Privacy Policy
On this page
1. Who we are
Mizada is an AI-first financial reporting platform for individuals and small entities, operated by Mizada FinTech FZ-LLC, a free-zone company registered in Dubai, United Arab Emirates ("Mizada", "we", "us"). For the purposes of the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, the "PDPL") and applicable data-protection regulations, Mizada is the controller of the personal data described here.
Mizada is a reporting, analysis and document-storage platform. It is not a bank and does not hold or move customer funds. You can reach us about privacy at contact@mizada.ae.
2. Scope of this policy
This policy applies to the Mizada mobile and web applications, this website, and related communications (together, the "Service"). It explains what personal data we collect, why, who we share it with, how long we keep it, and the rights you have. It does not apply to third-party services we link to, which have their own policies.
3. Information we collect
3.1 Information you give us
- Account details — your name, email address, and (if you choose) phone number.
- Business details (SMEs) — entity name, trade-licence information, Tax Registration Number (TRN) and similar identifiers you enter to prepare books and filings.
- Documents you upload — receipts, invoices, bank statements, contracts, leases and similar records, including any personal data they contain.
- Support and communications — messages you send us and your preferences (for example, opting in to launch updates).
3.2 Information created when you use the Service
- Extracted and derived data — figures, dates, merchants and categories our software reads from your documents, and the reports, statements and filings prepared from them.
3.3 Information collected automatically
- Device and technical data — device type, operating system, app version, and general location inferred from IP address.
- Usage and diagnostics — actions taken in the app and error/crash logs used to keep the Service working and secure.
- Cookies and local storage on the website — see our Cookie Policy.
We do not intentionally collect special-category data (such as health or biometric data). Face ID / fingerprint unlock is handled by your device; Mizada does not receive your biometrics.
4. How and why we use your information
We use your personal data only for the purposes below, each with a lawful basis under the PDPL:
| Purpose | Lawful basis |
|---|---|
| To provide the Service: read and organise your records, generate reports, and prepare filings you ask for. | Performance of our contract with you. |
| To secure your account and prevent misuse and fraud. | Our legitimate interests; legal obligation. |
| To communicate with you about the Service, including launch updates you opted in to. | Your consent and/or performance of contract. |
| To comply with legal, tax and regulatory obligations. | Legal obligation. |
| To maintain and improve the Service using aggregated or de-identified data. | Our legitimate interests. |
We will not use your data for a new, incompatible purpose without telling you and, where required, obtaining your consent. We do not sell your personal data, and we do not use it for third-party advertising.
5. AI and automated processing
Mizada uses automated and AI-assisted processing to read documents, categorise transactions, and draft statements and filings. These outputs are tools to help you: you review and confirm them, and nothing is submitted to any authority without your explicit confirmation. We do not make decisions that produce legal or similarly significant effects about you on a solely automated basis. You can correct categorisations and figures at any time.
6. When we share information
We share personal data only as follows:
- Service providers (processors) — vetted providers that host and run the Service (for example, cloud infrastructure) under contracts that require them to protect your data and use it only on our instructions.
- Professional advisers — auditors, lawyers and insurers, where reasonably necessary and under confidentiality.
- Authorities — where we are legally required to disclose, or to establish, exercise or defend legal claims. Filings you prepare are submitted to the relevant authority only when you confirm them.
- Business transfers — if Mizada is involved in a merger, acquisition or asset sale, your data may transfer subject to this policy.
We never sell your data, and we never share it to move money.
7. International transfers
We aim to host and process personal data in or for the United Arab Emirates. Where data is transferred to or accessed from another country (for example, a service provider's infrastructure), we put in place safeguards required by the PDPL, such as transfers to jurisdictions with an adequate level of protection or appropriate contractual protections.
8. How long we keep it
We keep your personal data for as long as your account is active and as needed to provide the Service. We keep certain records longer where the law requires it (for example, accounting and tax records, which UAE law generally requires to be retained for several years). When data is no longer needed, we delete or irreversibly anonymise it. You can ask us to delete your data at any time, subject to those legal retention requirements.
9. How we protect it
- Encryption of documents and data in transit and at rest using AES-256.
- App access locked to your device with your device's own biometrics or passcode.
- Access controls on the principle of least privilege, and logging of access to records.
- An audit trail that links every figure to its source document.
No system is perfectly secure, but we work to protect your data and will notify you and the relevant authority of a personal-data breach where the law requires.
10. Your rights
Subject to the PDPL, you have the right to:
- access the personal data we hold about you and ask how it is processed;
- have inaccurate data corrected and incomplete data completed;
- have your data deleted ("right to be forgotten"), subject to legal retention;
- restrict or object to certain processing;
- receive your data in a portable, machine-readable format and have it transferred;
- withdraw consent at any time, without affecting prior processing; and
- lodge a complaint with the UAE Data Office or competent authority.
To exercise any right, email contact@mizada.ae. We will respond within the period required by law and may need to verify your identity first.
11. Children
The Service is intended for adults and is not directed to children under 18. We do not knowingly collect data from children. If you believe a child has provided us personal data, contact us and we will delete it.
12. Changes to this policy and how to contact us
We may update this policy as the Service and the law evolve. We will post the updated version here and, for material changes, give reasonable notice. Questions, requests and complaints can be sent to contact@mizada.ae, Mizada FinTech FZ-LLC, Dubai, UAE.