Privacy Policy
Last updated: 14/09/2026
This Privacy Policy explains how RAIMS Digital Technologies SP LLC ("we", "us", "our") collects,
uses, shares, stores and protects personal data in connection with Risper CRM - TAX,
our website at rispercrm.tax, our marketing, and the messages we exchange
with you by email, phone or WhatsApp.
It is written to meet Federal Decree-Law No. 45 of 2021 on the Protection of Personal
Data ("UAE PDPL") and its executive regulations, and to be understood by the people it
is about.
1. Two different roles — and why it matters to you
We handle personal data in two distinct capacities, and your rights differ between them:
- As controller — for data about our own visitors, enquirers, trial users,
account owners and the staff of our customers who log in. We decide why and how that data is
used, and this Policy governs it.
- As processor — for the data our customers put into their own accounts about
their clients, employees, leads and suppliers. We process it only on our customer's documented
instructions, under our
Data Processing Agreement. If you are a client or
employee of one of our customers, that customer is the controller of your data: contact them
first, and we will support them in answering you.
2. What we collect
- Account and identity data — name, business name, job title, email address,
telephone or WhatsApp number, country, and where required for invoicing, trade licence and tax
registration details.
- Billing data — plan and add-ons purchased, invoices, receipts, the last four
digits and brand of a card, and the payment reference. We do not store full card
numbers or CVV codes; those go directly to our payment provider.
- Usage and technical data — IP address, device and browser type, pages
viewed, features used, timestamps, and diagnostic logs and error reports.
- Support and communications data — the messages, tickets, calls and emails
you exchange with us, and the notes we keep about them.
- Content data — the records, documents and files you upload into your account.
We hold this as processor, on your instructions.
- Marketing data — where you have enquired or subscribed, your contact
preferences and whether you opened or clicked our messages.
We do not deliberately collect special-category data (health, biometric, religious or similar)
about you as a visitor or account owner. If your own use of the Service involves such data about
your staff or clients, you are its controller and must have a lawful basis for it.
3. Why we use it, and on what basis
- To provide the Service — create and run your account, authenticate logins,
store your data, send service messages. Basis: performance of our contract with you.
- To bill you — take payments, issue tax invoices, chase failed payments,
keep accounting records. Basis: contract, and our legal obligations under UAE tax law.
- To support you — answer questions, investigate faults, restore data.
Basis: contract and our legitimate interest in running a supportable service.
- To keep the platform safe — detect abuse, fraud and intrusion, apply rate
limits, keep audit logs. Basis: our legitimate interest in security, and legal obligation.
- To improve the Service — understand which features are used, diagnose
performance, plan changes. We use aggregated and de-identified data for this wherever it will
do. Basis: legitimate interest.
- To market to you — send you offers and product news. Basis: your consent, or
our legitimate interest where you are an existing business customer. Every marketing message
carries an unsubscribe, and unsubscribing never affects service messages.
- To comply with the law — respond to a lawful request from a competent UAE
authority, keep records we are required to keep, and enforce our terms.
Where we rely on your consent, you can withdraw it at any time; that does not affect
processing already carried out.
4. Automated decisions and AI features
We do not make decisions producing legal effects about you by purely automated means. The
Service includes AI assistants that draft text, summarise records and answer questions. What
they produce is a suggestion for a person to review, never a decision. How those features handle
data is set out in our AI Features Disclaimer.
5. Who we share it with
We do not sell personal data. We share it only with:
- Sub-processors who run parts of the Service for us — hosting and
infrastructure, email delivery, messaging delivery, payment processing, error monitoring and,
where you enable them, AI providers. The current list, and what each one does, is published in
our Data Processing Agreement. Each is bound by
written terms no less protective than this Policy.
- Providers you connect yourself — an accounting platform, a messaging number,
a payment gateway or a government portal that you switch on. That transfer happens at your
instruction and under their privacy policy.
- Professional advisers — auditors, lawyers and insurers, under a duty of
confidence.
- Authorities — where a competent UAE authority makes a lawful request, or
where disclosure is necessary to establish or defend a legal claim.
- A buyer — if our business or part of it is sold or reorganised, under
confidentiality and with the same protections continuing.
6. Where the data is held, and transfers out of the UAE
We host the Service on infrastructure selected for its security and reliability. Some
sub-processors operate outside the UAE. Where personal data is transferred out of the UAE, we do
so only where the destination is recognised as providing an adequate level of protection, or
under appropriate safeguards such as contractual clauses obliging the recipient to protect the
data to the standard required by the UAE PDPL, or with your explicit consent, as permitted by
Articles 22 and 23 of the PDPL. Details of a specific transfer are available on request.
7. How long we keep it
- Account and content data — for as long as the account is active, and then
for the windows set out in our
Data Deletion & Retention Policy.
- Invoices and accounting records — for the period UAE tax law requires, which
is currently at least five years from the end of the relevant tax period, and longer for records
relating to real estate.
- Security and audit logs — typically twelve months.
- Marketing data — until you unsubscribe, and then a minimal suppression
record so that we do not contact you again.
8. How we protect it
- Encryption in transit (HTTPS/TLS) for every page and API call.
- Each customer's data is held in its own separated tenancy, and every request is scoped to the
account and company that owns it.
- Role-based permissions, so a user sees only what their role allows.
- Passwords stored only as salted one-way hashes; secrets held outside the application code.
- Activity logging on business records — who changed what, when, and from where.
- Regular backups, access restricted to staff who need it, and least-privilege administration.
No system is perfectly secure. If a personal data breach occurs that is likely to prejudice
the privacy, security or confidentiality of personal data, we will notify the UAE Data Office
and affected controllers or individuals as required by Article 9 of the PDPL, without undue
delay.
9. Your rights
Subject to the conditions and exceptions in the UAE PDPL, you have the right to:
- be informed how your data is processed, and to obtain a copy of it;
- request a portable copy in a structured, machine-readable format;
- have inaccurate or incomplete data corrected;
- request erasure of your data;
- restrict or object to certain processing, including profiling and direct marketing;
- withdraw a consent you have given;
- complain to the UAE Data Office if you believe your data has been mishandled.
To exercise any of these, write to
privacy@rispercrm.tax. We will verify your identity and
respond within the period required by law. There is no charge unless a request is manifestly
unfounded or excessive. If your data sits inside a customer's account, we will pass your request
to that customer, who is its controller.
10. Children
The Service is a business tool and is not directed at children. We do not knowingly collect
personal data from anyone under 18. If you believe a child's data has reached us, tell us and we
will delete it.
11. Cookies
Our use of cookies and similar technologies is described in our
Cookie Policy.
12. Changes to this Policy
We may update this Policy. The current version is always at
https://rispercrm.tax/privacy with its last-updated date, and we will give notice of
a material change by email or inside the Service.
13. How to contact us
For any privacy question, or to exercise a right:
RAIMS Digital Technologies SP LLC
Email: privacy@rispercrm.tax