Legal

Privacy Policy

This policy explains what we do with personal data: the data you give us as a firm, and the data your firm holds about its own clients inside the platform. Those are two different things, and we treat them differently.

Last updated27 August 2026

1. Overview

AudiTax is a product operated by WalQalum Technologies LLC ("we", "us") — the company that contracts with you, takes your payment, and is the data controller named in this policy. "AudiTax" is the name of the product, not a separate legal entity. The platform is a compliance and practice-management system for tax, accounting and audit firms in the United Arab Emirates, and this policy applies to our marketing website at auditax.ai, our web and mobile applications, and the support and sales channels attached to them.

It is written to be read, not to be survived. Where something about how we handle data involves a trade-off, we have said what the trade-off is rather than describing it in a way that sounds better than it is.

The service is sold to businesses. It is not intended for personal or household use, and it is not intended for anyone under 18.

2. The two roles we play

Almost every question about this platform's privacy has a different answer depending on whose data is being asked about.

When we are the controller

For the people who deal with us directly — the person who fills in the contact form, the administrator who opens an account, the staff members that administrator invites — we decide why and how their data is processed. We are the controller, and this policy is the full account of what we do.

When we are the processor

For the client records your firm creates inside the platform — the companies you file for, their trade licences, their passports and Emirates IDs, their documents — your firm is the controller and we are the processor. We hold and process that data on your instructions, in order to run the service you are paying for. We do not decide what goes in, we do not use it for our own purposes, and we do not sell it.

3. What we collect

Account and profile data

When an account is created we collect the account holder's name, work email address, phone number, password and role. Staff profiles may also carry a job title, department, an avatar image and internal notes written by the firm's administrator. Passwords are stored only as a bcrypt hash — we never hold the password itself and cannot recover or read it.

Client records your firm enters

The platform exists to hold the compliance record of your firm's clients. Depending on which parts of it you use, that can include:

  • Identity and contact details — name, email address, phone number, physical address and emirate
  • Government identifiers — passport number and expiry date, Emirates ID number, residency status
  • Licensing — trade licence number and expiry, establishment card and expiry
  • Tax registration — VAT registration status and TRN, corporate tax registration number, financial year end, filing periods and due dates
  • Know-your-customer records, including details of related parties, shareholders and beneficial owners
  • Credentials for the Federal Tax Authority portal, where your firm chooses to store them (see section 6)
  • Documents uploaded to the vault — licences, passports, contracts, financial statements and anything else you put there

Some of this is sensitive by any standard. We have designed around that, and sections 5 to 8 explain how.

Billing data

Subscriptions are processed by Stripe. Card numbers are entered directly with Stripe and never reach our servers — we hold only the subscription status, plan, billing history and the identifiers Stripe gives us to match a payment to an account.

Things you send us

The contact form on our website records the name, work email, phone number, business name and message you submit, together with the IP address the submission came from, which we keep to detect abuse of the form. Support conversations, sales emails and messages sent through the in-app team chat are retained as part of the record of the service.

Technical data

Our servers keep operational logs — request times, error traces, and the account and organisation an action belonged to. Within the application, an audit trail records who changed which record and when; that trail is a compliance feature of the product and is visible to your firm's administrators.

4. How we use it

We use personal data to:

  • Provide the platform — authenticate users, show the right records to the right people, run the compliance calendar and send the reminders it generates
  • Send service messages — verification codes, deadline alerts, notifications about your account, and push notifications on mobile where you have enabled them
  • Take payment and manage subscriptions, seats and add-ons
  • Provide support, and investigate problems you report
  • Keep the service secure — rate limiting, abuse detection, and the audit trail that shows what happened to a record
  • Meet our own legal and accounting obligations
  • Respond to sales enquiries you send us

We do not sell personal data. We do not share it with advertisers, and we do not use the client records held in the platform to build profiles, train models, or market to the individuals in them.

6. Documents, encryption, and what recovery costs you

Documents placed in the vault can be individually protected with a password. When they are, the file is encrypted with AES-256-GCM under a randomly generated key, and that key is wrapped with a key derived from the password using scrypt. We do not store the password and we do not store a hash of it — an incorrect password simply fails to unwrap the key.

The recovery copy, stated plainly

By default, a second wrapped copy of that same file key is also stored, wrapped under a platform master key. It exists so that a firm does not permanently lose a statutory record when the staff member who set the password leaves. It can only be used through an administrator reset, and that reset is written to the audit trail.

If you need zero-knowledge, the platform supports it. A document saved without the recovery copy can be opened only with its password, and if that password is lost the document cannot be recovered by anyone, including us. That is the trade you are making, in whichever direction you make it.

Federal Tax Authority credentials

If your firm chooses to store a client's FTA portal username and password against their record, that is a convenience feature we provide at your instruction. Those credentials are protected by the same infrastructure controls as the rest of your data and are masked in the record's change history — but they are readable by users in your firm who have access to that client, and they are included in the client data exports your firm can generate. Treat access to them as you would treat access to the portal itself.

Uploaded files are scanned before they are made available, and files that fail the scan are quarantined rather than served.

7. Who else touches the data

We use a small number of service providers to run the platform. They process data on our instructions and are bound to protect it.

ProviderWhat it doesWhat it sees
MongoDB AtlasManaged databaseAll application data
Amazon Web Services (S3)File and document storageUploaded files and documents
StripeSubscription paymentsBilling contact and payment details
OneSignalMobile push notificationsDevice tokens and notification content
Email delivery providerTransactional emailRecipient address and message content

Beyond those, we disclose personal data only where we are legally required to — a binding order from a competent authority — or where a business is transferred, in which case the acquirer is bound by this policy until it is properly replaced and you are told about it.

We do not give any third party the right to use your data for its own purposes.

8. Where your data is held

Data is stored on managed cloud infrastructure operated by Amazon Web Services and MongoDB Atlas. Backups are held with the same providers.

Personal data may be stored and processed outside the United Arab Emirates. Where it is, we rely on the transfer mechanisms permitted by the applicable law, including contractual protections with our providers that hold them to the standard of protection described in this policy.

If you need to know the specific region your firm’s data is held in — for your own regulatory assessment, or for a client’s — write to info@auditax.ai and we will tell you in writing.

9. How long we keep it

DataKept for
Account and profile dataAs long as the account is open
Client records and documentsAs long as your firm keeps them, plus the retention your own regulatory duties require
Deleted files30 days in trash, then permanently purged from storage
Audit and activity logsRetained as a compliance record of the account
Billing recordsAs long as tax and company law requires us to keep them
Contact form enquiriesRetained while the enquiry is live and for our sales records afterwards

When a subscription ends, contact us to arrange an export before the account is closed. Deletion is not instantaneous everywhere — backups roll off on their own cycle — but data removed from the live system is not restored to it.

Note that a firm's own regulatory obligations may require it to keep client records for a period defined by UAE law. Where that is the case, the firm's retention duty governs, not ours.

10. Security

The measures we take include:

  • Encryption in transit (TLS) and at rest
  • Passwords stored only as bcrypt hashes, never in a recoverable form
  • Role-based access control, so staff see only what their role permits
  • Tenant isolation — every record is scoped to the organisation that owns it, enforced at the data layer rather than left to each query
  • An audit trail on record changes, showing who did what and when
  • Rate limiting and abuse protection on public endpoints
  • Malware scanning on uploaded files

No system is perfectly secure, and we will not claim otherwise. If a breach affects your personal data we will notify you and the relevant authority as the applicable law requires.

11. Your rights

Subject to the law that applies to you, you can ask us to:

  • Give you a copy of the personal data we hold about you
  • Correct it, if it is wrong
  • Delete it, where we have no continuing basis to keep it
  • Provide it in a portable format
  • Restrict or object to a particular use of it
  • Withdraw a consent you previously gave

Write to info@auditax.ai and we will respond within 30 days. We may need to verify who you are first — the alternative is disclosing someone's tax records to whoever asks for them.

You also have the right to complain to your data protection authority.

13. Changes to this policy

When we change this policy we update the date at the top of the page. If a change materially affects how we handle your data — a new category of data, a new purpose, a new class of recipient — we will tell account holders by email before it takes effect, rather than relying on you to re-read the page.

14. Contact us

For anything in this policy, including a request to exercise your rights:

  • Email — info@auditax.ai
  • General enquiries — hello@auditax.ai
  • Registered entity — WalQalum Technologies LLC
  • Trade licence — 2542734
  • Registered address — Sharjah Media City, Sharjah, United Arab Emirates