Privacy Policy

Last updated 10 August 2026

This policy explains how Infinite Barakah Ventures (“we”), the provider of Cashflow OS, collects, uses, stores and protects personal data. It is written to meet Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the UAE PDPL).

1. Who we are

Infinite Barakah Ventures, Dubai, United Arab Emirates, is the data controller for account and billing data. For the financial records a customer loads into Cashflow OS, the customer is the controller and we act as their processor.

Privacy contact: privacy@infinitebarakah.com.

2. What we collect

3. Why we process it, and on what basis

PurposeLawful basis (PDPL Art. 4)
Providing the service to your organizationNecessary for performance of a contract
Maintaining the audit trail and security logsLegitimate interest in security and record integrity; legal obligation where accounting rules apply
Billing, invoicing and tax recordsLegal obligation (UAE VAT and e-invoicing rules)
Service email such as the daily cash summaryConsent — opt-in, withdrawable at any time from Settings or the unsubscribe link in every message

4. Who we share it with

We do not sell personal data. We use a small number of processors:

5. Where the data lives

Customer data is stored in AWS ap-southeast-2 (Sydney, Australia), via Supabase. The UAE PDPL does not require data localisation, and no transfer restriction applies to this arrangement; the region is disclosed so customers can assess it. Customers with a contractual or regulatory need for a different region should contact us before onboarding.

6. How long we keep it

Customer content is retained for as long as the organization's account is active, and deleted within 90 days of account closure unless a longer period is required by law. Audit and billing records are retained for the statutory retention period. You can export a full copy of your organization's data at any time from Settings, in Excel format.

7. Your rights

Under the PDPL you may request:

Write to privacy@infinitebarakah.com. We respond within 30 days. If you are an employee of a customer organization, we may need to route your request through that organization, since they control the record.

8. Security

Data is encrypted in transit (TLS 1.2+) and at rest. Every tenant table is protected by database-level row-level security keyed on organization, so one customer's query cannot return another's rows. Access inside a customer organization is role-based, and every write is recorded in an append-only audit trail. A security summary is available on request.

9. Breach notification

If a personal data breach occurs that is likely to prejudice the privacy, confidentiality or security of data subjects, we notify the UAE Data Office and affected customers without undue delay, and in any case within 72 hours of becoming aware of it. Notification describes what happened, the data involved, the likely consequences, and the steps taken.

10. Changes

We will post any change here and update the date above. Material changes are also emailed to organization administrators.