01Operator and contact details
Manara One operates this website through two entities: [UAE ENTITY LEGAL NAME], licensed in the Emirate of Sharjah under licence number [LICENCE NO.], with its address at [SHARJAH ADDRESS]; and [US ENTITY LEGAL NAME], established in [US STATE], with its address at [US ADDRESS]. The relevant entity is identified in a customer’s signed agreement. Website legal correspondence may be sent to legal@manaraone.com; privacy and Data Protection Officer enquiries to privacy@manaraone.com; security reports to security@manaraone.com; and accessibility feedback to accessibility@manaraone.com. Please identify the relevant service and request without including unnecessary personal or confidential information.
02Applicable law and processing roles
This statement describes Manara One’s data protection approach under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and oversight by the UAE Data Office. For website processing, the relevant operating entity acts as controller where it determines purposes and means. For customer ERP data, the customer is the controller and Manara One acts as processor under a written data processing agreement. The DPA identifies instructions, responsibilities and authorised processing. Customers operating in DIFC or ADGM are subject to their own data protection laws; those requirements and contractual arrangements are addressed in their customer agreement.
03Lawfulness, records and individual rights
Processing must have consent or another lawful ground permitted by the governing law, a specified purpose and proportionate collection. Customers determine the lawful basis for employee, customer and device records and issue the required notices. Manara One maintains records of processing for its responsibilities and assists the controller under the DPA. Data subjects may exercise information and access, portability, rectification, erasure, restriction, stopping processing and objection to automated decisions, subject to applicable conditions. Direct privacy or Data Protection Officer matters to privacy@manaraone.com; requests about customer controlled records are coordinated with that customer rather than overriding its lawful instructions.
04Manara Hub and device information
Manara Hub device information, including GPS readings, attendance and camera events, is processed in Frankfurt, EU region eu-central-1. Tenant isolation uses row-level security and secrets are kept in a vault. Hub readings are held only as long as delivery requires; the ERP is the record of truth. Biometric templates are never collected or stored. Cameras do not place video in the ERP and do not perform face recognition. Customers must establish a lawful purpose and provide appropriate notices for workplace monitoring. Phone tracking and high risk surveillance require an approved DPIA before use; technical availability alone does not authorise monitoring.
05Manara AI and impact assessments
For customer Manara AI, personal data is pseudonymised before reaching the model provider. Tools are read only and operate under the user’s own permissions, not elevated access. Call logs are append-only. Use is enabled only after the customer records a DPA and an approved data protection impact assessment. High risk processing is assessed before activation and reviewed when purposes, data or risk materially change. The customer remains responsible for human oversight and lawful decisions. Website AI interactions are a separate public flow described in the Privacy Policy. Neither product AI controls nor model output replace a controller’s legal obligations.
06International transfers and subprocessors
EU processing means customer data may leave the UAE. Transfers are limited to countries providing adequate protection or arrangements using contractual or other safeguards permitted by applicable law. Safeguards include provider data processing terms, TLS in transit, encryption at rest and access controls. Subprocessor categories are cloud hosting through Supabase EU; Anthropic as AI model provider when Manara AI is enabled; messaging providers when Manara Cadence WhatsApp, voice, email or SMS channels are enabled; and maps through Google Maps or OpenStreetMap. The DPA governs authorisation and relevant supplier obligations. Enabling an optional integration must respect the controller’s instructions and applicable transfer requirements.
07Security, retention and incident response
Security measures include tenant isolation, least privilege, role, field and company permissions, audit trails and controlled secrets. Retention is configurable per customer and must reflect purpose, legal duties and the DPA. Temporary delivery readings are distinct from the ERP record retention schedule. Controllers decide lawful deletion and retention requirements and Manara One processes under those instructions. Incidents are assessed and contained, with relevant evidence preserved securely. We coordinate with the controller and support notification to the UAE Data Office and affected individuals where required by the PDPL. Notification obligations are determined by applicable law, not an assumed universal deadline.
08Accountability and ongoing assistance
Customers must configure permissions, review access, document processing purposes and ensure authorised users understand their responsibilities. Manara One supports the agreed processing controls and provides a privacy channel for rights, transfer and DPA questions. Our privacy and Data Protection Officer contact is privacy@manaraone.com. A request should identify the relevant entity, tenant and concern without disclosing unnecessary records. We may route a request to the controller, seek proportionate verification and explain applicable limitations. Records of processing, DPIA evidence and operating parameter histories support accountability; they do not constitute certification or guarantee compliance for every customer configuration. The signed agreement defines the assistance provided.