Privacy Policy

Effective: 14 August 2026

This Privacy Policy explains what personal data Zakomo FZCO ("we") collects when you use TenderYeti, why we collect it, and the rights you have over it. Zakomo FZCO is a company registered in Dubai, United Arab Emirates, and TenderYeti's servers are hosted in the UAE. Our primary legal framework is the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, "PDPL"). Where a customer resides in a jurisdiction with stronger local rights — notably California (CCPA/CPRA) or the EEA/UK (GDPR) — we honor those rights on request even though we are not a data controller established in those jurisdictions.

1. Data We Collect

2. Why We Use It

3. Legal Basis for Processing

Under the UAE PDPL (and the analogous provisions of GDPR / CCPA where they apply):

4. Third-Party Processors

We share personal data with the following service providers, each under a written data-processing agreement:

We do not sell personal data. We do not share it for third-party advertising.

5. Hosting and International Transfers

The TenderYeti application and its primary database are hosted in the United Arab Emirates. Some third-party processors listed above operate infrastructure outside the UAE (Paddle in the United Kingdom; Cloudflare's global edge network; Anthropic/OpenAI in the US when AI relevance scoring is enabled). For personal data of EEA/UK residents, any onward transfer relies on the processor's own adequacy mechanism (EU-US Data Privacy Framework or Standard Contractual Clauses); for UAE and international customers, transfers are governed by the UAE PDPL cross-border-transfer rules and each processor's contractual safeguards.

6. Retention

7. Your Rights

Under the UAE PDPL — and additionally under CCPA/CPRA (California residents) or GDPR (EEA/UK residents) where those apply — you have rights to:

Contact [email protected] to exercise any of these rights. We respond within 30 days as required by the UAE PDPL.

8. Cookies and Tracking

We use only strictly necessary cookies — a session cookie and a persistent authentication token — to keep you logged in. We do not use analytics, advertising, or cross-site tracking cookies.

9. Security

Passwords are hashed with bcrypt. Traffic is encrypted in transit via TLS. Sensitive fields at rest are encrypted with database-level or column-level encryption. Rate limiting and IP-based lockout defend against brute-force attacks. We disclose material security incidents affecting your data within 72 hours of discovery.

10. Children

The Service is a business tool and is not directed at, nor intended for use by, individuals under 18. We do not knowingly collect data from minors.

11. Changes

Material changes to this Policy will be notified by email at least 14 days before they take effect. The effective date at the top of this page reflects the current version.

Data Controller Zakomo FZCO
Dubai, United Arab Emirates
Email: [email protected]