VAT Guard by SITUS

Privacy Notice

Version 2026-09-06-v7

Architecture summary. VAT Guard is designed to separate readable account/subscription metadata from customer compliance content. Customer content is encrypted in the browser. The app keeps an encrypted browser copy and can write encrypted workspace files and retained revisions to a folder you select in Chrome or Edge. A locally synced OneDrive, SharePoint or Google Drive folder may transfer those files through your organisation’s sync software. VAT Guard does not operate that transfer or provide managed cloud backup. Separate encrypted backup export and restore are available.

1. Controller

SITUS FZ L.L.C., Expo City Dubai Authority Service Licence No. 00134, Dubai, United Arab Emirates, is the controller of personal data it processes for website, account, billing and service-administration purposes, unless a different role is expressly stated for a feature.

2. Data we process

3. Why we process data

We process data to provide and secure VAT Guard, authenticate users, administer subscriptions, enforce plan entitlements, provide encrypted backup-file export/recovery, deliver transactional communications, detect abuse, maintain legal/security records, comply with law and improve reliability.

Early-bird email offers

If you request an offer, we store your email, selected plan, verification and consent timestamps, offer status, delivery records and subscription identifiers. For instant offers, we also store the original five-minute deadline and an opaque checkout-session reference. Your browser stores a signed offer reference so refreshing does not restart the timer; it does not grant access to your account. We do not send a confirmation email before instant checkout. An optional, unchecked choice lets you request up to three promotional reminders over seven days after your request. The first two do not renew an expired five-minute discount; the final reminder may contain a separate first-month-free offer. Earlier confirmation-email offers retain their original reminder schedule after confirmation. The discount is available without this marketing choice. You can withdraw consent using the unsubscribe link in each message; this stops offer reminders but does not cancel a subscription or necessary billing notices.

We check Stripe subscription status before sending reminders and stop the sequence on purchase, withdrawal, a bounce or complaint. Email and IP hashes help limit abuse and are deleted after seven days. Campaign lead, offer-session and delivery records are deleted after 90 days from the request, once any free trial has ended. Billing and legally required records follow their separate retention rules. Email-provider delivery logs may follow that provider’s retention settings. Campaign emails do not use open or click tracking. Contact consult@thevatguide.ae to exercise your rights.

4. Customer-side encrypted content

Customer Content in the local vault is encrypted in the browser. Where the customer exports a .vgbackup file, the exported content remains encrypted. The current build does not automatically upload that backup to SITUS, Google Drive or iCloud. SITUS does not need the customer’s vault passphrase or recovery key to administer subscriptions. Customers must protect their recovery credentials. If the encryption architecture makes recovery technically impossible without the key, SITUS may be unable to restore readable content when the key is lost.

5. Service providers

VAT Guard may use service providers for website hosting, application hosting/CDN, authentication, subscription payments, transactional email, monitoring and security. The current service uses Tilda for marketing pages, Cloudflare Pages for app and demo hosting, Supabase for authentication and account/subscription metadata, Stripe for payments, and Resend for transactional email and consented offer reminders. The Supabase project is hosted in Frankfurt. Other providers operate internationally; their processing locations and contractual terms apply. Supplier documents are processed locally for PDF reading and OCR, rather than sent to an external document-analysis service. Your organisation selects and controls any provider used to sync its workspace folder.

6. International processing

Service providers may process data in jurisdictions outside the UAE. SITUS will use contractual, technical and organisational safeguards required by applicable UAE data-protection law where cross-border transfers occur.

7. Retention

Account, subscription, security, tax-invoice and legal records are retained for periods reasonably necessary for their purposes and applicable legal obligations. Customer Content kept in the local encrypted vault remains under the customer’s browser/device storage controls. Customers are responsible for maintaining exported encrypted backups where needed. Account/control-plane records are retained according to the Service’s subscription, termination and legal-retention settings.

8. Security

SITUS uses reasonable technical and organisational measures appropriate to the Service. No internet, browser, encryption or cloud system is absolutely secure. Customers are responsible for authorised-user management, endpoint security, strong credentials and recovery-key custody.

9. Rights

Individuals may have rights under applicable UAE data-protection law, including rights relating to access, correction, deletion or other processing controls, subject to legal limitations and verification of identity. Requests should be sent through the privacy/contact channel published on the VAT Guard website.

10. Cookies and local storage

The application may use strictly necessary browser storage for authentication and the encrypted working vault. With your permission, Google Ads measures visits and completed paid purchases using advertising click identifiers, first-party cookies, the amount paid, currency and an opaque transaction identifier. This helps us understand which ads lead to subscriptions. Free trial sign-ups are not reported as paid purchases. Google receives technical request information such as IP address and browser details. We do not send passwords, verification links, email addresses, supplier records, invoices or document contents to Google Ads. Automatic enhanced conversions and personalised advertising are disabled in this implementation. Measurement runs in a dedicated page with a clean URL, rather than sending your account-access URL. Your choice is shared across thevatguide.ae and its app subdomain for 180 days; advertising attribution and duplicate-prevention records are retained for up to 90 days. A pending purchase measurement can retry for up to 30 days. Choosing No thanks leaves Google Ads measurement off and does not affect purchase or app access. . You can also clear your browser cookies and site data. Google processes measurement data under its Privacy Policy. Tilda supplies the marketing-page hosting and its necessary technical services.

11. Changes

This Notice may be updated as the product architecture or law changes. Material changes will be identified by a new version/effective date and notified where appropriate.

12. Contact

Privacy questions and requests can be sent to consult@thevatguide.ae. Do not send your workspace passphrase or recovery key.