Template — to be reviewed when the company is registered. Rawad is an online service in beta and is not a registered company yet.
Privacy Policy
Version: 2026-10-08 · Rawad (رواد) — online service, beta
What we collect, why, where it is kept and your rights.
1. Who processes your data
If you are an employee or user of a company that uses Rawad, your company is the controller of your data and Rawad processes it on its behalf. Rawad is an online service in beta and is not a registered company yet.
2. What we collect
Account data (name, email, hashed password, two-step secret, sessions and known devices); what the company enters about its employees, customers and suppliers; check-in location only with your consent; feedback you send from the app (text, page and your role, and a screenshot if you attach one); technical security records (internet addresses, attempt counters); and aggregate usage counts with no content.
3. Why we use it
Only to provide the service, support and security. We do not sell data, use it for advertising or set trackers; cookies are essential only (session, language, theme, country choice).
4. Where it is kept and who receives it
Data is hosted in Germany with Hetzner (EU), encrypted, backed up daily and isolated per company. Regional hosting is planned, with no date set. Cloudflare receives requests in transit; Resend (Ireland) receives recipients' names, addresses and the notification text to send email; browser push services receive a notification's title and link only. The password check (Have I Been Pwned) receives no personal data.
5. Check-in location
Your location at check-in is recorded only with your explicit consent inside the app, given once and kept with its date and text version, in addition to the browser permission. You can withdraw it at any time from “My space”; check-in works without location, and your company then sees “no location consent”.
6. How long we keep it
Payroll and accounting records: 10 years by default, a period the company sets. Sessions 7 days; failed sign-ins 24 hours; known devices and attempt counters for short periods; error reports 90 days; feedback and pilot requests until handled, then 12 months; usage counts 12 months.
7. Your rights
To see your data and download a copy (from “My account”), to ask your company to correct or delete it, and to withdraw your consent to location and notifications, under your country's personal data protection law. Requests that reach us directly are passed to your company, the controller.
8. Breaches
If a breach affects your data we notify your company without delay; it informs you and the authority where its law requires.
9. Contact
For any privacy question: [email protected] (email only).
Sub-processors
| Who | Country | Role | What it receives |
|---|---|---|---|
| Hetzner Online GmbH | Germany | Hosting | All data: the database, files and the on-server backups |
| Cloudflare, Inc. | Global network (United States) | Network edge: protection and passing the encrypted connection | Requests in transit and internet addresses; no content is stored there |
| Resend | Ireland | Sending email | Recipients' names, email addresses and the notification text |
| Google · Apple · Mozilla | Depends on the user's browser | Browser push services | The notification's title and link only — never amounts or personal details |
| Have I Been Pwned | — | Leaked-password check | No personal data: only the first 5 characters of the password's hash |