zaniiid

Privacy Policy

Version 2026-09-05.2-uae-draft · Prepared under Federal Decree-Law No. 45 of 2021 (UAE Personal Data Protection Law)

Draft. Prepared for review by UAE counsel and not yet in force. Every statement below about what the service does is implemented and tested; the statements about legal process await counsel's sign-off.

1. Controller

Zanii, United Arab Emirates, info@zanii.agency, is the controller of the personal data processed to operate Zanii ID. Applications you sign in to ("Relying Parties") are separate controllers for what they receive; the consent screen names the organization behind each one.

2. What we hold, why, and on what basis

DataPurposeLegal basis (PDPL)Kept
Email address; name if givenYour login identity; the claims an application receives when you approve the email and profile scopesNecessary to provide the service you asked for (Art. 4); consent for sharing with each applicationLife of the account
Password hash (Argon2id); encrypted authenticator secret; hashed recovery codes; passkey public keysAuthenticationNecessary to provide the service; security obligation (Art. 20)Until you change or remove them; deleted with the account
Sessions: IP address, browser identifier, times, whether a second factor was usedKeeping you signed in; letting you see and end sessions; fraud detectionNecessary to provide the service; our legitimate interest in security, which does not override your rightsUntil ended; expired sessions are purged
Consents: which application, which scopes, whenKnowing what you approved; letting you revoke itNecessary to provide the serviceUntil revoked or the account is deleted
Security audit log: sign-ins, failures, changes, operator actions with their stated reasonInvestigating incidents; showing you what happenedLegitimate interest in security; legal obligation to keep records of processing (Art. 7)Life of the account plus 12 months
Custodial cryptographic identity (a did:key) and the public ledger receipts recorded under a pseudonymous tagLetting you audit what AI agents, and Zanii itself, did on your accountNecessary to provide the serviceLedger entries are public and permanent by design; they carry a pseudonymous tag and hashes, never your email, name or content
Lifecycle event deliveries to applicationsTelling an application you deleted your account, revoked it, or changed your email or passwordNecessary to give effect to your rightsDelivery records for 30 days

We do not process sensitive personal data, do not profile you, make no decisions about you by automated means, and do not use your data for marketing, ours or anyone else's.

3. What an application receives

Only the claims covered by the scopes you approved. Applications registered by outside organizations receive a pairwise identifier that is stable for that organization and cannot be matched against another organization's identifier for you. Zanii's own first-party applications receive your global account identifier. A second-factor indicator (acr, amr) tells the application how you signed in, not which device you used.

4. Who else sees data

5. Where data is processed

Data is processed on infrastructure operated for Zanii. Where a processor is located outside the United Arab Emirates, the transfer is made under Articles 22 and 23 of the PDPL: to a jurisdiction the UAE Data Office recognises as adequate, or under contractual safeguards that bind the recipient to the protections in this policy. Free-zone establishments (DIFC, ADGM) applying their own data protection laws are treated as separate jurisdictions for this purpose.

6. Your rights

Under the PDPL you can ask for access to and a copy of your data, correction, erasure, restriction, an end to processing, portability, and you can object to processing and to any automated decision. Most of these you can do yourself, immediately, at your account page: export the claims we hold via /userinfo, correct your name and email, revoke any application, end sessions, and delete the account, which removes your data and notifies every application you used. For anything else write to info@zanii.agency; we answer within 30 days. Where we cannot verify it is you, we will ask you to sign in first.

If you are not satisfied, you may complain to the UAE Data Office. If you are in a free zone with its own authority, that authority may be competent instead.

7. Security

Passwords are hashed with Argon2id; signing keys, custodial keys, authenticator secrets and organization salts are encrypted at rest; sessions use host-only secure cookies; every privileged action by Zanii on your account is recorded on a public append-only ledger you can verify offline. Two-step verification and passkeys are available to every account.

8. If something goes wrong

If a breach of personal data is likely to harm your privacy or security, we notify the UAE Data Office as soon as we become aware of it, as Article 9 requires, and we notify you when the breach is likely to cause you harm, with what happened, what data was involved, what we did, and whom to contact.

9. Children

Zanii ID is not intended for anyone under 18. If you believe a child has an account, tell us and we will remove it.

10. Changes

The version number above changes when this policy changes. Reductions in your rights take effect no sooner than 30 days after we email account holders.