Daira home
Solutions
Industries
Insights
Pricing
About
Contact
Client PortalBook a Demo

Privacy Policy

Data collection, processing and protection, including our Data Processing Terms.

Version
2.1
Effective date
15 September 2026

Flow Metrics Accounting and Bookkeeping L.L.C. (“Daira,” “we,” “us,” or “our”) is committed to protecting the privacy and security of data processed through our technology platform (the “Platform”) and in the course of providing our accounting, bookkeeping, tax compliance, and related professional services (the “Professional Services”). This Privacy Policy explains how we collect, use, store, share, and protect information when you use the Platform or engage the Professional Services, including data obtained from your enterprise resource planning (“ERP”) systems and accounting software and documents you provide to us directly.

This Privacy Policy applies to all users of the Platform and all clients of the Professional Services worldwide, including business administrators, authorised users, and any individual whose personal data may be processed by Daira. By using the Platform or engaging the Professional Services, you consent to the practices described in this Privacy Policy.

This Privacy Policy incorporates our Data Processing Terms (Section 13) which apply when Daira processes data on behalf of its Customers.

1. Data Controller and Processor Roles

1.1 Roles

When Daira processes Customer Data through the Platform or in the course of providing the Professional Services on behalf of its Customers, Daira acts as a data processor (or “service provider” under applicable US state privacy laws). The Customer acts as the data controller (or “business”) and determines the purposes and means of processing Customer Data.

Daira acts as a data controller in respect of User Account Data (login credentials and usage logs) collected for the purpose of providing access to and securing the Platform.

1.2 Contact Information

For matters relating to data privacy, you may contact us at:

  • Email: contact@daira.me
  • Address: Office 411, Downtown Dubai Mall – Level M, Fountain Views, Dubai, UAE

2. Data We Collect

2.1 Financial Transaction Data

When you connect your ERP system (such as Zoho Books, Odoo, QuickBooks, Xero, or other supported platforms) to the Daira Platform via API integration, or when you provide financial records to us directly in the course of the Professional Services, we access and process the following categories of financial data:

  • Chart of accounts, account balances, and general ledger entries
  • Accounts receivable and accounts payable records, including invoice details, payment terms, and aging schedules
  • Bank transaction records, including deposits, withdrawals, transfers, and reconciliation data
  • Revenue and expense transactions, categorised by account type, department, or cost centre
  • Cash flow records, including opening and closing balances
  • Tax-related data, including VAT records, tax filing information, and compliance data
  • Payroll summary data (aggregate figures only; individual employee salary data is not collected unless expressly authorised)
  • Fixed asset registers and depreciation schedules

Important: Through the Platform, Daira processes aggregated financial numbers only. We do not store audited financial statements, personal data of directors, signatories, beneficial owners, or any personal identification information beyond the User Account Data described in Section 2.3, and we do not store ERP credentials; all ERP connections are made via API integrations using token-based authentication. In the course of the Professional Services, we may additionally receive and store supporting documents that you provide to us directly (such as bank statements, invoices, supplier bills, payroll information, and tax registration details) which are handled under the same security, confidentiality, and retention standards described in this Privacy Policy.

2.2 Business Profile Data

  • Company name, trade licence number, and registration details
  • Industry classification and business type
  • Contact information for authorised business representatives
  • Banking institution details (bank name and branch; not account numbers or credentials)

2.3 User Account Data

This is the only category of personal data that Daira stores:

  • Name and email address of authorised users
  • Role and access level within the Platform
  • Login credentials (stored in encrypted form; passwords are hashed and never stored in plaintext)
  • Usage logs, including login times, features accessed, and actions performed within the Platform

3. How We Record and Store Data

3.1 Data Synchronisation

The Platform connects to your ERP system via secure API integrations using OAuth or token-based authentication. Daira does not store your ERP login credentials at any time. Data is synchronised at regular intervals as configured by the Customer (e.g., daily, weekly, or in real-time where supported). Each synchronisation event is logged with a timestamp, data volume summary, and synchronisation status for audit trail purposes. Where enabled, the Platform also creates and updates records in your ERP system (such as transaction classifications, journal entries, and reconciliations) as part of the services, including through automated and AI-powered processing. All write operations are logged.

3.2 Data Storage

All Customer Data is stored on secure cloud infrastructure hosted in the United Arab Emirates, unless otherwise agreed with the Customer in writing. Data is encrypted both at rest (using AES-256 encryption) and in transit (using TLS 1.2 or higher). Access to stored data is controlled through role-based access controls.

3.3 Data Retention

Customer Data is retained for the duration of the Customer’s subscription or engagement and for a period of one hundred and eighty (180) days following termination, after which it is permanently deleted unless:

  • The Customer requests earlier deletion;
  • Retention is required by applicable law or regulation; or
  • The data has been anonymised and aggregated in a manner that does not identify the Customer.

4. How We Use Your Data

4.1 Primary Purposes

  • To provide the accounting, bookkeeping, tax compliance, and related Professional Services engaged by the Customer
  • To provide, maintain, and improve the Platform and its features
  • To generate financial health scores, cash flow forecasts, and analytical insights for the Customer
  • To produce reports, dashboards, and benchmarks requested by the Customer
  • To provide customer support and technical assistance
  • To ensure the security and integrity of the Platform

4.2 Aggregated and Anonymised Data

We may create Aggregated Data by combining and anonymising Customer Data such that no individual Customer or business can be identified. We use Aggregated Data for:

  • Developing and publishing industry benchmarks, trend reports, and research insights
  • Improving our algorithms, machine learning models, and analytical capabilities
  • Creating comparative analyses that help SMEs understand their performance relative to industry peers
  • Marketing and promotional purposes (in anonymised form only)

For the avoidance of doubt, Aggregated Data will never reveal the identity, specific financial figures, or proprietary business information of any individual Customer.

4.3 Communications

We may use your contact information to send transactional communications (such as service notifications, security alerts, and billing information) and, with your consent, marketing communications about Daira products and services. You may opt out of marketing communications at any time.

5. Data Sharing and Disclosure

We do not sell Customer Data or personal data to third parties. We may share data in the following limited circumstances:

  • Service Providers: We engage trusted third-party service providers who assist in operating the Platform (e.g., cloud hosting providers, analytics tools, customer support platforms). These providers are contractually bound to use Customer Data only for the purposes of providing services to Daira and are subject to confidentiality obligations no less protective than those in this Privacy Policy. A list of sub-processors is available upon request.
  • Legal Requirements: We may disclose data if required by law, regulation, legal process, or governmental request, including to comply with UAE Federal authorities, ADGM, DIFC, or other regulatory bodies in jurisdictions where we operate.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, Customer Data may be transferred to the successor entity, subject to the same privacy protections described herein.
  • With Customer Consent: We may share data with third parties where the Customer has provided explicit written consent.

6. Data Subject Rights

Depending on applicable data protection laws, individuals whose personal data is processed by Daira may have certain rights. The specific rights available depend on the jurisdiction of the data subject:

6.1 Universal Rights

  • The right to access personal data held about them
  • The right to request correction of inaccurate or incomplete personal data
  • The right to request deletion of personal data (subject to legal retention requirements)
  • The right to data portability

6.2 Additional Rights Under US State Privacy Laws

  • The right to opt out of the sale or sharing of personal data (note: Daira does not sell personal data)
  • The right to non-discrimination for exercising privacy rights

6.3 Additional Rights Under India’s DPDP Act

  • The right to nominate another individual to exercise rights in case of death or incapacity
  • The right to have access to information about processing in clear and plain language

To exercise any of these rights, please contact us at contact@daira.me. We will respond to verified requests within thirty (30) calendar days, or such shorter period as required by applicable law.

7. Security Measures

Daira implements and maintains comprehensive security measures designed to protect data, including:

  • Encryption of data at rest (AES-256) and in transit (TLS 1.2+)
  • Role-based access controls with principle of least privilege
  • Regular security audits and penetration testing
  • Employee security training and background checks
  • Secure software development lifecycle practices
  • Incident detection and response procedures
  • Automated monitoring and alerting for suspicious activity

8. International Data Transfers

Customer Data is primarily stored and processed within the United Arab Emirates. Daira serves Customers across multiple jurisdictions and ensures compliance with applicable cross-border data transfer requirements:

  • United States: Daira complies with applicable US state privacy laws and enters into Data Processing Agreements with US Customers as required.
  • India: Daira complies with the Digital Personal Data Protection Act, 2023 and applicable rules. As of the effective date of this Policy, the UAE is not on India’s restricted list for cross-border data transfers.
  • GCC Countries: Daira complies with applicable data protection laws in Bahrain, Saudi Arabia, Qatar, Oman, and Kuwait, including the respective personal data protection laws of each jurisdiction.

If any data is transferred to jurisdictions outside the UAE, Daira shall ensure that appropriate safeguards are in place in accordance with applicable data protection laws.

9. Cookies and Tracking Technologies

The Platform may use cookies, web beacons, and similar tracking technologies to enhance your experience, analyse usage patterns, and improve our services. You may manage your cookie preferences through your browser settings or through our cookie consent mechanism. Essential cookies required for the Platform to function may not be disabled.

10. Children’s Data

The Platform is not intended for use by individuals under the age of eighteen (18). We do not knowingly collect personal data from minors. If we become aware that we have collected personal data from a minor, we will take steps to delete such data promptly.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to Customers through the Platform or by email at least thirty (30) days before they take effect. The “Effective Date” at the top of this Privacy Policy indicates when it was last revised.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Flow Metrics Accounting and Bookkeeping L.L.C.

Email: contact@daira.me

Address: Office 411, Downtown Dubai Mall – Level M, Fountain Views, Dubai, UAE

13. Data Processing Terms

These Data Processing Terms (“DPT”) form part of this Privacy Policy and apply whenever Daira processes Customer Data on behalf of a Customer. These terms satisfy the requirements of a Data Processing Agreement under applicable data protection laws, including UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, US state privacy laws, and India’s DPDP Act.

13.1 Scope and Applicability

These DPT apply to all processing of Customer Data by Daira on behalf of the Customer. In the event of any conflict between these DPT and the main body of this Privacy Policy, these DPT shall prevail.

13.2 Processing Instructions

Daira shall process Customer Data only on documented instructions from the Customer, including with regard to transfers of personal data to a third country, unless required to do so by applicable law. Daira shall inform the Customer of any such legal requirement before processing, unless prohibited by law.

13.3 Confidentiality

Daira shall ensure that persons authorised to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

13.4 Security

Daira shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Section 7 of this Privacy Policy.

13.5 Sub-processors

Daira shall not engage another processor (sub-processor) without prior general or specific written authorisation of the Customer. Where general written authorisation has been given, Daira shall inform the Customer of any intended changes concerning the addition or replacement of sub-processors, giving the Customer the opportunity to object. A current list of sub-processors is available upon request.

13.6 Data Subject Rights

Taking into account the nature of the processing, Daira shall assist the Customer by appropriate technical and organisational measures, insofar as possible, for the fulfilment of the Customer’s obligation to respond to requests for exercising the data subject’s rights.

13.7 Assistance with Compliance

Daira shall assist the Customer in ensuring compliance with obligations relating to security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of processing and the information available to Daira.

13.8 Data Breach Notification

Daira shall notify the Customer without undue delay (and in any event within forty-eight (48) hours) after becoming aware of a personal data breach affecting Customer Data. Such notification shall include:

  • A description of the nature of the breach, including the categories and approximate number of data subjects and data records concerned;
  • The name and contact details of Daira’s point of contact for further information;
  • A description of the likely consequences of the breach; and
  • A description of the measures taken or proposed to be taken to address the breach.

13.9 Deletion and Return of Data

At the choice of the Customer, Daira shall delete or return all Customer Data to the Customer after the end of the provision of services, and delete existing copies unless applicable law requires storage. Data shall be deleted within one hundred and eighty (180) days of termination unless the Customer requests earlier deletion or return.

13.10 Audit Rights

Daira shall make available to the Customer all information necessary to demonstrate compliance with these DPT and shall allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer. Such audits shall be conducted with reasonable notice (not less than thirty (30) days), during normal business hours, and shall not unreasonably interfere with Daira’s operations.

13.11 Governing Law

These DPT shall be governed by the laws of the United Arab Emirates, unless mandatory data protection laws of the Customer’s jurisdiction require otherwise.

Daira home
contact@daira.me+971 58 529 4814
Offices 411-417, Cloud Spaces,
Dubai Mall Fountain Views,
Dubai, UAE

What we offer

OneFinance™→
  • Books
  • Tax Compliance
  • Performance Reporting
  • Forecasting & Budgeting
  • Procurement
  • Cash Management
AI-powered Accounting
  • Accounting & Bookkeeping
  • Tax Compliance

Industries

  • Construction
  • Real Estate
  • Restaurants
  • Auto Parts
  • Retail & Supermarkets
  • Professional Services
  • Accommodation & Hospitality
  • Logistics & Trading
  • Healthcare & Clinics

Company

  • About
  • Insights
  • Pricing
  • Contact

Follow Us

5.0 on GoogleLeave a review

© 2026 Daira / FLOW METRICS ACCOUNTING & BOOKKEEPING L.L.C. All rights reserved.

Privacy PolicyTerms of Service