Dariba
dariba.io

Legal · Privacy

Privacy Policy

Effective: 4 September 2026Last updated: 4 September 2026Governing law: Kingdom of Saudi ArabiaRegulation: PDPL — Royal Decree M/19

1.Controller Identity

This Privacy Policy governs the collection, use, storage, disclosure, and protection of personal data by Dariba ("Dariba", "we", "us", "our"), operator of the VAT Assure platform accessible at dariba.io. Dariba is the data controller within the meaning of the Saudi Personal Data Protection Law (PDPL), Royal Decree M/19, as applicable from September 2023. Enquiries regarding data protection matters may be directed to privacy@dariba.co.


2.Personal Data Collected

Dariba collects personal data in the following categories. Account and registration data: when a user creates an account, we collect their email address, password (stored exclusively as a bcrypt hash and never in plaintext), organisation name, Tax Registration Number (TRN), telephone number, and, where provided, a business address comprising building number, street name, district, postal code, city, and country. Onboarding data: during the onboarding process, we additionally collect the name and telephone number of a nominated contact person, industry classification, VAT filing period, the date range of the review engagement, the name of the ERP or accounting system in use, preferred column header language, and any supplementary notes entered by the user. Documents uploaded during onboarding are stored in Supabase secure object storage. VAT review data: to perform a compliance review, users upload sales invoice registers, purchase invoice registers, trial balance extracts, filed VAT-301 return data, and, optionally, customs figures and ZATCA FATOORA e-invoicing data. This data is processed by the VAT Assure engine and the results — comprising assurance scores, rule findings, reconciliation bridges, simulated return boxes, and period statistics — are stored persistently against the user's organisation record. Billing data: we record the subscription plan selected and billing frequency. Dariba does not process payment card data; billing is conducted by manual invoice and no payment credentials are collected or stored by the platform. Audit log data: the platform maintains an internal audit log recording user ID, organisation ID, action type (including authentication events, file uploads, and review executions), and associated metadata such as assurance grade and finding count. Authentication events capture the method used (password or one-time passcode) and the email address. Usage data: server-side logs capture IP address at the point of authentication, browser type, and error events for security and diagnostic purposes. No client-side analytics script is deployed.


3.Purposes of Processing

Personal data is processed for the following purposes: (a) service delivery — operating the VAT Assure engine on uploaded financial data to generate compliance scores, findings, reconciliation bridges, and workpaper exports; (b) account management — creating and maintaining user accounts, managing subscription entitlements, authenticating access via password or one-time passcode, and administering the platform; (c) security and integrity — maintaining the audit log, detecting unauthorised access, preventing abuse, and ensuring multi-tenant data isolation; (d) service communications — sending transactional notifications relating to review completion, account status, and subscription matters; (e) regulatory compliance — retaining records as required by applicable Saudi law and responding to lawful requests from ZATCA, SDAIA, or judicial authorities. We do not use personal data for advertising, third-party profiling, or any purpose beyond those listed above, and we do not sell, rent, or trade personal data.


4.Legal Basis for Processing

Processing of personal data for service delivery, account management, and service communications is carried out on the basis of performance of contract under PDPL Article 5, as such processing is necessary to provide the service subscribed to by the user. Processing for security monitoring and audit logging is carried out on the basis of legitimate interest in protecting the integrity of the platform and the data of all users, such interests not being overridden by the rights and interests of affected individuals given the limited nature of the data involved. Processing required to comply with a legal obligation imposed by Saudi law, including requests from ZATCA or judicial authorities, is carried out on the basis of legal obligation under PDPL Article 5.


5.Disclosure to Third Parties

Dariba does not sell, rent, or disclose personal data to third parties for commercial purposes. Personal data is shared only with the following sub-processors, who process data exclusively on Dariba's instructions under binding data processing agreements: Supabase Inc., which provides database, authentication, and file storage services and holds SOC 2 Type II and ISO 27001 certifications; and Vercel Inc., which provides application hosting and delivery services and holds SOC 2 Type II and ISO 27001 certifications. Personal data may additionally be disclosed where required by a valid order of a Saudi court, a request from ZATCA or SDAIA acting within their statutory powers, or any other legal obligation to which Dariba is subject. Where Dariba is permitted by law to notify the affected user of such a disclosure in advance, it will do so. In the event of a merger, acquisition, or transfer of Dariba's business, personal data may be transferred to the successor entity, which will be bound by this policy or an equivalent instrument.


6.International Data Transfers

Personal data processed by Dariba is stored and may be processed on infrastructure operated by Supabase and Vercel, whose servers are located in the United States and the European Union. Such transfers outside the Kingdom of Saudi Arabia are conducted in accordance with PDPL Article 17 on the basis of standard contractual clauses incorporated into data processing agreements with each sub-processor, which provide enforceable data subject rights and protections at least equivalent to those afforded under the PDPL. Users who require confirmation of the specific data residency configuration applicable to their account may submit a written request to privacy@dariba.co.


7.Retention

Account and profile data, onboarding data, VAT review data (including uploaded registers and all generated outputs), and audit log records are retained for the duration of the active account and for a period of twelve months following account closure, after which they are securely deleted. Authentication session tokens are invalidated on sign-out and expire independently after seven days at most. Server-side error and diagnostic logs are retained for ninety days on a rolling basis. Data uploaded during onboarding and stored in Supabase object storage is deleted upon exercise of the right to erasure or upon expiry of the retention period above. Dariba may retain data for a longer period where required to do so by applicable Saudi law or a lawful order.


8.Security

Dariba implements the following technical and organisational measures to protect personal data. All data transmitted between the user's browser and the platform is encrypted using TLS 1.3. All data stored in the database is encrypted at rest by Supabase using AES-256. Row-level security policies enforced at the database layer ensure that each organisation can access only its own data, providing multi-tenant isolation independent of application-layer controls. Passwords are stored exclusively as bcrypt hashes. Session tokens are short-lived and automatically rotated. The platform's infrastructure sub-processors, Supabase and Vercel, are independently audited against SOC 2 Type II and ISO 27001 standards. In the event of a personal data breach that poses a material risk to individuals, Dariba will notify affected users and report the breach to SDAIA within seventy-two hours of becoming aware of it, in accordance with PDPL Article 24. Security vulnerabilities may be reported responsibly to security@dariba.co.


9.Rights of Data Subjects

Under the PDPL, individuals whose personal data is processed by Dariba have the following rights: the right to be informed of the data held about them and the purposes of its processing; the right to access a copy of their personal data; the right to request correction of inaccurate or incomplete personal data; the right to request deletion of their personal data, subject to any legal retention obligation that may apply; the right to receive their personal data in a structured, machine-readable format; and the right to object to processing carried out on the basis of legitimate interest. The platform provides an in-application data deletion function enabling the account owner to permanently delete all organisation data, including all review records, onboarding files, and entity settings. To exercise any of the above rights, users should submit a request by email to privacy@dariba.co with the subject line PDPL Data Request. Dariba will respond within thirty days and may require verification of identity before acting on a request. Deletion of account data will result in termination of access to the platform.


10.Cookies and Session Management

VAT Assure uses two strictly necessary session cookies set by Supabase: an authentication token cookie maintaining the user's authenticated session for the duration of the browser session, and a refresh token cookie enabling silent session renewal, which persists for a maximum of seven days. No advertising cookies, third-party tracking scripts, or client-side analytics tools are used. The platform does not employ cookie consent banners because no non-essential cookies are set.


11.Minors

VAT Assure is a professional platform intended exclusively for use by businesses and their authorised representatives. It is not directed at individuals under the age of eighteen. Dariba does not knowingly collect personal data from minors. If Dariba becomes aware that it has inadvertently collected personal data from a minor, it will delete such data promptly. Suspected instances should be reported to privacy@dariba.co.


12.Amendments

Dariba reserves the right to amend this Privacy Policy at any time. In the event of a material change, registered users will be notified by email no fewer than fourteen days before the amended policy takes effect, and the effective date set out above will be updated accordingly. Continued use of VAT Assure after the effective date of an amended policy constitutes acceptance of the revised terms. Prior versions of this policy are available upon written request.


13.Complaints and Supervisory Authority

Enquiries and complaints concerning the processing of personal data by Dariba should be addressed in the first instance to privacy@dariba.co. If a user believes that their personal data has been processed unlawfully and Dariba has not adequately addressed their concern, they have the right to lodge a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA), the competent supervisory authority for the PDPL in the Kingdom of Saudi Arabia, via the National Data Management Office at ndmo.gov.sa.

© 2026 Dariba. All rights reserved.

Compliant with the Personal Data Protection Law of the Kingdom of Saudi Arabia (PDPL), Royal Decree M/19, enforced from September 2023.

dariba.io/privacy