Legal

Privacy Policy

This policy explains what we collect when you use Darwa, why we collect it, how long we keep it, and what you can ask us to do with it.

Version 3.1Effective 1 August 2026Updated 1 August 2026
In short
  • We do not sell personal data, and we do not use your content to train models.
  • Your application data belongs to you. We process it only to run the services you deploy.
  • Analytics on darwa.com are cookie-free and cannot identify you individually.
  • You can export or delete your account data at any time from the dashboard.

Who we are

Darwa Technologies FZ-LLC is the data controller for account and website data, and a data processor for the application data you deploy. Where we act as a processor, the Data Processing Addendum governs that relationship.

What we collect

CategoryExamplesWhy
Accountname, email, organisation, password hash, provider identityTo create and secure your account
Billingplan, usage totals, invoices, tax identifiersTo charge correctly and meet accounting law
Repository metadatarepository name, branch, commit SHA, authorTo build and attribute deploys
Operationallogs, metrics, traces, request timingsTo run the platform and let you debug it
Supportmessages you send us and their attachmentsTo answer you
Websitepage, referrer, country, device classAggregate analytics — no cookies, no identifiers

We do not collect special category data deliberately. If your application stores it, that is your content and we process it only as described in the DPA.

Your application content

Databases, object storage, environment variables, and everything your code writes are your content. We access it only when you ask us to for support, when required to prevent abuse, or when compelled by law. Access by our staff is authenticated, scoped, time-limited, and recorded in an audit log you can request.

Model training

We do not train models on your code, logs, prompts, or data. AI features send only the specific context needed for the request you triggered, and providers process it under zero-retention terms.

How long we keep it

  • Logs and traces: 7 to 90 days depending on your plan, then deleted.
  • Metrics: aggregated to 13 months, then discarded.
  • Backups: for the retention window on your plan, then destroyed.
  • Account and billing records: 7 years after closure, because tax law requires it.
  • Deleted resources: purged within 30 days, including from backup media.

Who we share it with

Sub-processors are limited to infrastructure, payment, email, and model providers. The current list, with location and purpose, is published in the DPA and we give 30 days notice before adding one. We do not sell personal data and we do not share it for advertising.

International transfers

You choose the regions your services run in, and your application data stays in those regions. Account and billing data is processed in the UAE and the EU. Transfers rely on Standard Contractual Clauses or an adequacy decision.

Your rights

You can access, correct, export, or delete your personal data, object to processing, or withdraw consent. Export and deletion are self-service in the dashboard; anything else, email privacy@darwa.com and we respond within 30 days. You may also complain to your local supervisory authority.

Children

Darwa is not directed at anyone under 16, and we do not knowingly create accounts for them.

Changes

Material changes are announced by email and in the dashboard at least 30 days before they take effect. Previous versions remain available on request.

Contact

Darwa Technologies FZ-LLC, Dubai Internet City, Dubai, United Arab Emirates. Written notice may be sent to legal@darwa.com. Security reports go to security@darwa.com. Privacy requests go to privacy@darwa.com.