Data Rights & GDPR
We are committed to full compliance with the EU General Data Protection Regulation (GDPR) and the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection. This page explains your rights, how to exercise them, and how we handle cross-border data transfers.
Your Data Rights
Under GDPR (Articles 15–22) and the UAE PDPL, you have the following rights. We respond to all verified requests within 30 calendar days.
Submit a Data Request
Use the form below to formally exercise any of your GDPR or UAE PDPL rights. All requests are processed within 30 days. We may contact you to verify your identity before processing.
What We Process & Why
The following table maps every category of personal data we process to its legal basis under GDPR Article 6 and the UAE PDPL.
International Data Transfers
Dayn processes data across two primary regions:
- eu-west-1 — Primary region for EU and UK users. Ensures data residency within the EEA.
- me-south-1 — Primary region for GCC and UAE users. AWS Bahrain has an established data centre with physical security to ISO 27001 standards.
For transfers outside the EEA or UAE, we rely on:
- Standard Contractual Clauses (SCCs) — European Commission-approved clauses with all sub-processors.
- Adequacy decisions — where the destination country has been deemed adequate by the European Commission or UAE Data Office.
- Binding Corporate Rules — for AWS Group internal transfers.
Data Breach Procedure
In the event of a personal data breach, we follow this escalation procedure:
- Within 24 hours: Internal incident team convened. Scope and risk assessment begins.
- Within 72 hours: Notification to relevant supervisory authority (UAE Data Office / applicable EU DPA) if the breach poses a risk to individuals' rights.
- Without undue delay: Direct notification to affected users if the breach is likely to result in high risk to their rights and freedoms.
- Within 30 days: Full incident report with root cause, remediation steps, and preventive measures.
To report a suspected security issue, email [email protected] or use our responsible disclosure programme at getdayn.com/security.
Data Protection Officer
BytesWave has appointed a Data Protection Officer (DPO) responsible for overseeing our data protection strategy and ensuring GDPR and UAE PDPL compliance.
[email protected]
5 business days (initial); 30 days (full)
DPO, BytesWave Technology LLC,
Abu Dhabi, UAE
English & Arabic
You also have the right to lodge a complaint with your local supervisory authority:
- UAE — UAE Telecommunications and Digital Government Regulatory Authority (TDRA)
- EU — Your national Data Protection Authority (find yours at edpb.europa.eu)
- UK — Information Commissioner's Office (ICO)