Skip to main content
Document status

Version v1.0, effective 2026-08-31. The official language of the Terms is English; any translation is provided for convenience only.

KOMASHI PRIVACY POLICY

Module D(1) — Privacy Policy

Version: v1.0 · Effective date: 2026-08-31

This Privacy Policy explains how BMSHI TECHNOLOGY SERVICES - FZCO ("Komashi", "we", "us") handles personal data in connection with the Komashi Platform. It is drafted to comply with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("PDPL") and, because we serve users globally including in the EU/EEA, the EU General Data Protection Regulation ("GDPR").


1. Who We Are; Contact

In short: Komashi is a Dubai company. Here's who we are and how to reach us. This summary is for convenience only and is not legally binding.

1.1. Controller / establishment: BMSHI TECHNOLOGY SERVICES - FZCO, registered in the IFZA free zone (Dubai Silicon Oasis) and licensed by the Dubai Integrated Economic Zones Authority, license number 76747, Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, UAE. Email: info@komashi.com.

1.2. EU representative (GDPR Art. 27): Komashi has not yet designated a representative in the Union under Article 27 GDPR. Komashi will designate one before it offers the Platform to, or monitors the behaviour of, data subjects in the European Union, and will publish the representative's name, address and contact details in this Section at that time. Until then, please address all GDPR matters directly to Komashi at info@komashi.com, and see Section 7 for how to exercise your rights and Section 7.4 for your right to complain to a supervisory authority.

1.2a. UK representative (UK GDPR Art. 27): Komashi has not designated a representative in the United Kingdom, because it does not currently offer the Platform to, or monitor the behaviour of, individuals in the United Kingdom. If that changes, Komashi will designate a UK representative and publish that representative's name and address here before doing so. A representative designated in the Union under Article 27 of the EU GDPR does not serve as a UK representative; the two are separate appointments. Until then, you may contact Komashi directly on all matters relating to the UK GDPR at info@komashi.com.

1.3. Privacy contact: info@komashi.com. Komashi is not required to appoint a Data Protection Officer under Article 37 GDPR or under the PDPL, and has not appointed one; all privacy enquiries, data subject requests and complaints should be sent to that address, which reaches the people responsible for them.

2. Our Two Roles: Controller and Processor

In short: For your data as a Komashi user (Provider, Partner, or your own account data), Komashi is the controller and this Policy applies in full. For data that Providers hold about their customers on the Platform, the Provider is the controller and Komashi only processes it on the Provider's instructions — check that Provider's own privacy policy. Non-binding summary.

2.1. Komashi as controller. We act as controller for personal data of: (a) Providers and their staff; (b) Partners; (c) visitors to our own websites; and (d) End Users, but only for the narrow set of data described in Section 2.1a.

2.1a. What we control in relation to End Users, and nothing beyond it. A Provider's End User data belongs to the Provider. There is no separate Komashi End User account, and Komashi does not build its own customer relationship with a Provider's End Users. We are controller for End User data only where we decide the purpose ourselves and no Provider instructs us to do so, which is limited to:

    (a) security, abuse prevention and platform integrity — authentication and access events, IP address, device and browser information, and security log entries, used to keep the Platform available and to detect and stop attacks, fraud and abuse;

    (b) the technical operation of the Platform itself — error and infrastructure logs generated by our systems; and

    (c) compliance with our own legal obligations — including responding to authorities, and the records we must keep under Section 9.2a.

    Everything else about an End User — identity, contact details, bookings, subscriptions, invoices, QR codes, messages, and the customer record as a whole — is processed for the Provider, as the Provider's processor (Section 2.2). For that data, the Provider's privacy policy applies and requests should go to the Provider (Section 7.3).

2.1b. Who is controller is a question of fact. The allocation in Sections 2.1 to 2.2 describes who actually decides the purposes and means of each processing operation. It is not a nomination, and neither Komashi nor a Provider can change it by agreement alone: if either party in practice determines the purpose of a processing operation, it is controller for it whatever the paperwork says. Where a new feature changes who decides, this Policy is updated before the feature goes live.

2.2. Komashi as processor. For personal data that a Provider collects and manages about its End Users through the Platform (bookings, invoices, customer records), the Provider is the controller and Komashi is the Provider's processor. We process that data only on the Provider's documented instructions under the Data Processing Agreement (Module D(2)). For information about how a Provider uses your data, please read that Provider's privacy policy and contact the Provider.

2.3. Payment data — no involvement in the money flow. Komashi is not part of the money flow. Payments for Provider Services go directly from End Users, via an independent licensed Payment Provider, to Providers. Komashi is not a merchant of record, not a payment service provider, and never holds, receives, controls, or transmits End User funds. Accordingly, we do not collect, hold, or process card numbers or payment credentials; payment data is processed by the Payment Provider as described in its own privacy policy. We receive limited payment-related metadata after the fact, and its scope is fixed: transaction reference, amount, currency, timestamp, success or failure, refund status, and the type of payment method used (for example "card" or "transfer"). That is the whole of it. We do not receive, and the Platform is not built to accept, card numbers, expiry dates, CVC or other card security codes, bank account credentials, cardholder authentication data, or any payment token capable of initiating a payment. We use this metadata for one purpose only: to determine whether an invoice was paid, which drives Commission accrual under Section 4.1a of the Provider Terms.

3. What Data We Collect

In short: Account details, the content you or your Provider put on the Platform, technical and usage data, and support communications. We don't collect card numbers. Non-binding summary.

3.1. Depending on your role, we collect: (a) identification and contact data — name, email address, phone number, business details; (b) account and authentication data — login events, one-time login codes/links metadata, device identifiers, and, where you choose to sign in with a third-party identity provider, the account identifier and the name and email address that provider returns; (c) platform content — data you or your Provider enter (bookings, invoices, service details), including QR-code usage events; (d) technical and usage data — IP address, browser and device information, logs, approximate location derived from IP; (e) communications — support requests, complaints; and (f) cookie data (Section 8).

3.2. Special categories of personal data. The Platform has no field designed to hold special-category data (Article 9 GDPR — health, religion, biometrics, and the rest), and we do not intentionally collect it. Providers must not enter it, or invite End Users to enter it, into free-text fields such as booking notes, service descriptions or messages, and must not otherwise instruct us to process it through the Platform without a separate written agreement under Section 2.1(d) of the Data Processing Agreement.

    This matters most where it is easiest to overlook. A service name, a booking note, or a message can amount to health data without anyone intending it — a Provider in physiotherapy, wellness, or a similar field can generate special-category data simply by describing what was booked. Where a Provider's business necessarily involves such data, it must raise this with us under Section 2.1(d) of the DPA before it starts processing, so that the additional safeguards are in place first. The Provider is the controller of what it and its End Users type into those fields, and is responsible for having a valid Article 9 condition for it.

In short: We use your data to run the Platform, keep it secure, bill Providers, comply with the law, and improve the service — each on a recognized legal basis. Non-binding summary.

4.1. Where Komashi acts as controller, we process personal data for the following purposes and legal bases (GDPR Art. 6; PDPL equivalents):

PurposeLegal basis
Creating and administering accounts; providing the PlatformPerformance of a contract (Art. 6(1)(b))
Passwordless authentication; fraud prevention; securityPerformance of a contract; legitimate interests (Art. 6(1)(f)) in securing the Platform
Billing Providers; Partner commission administrationPerformance of a contract; legal obligation (tax/accounting) (Art. 6(1)(c))
Compliance with UAE and other applicable law, court ordersLegal obligation (Art. 6(1)(c))
Service improvement, aggregated analyticsLegitimate interests (Art. 6(1)(f)); consent where required for cookies
Marketing communicationsConsent (Art. 6(1)(a)) or soft opt-in where permitted; opt-out always available
Establishing, exercising or defending legal claimsLegitimate interests (Art. 6(1)(f))

4.2. Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights; you may object at any time (Section 7).

4.3. Where we rely on consent, you may withdraw it at any time without affecting prior processing.

5. Who We Share Data With

In short: The application services we use to run the Platform — invoicing, AI features, sign-in and analytics — plus the Provider you deal with, the payment companies (which process your payment data on their own account, not on ours), and authorities where the law requires it. We run the Platform on our own equipment, so there is no hosting company in the picture. We don't sell personal data. Non-binding summary.

5.1. We share personal data with: (a) sub-processors listed at https://komashi.com/legal/subprocessors. We run the Platform's application, database, storage and log indexing on equipment we own, at our own premises in the EU/EEA, and rent no compute, hosting, database, or log-analytics service from anyone. Outbound transactional email is sent from our own mail servers. As a result there is no infrastructure sub-processor at all — no cloud provider, no data-centre operator, and no email delivery provider — and no third party holds any account over our database, logs, or mail. The sub-processors we do engage are application-level services only — invoicing, AI features, sign-in and analytics, and payment-side verification — and each is named at that address, together with the categories of data it actually receives. Annex 3 of the DPA also records which third parties are not sub-processors and why; (b) Providers — data relating to their own End Users and their account; (c) Payment Providers — limited data necessary to initiate their own processing. A Payment Provider is an independent controller, not our sub-processor: it determines its own purposes and means for that processing under its own licence and regulatory obligations, and it is therefore not listed at the sub-processor URL above and is not subject to the sub-processor objection right in Section 4.2 of the Data Processing Agreement; (d) professional advisers, auditors, insurers; (e) authorities and courts where legally required; and (f) a successor entity in a merger or acquisition, with notice.

5.2. We do not sell personal data and do not share it with third parties for their own advertising.

6. International Transfers

In short: Your data is held in the EU/EEA, and none of it goes to the UAE or can be reached from there. Some of it does reach service providers in the United States — for AI features, third-party sign-in, our own analytics, and payment and verification — and those transfers are made under the EU Standard Contractual Clauses. Non-binding summary.

6.1. Where your data is held. The Platform's application, database, storage and backups are located in the EU/EEA. Although Komashi is registered as a company in the UAE, no personal data is transferred to, stored in, or accessible from the United Arab Emirates (DPA Module D(2), Section 5.2). That is true both of data we process as a processor for Providers and of data we process as controller about Providers, Partners, and website visitors.

6.2. Data that does leave the EU/EEA, and why. Some of the service providers we engage are established in the United States. Personal data therefore reaches those providers, limited in each case to what that function requires:

    (a) AI features — the text submitted to an AI feature, which includes support questions and the content of support tickets;

    (b) sign-in with a third-party identity provider — where you choose it, your name, email address and account identifier with that provider;

    (c) web analytics we operate on our own account — IP address, device and browser data, and usage and event data; and

    (d) payment and Provider verification — the identification, billing and verification data described in Section 6.2a.

    The recipient of each of these, and the exact categories it receives, are named in the sub-processor list at https://komashi.com/legal/subprocessors. Nothing beyond the categories stated there leaves the EU/EEA — that limit is itself one of the safeguards described in Section 6.2b.

6.2a. Payment and payout data. Our own fee collection from Providers, and the payment of Partner Commission, are carried out through payment service providers, some of which are not established in the EU/EEA. The data necessary for those operations — the identification and billing data of the Provider or Partner concerned, and the associated payment references — therefore reaches those providers. For the payment transaction itself they act as independent controllers under their own regulatory obligations (Section 5.1(c)), and that processing is governed by their own privacy terms. Where such a provider instead acts on our instructions — for example, verification checks we ask it to run during Provider onboarding — it acts as our sub-processor and is listed as such.

6.2b. Safeguards for those transfers. Each transfer described in Sections 6.2 and 6.2a is made under the EU Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), on the terms set out in DPA Section 5.2a. We rely on the Clauses as the primary mechanism even where a recipient is certified under the EU–US Data Privacy Framework, so that the safeguard does not depend on an adequacy decision remaining in force.

    We have carried out and documented a transfer impact assessment for these transfers, we review it at least annually and whenever the sub-processor list changes, and we apply the supplementary measures it records — including encryption in transit, strict limitation of the categories that leave the EU/EEA, a contractual prohibition on the recipient using the data for its own purposes (including model training), and a commitment to notify us of any binding request from a public authority so far as the recipient is legally permitted to do so.

    A copy of the relevant safeguards is available on request at info@komashi.com.

6.2c. UK data. For personal data subject to the UK GDPR, the same Clauses apply as amended by the UK International Data Transfer Addendum.

6.3. Transfers of PDPL-covered data outside the UAE are made in accordance with Articles 22–23 PDPL (adequacy, appropriate safeguards, or another permitted basis).

7. Your Rights

In short: You can ask for access, correction, deletion, restriction, portability, and object to some processing. If we're only the processor for your data, we'll point you to your Provider. You can also complain to a data protection authority. Non-binding summary.

7.1. Subject to applicable law, you have the right to: access your personal data; rectify inaccurate data; erase data; restrict processing; data portability; object to processing based on legitimate interests or for direct marketing; withdraw consent; and not to be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you.

7.1a. One decision on the Platform is fully automated: blocking a Provider Account for non-payment. We tell you about it here because Article 22 GDPR requires it.

    (a) What the decision is. If an invoice we have issued to a Provider for our own platform fees is still unpaid after the due date, the Platform blocks that Provider's Account automatically, without a person reviewing the case first.

    (b) The logic involved. It is a simple payment check. It does not evaluate you, your conduct, or your characteristics, and the whole of it is this: the invoice falls due ten days after its date; where the Fee is charged automatically, the charge is retried over seven days, and we email you on each failed attempt so that you can check your payment method; and if the amount is still outstanding ten days after the due date, the Account is blocked (Sections 5.1–5.2 of the Provider Terms).

        To be precise about what you do and do not receive: the notices are about the failed payment attempts, not about the block. There is no separate warning email immediately before the Account is blocked — the block follows automatically once the ten days after the due date have run. The failed-charge emails, together with the invoice and this Policy, are the notice you get.

    (c) Significance and consequences. While the Account is blocked, the Provider presence is switched off and Provider Services are treated as expired towards End Users (Provider Terms Section 5.4). The block is lifted as soon as the outstanding amount is paid, and no reactivation fee is charged (Provider Terms Section 5.3).

    (d) Legal basis. The decision is necessary for the performance of the contract between you and Komashi (Article 22(2)(a) GDPR).

    (e) Your safeguards. You may obtain human intervention on our part, express your point of view, and contest the decision by writing to info@komashi.com; a person will review it, and we will lift the block where the review shows it was not justified. Where you are a business user within the scope of Regulation (EU) 2019/1150, we also provide a statement of reasons under Section 5.2a of the Provider Terms, and the review route in Section 4.3 of the Acceptable Use Policy is available to you.

7.1b. We take no other solely automated decisions with legal or similarly significant effects. Fee calculations (rate band, free allowance, loyalty rate, Partner Commission) are the application of published formulas and do not evaluate personal aspects. Enforcement measures under the Acceptable Use Policy are taken by a human reviewer on the basis of a report, a legal obligation, or an authority's order; no automated content moderation, filtering, classification, or risk scoring is applied (Acceptable Use Policy Section 1.3). You may contest any account-level measure and request human reconsideration at info@komashi.com.

7.2. To exercise your rights, contact info@komashi.com (or, once designated, our EU representative — Section 1.2). We respond within the time limits of the GDPR (generally one month) and the PDPL. We may need to verify your identity.

7.3. If Komashi processes your data only as a Provider's processor (Section 2.2), we will direct you to the relevant Provider (Komashi cannot itself forward the request), as the controller responsible for responding.

7.4. You may lodge a complaint with a supervisory authority: in the UAE, the UAE Data Office; in the EU/EEA, the supervisory authority of your residence or workplace. We would appreciate the chance to resolve your concern first via info@komashi.com.

8. Cookies and Similar Technologies

In short: We use necessary cookies to make the Platform work, and optional ones (like analytics) only with your consent, which you give in the cookie banner and can change or withdraw at any time on our cookie settings page. Non-binding summary.

8.1. We use strictly necessary cookies (session, security, load balancing) without consent, as permitted by law.

8.2. Optional cookies (analytics and preferences — we set no advertising or cross-site tracking cookies) are set only with your prior consent, collected via our cookie banner, where required by applicable law (including the ePrivacy rules of EU member states). You can withdraw or adjust consent at any time via https://komashi.com/legal/cookie-settings.

8.3. Details of individual cookies, their purposes and durations are listed in our Cookie Notice at https://komashi.com/legal/cookies.

9. Retention

In short: We keep data only as long as needed, and this section states the actual periods — it is the single place where retention is defined for the whole Komashi terms package. Non-binding summary.

9.1. We retain personal data only as long as necessary for the purposes above, and thereafter as required for legal obligations or the establishment or defense of legal claims.

9.2. Retention schedule. This Section 9.2 is the single governing source of retention and deletion periods for the entire Terms package; where any Role Term or the DPA refers to retention or deletion periods, it refers to this Section. Deletion at the end of a period is scheduled and automatic, not on request; the only data that outlives its period is data caught by a statutory retention duty in Section 9.2a or by a legal hold under Section 9.2c.

    (a) Account lifecycle.

Data / stagePeriod
Soft-delete (deactivated, non-public) after Account termination30 days
Export window for the former Account holder30 days from termination
Permanent deletion or irreversible anonymization of Account and User Content90 days after termination

    (b) Operational records, while the Account is live.

Data / stagePeriod
Booking, order and customer records24 months after the booking or order to which they relate, then deleted or irreversibly anonymized
Activity log (in-application audit trail)12 months
Technical and security logs (server, application, access)12 months
Infrastructure and file-level logs14 days
Record of outgoing transactional email (delivery metadata)90 days
Support communications24 months after the case is closed
Cookie and consent records12 months from collection of the consent, or until withdrawal if earlier

    (c) Backups. Backups are retained on a fixed rotation and are not searched or edited to remove individual records; data deleted under paragraphs (a), (b) or Section 9.2a disappears from backups as the rotation expires, and is not restored into production.

Backup tierPeriod
Daily backups2 weeks
Weekly backups2 months
Monthly backups6 months

9.2a. Records kept because the law requires it. The following survive Account termination and the periods in Section 9.2, because a statutory retention duty applies to them. They are held in a restricted state: available only for the purpose that justifies keeping them, not used to operate the Platform or to contact anyone, and deleted at the end of the period.

    (a) Komashi's own accounting records — the invoices Komashi issues to Providers for its Fees, and the supporting records: 5 years from the end of the tax period to which they relate (UAE Federal Decree-Law No. 8 of 2017 on Value Added Tax and the UAE Commercial Transactions Law).

    (b) Invoices a Provider issues through the Platform are the Provider's own accounting records, not Komashi's, and Komashi holds them as processor (DPA Section 3.8). They are retained for the statutory record-keeping period that applies to that Provider — 8 years from the end of the calendar year of issue where the Provider is established in the European Union, and 5 years otherwise — after which they are deleted. A Provider may instruct Komashi in writing to apply a longer period required by its own national law.

    (c) Platform-operator tax reporting records. Where Komashi is a reporting platform operator under Council Directive (EU) 2021/514 (DAC7), the records of the due-diligence steps and the information relied on are retained for 5 years following the end of the reportable period to which they relate. That Directive sets a floor of 5 years and a ceiling of 10; Komashi applies the floor.

    (d) Records kept to establish, exercise or defend legal claims — where a claim is pending or reasonably anticipated: until the claim is finally resolved and the applicable limitation period has expired.

9.2b. What "deleted" means. Deletion means the record is removed from the production systems, or is irreversibly anonymized so that it can no longer be attributed to an identified or identifiable person, without a key or other means of re-identification being retained. Backups follow Section 9.2(c).

9.2c. Legal hold. Komashi may suspend a scheduled deletion for specific records where required by law, by an order of a competent authority, or to preserve evidence for a pending or reasonably anticipated claim. A hold is limited to the records concerned and to the period for which the reason subsists, and deletion resumes as soon as it ends.

9.2d. Erasure requests. A request to erase personal data is honoured under Section 7 in respect of everything in Section 9.2. It does not override Section 9.2a, because that data is retained to comply with a legal obligation or to establish, exercise or defend legal claims (Articles 17(3)(b) and (e) GDPR). Where an erasure request is refused on that basis, we tell you which category applies and when the record will be deleted.

9.3. Terminated accounts follow the soft-delete → permanent-deletion sequence in Section 9.2(a), subject to Section 9.2a. For Provider-controlled End User data, deletion or return on termination is governed by the DPA (Module D(2) Section 3.8), which applies the periods in this Section 9.

10. Security

In short: We protect data with technical and organizational measures appropriate to the risk — encryption in transit, access controls, logging, and more. Non-binding summary.

10.1. We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or loss, including encryption in transit, access controls, least-privilege administration, logging and monitoring, and regular review. A summary of measures is in Annex 2 of the DPA.

10.2. In the event of a personal data breach, we will notify the competent authority and affected individuals where and as required by the PDPL and GDPR, and affected Provider controllers under the DPA.

11. Children

In short: Komashi is for adults — you must be 18 to have an account. We do not knowingly hold children's data. If you think a child gave us data, tell us. Non-binding summary.

11.1. The Platform is not directed at children, and accounts require a minimum age of 18. We do not knowingly process children's personal data as controller; if you believe a child has provided us data, contact info@komashi.com.

12. Changes to This Policy

In short: We may update this Policy. If a change matters to you, you get advance notice and a grace period, and the current version is always at the address below. Non-binding summary.

12.1. We may update this Policy from time to time. Material changes will be notified in accordance with Section 4 of the General Terms (advance notice with a grace period). The current version is always available at https://komashi.com/legal/privacy.