Privacy Policy
This policy explains what we do with personal data: the data you give us as a firm, and the data your firm holds about its own clients inside the platform. Those are two different things, and we treat them differently.
Last updated — 27 August 2026
1. Overview
AudiTax is a product operated by WalQalum Technologies LLC ("we", "us") — the company that contracts with you, takes your payment, and is the data controller named in this policy. "AudiTax" is the name of the product, not a separate legal entity. The platform is a compliance and practice-management system for tax, accounting and audit firms in the United Arab Emirates, and this policy applies to our marketing website at auditax.ai, our web and mobile applications, and the support and sales channels attached to them.
It is written to be read, not to be survived. Where something about how we handle data involves a trade-off, we have said what the trade-off is rather than describing it in a way that sounds better than it is.
The service is sold to businesses. It is not intended for personal or household use, and it is not intended for anyone under 18.
2. The two roles we play
Almost every question about this platform's privacy has a different answer depending on whose data is being asked about.
When we are the controller
For the people who deal with us directly — the person who fills in the contact form, the administrator who opens an account, the staff members that administrator invites — we decide why and how their data is processed. We are the controller, and this policy is the full account of what we do.
When we are the processor
For the client records your firm creates inside the platform — the companies you file for, their trade licences, their passports and Emirates IDs, their documents — your firm is the controller and we are the processor. We hold and process that data on your instructions, in order to run the service you are paying for. We do not decide what goes in, we do not use it for our own purposes, and we do not sell it.
3. What we collect
Account and profile data
When an account is created we collect the account holder's name, work email address, phone number, password and role. Staff profiles may also carry a job title, department, an avatar image and internal notes written by the firm's administrator. Passwords are stored only as a bcrypt hash — we never hold the password itself and cannot recover or read it.
Client records your firm enters
The platform exists to hold the compliance record of your firm's clients. Depending on which parts of it you use, that can include:
- Identity and contact details — name, email address, phone number, physical address and emirate
- Government identifiers — passport number and expiry date, Emirates ID number, residency status
- Licensing — trade licence number and expiry, establishment card and expiry
- Tax registration — VAT registration status and TRN, corporate tax registration number, financial year end, filing periods and due dates
- Know-your-customer records, including details of related parties, shareholders and beneficial owners
- Credentials for the Federal Tax Authority portal, where your firm chooses to store them (see section 6)
- Documents uploaded to the vault — licences, passports, contracts, financial statements and anything else you put there
Some of this is sensitive by any standard. We have designed around that, and sections 5 to 8 explain how.
Billing data
Subscriptions are processed by Stripe. Card numbers are entered directly with Stripe and never reach our servers — we hold only the subscription status, plan, billing history and the identifiers Stripe gives us to match a payment to an account.
Things you send us
The contact form on our website records the name, work email, phone number, business name and message you submit, together with the IP address the submission came from, which we keep to detect abuse of the form. Support conversations, sales emails and messages sent through the in-app team chat are retained as part of the record of the service.
Technical data
Our servers keep operational logs — request times, error traces, and the account and organisation an action belonged to. Within the application, an audit trail records who changed which record and when; that trail is a compliance feature of the product and is visible to your firm's administrators.
4. How we use it
We use personal data to:
- Provide the platform — authenticate users, show the right records to the right people, run the compliance calendar and send the reminders it generates
- Send service messages — verification codes, deadline alerts, notifications about your account, and push notifications on mobile where you have enabled them
- Take payment and manage subscriptions, seats and add-ons
- Provide support, and investigate problems you report
- Keep the service secure — rate limiting, abuse detection, and the audit trail that shows what happened to a record
- Meet our own legal and accounting obligations
- Respond to sales enquiries you send us
We do not sell personal data. We do not share it with advertisers, and we do not use the client records held in the platform to build profiles, train models, or market to the individuals in them.
5. Our legal grounds for processing
Where the UAE Personal Data Protection Law or the EU/UK GDPR applies to a given processing activity, we rely on the following grounds:
| What we do | Ground we rely on |
|---|---|
| Running the platform for a firm that subscribes to it | Performance of a contract |
| Processing client records inside the platform | Our customer's instructions, under a processing agreement |
| Billing, dunning and financial record-keeping | Contract, and our legal obligations |
| Security, abuse prevention and audit logging | Legitimate interests in keeping the service and its data safe |
| Responding to a sales enquiry you sent us | Your request, and our legitimate interest in replying to it |
| Optional marketing email | Your consent, which you can withdraw at any time |
6. Documents, encryption, and what recovery costs you
Documents placed in the vault can be individually protected with a password. When they are, the file is encrypted with AES-256-GCM under a randomly generated key, and that key is wrapped with a key derived from the password using scrypt. We do not store the password and we do not store a hash of it — an incorrect password simply fails to unwrap the key.
The recovery copy, stated plainly
By default, a second wrapped copy of that same file key is also stored, wrapped under a platform master key. It exists so that a firm does not permanently lose a statutory record when the staff member who set the password leaves. It can only be used through an administrator reset, and that reset is written to the audit trail.
If you need zero-knowledge, the platform supports it. A document saved without the recovery copy can be opened only with its password, and if that password is lost the document cannot be recovered by anyone, including us. That is the trade you are making, in whichever direction you make it.
Federal Tax Authority credentials
If your firm chooses to store a client's FTA portal username and password against their record, that is a convenience feature we provide at your instruction. Those credentials are protected by the same infrastructure controls as the rest of your data and are masked in the record's change history — but they are readable by users in your firm who have access to that client, and they are included in the client data exports your firm can generate. Treat access to them as you would treat access to the portal itself.
Uploaded files are scanned before they are made available, and files that fail the scan are quarantined rather than served.
8. Where your data is held
Data is stored on managed cloud infrastructure operated by Amazon Web Services and MongoDB Atlas. Backups are held with the same providers.
Personal data may be stored and processed outside the United Arab Emirates. Where it is, we rely on the transfer mechanisms permitted by the applicable law, including contractual protections with our providers that hold them to the standard of protection described in this policy.
If you need to know the specific region your firm’s data is held in — for your own regulatory assessment, or for a client’s — write to info@auditax.ai and we will tell you in writing.
9. How long we keep it
| Data | Kept for |
|---|---|
| Account and profile data | As long as the account is open |
| Client records and documents | As long as your firm keeps them, plus the retention your own regulatory duties require |
| Deleted files | 30 days in trash, then permanently purged from storage |
| Audit and activity logs | Retained as a compliance record of the account |
| Billing records | As long as tax and company law requires us to keep them |
| Contact form enquiries | Retained while the enquiry is live and for our sales records afterwards |
When a subscription ends, contact us to arrange an export before the account is closed. Deletion is not instantaneous everywhere — backups roll off on their own cycle — but data removed from the live system is not restored to it.
Note that a firm's own regulatory obligations may require it to keep client records for a period defined by UAE law. Where that is the case, the firm's retention duty governs, not ours.
10. Security
The measures we take include:
- Encryption in transit (TLS) and at rest
- Passwords stored only as bcrypt hashes, never in a recoverable form
- Role-based access control, so staff see only what their role permits
- Tenant isolation — every record is scoped to the organisation that owns it, enforced at the data layer rather than left to each query
- An audit trail on record changes, showing who did what and when
- Rate limiting and abuse protection on public endpoints
- Malware scanning on uploaded files
No system is perfectly secure, and we will not claim otherwise. If a breach affects your personal data we will notify you and the relevant authority as the applicable law requires.
11. Your rights
Subject to the law that applies to you, you can ask us to:
- Give you a copy of the personal data we hold about you
- Correct it, if it is wrong
- Delete it, where we have no continuing basis to keep it
- Provide it in a portable format
- Restrict or object to a particular use of it
- Withdraw a consent you previously gave
Write to info@auditax.ai and we will respond within 30 days. We may need to verify who you are first — the alternative is disclosing someone's tax records to whoever asks for them.
You also have the right to complain to your data protection authority.
13. Changes to this policy
When we change this policy we update the date at the top of the page. If a change materially affects how we handle your data — a new category of data, a new purpose, a new class of recipient — we will tell account holders by email before it takes effect, rather than relying on you to re-read the page.
14. Contact us
For anything in this policy, including a request to exercise your rights:
- Email — info@auditax.ai
- General enquiries — hello@auditax.ai
- Registered entity — WalQalum Technologies LLC
- Trade licence — 2542734
- Registered address — Sharjah Media City, Sharjah, United Arab Emirates