Privacy Policy
Effective 15 May 2026. This policy reflects our data-processing practices.
At DocChat, we are fundamentally committed to the protection and lawful processing of personal data. As a B2B platform serving the United Arab Emirates financial sector, we have built our architecture to adhere to the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and other applicable regional regulations, including the DIFC Data Protection Law No. 5 of 2020 where applicable.
1. Who we are
DocChat is a product operated by AgileCatalyst ai LTD, based in the Dubai International Financial Centre (DIFC), United Arab Emirates ("we," "us," "the Company"). This policy explains how we process personal data in connection with the DocChat service (the "Service").
2. Our role
- End-customer data (uploaders): We act as a Data Processor on behalf of the financial institution (the Data Controller) that sent the document request. The institution's own privacy policy governs primary collection and use. We process this data only on the institution's instructions. See our Data Processing Addendum.
- Operator data (institution staff): For account and administrative data of institution users, and for website visitors, we act as Data Controller.
3. Data we process
We collect personal data through your interactions with our Services. The categories of data we collect vary depending on whether you are a Customer Operator or an End-Customer:
- Operator/account data: Name, corporate email address, business phone number, job title, hashed passwords, and billing contact details.
- End-customer data (on behalf of the institution):
- Contact details (email address and/or mobile phone number) provided by the institution to deliver the secure request link.
- Uploaded document files (which may contain Emirates ID details, passport copies, bank statements, etc.). These payloads are encrypted with AES-256; Company personnel do not access document contents in the ordinary course.
- Technical/usage data: IP address, browser/device information, timestamps, and (with consent) analytics on site usage. This supports security, the Cryptographic Audit Chain, and service improvement.
4. How we use data
We use the collected data for specific, defined purposes: to authenticate users; deliver document requests and links; process and store uploads; generate the Cryptographic Audit Chain; send transactional notifications; provide support and billing; and (with consent) run product analytics. We apply strict data minimisation principles throughout.
5. Data residency
Customer documents, uploaded files, and audit records are stored in the Microsoft Azure UAE North region. To deliver the Service, certain limited contact and technical data—such as the email address or phone number used to send a secure link, and IP/usage data—is processed by international service providers (for email, SMS, content delivery, and analytics). See the sub-processor list in our Data Processing Addendum for details and locations.
6. Sub-processors
We use a limited set of sub-processors to deliver the Service. The current list, with purposes and locations, is maintained in our Data Processing Addendum. We bind sub-processors to appropriate confidentiality and security obligations and provide advance notice of changes to Controllers per the DPA.
7. Cookies & analytics
Our marketing website uses cookies for essential functionality and, only with your consent, analytics (Google Analytics and PostHog). You can accept or reject analytics cookies via our consent banner and change your choice anytime via "Cookie Preferences" in the footer. See our Cookie Policy.
8. Data-subject rights (UAE PDPL)
Under the UAE Personal Data Protection Law, individuals are granted specific rights including access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.
- End-customers: Direct your requests to the institution that requested your documents (the Data Controller); we assist the Controller in fulfilling these requests.
- Operators/visitors: Contact us at security [at] docchat.co.
9. Retention
End-customer documents are retained per the Controller institution's configured retention policy; automated deletion tools are provided. Operator data is retained for the contract term, then purged within a defined period, excluding records required to be kept by UAE law.
10. Security
We apply robust technical measures: AES-256 encryption at rest; TLS in transit; HSM-protected keys for audit-chain signing; row-level tenant isolation; malware scanning on upload; and private network paths. See our Security Overview for full details.
11. International transfers
Where contact or technical data is processed outside the UAE by our sub-processors, we rely on appropriate safeguards consistent with the UAE PDPL's cross-border transfer provisions.
12. Children's Privacy
DocChat is a B2B enterprise platform and is not directed at children under the age of 18. We do not knowingly collect personal data from children. If an institution utilizes DocChat to collect documentation related to minors (e.g., for opening a juvenile savings account), the institution is solely responsible for obtaining the verifiable consent of the parent or legal guardian.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. If we make material changes, we will notify Customer Operators via email or a prominent notice within the Operator Console prior to the change becoming effective.
14. Contact Us
If you have any questions, concerns, or complaints regarding this Privacy Policy or our data processing practices, please contact our security and privacy team:
Email: security [at] docchat.co
Address: AgileCatalyst ai LTD, DIFC, Dubai, United Arab Emirates
Data Protection Officer (DPO): Formal Appointment Pending