← Back to Home

GDPR & UAE PDPL Compliance

Last Updated: June 30, 2026

1. Scope & Applicability

This compliance document describes how Islamic-Microfinance.com (operated by Koodo Tech LLC FZ, Sharjah, UAE) adheres to:

This document is intended for: enterprise clients, partner organizations, regulatory bodies, and data protection authorities. It serves as both a compliance declaration and a reference for data processing agreements (DPAs).

2. Regulatory Framework

RegulationJurisdictionStatus
UAE PDPL (Law #45/2021)United Arab EmiratesCompliant
GDPR (EU) 2016/679European Union / EEACompliant
CBUAE Consumer Protection RegulationUAE Banking SectorCompliant
Dubai Data Law (Law #26/2015)Dubai, UAECompliant

2.1 Data Controller & Data Processor Classification

3. Data Processing Activities

We process personal data for the following purposes:

Processing ActivityData CategoriesPurposeLawful Basis (GDPR)
AI Chat QueriesQuery text (may contain personal info)AI response generation, service improvementLegitimate Interest / Consent
Zakat CalculationFinancial figures (no PII required)Zakat calculationLegitimate Interest
Demo BookingName, email, institution, phoneSales follow-up, demo schedulingConsent / Pre-contractual
Account ManagementEmail, billing info, usageService delivery, billingContractual Necessity
AnalyticsIP address, page views, device infoSite improvement, troubleshootingLegitimate Interest
Enterprise White-LabelPer enterprise agreementClient-specific service deliveryContractual Necessity

Under GDPR Article 6, we rely on the following lawful bases:

Lawful BasisApplication
Consent (Art. 6(1)(a))Demo booking form, cookie preferences, marketing communications
Contractual Necessity (Art. 6(1)(b))Account creation, service delivery, billing, enterprise agreements
Legal Obligation (Art. 6(1)(c))Regulatory compliance, tax reporting, legal requests
Legitimate Interest (Art. 6(1)(f))Analytics, service improvement, security monitoring (balanced against user rights)

🕌 Islamic Finance Context: Our AI processing does not involve automated decision-making with legal or similarly significant effects concerning individuals. All zakat calculations and stock screening results are estimates requiring human verification with qualified scholars. AI responses are informational only.

5. Data Subject Rights

We honour all rights under both GDPR and UAE PDPL. Response time: within 30 days (free of charge, unless requests are manifestly unfounded or excessive).

RightGDPRUAE PDPLImplementation
AccessArt. 15Art. 10Submit request → CSV/JSON export within 30 days
RectificationArt. 16Art. 11Update account settings or submit correction request
ErasureArt. 17Art. 12Account deletion via support or automated (self-serve coming Q3 2026)
RestrictionArt. 18Art. 13Request via DPO; data flagged and restricted
PortabilityArt. 20Machine-readable export (JSON/CSV)
ObjectionArt. 21Art. 14Opt-out of marketing; object to legitimate interest processing
Withdraw ConsentArt. 7(3)Art. 15Cookie settings, email unsubscribe, DPO request

To exercise any right: Email privacy@islamic-microfinance.com or contact our DPO (see Section 12). We verify identity before processing requests.

6. Technical & Organizational Measures

6.1 Technical Measures

MeasureDetails
Encryption at RestAES-256 for all stored data (databases, backups, logs)
Encryption in TransitTLS 1.3 for all HTTPS connections; TLS 1.2+ for API calls
Server HardeningMinimal attack surface: only port 443 (HTTPS) and 22 (SSH, key-only) exposed
AuthenticationSSH key-only (no passwords); 2FA for admin accounts
AI SandboxingModel runs in isolated GPU environment; prompts not persisted beyond session
Logging & MonitoringStructured logging with alerting; 90-day log retention
BackupEncrypted daily backups; 90-day retention; off-site storage
Penetration TestingAnnual third-party penetration test (next: Q3 2026)
Vulnerability ScanningWeekly automated CVE scanning on all infrastructure
Access ControlRBAC for infrastructure; principle of least privilege
WAFWeb Application Firewall rate-limiting and DDoS protection

6.2 Organizational Measures

7. Sub-Processors

We use the following sub-processors to deliver our service. All have executed DPAs and meet our security requirements.

Sub-ProcessorServiceData ProcessedLocationSOC2/ISO
Stripe, Inc.Payment processingBilling info (no card numbers stored by us)USA / GlobalSOC 2 Type II
Google Cloud PlatformInfrastructure, computeAll platform data (configurable region)USA / Europe / GCC*ISO 27001, SOC 2/3
Hetzner Online GmbHGPU compute (AI inference)AI prompts & responses (in-memory only)Finland / GermanyISO 27001
OllamaAI model servingNo data stored; in-memory processingSelf-hostedN/A

* GCC data residency available for enterprise clients (UAE/Saudi Arabia availability zones).

8. Data Residency & Transfers

8.1 Standard Users

8.2 GCC Enterprise Clients

🇦🇪 GCC Data Residency: Enterprise clients can elect to have all data — including AI processing — handled within the GCC region (UAE / Saudi Arabia availability zones). Additional charges apply for dedicated regional infrastructure.

8.3 Transfer Safeguards

9. Breach Notification

RequirementOur Commitment
Notification to Data Protection AuthorityWithin 72 hours of becoming aware (GDPR Art. 33)
Notification to Data SubjectsWithout undue delay when high risk to rights and freedoms (GDPR Art. 34)
Notification to UAE PDPL AuthorityAs specified in UAE PDPL implementing regulations
Notification to Enterprise ClientsWithin 24 hours for confirmed breaches affecting client data
Incident LogAll data breaches documented in internal incident register with root cause analysis

10. Data Processing Agreement (DPA)

Enterprise clients and partners can request a signed Data Processing Agreement. Our DPA covers:

📄 Request DPA: Email dpo@islamic-microfinance.com with the subject "DPA Request." We will provide a signed DPA within 5 business days.

11. Data Retention & Deletion

Data CategoryRetention PeriodDeletion Mechanism
Account dataAccount duration + 12 monthsAutomated purge after 12 months inactivity
Demo / inquiry records24 months after last contactQuarterly purge script
AI chat logs (standard)Not stored server-side (browser localStorage only)User clears browser data
Enterprise query logsPer enterprise agreement (default 90 days)Automated deletion after TTL
AnalyticsAggregated: indefinite; raw: 26 monthsAnonymisation after 26 months
Backups90 days rollingOverwritten on rolling cycle
Billing records7 years (legal/regulatory requirement)Encrypted archive, restricted access

11.1 Deletion Requests

Data subjects can request deletion at any time. We verify identity and complete deletion within 30 days, except where retention is legally required (e.g., billing records). Deletion confirmation sent to the requester.

12. Contact & Data Protection Officer

Data Controller / OperatorKoodo Tech LLC FZ, Sharjah, United Arab Emirates
Data Protection Officerdpo@islamic-microfinance.com
Privacy Inquiriesprivacy@islamic-microfinance.com
Legal Inquirieslegal@islamic-microfinance.com
Supervisory Authority (GDPR)Irish Data Protection Commission (Lead SA) — complaints@dataprotection.ie
Supervisory Authority (UAE)UAE Data Office — info@dataoffice.ae

Your Rights Matter. We are committed to protecting your privacy and handling your data with the utmost care. If you have any concerns about how we process your personal data, please contact our DPO first — we will respond within 5 business days. You also have the right to lodge a complaint with your local data protection authority at any time.

This compliance document was last updated on June 30, 2026. It is reviewed quarterly and updated as regulations evolve.

← Privacy Policy | Terms of Service