Controller and contact
The controller is the operator of the dha.ee service. Privacy and data-rights requests can be sent to [email protected]. The controller’s registered legal name and postal details will be added when the commercial operator is formally appointed.
Data categories
The service may process account and contact data, encrypted security settings, session and device information, 2FAS verification results, payment and gift records, support requests, and security audit data.
Purposes and legal bases
Account and gift services are processed to perform the service contract. Security, fraud prevention, and incident investigation rely on the controller’s legitimate interests and applicable legal obligations. Consent is requested where it is the appropriate basis.
Service areas
Device and session signals protect access. 2FAS and PIN results protect restricted actions. Payment providers process payment details when a payment is made. Messages and support requests are processed to deliver and answer them.
Retention and deletion
Data is kept only for the period required for its purpose, contract, accounting, dispute, and security obligations. Expired sessions and challenges are deleted automatically. Security signals described below are deleted no later than 24 months after the event, unless a shorter period applies.
For security and investigation of unauthorised access, the site may process IPv6 EUI-64 indicators and their protected HMAC pseudonyms. The retention period is no more than 24 months from the event, after which the data is deleted.
Processors and recipients
Categories of processors may include hosting and network protection, email and SMS delivery, payment providers, and technical support. Data is disclosed to authorities only when a valid legal duty applies.
Transfers outside the EEA
A processor may handle data outside the EEA only where a lawful transfer mechanism and appropriate safeguards apply. Current processor information can be requested from the contact above.
Cookies
Strictly necessary cookies maintain the session, CSRF protection, and security state. Non-essential cookies are not activated without the consent required by law.
Your rights
Depending on the legal basis and circumstances, you may request access, rectification, erasure, restriction, portability, or object to processing. You may also withdraw consent without affecting earlier lawful processing. At present, withdrawal is requested at [email protected]; this is a data-subject rights request, not a complete technical consent-withdrawal mechanism.
Requests
Send a request to [email protected].
Profiling and automated decisions
The service does not make decisions producing legal or similarly significant effects solely by automated processing. Automated security rules may temporarily delay or block suspicious attempts; the underlying event can be reviewed by authorised staff.