Privacy policy
Last updated September 1, 2026
This policy reflects how Kodowo’s systems are actually built and operated. It is written with reference to the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and its Executive Regulation.
1. Who this covers
Kodowo is business-to-business middleware, a product of Anqor Studios LLC FZ. Our direct customers (“tenants”) are companies, not individual consumers. This policy covers two categories of personal data we handle: (a) data about people at our tenants and prospective tenants, names, work emails, and similar contact details submitted through this site or provided during onboarding; and (b) personal data that may appear inside invoice payloads our tenants submit to us for processing — depending on what the source document contains, this can include named contacts, addresses, phone numbers, email addresses, bank or payment details, employee information, or other information capable of identifying a natural person, not only a named contact on an invoice line.
Kodowo is a software middleware provider and is not an Accredited Service Provider under the UAE Electronic Invoicing System. Kodowo does not operate a UAE Peppol Access Point and does not directly report Tax Data to the Federal Tax Authority; every submission is routed through the tenant’s own chosen, accredited ASP, which remains responsible for the regulated exchange and reporting functions an ASP performs.
2. What we collect directly
- Early-access and contact form submissions: name, company, work email, role, source system, and any message you provide.
- API and account activity: requests made with a tenant’s API key, for security, debugging, and the audit trail described in our platform documentation.
- Standard web server logs: IP address, user agent, and request timestamps for the pages on this site.
3. Data submitted through the compliance API
When a tenant submits an invoice for validation or transmission, the payload may contain personal data about the parties to that invoice. We process this data as a processor acting on the tenant’s instructions, not as the party who decided to collect it. It is persisted to a tenant-isolated ledger protected by Postgres Row-Level Security, and to an append-only audit log, for as long as is necessary to provide the service and meet the tenant’s own regulatory retention obligations. We also record technical metadata about each transmission attempt (timestamps, payload size, success or failure) for audit integrity and usage metering. We do not sell this data, and we do not use it to build profiles for any purpose unrelated to providing the service.
4. Business verification documents
To activate live invoice transmission, we require a copy of your valid UAE Trade License and your FTA TRN Certificate. These documents can contain personal data, for example the names of owners or managers appearing on a trade license. We collect them to verify your business before granting access to the live transmission network; this is necessary to provide the service you are signing up for.
Documents are encrypted at rest in a private storage container with no public access, using envelope encryption (Section 6). Access is limited to authorized internal reviewers via short-lived, expiring links. A document you replace is superseded, not publicly retained, and a rejected or withdrawn application’s documents are deleted within 90 days.
5. How we use personal data
- To respond to early-access and contact requests.
- To provision, operate, and secure tenant accounts and API access.
- To validate, route, and maintain an audit trail for invoices submitted through the API, on the tenant’s behalf.
- To verify your business before enabling live invoice transmission.
- To investigate and respond to security incidents.
6. Where data is stored
Our production infrastructure currently runs on Amazon Web Services in the United States. This does not put a tenant’s own e-invoicing compliance at risk, for a specific reason: Kodowo is not performing the regulated ASP function. The UAE’s June 2026 Electronic Invoicing Guidelines confirm that compliant invoice storage can occur on infrastructure inside or outside the UAE, provided retention, integrity, security, and availability-to-the-Authority conditions are met — the hosting and data-residency conditions tied to ASP accreditation apply to ASPs specifically, not to middleware sitting upstream of one. Personal data may still be processed outside the UAE, including in the United States; where it is, we apply the safeguards and contractual measures required by applicable UAE data protection law. ASP credentials are encrypted with AES-256-GCM envelope encryption before storage, with the key-encryption key held outside the database. For our full technical and organizational security measures, including current certification status, see our Data Processing Agreement or contact us for our security documentation.
One feature is a deliberate exception to how we otherwise handle data: PDF vision-intake, for customers with no ERP to connect. If you choose to upload a raw invoice PDF through that feature, we send that document, unredacted, to Anthropic (our AI provider) so it can read and propose the invoice’s fields for your own review before anything is submitted. Every other AI-assisted feature we offer operates only on de-identified, redacted data, with names, amounts, and tax registration numbers replaced before any AI provider sees them. This unredacted flow only happens for a document you affirmatively choose to upload through this specific feature.
7. Retention
Your own legal retention obligation for invoices you issue is governed by UAE tax recordkeeping law, not by this policy — that responsibility stays with you as the business issuing the invoice. Separately, as our own operational policy, we retain invoice and account data for as long as your account is active, plus 30 days after termination for export, then delete it within a further 30 days except where it exists transiently in encrypted backups pending their normal deletion cycle. Audit log data is retained for 6 years from creation as our own policy choice supporting dispute resolution and regulatory defense — not a period UAE e-invoicing law specifically mandates for a middleware provider’s own logs.
8. Your rights
Subject to applicable law, individuals whose personal data we hold may have rights to access, correct, or request deletion of that data. Because most personal data we process arrives inside a tenant’s invoice submissions, requests concerning that data should generally go to the relevant tenant first, as they control what is submitted. For data we hold directly (contact form submissions, account data), reach out at privacy@kodowo.com or through the early-access page.
9. Breach notification
Where a breach affects data we process on your behalf, our first obligation is to notify you without undue delay, so you can determine and meet whatever regulatory notification duty applies to your own business. For data we hold directly, we assess the risk to affected individuals and, where required, notify the UAE Data Office without undue delay, and notify affected individuals directly where a breach poses a high risk to their rights.
10. Changes to this policy
We may update this policy from time to time. Material changes are notified to account administrators at least 15 days before taking effect.
The full version of this policy, including the complete cross-border transfer and retention detail, is maintained at docs/legal/PRIVACY_POLICY_DRAFT.md in our source repository and controls in the event this summary omits a detail.