Privacy Policy

We explain here how your data is collected, used and protected when you use Dawrk AI services.

Last updated: August 2026

1. Scope of this policy

This policy applies to the processing of personal data carried out through the Dawrk AI website, its linked applications, customer and business accounts and their staff, bookings, queues, appointments and orders, support and communication systems, and any other services or sectors operating through the Dawrk AI technical infrastructure.

The nature of data processed may vary depending on the type of user, sector or service used.

2. Data controller

Dawnk Powered bgAi LLC is the data controller when it determines the purposes and means of processing personal data.

For certain services provided by independent businesses through the platform, the business itself may be an independent controller for some data relating to its customers or staff, while Dawrk processes that data according to the technical and contractual role defined for each service.

This policy is not intended to transfer controller or processor responsibilities from one party to another in a manner contrary to the actual role of each or to what the law prescribes.

3. Personal data we may process

Depending on the service used, personal data may include: account and identity data such as name, phone number, email, login details, language and preferences; business data such as business name, sector, commercial registration, branches, contact details, authorized persons and documents; customer and service data such as bookings, appointments, queues, orders, visit records and preferences; staff and authorized-user data such as role, branch, permissions and activity; technical and usage data such as device and browser type, session information and security logs; support and communication data such as messages and attachments; and subscription and payment data such as plan, payment status and invoices.

Actual payment data may be processed by an independent payment provider according to the service used. Dawrk does not retain complete card details unless the technical and legal structure of the service expressly permits it.

4. Sensitive data

Some sectors or services may allow processing of data types that the law regards as special or sensitive. Where the law requires prior authorization, special consent or additional measures, processing does not take place until the applicable legal and regulatory requirements are met.

Making a technical feature available in the platform is not in itself authorization for a business or user to process data that is legally prohibited.

5. Data sources

We may obtain personal data directly from the data subject, from the business whose services the person uses, from an employee or authorized user of the business, from a guardian or legal representative where applicable, from systems or services integrated with the platform, or from data generated technically through platform use.

Data is handled according to the purpose for which it was collected and the relevant legal requirements.

6. Purposes of processing

Personal data may be processed for purposes including: creating and managing accounts; verifying identity or capacity; operating the platform and providing requested services; managing bookings, queues, appointments and orders; managing businesses, branches, users and permissions; fulfilling subscriptions and paid services; sending operational notifications; responding to inquiries and providing technical support; protecting accounts and the platform from fraud; monitoring faults and improving performance; developing features; complying with legal obligations; and proving operations or defending legal rights.

Data is not processed for purposes incompatible with the stated purpose except as permitted by law.

7. Legal basis and consent

Where the law requires the data subject's consent, consent is obtained in a clear, explicit and provable manner. The law may also allow processing without separate consent in certain cases, such as performing a contract, complying with a legal obligation, protecting a vital interest or other cases prescribed by law.

Consent is not regarded as a waiver of any legally granted right. The data subject may withdraw consent whenever it is the basis of processing, without affecting the lawfulness of processing carried out before withdrawal.

8. Data minimisation

Dawrk aims to limit personal data processing to what is necessary and proportionate to the stated purpose. Businesses and their users should not enter personal data that the service does not require, or upload data that exceeds the purpose of the field or feature used.

9. Data accuracy

Users undertake to provide accurate data as far as possible. Data may be updated or corrected through the functions available in the account, or by submitting a request to the relevant contact under this policy.

10. Data sharing and disclosure

Dawrk does not sell personal data. The minimum necessary data may be shared with other parties when this is necessary to operate the service or to comply with a legal obligation.

These parties may include hosting and cloud infrastructure providers, messaging and communication providers, email providers, payment service providers, technical or security service providers, map providers, technical analytics or fault-monitoring providers, professional advisers when there is a legitimate need, and judicial, regulatory or government authorities when disclosure is required by law.

Sharing is limited to the scope necessary for the relevant purpose and complies with applicable legal and contractual obligations.

11. Businesses and their customer data

When an independent business uses the Dawrk platform to manage its customers, staff or services, the business is responsible for ensuring the lawfulness of the data it enters into the system and the permissions it grants its users. The business must obtain any legally required consents or authorisations before entering or sharing data with the platform.

Dawrk may not be used to store or process data obtained unlawfully.

12. Cross-border data transfers

The Dawrk AI platform uses cloud service providers whose infrastructure is located outside the Sultanate of Oman, and some personal data may be processed or hosted with them. A list of provider categories and processing locations is made available to data subjects on request through the privacy channel.

Where the Personal Data Protection Law applies, personal data is transferred outside the Sultanate in accordance with the legal controls prescribed, including obtaining explicit consent when required, verifying that the external processor provides an adequate level of protection, and conducting the necessary transfer-risk assessments. Data is not transferred if the transfer is prohibited by law or would result in harm contrary to the law.

13. Information security

Dawrk implements appropriate technical and organisational measures to protect personal data, taking into account the nature of the data, the type of processing and the associated risks. These measures may include access-control, authentication and identity verification, protection of communications and data transfers, security event logging, database and system protection, backup and recovery, restricting employee and user access, reviewing and testing the effectiveness of security measures, and handling security incidents according to defined procedures.

However, no user should share login credentials or verification codes, or enable an unauthorised person to use their account.

14. Personal data breaches

When a personal data breach occurs, Dawrk assesses the nature, severity and potential impact of the breach and takes the necessary technical and organisational measures to contain and address it. Where the law requires reporting, the competent authority is notified within the statutory period.

When a breach is likely to result in serious harm or high risk to data subjects, they are notified in accordance with the requirements and timeframes set by the law and its implementing regulations.

15. Data retention

Dawrk does not keep personal data longer than is necessary for the legitimate purposes for which it was collected or processed. Retention periods are determined according to the nature of the data, the purpose of processing, the duration of the contractual relationship, legal, accounting or regulatory obligations, the legitimate need to prove operations or defend rights, and any pending dispute, investigation or legal claim.

Once the legitimate need for retention ends, data is deleted, anonymised or handled in accordance with approved legal and technical procedures.

16. Account closure and deletion

You can request account deletion from inside the app via Settings → Profile → Delete account, or review the public steps at /delete-account.

Closing an account does not necessarily mean immediate deletion of all related records. Some information may be retained if necessary to comply with a legal obligation, document operations, settle financial obligations, handle a pending dispute or protect legal rights. Data for which there is no longer a legitimate need is deleted or anonymised.

17. Rights of data subjects

Under the Personal Data Protection Law and its implementing regulations, data subjects may, as applicable, exercise their legal rights, including: withdrawing consent where processing is based on consent; requesting correction or updating of data; requesting blocking of data in prescribed cases; obtaining a copy of personal data being processed; requesting transfer of data to another controller in accordance with legal conditions; requesting erasure of data in cases prescribed by law; requesting suspension of processing pending review of certain requests; receiving notification of data breaches where the law requires it; and submitting a complaint to the competent authority.

These rights may not be exercised in a way that harms the rights of others or violates a mandatory legal obligation.

18. Requests to exercise rights

Data subjects may submit a written request to exercise their rights through the privacy contact channel or the official channels designated by Dawrk. The company may request reasonable information to verify the requester's identity and protect data from disclosure to an unauthorised person.

Requests are handled within the period prescribed by law. A request may be refused in whole or in part in cases permitted by law, with the reason for refusal stated in accordance with legal requirements.

19. Data protection officer

Dawnk Powered bgAi LLC appoints a data protection officer in accordance with legal requirements. The data protection officer is the contact point for data protection matters and for monitoring the company's compliance with relevant policies and regulatory requirements.

Name: Data Protection Officer — Dawnk Powered bgAi LLC Email: [email protected] Contact method: WhatsApp: 96890140680

20. Marketing and commercial messages

Dawrk does not send advertising, marketing or commercial materials to data subjects where the law requires prior consent, except after obtaining the necessary consent. When marketing materials are sent, a clear and free opt-out mechanism is provided.

Opting out of marketing messages is not a cancellation of the operational notifications necessary for the account, security or the service requested by the user.

21. Operational notifications

The platform may send notifications necessary to operate the service, such as verification codes, security alerts, account updates, booking or appointment status, important operational changes, subscription or payment notices, and messages related to a support request submitted by the user. The ability to turn off these notifications varies depending on their nature and purpose.

22. Cookies and similar technologies

The platform may use cookies, storage mechanisms and similar technologies for purposes necessary to operate the service, such as session management, login protection, saving language or preferences, enabling site features, and measuring performance and faults. Non-essential analytics technologies are used only in accordance with applicable settings and consent where required by law.

Users can control some of these technologies through browser settings or consent tools available on the platform. Disabling essential technologies may cause some site features to malfunction.

23. Children's data

The Dawrk platform is not generally directed at children to create independent accounts unless a service is designed for that purpose and implemented in accordance with legal requirements. Some platform sectors, such as education, may process data about students or children managed by the educational institution, guardian or legally authorised person.

Where data is considered a child's personal data under the law, it is handled in accordance with the special requirements for protecting children's data, including guardian consent when required. Processing must be specific, clear and limited to the minimum necessary for its purpose. A child's data may not be disclosed or shared in violation of legal requirements.

24. Third-party services and sites

The platform may contain links or integrations leading to services or sites operated by independent third parties. The privacy policies of those parties apply to processing they carry out independently. The presence of a link or integration does not mean that Dawrk assumes responsibility for that party's independent practices beyond what is determined by law or contract.

25. Automated decisions and artificial intelligence

Some Dawrk features may use automated technologies or artificial intelligence to facilitate operations, analyse information or assist users. When these technologies are used to process personal data, the processing is subject to this policy and applicable legal controls.

Automated features may not be used to circumvent the legal rights of data subjects or to make decisions with significant legal effect contrary to the law.

26. Data confidentiality within a business

Each business determines the permissions of its employees and users within its account. The business owner or authorised manager is responsible for granting permissions to the right people and revoking them when no longer needed. Dawrk provides technical access-control tools according to what each service offers, but the business remains responsible for improper permission granting on its part unless the cause is a fault on Dawrk's side.

27. Security and activity logs

Dawrk may keep technical and security logs related to system use when necessary to protect accounts, investigate suspicious activity, track faults, prove operations, comply with legal requirements, or protect the rights of the company or users. Access to these logs is restricted to authorised persons or systems.

28. Changes to this privacy policy

This policy may be updated as a result of changes to services, the addition of new features, changes to processing methods, changes to legal or regulatory requirements, or developments in security and privacy procedures. The current version is published with its last updated date.

When a material change affects the nature of data processing or users' rights, Dawrk adopts an appropriate notification method where required by law or warranted by the nature of the change.

29. Complaints

If a data subject believes that their data is being processed in violation of the law or this policy, they may first contact Dawrk or the data protection officer to discuss the matter. This does not affect their right to file a complaint with the Ministry of Transport, Communications and Information Technology or the competent authority in accordance with the procedures and deadlines prescribed by law.

30. Primacy of law

If any provision of this policy conflicts with a mandatory rule of Omani law, the legal rule applies to the extent of the conflict. No provision of this policy may be interpreted as a waiver by the data subject of a right that cannot be waived by law. This policy may also not be interpreted as an absolute guarantee against any technical incident; rather, the company undertakes to take the measures imposed by law and proportionate to the nature and risks of processing.

31. Contact us about privacy

For inquiries related to privacy or requests to exercise data-subject rights, you can contact us through the Support & Contact page on the Dawrk AI platform or through the data protection officer details published in this policy.

Dawnk Powered bgAi LLC · سلطنة عُمان · Commercial Registration No.: 1669482