Privacy Policy
This policy explains how the Diwan One platform handles data. It is written to reflect the product's actual architecture: a white-label platform deployed per client, where each client's data stays within their own infrastructure or their isolated database project.
1. Roles of the parties
The client (the subscribing organization) is the controller of the data entered into their platform. The provider supplies the software and acts as a processor only to the extent it hosts or supports on the client's instructions. Each client's operational data is isolated from every other and is never pooled into a shared store.
2. Data the platform handles
- Account data: name, email, and the roles and entities assigned.
- Operational data: the records the organization enters across the modules.
- Audit trail: who changed which field, with the old and new value and the time.
3. Where data is stored
Data is stored in the client's own infrastructure or in a dedicated, isolated database project. We do not move one client's data to another, and we do not process it outside the agreed scope of service.
4. Cookies
Cookies on the platform are limited to what running it requires: a session cookie for authentication that keeps you signed in, and a language preference cookie (Arabic or English). We do not use cookies for tracking or advertising.
5. No analytics tracking inside the platform
The platform embeds no third-party analytics tools or tracking scripts. Every request stays within the client's deployment and database.
6. This marketing site
This marketing site self-hosts its fonts and loads no third-party tracking scripts. The only way it collects your information is when you choose to contact us by email.
7. Security
The platform relies on per-client database isolation, row-level security (RLS) inside the database, transport encryption over HTTPS, and a permanent audit trail of every change. Security of the client-managed infrastructure is the client's responsibility.
8. Data retention and deletion
The client controls how long their data is retained and when it is deleted, since it sits within their scope. On termination, the client can export their data before access is suspended.
9. Data subject rights
Because the client is the data controller, requests for access, correction, or deletion are directed to the client organization whose data is managed in the platform, which can act on them directly inside the system.
10. International data transfers
Any international transfer is determined by the hosting location the client chooses; the client governs this to suit the regulations that apply to them.
11. Changes to this policy
We may update this policy from time to time. A change takes effect on the date it is published on this page.
Note: this page is a jurisdiction-neutral, generic draft and is not legal advice. The publishing owner should have it reviewed by counsel and adapt it to the regulations that apply before commercial reliance.
12. Contact
For any privacy question, contact us at info@diwanone.com.