Privacy Policy
Version 2026-09-05.2-uae-draft · Prepared under Federal Decree-Law No. 45 of 2021 (UAE Personal Data Protection Law)
1. Controller
Zanii, United Arab Emirates, info@zanii.agency, is the controller of the personal data processed to operate Zanii ID. Applications you sign in to ("Relying Parties") are separate controllers for what they receive; the consent screen names the organization behind each one.
2. What we hold, why, and on what basis
| Data | Purpose | Legal basis (PDPL) | Kept |
|---|---|---|---|
| Email address; name if given | Your login identity; the claims an application receives when you approve the email and profile scopes | Necessary to provide the service you asked for (Art. 4); consent for sharing with each application | Life of the account |
| Password hash (Argon2id); encrypted authenticator secret; hashed recovery codes; passkey public keys | Authentication | Necessary to provide the service; security obligation (Art. 20) | Until you change or remove them; deleted with the account |
| Sessions: IP address, browser identifier, times, whether a second factor was used | Keeping you signed in; letting you see and end sessions; fraud detection | Necessary to provide the service; our legitimate interest in security, which does not override your rights | Until ended; expired sessions are purged |
| Consents: which application, which scopes, when | Knowing what you approved; letting you revoke it | Necessary to provide the service | Until revoked or the account is deleted |
| Security audit log: sign-ins, failures, changes, operator actions with their stated reason | Investigating incidents; showing you what happened | Legitimate interest in security; legal obligation to keep records of processing (Art. 7) | Life of the account plus 12 months |
Custodial cryptographic identity (a did:key) and the public ledger receipts recorded under a pseudonymous tag | Letting you audit what AI agents, and Zanii itself, did on your account | Necessary to provide the service | Ledger entries are public and permanent by design; they carry a pseudonymous tag and hashes, never your email, name or content |
| Lifecycle event deliveries to applications | Telling an application you deleted your account, revoked it, or changed your email or password | Necessary to give effect to your rights | Delivery records for 30 days |
We do not process sensitive personal data, do not profile you, make no decisions about you by automated means, and do not use your data for marketing, ours or anyone else's.
3. What an application receives
Only the claims covered by the scopes you approved. Applications registered by outside organizations receive a pairwise identifier that is stable for that organization and cannot be matched against another organization's identifier for you. Zanii's own first-party applications receive your global account identifier. A second-factor indicator (acr, amr) tells the application how you signed in, not which device you used.
4. Who else sees data
- Processors acting for us: a transactional email provider (verification, reset and security emails) and our hosting provider. The list is kept in
docs/legal/README.mdand organizations are told before it changes. - Relying Parties, as described in section 3, are controllers, not our processors.
- Authorities, where UAE law requires disclosure and after we have checked the request is lawful.
5. Where data is processed
Data is processed on infrastructure operated for Zanii. Where a processor is located outside the United Arab Emirates, the transfer is made under Articles 22 and 23 of the PDPL: to a jurisdiction the UAE Data Office recognises as adequate, or under contractual safeguards that bind the recipient to the protections in this policy. Free-zone establishments (DIFC, ADGM) applying their own data protection laws are treated as separate jurisdictions for this purpose.
6. Your rights
Under the PDPL you can ask for access to and a copy of your data, correction, erasure, restriction, an end to processing, portability, and you can object to processing and to any automated decision. Most of these you can do yourself, immediately, at your account page: export the claims we hold via /userinfo, correct your name and email, revoke any application, end sessions, and delete the account, which removes your data and notifies every application you used. For anything else write to info@zanii.agency; we answer within 30 days. Where we cannot verify it is you, we will ask you to sign in first.
If you are not satisfied, you may complain to the UAE Data Office. If you are in a free zone with its own authority, that authority may be competent instead.
7. Security
Passwords are hashed with Argon2id; signing keys, custodial keys, authenticator secrets and organization salts are encrypted at rest; sessions use host-only secure cookies; every privileged action by Zanii on your account is recorded on a public append-only ledger you can verify offline. Two-step verification and passkeys are available to every account.
8. If something goes wrong
If a breach of personal data is likely to harm your privacy or security, we notify the UAE Data Office as soon as we become aware of it, as Article 9 requires, and we notify you when the breach is likely to cause you harm, with what happened, what data was involved, what we did, and whom to contact.
9. Children
Zanii ID is not intended for anyone under 18. If you believe a child has an account, tell us and we will remove it.
10. Changes
The version number above changes when this policy changes. Reductions in your rights take effect no sooner than 30 days after we email account holders.