Privacy Policy
DRBY Software Development L.L.C · Trade License No. 1546497
Introduction
This Privacy Policy explains how Drby [DRBY Software Development L.L.C, a company with Trade License no. 1546497 issued by the Dubai Department of Economy and Tourism, having its registered address at Office 43-44, Owned by Dubai Municipality, Al Fahidi, Bur Dubai] (“Drby”, “we”, “us”, or “our”) collects, uses, processes, stores, and protects Personal Data in connection with its platform and services.
Drby operates a technology platform that enables payments for education-related goods and services between Parents, Companies, and Recipients, including Schools and Merchants, through a licensed Payment Gateway. We are not a bank, financial institution, wallet provider, or lending service. The App does not collect, store, hold, receive, send, pool, or control funds. All payment processing and settlement activities are performed exclusively by the licensed Payment Gateway.
This Privacy Policy applies to all users of the Platform, including:
- ·Parents and Guardians using the mobile application;
- ·Companies using the platform to make payments on behalf of Employees; and
- ·Schools and other Recipients using the platform to receive payments.
Drby is committed to processing Personal Data in accordance with Applicable Law, including the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (“PDPL” or “Applicable Law”).
By using the Platform, you acknowledge that your Personal Data will be processed in accordance with this Privacy Policy.
Who We Are (Data Controller)
Drby is the entity responsible for the collection and processing of Personal Data in connection with the Platform.
For the purposes of Applicable Law, Drby acts as a data controller in relation to the operation of the Platform, including account management, platform functionality, and user communications.
In certain circumstances, Drby may also act as:
- ·a data processor, where it processes Personal Data strictly under the instructions of Schools or Companies for the purpose of facilitating payments; or
- ·a joint or independent data controller, where multiple parties determine the purposes and means of processing Personal Data.
The roles of Drby, Schools, and Companies in relation to Personal Data may vary depending on the nature of the interaction and the specific processing activity.
For any questions, requests, or concerns regarding this Privacy Policy or the processing of Personal Data, Drby may be contacted using the contact details provided in Section 17.
Scope and Applicability
This Privacy Policy applies to all Personal Data processed by Drby in connection with the use of the Platform.
This includes Personal Data collected or processed through:
- ·the mobile application used by Parents and Guardians;
- ·the Company portal used by businesses making payments on behalf of Employees; and
- ·the School or Recipient portal used to receive and manage payments.
This Privacy Policy applies to the following categories of individuals:
- ·Parents and Guardians;
- ·Employees of Companies using the Platform;
- ·Students or beneficiaries; and
- ·authorised representatives of Schools and Companies.
This Privacy Policy does not apply to services operated by third parties, including the Payment Gateway, or to the processing of Personal Data by Schools or Companies outside the scope of the Platform.
Categories of Personal Data Collected
4.1 Personal Data of Parents and Guardians
- ·identification information (such as name and Emirates ID details, where applicable);
- ·contact information (such as email address and phone number);
- ·account and login information;
- ·payment-related information (excluding full card details, which are processed by the Payment Gateway); and
- ·transaction history and usage data.
4.2 Personal Data of Company Representatives and Employees
- ·identification and employment-related information (such as name, company affiliation, and role);
- ·contact information;
- ·account and access credentials; and
- ·payment-related and transaction data linked to education payments.
4.3 Personal Data of Students
- ·name and identification details (such as student ID or reference number);
- ·school or educational institution details;
- ·payment-related information linked to the Student; and
- ·other limited data necessary to facilitate payments.
4.4 Personal Data of Schools and Recipients
- ·institution details, licensing information, and authorised representatives;
- ·contact and account information; and
- ·transaction and payment-related data.
4.5 Technical and Usage Data
- ·device information, IP address, and browser type;
- ·log data and usage activity; and
- ·interaction with the Platform.
4.6 Data Minimisation
Drby limits the collection of Personal Data to what is necessary for the provision of the Services and compliance with Applicable Law.
Sources of Personal Data
5.1 Direct Collection from Users
Personal Data is collected directly from Parents, Company representatives, and School users when they create an account, use the Platform, initiate or manage payments, or communicate with Drby.
5.2 Data Provided by Companies
Companies may provide Personal Data relating to Employees and associated Students for the purpose of facilitating payments through the Platform.
5.3 Data Provided by Schools or Recipients
Schools and other Recipients may provide Personal Data relating to Students or payment details required to facilitate transactions.
5.4 Data from Payment Gateway
Drby may receive limited transaction-related information from the Payment Gateway, excluding sensitive payment card details.
5.5 Automatic Collection
Certain technical and usage data is collected automatically through the use of the Platform, including device and log information.
5.6 Responsibility for Data Provided
Any party providing Personal Data to Drby represents that such data has been obtained lawfully and that all necessary consents or authorisations have been obtained in accordance with Applicable Law.
Purposes of Processing
6.1 Provision of Services
- ·create, authenticate, and manage user accounts;
- ·enable payment initiation and coordination through the Platform;
- ·generate and manage Payment Links;
- ·provide transaction tracking, reporting, and reconciliation; and
- ·display fee and billing information.
6.2 Payment Facilitation
Personal Data is processed to facilitate payments between Parents, Companies, and Recipients through the Payment Gateway.
6.3 Communication
Personal Data is used to communicate with users, including sending notifications, updates, confirmations, and support responses.
6.4 Compliance with Legal Obligations
Personal Data is processed to comply with Applicable Law, including regulatory, reporting, and compliance requirements.
6.5 Fraud Prevention and Security
Personal Data is used to detect, prevent, and investigate fraud, misuse, or unlawful activity, and to ensure the security of the Platform.
6.6 Platform Improvement
Personal Data may be used to analyse usage, improve functionality, and enhance the user experience.
6.7 Limited Use
Personal Data shall not be used for purposes incompatible with those set out in this Section. For the avoidance of doubt, Drby does not:
- ·Process or authorize any payments
- ·Capture, store, or transmit card data
- ·Hold, pool, control, or move funds
- ·Execute settlement or reconciliation
- ·Provide financial or lending services
Legal Basis for Processing
7.1 Contractual Necessity
Personal Data is processed where necessary for the performance of a contract, including providing access to the Platform, facilitating payments, and delivering the Services.
7.2 Legal Obligations
Personal Data is processed where required to comply with Applicable Law, including regulatory, reporting, and compliance obligations.
7.3 Legitimate Interests
Personal Data may be processed where necessary for Drby's legitimate interests, including ensuring the security and integrity of the Platform, preventing fraud and misuse, and improving the Services.
7.4 Consent
Where required, Personal Data is processed based on the consent of the individual, including processing of certain categories of Personal Data and processing of Personal Data relating to Students.
7.5 Withdrawal of Consent
Where processing is based on consent, such consent may be withdrawn at any time, subject to legal or contractual limitations.
Data Sharing and Disclosure
8.1 Payment Gateway
Personal Data necessary for payment processing is shared with the Payment Gateway, which processes such data in accordance with its own terms and privacy policies.
8.2 Schools and Recipients
Personal Data may be shared with Schools and other Recipients to facilitate payments, verify transactions, and support the provision of education-related goods or services.
8.3 Companies
Personal Data may be shared with Companies where payments are made on behalf of Employees, for purposes including payment management, reporting, and reconciliation.
8.4 Service Providers
Drby may share Personal Data with third-party service providers supporting the Platform, including cloud hosting providers, analytics providers, IT security and maintenance, and communication service providers.
8.5 Legal and Regulatory Authorities
Drby may disclose Personal Data to regulatory authorities, law enforcement agencies, or other third parties where required to comply with Applicable Law.
8.6 Business Transfers
Personal Data may be transferred as part of a corporate transaction, including a merger, acquisition, or sale of assets, subject to appropriate safeguards.
8.7 No Selling
Drby never sells or trades personal data.
Data Roles and Responsibilities
9.1 Drby as Data Controller
Drby acts as a data controller where it determines the purposes and means of processing Personal Data, including operating the Platform, managing accounts, and ensuring security and compliance.
9.2 Drby as Data Processor
Drby may act as a data processor where it processes Personal Data on behalf of Schools or Companies, strictly under their instructions as Data Controllers for student and billing related data.
9.3 Independent or Joint Controllers
Drby, Schools, and Companies may act as independent or joint data controllers where each party determines the purposes and means of processing Personal Data for their respective activities.
9.4 Responsibilities of Schools and Companies
- ·determining the lawful basis for their processing of Personal Data;
- ·obtaining all necessary consents or authorisations from Parents, Employees, or Students; and
- ·ensuring that Personal Data shared with Drby is accurate and lawfully obtained.
Children's Data
10.1 Processing of Student Data
Drby may process Personal Data relating to Students solely for the purposes of providing the Services, including facilitating payments and related platform functionality. Schools remain the primary Data Controller for student information.
10.2 Parental or Authorised Consent
Personal Data relating to Students must be provided by a Parent, Guardian, or authorised party who has the legal authority to do so.
10.3 Data Minimisation
Drby limits the collection and processing of Student Personal Data to what is strictly necessary for the provision of the Services.
10.4 Use Limitation
Student Personal Data is used only for purposes directly related to payment facilitation, service coordination, compliance, and platform operation.
10.5 Sharing of Student Data
Student Personal Data may be shared with Schools, Companies, and the Payment Gateway only to the extent necessary to provide the Services or comply with Applicable Law.
Cross-Border Data Transfers
11.1 International Processing
Personal Data may be transferred to, stored in, or processed in jurisdictions outside the United Arab Emirates where Drby or its service providers operate.
11.2 Safeguards
Where Personal Data is transferred outside the United Arab Emirates, Drby implements appropriate safeguards in accordance with Applicable Law to ensure that such data is protected.
11.3 Acknowledgement
By using the Platform, users acknowledge that Personal Data may be transferred outside the United Arab Emirates in accordance with this Privacy Policy.
Data Retention and Deletion
12.1 Retention Period
Drby retains Personal Data only for as long as necessary to fulfil the purposes set out in this Privacy Policy, including providing the Services, complying with Applicable Law, and supporting disputes, audit requirements, and operational logs.
12.2 Legal and Regulatory Requirements
Personal Data may be retained for longer periods where required to comply with legal, regulatory, or reporting obligations.
12.3 Account Closure
Upon termination or closure of an account, Personal Data may be retained for a reasonable period for compliance, record-keeping, and dispute resolution purposes.
12.4 Deletion or Anonymisation
Where Personal Data is no longer required, Drby will take reasonable steps to delete or anonymise such data in accordance with Applicable Law.
Data Security Measures
13.1 Security Controls
Drby implements appropriate technical and organisational measures to protect Personal Data against unauthorised access, loss, misuse, alteration, or disclosure.
13.2 Access Management
Access to Personal Data is restricted to authorised personnel and service providers on a need-to-know basis and subject to appropriate access controls.
13.3 System Protection
Drby applies reasonable security practices, including encryption, access controls, authentication mechanisms, monitoring, and periodic testing, to safeguard Personal Data.
13.4 No Absolute Guarantee
While Drby takes reasonable measures to protect Personal Data, no system can be guaranteed to be completely secure.
Data Subject Rights
14.1 Rights of Individuals
Subject to Applicable Law, individuals have the right to:
- ·request access to their Personal Data;
- ·request correction of inaccurate or incomplete Personal Data;
- ·request deletion of Personal Data;
- ·request restriction of processing;
- ·object to certain processing activities; and
- ·request transfer of Personal Data, where applicable.
14.2 Exercise of Rights
Requests to exercise data subject rights may be submitted to Drby through the contact details provided in this Privacy Policy.
14.3 Verification
Drby may require verification of identity before processing any request relating to Personal Data.
14.4 Complaints
Individuals have the right to lodge a complaint with the relevant data protection authority in the United Arab Emirates.
Data Breach Notification
15.1 Incident Response
Drby maintains procedures to identify, assess, and respond to incidents involving Personal Data.
15.2 Notification to Individuals
Where required under Applicable Law, Drby will notify affected individuals of a Personal Data breach that is likely to result in a risk to their rights or interests.
15.3 Regulatory Notification
Drby may notify relevant regulatory authorities of a Personal Data breach where required under Applicable Law.
Updates to this Privacy Policy
16.1 Changes to the Policy
Drby may update this Privacy Policy from time to time to reflect changes in the Services, legal requirements, or data processing practices.
16.2 Notification
Where required, Drby will notify users of any material changes through the Platform or other communication channels. It is the user's responsibility to frequently review the Privacy Policy.
16.3 Continued Use
Continued use of the Platform after the effective date of any updates constitutes acceptance of the revised Privacy Policy.
Contact Details and Complaints
17.1 Contact Information
For any questions, requests, or concerns regarding this Privacy Policy or the processing of Personal Data, you may contact Drby at hello@drby.com.
17.2 Data Requests
Requests relating to access, correction, deletion, or other data subject rights may be submitted through the contact channels made available by Drby.
17.3 Complaints
If you believe that your Personal Data has been processed in violation of Applicable Law, you have the right to lodge a complaint with the relevant data protection authority in the United Arab Emirates.
Third-Party Links
The Drby Platform may display or redirect users to third-party links. Drby is not responsible for the privacy practices of third-party sites.