Privacy Policy
Last updated: 2026-05-09
Damagix is operated by KBR Global FZ-LLC (the "Company", "we"). This policy describes what we collect, why, and what your rights are under UAE Federal Decree-Law No. 45 of 2021 (PDPL) and other applicable law.
What we collect
- Account data: name, email, role (tenant / landlord / buyer), phone (optional).
- Property metadata: address, Ejari contract number, Makani number, room layout.
- Inspection content: photos and short videos you capture, AI-generated defect descriptions you confirm, optional voice notes.
- Device data: GPS coordinates and bearing at capture (watermarked into photos), device timestamp, server-side timestamp.
- Payment data: Apple / Google purchase receipt token (we never see your card). VAT-inclusive amount.
- Logs: request URL, IP, user-agent — kept up to 90 days for security and rate-limit enforcement.
What we don't collect
- Card numbers, CVV, or bank credentials — Apple / Google handle the payment flow end-to-end.
- Contacts, calendar, microphone (until you tap the mic button), or browsing history.
- Health, biometric, or children's data.
How we use it
- To generate your inspection report (the entire purpose of the app).
- To verify a report's authenticity when a third party scans the QR code.
- To run the AI defect detection (Manus AI). Photos are sent to Manus; their privacy policy applies in addition to ours.
- To send transactional email (Resend) and SMS (Unifonic) — signature requests, magic-link tokens, refund notifications.
- To prevent fraud and abuse — rate limits, refund / chargeback handling.
Where it lives
- Photos and PDFs: Cloudflare R2, UAE-region edge.
- Database: Postgres on Railway (encrypted at rest, TLS in transit).
- Logs: Railway log retention (rolling 30 days).
Who we share with
- Manus AI — photo content for defect detection.
- Apple / Google — purchase receipts only (you initiated the transaction).
- Resend — email delivery.
- Unifonic — SMS delivery (UAE).
- Counterparty — when you sign a report, the counterparty (landlord / tenant) sees the report and your name. This is the entire point.
- Authorities — only when legally compelled by UAE court order.
How long we keep it
Reports and supporting media: 7 years (UAE record-keeping standard for property contracts). Account data: until you delete the account. Logs: 90 days.
Your rights
- Access — email privacy@damagix.com and we'll export your data within 30 days.
- Deletion — same email. We'll delete account + media; reports already issued may remain in our verification log (revoked status) so counterparties get a "Report Revoked" page rather than 404.
- Correction — edit your profile in the app or email us.
- Withdraw consent — you can stop using the app and we'll stop processing.
Contact
KBR Global FZ-LLC, Dubai, UAE. privacy@damagix.com.
← Back to home