Legal

Privacy Policy

Opeare FZE · Trading as OpeAre · opeare.com

Effective date: 2 July 2026 · Last updated: 2 July 2026

How OpeAre handles your Personal Data under the UAE PDPL. Read alongside our Terms of Service and DPA.

Opeare FZE (OpeAre, we, us, or our) respects your privacy. This Privacy Policy explains how we collect, use, share, retain, and protect Personal Data when you use the OpeAre legal operations platform and related services at opeare.com (the Service).

This Privacy Policy is issued in accordance with the United Arab Emirates Personal Data Protection Law, Federal Decree-Law No. 45 of 2021 (the PDPL) and the Executive Regulations issued under Cabinet Decision No. 111 of 2023. The PDPL is enforced by the United Arab Emirates Data Office, established under Federal Decree-Law No. 44 of 2021.

For the purposes of the PDPL, OpeAre is the Controller of Personal Data Processed in connection with your use of the Service. In respect of Personal Data of third parties that you input into the Service or upload as Customer Content, OpeAre acts as a Processor on your behalf, subject to our Customer Data Processing Agreement available at opeare.com/legal/dpa. If you do not agree with this Privacy Policy, please do not use the Service.


1. Who we are

1.1 The entity responsible for the Service is:

Legal name: Opeare FZE

Trade Licence No.: 4430085.01

Jurisdiction: SPC Free Zone, Sharjah, United Arab Emirates

Registered office: SPC Free Zone, Sharjah, United Arab Emirates

Contact email: contact@opeare.com

1.2 For any questions about this Privacy Policy or about how we Process Personal Data, contact us at contact@opeare.com.


2. Personal Data we collect

2.1 We collect Personal Data that you provide directly to us, that is generated by your use of the Service, and that we receive from third parties such as payment processors.

2.2 The categories of Personal Data we Process include:

(a) Account and contact data: name, email address, password (hashed), company name, role or job title, country, and (for team accounts) User seat information.

(b) Payment data: billing name, address, VAT registration number (where applicable), and payment method tokens. Full payment card details are processed directly by our payment processor (Stripe) and are not stored by OpeAre.

(c) Usage data: information about how you use the Service, including modules accessed, templates viewed and downloaded, features used, AI Feature interactions, dates and times of access, and pages visited.

(d) Uploaded and generated content: documents you upload for review or processing, populated templates, AI-generated outputs derived from your inputs, and other Customer Content. This may include Personal Data of third parties (such as employees, counterparties, or Data Subjects referenced in your documents), in respect of which you are the Controller.

(e) Device and technical data: IP address, browser type and version, operating system, device identifiers, and similar technical information.

(f) Communications data: records of communications between you and OpeAre, including support requests and feedback.

2.3 Where you use the Service to draft, review, or process documents involving third parties, you may input Personal Data about those third parties. That Personal Data is stored only as necessary to provide the Service to you. You are the Controller of such third-party Personal Data, and OpeAre acts as a Processor on your behalf. The terms of that Processing are set out in our Customer Data Processing Agreement.


3. How we use Personal Data

3.1 We Process Personal Data for the following purposes and on the following lawful bases under Article 4 of the PDPL:

(a) Providing the Service (basis: performance of a contract with you): creating and managing your Account, providing access to features and modules, processing payments, delivering AI Features, and operating the Service.

(b) Customer support (basis: performance of a contract): responding to your queries, providing technical assistance, and resolving issues.

(c) Service improvement (basis: legitimate interests of OpeAre in operating and improving the Service): analysing usage patterns, debugging, security monitoring, and enhancing Content, features, and AI Features. Aggregated and anonymised data may be used for this purpose.

(d) Compliance with legal obligations (basis: compliance with a legal obligation): meeting requirements under UAE tax law (including retention obligations under Federal Decree-Law No. 8 of 2017 on Value Added Tax and Federal Decree-Law No. 47 of 2022 on Corporate Tax), and responses to lawful requests from UAE authorities.

(e) Protection of rights and security (basis: legitimate interests): detecting fraud, preventing misuse of the Service, enforcing our Terms of Service, and protecting our legal rights.

3.2 Where we rely on your consent to Process Personal Data, you may withdraw that consent at any time by contacting us at contact@opeare.com. Withdrawal of consent does not affect the lawfulness of Processing carried out before withdrawal.

3.3 OpeAre does not use identifiable Personal Data or Customer Content to train third-party AI models without your instruction. Aggregated and anonymised data derived from use of the Service may be used to improve OpeAre’s own Service and AI Features.


4. Sharing Personal Data

4.1 We share Personal Data only as necessary for the purposes set out in this Privacy Policy, and only with the following categories of recipients:

(a) Service providers (Subprocessors) that support OpeAre’s operations. The Subprocessors currently engaged are:

- Stripe - Payment processing and Subscription billing. Primary processing location: Ireland (European Union).

- Vercel - Hosting of the Service and platform infrastructure. Primary processing location: United Kingdom (London, eu-west-2). Edge locations global.

- Supabase - Database hosting and authentication. Primary processing location: United Kingdom (London, eu-west-2).

- Resend - Transactional email delivery (Account confirmations, password resets, Service notifications). Primary processing location: United States.

- AI service providers - Provision of AI Features including document review, summarisation, and drafting assistance. Primary processing location: United States and/or European Union.

Each Subprocessor is bound by contractual obligations to process Personal Data only on OpeAre’s documented instructions and to apply appropriate technical and organisational security measures. An up-to-date list of Subprocessors, including current AI service providers, is available on request to contact@opeare.com.

(b) Professional advisers: our lawyers, accountants, and auditors, where necessary for OpeAre’s legitimate business purposes.

(c) Authorities: UAE federal and local government authorities, regulators, courts, and law enforcement, where required by Applicable Law or in response to a lawful request.

(d) Corporate transactions: in connection with a sale, merger, financing, or other corporate transaction, where Personal Data may be transferred subject to appropriate safeguards.

4.2 We do not sell Personal Data. We do not share Personal Data with third parties for their own marketing purposes.


5. Cross-border data transfers

5.1 OpeAre is based in the United Arab Emirates. Some of our Subprocessors store or process Personal Data outside the UAE, including in the United Kingdom, the European Union, and the United States, as identified in Section 4.

5.2 Where Personal Data is transferred outside the UAE, OpeAre relies on the following safeguards under Article 22 of the PDPL:

(a) Transfers to jurisdictions recognised as providing an adequate level of data protection under the PDPL or by the UAE Data Office; or

(b) Transfers subject to appropriate contractual safeguards, including data protection clauses imposing on the recipient obligations equivalent to those required under the PDPL.

5.3 For further information about the cross-border transfer mechanism applied to a specific Subprocessor, contact us at contact@opeare.com.


6. Data retention

6.1 We retain Personal Data only as long as necessary for the purposes for which it was collected, and as required by Applicable Law. Specific retention periods are:

(a) Account data: retained for the duration of your Account and for thirty (30) days after Account closure to allow for recovery and dispute resolution. After that period, Account data is deleted, save for records subject to statutory retention requirements below.

(b) Payment, invoicing, and tax records: retained for a minimum of five (5) years from the end of the relevant tax year, as required by UAE VAT Law (Federal Decree-Law No. 8 of 2017), and for seven (7) years from the end of the relevant tax period as required by UAE Corporate Tax Law (Federal Decree-Law No. 47 of 2022). These retention periods apply notwithstanding Account closure.

(c) Corporate and commercial records: retained for the periods required under UAE Commercial Companies Law (Federal Decree-Law No. 32 of 2021) and other applicable UAE laws governing commercial record-keeping.

(d) Uploaded documents and Customer Content: retained during your Account and for thirty (30) days after Account closure, unless you request earlier deletion or the content is subject to a statutory retention requirement.

(e) Usage and technical data: retained for twelve (12) months for analytics and security purposes, then deleted or anonymised.

(f) Communications and support data: retained for three (3) years from the date of communication, for record-keeping and dispute resolution.

6.2 Where retention is required by Applicable Law, we retain the relevant records for the period required by law even where you have requested deletion. Where we no longer have a lawful basis to Process your Personal Data, we will delete, anonymise, or restrict access to it.


7. Security

7.1 We implement appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Measures include:

(a) encryption of Personal Data in transit (TLS) and at rest;

(b) role-based access controls and least-privilege principles for OpeAre personnel;

(c) multi-factor authentication for administrative access;

(d) monitoring of systems for security events and unauthorised access;

(e) regular review of security controls and contractual obligations on Subprocessors;

(f) documented incident response procedures.

7.2 No security measure can be guaranteed to be impenetrable. In the event of a Personal Data Breach, OpeAre will notify the UAE Data Office and, where required, affected Data Subjects in accordance with the PDPL.


8. Your rights under the PDPL

8.1 The PDPL grants you the following rights in relation to your Personal Data:

(a) Right to access: you may request confirmation of whether we Process Personal Data about you, and request a copy.

(b) Right to correction: you may request correction of inaccurate or incomplete Personal Data.

(c) Right to deletion: you may request deletion of your Personal Data in defined circumstances. We may decline deletion where retention is required by Applicable Law.

(d) Right to restriction: you may request restriction of Processing in defined circumstances.

(e) Right to portability: you may request a copy of your Personal Data in a structured, commonly used, machine-readable format.

(f) Right to object: you may object to Processing based on legitimate interests.

(g) Right to withdraw consent: where Processing is based on consent, you may withdraw that consent at any time.

(h) Right to complain: you may lodge a complaint with the UAE Data Office if you consider that your rights under the PDPL have been infringed.

8.2 To exercise any of these rights, contact us at contact@opeare.com. We will respond within the timeframes required by the PDPL. We may need to verify your identity before processing your request to prevent unauthorised disclosure.


9. Cookies and similar technologies

9.1 The Service uses cookies and similar technologies (such as local storage) to operate the Service and remember your preferences. We do not use marketing or advertising cookies.

9.2 The categories of cookies used are:

(a) Strictly necessary cookies: required for the Service to function, including session and authentication cookies, security and fraud prevention cookies, and load balancing. These cookies cannot be disabled without breaking the Service.

(b) Functional cookies: remember your preferences (such as language or interface settings) and improve your experience.

(c) Analytics: we use privacy-respecting analytics tools that aggregate usage data without identifying individual users. These tools do not track you across websites and do not build advertising profiles.

9.3 We will update this Privacy Policy and provide an appropriate consent mechanism if we introduce additional categories of cookies in the future.

9.4 You can control cookies through your browser settings. Disabling cookies, including strictly necessary cookies, may affect the functionality of the Service.


10. Children

10.1 The Service is intended for use by adults and businesses. It is not directed at, and we do not knowingly collect Personal Data from, children under the age of 18.

10.2 If you believe a child has provided Personal Data to OpeAre, please contact us at contact@opeare.com and we will take appropriate steps to delete it.


11. Changes to this Privacy Policy

11.1 OpeAre may update this Privacy Policy from time to time. The "Last Updated" date at the top of this document reflects the date of the most recent update. Material changes will be notified to you by email or through the Service before they take effect.


12. Contact and complaints

12.1 For any questions, requests, or complaints about this Privacy Policy or our Processing of your Personal Data, contact us at contact@opeare.com.

12.2 If you are not satisfied with our response, you have the right to lodge a complaint with the UAE Data Office, the federal data protection regulator established under Federal Decree-Law No. 44 of 2021.


Questions or requests about your data? Email contact@opeare.com and we will respond within the timeframes required by the PDPL.