Skip to content
Hayatiqحياتيك

Privacy Policy

Draft of September 14, 2026

Draft for review. This document has not yet been reviewed by a lawyer and is not in force. It is published so you can read what Hayatiq intends to offer; bracketed items are still to be settled, and the final text will be published before checkout opens.

This policy explains what Hayatiq Financials (the Service) does with data, where that happens, who else is involved, and what you can ask of us. It is written to be read alongside the Terms of Service; firms that process their clients' data through the Service can also enter into our Data Processing Agreement.

Who we are. The Service is operated by [registered name of the FZE that operates hayatiq.ai], a free zone establishment registered in Ajman, United Arab Emirates, at [registered address, Ajman, United Arab Emirates] — the same entity as in the Terms (Hayatiq, we). Contact for anything in this policy, including every request about your data: privacy@hayatiq.ai. Help using the Service: support@hayatiq.ai. Anything else: hello@hayatiq.ai. [Lawyer to confirm whether a data protection officer, a KSA-appointed representative or an EU/UK representative is required, and to name them here if so].

Two roles. For your account, the waitlist, billing, support and this website, Hayatiq decides why and how data is processed: we are the controller. For the trial balances, mappings, answers and names you enter into an engagement — data about your business or your clients' businesses — you decide; Hayatiq processes it only on your instructions as your processor, under the Data Processing Agreement.

Where the product stands. This draft is dated 14 September 2026, during a private beta. Sign-in and saving engagements are in development at that date; the purge job, column-level encryption, the assistant's zero-data-retention arrangement and DOCX/XLSX export are planned. Each is marked as such below rather than described as if it were already running.

1. The short version

  • The engine runs in your browser. Uploading a trial balance, mapping it, answering the questionnaire, filling the worksheet, generating the statements, the tie-outs and the checklist all happen on your device. Nothing about an engagement is sent to Hayatiq until you take one of four explicit actions: save, ask the assistant, generate note narrative, or export.
  • Until you save, an engagement lives in your browser's own storage (IndexedDB), under your control; clearing site data removes it.
  • When you save, Hayatiq stores canonical balance rows and a rebuildable snapshot of your choices — never the uploaded file itself — in a database in Frankfurt, Germany, isolated per organisation by row-level security.
  • Hayatiq never puts client financial data in logs or analytics.
  • The assistant is disabled until its model provider has confirmed zero data retention in writing.
  • We use six sub-processors, listed in section 11 with what each receives.
  • You can ask us to access, correct, export or delete your data (section 15).

2. What happens in your browser, and what reaches Hayatiq

StepWhere it runsWhat Hayatiq receives
Creating an engagement (entity name, period, currency)Browser (IndexedDB)Nothing, until you save
Uploading and parsing the trial balances (Excel or CSV)Browser, in a Web WorkerNothing. The file is read on your device; Hayatiq never receives the file
Mapping accounts by keyword rules and the standard chartBrowserNothing
Asking the assistant for a mapping suggestionHayatiq server, then model providerAccount codes, account names and a category label only — no balances. Disabled until zero data retention is in place
Questionnaire and cash-flow worksheetBrowserNothing, until you save
Generating statements, tie-outs and the checklistBrowser, in a Web WorkerNothing
Saving the engagementHayatiq server (Supabase)The snapshot described in section 3, under your signed-in identity. In development
Generating note narrative with the assistantHayatiq server, then model providerA facts object for the note (the engine's figures and your answers, not the trial balance). Disabled until zero data retention
Exporting DOCX or XLSXHayatiq serverThe snapshot, from which the server rebuilds the statements and renders the files. Planned

The header of every engagement screen carries a "Where your data is" indicator that reads "In this browser only" until a save has happened, and links back to this policy.

3. The save boundary: what a saved engagement holds

When you save an engagement, the Service sends Hayatiq a rebuildable snapshot of your work, together with the version numbers of the engine, the line-item schema, the chart of accounts and the framework pack it was built with, so that the same figures can be rebuilt later. The snapshot holds:

  • canonical balance rows for both years — account code, account name and balance — together with the parse report (row counts, warnings);
  • the confirmed mapping — each account's statement line, status, traits and who confirmed it (the assistant's suggestions are not stored; they are re-derived on load);
  • questionnaire answers and the cash-flow policies you chose;
  • the cash-flow worksheet, including confirmed derived figures, the prior-year cash-flow statement, note worksheet tables, and any equity movements you classified;
  • the no-storage flag, if you set it (section 10).

The snapshot never holds the uploaded file itself, the assistant's per-account suggestions, or a generated statement set: statements are rebuilt from the snapshot on the server at export time and are not kept between exports. For each upload the Service keeps metadata only — file name, size, a cryptographic hash of the contents, the layout detected and row counts — never the rows.

Names of people can appear in a snapshot where they appear in your data: an account name, a related-party answer, a director named in a note table. That is why the two columns that hold answers and snapshots are the ones scheduled for column-level encryption (section 13), and why the Data Processing Agreement treats the snapshot as your personal data processed on your instructions.

4. Account and sign-in data

Sign-in to Hayatiq ID is by a one-time link sent to your e-mail address (in development at the draft date). We hold your e-mail address, the organisation you belong to and your role in it (owner, preparer, reviewer), the time of sign-in, and the session that keeps you signed in. Hayatiq stores no passwords. Legal basis (where the GDPR applies): performance of the contract with you; PDPL basis: necessary to perform the agreement to which you are party.

An organisation's owner can invite members by e-mail address. If the address is already registered, that person becomes a member at once; otherwise they become one on sign-up. The invitation call returns nothing, so an owner cannot use it to learn whether an address is registered — though they will see a registered address in their own roster.

5. The waitlist

The landing page's waitlist form collects an e-mail address only — no name, no company — and stores it, lower-cased, with the time of submission and the word "landing". It is used solely to tell you when sign-up opens. We keep it until you sign up or ask to be removed, or for [twelve (12) months after launch — owner to confirm the retention period], whichever is sooner. Legal basis: your consent, given by submitting the form; withdraw it at any time by writing to privacy@hayatiq.ai.

6. Billing data

Purchases are made from Paddle, our merchant of record. Paddle collects your name, e-mail address, billing address, tax number where relevant, and payment details, and issues receipts; Paddle is a controller of that data under its own privacy notice (section 11). Hayatiq receives from Paddle the events needed to run your subscription — a customer and subscription identifier, the plan, the billing period and the status — and stores only the fields it acts on. Hayatiq never receives or stores card numbers, and its record of a Paddle event holds no name, e-mail address, postal address or amount; the full record stays in Paddle.

7. Support and correspondence

If you write to us — support@hayatiq.ai for help with the Service, hello@hayatiq.ai for anything else — we keep the correspondence and the details in it for as long as needed to deal with your request and for [twenty-four (24) months — owner to confirm] afterwards for reference. Please do not send trial balances or client data by e-mail; the Service is built so that you never need to.

8. Analytics and logs — no client financial data

Hayatiq measures how the product is used with Vercel Analytics. The events it sends are named steps — upload, mapped, generated, exported, checkout — with counts, category values and true/false flags only. No entity name, account name, balance or file name is ever sent to analytics; this is a hard rule of the codebase enforced by a review gate. The page-view beacon reports the page path, which on an engagement screen contains the engagement's random identifier (an opaque code), never a client value. Vercel Analytics does not use cookies and does not track you across sites.

Server logs record reason codes and counts — "parse failed, 3 rows" — never a row from a trial balance, an account name, a balance or a difference. Code that could log anything else is blocked by an automated lint rule with a single, reviewed exception that accepts codes and counts only. Hosting providers keep their own connection logs (IP address, time, URL, user agent) for security and operations, for the periods in their notices (section 11); Hayatiq's own log retention is [owner to state the log retention configured in Vercel and Supabase].

9. Cookies and browser storage

The Service uses only what it needs to work:

  • a locale preference cookie set by the site framework (NEXT_LOCALE) so that pages open in your language;
  • session cookies that keep you signed in to Hayatiq ID (once sign-in is available), set by the authentication provider and readable only by the Service;
  • IndexedDB, the browser's local database, which holds each engagement draft on your device until you save it or delete it (section 1).

There are no advertising cookies, no third-party tracking cookies and no fingerprinting. [Lawyer to confirm that no consent banner is required for this set of strictly necessary cookies in the jurisdictions served].

10. Retention, deletion and no-storage mode

DataKept for
An unsaved engagement draftIn your browser only, until you delete it or clear site data. Hayatiq never has it
A saved engagement snapshot and its working rowsUntil you delete the engagement, or the purge job removes them in no-storage mode (below). [Owner to confirm any maximum retention after account closure]
Engagement record, upload metadata, mapping templateUntil you delete the engagement or close the account; these survive a no-storage purge so next year's roll-forward still works
Export files (planned)Stored so you can download them again; removed by the purge in no-storage mode; the record that an export happened (format, time, plan usage) is kept as metadata for billing
Account (e-mail, organisation, role)Until you close the account, then [thirty (30) days — owner to confirm] before deletion, except records we must keep for tax, billing or legal reasons
Billing events from PaddleFor the life of the subscription and [the statutory record-keeping period — lawyer to state] afterwards
Waitlist e-mailSection 5
BackupsPoint-in-time recovery on the database is a planned launch item; when on, a deleted row can persist in backups for the recovery window, currently intended to be [seven (7) days — owner to confirm the configured window]

No-storage mode. When saving, you can flag an engagement for no-storage mode. The purge job for that flag deletes the engagement's snapshots, mappings, cash-flow worksheets, questionnaire answers and review notes, and its export files, and keeps the engagement record, the upload metadata, the export records (metadata only) and the mapping template. The purge job is planned, not running, at the draft date: until it is, a snapshot saved with the flag stays until you delete the engagement, and the save screen says so. The flag itself is stored now so that nothing is designed to rely on a purged table.

11. Sub-processors

Hayatiq relies on the following providers. Each receives only what the "What it receives" column describes, under a contract that binds it to process that data only for Hayatiq. Hayatiq gives customers with a Data Processing Agreement at least [thirty (30) days'] notice before adding or replacing a sub-processor.

ProviderRoleLocationWhat it receives
SupabaseDatabase, authentication, file storageFrankfurt, Germany (AWS eu-central-1)Everything Hayatiq stores: accounts, organisations, saved snapshots, upload metadata, billing events, waitlist e-mails, and export files once export ships
VercelHosting of the web application, serverless functions, edge network, product analyticsGlobal edge network; functions pinned to Frankfurt, Germany (fra1), alongside the Supabase projectEvery request to the Service, including anything you send when you save, ask the assistant, generate narrative or export, in transit; analytics events (counts and flags only)
AnthropicThe assistant's language modelUnited StatesFor a mapping suggestion: account codes, names and a category label. For note narrative: the facts object. Nothing is sent until zero data retention is confirmed in writing
ResendTransactional e-mail (sign-in links, service notices)United States [owner to confirm whether Resend's EU region is selected]Your e-mail address and the content of the e-mail
PaddleMerchant of record: checkout, payment, tax, invoices, refundsUnited Kingdom, with global payment processingYour billing details and payment; Paddle is a controller of these under its own notice
CloudflareDNS for the hayatiq.ai domain [owner to confirm whether Cloudflare's proxy is on for financials.hayatiq.ai; if so add "and network edge"]Global network, United StatesConnection metadata (your IP address, the hostname requested); no engagement content

Each provider publishes its own privacy and security documentation: Supabase, Vercel, Anthropic, Resend, Paddle, Cloudflare.

12. International transfers

Saudi Arabia (PDPL). Hayatiq is established in the United Arab Emirates, outside the Kingdom, and stores data in Germany, so data of people in Saudi Arabia that you enter into the Service — your own account details and any individual named in an engagement — is transferred outside the Kingdom. Hayatiq's position is that such transfers take place under the Standard Contractual Clauses issued by the Saudi Data & Artificial Intelligence Authority (SDAIA) in accordance with the Regulation on Personal Data Transfer Outside the Kingdom, supported by a transfer risk assessment, and that the Data Processing Agreement incorporates those clauses for customers who are controllers in the Kingdom. [Lawyer to confirm: execution of the SDAIA SCCs between Hayatiq and each KSA customer (or by incorporation into the DPA), completion of the transfer risk assessment, whether Hayatiq must register on the national register of controllers or appoint a representative in the Kingdom, and the PDPL basis for each processing purpose above. At the draft date the SCCs and the assessment are on the launch checklist and not yet in place]. Financial statements are largely commercial rather than personal data, which narrows what falls under the PDPL; names of directors, shareholders, related parties and employees are the usual personal data in an engagement, and you should enter only what the financial statements need.

European Union and United Kingdom (GDPR). Data is stored in Frankfurt. Where a sub-processor outside the EEA or the UK receives personal data — Vercel, Anthropic, Resend, Cloudflare in the United States; Paddle in the United Kingdom — the transfer relies on the mechanism that provider offers: the European Commission's Standard Contractual Clauses, the UK addendum, or a certification under the EU–US Data Privacy Framework where the provider holds one. [Lawyer to verify the transfer mechanism in force for each of the six providers and record it here, and to confirm whether Hayatiq needs an Article 27 representative in the EU or the UK].

13. Security

Implemented at the draft date:

  • Row-level security on every database table, so that a signed-in user can read and write only rows belonging to organisations they are a member of; an automated suite proves cross-organisation reads and writes are denied on every change, and the public database role holds no table grants.
  • Client data stays on your device until you act (section 2); the assistant's mapping request carries a fixed set of fields and scrubs figure-shaped values before sending.
  • Encryption in transit (HTTPS) between your browser, Hayatiq and every sub-processor; encryption at rest on the database and storage disks as provided by Supabase's infrastructure.
  • No client financial data in logs or analytics (section 8), and Paddle event records limited to the fields acted on.
  • Secrets never in source code; deployment credentials held only in the hosting provider's encrypted configuration, and a tooling guard that blocks any automated change to secret files.

Planned before the first real client data is saved (the launch checklist):

  • Column-level encryption of the two database columns that hold questionnaire answers and engagement snapshots, using the database's vault; until then real client data is not saved.
  • Zero data retention with the assistant's model provider, confirmed in writing; until then the assistant is disabled (section 14).
  • Point-in-time recovery on the database, and rotation of the development project's credentials before any real data reaches it.

Built and in review at the draft date, not yet deployed: sign-in by one-time e-mailed link with no password store, and the save boundary described in section 3.

No system is perfectly secure. If Hayatiq becomes aware of a breach affecting your personal data, we will tell you without undue delay and, where the law requires, notify the competent authority within the period it sets; the Data Processing Agreement states the notice terms for customers.

14. The assistant and zero data retention

The assistant uses a language model hosted by Anthropic (section 11). By design it writes prose only: every number in a note is placed by Hayatiq's engine and checked back against it, and a mapping suggestion becomes a mapping only when you confirm it. The model provider's published commercial terms state that it does not train its models on data sent through its API and that inputs are retained for a limited period by default; a zero-data-retention arrangement removes that retention.

Hayatiq's zero-data-retention arrangement with Anthropic is not yet in place; the assistant is disabled until it is. Until Anthropic confirms zero data retention for Hayatiq's account in writing, no real account name, balance or entity name is sent to the model — the assistant's controls in the Service are shown disabled with that reason, and Hayatiq's own tests run the model only against synthetic fixture data. When the arrangement is in place, this section will state the date and what the provider retains (which should be nothing beyond the request itself).

15. Your rights and how to exercise them

Depending on where you are, you have rights to access the personal data we hold about you, to correct it, to have it deleted, to restrict or object to its processing, to receive a copy in a portable form, to withdraw consent where consent is the basis, and to complain to a supervisory authority — in Saudi Arabia, SDAIA; in the EU or UK, your local data protection authority.

To exercise a right, e-mail privacy@hayatiq.ai from the address on your account, or tell us how to verify that you are the person concerned. We answer within thirty (30) days of a verified request, and tell you if we need longer for a complex one. Most of what we hold you can also see or change yourself in the Service: your organisation, its members, and each engagement, which you can delete at any time.

If your data is in an engagement that one of our customers saved — you are a director or related party named in their financial statements — that customer is the controller. Please write to them; if you write to us instead, we will pass your request on and help them answer it, as the Data Processing Agreement requires.

16. Children

The Service is for business use by adults. We do not knowingly collect data from anyone under [eighteen (18) — align with the Terms]; if you believe we have, contact us and we will delete it.

17. Changes to this policy

We will update this policy when the product or the law changes — in particular when the items marked "planned" or "in development" above go live. Material changes are notified by e-mail or in the Service; the current version, with its date, is always at financials.hayatiq.ai/en/privacy.

18. Contact

[registered name of the FZE that operates hayatiq.ai], [registered address, Ajman, United Arab Emirates] · privacy@hayatiq.ai (data and privacy) · hello@hayatiq.ai (general). This draft is dated 14 September 2026; effective date: [effective date].