Privacy Policy
Last updated: 11 July 2026
This policy explains how [LEGAL ENTITY NAME] (“Ehraam”, “we”) handles personal data in the Ehraam property-management platform. Two roles apply: for account data of the property businesses that sign up, we are the data controller; for guest, renter and owner data that a property enters or receives through the Service, the property is the controller and we process it on their behalf.
1. What we process
Account data: names, emails, hashed passwords, roles, business identity (KYC) details and documents, billing records. Guest & renter data (on behalf of properties):contact details, nationality and ID details (ID numbers are encrypted at rest; ID scans stored as uploaded documents), stay and lease records, folios and payment records, service requests, and message threads — including WhatsApp and web-chat conversations with the property’s guest assistant. Technical data: logs necessary to run and secure the Service.
2. What we use it for
Providing and securing the Service; sending operational communications (booking confirmations, rent reminders, staff notifications); billing; support; and legal compliance. We do not sell personal data or use guest data for advertising.
3. AI features
Some features send message content to an AI provider to generate a response: the guest chatbot, staff reply drafting, and automatic translation of staff replies into the guest’s language. Depending on the property’s configuration the provider is Anthropic, OpenAI or Google. Content is sent via API for processing only; properties can disable AI features or bring their own provider key in Settings.
4. Subprocessors
We use these categories of service providers: hosting/infrastructure ([HOSTING PROVIDER]); email delivery (Resend); subscription billing and payments (Stripe); WhatsApp messaging (Meta Platforms — WhatsApp Business Platform); AI processing (Anthropic / OpenAI / Google, per configuration); channel-manager connectivity (Channex, where enabled); encrypted offsite backup storage ([BACKUP STORAGE PROVIDER]). The current list is published at /subprocessors.
5. Security
Data is isolated per property with database row-level security; sensitive fields (ID numbers, business IDs, provider API keys) are encrypted at rest (AES-256-GCM); transport is encrypted (TLS); access is role-based with audit logging; passwords are hashed. Daily backups are taken and replicated offsite.
6. Retention
Account data is kept while the account is active and deleted or anonymised within [90] days of termination, except where law requires longer retention (e.g. invoices). Guest and renter data is retained under the controlling property’s instructions; properties can delete records and configure chat-history retention. Backup copies expire on a rolling schedule.
7. Your rights
Depending on your jurisdiction (GDPR, India’s DPDP Act, Saudi PDPL and similar), you may have rights of access, correction, export, deletion and objection. Property staff exercise these in-app (per-person data export and deletion tooling is built in). Guests and renters should contact the property they dealt with, as the controller of their data; we support properties in fulfilling such requests. You can also reach us at [PRIVACY EMAIL].
8. Cookies
The app uses strictly necessary cookies only: an authentication session cookie and security (CSRF) protection. No advertising or cross-site tracking cookies.
9. International transfers
Subprocessors may process data outside your country. Where required, we rely on appropriate safeguards (e.g. standard contractual clauses) with those providers.
10. Changes and contact
We will notify material changes in-app or by email. Contact: [LEGAL ENTITY NAME], [ADDRESS], [PRIVACY EMAIL].