Data Protection Protocol.
Effective 26 July 2026 · AFSA FZE · United Arab Emirates
Article 8 of the UAE Personal Data Protection Law requires a controller to apply appropriate technical and organisational measures and to be able to demonstrate them. This page documents ours. For what we collect and why, read the Privacy Policy — this one is about how it is defended.
01. Scope and Standard
This protocol covers all personal data processed by AFSA FZE across afsa.ae and its connected services. We operate on a least-privilege basis: a system, a service or a person gets access to personal data only where a defined role requires it, and that access is revoked when the role ends.
It should be read with our Privacy Policy, which sets out the legal basis, retention periods and your rights.
02. Encryption
- In transit: All traffic between your device and our services, and between our internal services, uses HTTPS with TLS 1.3. Plain HTTP is redirected, never served.
- At rest: Stored data is encrypted with AES-256 on Google Cloud and Firebase infrastructure, with keys managed by the platform's key management service.
- Credentials: Passwords are hashed by Firebase Authentication and are never stored, logged or visible to us in recoverable form.
- Payment data: Card numbers are captured directly by our PCI-DSS compliant payment provider. They do not transit or persist on our servers; we retain only the card type and last four digits for reconciliation.
03. Access Control
- Authentication: Sessions are established through Firebase Authentication and verified server-side on every privileged request, so a modified client cannot elevate itself.
- Authorisation: Roles are enforced in Firestore and Storage security rules at the data layer, not merely hidden in the interface — a user cannot read another user's record even by calling the API directly.
- Administrative access: Restricted to named personnel, granted per-role, reviewed periodically and logged.
- Segregation: Customer, partner and administrative data are logically separated, so a compromise in one surface does not expose the others.
04. Processors and Sub-Processors
Where a third party processes personal data on our behalf — hosting, payments, delivery, messaging, AI inference — a written data processing agreement requires them to act only on our documented instructions, apply equivalent security, restrict onward transfer, and delete or return data when the engagement ends. We assess a provider's security posture before onboarding it. The categories of recipient are listed in section 05 of the Privacy Policy.
Content you submit to our AI-assisted features is sent to a model provider to generate the output. We do not permit those providers to use your content to train their models.
05. Cross-Border Safeguards
Some infrastructure sits outside the UAE. Articles 22 and 23 of the PDPL allow this where the destination provides adequate protection or appropriate contractual safeguards exist. We rely on standard contractual clauses with our processors and transfer the minimum the service requires.
06. Retention and Deletion
Personal data is kept only as long as the purpose or a legal duty requires — the full schedule is in section 07 of the Privacy Policy. When a period expires, records are deleted or irreversibly anonymised, including in backups on their own rotation cycle. Deletion requests are honoured except where tax, accounting or KYC law obliges us to retain a record; where that applies we tell you which obligation and for how long.
07. Monitoring and Incident Response
Application and administrative events are logged and retained for 12 months to support security investigation. If we detect a breach of personal data we contain it, assess the risk, and notify the UAE Data Office without undue delay in line with Article 9 of the PDPL. Where the risk to you is high we contact you directly, describing what happened, the likely consequences and the steps we are taking.
08. Governance
Our Data Protection Officer owns this protocol and reviews it at least annually and whenever we introduce a materially new processing activity. Higher-risk processing — new AI features, large-scale profiling, biometric or KYC data — receives a documented impact assessment before launch. Staff with access to personal data are briefed on their obligations under the PDPL.
Note on timing: the PDPL's Executive Regulations were issued in 2026 with a grace period before full enforcement. We are not waiting for that deadline — the measures above are in force now, and this document will be updated as the regulations' detailed requirements are finalised.
09. Reporting a Vulnerability
If you find a security weakness, please report it to privacy@afsa.ae rather than disclosing it publicly. We will acknowledge within 5 working days and keep you updated. We will not pursue action against researchers who act in good faith, avoid privacy violations and data destruction, and give us reasonable time to fix the issue.
Who You Are Contracting With
AFSA FZE, trading as afsa at afsa.ae.
Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates
+971 54 595 9540 · hello@afsa.ae
Unresolved complaint? You may escalate to the UAE Ministry of Economy & Tourism — Consumer Protection Department on 600 522 225 or via moet.gov.ae.