Privacy notice
Last updated 2026-09-17. This notice explains what data Emivra MENA processes on behalf of account owners, why, how long it is kept and how you control it.
Controller and contact
Controller: [Registered company name] · Privacy contact: [privacy@yourdomain]
These placeholders must be replaced with the operating entity's legal name and a monitored privacy mailbox before this notice is published.
1. Data we process
- Account data: name, work email address and encrypted authentication credentials.
- Company data: company name, industry, operating location or free zone, employee range and selected operations.
- Activity data: monthly consumption and transport figures you enter (kWh, litres, kilometres, tonne-kilometres), the unit, notes and category qualifiers such as fuel type or carrier arrangement.
- Calculation data: the emission factor identifier, factor version and the resulting emissions figure.
- Evidence files: documents you optionally attach to an activity entry, such as utility bills or fuel receipts.
- Change records: which account made or changed an entry and when, kept as an audit trail.
We do not ask for, and you should not upload, special-category personal data, identity documents, payroll data or customer personal data. Evidence files should be redacted of personal details before upload.
2. Why we process it
- To operate the account and authenticate the user (performance of a contract).
- To calculate a corporate greenhouse-gas inventory from your activity data (performance of a contract).
- To maintain an audit trail of who changed what, so figures can be verified (legitimate interest in data integrity).
- To keep the service secure and prevent misuse (legitimate interest in security).
We do not sell data, do not use it for advertising, and do not use it to train models.
3. Data minimisation
Only the fields required to calculate and evidence an emissions figure are collected. Optional fields (facility name, notes, evidence) can be left empty, and evidence attachments are never mandatory.
4. Retention
- Activity records, calculation details and audit entries: retained for five reporting years, so a finalised inventory can still be traced back to its inputs. Article 6(1)(c) of UAE Federal Decree-Law No. 11 of 2024 specifies five-year retention of measured-emissions records for sources determined to be within its scope; whether your organisation is subject to that obligation is not assessed by Emivra and requires review.
- Finalised report snapshots: immutable for the same retention period; they cannot be edited after creation.
- Evidence files: retained alongside the record they support and removed with it.
- Account data: retained while the account is active.
Deleting your account removes all of the above ahead of those periods.
5. Your rights and how to use them
- Access and portability: download a complete machine-readable copy of your company profile, activity records, targets, reports and audit trail from Privacy & data inside the app.
- Correction: edit or delete any individual activity entry in the Data Hub; the change is logged and totals recalculate immediately.
- Erasure: delete your account and all associated company data from Privacy & data. This action is immediate and cannot be undone.
- Objection or complaint: contact the privacy mailbox above; you may also complain to your competent data-protection authority.
6. Processors and transfers
The application uses a managed cloud database, authentication service and file storage to host the data described above. No other recipients receive your data. Where hosting is located outside your country, the transfer relies on the hosting provider's contractual safeguards. The current hosting region and provider details are available from the privacy contact on request.
7. Security measures
- Access is scoped per account at the database level, so one company's records cannot be read by another.
- Passwords are stored hashed by the authentication service and never handled in plain text by the application.
- Evidence storage is private; files are reachable only through short-lived links issued to the owning account.
- Report snapshots and audit entries are append-only and cannot be silently altered.
- Server-side credentials are held as encrypted environment secrets and never shipped to the browser.
No system can be guaranteed secure. These are the controls in place, not a warranty against all compromise.
8. Cookies and tracking
Emivra sets only the storage needed to keep you signed in. There is no advertising, profiling or third-party analytics tracking, so no cookie consent banner is required.
This notice describes the product's data handling. It is not legal advice, and it does not by itself establish compliance with any specific regulation — the operating entity should have it reviewed by qualified counsel and complete the placeholders above.