Privacy policy
Draft v1.0 — under review. The Arabic text governs; this English text is for convenience only.
English convenience translation
This English text is an unofficial convenience translation. The Arabic text in Part One is the sole governing text. In the event of any discrepancy or conflict in meaning between the two, the Arabic text prevails.
Privacy Notice
This Notice explains the data collected by [●] Company W.L.L. (commercial licence no. [●]), as operator of the Coodooo platform, how it is used and retained, and how data subjects' rights are protected.
1 — Controller and Contact
| Field | Value | |---|---| | Responsible entity | [●] Company W.L.L. | | Commercial licence | No. [●] | | Address | [●], State of Kuwait | | Privacy email | [●] | | Telephone / WhatsApp | [●] | | Response time | Fifteen (15) business days |
2 — Applicable Regulatory Framework
2.1 The Company complies with Chapter Seven of Law No. 20 of 2014 on Electronic Transactions — the binding framework requiring the data subject's consent before collecting, processing or disclosing personal data, and imposing liability for unauthorised disclosure.
2.2 The Company also complies with Decree-Law No. 10 of 2026 Regulating Work in the Digital Commerce Sector, in particular Article 23 on record retention and Articles 15 and 32 on security measures, and with Law No. 63 of 2015 on Cybercrime.
2.3 As to the Data Privacy Protection Regulation issued by the Communication and Information Technology Regulatory Authority (CITRA) by Administrative Decision No. 26 of 2024: its scope is confined to entities licensed by CITRA in the telecommunications sector. The Company is not a CITRA licensee, and the Regulation therefore does not apply to it as a matter of law. Nevertheless the Company voluntarily follows its data-minimisation, purpose-limitation and retention-limitation principles as best practice, without that voluntary adherence creating any submission to CITRA's jurisdiction.
⚠️ Reviewer note (Q-127)
2.4 As at the date of this Notice there is no general, unified personal data protection law in the State of Kuwait.
3 — Data We Collect
3.1 — From the Merchant
| Category | Data | |---|---| | Entity data | Trade name, commercial licence number and expiry, commercial register number, digital-commerce register entry number, activity, governorate, website or online account | | Authorised persons | Name, capacity, telephone, email (encrypted) | | Verification documents | Copies of licence, register and register-entry documents | | Operational data | Program settings, active codes, reported order data (order reference, amount, code, delivery status) | | Payment data | Tokenised card identifier held with a licensed payment services provider, and invoice references — we hold no full card data | | Records | Agreement version and hash, acceptance time, IP address, OTP reference |
3.2 — From the Marketer
| Category | Data | |---|---| | Identity | Name, marketer type, account handle, Civil ID (encrypted, with a hash for lookup) and expiry | | Eligibility | Registration or licence number, expiry and document; declared residency status; public-sector declaration | | Contact | Telephone and email (encrypted, with a hash for lookup) | | Payment | IBAN (encrypted, with last four digits displayed), bank name, account name-match status | | Performance | Attributed Conversions, commissions, Statements, payments, objections | | Records | Agreement version and hash, acceptance time, IP address, OTP reference |
3.3 — From the Merchant's End Customers — the minimum
| Category | What we collect | What we do not collect | |---|---|---| | Clicks | A hashed IP value using a periodically rotated key; approximate country and network operator; browser and OS family; bot and duplicate indicators; timestamp | We do not collect name, email, telephone, plain IP address, persistent device identifier or precise location | | Conversions | Order reference, amount, code used, delivery status, order date | We do not collect the buyer's name, telephone, address, basket contents or payment method | | Leads (Offer Pages) | Name and telephone, encrypted, plus code and Program references | Nothing further |
Absolute rules:
- We do not create, buy, sell or make available any customer lists of Merchants.
- We pass no Merchant customer data to any Marketer, in any case.
- Lead data (name and telephone) is erased within thirty (30) days of handover to the Merchant, retaining only an irreversible hash for de-duplication.
- We use no third-party advertising tracking cookies; only a first-party attribution identifier.
4 — Purposes and Basis
| Purpose | Data | Basis | |---|---|---| | Account creation and identity verification | Identity, contact | Contract performance + consent | | Eligibility verification (registration/licence, residency, public sector) | Eligibility documents | Regulatory obligation (Article 3 of Decree-Law 10/2026) + consent | | Issuing Codes and Links and operating attribution | Click and Conversion data | Contract performance + consent | | Calculating commissions, issuing Statements and Invoices, payment | Performance, payment | Contract performance | | AML and beneficiary verification | Identity, bank account | Regulatory obligation (Law 106/2013) | | Fraud and code-leak prevention | Technical indicators, conversion patterns | Legitimate interest in protecting the contracting parties | | Retaining compliance records and exporting them to the Merchant | Agreements, terms, Conversions, Statements | Regulatory obligation (Article 23 of Decree-Law 10/2026) | | Service messages | Contact | Contract performance | | Marketing messages | Contact | Express, separate consent only | | Platform improvement and performance measurement | Aggregated, non-identifying data | Legitimate interest |
5 — Consent and Its Withdrawal
5.1 Consent is taken expressly on registration by clicking the acceptance button coupled with the one-time code, and is recorded with the version number, time and IP address.
5.2 Marketing consent is separate from acceptance of the Terms of Use and is not a condition of receiving the service.
5.3 Consent may be withdrawn at any time through the dashboard or by written request to the privacy email, effective within seven (7) business days for marketing messages.
5.4 Withdrawal does not extend to data that must be retained under a regulatory obligation (Article 23 records), nor to prior processing that was lawful when carried out.
5.5 Visitor consent for the tracking tag on the Merchant's properties is the Merchant's responsibility; it shall subject the tag to its own consent mechanism.
6 — Retention Schedule
| Data category | Retention | Basis | |---|---|---| | Agreements (version, hash, acceptance time, IP, OTP reference) | 10 years | Internal policy exceeding the statutory minimum | | Program Terms and their versions | 10 years | Internal policy | | Code and Link allocations | 10 years | Internal policy | | Conversions, adjustments, Statements and payments | 10 years | Internal policy / accounting requirements | | Statutory minimum for all of the above | 5 years | Article 23 of Decree-Law 10/2026 | | Identity and eligibility verification documents | 5 years from end of the relationship | Law 106/2013 and Article 23 | | Click records (hashed, no personal data) | 90 days, then aggregated statistically | Data minimisation | | Lead data (name and telephone) | 30 days from handover, then erased | Data minimisation — only a hash is retained | | One-time codes (OTP) | 24 hours for the value; the use reference is kept with the agreement record | Security | | System and audit logs | 5 years | Security and accountability | | Marketing data after withdrawal of consent | Deleted within 7 business days, save the withdrawal record itself | Proof of compliance |
7 — Disclosure and Sharing
7.1 We share data to the narrowest extent and for a specified purpose only, with:
| Recipient | What is shared | Purpose | |---|---|---| | The Merchant | Data of Marketers enrolled in its Program, their participation and Conversion records, and accepted Program Terms | Enabling the Merchant to discharge its retention duty under Article 23 | | The Marketer | Only its own Conversions, commissions and Statements | Contract performance — no Merchant customer data whatsoever | | Payment services providers licensed by the Central Bank of Kuwait | Payment and transfer data required | Collection and payment | | Hosting and infrastructure providers | Encrypted stored data, under confidentiality and processing terms | Service operation | | Identity verification providers (where enabled) | Identity documents | Verification | | Competent authorities | What is required by law or judicial order | Regulatory obligation |
7.2 We do not sell, rent or make personal data available for third-party advertising purposes.
8 — Hosting Location and Data Transfer
8.1 Platform data is hosted on servers with [●] in [●], and backups may be processed in [●].
8.2 As at the date of this Notice there is no confirmed Kuwaiti statutory provision imposing data localisation on the Company's activity. The Company nevertheless discloses hosting locations and requests express consent to transfer.
⚠️ Reviewer note (Q-127)
8.3 By accepting the Platform Terms of Use the User expressly consents to the transfer of its data to, and its processing in, the locations stated above, subject to: encryption in transit and at rest; contractual confidentiality, purpose limitation and a prohibition on secondary processing by the provider; and the Company's right to retrieve and delete the data.
8.4 The Company notifies Users of any material change in hosting location fourteen (14) days before it takes effect.
9 — Security Measures
9.1 Encryption at rest of sensitive data (Civil ID, IBAN, telephone, email), with hashes used only for lookup. 9.2 Full transport encryption (TLS), least-privilege access control, and two-step verification for administrative accounts. 9.3 Periodic rotation of the IP-hashing key so as to prevent long-term linkage. 9.4 An immutable audit log of every sensitive administrative operation. 9.5 On a security incident affecting personal data: containment, impact assessment, and notification of affected persons and the competent authorities without undue delay as the law requires.
⚠️ Reviewer note (Q-127)
10 — Data Subject Rights
Every User is entitled to:
10.1 Access its retained data and request a copy. 10.2 Rectification of any inaccurate or outdated data. 10.3 Withdrawal of consent for consent-based processing, in particular marketing messages. 10.4 Objection to processing it considers to exceed the stated purpose. 10.5 Erasure of data for which no regulatory or contractual retention basis exists. This does not extend to records required to be retained under Article 23 of Decree-Law 10/2026 or the AML law, for their statutory periods. 10.6 Export of its records in machine-readable form. 10.7 Complaint — to the privacy email in clause 1; the Company responds within fifteen (15) business days. This does not prejudice recourse to the competent authorities, to the dispute committee under Articles 36 to 38 of Decree-Law 10/2026, or to the courts of the State of Kuwait.
11 — Children
The Platform is not directed to persons under eighteen, and their participation as Marketers is not accepted. Minor's data discovered is deleted immediately.
12 — Amendment and Language
12.1 This document is amended on fourteen (14) days' prior notice, effective prospectively only.
12.2 Language: this Notice is made in Arabic; an English translation may be made available for convenience only. In the event of any difference or conflict in meaning between the two texts, the Arabic text alone prevails and is the governing text.
End of document 05 — v1.0-draft — 2026-08-23