Data Processing Summary
Last updated: 30 June 2026
Roles
StayValid is designed around the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) model of controllers and processors:
- The customer organisation is the controller. It decides what data goes into StayValid and why, and it owns that data.
- StayValid is a processor. We process the data only to provide the service, and only on the customer's instructions.
- An invited PRO agency is also a processor with respect to the organisation that invited it, acting within the scope of access the organisation grants.
What we process
On behalf of a customer: document records and their expiry dates, the people and legal entities they relate to, owners and approvers assigned to renewals, uploaded document files, and the audit log of actions taken in the account.
Where it is processed
The product application and its data are designed to be hosted in the Microsoft Azure UAE North (Dubai) region, with tenant data isolated at the database layer. The development team works from outside the UAE but connects through a secure tunnel and does not download live customer data outside the UAE.
Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Application hosting, database, and document storage | UAE North (Dubai) |
| Hostinger | Marketing website and business email | Provider infrastructure |
| Cloudflare | Content delivery and security for the website | Global edge network |
| FormSubmit | Relays the early-access form to our inbox | May process outside the UAE |
We will keep this list current and notify customers of material changes to subprocessors used for product data.
Security measures
- Encryption at rest for the database and document storage, and encryption in transit.
- Tenant isolation enforced at the database layer, so one organisation's queries are scoped to its own data.
- Scoped, revocable access for people and invited PRO agencies.
- A time-stamped, append-only audit log of actions, alerts, and renewals.
- Soft delete and versioning on stored files so accidental loss can be recovered within a retention window.
No system can be made completely secure, so we do not promise absolute security, but these measures are designed to protect customer data and limit access to it.
Data subject requests
Because the customer organisation is the controller, requests from individuals (access, correction, deletion) are normally handled by that organisation. StayValid supports the controller in responding, and will action verified instructions to export or delete data. Direct queries can be sent to contact@stayvalidhq.com.
International transfers
Product data is intended to stay within the UAE region. The one routine exception is the marketing-site early-access form, which is relayed through FormSubmit and may be processed outside the UAE. That flow is limited to delivering your request to us.
Contact
Data processing questions: contact@stayvalidhq.com.