Processing map
| Data | Purpose and basis | Recipients and location | Normal retention |
|---|---|---|---|
| Account, business profile and legal records | Identity, access and contract administration; contract, consent and legitimate security interests | Cloudflare/OpenAI Sites; processing may occur outside the UAE | Active relationship plus 24 months; legal acceptance up to 6 years after closure |
| Preview, purchase, download and booking records | Requested delivery, entitlement and accounting; contract and legal obligations | Cloudflare, Stripe, Google Calendar and Resend as applicable | Preview link 15 minutes; access activity 12 months; core transactions 5 years |
| Chats, voice transcripts, saved facts and tool audits | Customer support, continuity, requested actions and security; contract and legitimate interests | Meta, Google Gemini and Cloudflare/OpenAI Sites | Up to 12 months after last activity |
| Contact requests and email logs | Follow-up and delivery evidence; contract and legitimate interests | Resend, Cloudflare and authorised operations staff | Requests 24 months after closure; marketing withdrawal evidence 3 years |
| Sessions, tokens, rate limits and security events | Authentication, fraud prevention and system protection; legitimate interests | Cloudflare/OpenAI Sites and authorised operations staff | Sessions 30 days; one-time tokens until use or expiry; security records for the operational period or up to 12 months |
Providers and international processing
Cloudflare and OpenAI Sites provide hosting, D1 records and R2 file storage. Meta supports text responses. Google supports sign-in, Gemini Live and Calendar. Stripe handles payment credentials and payment verification. Resend delivers account, purchase, booking and support email. Each receives data needed for its service and may process it outside the UAE under its available safeguards.
Cookies and browser storage
An essential secure cookie keeps signed-in accounts authenticated. Session storage preserves anonymous chat continuity only in the current tab and remembers interface recovery state. Google and Stripe components may set essential third-party state when used. The service does not use advertising cookies.
Rights and requests
Requests for access, correction, deletion, restriction, objection or marketing withdrawal can be sent to support@gccdatamatrix.com. Identity is verified before account data is disclosed or changed. Requests are logged, assessed against applicable retention duties and answered within the period required by applicable law.
Security and incident response
Controls include server-side ownership checks, hashed credentials and sensitive tokens, short-lived file grants, signed Stripe webhooks, rate limits, tool allowlists and audit logs. Suspected incidents are contained, investigated and documented. Affected people and competent authorities are notified where legally required.
Internal processing record
The controller maintains a working record of processing covering the purposes, data categories, recipients, transfers, retention, safeguards and responsible service owner reflected above. Material provider or product changes trigger a review of this record and the public notices.
