Legal
Privacy & Policy
Version v2 · Last updated: 24 July 2026 · Draft pending legal review
- 1
Who we are
Darify FZ-LLC ("Darify") operates a real-estate CRM and advertising platform for licensed agencies and agents in the United Arab Emirates. Darify is the data processor for agency-owned records (leads, contacts, deals, listings) and the controller for platform account data, verification documents and billing.
- 2
Legal framework
We process personal data in accordance with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, "PDPL") and applicable Dubai Land Department regulations. Primary records are stored in UAE-region infrastructure (AWS me-central-1). Some processing is performed outside the UAE by the sub-processors listed on our Sub-processors page — see "International transfers" below.
- 3
Data protection contact
Our data protection officer can be reached at privacy@darify.ae, or by post at Darify FZ-LLC, Dubai, United Arab Emirates. Use this contact for any question about this policy, to exercise your rights, or to raise a concern. You also have the right to complain to the UAE Data Office.
- 4
What we collect
Account data (name, email, phone, role, licence identifiers). Verification/KYC documents (trade licence, Emirates ID front and back, a live selfie used to confirm the ID belongs to you, broker cards, creator licences). Agency compliance records (trade licence, RERA registration, VAT). Client and buyer-lead details entered or imported by agencies (name, contact details, nationality, budget, preferences, notes, and a lead score/temperature derived from that information). Transaction records and deal documents, which may include identity documents, title deeds and cheques uploaded by an agency. WhatsApp conversations conducted through the platform. AI Studio and support conversations. Usage and security logs.
- 5
Why we collect it, and our lawful basis
To provide the CRM and perform our contract with your agency (contractual necessity). To verify agencies, agents and creators with the Dubai Land Department and meet DLD, AML and tax record-keeping duties (legal obligation). To route buyer leads, secure the platform, prevent fraud and abuse, and improve the service (legitimate interests, balanced against your rights). To process payments (contractual necessity and legal obligation). Where we rely on consent — for example marketing communications, or where an agency captures a buyer’s consent at the point of enquiry — you may withdraw it at any time without affecting prior processing.
- 6
Buyer leads and lead marketplace
Buyer contact details captured through Darify advertising campaigns are masked by default. Where a campaign lead is offered to an advertiser, the buyer’s name, phone and email are disclosed to the acquiring agency once that agency pays the listed lead fee; the acquiring agency then becomes an independent controller of that data. Buyer data never appears in URLs or logs, and every disclosure is recorded. We do not otherwise sell, rent or trade personal data, and we do not share it for third-party advertising.
- 7
WhatsApp messaging
When an agency connects WhatsApp, we process the customer’s phone number, the full content of messages sent and received through the platform, any media they send, and delivery and read receipts. Messages are transmitted via Meta’s WhatsApp Business Cloud API, which is subject to Meta’s own terms and privacy policy. Conversation content is stored against the related CRM record so the agency has a history of the exchange.
- 8
Automated document reading
To speed up verification we use automated document-reading (OCR and machine-vision) to extract details such as licence numbers, expiry dates and the holder’s name from the identity and licensing documents you upload. This assists a human reviewer — no decision about your account is made by automated means alone, and you may ask for a human review of any verification outcome. Documents processed this way are sent to the AI sub-processor named on our Sub-processors page.
- 9
AI Studio and Ask Darify
When you use AI Studio, your prompts, any files you attach, and the scoped CRM records needed to answer are processed by our AI sub-processor, Anthropic, via its API. Anthropic does not train models on this data. Phone numbers and email addresses in CRM tool results are masked before reaching the model except where your request requires them; names, budgets and free-text notes are not masked, and files you attach are sent as provided — so avoid attaching documents that are not necessary for your question. We log query metadata (who, when, which data tools, token counts) for security and metering — not the conversation text. Saved chats are stored in your own browser, not on our servers.
- 10
Connected social accounts (creators)
If you connect a social account in the creator portal, we receive only your public profile basics — handle/channel name and audience count — via the platform’s official API (YouTube API Services, Instagram/Facebook Graph, TikTok, X), and we refresh that count when you sync. Snapchat shares only your display name via Snap’s Login Kit to verify account ownership; its audience count remains self-reported. We never post on your behalf, read messages, or access contacts. OAuth tokens are stored encrypted and used solely for these reads. Disconnect any platform in the portal at any time, or revoke access from the platform itself (for Google: myaccount.google.com/permissions). Darify’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements; see also the Google Privacy Policy (policies.google.com/privacy).
- 11
Marketplace visibility
Creator profiles exist to be discovered: your display name, photo, bio, portfolio, connected platforms, handles and audience counts are shown to agencies browsing the influencer marketplace. Withdraw a platform or portfolio item and it disappears from the marketplace with it.
- 12
Sharing and sub-processors
Data is shared only with: the agency that owns the record; counterparties a transaction requires; the sub-processors listed in full on our Sub-processors page (hosting, AI, payments, messaging, email and social-platform APIs — each bound by a written contract); and authorities where the law demands it. We keep that list current and give notice before adding a sub-processor that materially changes how your data is handled.
- 13
Cookies and local storage
We use strictly necessary cookies and browser storage to keep you signed in and to run the app — there are no advertising or third-party analytics trackers. Your browser also stores your saved AI Studio chats locally, which can contain CRM details such as client names and phone numbers; these never leave your device. Signing out clears your credentials and saved chats from that browser, and you should sign out on shared devices.
- 14
International transfers
Primary storage is in the UAE. Some sub-processors process data outside the UAE — their locations are listed on our Sub-processors page. Where data leaves the UAE we rely on the transfer conditions permitted by the PDPL, including transfers to jurisdictions recognised as providing adequate protection and, otherwise, appropriate contractual safeguards with the recipient. You can ask us for details of the safeguards applying to a specific transfer.
- 15
Retention
Expired buyer leads are erased 90 days after expiry. Transacted records are kept for 2 years. Account, verification and compliance records are kept for the duration of the subscription plus any statutory retention period, then erased or anonymised. WhatsApp media and inactive sessions are cleared on their own schedules. Retention is enforced by a scheduled process, and records under a legal or regulatory hold are retained until that hold lifts.
- 16
Security
Data is protected with encryption in transit and at rest, tenant isolation enforced at the database layer, role-based access, audit logging and least-privilege operational access. Verification documents are held in private storage accessible only to authorised reviewers. Report vulnerabilities to security@darify.ae.
- 17
Personal data breaches
We maintain an incident response procedure. If a breach occurs that is likely to prejudice your privacy, confidentiality or security, we will notify the UAE Data Office without undue delay after becoming aware of it, and notify affected individuals where the breach is likely to cause them serious harm. Where Darify acts as processor for an agency, we notify that agency without undue delay so it can meet its own obligations, and assist with its notifications.
- 18
Your rights
Under the PDPL you may request access to your personal data, correction of inaccurate data, erasure, a portable machine-readable copy, restriction of or objection to certain processing, and withdrawal of consent where processing relies on it. Account holders can request a copy of their data or the erasure of their account from Settings → Your data; anyone else — including a buyer whose details an agency holds — can email privacy@darify.ae. We respond within 30 days and will tell you if we need one further 30-day extension. We may be unable to erase data we are legally required to keep (for example DLD, anti-money-laundering or tax records); if so we will tell you which data is affected, why, and when the obligation ends, and we will restrict its use in the meantime.
- 19
Changes & contact
We may update this policy as the product and the law evolve; material changes are announced in-app and, where the change is significant, we will ask you to review the updated policy. Questions: privacy@darify.ae or your Darify account manager.