Privacy Policy

Last updated: [DATE]

This policy explains how Dazenga collects and uses personal data. It applies to the Dazenga website, the Dazenga web app, and the Dazenga NFC/QR review stands (together, the “Service”).

1. Who we are

The Service is operated by Mash'al Abdulqadir, trading as Dazenga (“Dazenga”, “we”, “us”, “our”). For most personal data we process, Mash'al Abdulqadir, trading as Dazenga is the data controller.

You can contact us about privacy at privacy@dazenga.com (or support@dazenga.com). Our postal address is 166 Hagley Road, Birmingham, B16 9NZ.

2. The two groups this policy covers

Dazenga is used by two groups, and we handle their data differently:

  • Account holders — the businesses, and the people acting for them, who sign up, subscribe and manage feedback. For account-holder data we are the controller.
  • Members of the public — customers of those businesses who tap or scan a Dazenga stand and choose to leave private feedback. For the content of that feedback we act as a processor on behalf of the business it was left for: that business decides what to do with it. We are the controller for the limited technical data we collect to run and protect the Service (section 5).

3. Data we collect from account holders

  • Account & identity: your email address, a password (stored only as a salted hash by our authentication provider — we never see it), and an account name.
  • Business details you enter: business name, category, address, phone number, website, your review link, and a notification email address.
  • Billing: your plan and subscription status, and a record of payments (amount, date, currency, type). Card details are entered directly with our payment provider, Stripe, and are not stored by Dazenga.
  • Hardware orders: quantities, delivery name and address, and tracking references for stands you order.
  • Partner Programme data (if you join): your name, how you plan to promote Dazenga, and the payout details you give us (a PayPal email, or an account name, sort code and account number), plus a record that you accepted the Partner terms.
  • Technical & usage data: IP address, browser and device information, pages visited and actions taken in the app. We use short-lived IP-based records to rate-limit requests and prevent abuse.
  • Support correspondence: messages you send us and our replies.

4. Data we collect from members of the public

When someone uses a Dazenga stand and chooses “Report an issue / speak to management”:

  • Their message — the free text they write.
  • Their email address — only if they provide it. Leaving feedback anonymously is offered and supported; if they choose that, no email is collected.
  • A source tag (NFC, QR or link) and the date and time.

When someone uses a stand at all (either option, or just the landing page):

  • We record anonymous, aggregated events (a visit, a redirect to the review site, a feedback submission) for the business’s statistics. These contain no names or contact details.
  • We process the visitor’s IP address transiently to rate-limit submissions and filter automated traffic. Where any IP-derived value is kept beyond the moment (for example in our referral-click log) it is stored as a one-way hash, not the address itself.

We do not ask members of the public for anything more than this, and we ask that special category data (such as health, or political or religious views) is not submitted through the feedback form.

5. Why we use personal data, and our legal bases (UK GDPR)

WhatWhyLegal basis
Create and run your account; provide the Service; take paymentTo perform our contract with youContract
Send service emails (confirmation, password reset, feedback alerts, billing)To perform our contract and operate the ServiceContract / legitimate interests
Deliver private feedback to the business it was left forTo provide the feedback service the business asked for; the business has a legitimate interest in hearing from its customersLegitimate interests (we act as the business’s processor for the message)
Aggregate, non-identifying statisticsTo give businesses useful insight and improve the ServiceLegitimate interests
Security, fraud prevention, rate limiting, referral-fraud flaggingTo protect the Service, our users and usLegitimate interests / legal obligation
Keeping financial recordsTo meet tax and accounting lawLegal obligation
Cookies that are not strictly necessary (see Cookie Policy)Consent

We do not use your data for advertising, we do not sell it, and we do not send marketing emails unless you have separately opted in. Where we rely on legitimate interests we have weighed them against your rights and do not consider our processing overridden. You can object at any time (section 9).

6. Automated decision-making

We use automated checks to flag possible referral fraud (for example, a partner referring themselves) for a person to review. We do not make solely automated decisions that produce legal or similarly significant effects — a person always reviews a flag before any action is taken.

7. Who we share personal data with

We use a small number of service providers (“sub-processors”) who process personal data on our behalf under contract and may only use it to provide services to us.

ProviderPurposeLocation / safeguard
SupabaseDatabase and user-authentication hostingData stored in the UK/EU (London region); data-processing agreement in place
VercelApplication and website hosting, content deliveryUS company with global infrastructure; data-processing agreement and Standard Contractual Clauses / UK IDTA
StripePayment processing and subscription billingStripe Payments UK/Europe; PCI-DSS compliant; SCCs / UK IDTA for any transfer
ResendSending transactional emailsUS company; data-processing agreement and SCCs / UK IDTA

We may also disclose personal data:

  • to professional advisers (lawyers, accountants) under confidentiality;
  • if we buy or sell a business or assets, to the prospective buyer or seller;
  • where required by law, court order, or to establish, exercise or defend legal claims, or to protect the rights, property or safety of Dazenga, our users or others.

We are not responsible for the privacy practices of Google or any review platform your stand links to — your use of those services is governed by their own terms and privacy policies.

8. International transfers

Our primary database is hosted in the UK/EU. Some providers (Vercel, Stripe, Resend) are based in, or transfer data to, the United States or other countries outside the UK. Where they do, the transfer is protected by an appropriate safeguard — an adequacy decision, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum. Ask us using the contact in section 1 for more detail.

9. Your rights

Under UK data protection law you have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate or incomplete data;
  • erase your data (“right to be forgotten”), subject to legal retention obligations;
  • restrict or object to our processing;
  • data portability — receive certain data in a structured, machine-readable format;
  • withdraw consent at any time where we rely on it (this does not affect earlier processing);
  • not be subject to solely automated decisions with legal or significant effect (section 6).

Account holders can export their data and permanently delete their account from the Account page in the app. To exercise any other right, email privacy@dazenga.com. We will respond within one month.

Members of the public: private feedback you leave is controlled by the business it was left for. To have it corrected or deleted, contact that business, or contact us and we will pass your request on and act on our own records.

You also have the right to complain to the ICO (ico.org.uk, 0303 123 1113), though we would ask you to contact us first so we can try to help.

10. How long we keep personal data

  • Account data: for as long as your account is open, then deleted when you delete your account, except where we must keep certain records longer.
  • Financial records (payments, invoices): retained for at least 6 years to meet UK tax law, including within Stripe.
  • Private feedback: kept for the business it was left for while their account is open; deleted with the business or the account, or earlier on a valid erasure request.
  • Security and rate-limiting records: short-lived — automatically purged (rate-limit records within about 24 hours).
  • Aggregate statistics: kept indefinitely in non-identifying form.
  • Backups: our providers keep encrypted backups for a limited rolling period; data in backups is overwritten on their normal cycle.

11. How we protect personal data

Data is encrypted in transit (HTTPS/TLS) and at rest by our hosting providers. Access to production systems is limited to those who need it. Passwords are stored only as salted hashes. We apply security headers, rate limiting and abuse filtering across the Service. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data, and we will notify the ICO and affected individuals of a personal data breach where the law requires.

12. Cookies

See our separate Cookie Policy. In short: we use a strictly-necessary cookie to keep you logged in, and one cookie to credit a partner who referred you. We use no advertising or third-party analytics cookies.

13. Children

The Service is for businesses and is not directed at children. We do not knowingly collect data from children. The feedback form is intended for adult customers of a business.

14. Changes to this policy

We may update this policy. The “last updated” date will change, and for significant changes affecting account holders we will send an email. Continuing to use the Service after a change means you accept the updated policy.

15. Contact

Mash'al Abdulqadir, trading as Dazenga
166 Hagley Road, Birmingham, B16 9NZ
privacy@dazenga.com