Privacy Policy
Effective: 14 August 2026
This Privacy Policy explains what personal data Zakomo FZCO ("we") collects when you use TenderYeti, why we collect it, and the rights you have over it. Zakomo FZCO is a company registered in Dubai, United Arab Emirates, and TenderYeti's servers are hosted in the UAE. Our primary legal framework is the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, "PDPL"). Where a customer resides in a jurisdiction with stronger local rights — notably California (CCPA/CPRA) or the EEA/UK (GDPR) — we honor those rights on request even though we are not a data controller established in those jurisdictions.
1. Data We Collect
- Account data — email address, name, company name, hashed password, chosen role.
- Configuration data — keywords, saved searches, notification preferences, AI relevance thresholds you set.
- Usage data — dashboard interactions, API requests, IP address at login for security and rate-limiting.
- Billing data — processed by Paddle; we receive customer ID, subscription status, and invoice metadata. We do not store card numbers.
- Support communications — the content of emails you send to support and any attachments.
2. Why We Use It
- To deliver the Service (match tender notices to your keywords, send digests).
- To bill you and comply with tax and accounting obligations.
- To secure the Service (detect abuse, brute-force attempts, unauthorized access).
- To provide support when you contact us.
- To send service announcements (billing changes, security incidents, planned maintenance). Marketing emails are opt-in only.
3. Legal Basis for Processing
Under the UAE PDPL (and the analogous provisions of GDPR / CCPA where they apply):
- Contract necessity — we process account, configuration, and usage data because it's required to deliver the Service you subscribed to.
- Legitimate interest — we process security and abuse-prevention data to protect the Service and our other customers.
- Legal obligation — we retain billing records to comply with UAE tax and accounting law (Federal Tax Authority requirements).
4. Third-Party Processors
We share personal data with the following service providers, each under a written data-processing agreement:
- Paddle.com Market Ltd. — payment processing, invoicing, tax computation.
- Cloudflare, Inc. — content delivery, DDoS protection, DNS.
- Neue Medien Muennich GmbH (All-Inkl.com) — outbound transactional email delivery.
- Anthropic, PBC / OpenAI, L.L.C. — where you enable AI relevance scoring; only tender text (public) plus your keywords are sent, never account or billing data.
We do not sell personal data. We do not share it for third-party advertising.
5. Hosting and International Transfers
The TenderYeti application and its primary database are hosted in the United Arab Emirates. Some third-party processors listed above operate infrastructure outside the UAE (Paddle in the United Kingdom; Cloudflare's global edge network; Anthropic/OpenAI in the US when AI relevance scoring is enabled). For personal data of EEA/UK residents, any onward transfer relies on the processor's own adequacy mechanism (EU-US Data Privacy Framework or Standard Contractual Clauses); for UAE and international customers, transfers are governed by the UAE PDPL cross-border-transfer rules and each processor's contractual safeguards.
6. Retention
- Account and configuration data: retained while your account is active, then 30 days after cancellation for possible reactivation.
- Usage / security logs: 90 days.
- Billing records: 7 years (UAE tax retention obligation).
7. Your Rights
Under the UAE PDPL — and additionally under CCPA/CPRA (California residents) or GDPR (EEA/UK residents) where those apply — you have rights to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and associated data (subject to legal retention obligations, e.g. invoices).
- Export your data in a structured, machine-readable format.
- Object to or restrict certain processing.
- Lodge a complaint with the UAE Data Office (primary regulator) or, if you reside in the EEA/UK/California, with your local data-protection authority.
Contact [email protected] to exercise any of these rights. We respond within 30 days as required by the UAE PDPL.
8. Cookies and Tracking
We use only strictly necessary cookies — a session cookie and a persistent authentication token — to keep you logged in. We do not use analytics, advertising, or cross-site tracking cookies.
9. Security
Passwords are hashed with bcrypt. Traffic is encrypted in transit via TLS. Sensitive fields at rest are encrypted with database-level or column-level encryption. Rate limiting and IP-based lockout defend against brute-force attacks. We disclose material security incidents affecting your data within 72 hours of discovery.
10. Children
The Service is a business tool and is not directed at, nor intended for use by, individuals under 18. We do not knowingly collect data from minors.
11. Changes
Material changes to this Policy will be notified by email at least 14 days before they take effect. The effective date at the top of this page reflects the current version.