Scope & introduction
This Privacy Policy describes how Darwaza Enterprise ("we", "us", "our") processes information when employees, contractors, and authorised partners use the Darwaza internal portal and any connected workflow, approval, or service-desk modules (collectively, the "Platform").
By signing in with your corporate credentials you acknowledge the practices set out below. This policy works alongside the Terms of Use and any role-specific data agreements provided by your line of business.
Information we collect
We collect only the information needed to operate the Platform, route approvals correctly, and meet our legal obligations. The categories below summarise what we hold:
- Identity data
- Full name, employee ID, job title, department, line manager, work location.
- Contact data
- Corporate email, work phone number, office address.
- Authentication
- Single sign-on tokens, multi-factor enrolment status, session timestamps.
- Operational data
- Service requests you raise, approvals you issue, files you attach, comments you post.
- Technical data
- Device type, browser, IP address, locale, pages visited, performance traces.
We do not collect special-category data (health, biometric, religious belief) through Darwaza unless explicitly required by a workflow you initiate, in which case the form will state the purpose and lawful basis at the point of capture.
How we use your information
Information is processed for the following purposes:
- Authenticating you, presenting your personalised dashboard, and routing requests to the correct approver chain.
- Providing audit trails so that managers, finance, and compliance can verify who approved what and when.
- Improving Platform reliability through aggregated usage metrics and incident diagnostics.
- Meeting statutory record-keeping obligations under applicable Sultanate of Oman regulations and internal policy.
- Communicating service notifications, scheduled-maintenance alerts, and security advisories.
Data retention
We retain operational records for the period required to satisfy the original purpose, contractual commitments, and statutory obligations. Closed service requests and supporting attachments are retained for seven years, after which they are securely archived or deleted in line with our records-management schedule.
Your rights
Subject to applicable law and your employment agreement, you may exercise the following rights with respect to your personal information:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete information.
- Restriction — request that we limit processing in specific circumstances.
- Objection — object to processing where we rely on legitimate interest.
- Portability — receive a structured, machine-readable export of your records.
Requests can be raised via the in-portal data-rights form or by emailing the Data Protection Office. We aim to respond within thirty calendar days.
Security
The Platform is protected by enterprise-grade controls including encrypted transport (TLS 1.3), encrypted storage, role-based access, mandatory MFA for privileged accounts, continuous logging, and quarterly penetration testing. Despite these measures, no system is completely immune to risk; we encourage you to report suspicious activity to the IT Security desk immediately.
Contact us
For questions about this policy or to exercise your data rights, contact the Darwaza Data Protection Office.
Data Protection Office
privacy@darwaza.app · +968 24 000 000 · Building H, Floor 4