Legal Document

Privacy Policy

This policy explains how BytesWave LLC ("Dayn", "we", "us") collects, uses, stores, and protects personal data when you use our debt instrument documentation platform.

Effective: 1 January 2026
Last updated: 1 April 2026
Plain-language summary: We collect only what we need to run the platform. We never sell your data. You can request deletion or export at any time. We use bank-grade encryption for all sensitive records.

Who We Are

BytesWave LLC is a technology company incorporated in Abu Dhabi, United Arab Emirates. We operate the Dayn platform, accessible at getdayn.com, which enables individuals and businesses to issue, verify, and manage legally binding debt instruments across multiple jurisdictions.

For the purposes of applicable data protection laws (including UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection, and the EU General Data Protection Regulation where applicable), BytesWave LLC is the data controller.

Registered address: BytesWave LLC, Abu Dhabi Global Market Square, Al Maryah Island, Abu Dhabi, UAE.
Data Protection Officer: [email protected]

Data We Collect

We collect data in three ways: information you provide directly, information generated through platform usage, and information we receive from third parties.

CategoryExamplesWhy Collected
IdentityFull name, national ID number, photolegal document issuance
ContactEmail address, phone number, mailing addressAccount management, OTP delivery, notifications
OrganizationCompany name, commercial registration, authorized signatoriesBusiness instrument issuance
FinancialDebt amounts, currencies, payment records, bank details (billing only)Instrument documentation, subscription billing
UsagePages visited, features used, session duration, IP addressPlatform improvement, fraud detection
DeviceBrowser type, OS, device ID, time zoneSecurity, session management
CommunicationsSupport tickets, chat messages, emails to usCustomer support

We do not collect: social media passwords, genetic or biometric data, or data about minors under 18.

How We Use Your Data

  • Platform services: Creating, storing and verifying debt instruments; sending OTP confirmations to debtors; generating PDF instrument documents.
  • Identity: AML checks as required by UAE law and the jurisdictions in which instruments are issued.
  • Communications: Transactional emails (document status, payment alerts, due-date reminders, security notices). You can opt out of non-essential notifications in your account settings.
  • Billing: Processing subscription payments via our payment provider. We do not store raw card data.
  • Security & fraud prevention: Monitoring for suspicious login activity, rate-limiting, IP reputation checks.
  • Legal compliance: Responding to lawful requests from courts, regulators, and enforcement authorities.
  • Platform improvement: Aggregated, anonymised analytics to improve features and performance. We never use identifiable data for marketing profiling.
We never sell your personal data to third parties, data brokers, or advertisers. Dayn products are ad-free.

Legal Basis for Processing

Under GDPR and the UAE Personal Data Protection Law, we process your data under one or more of the following lawful bases:

  • Contract performance — processing necessary to deliver the services you signed up for.
  • Legal obligation — AML requirements, court orders, regulatory requests.
  • Legitimate interests — fraud prevention, platform security, aggregated analytics.
  • Consent — marketing communications and optional cookies (you can withdraw consent at any time).

Data Sharing & Third Parties

We share data only where strictly necessary, with the following categories of recipients:

  • Cloud infrastructure — AWS hosts our platform data in the eu-west-1 and me-south-1 regions.
  • Payment processing — Stripe, Inc. processes subscription billing. Stripe is PCI-DSS Level 1 certified.
  • SMS delivery — Twilio sends OTP verification codes. Only the recipient's phone number is shared.
  • Email delivery — Amazon SES transmits transactional emails.
  • Error monitoring — Sentry receives anonymised crash reports with no personally identifiable data.
  • Legal authorities — Courts, regulators, and enforcement bodies where we are legally required to disclose.

All third parties are bound by data processing agreements and are prohibited from using your data for their own purposes.

International Data Transfers

Your data may be transferred to and processed in countries outside the UAE or EEA. When this occurs, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Adequacy decisions where applicable.
  • AWS regions chosen to minimise cross-border transfers where possible (Ireland for EU users, Bahrain for GCC users).

Data Retention

Data TypeRetention PeriodReason
Account dataDuration of account + 3 yearsContractual obligations
Debt instrument records7 years from instrument creationLegal / audit requirements (UAE Commercial Transactions Law)
Payment records7 yearsTax and accounting regulations
Identity documents5 years after last transactionAML compliance
Support communications3 yearsDispute resolution
Security logs12 monthsFraud investigation
Anonymised analyticsIndefinitely (no personal data)Platform improvement

When you delete your account, we initiate deletion of your personal data within 30 days, except where retention is required by law.

Security Measures

  • All data encrypted in transit (TLS 1.3) and at rest (AES-256).
  • Amazon Aurora with automated backups and point-in-time recovery.
  • Multi-factor authentication (SMS OTP & TOTP) available for all accounts.
  • Role-based access control — staff access is least-privilege and audit-logged.
  • Regular penetration testing and vulnerability scanning.
  • SOC 2-compliant hosting infrastructure via AWS.

In the event of a data breach that poses a risk to your rights, we will notify you and relevant supervisory authorities within 72 hours of discovery.

Your Rights

Depending on your location, you have the following rights regarding your personal data:

  • Access — request a copy of all personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion of your data ("right to be forgotten"), subject to legal retention requirements.
  • Restriction — request we limit processing while a dispute is resolved.
  • Portability — receive your data in a structured, machine-readable format (JSON or CSV).
  • Object — object to processing based on legitimate interests or for direct marketing.
  • Withdraw consent — for consent-based processing, withdraw at any time without penalty.
To exercise any of these rights, email [email protected] or use the Account Settings → Danger Zone → Export All Data feature in your dashboard. We respond to all verified requests within 30 days.

You also have the right to lodge a complaint with your local data protection authority. For UAE residents, this is the UAE Data Office For EU residents, this is your national supervisory authority.

Cookies & Tracking

We use strictly necessary cookies to operate the platform (session tokens, CSRF tokens, language and theme preferences). We do not use advertising cookies or third-party tracking pixels.

CookiePurposeDuration
dayn_sessionAuthenticated session token (HttpOnly, Secure, SameSite=Strict)Session / 30 days if "Remember me"
dayn_csrfCross-site request forgery protectionSession
dayn_themeLight/dark mode preference (localStorage)Persistent
dayn_langInterface language preference (localStorage)Persistent

Contact & Data Protection Officer

For any privacy-related questions, data requests, or complaints, contact our Data Protection Officer:

Response time
Within 30 calendar days
Postal address
BytesWave LLC, Abu Dhabi, UAE