Privacy Policy
Effective date: May 10, 2026 · Last updated: May 10, 2026
AMANA is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data in compliance with the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL), applicable UAE data protection requirements, and where applicable the EU General Data Protection Regulation (GDPR — Regulation 2016/679) for users in the European Economic Area.
⚠️ DIFC Data Protection Law applicability subject to local legal review.
1. Data Controller
The data controller responsible for processing your personal data is:
Denhill International LLC
IFZA Business Park, Dubai Silicon Oasis, Dubai, United Arab Emirates
Privacy contact and DPO: contact@amana-uae.com
2. Personal Data We Collect
We collect the following categories of personal data:
| Category | Data Collected | Purpose | Legal Basis (GDPR Art. 6) | Retention |
|---|---|---|---|---|
| Account | Email, hashed password, account creation date, account type | Account creation and authentication | Contract (Art. 6.1.b) | Duration of account + 30 days |
| Profile | Full name, title, company, industry, country, city, bio, headline, avatar, languages, skills, markets, open_to, website, social links | Professional profile visible to members | Contract (Art. 6.1.b) | Duration of account |
| Company Page | Company name, legal name, industry, country, city, description, logo, banner, website, social links, employee count, languages, video URL | Operating company pages | Contract (Art. 6.1.b) | Duration of account |
| Experience & Education | Employers, roles, dates, schools, degrees, certifications | Enriching professional profile | Contract (Art. 6.1.b) | Duration of account |
| Verification | Trade License documents, business registration data, LinkedIn URL | Verification, fraud prevention, trust & safety, legal compliance | Legitimate interest (Art. 6.1.f) + Consent (Art. 6.1.a) | 12 months after verification decision |
| Content | Posts, messages, comments, opportunities, recommendations | Operating platform features | Contract (Art. 6.1.b) | Duration of account; messages until deleted by both parties |
| Contact Requests | Sender, recipient, message, timestamp | Enabling connections | Contract (Art. 6.1.b) | 2 years |
| Payment | Billing name, subscription plan, payment history, Stripe transaction IDs (full card details processed by Stripe only — not stored by AMANA) | Processing subscription payments | Contract (Art. 6.1.b) | Applicable accounting, tax, and legal retention requirements |
| Usage Data | IP address, browser type, pages visited, click behavior, session duration, device type, referrer | Platform security, fraud prevention, product improvement | Legitimate interest (Art. 6.1.f) | 13 months |
| Communications | Transactional emails (connection requests, verifications, alerts) | Notifying platform activity | Contract (Art. 6.1.b) | 3 years |
| Marketing | Email for newsletters | Marketing communications | Consent (Art. 6.1.a) — opt-in only | Until consent withdrawn |
| Fraud Prevention | Abuse reports, moderation records, investigation notes, evidence | Fraud prevention, security, legal compliance | Legitimate interest (Art. 6.1.f) + Legal obligation (Art. 6.1.c) | 3 years or duration of proceedings |
| Legal/Consent | Terms acceptance date, consent timestamps, IP at consent, support messages | Proof of consent, legal compliance | Legal obligation (Art. 6.1.c) | 5 years |
3. Trade License Data
AMANA collects and processes Trade License documents and related business registration data solely for the following purposes:
- Verification review — confirming the legitimacy of businesses on the platform
- Fraud prevention — detecting and preventing fraudulent or misrepresentative accounts
- Platform trust and safety — maintaining the integrity of the AMANA professional network
- Legal compliance — meeting applicable regulatory or legal requirements
Documents are not shared with third parties except as required by law. Access is restricted to authorized AMANA personnel involved in the verification process, subject to confidentiality obligations.
Retention
⚠️ Retention period subject to local legal review.
4. Legal Bases for Processing
Under the GDPR (for EEA users) and applicable UAE PDPL requirements, we process your personal data on the following legal bases:
⚠️ Legal bases under UAE PDPL subject to local legal review.
5. How We Use Your Data
We use your personal data to:
- Create and manage accounts and professional profiles
- Enable networking, connections, and messaging features
- Display profiles to other members in accordance with privacy settings
- Process subscriptions and manage billing via Stripe
- Review verification requests and Trade License documents
- Send transactional emails (connection requests, verifications, security alerts)
- Send marketing communications (with explicit consent, opt-in only)
- Detect and prevent fraud, abuse, and policy violations
- Comply with legal and regulatory obligations
- Improve platform features based on anonymized analytics
AMANA will NEVER sell personal data to third parties. No automated decision-making producing legal effects will occur without explicit consent.
6. Private Messages
AMANA does not routinely monitor private messages exchanged between users on the platform. We respect the confidentiality of your communications.
However, AMANA may access or review messages when necessary to investigate:
- Abuse, harassment, or inappropriate conduct
- Fraud or security incidents
- Legal requests from competent authorities
- User reports of Terms of Service violations
- Active safety investigations
Message content may be retained as evidence in ongoing investigations for as long as the investigation or related legal proceedings remain active.
⚠️ Access to messages subject to applicable law and local legal review.
8. International Data Transfers
Some of our service providers are located outside the European Economic Area (EEA), notably in the United States. Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Technical and organizational measures ensuring equivalent data protection
You may request a copy of the applicable transfer mechanisms by contacting us at contact@amana-uae.com.
⚠️ Transfer mechanisms under UAE PDPL subject to local legal review.
9. Data Retention
We retain personal data for as long as necessary to fulfil the purposes described in this policy, comply with legal obligations, and resolve disputes. The following retention periods apply:
| Data category | Retention period |
|---|---|
| Account data | Duration of account + 30 days post-deletion |
| Profile data | Duration of account |
| Company page data | Duration of account |
| Trade License documents | 12 months after verification decision or account deletion (whichever is later) |
| Verification records | 2 years |
| Payment records | Applicable accounting, tax, and legal retention requirements |
| Consent logs | 5 years |
| Abuse reports and moderation records | 3 years or duration of proceedings, whichever is longer |
| Security logs | 13 months |
| Messages | Until deleted by both parties, except where retained as evidence in active investigations |
| Deleted accounts | Profile and content deleted within 30 days; legally required data retained longer |
| Backups | May retain encrypted data in backups up to 90 days after deletion cycle |
| Anonymized analytics | Retained indefinitely |
⚠️ UAE accounting retention requirements subject to local legal review and may require longer retention periods for certain financial records.
10. Data Breach
In the event of a personal data breach, AMANA will assess the breach, notify affected users and/or competent authorities where required by applicable law, and take appropriate remediation steps.
If you become aware of or suspect a data security incident involving your data, please contact us immediately at contact@amana-uae.com.
11. Security
AMANA implements appropriate technical and organizational measures to protect your personal data. These measures include:
- Encryption of data in transit using TLS (Transport Layer Security)
- Role-based access controls limiting who can view personal data
- Limited admin access with audit logging
- Secure application hosting via Vercel
- Payment data processed exclusively by Stripe under PCI-DSS compliance
No system is completely secure. While we take reasonable precautions, we cannot guarantee absolute security.
12. Your Rights
Under the GDPR (for EEA users) and applicable UAE PDPL requirements, you have rights regarding your personal data. You may exercise any of these rights by contacting us at contact@amana-uae.com. We will respond within 30 days.
Right of access (Art. 15)
Obtain a copy of your personal data and information about how it is processed.
Right to rectification (Art. 16)
Request correction of inaccurate or incomplete personal data.
Right to erasure (Art. 17)
Request deletion of your personal data where no overriding legitimate ground for retention exists.
Right to restriction (Art. 18)
Request that we limit processing of your data in certain circumstances.
Right to data portability (Art. 20)
Receive your data in a structured, machine-readable format and transmit it to another controller.
Right to object (Art. 21)
Object to processing based on legitimate interest, including for direct marketing purposes.
Right to withdraw consent
Withdraw consent for marketing or verification at any time via account settings or by emailing us. Withdrawal does not affect prior processing.
Right to lodge a complaint
UAE supervisory authority: UAE Data Office (uaedataoffice.gov.ae). EU: your national DPA (e.g. CNIL for France).
⚠️ Rights framework under UAE PDPL subject to local legal review.
13. Automated Decision-Making
AMANA does not make decisions producing legal or similarly significant effects on users solely through automated processing of personal data, unless clearly disclosed and permitted by applicable law.
14. Marketing
AMANA sends marketing and promotional communications on an opt-in only basis. We will only send you marketing emails if you have explicitly consented to receive them.
You may withdraw your marketing consent at any time via your account settings or by emailing us at contact@amana-uae.com. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
15. Business Transfers
If AMANA is involved in a merger, acquisition, financing, restructuring, or sale of assets, personal data held by AMANA may be transferred to the relevant successor entity as part of that transaction, subject to appropriate safeguards and notice where required by applicable law.
16. Minors
AMANA is a professional networking platform intended exclusively for individuals aged 18 years and above. We do not knowingly collect, process, or retain personal data from individuals under the age of 18.
If you believe a minor has registered on AMANA or submitted personal data to us, please report this immediately to contact@amana-uae.com.
17. Changes to this Policy
We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' advance notice via email notification or a prominent in-app notice. The updated policy will display a new effective date.
18. Contact and DPO
For any privacy-related questions, data subject rights requests, or complaints, please contact:
Privacy Team & DPO
Denhill International LLC
IFZA Business Park, Dubai Silicon Oasis, Dubai, United Arab Emirates
contact@amana-uae.comSupervisory Authorities
UAE Data Office: uaedataoffice.gov.ae
EEA users — CNIL (France): cnil.fr