Legal
Privacy Policy
Last updated: 12 August 2026
1. Who we are
Hades DMCC (“Hades”, “we”, “our”) is a software studio registered in Dubai, United Arab Emirates. This Privacy Policy explains how we collect, use, and protect personal data when you use our website (hades.ae) and the platforms we operate — including whatsapp.hades.ae,crm.hades.ae, pos.hades.ae, and any related mobile applications (together, the “Services”).
2. Data we collect
Depending on which Services you use, we may collect:
- Account data — your name, email, phone number, business name, and password (stored hashed).
- WhatsApp Business data — customer phone numbers, messages, contact profiles, media, delivery receipts, quality ratings, and template statuses shared via the Meta WhatsApp Business Cloud API.
- Business content — templates, quick replies, tags, notes, follow-ups, and AI knowledge-base documents you upload.
- Payment metadata — for purchases we take on hades.ae, Stripe processes card data on our behalf; we retain only receipt IDs, order status, and amounts (never full card numbers).
- Technical data — IP address, browser + device fingerprint, service usage logs, session tokens.
- Cookies — a session cookie for login and analytics cookies you may disable.
3. How we use your data
- Provide the Services (deliver messages, run automations, show analytics).
- Authenticate you and secure your account.
- Process purchases, licences, and support requests.
- Comply with Meta's WhatsApp Business Platform policies.
- Send transactional emails (receipts, account alerts, security notices).
- Improve the Services through aggregated, anonymised usage analytics.
We do not sell personal data. We do not use your WhatsApp conversation content to train third-party AI models.
4. Legal basis
We rely on the following legal bases (aligned with UAE PDPL 2022 and GDPR where applicable):
- Performance of contract — to deliver the Services you signed up for.
- Legitimate interest — to secure, improve, and support the Services.
- Consent — for optional marketing communications you can withdraw at any time.
- Legal obligation — to comply with tax, accounting, and regulatory duties.
5. WhatsApp / Meta data
If you connect your WhatsApp Business number to our platform, Meta acts as a data processor for message transport. We store the messages you and your customers exchange only for as long as needed to deliver the Services (see Section 8). We access your WhatsApp Business Account (WABA) strictly using the credentials you provide, only for the purposes you configured, and we never share those credentials with third parties.
6. AI processing
If you enable AI auto-reply, we send the necessary conversation context (recent messages + your uploaded knowledge base) to a large-language-model provider (xAI Grok or OpenAI, as configured) purely to generate a reply. We do not authorise these providers to retain or train models on your data. See our current AI provider's privacy commitments for details.
7. Sharing your data
We share data only with:
- Sub-processors we rely on to run the Services — Meta (WhatsApp Cloud API), Stripe (payments), Firebase Cloud Messaging (mobile push), and our hosting provider (Hostinger VPS in Europe).
- Legal authorities where compelled by valid UAE court order or regulator request.
- Successors in the event Hades is acquired or reorganised — we'll notify you first.
8. Data retention
- Active accounts: we retain data for the lifetime of your subscription and 30 days after cancellation.
- WhatsApp messages: retained by default; you may delete individual conversations at any time from the platform, or request bulk deletion via Section 10.
- Purchase records: 5 years, as required by UAE tax law.
- Server logs and technical data: 90 days.
9. Data security
We encrypt data in transit using TLS 1.2 or higher. Passwords are hashed with bcrypt. Access to production systems is limited to authorised personnel and audited. Payments run through PCI-DSS-compliant Stripe. We perform routine backups of your data.
10. Your rights
You may at any time:
- Access or download a copy of your data.
- Correct inaccurate data.
- Delete your data (see Data Deletion).
- Withdraw consent for marketing.
- Object to certain processing.
- Lodge a complaint with the UAE Data Office or your local supervisory authority.
To exercise any right, email privacy@hades.ae. We respond within 30 days.
11. International transfers
Some sub-processors (Meta, Stripe, Firebase) operate globally and may process data outside the UAE. Where this happens, they are contractually bound to protect your data at UAE / GDPR-equivalent standards.
12. Children
The Services are not intended for anyone under 18. We do not knowingly collect data from minors.
13. Changes
We may update this Policy from time to time. Material changes will be notified by email (to registered users) and posted on this page with a new “Last updated” date.
14. Contact
Hades DMCC
Dubai, United Arab Emirates
Email: privacy@hades.ae
Support: support@hades.ae