Privacy Policy
What personal data PropFi processes, why we process it, who we share it with, and how long we keep it.
Last updated 5 September 2026
1. Who we are
PropFi provides software that corporate service providers (“CSPs”) use to run company formation and ongoing corporate services for their clients. The controller of the personal data described here is PropFi FZCO, a free zone company registered in the Dubai Multi Commodities Centre (DMCC), Dubai, United Arab Emirates. You can reach us about this policy at info@getpropfi.com.
Two different relationships matter for this policy. Where a CSP uses PropFi to serve its own clients, the CSP decides what to collect and why, the CSP is the controller and PropFi is its processor. Where we operate the platform itself, accounts, billing, security, and our own marketing, PropFi is the controller. Section 4 says which is which.
2. What we collect
- Account data. Name, work email, the organizations you belong to and your role in each, and whether you have enrolled a second authentication factor.
- Content you put into the platform. Engagements, tasks, documents you upload, and the details of the entities and people a matter concerns, which routinely includes identity documents your clients provide for Know Your Customer (KYC) checks.
- Activity records. We keep an append-only audit log of actions taken in the platform: who did what, to which record, when, from which IP address and browser. This is a deliberate product feature, not incidental telemetry, an auditable trail is what CSPs use PropFi for, and it is described in Section 5.
- Enquiry and assessment data. If you submit the contact form or the CSP Operations Audit, we keep what you entered, including your firm name, your answers and the resulting score.
- Feedback you send us. If you use the in-product feedback button, we keep what you wrote and, if you include one, the screenshot, which captures whatever was on your screen at the time.
- Referral tracking. If you arrive through a referral link we record the click and, if you sign up, which referrer to credit. This is how a referrer gets paid, so it is part of performing that agreement rather than analytics.
- Product analytics. Only if you accept cookies. See Section 6.
3. Why we process it
To provide the platform and the features you use; to authenticate you and keep accounts secure; to produce the audit and compliance records the product exists to produce; to bill you and collect payment; to send transactional email you have asked for or that the service requires; to respond to enquiries; and to detect and investigate misuse.
We do not sell personal data, and we do not use the content you or your clients put into the platform to train machine-learning models.
4. Who we share it with
We use the following processors. Each receives only what its function needs.
- Supabase for database, authentication and file storage. Holds essentially all platform data, including uploaded documents. Hosted in Amazon Web Services’ Mumbai region, in India.
- Vercel for application hosting and delivery. Processes request metadata such as IP addresses. Runs in the same Mumbai region as the database.
- Resend for transactional email delivery. Receives recipient addresses and message content.
- Stripe for subscription billing and, where a firm receives payouts, Stripe Connect. Card details go to Stripe directly and are never stored by PropFi.
- Slack for internal operational alerting. Receives enquiry and booking details, and product feedback including any screenshot you attach to it.
- Google for push notification delivery, through Firebase Cloud Messaging. Receives device tokens and the title and body of the notification.
- Redis (Redis Cloud) for caching, rate limiting and stopping duplicate submissions. Holds short-lived operational data, including IP addresses, user identifiers and the state of an in-progress connection to a service your firm links, typically for minutes at a time. Runs in the same Mumbai region as the database, and nothing there is kept: a restart discards it.
- Zoho for where your firm connects it: CRM for enquiry and contact sync, WorkDrive for document sync, and Bookings for scheduled calls. What is shared depends on which integration your firm enables. Which Zoho data center holds it depends on where your firm’s own Zoho account is registered.
- Microsoft Clarity for product analytics. Only loaded if you accept cookies. See Section 6.
We also disclose data where we are legally required to, and to professional advisers bound by confidentiality.
None of these processors holds your data in the UAE, so personal data you and your clients put into PropFi leaves the country.
Where it does, we rely on two things: the transfer is necessary to perform our contract with your firm, and we hold written data processing terms with each processor that impose data-protection obligations equivalent to our own, including the standard contractual clauses each of them publishes. We do not rely on any country having been designated as providing an adequate level of protection, because the UAE has made no such designation.
Hosting in a particular jurisdiction may be available under an Enterprise agreement. If your firm has a data-residency requirement, raise it with us before you sign so we can scope it, rather than assuming the current arrangement will change.
5. How long we keep it
Every period below is set by our internal data-retention standard, and this page states only what that standard says. Where the law requires a minimum, the longer period wins.
When your organization’s access ends, we keep everything for 30 days so you can retrieve it using the export features in the product. After that we delete or anonymise it on your instruction, and in any event within 90 days of access ending. The 90 days runs from closure, not from your request, asking makes it sooner, never later.
- Engagement records, documents and entity data. Kept while your organization has an account, then as above. A retention policy set on a document vault governs first: it can hold documents for longer, or expire them earlier, and your firm decides which.
- Your account. Profile, membership of organizations, and authentication settings, kept while the account exists, then as above.
- The audit log for seven years from the date of each entry. Our audit surfaces show the last twelve months by default and a wider window is available in the product. This is the longest-lived record on the platform, and deliberately so: an audit trail that can be quietly shortened is not an audit trail.
- Billing, invoices and payment records for seven years from the end of the relevant tax period, which is what UAE corporate-tax law requires of us. Card details are held by Stripe and never by PropFi.
- Notifications. Your inbox is cleared after three months; delivery records after 90 days. Your notification preferences last as long as your account, and a device’s push registration until that device unregisters.
- Enquiries and CSP Operations Audit submissions for two years from our last contact with you about them. Newsletter subscriptions last until you unsubscribe, and we keep a record of the unsubscribe for two years afterwards as proof we honored it.
- Security records. Recovery codes last as long as your account. Failed authentication attempts are cleared once you sign in successfully, and otherwise after 90 days. Records of what permission checks refused, which we keep to diagnose access problems, last twelve months.
- Integrations. Access tokens are revoked and deleted when you disconnect an integration. The records of what synchronised are kept for twelve months, or until you disconnect.
- Feedback for twelve months from when you send it, screenshot included.
- Referrals. A referral payment and the record of who earned it are kept for seven years, like any other payment. The click data behind it is kept for twenty-four months.
Two things outlive the rest, and you should know why.
- A legal hold overrides every period on this page. Where a record is under one, it is kept until the hold is released, whatever else would have applied and regardless of a deletion request.
- Deletion is not instantaneous. Data already written to our hosting provider’s backups persists until that backup window rolls off, which is currently seven days. Our hosting and application providers keep their own request logs on their own short windows, and the processors in section 4 keep their own copies under their own retention policies.
Where your firm is the controller, how long a matter’s records are kept is your firm’s decision, not ours. We do not delete against it, and we delete on your instruction. Your firm stays responsible for the record-keeping periods it is subject to, in the UAE commonly five years for anti-money-laundering records, seven for corporate tax, and longer for some real-estate records. Those duties survive your PropFi account, so export before you close it.
6. Cookies and analytics
We use cookies that are strictly necessary to sign you in and keep your session, and only with your consent Microsoft Clarity to understand how the product is used. Rejecting consent means Clarity is never loaded; the sign-in cookies remain, because without them the platform cannot authenticate you. You can change your choice at any time on the cookies page.
7. Your rights
This policy is governed by Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, the UAE’s federal data-protection law. It applies to us because PropFi is registered in the DMCC rather than in the DIFC or ADGM, each of which has its own regime. Under it you may ask for a copy of your personal data, ask us to correct or delete it, object to or restrict some processing, ask us to transfer it, and withdraw consent you have given. Where another country’s data-protection law applies to you, the rights it gives you apply in addition to these.
Two limits apply, and we would rather state them here than in a reply.
- We may refuse to erase an audit record. The law permits a controller to decline where erasure would affect an investigation, a claim of rights, legal proceedings or its own defense, and an audit trail is exactly that kind of record. So this is a refusal we are entitled to make, not merely one the system forces on us. An entry also keeps the details of what it recorded, which can include a name or an email address, because an entry that cannot say what happened evidences nothing.
- Where a firm put your data into PropFi, that firm is the controller. We refer your request to them, and they weigh it against their own legal duties. That applies to a member of a firm as much as to its clients: what you did inside an organization is that organization’s record, not your personal data to withdraw. We will delete your PropFi account itself on request.
To make a request, email info@getpropfi.com. If you are not satisfied with how we have handled it you can complain to the UAE Data Office.
8. Security
Access to data is restricted by role and by organization. Connections to PropFi are encrypted with HTTPS. Our hosting providers, Supabase and Vercel, state that the disks their systems run on and their scheduled backups are encrypted at rest with AES-256. That is their control rather than ours, and we do not hold those keys. What we encrypt ourselves is a short list: stored CRM access tokens, inbound webhook secrets and payee bank details, each with AES-256-GCM under a key derived per firm, so no two firms share a key. Documents you upload, including identity documents your clients provide for KYC, are not separately encrypted by PropFi, and access to them is governed by the same role and organization rules as everything else. Optional multi-factor authentication is available on all accounts and we recommend enabling it. No system is perfectly secure, and we do not claim otherwise.
9. Changes and contact
If we change this policy we will update the date at the top of this page, and tell you directly where the change is material. Questions about it go to info@getpropfi.com.