Legal
Privacy Policy
Privacy Policy
Counsel review pending. Structural skeleton; final wording before public launch (Spec §1.4).
1. Who we are
Deena is a SaaS for halal butcher shops, run by DEENA_LEGAL_TODO (operator legal entity). For data-processing matters please contact hello@deena.pro.
2. What data we process
From shop owners and staff
- Email address, name, password (stored hashed)
- Shop name, address, opening hours, languages
- Stripe customer + subscription identifiers
- WhatsApp Business Account ID (after Meta-Embedded-Signup)
- Server logs (IP, user-agent, request path) — minimised, no PII bodies
From customers messaging a connected shop
- Phone number
- Message text (and voice transcripts, post-launch)
- Media attached to a message
- Order metadata derived from the conversation
3. Why we process it
- Service operation — fulfil the contract with the shop (legal basis: GDPR Art. 6 (1) (b))
- Security & abuse prevention — rate-limiting, audit logs (Art. 6 (1) (f))
- Billing — Stripe Tax / EU OSS compliance (Art. 6 (1) (c))
4. Where the data lives
All personal data is processed in the EU:
- Application + database: AWS Lightsail Frankfurt (
eu-central-1) - Object storage: AWS S3 (
eu-central-1) - Email transport: Resend EU region
- AI inference: OpenAI EU data residency, Zero Data Retention
The full sub-processor list is at /legal/sub-processors.
5. Retention
DEENA_LEGAL_TODO: per-category retention table — typically 30/60-day data-erasure ladder for cancelled tenants (see plan/cross-cutting/billing-stripe.md §7).
6. Your rights
Under GDPR (Art. 15–22) you may request:
- Access to your personal data
- Rectification of inaccurate data
- Erasure ("right to be forgotten")
- Portability of data you provided
Send requests to hello@deena.pro. We respond within 30 days. You may also lodge a complaint with the supervisory authority in your jurisdiction.
7. Cookies
We set only strictly-necessary cookies. Detail at /legal/cookies.
8. Updates
DEENA_LEGAL_TODO: how we notify of changes (in-app banner + email at version bump per plan/modules/08-legal-static.md §1.2).