Privacy Policy

Your privacy — and the privacy of children served by your center — is paramount to us. Because Manaria operates as a specialized SaaS platform for special education and learning difficulty center management, we handle sensitive educational, diagnostic, and IEP goal records. This policy clearly explains what data we process, why, who owns it, and how your rights are protected under UAE and GCC privacy frameworks.

1. Scope of This Policy

This Privacy Policy applies to the Manaria marketing website, blog, and cloud application platform accessed by special education centers, specialists, and parents. By accessing our website or platform, you acknowledge that you have read and understood this policy.

2. Data Ownership & Separation of Roles

We strictly distinguish between the legal data roles defined by privacy laws in the UAE and GCC:

For data collected directly by Manaria for marketing inquiries or trial signups, Manaria acts as the Data Controller and adheres to the standards outlined in this policy.

3. Children's Data & Parent Consent

Manaria does not collect personal data directly from minors. All student data is entered into the platform by licensed centers or parents. Partner centers commit under our Terms of Service to:

All diagnostic notes, IEP goals, and evaluation records are treated as sensitive personal data subject to strict access controls and encryption.

4. Data We Collect

Via Marketing Site: Information provided voluntarily when requesting a demo or contact (Name, Work Email, Phone/WhatsApp number, Center Name, Role), and communication logs via WhatsApp.

Via Cloud Platform (Subscriber Accounts): Account details (staff names, roles, credentials), student records entered by the center (identifying details, IEP goals, session logs, attendance, parent progress reports), and essential technical usage logs for system security.

5. Why We Process Data

6. Regulatory Framework

Manaria operates in compliance with UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL), UAE Federal Law No. 2 of 2019 regarding Information Technology in Health Fields (where applicable to healthcare/therapeutical records), and GCC regional data standards.

7. Data Residency & Cross-Border Transfer

We adhere to strict data residency rules, ensuring sensitive student and health-related data remains stored within secure data center infrastructure compliant with UAE and GCC regulations. Subprocessors (such as cloud hosting or SMS providers) are bound by strict contractual obligations matching this policy.

8. Data Sharing Practices

9. Data Retention & Secure Erasure

We retain data only as long as necessary to fulfill service agreements or regulatory requirements. Upon subscription termination, centers are provided a grace period to export their records as defined in our Terms of Service, after which data is securely purged or anonymized.

10. Your Rights & How to Exercise Them

Users and data subjects hold rights under applicable UAE and GCC laws, including access, correction, deletion, restriction, and consent withdrawal.

11. Security Measures & Breach Notification

We implement technical and organizational security controls: end-to-end encryption in transit (TLS 1.3) and at rest (AES-256), role-based access, audit logging, and regular vulnerability assessments. In the event of a security incident impacting data, affected centers and relevant authorities will be notified without unreasonable delay.

12. Cookies & Analytics

Our marketing website does not currently use invasive tracking cookies. The cloud application utilizes only essential technical cookies necessary for user authentication and session management.

13. Policy Updates & Contact

We may update this policy periodically to reflect operational or legal updates. Any material changes will be announced on this page with an updated "Last Updated" date. For privacy questions, reach us via WhatsApp at (+971 55 540 8064).