Privacy Policy

Last updated: 2026-04-20 · Version 1.0

سياسة الخصوصية

آخر تحديث: 2026-04-20 · الإصدار 1.0

1. Who we are

Devanza is a salon-booking and salon-management platform operated by DEVURA FZ LLE, a Limited Liability Establishment registered in the Fujairah Creative City Free Zone, United Arab Emirates.

  • Legal entity: DEVURA FZ LLE
  • Trade licence number: 16097/2020
  • Free-zone authority: Fujairah Creative City Free Zone Authority (Media Free Zone)
  • Registered address: Twin Towers, P.O. Box 4422, Fujairah, UAE
  • Executive Director: Haneen Omar Amin Taha
  • Licensed activity: IT Consultancy, Portal Services
  • Data Protection Officer (DPO): Majdi Mohammad, Chief Technology Officer — m.mohammad@devura.com
  • Privacy contact: privacy@devura.com
  • General contact: info@devura.com

DEVURA FZ LLE is the Controllerof your personal data within the meaning of UAE Federal Decree-Law No. 45 of 2021 ("PDPL"). This Policy explains what data we collect, why we collect it, how we use and protect it, and the rights you have as a data subject.

2. Personal data we collect

We collect only data necessary to provide and improve the Devanza service. Categories:

a. Account data

Full name, mobile number, email address, profile photo (optional), preferred language, city.

b. Authentication data

Hashed password (if using password login), OAuth subject identifiers from Google, Apple, or Facebook (if using social sign-in), one-time SMS codes, and device-bound public keys if you enable biometric unlock.

c. Booking data

Appointment dates, selected salon and branch, services booked, staff selected, notes you add, "Booking for: Self / Child" flag, optional child first name (if you book for a child — see Section 10).

d. Location data

Coarse location (city / area) for nearby-salon discovery. Precise GPS only while the map picker is open and only with your permission; it is not stored after the session ends.

e. Device and diagnostic data

Device model, operating system version, app version, locale, anonymous install identifier, crash stack traces, performance metrics.

f. Communications data

Messages you send to support, your complaints, and your feedback.

g. Payment data (future)

When Stripe is enabled, Stripe processes your card details directly. Devanza stores only the last four digits, card brand, expiry, and Stripe customer / payment-method identifiers. Devanza never stores your full card number or CVC.

h. Consent log

Timestamped record of which version of the Privacy Policy and Terms you accepted, and whether you opted in to marketing.

We do not collect: government ID numbers, biometric templates (biometric authentication uses on-device secure enclaves; no template leaves your device), race or religion, health data beyond the service category you book.

3. Purposes and lawful bases (PDPL Art. 5)

PurposeData usedLawful basis (PDPL Art. 5)
Creating and securing your accountAccount + authentication dataPerformance of a contract
Taking and managing your bookingsBooking + account dataPerformance of a contract
Sending OTP codes for login and confirmationMobile numberPerformance of a contract
Showing nearby salonsCoarse / session-only precise locationYour consent
Diagnosing crashes and improving stabilityDevice / diagnostic dataLegitimate interest in secure operation
Preventing fraud and abuseAll categories as neededLegitimate interest / legal obligation
Marketing emails and push notificationsEmail, push token, preferencesYour consent (optional, separate)
Tax and accounting records (when payments launch)Transaction dataLegal obligation
Responding to a data-subject rights requestAs needed to verify and respondLegal obligation
Responding to a lawful request from a UAE authorityAs specified in the lawful requestLegal obligation

4. Recipients and processors

We share personal data only with service providers ("Processors") bound by written contracts that restrict them to processing on our instructions:

  • Microsoft Azure (hosting of application and databases — primary region Azure UAE North)
  • Twilio (OTP and SMS delivery; routed through US / EU edge infrastructure)
  • Google, Apple, Facebook (social sign-in identity providers; only the OAuth subject identifier and the scopes you approve)
  • Stripe (future — card payments; Stripe is an independent controller for payment-network compliance)
  • Expo / Google Firebase Cloud Messaging / Apple Push Notification service (delivery of push notifications you have opted into; device push tokens only)
  • Error monitoring and analytics (aggregated, device-level — no personal content of messages)

We do not sell personal data. We do not share data with advertising networks.

5. Cross-border transfers

Your personal data is primarily hosted in Microsoft Azure UAE North (Dubai). However, some processors route traffic or store operational data outside the UAE:

  • Twilio — OTP and SMS traffic may transit US and EU edge routes to reach the correct telecom operator.
  • Microsoft Azure — backup, identity, and platform services may involve Microsoft's global infrastructure.
  • Google, Apple, Facebook — social sign-in metadata is exchanged with servers in the United States.
  • Stripe (future) — payment processing involves Stripe's global infrastructure (primarily the United States and the EU).

These transfers are necessary to deliver the Service. They are governed by data-processing agreements with each provider containing appropriate contractual safeguards (including standard data-protection clauses) in line with PDPL Articles 22–23. Where the destination jurisdiction does not have an adequacy decision, we rely on contractual safeguards and processor certifications (ISO/IEC 27001, SOC 2).

6. Retention periods

We retain personal data no longer than necessary.

CategoryRetention
Active account dataUntil you delete your account
Booking history5 years from booking date (tax and dispute record)
Consent log7 years post account closure (legal obligation)
OTP codes5 minutes
Device / crash diagnostics90 days
Support conversations2 years from last message
Marketing preferencesUntil you withdraw consent, plus 30 days
Soft-deleted account30 days (reversible), then hard delete
Payment records (future)5 years (tax law)

After the retention period ends, data is hard-deleted or irreversibly anonymised.

7. Your rights under PDPL

Under Articles 13–18 of the PDPL you have the following rights:

  • Right of access — obtain a copy of your personal data.
  • Right of rectification — correct inaccurate data.
  • Right of erasure — request deletion of your data (subject to legal retention obligations).
  • Right of objection — object to processing based on legitimate interest.
  • Right of portability — receive your data in a structured, machine-readable format.
  • Right of restriction — ask us to pause processing while a request is being handled.
  • Right to withdraw consent — at any time, for processing that relies on consent.
  • Right to lodge a complaint — with the UAE Data Office (Section 13).

To exercise any right, email privacy@devura.com from the address linked to your account, or write from within the app via Settings → Privacy → Contact us. We will:

  1. Acknowledge within 72 hours.
  2. Verify your identity (phone or email match plus OTP).
  3. Respond substantively within 30 days of verification.

If we cannot fulfil a request (for example, erasure that conflicts with a legal retention duty), we will explain why and tell you what portions we can still honour.

9. Security measures

We protect your data with layered controls:

  • Encryption at rest — personal data encrypted in Azure-managed storage.
  • Encryption in transit — TLS 1.3 with certificate pinning (SSL pinning) on mobile.
  • Secure on-device storage — tokens and sensitive values stored in iOS Keychain / Android Keystore via expo-secure-store; never in plain storage.
  • Biometric authentication — if enabled, uses device secure-enclave public-key cryptography; no biometric template ever leaves your device, and DEVURA never sees your fingerprint or face.
  • Rate limiting — throttling on login, OTP, and password-reset endpoints to prevent brute-force abuse.
  • Audit logs — access to personal data by our staff and automated systems is logged; logs use HMAC-hashed identifiers so that raw personal data does not appear in log tooling.
  • Access control — least-privilege access for staff; production database access logged and reviewed.
  • Vulnerability management — dependency and container scanning on every build; monthly penetration testing cadence in line with internal policy.
  • Incident response — documented runbook with a 72-hour breach-notification target to the UAE Data Office in line with PDPL Article 9.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify you and the UAE Data Office without undue delay.

10. Children

Devanza is an adult-only service. You must be 18 years or older to create an account.

We use a parent-booking model (Model A):

  • There are no child sub-profiles.
  • A parent books on their own adult account and marks each booking with the flag "Booking for: Self / Child".
  • If the booking is for a child, the parent may optionally provide the child's first name only so the salon knows who to expect.
  • We do not collect the child's date of birth, national ID, photograph, contact details, or any other personal data.
  • The parent remains the data subject and the accountholder.

If we learn that an account was created by a person under 18, we will suspend the account and delete the data within 30 days.

11. Automated decision-making

Devanza does not use automated decision-making or profiling that produces legal or similarly significant effects on you. All bookings are confirmed by the salon (or their staff) and there is no algorithmic approval, scoring, or denial in version 1 of the Service.

If this changes in a future version, we will update this Policy and request fresh consent.

12. Changes to this Policy

We may update this Policy as the Service evolves. For material changes (new data categories, new purposes, new processors outside the current list, changes in retention) we will:

  1. Publish the new version at /legal/privacy.
  2. Compute a content hash of the new version.
  3. Show an in-app prompt at next launch asking you to review and re-consent.
  4. Send an email summary for material changes.

For minor editorial fixes we will update the version number and the "Effective date" at the top without prompting re-consent.

You can view prior versions by writing to privacy@devura.com.

13. Complaints

If you believe we have not handled your personal data lawfully, you have the right to complain.

First, please contact us at privacy@devura.com — we treat every complaint as an inbound data-subject rights request and aim to resolve it within 30 days.

If you remain dissatisfied, you may address a complaint to the UAE Data Office (under the Ministry of Cabinet Affairs) via the public contact channel at u.ae/en/help/contact-us.

14. Contact

  • Data Controller: DEVURA FZ LLE
  • Registered address: Twin Towers, P.O. Box 4422, Fujairah, UAE
  • Privacy team: privacy@devura.com
  • Data Protection Officer: Majdi Mohammad — m.mohammad@devura.com
  • General enquiries: info@devura.com

We respond to all privacy enquiries within 72 hours and resolve substantive requests within 30 days.