Privacy Policy

Version: 1.1 · Effective date: 29 September 2026 · First published: 11 May 2026 (version 1.0)

This Privacy Policy describes how Hibr AI ("we", "us", "HIBR ERP") collects, uses, stores, and protects personal data of customers, prospects, and visitors. We comply with UAE Federal Decree-Law 45/2021 on the Protection of Personal Data ("PDPL") and, where applicable, GDPR. Waitlist and contact-form data is stored on HIBR's backend host (Hostinger, United Kingdom). HIBR ERP's development build runs on Frappe Cloud; the production hosting region will be published here before any customer business data is stored.

Contents

1. Data controller 2. What we collect 3. How we use it 4. Legal basis (PDPL Article 5) 5. Sharing & processors 6. Data residency & transfers 7. Retention 8. Your rights (PDPL Articles 12–17) 9. Security 10. Cookies 11. Changes to this policy 12. Contact

1. Data controller

The data controller is HIBR e trade (trading as Hibr AI), licensed in Sharjah, United Arab Emirates. For any privacy matter or data-subject request, contact info@hibr.ai.

2. What we collect

Account & identity data

Operational data (when you use HIBR ERP)

Usage & technical data

Demo & lead-magnet inputs

3. How we use it

4. Legal basis (PDPL Article 5)

We process personal data on the following lawful bases:

5. Sharing & processors

We do not sell personal data. We share data only with the sub-processors listed at hibr.ai/subprocessors. Those relevant to HIBR ERP are:

HIBR transmits nothing to the FTA: you submit your own returns through the FTA's EmaraTax portal.

All sub-processors are bound by data processing agreements that include PDPL/GDPR-equivalent obligations.

6. Data residency & cross-border transfers

Waitlist, contact-form and enquiry data is stored today on HIBR's backend host, Hostinger, in the United Kingdom, outside the UAE. HIBR ERP's development build runs on Frappe Cloud; the production hosting region for HIBR ERP customer business data is not yet confirmed and will be published here before any customer business data is stored. Some sub-processors (Stripe, Anthropic) also process data outside the UAE. We rely on Standard Contractual Clauses or adequacy decisions for any transfer. The current list is at hibr.ai/subprocessors.

7. Retention

8. Your rights (PDPL Articles 12–17)

As a UAE data subject, you have the right to:

To exercise any right, email info@hibr.ai. We respond within 30 days as required by PDPL Article 19.

9. Security

We use TLS 1.3 in transit and role-based access control for staff access, and we keep append-only audit logs of AI-assisted answers. We do not currently encrypt stored documents at rest beyond the encryption our hosting provider applies, and HIBR holds no ISO 27001 or SOC 2 certification and none is in progress. An earlier version of this page claimed AES-256 encryption at rest; that was not accurate and has been corrected.

10. Cookies

We use strictly necessary cookies (session authentication, CSRF protection) without consent. Analytics and marketing cookies are loaded only after explicit consent via the cookie banner. You can withdraw consent anytime via the "Cookie preferences" link in the footer of any HIBR ERP page.

11. Changes to this policy

We may update this policy. Material changes will be announced by email to active customers and posted to this page with a new effective date. Historical versions remain available on request.

12. Contact