GOVERNANCE · LAST UPDATED 28 AUGUST 2026

How customer data is governed.

This operational summary brings together the service’s processing map, providers, retention periods, cookies, rights handling and security response.

Translucent jade data nodes connected through a precise brass governance network

Processing map

DataPurpose and basisRecipients and locationNormal retention
Account, business profile and legal recordsIdentity, access and contract administration; contract, consent and legitimate security interestsCloudflare/OpenAI Sites; processing may occur outside the UAEActive relationship plus 24 months; legal acceptance up to 6 years after closure
Preview, purchase, download and booking recordsRequested delivery, entitlement and accounting; contract and legal obligationsCloudflare, Stripe, Google Calendar and Resend as applicablePreview link 15 minutes; access activity 12 months; core transactions 5 years
Chats, voice transcripts, saved facts and tool auditsCustomer support, continuity, requested actions and security; contract and legitimate interestsMeta, Google Gemini and Cloudflare/OpenAI SitesUp to 12 months after last activity
Contact requests and email logsFollow-up and delivery evidence; contract and legitimate interestsResend, Cloudflare and authorised operations staffRequests 24 months after closure; marketing withdrawal evidence 3 years
Sessions, tokens, rate limits and security eventsAuthentication, fraud prevention and system protection; legitimate interestsCloudflare/OpenAI Sites and authorised operations staffSessions 30 days; one-time tokens until use or expiry; security records for the operational period or up to 12 months

Providers and international processing

Cloudflare and OpenAI Sites provide hosting, D1 records and R2 file storage. Meta supports text responses. Google supports sign-in, Gemini Live and Calendar. Stripe handles payment credentials and payment verification. Resend delivers account, purchase, booking and support email. Each receives data needed for its service and may process it outside the UAE under its available safeguards.

Cookies and browser storage

An essential secure cookie keeps signed-in accounts authenticated. Session storage preserves anonymous chat continuity only in the current tab and remembers interface recovery state. Google and Stripe components may set essential third-party state when used. The service does not use advertising cookies.

Rights and requests

Requests for access, correction, deletion, restriction, objection or marketing withdrawal can be sent to support@gccdatamatrix.com. Identity is verified before account data is disclosed or changed. Requests are logged, assessed against applicable retention duties and answered within the period required by applicable law.

Security and incident response

Controls include server-side ownership checks, hashed credentials and sensitive tokens, short-lived file grants, signed Stripe webhooks, rate limits, tool allowlists and audit logs. Suspected incidents are contained, investigated and documented. Affected people and competent authorities are notified where legally required.

Internal processing record

The controller maintains a working record of processing covering the purposes, data categories, recipients, transfers, retention, safeguards and responsible service owner reflected above. Material provider or product changes trigger a review of this record and the public notices.