Tajdeed Privacy Policy
Effective date: 7 September 2026 Operator (data controller for the service): OpsBreak Technologies FZ-LLC (RAKEZ services licence no. 47034938), CWEP4830 Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates ("OpsBreak Technologies", "we", "us") Contact: support@opsbreak.ae (subject "Privacy request")
Plain-language notice. This policy was written by the Tajdeed team to describe what the service actually does on 7 September 2026. It has not yet been reviewed by legal counsel; a UAE-qualified lawyer will review it and we will publish any change here with a new effective date. Where we describe legal rights we do so in good faith, not as legal advice.
1. Who we are and what this covers
Tajdeed (تجديد) is a document expiry and renewal tracker for people and businesses in the UAE. You record documents such as an Emirates ID, residence visa, Mulkiya (vehicle registration), driving licence, trade licence or tenancy contract, either by typing the details or by uploading a photo or PDF that our AI extraction reads for you. Tajdeed stores the record and emails you before the expiry date.
This policy covers the Tajdeed website and web app at tajdeed.opsbreak.ae and the Tajdeed Android app (beta). There is no iOS app yet. Tajdeed is not a government service and is not affiliated with ICP, GDRFA, RTA, MOHRE, DHA, DLD, RAKEZ or any other authority.
We process personal data under UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL") and its implementing rules. Our hosting providers in the European Union are additionally subject to EU data-protection law for their own handling of data.
2. What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Account data | Email address, name, optional phone number, language preference, password (stored only as a bcrypt hash), email-verification status | You, at sign-up and in Settings |
| Google sign-in data (when enabled and you choose it) | Google account identifier, verified email address and basic profile name; a short-lived login transaction | Google after your sign-in consent |
| Organisation data | Organisation or family name, kind (family or business), plan, seats, reminder preferences (for example "reminders paused") | You |
| Members and invitations | Email addresses and roles of people you invite to your organisation | You (the inviter) and the invitee |
| Document images and PDFs | Photos, scans or PDFs of documents you choose to upload | You |
| Extracted and typed fields | Document type, title, holder name, document number (this can include Emirates ID numbers, passport numbers, plate numbers and licence numbers), issuing authority, issue date, expiry date, notes, an AI confidence score, and the raw AI output for the scan you confirmed | Generated by AI extraction from your image and then confirmed or corrected by you, or typed by you |
| Subjects | Names and short notes about the people, vehicles, companies or properties you track (for example an employee's name or a car's plate) | You |
| Reminder and delivery data | Which reminders were scheduled, sent, delivered, bounced or failed, the email provider's message id, and the weekly digest history | Generated by the service; delivery events come from Amazon SES |
| Renewal history | Previous expiry dates and numbers when you mark a document as renewed | You |
| Usage counters | Number of AI scans used per month per organisation | Generated by the service |
| Billing data | Plan, subscription status and, once card payments are live, a Stripe customer id. Until then, invoices and bank-transfer references are kept in our accounting records. We never see or store your full card number. | You; Stripe |
| Technical and security data | IP address (as forwarded by our hosting proxy), browser or app version, request logs, error logs, rate-limit counters, session records (creation, expiry, revocation), an audit log of security-relevant actions (login, invitations, deletion) | Collected automatically |
| Support correspondence | Emails you send to support@opsbreak.ae | You |
We do not ask for, and you should not upload, data you are not entitled to share. If you upload documents belonging to employees, family members or clients, you are responsible for having a lawful basis to do so (section 10).
3. Why we use your data (purposes and legal basis)
| Purpose | Data used | Basis under the PDPL |
|---|---|---|
| Create and run your account, sign you in, keep sessions revocable | Account data, session records | Performance of our contract with you |
| Read expiry dates and other fields from uploaded documents | Document images, extracted fields | Performance of our contract (the core service) |
| Store your documents and files so you can find them later | Document images, extracted and typed fields, subjects | Performance of our contract |
| Send renewal reminders and the weekly digest by email | Reminder data, verified email address, document title, type and expiry date | Performance of our contract; you can pause reminders in Settings |
| Let you invite members to your organisation | Members and invitations | Performance of our contract |
| Export your data (JSON, CSV, calendar feed) | Your organisation's records | Performance of our contract; your right to data portability |
| Enforce plan limits and AI scan quotas, prevent abuse | Usage counters, technical data | Performance of our contract; our legitimate interest in running a safe, affordable service |
| Take payment and keep financial records | Billing data | Performance of our contract; legal obligation to keep accounting and tax records |
| Keep the service secure, detect fraud, fix bugs | Technical and security data, audit log | Our legitimate interest in running a secure service; legal obligation to protect personal data |
| Answer your questions | Support correspondence | Performance of our contract; our legitimate interest |
| Comply with UAE law, respond to lawful requests | Any | Legal obligation |
We do not sell personal data, do not use it for advertising and do not build profiles of you for third parties. We do not send marketing emails today; if we start, they will be opt-in with an unsubscribe link in every email.
4. AI processing
When you choose Scan with AI, the image or PDF you selected (and a fixed instruction prompt) is sent to a vision model that returns the fields as text. Only the file you chose is sent; we do not send your name, email or account details with it.
- Configured provider: Amazon Bedrock, using the regional Anthropic Claude Haiku model in AWS Frankfurt (eu-central-1). The UAE testing account is awaiting AWS access approval, so AI extraction is not yet available there. The current configuration does not use a cross-region inference profile. Manual document entry remains available.
- Alternative provider: our software can also call Anthropic's own API directly (Anthropic, PBC, United States). This is not enabled in production. If we ever switch it on, we will update this policy first, including the transfer basis, because Anthropic would then process images outside the EU and UAE.
- What we keep: the extracted text you confirmed and, for your reference, the raw extraction result for that scan. Photos are downscaled in your browser before upload (longest side about 2,000 px) to reduce the data sent.
- Quotas: each organisation has a monthly AI scan allowance. The counter is kept per organisation and month; deleting documents does not reset it.
- AI can be wrong. You must check every extracted date against the original document before saving (see the Terms of Service).
If you prefer not to use AI extraction, choose Enter details manually. No file is sent to the AI provider in that case. You can also save a document without any file: only the dates and details are kept.
5. Where your data is stored and who else handles it
Tajdeed runs on Amazon Web Services (AWS). There is no Supabase, Vercel or Resend in the production service.
| Component | Service and region | What it holds |
|---|---|---|
| Application servers | Amazon EC2 with a Caddy web proxy, Frankfurt (eu-central-1) | Runs the website, web app and API; request logs |
| Database | Amazon RDS for PostgreSQL 16, Frankfurt (eu-central-1), in a private network reachable only from the application, encrypted at rest, TLS with server verification in transit | Accounts, organisations, members, documents' fields, subjects, reminders, sessions, audit log, usage counters |
| File storage | Amazon S3, Frankfurt (eu-central-1), private bucket, server-side encryption | Uploaded document images and PDFs, under a key that contains only your organisation id and the document id |
| Email sending | Amazon SES, Frankfurt (eu-central-1) | To send an email, the recipient address, subject and body are transmitted to SES in Frankfurt. The testing account currently has SES sandbox sending restrictions. Reminder emails contain the document title (which may include a holder's first name), document type, expiry date and any document number masked to its last four characters; account emails contain your address and a one-time link. SES also returns delivery, bounce and complaint events to us |
| AI extraction | Amazon Bedrock, regional Claude Haiku in eu-central-1 (access approval pending) | The file you chose to scan, for the duration of the request only (section 4) |
| Secrets and configuration | AWS Systems Manager Parameter Store, eu-central-1 | Our own credentials, not your data |
| Backups | Amazon RDS automated backups, eu-central-1, encrypted | Copies of the database (section 6) |
Other organisations that receive data:
| Recipient | Role | Data |
|---|---|---|
| Amazon Web Services EMEA SARL / Amazon Web Services, Inc. | Processor (hosting, storage, email, AI inference) | Everything above, in the regions listed |
| Anthropic, PBC | Model provider behind Bedrock; does not receive your data under Bedrock's terms | None, unless the direct API is enabled (section 4) |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Processor for card payments and invoices, once card payments are switched on | Name, email, plan, card details (entered on Stripe's own pages, never on ours) |
| Google (optional sign-in provider) | Authenticates your Google account when you choose Google sign-in | Google provides your account identifier, verified email and basic profile name. Login does not request access to Gmail, Drive, Calendar or your documents. Google handles its own sign-in under its Privacy Policy. |
| Our accountant or bank | Legal record-keeping for invoices paid by bank transfer | Company name, contact name, invoice amount |
| A UAE court or competent authority | Where we are legally required to disclose | Only what the lawful request covers |
Each processor is bound by a data-processing agreement or equivalent published terms (the AWS Data Processing Addendum and Stripe's Data Processing Agreement). We do not use advertising networks, tracking pixels, third-party analytics scripts or social-media plug-ins on the website or in the app.
Cross-border transfers (PDPL Articles 22 and 23)
The application database, files and configured email-sending service are hosted outside the UAE, in Frankfurt, Germany. Optional Google sign-in is also handled by Google under its own privacy policy. Under the PDPL, personal data may be transferred outside the UAE to a country that provides an adequate level of protection, or, where no adequacy decision applies, with appropriate safeguards such as a contract that obliges the recipient to protect the data to the PDPL's standard, or with your explicit consent for a specific transfer.
- EU hosting: Germany is subject to the EU General Data Protection Regulation, which we consider to provide an adequate level of protection; our contract with AWS (the AWS DPA, including its standard contractual clauses) provides the contractual safeguards.
- Email sending: Amazon SES in Frankfurt receives the email fields described above. Mail subsequently travels to the recipient's email provider, which may process it in other countries.
- No AWS UAE region is used today. We may host in the AWS Middle East (UAE) region in future where a customer or regulation requires in-country storage; we will state the active region here.
By creating an account you acknowledge these transfers. Business customers who need an in-country arrangement should contact us before uploading employee data.
6. How long we keep data
| Data | Retention |
|---|---|
| Document files (images, PDFs) | For as long as the document exists. When you delete a document, its file is deleted from S3 in the same request; if S3 is temporarily unreachable the deletion is recorded and retried automatically until it succeeds. When you delete your account, every file under your organisation is deleted before the account rows are removed. |
| Extracted and typed fields, subjects, renewal history | Until you delete the document, the subject or your account. |
| Temporary uploads | Files that were uploaded but never attached to a saved document are deleted within 24 hours. |
| Account, organisation and member data | Until you delete your account (Settings, or by email). Deletion is immediate in the live database. |
| Reminder and delivery records | Deleted with the document or account. Delivery events from SES are kept up to 12 months for troubleshooting, then deleted. |
| Sessions | 30 days, or until you log out or revoke them. |
| Google account link | Kept with your application account and removed when that account is deleted. Google access and refresh tokens are not retained. |
| Google login transaction | Expires after ten minutes and is consumed when the callback is handled. Expired transaction rows are cleaned up when another Google login flow starts. |
| Audit log | Up to 12 months; entries for a deleted organisation refer to it only by id. |
| Usage counters (AI scans) | Per month; kept for the current and previous 12 months for billing disputes. |
| Billing records (invoices, amounts, dates) | 5 years, as required by UAE commercial and tax record-keeping rules; held by Stripe (when used) and in our accounting records. |
| Server logs and error logs | Up to 90 days. |
| Backups | The current testing database keeps encrypted automated backups for one day. A deleted record can survive in a backup for that period and is never restored to the live service except to recover from a failure. |
Free accounts inactive for more than 18 months may be closed after two email notices, and their data deleted.
7. Your rights and how to exercise them
Under the PDPL you can ask us to:
- Access the personal data we hold about you and receive a copy.
- Correct inaccurate data (you can edit most fields directly in the app).
- Delete your data. You can delete individual documents (with their files) in the app at any time, and delete your whole account and organisation from Settings → Your data → Delete my account (owners), or by emailing us. Members can ask the owner or us.
- Port your data: Settings → Your data gives a full JSON export; a CSV export and a calendar (ICS) feed are also available.
- Restrict or object to processing that is based on our legitimate interests.
- Withdraw consent where processing is based on consent.
- Complain to the UAE Data Office if you believe we have not handled your data properly. We would rather hear from you first.
Send requests to support@opsbreak.ae with the subject "Privacy request". We will verify that the request comes from the account holder (for example by asking you to write from the account's email address) and respond within 30 days.
8. Security
- All traffic is encrypted in transit (TLS 1.2 or higher). The database and file bucket are encrypted at rest, and the database accepts connections only from our application network, with certificate verification.
- Every request is authorised against your organisation on the server. Files are never publicly accessible; the app fetches them through short-lived links (five minutes).
- Passwords are stored as bcrypt hashes. Sessions are recorded server-side and can be revoked; changing your password or resetting it logs out other sessions.
- Reminders are only sent to a verified email address, and identity numbers in emails are masked to the last four characters.
- The website sends a strict Content-Security-Policy and related security headers, and rate-limits login, sign-up and password-reset attempts.
- Staff access to production data is limited to the founder and to what is needed to run the service; administrative access to the database and bucket requires authorized AWS credentials, and security-relevant actions are logged.
- If we discover a breach that is likely to affect your rights, we will notify the UAE Data Office and affected users as required by the PDPL.
No system is perfectly secure. Please use a strong, unique password and keep your devices locked.
9. Android app (beta) and notifications
The Android app is distributed as a direct APK (beta), outside Google Play. It uses the same account and API as the web app; documents you save from the app are stored as described above.
- Camera and photos are used only when you choose to scan or pick a file. The image is uploaded to our server in Frankfurt and handled as in section 4.
- Notifications are scheduled locally on your device for each reminder date. We do not use a push-notification service and do not collect device push tokens. Logging out cancels the scheduled notifications on that device.
- The app does not contain advertising or analytics SDKs and requests no location, contacts or SMS permissions.
10. Business customers and other people's data
If you use Tajdeed for your company, your employees, your clients or your family, you are the data controller for the documents you upload and Tajdeed (OpsBreak Technologies) is your processor for that data. You must:
- have a lawful reason to hold those documents (for example an employer's obligation to keep visas and work permits current);
- tell the people concerned that their documents are tracked in Tajdeed and where the data is stored (section 5);
- only invite members who need access, and remove documents when you no longer need them.
We process that data only on your instructions as set out in this policy and our Terms of Service, and we will assist you with data-subject requests that reach us. A data-processing addendum, including the list of sub-processors and regions above, is available on request for Business and PRO customers. PRO customers must keep different clients in separate organisations; we never place different clients in shared access.
11. Children
Tajdeed is not intended for use by anyone under 18. Adults may store documents belonging to their children (for example a child's Emirates ID or passport) as part of a family account; the adult confirms that they are the child's parent or guardian and is responsible for that data. We do not knowingly collect data directly from children.
12. Cookies
The website uses only strictly necessary cookies: a session cookie that keeps you signed in (httpOnly, secure, 30 days), a language cookie that remembers English or Arabic, and a short-lived token that protects forms against cross-site request forgery. When you choose Google sign-in, a short-lived HttpOnly cookie binds the Google callback to your browser. Google may use its own cookies on its sign-in pages. We do not retain Google access or refresh tokens. There are no analytics or advertising cookies on the Tajdeed website. The app's browser storage may keep an unsaved document draft on your own device until you save or discard it.
13. Changes to this policy
If we make material changes we will email account holders and show a notice in the app at least 14 days before the change takes effect. The current version is always at tajdeed.opsbreak.ae/privacy.
14. Contact
OpsBreak Technologies FZ-LLC CWEP4830 Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, UAE Email: support@opsbreak.ae Manager: Syed Ahsan Ghaffar
ملخص سياسة الخصوصية (بالعربية)
تاريخ السريان: 7 سبتمبر 2026 — المشغّل: OpsBreak Technologies FZ-LLC، رأس الخيمة، الإمارات — للتواصل: support@opsbreak.ae
- ما نجمعه: بريدك الإلكتروني واسمك ورقم هاتفك (اختياري)، وكلمة المرور (مشفّرة بالتجزئة)، وصور المستندات أو ملفات PDF التي ترفعها، والبيانات المستخرجة منها أو التي تكتبها (نوع المستند، اسم صاحبه، رقمه بما في ذلك رقم الهوية الإماراتية، تاريخ الإصدار والانتهاء)، وأسماء الأشخاص والمركبات والشركات التي تتابعها، وسجلات التذكيرات وتسليم البريد، وعدد عمليات المسح الذكي، وبيانات الاشتراك. لا نخزّن أرقام البطاقات البنكية.
- لماذا: لتشغيل حسابك، وقراءة تاريخ الانتهاء تلقائياً، وحفظ مستنداتك، وإرسال تذكيرات التجديد والملخص الأسبوعي بالبريد الإلكتروني، ودعوة أعضاء مؤسستك، وتصدير بياناتك، وتطبيق حدود الخطة، وحماية الخدمة، والوفاء بالتزاماتنا القانونية. لا نبيع بياناتك ولا نستخدمها للإعلانات.
- الذكاء الاصطناعي: عند اختيار «المسح الذكي» تُرسل الصورة أو ملف PDF فقط إلى خدمة Amazon Bedrock (نموذج Claude من Anthropic عبر ملف استدلال أوروبي) من خوادمنا في فرانكفورت. بموجب شروط Bedrock لا تُخزَّن مدخلاتك ولا تُشارك مع Anthropic ولا تُستخدم لتدريب النماذج. يمكنك إدخال البيانات يدوياً بدلاً من المسح، ويجب عليك دائماً التحقق من التاريخ المستخرج مقابل المستند الأصلي.
- أين تُخزّن: على Amazon Web Services في فرانكفورت (الاتحاد الأوروبي): قاعدة بيانات RDS PostgreSQL خاصة ومشفّرة، ومخزن S3 خاص ومشفّر للملفات، وخوادم App Runner. تُرسل رسائل البريد عبر Amazon SES في الولايات المتحدة (us-east-1)؛ تتضمن رسائل التذكير عنوان الترجمة ونوع المستند وتاريخ الانتهاء ورقم المستند مقنّعاً (آخر 4 خانات فقط). لا نستخدم Supabase أو Vercel أو Resend. النقل خارج الإمارات يتم وفق المادتين 22 و23 من قانون حماية البيانات الشخصية بموجب اتفاقية معالجة البيانات مع AWS.
- مدة الاحتفاظ: طوال فترة نشاط حسابك. حذف المستند يحذف ملفه من S3 فوراً (مع إعادة المحاولة تلقائياً إذا تعذّر). حذف الحساب يحذف كل الملفات ثم كل السجلات. تُحذف الملفات المؤقتة خلال 24 ساعة. تُحفظ النسخ الاحتياطية المشفّرة حتى 30 يوماً، وسجلات الخوادم حتى 90 يوماً، وسجلات الفواتير 5 سنوات وفق القانون.
- حقوقك: وفقاً للمرسوم بقانون اتحادي رقم 45 لسنة 2021، يحق لك الاطلاع على بياناتك وتصحيحها وحذفها ونقلها (تصدير JSON وCSV وتقويم من الإعدادات) والاعتراض على معالجتها وسحب موافقتك، والشكوى إلى مكتب البيانات الإماراتي. راسلنا على support@opsbreak.ae بعنوان «Privacy request» وسنرد خلال 30 يوماً.
- الأمان: تشفير أثناء النقل وعند التخزين، جلسات قابلة للإلغاء، تذكيرات إلى بريد مؤكد فقط، أرقام الهوية مقنّعة في الرسائل، سياسة أمان محتوى صارمة وجدار حماية تطبيقات.
- تطبيق أندرويد (تجريبي): يستخدم الكاميرا والصور عند اختيارك فقط، والإشعارات محلية على جهازك بلا رموز دفع، ولا يحتوي على إعلانات أو أدوات تحليل.
- العملاء من الشركات: أنت المتحكم في بيانات موظفيك وعملائك ونحن المعالج؛ عليك إبلاغهم بأن مستنداتهم تُتابع في تجديد وبمكان تخزينها. ملحق معالجة البيانات متاح عند الطلب.
- الأطفال: الخدمة مخصصة لمن هم فوق 18 عاماً. يمكن للوالدين أو الأوصياء حفظ مستندات أطفالهم ضمن حساب العائلة على مسؤوليتهم.
- ملاحظة: هذه النسخة العربية ملخص للتوضيح؛ النص الإنجليزي هو المعتمد، وهذه السياسة بانتظار مراجعة مستشار قانوني.