01Operator and contact details
Manara One operates this website through two entities: [UAE ENTITY LEGAL NAME], licensed in the Emirate of Sharjah under licence number [LICENCE NO.], with its address at [SHARJAH ADDRESS]; and [US ENTITY LEGAL NAME], established in [US STATE], with its address at [US ADDRESS]. The relevant entity is identified in a customer’s signed agreement. Website legal correspondence may be sent to legal@manaraone.com; privacy and Data Protection Officer enquiries to privacy@manaraone.com; security reports to security@manaraone.com; and accessibility feedback to accessibility@manaraone.com. Please identify the relevant service and request without including unnecessary personal or confidential information.
02Scope, information and enquiry handling
This policy covers website visitors and business enquiries, not the customer’s own ERP privacy notice. Contact and demo forms request name, company, email, optional phone, country, interest and message. Their purpose is to respond to enquiries and arrange demonstrations, with relevant B2B follow-up. The forms validate information before securely submitting an enquiry. These records are stored in our Supabase database in Frankfurt, EU region eu-central-1. Enquiry retention is 24 months from the last contact, followed by deletion unless a customer relationship begins and a separate retention purpose applies.
03Purposes and lawful grounds
We process information to fulfil the individual’s request, arrange a demo and protect the website. Consent is used where required and may be withdrawn through privacy@manaraone.com, without affecting earlier lawful processing. B2B follow-up serves a legitimate business interest where the applicable law permits that ground; it is not asserted as a standalone exception under UAE PDPL. For UAE processing we rely on consent or another ground permitted by Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. We limit collection to relevant information, document the applicable basis and honour requests to stop marketing contact.
04AI interactions and confidentiality
Messages submitted to website AI chat on /ai and the Solution advisor are sent to an AI model provider through Lovable’s AI gateway to generate an answer or recommendation. The chat sends submitted messages to generate a streamed answer. Do not enter personal data, credentials or confidential business information in public AI interactions. Conversations are not used for advertising and are retained only as long as needed to answer and protect the service. These website interactions do not access customer ERP records. Customer Manara AI has separate pseudonymisation, permission and contractual controls described in the Data Protection Statement.
05Hosting, external resources and storage
Lovable hosts and delivers the website. Security logs may include IP address, user agent and timestamps and are retained for up to 30 days for service protection. Fonts load from Google Fonts and images may load from Unsplash; those providers receive technical requests necessary to deliver the resources and apply their own privacy terms. We do not use advertising or analytics cookies. Strictly necessary storage is limited to language preferences, where stored, and hosting security cookies. The Cookie Policy describes their purpose and duration. No optional cookie will be introduced without requesting consent first. Public page language can also be selected through its URL.
06Transfers, safeguards and incidents
EU hosting means relevant personal data leaves the UAE. Transfers are made only to countries with adequate protection or using contractual or other safeguards permitted by applicable law. Our safeguards include contractual data processing terms with providers, encryption in transit using TLS, encryption at rest and restricted access. Recipients are limited to providers and authorised personnel needed for the stated purposes, or authorities where disclosure is legally required. We maintain records of processing and assess high risk activities through DPIAs where required. Personal data breaches are assessed, contained and notified to the UAE Data Office and affected individuals where the PDPL requires notification.
07Your rights and privacy requests
Subject to applicable conditions and exceptions, data subjects may request information and access, portability, rectification, erasure, restriction, stopping processing and objection to automated decisions. Send requests or consent withdrawals to privacy@manaraone.com, our privacy and Data Protection Officer contact channel. We may request proportionate identity verification and explain a lawful refusal or limitation. Do not send identity documents unless requested through an appropriate channel. Customers in DIFC or ADGM are subject to their respective data protection laws, addressed in the customer agreement. This policy does not remove the right to complain to the competent authority or to exercise mandatory local rights.
08US residents, marketing and children
Where applicable, California residents have rights under the CCPA as amended by the CPRA to know, delete and correct personal information, opt out of sale or sharing, and receive no discrimination for exercising rights. We do not sell personal information or share it for cross-context behavioural advertising. A request headed “Do Not Sell or Share” may be sent to privacy@manaraone.com. Marketing emails provide an unsubscribe route consistent with CAN-SPAM. The website is not directed at children under 13 under COPPA, or persons under 18 in the UAE context. Notify us if a child supplies data so we can address it appropriately.