its Sonar API. Our signed Data Processing Addendum with Perplexity (Section 5) expressly prohibits Perplexity from using your data to train its AI models and from retaining or combining it with data from any other source. Personal data is deleted within thirty days of the end of our service relationship with Perplexity.
How to opt out. Don't click the “Research this live” button. The default answer path never sends anything to Perplexity. Live search is strictly user-triggered, per-question, and rate-limited.
This is the only outbound transfer of your question content to a third-party research provider beyond the processors listed in Section 6. If we add another such provider in future, we will update this section and email account holders before activation.
The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) gives you the following rights:
Right to Know
Ask us what data we hold about you at any time. We'll send a full copy within 5 business days.
Right to Access
Log into your dashboard to see all your data directly. For a machine-readable export (JSON/CSV), email us.
Right to Correct
Edit most of your data directly in the dashboard. For anything stuck, email us and we'll fix it within 2 business days.
Right to Delete
Delete your account from dashboard settings. This permanently removes your profile, all compliance data, all uploaded documents, and all expiry tracking records.
Right to Restrict Processing
If you believe your data is incorrect or being processed unlawfully, ask us to pause processing while we investigate.
Right to Data Portability
Request a copy of your data in CSV or JSON format within 5 business days.
Right to Object
If we're processing your data for a purpose you didn't agree to, you can object and we'll stop.
To exercise any right: privacy@dembri.com — we respond within 5 business days and may ask you to verify your identity.
| Measure | What It Means |
|---|---|
| Encryption in transit | All data sent between your browser and our servers is encrypted with TLS 1.3 |
| Encryption at rest | Your data is encrypted on Supabase's servers |
| Access controls | Only you and authorised team members can access your data, with role-based permissions |
| Regular backups | Your data is backed up daily. Backups are encrypted and stored separately. |
| No third-party tracking | We don't use analytics scripts from Google, Facebook, or other ad networks |
We use only essential cookies:
We do not use tracking cookies, advertising cookies, or third-party analytics cookies. Blocking all cookies will prevent you from logging in.
If we change this privacy policy, we will:
Significant changes (new data collection, new third-party processors) will require your explicit consent. Minor changes take effect immediately.
| Processing Activity | Legal Basis |
|---|---|
| Account creation and management | Your consent (you signed up and agreed to this policy) |
| Renewal reminders | Contractual necessity (this is the core service you signed up for) |
| AI document analysis | Your consent (you choose which documents to analyse) |
| Payment processing | Contractual necessity (we can't provide the service without payment) |
| Legal compliance (tax records) | Legal obligation (UAE tax law requires us to retain certain records) |
Dembri is a business-to-business service. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us with personal data, email privacy@dembri.com and we'll delete it immediately.
Your data is stored in Frankfurt, Germany (Supabase EU region). Some third-party processors (Anthropic, Resend, Stripe, Meta WhatsApp Cloud API, Perplexity) may process data in other countries, including the United States.
Where these countries have data protection laws that differ from UAE PDPL, we rely on:
In line with UAE PDPL Article 10, Dembri has appointed a Data Protection Officer (DPO) responsible for monitoring our PDPL compliance, advising on data protection impact, acting as the contact point for the UAE Data Office, and handling all data-subject requests.
DPO: Asif Nagarkatti, Founder & Security Officer
Email: dpo@dembri.com
Response time: Within 5 business days for general queries; within 72 hours for suspected data breaches.
Language: English or Arabic
If you believe your personal data has been mishandled or breached, contact the DPO immediately. We're also happy to explain anything in this policy in simpler terms — just ask.
Pending formal legal review. This section sets out a baseline controller/processor framework. Regulated Firms (banks, healthcare, government suppliers) and Firms whose own customers contractually require a counter-signed DPA should request the standalone DPA below before onboarding. Click-through acceptance of this Privacy Policy is the default contract for SME engagements only.
When a PRO firm or business setup consultant (each, a "Firm") uses Dembri to manage compliance for their own end-clients (each, a "Managed Client"), the roles under UAE PDPL are:
Firm responsibilities (controller obligations):
Dembri responsibilities (processor obligations):
Data Processing Agreement. The Firm's acceptance of this Privacy Policy at signup, together with the order documentation for the Firm's subscription tier, constitutes a Data Processing Agreement between the Firm (controller) and Dembri (processor) for the purposes of UAE PDPL. A standalone signed DPA is available on request for Firms that require it.
Request standalone DPA