Privacy Policy

Version 3.0.0Last updated: 2026-06-25

c0m.ae Privacy Policy How c0m.ae collects, uses, and protects your personal data VERSION 3 — UPDATED June 25, 2026

YUSUF MARYAM PROJECT MANAGEMENT SERVICES EST. Trade Licence No. 1389599 2105, Citadel Tower, Business Bay, Dubai, United Arab Emirates Original Effective Date: April 27, 2025 | Version 2: June 14, 2026 Version 3 — Updated: June 25, 2026 | Ref: Legal Briefing #63

UPDATED DOCUMENT — VERSION 3 — June 25, 2026 Updated per Legal Briefing #63. Prior version: June 14, 2026 (BYOK/AI sub-processor correction). Original effective date: April 27, 2025. This update: Explicit cross-border consent mechanism added for AWS Mumbai hosting (PDPL Articles 22-23); Controller/Processor dual-role disclosure added; Data Subject Rights re-mapped to PDPL Articles 13-18; Data Protection Officer (Article 10) policy added.

  1. Introduction YUSUF MARYAM PROJECT MANAGEMENT SERVICES EST. (Trade Licence No. 1389599) is committed to protecting your privacy. This Privacy Policy ("Policy") explains what personal data we collect, why, how we use and protect it, and your rights. This Policy complies with UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL) and its implementing regulations, UAE Federal Law No. 34 of 2021, and UAE Federal Law No. 1 of 2006 on Electronic Commerce and Transactions. By using c0m.ae, you consent to the processing of your personal data as described in this Policy, and where required by Section 7, you will be asked for your explicit, separate consent to specific cross-border transfers before you can complete registration.

  2. Data Controller and Dual-Role Disclosure Data Controller: YUSUF MARYAM PROJECT MANAGEMENT SERVICES EST. Trade Licence No.: 1389599 Address: 2105, Citadel Tower, Business Bay, Dubai, United Arab Emirates Privacy Contact: [email protected] | Legal Contact: [email protected]

2.1 Our Dual Role Under the PDPL NEW DISCLOSURE: The Company acts in two distinct capacities under the PDPL, and the applicable role determines whose instructions govern the data and who bears primary compliance responsibility.

AS A CONTROLLER: in respect of your own account and billing data — your name, email, business registration details, payment and subscription records — the Company is the Data Controller. We determine the purposes and means of processing this data, as described throughout this Policy.

AS A PROCESSOR: in respect of any personal data that YOUR website visitors submit through YOUR Published Site (for example, names and contact details entered into a contact form, or visitor analytics data), the Company acts solely as a Data Processor. You — the Subscriber who built and operates the Published Site — are the Data Controller for that visitor data. We process it only on your instructions, as configured through the Service, and you are responsible for ensuring you have a lawful basis to collect it and for honouring any data rights requests your own website visitors may make to you directly.

This dual-role structure means that if you are a Subscriber building a Published Site that collects visitor data (e.g., via a contact form), you should ensure your own use of that data complies with the PDPL and any other applicable law, as you are the Controller for that data, and the Company is merely your Processor providing the underlying hosting infrastructure.

  1. Personal Data We Collect 3.1 Data You Provide Directly (Controller Role) • Identity data: your name, email address, and profile information from your Google account at Sign-In; • Business information: business name, category, description, services, contact details (including WhatsApp number), address, and operating hours; • Billing data: your subscription plan, billing history, and payment status as communicated to us by Stripe (we do not receive or store your full card number); • User Content: text, images, and other material you upload or approve for publication. 3.2 Data We Collect Automatically • Log data: IP address, browser type, device type, pages accessed, timestamps, HTTP request data; • Usage data: AI generation request counts, template selections, publish events — not the content of AI requests/responses; • Authentication tokens: JWT session tokens in an httpOnly Secure cookie (web) or Expo SecureStore (mobile); • Error and performance data: anonymised crash reports via Sentry, with sensitive-string redaction configured. 3.3 Data Sent for AI Generation When you use 'Fill with AI', business-descriptive information you provide (business name, category, language, and optional context including a free-text 'details' field) is sent to our AI sub-processors. No platform account identifiers (email, user ID, payment data) accompany these requests.

Important — Free-Text Field: The 'details' field accepts unconstrained user input. Although intended for business-descriptive content, a user may enter personal data (e.g., an owner's full name). We cannot guarantee that this field is always free of personal data. This content is transmitted to OpenRouter (US) and processed by DeepInfra (US). You are advised to limit entries in the 'details' field to business-descriptive information.

See Section 6 for the full sub-processor chain and data-flow disclosure. 3.4 Visitor Data on Published Sites (Processor Role) When third parties visit a Published Site on *.c0m.ae, request data passes through Cloudflare's infrastructure. Where your Published Site includes a contact form, WhatsApp button, or similar feature, any personal data your visitors submit through it is collected and processed by the Company strictly as your Processor, on your instructions, for the purpose of delivering that data to you. The Company does not use this visitor data for its own purposes. Site owners are responsible for their own PDPL compliance in respect of any visitor data they independently collect. 3.5 Data We Do Not Collect We do not collect: full payment card numbers; precise geolocation; biometric data; national ID or passport numbers; or data relating to minors under 18.

  1. How We Use Your Personal Data Service delivery (Controller) — account, billing, hosting, AI generation | Legal basis: contractual necessity Hosting visitor-submitted data (Processor) — relaying contact-form/visitor data to the Subscriber | Legal basis: Subscriber's instructions under our Processor agreement (these Terms) Authentication — identity verification, account security | Legal basis: contractual necessity, legitimate interest Billing — subscription management via Stripe | Legal basis: contractual necessity, legal obligation Transactional communications — confirmations, renewal reminders, security notices | Legal basis: contractual necessity Security and fraud prevention | Legal basis: legitimate interest, legal obligation Legal compliance — UAE record-keeping, authority requests, content moderation, .aeDA compliance | Legal basis: legal obligation Service improvement — aggregated, anonymised analysis | Legal basis: legitimate interest

We do not use your data for advertising and do not sell, rent, or broker personal data.

  1. Data Protection Officer (PDPL Article 10) NEW DISCLOSURE: Under PDPL Article 10, a Controller must appoint a Data Protection Officer (DPO) where its core activities involve large-scale systematic monitoring of data subjects, or large-scale processing of sensitive personal data.

As of the effective date of this Policy, the Company's processing activities — a single-page website builder serving small and medium UAE businesses — do not, in the Company's assessment, constitute large-scale systematic monitoring or large-scale sensitive-data processing of the kind that triggers a mandatory Article 10 DPO appointment. The Company does not currently perform automated profiling of data subjects for legal or similarly significant effect. The Company commits to the following: (a) it will continuously monitor its processing volume and the nature of processing (including any future introduction of automated profiling features); (b) if and when its activities reach the Article 10 threshold, the Company will appoint a qualified Data Protection Officer and publish that officer's contact details in an updated version of this Policy within thirty (30) days of the threshold being met; and (c) until such appointment, the Company's designated privacy contact for all PDPL-related matters, including data subject rights requests, is available at [email protected].

  1. AI Data Flow and Sub-Processor Chain 6.1 The Sub-Processor Chain When you use 'Fill with AI', the data flow is: your device (UAE) → AWS Mumbai, India (platform hosting) → OpenRouter, Inc. (US, routing layer) → DeepInfra, Inc. (US, Google Gemma model serving). 6.2 OpenRouter Configuration Zero Data Retention (ZDR): ENFORCED Paid/free endpoints permitted to train on data: OFF Free endpoints permitted to publish prompts: OFF 1% data-discount (product improvement use): OFF Upstream model provider: DeepInfra, US region, 'No training' designation

The Company retains only token-count metadata for billing reconciliation — not prompt or completion content. 6.3 Absence of a Formal DPA with OpenRouter Disclosure: As of the effective date of this Policy, the Company does not hold a signed Data Processing Agreement with OpenRouter. The ZDR and no-training settings are account configurations enabled by the Company, not contractual guarantees from OpenRouter. The Company is pursuing a formal DPA and, in the interim, advises Users to avoid entering personal data into the free-text 'details' field used in AI generation requests.

  1. Cross-Border Data Transfer and Your Explicit Consent MANDATORY EXPLICIT CONSENT — PDPL ARTICLES 22 AND 23

c0m.ae is a UAE-based platform. However, due to regional infrastructure instability affecting the UAE AWS region, the Company migrated its hosting infrastructure from AWS Abu Dhabi to AWS's ap-south-1 region (Mumbai, India). Your personal account data — including identity, business, and billing data described in Section 3 — is currently stored and processed on servers located in India, outside the United Arab Emirates. This measure is intended to ensure operational continuity and the integrity of your data during a period of regional infrastructure instability.

In addition, as described in Section 6, certain AI generation requests are further transferred from India to the United States (OpenRouter and DeepInfra).

Under PDPL Articles 22 and 23, transferring personal data outside the UAE requires either: (a) a recognised adequate level of data protection in the receiving jurisdiction; (b) a bilateral or multilateral agreement to which the UAE is a party covering the transfer; or (c) your explicit consent to the specific transfer. Because neither (a) nor (b) can currently be confirmed for the India hosting region, the Company relies on your EXPLICIT CONSENT for this transfer.

At sign-up, you will be presented with a distinct, separate consent step — not bundled into general Terms acceptance — that specifically describes this cross-border transfer to India (and, for AI features, onward to the United States) and asks you to affirmatively consent before your account is created. You may withdraw this consent at any time by closing your account, which will result in the deletion of your data per the retention schedule in Section 9. Withdrawing consent without closing your account is not possible, because cross-border hosting is currently structurally necessary to operate the Service.

The Company implements appropriate technical and contractual safeguards for all international transfers. Data processing agreements are in place with AWS, Cloudflare, Stripe, Resend, and Sentry governing their processing of personal data on the Company's behalf. A formal DPA with OpenRouter is not yet in place (see Section 6.3); the DeepInfra transfer is governed downstream by OpenRouter's Zero Data Retention obligations.

The Company is actively working to migrate hosting infrastructure back to a UAE-based AWS region (me-central-1) once that region is confirmed stable. You will be notified by email when this migration is complete, at which point this cross-border consent requirement for hosting (though not necessarily for the AI flow described in Section 6) may no longer apply.

  1. Third-Party Service Providers 8.1 Amazon Web Services, Inc. (AWS) Purpose: Cloud infrastructure. Data shared: all account and user data. Current region: ap-south-1 (Mumbai, India) — see Section 7 for the explicit consent basis for this transfer. Governed by a Data Processing Agreement with the Company. 8.2 Cloudflare, Inc. Purpose: CDN, DNS, DDoS protection, WAF, SSL/TLS. Data shared: IP addresses and HTTP request metadata only. Governed by a Data Processing Agreement with the Company. 8.3 Google LLC Purpose: Google Sign-In authentication and Search Console integration. Data shared: your Google account ID, name, and email at Sign-In. 8.4 OpenRouter, Inc. (United States) Purpose: AI request routing. Data shared: business-descriptive AI generation content (Section 6). ZDR enforced; no account identifiers shared. No formal DPA currently in place — see Section 6.3. 8.5 DeepInfra, Inc. (United States) Purpose: Upstream AI model serving (Google Gemma family). Data shared: AI prompt content routed via OpenRouter, under a 'No training' configuration. 8.6 Stripe, Inc. Purpose: Payment processing, invoicing, billing portal. Stripe is our current and sole payment gateway. Data shared: your email address and subscription details. Stripe handles all card data directly under its own PCI-DSS compliance programme; the Company never receives your full card number. Governed by a Data Processing Agreement with the Company. 8.7 Resend, Inc. Purpose: Transactional email delivery. Data shared: your email address and transactional content only. No marketing emails are sent. Governed by a Data Processing Agreement with the Company. 8.8 Sentry Technologies, Inc. Purpose: Application error monitoring. Data shared: anonymised crash reports, with sensitive-string redaction configured. Governed by a Data Processing Agreement with the Company. 8.9 Tabby FZ-LLC / Network International Purpose: Alternative payment processing (post-launch only, when enabled).

  2. Data Retention Active account: retained for the Subscription duration and any pending-deletion period Post-cancellation / post-termination: 30 calendar days from account closure (dispute resolution) Financial records (invoices, payment records): minimum 10 years — UAE Federal Law No. 18 of 1993 Security and fraud logs (IP addresses, access logs): 90 days rolling AI generation metadata (token counts only — no content): 90 days rolling AI prompt and completion content: not retained beyond the streamed response Visitor data submitted through Published Sites (Processor role): retained per the Subscriber's own configuration and instructions; deleted upon Subscriber account closure per the 30-day window above

  3. Your Data Subject Rights (PDPL Articles 13–18) 10.1 Right to Be Informed (Article 13) You have the right to receive clear information about how your personal data is collected, used, and shared. This Policy is our primary mechanism for fulfilling that right; you may also request further detail at [email protected]. 10.2 Right of Access (Article 14) You may request a copy of the personal data we hold about you. We will respond within thirty (30) days of a verified request. 10.3 Right to Rectification (Article 15) You may request correction of inaccurate or incomplete data. Most data can be corrected directly in your account settings. 10.4 Right to Erasure — "Right to Be Forgotten" (Article 16) You may request deletion of your personal data at any time. Requests will be fulfilled within thirty (30) days, subject to our legal retention obligations under Section 9 (for example, financial records required to be kept for ten (10) years cannot be deleted on request). Closing your account constitutes a request for erasure under this right. 10.5 Right to Restrict or Object to Processing (Article 17) You may request that we restrict or stop processing your personal data in certain circumstances — for example, while a dispute about data accuracy is being resolved, or where processing is based on our legitimate interest and you object to it on grounds relating to your particular situation. This right does not apply to processing necessary for performance of our contract with you (such as core billing) or for compliance with a legal obligation. 10.6 Right to Data Portability (Article 18) You may receive your personal data in a structured, commonly used, machine-readable format. You may export your Published Site data in JSON format through your account dashboard, or request a fuller export at [email protected]. 10.7 Exercising Your Rights Submit a written request to [email protected] with subject line "PDPL Data Rights Request" including your account email. We will verify your identity and respond within thirty (30) calendar days, extendable by a further thirty (30) days for complex requests with prior notification to you. 10.8 Complaint to Supervisory Authority You may lodge a complaint with the UAE competent authority on personal data protection if you believe your rights under the PDPL have been violated and we have not adequately addressed your concern.

  4. Security Measures • TLS 1.3 encryption for all data in transit; • Cloudflare SSL Full (Strict) mode across the delivery chain; • Parameterised database queries via Prisma ORM; • JWT-based authentication with strict expiry and refresh; • Rate limiting on all API endpoints, including AI generation (20 requests/user/hour); • Cloudflare WAF with IP-level rate limiting on AI endpoints; • Cloudflare Zero Trust with multi-factor authentication (TOTP) for admin systems; • Sentry configured with sensitive-string scrubbing filters; • No request body logging in web server access logs. In the event of a personal data breach likely to result in risk to your rights, we will notify the competent UAE authority within seventy-two (72) hours and affected users without undue delay, per PDPL Article 26.

  5. Cookies and Tracking Technologies Web sessions use a single strictly-necessary httpOnly, Secure, SameSite session cookie ("platform_session"). The mobile application uses Expo SecureStore instead of cookies. We do not use advertising or analytics tracking (no Google Analytics, Facebook Pixel, or similar). c0m.ae is an advertising-free, tracking-free platform.

  6. Children's Privacy The Service is restricted to users aged eighteen (18) or older. We do not knowingly collect data from individuals under 18 and will delete any such data immediately upon discovery.

  7. Changes to This Policy We will notify you of material changes by email no fewer than fourteen (14) days before they take effect, and will request fresh explicit consent under Section 7 where a change affects the nature or destination of a cross-border transfer.

  8. Contact Privacy Enquiries / PDPL Rights Requests / DPO Matters: [email protected] Legal Enquiries: [email protected]

YUSUF MARYAM PROJECT MANAGEMENT SERVICES EST. Trade Licence No. 1389599 2105, Citadel Tower, Business Bay, Dubai, UAE

Response target: 5 business days for privacy enquiries

This Privacy Policy was originally effective April 27, 2025, corrected June 14, 2026, and updated to Version 3 on June 25, 2026 pursuant to Legal Briefing #63.