GDPR & UAE PDPL Compliance

Data Rights & GDPR

We are committed to full compliance with the EU General Data Protection Regulation (GDPR) and the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection. This page explains your rights, how to exercise them, and how we handle cross-border data transfers.

Effective: 1 January 2026
Updated: 1 April 2026

Your Data Rights

Under GDPR (Articles 15–22) and the UAE PDPL, you have the following rights. We respond to all verified requests within 30 calendar days.

Right of Access
Request a copy of all personal data we hold about you, including purposes, recipients, and retention periods.
30 days
Right to Rectification
Correct inaccurate data or complete incomplete personal data without undue delay.
30 days
Right to Erasure
Request deletion of your personal data. Subject to legal retention obligations for instrument records.
30 days
Right to Restriction
Request we limit processing while accuracy is contested or a legal basis is disputed.
30 days
Right to Portability
Receive your data in structured JSON or CSV format, or have it transmitted to another controller.
30 days
Right to Object
Object to processing based on legitimate interests or for direct marketing purposes at any time.
Immediate
Self-service available: You can export all your data and initiate account deletion directly from Account Settings → Danger Zone without contacting us.

Submit a Data Request

Use the form below to formally exercise any of your GDPR or UAE PDPL rights. All requests are processed within 30 days. We may contact you to verify your identity before processing.

By submitting this form, you consent to us verifying your identity via the registered email address before processing your request. We will never charge a fee for responding to valid GDPR/PDPL requests.

What We Process & Why

The following table maps every category of personal data we process to its legal basis under GDPR Article 6 and the UAE PDPL.

Data Category
Legal Basis
Transferable?
Name & contact
Contract performance (Art. 6(1)(b))
✓ Portable
National ID
Legal obligation (Art. 6(1)(c)) — AML/CFT
Not portable
Instrument records
Contract + Legal obligation (7-year retention)
✓ Portable
Payment records
Legal obligation — tax/accounting law
✓ Portable
Usage analytics
Legitimate interests (Art. 6(1)(f)) — anonymised
Not applicable
Security logs
Legitimate interests — fraud prevention
Not portable
Marketing emails
Consent (Art. 6(1)(a)) — opt-in only
✓ Portable

International Data Transfers

Dayn processes data across two primary regions:

  • eu-west-1 — Primary region for EU and UK users. Ensures data residency within the EEA.
  • me-south-1 — Primary region for GCC and UAE users. AWS Bahrain has an established data centre with physical security to ISO 27001 standards.

For transfers outside the EEA or UAE, we rely on:

  • Standard Contractual Clauses (SCCs) — European Commission-approved clauses with all sub-processors.
  • Adequacy decisions — where the destination country has been deemed adequate by the European Commission or UAE Data Office.
  • Binding Corporate Rules — for AWS Group internal transfers.
A copy of our Standard Contractual Clauses is available on request at [email protected].

Data Breach Procedure

In the event of a personal data breach, we follow this escalation procedure:

  • Within 24 hours: Internal incident team convened. Scope and risk assessment begins.
  • Within 72 hours: Notification to relevant supervisory authority (UAE Data Office / applicable EU DPA) if the breach poses a risk to individuals' rights.
  • Without undue delay: Direct notification to affected users if the breach is likely to result in high risk to their rights and freedoms.
  • Within 30 days: Full incident report with root cause, remediation steps, and preventive measures.

To report a suspected security issue, email [email protected] or use our responsible disclosure programme at getdayn.com/security.

Data Protection Officer

BytesWave has appointed a Data Protection Officer (DPO) responsible for overseeing our data protection strategy and ensuring GDPR and UAE PDPL compliance.

Response SLA
5 business days (initial); 30 days (full)
Postal
DPO, BytesWave Technology LLC,
Abu Dhabi, UAE
Languages
English & Arabic

You also have the right to lodge a complaint with your local supervisory authority: