شروط الخدمةسياسة الخصوصيةEN

Privacy Policy

Last updated: 28 August 2026 · This is a courtesy translation; the Arabic version is the binding text.

In short: a real estate office’s client data belongs to that office, not to us — we host and process it on its behalf and on its instructions. We do not sell it and do not use it for advertising. Every office is isolated from every other inside the database itself. Visitor IP addresses are stored hashed, never raw. If you are a client of an office and want your data or its deletion, the office is your point of contact and we act on what it asks.

1. Scope and who we are

This policy covers the Diyari platform (diyariplatform.com): the office dashboard, the office sites published through the platform, the document verification pages, and the APIs. The responsible party is Bilal Raad, Baghdad, Republic of Iraq, reachable at [email protected].

Iraq has, to date, no consolidated personal data protection statute. We therefore build this policy on Article 17(1) of the 2005 Constitution of the Republic of Iraq, which protects privacy of personal life; on the protection of secrets under Penal Code No. 111 of 1969; and on Electronic Signature and Electronic Transactions Law No. 78 of 2012 — and, beyond that, we voluntarily apply the principles of the EU General Data Protection Regulation (GDPR): purpose limitation, data minimisation, storage limitation, security, and data subject rights.

2. Roles: who is controller, who is processor

This split is the key to the rest of the policy:

DataControllerOur role
An office’s client data: owners, tenants, buyers, property seekers — names, identity documents, financial entries, contractsThe real estate officeProcessor on its behalf and on its instructions
The office account itself: its users, subscription, invoices, security and audit logsUsController
Platform operation: technical logs, performance metrics, abuse signalsUsController

So: if you are a client of a real estate office that uses Diyari, that office is answerable to you for your data and for informing you about its processing, and we act on its instructions. Address your request to it first; if you cannot reach it, write to us and we will pass it on.

3. What data is processed

3.1 Office users

Name, phone number, email if given, role (owner / manager / agent), branch, and a password stored as a scrypt hash, never as text. We keep session tokens and sign-in times, and for platform administration actions we record in an audit log: the administrator’s email, the action, the entity, and an IP address.

3.2 Office client data (entered by the office)

Full name in the Iraqi triple form plus surname; identity document type, number, issuer, and issue date; phone and WhatsApp number; messaging consent status and its timestamp; address; notes — plus everything the office builds on top: lease, sale, sharecropping (مزارعة) and مكاتبة contracts, rent and instalment schedules, receipts, formal warnings (إنذار), bookings, deals and commissions, and leads (name, phone, source of interest).

We do not collect this data from the individuals themselves and do not decide what is collected; the office enters it and decides its extent, having warranted in the Terms of Service that it is entitled to do so.

3.3 Visitors to office sites, and the public

  • Page visits: path, listing viewed, referrer, browser type — and an IP address that is hashed, never stored raw.
  • QR scans: the fact of the scan, the document type, and the time, with a hashed IP as above.
  • Contact or booking request forms: name, phone, message, and the property concerned — passed to the office whose site it is, since that office is who you meant to reach.

We build no advertising profiles of visitors and do not track them across different offices’ sites.

3.4 Photos and media

The office uploads property photographs; we generate multiple sizes and stamp them with a watermark carrying the office’s name and phone. Published photographs are public and visible to any visitor. The office must therefore not upload images showing people, documents, or private detail without their subjects’ consent.

3.5 Subscription and payment data

We keep the plan, invoices, amounts, and the recorded payment method (cash via an agent, or an external payment channel). We never receive or store card, wallet, or bank details, and we hold no funds — see section 3.4 of the Terms of Service.

4. Purposes and legal bases

PurposeBasis
Operating the Service and performing the subscriptionPerformance of a contract
Processing an office’s client dataThe office’s instructions, as controller
Sending reminders and receipts over WhatsAppPrior express consent of the recipient, collected by the office
Security, fraud prevention, fault diagnosis, hashed visit statisticsLegitimate interest, balanced against individual privacy
Billing, accounting, responding to a lawful requestLegal obligation

We do not sell, rent, or trade personal data, and do not use it for third-party advertising.

5. Cookies and tracking

Our pages and the sites we publish use no advertising cookies from us. What we use is strictly technical: a session token stored in the dashboard user’s browser to keep them signed in, readable by no other site.

However, the platform lets an office add its own measurement or advertising pixels to its site (Google Analytics 4, Meta Pixel, TikTok Pixel). If it does, those parties’ scripts load on its site and may set cookies and collect identifiers — that is the office’s choice and responsibility, and it must inform its visitors and obtain consent where their local law requires. Consult those parties’ policies directly.

Typefaces are loaded from Google Fonts, which by the nature of the request discloses a visitor’s IP address to Google.

6. Who data is shared with

We share data only with the following categories, and only as far as necessary:

PartyPurposeLocation
Neon (managed PostgreSQL)Storing platform dataOutside Iraq
HetznerThe server running the applicationGermany / EU
CloudflareContent delivery, protection, custom hostnames, media storage (R2)Global network
Meta Platforms and the accredited WhatsApp providerDelivering WhatsApp messagesOutside Iraq
Google FontsPage typefacesOutside Iraq
External payment providersReached by the client directly via a link; we pass them no financial dataIraq and abroad

We may disclose data in response to a court order or a lawful official request from a competent authority, to the extent that request requires, and we notify the office concerned unless the law forbids it. On a merger or sale of the business, data passes to the successor under the same obligations and with prior notice.

7. Transfers outside Iraq

The platform’s infrastructure is hosted outside Iraq, meaning data is stored and processed in other countries. By using the Service the office consents to that transfer and confirms it has informed its clients. Where data of individuals in the European Union is involved, we rely on Standard Contractual Clauses (SCCs) or an equivalent mechanism with our providers.

8. Retention

  • While the subscription is active: the office’s data and its clients’ data are kept, because they are its working record.
  • After termination: data remains recoverable for 30 days, then is deleted from live systems and ages out of backups on their normal rotation.
  • Visit and QR scan logs: kept in hashed form for statistics only.
  • Invoices and audit logs: kept for as long as accounting and legal obligations require, even after the subscription ends.
  • An office may request earlier deletion of a specific client’s data, and we carry it out unless a legal obligation prevents us.

9. Security

These are measures actually in place, not intentions:

  • Office isolation inside the database: every table carries a tenant identifier and enforces mandatory Row-Level Security, and the tenant identifier is derived solely from the verified access token — never from anything the browser sends.
  • Passwords are stored as scrypt hashes, from which the original cannot be recovered.
  • IP addresses in visit and scan logs are hashed, never stored raw.
  • Traffic is encrypted with TLS, and the servers are not exposed to the public internet except through a managed tunnel.
  • The application’s database account is least-privilege and separate from the migration and backup accounts.
  • Role-based permissions inside each office, and an audit log of administrative actions.

No system is absolutely secure. On a breach likely to harm individuals, we notify the office concerned without undue delay, targeting 72 hours from becoming aware of it, and give it what it needs to notify its clients and the competent authorities.

10. WhatsApp messages

The system sends no automated message to a number without a recorded express opt-in. Consent can be withdrawn at any time by telling the office, and sending then stops. Once a message leaves the platform it is subject to Meta’s terms and policies.

11. Your rights

A data subject may request access to their data, its correction, its deletion, a copy in a portable format, withdrawal of consent, and objection to a particular processing.

  • If you are a client of a real estate office: address your request to that office — it is the controller of your data, and we act on what it asks of us. If you write to us directly, we refer your request to it and tell you.
  • If you are an office user or a subscriber: write to [email protected].

We respond within thirty days, and may ask for proof of identity before acting on a sensitive request, to prevent impersonation.

12. Children

The Service is aimed at people working in real estate and is not directed at anyone under 18; we do not knowingly collect their data. If we learn that a minor’s data has been entered without a basis, we delete it.

13. Changes to this policy

We may amend this policy; amendments are published here with an updated date. We notify offices of material changes at least thirty days before they take effect.

14. Contact

Bilal Raad — Baghdad, Republic of Iraq
Privacy and data rights: [email protected]
Legal: [email protected]