1. Introduction
iPayHub Solutions FZE LLC ("Company," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, engage our services, or interact with us in any way.
Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our services.
2. Information We Collect
We collect information you voluntarily provide to us, including:
- Contact Information: Name, email address, phone number, company name, job title, mailing address
- Project Details: Information about your business, infrastructure, requirements, and goals shared during discovery calls or consultations
- Payment Information: Billing address, payment method details (processed securely through third-party payment gateways)
- Communication: Messages sent through contact forms, emails, or support channels
- Documentation: Files, reports, credentials, access logs, and technical data shared during project execution
When you visit our website, we automatically collect:
- Device Information: IP address, browser type, operating system, device type
- Usage Data: Pages visited, time spent on site, links clicked, referral source
- Cookies: Session identifiers and preference tracking (see Section 7)
- Analytics: Aggregated, non-personally identifiable usage patterns
We may receive information about you from:
- Payment processors and financial institutions
- Business partners and referral sources
- Public databases and professional networks
3. How We Use Your Information
We use collected information for the following purposes:
- Service Delivery: To provide, maintain, and improve our IT consulting services
- Communication: To respond to inquiries, send project updates, and provide customer support
- Billing & Payments: To process transactions, issue invoices, and manage accounts
- Legal Compliance: To comply with laws, regulations, and contractual obligations
- Security: To detect, prevent, and address fraud, security issues, and technical problems
- Marketing: To send newsletters, case studies, and service updates (with your consent)
- Analytics: To understand how you use our services and optimize our offerings
- Dispute Resolution: To resolve claims and enforce our Terms & Conditions
4. Legal Basis for Processing (GDPR Compliance)
If you are located in the EU, EEA, or UK, we process your personal data based on the following legal grounds:
| Processing Purpose | Legal Basis |
|---|---|
| Service Delivery & Contracts | Contractual Necessity |
| Billing & Payment Processing | Contractual Necessity & Legal Obligation |
| Security & Fraud Prevention | Legitimate Interests |
| Marketing Communications | Consent |
| Legal Compliance | Legal Obligation |
| Analytics & Improvement | Legitimate Interests |
5. Data Sharing & Disclosure
We may share your information with:
- Service Providers: Cloud platforms (AWS, GCP, Azure), payment processors, email services
- Business Partners: Third-party vendors needed to deliver your project (with NDAs in place)
- Legal Requirements: Law enforcement, government agencies, or courts when legally compelled
- Business Transactions: In case of merger, acquisition, or asset sale (we will notify you)
We do NOT:
- Sell or rent your personal data to third parties
- Share data for marketing purposes without explicit consent
- Disclose Client systems, credentials, or proprietary information to unauthorized parties
6. Data Security
We implement industry-standard security measures to protect your information, including:
- SSL/TLS encryption for data in transit
- Encrypted storage for sensitive data at rest
- Access controls and role-based permissions
- Regular security audits and penetration testing
- Secure password policies and multi-factor authentication
- Employee confidentiality agreements and security training
Disclaimer: While we take security seriously, no system is 100% secure. We cannot guarantee absolute protection against all potential breaches. You are responsible for maintaining the confidentiality of your account credentials.
7. Cookies & Tracking Technologies
Cookies are small text files stored on your device to enhance your browsing experience. We use:
- Essential Cookies: Required for website functionality (authentication, security)
- Performance Cookies: Track usage analytics to improve our services
- Marketing Cookies: Remember your preferences for personalized content (optional)
You can control cookies through your browser settings. Disabling cookies may affect website functionality. We respect Do Not Track signals and do not track users across third-party websites.
8. Data Retention
We retain your information for as long as necessary to provide services and comply with legal obligations:
- Active Clients: Duration of engagement + 7 years (for tax/legal compliance)
- Prospective Clients: Up to 2 years from last interaction
- Website Visitors: Analytics data retained for 12 months
- Legal Holds: Extended retention if required by law enforcement or litigation
You may request data deletion at any time (subject to legal retention requirements).
9. Your Rights
If you are in the EU, EEA, UK, or any jurisdiction with similar laws, you have the right to:
- Access: Request a copy of your personal data we hold
- Correction: Ask us to correct inaccurate or incomplete information
- Deletion: Request erasure of your data ("Right to be Forgotten")
- Portability: Receive your data in a structured, machine-readable format
- Restrict Processing: Limit how we use your information
- Withdraw Consent: Opt-out of marketing communications anytime
- Object: Challenge certain processing activities
- File a Complaint: Contact your local data protection authority
To exercise these rights, email privacy@ipayhubsolutions.com with "Data Request" in the subject line. We will respond within 30 days.
10. International Data Transfers
We are UAE-based but serve global clients. When we transfer data internationally (e.g., to US or EU vendors), we:
- Use Standard Contractual Clauses (SCCs) for EU-US transfers
- Require Data Processing Agreements (DPAs) with all subprocessors
- Comply with GDPR adequacy decisions and mutual legal frameworks
By using our services, you consent to these international transfers under appropriate safeguards.
11. Third-Party Links & Services
Our website may contain links to third-party sites (payment gateways, cloud providers, analytics platforms). We are not responsible for their privacy practices. Please review their privacy policies before providing information.
Third-party services we use:
- Network International (primary payment processing for credit/debit cards)
- AWS, Google Cloud, Microsoft Azure (cloud infrastructure)
- Google Analytics (website analytics)
- Mailchimp, SendGrid (email communication)
12. Compliance with Specific Regulations
For healthcare clients, we sign Business Associate Agreements (BAAs) to ensure HIPAA compliance for Protected Health Information (PHI).
We maintain SOC 2 Type II compliance for financial data security and audit trails.
As a UAE-registered entity, we comply with UAE Federal Decree No. 45/2021 (Data Protection Law) and Dubai's DFSA regulations.
13. Children's Privacy
Our services are not directed to children under 13. We do not knowingly collect personal information from minors. If we become aware of data collection from a child, we will delete it immediately. Parents concerned about data collection may contact us at support@ipayhubsolutions.com.
14. Changes to This Privacy Policy
We may update this Privacy Policy periodically. We will notify you of material changes by:
- Posting the updated policy on our website with a new "Last Updated" date
- Sending an email notification for significant changes
Continued use of our services after updates constitutes acceptance of the revised policy.
15. Data Protection Officer & Contact Information
For privacy questions, data requests, or concerns:
iPayHub Solutions FZE LLC
Privacy Inquiries: privacy@ipayhubsolutions.com
General Support: support@ipayhubsolutions.com
Website: www.ipayhubsolutions.com
Response Time: 30 days for data requests
- We never sell your data
- Full GDPR & international data protection compliance
- Encrypted data in transit and at rest
- 7-year data retention for clients, automatic deletion otherwise
- Your rights: access, correction, deletion, portability