Legal
Privacy Policy
Last updated: 22 April 2026
ScanVAT is operated by JIQ MEDIA LLC, a company registered in the United Arab Emirates.
1. Who We Are
ScanVAT (“we”, “our”, “us”) is a UAE VAT compliance software service operated from the United Arab Emirates. Our platform helps businesses photograph invoices, extract VAT data, and prepare VAT returns in compliance with Federal Tax Authority (FTA) requirements.
Contact: hello@scanvat.app
2. Data We Collect
We collect the following categories of personal data:
- Account data — name, email address, company name, TRN number, password (hashed, never stored in plain text).
- Invoice data — photos of invoices you upload, extracted text (supplier name, TRN, amounts, VAT), and processed VAT figures.
- Usage data — feature usage, device type, app version, error logs. No advertising trackers.
- Payment data — handled entirely by Stripe. We never see or store your card number. We receive only subscription status and a Stripe customer ID.
3. How We Use Your Data
- To provide the ScanVAT service — OCR extraction, VAT calculation, Form 201 generation.
- To authenticate your account and maintain session security.
- To send transactional emails — account registration, accountant invitations, VAT deadline reminders.
- To improve OCR accuracy and product features (aggregated, anonymised metrics only).
- To comply with UAE law and respond to lawful requests from the FTA or other authorities.
We do not sell your data. We do not use your invoice data for advertising.
4. Data Residency & Storage
All invoice data, account data, and VAT records are stored exclusively in AWS me-central-1 (UAE — Abu Dhabi). No data is replicated outside the UAE region without your explicit consent.
Data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
5. Data Sharing
We share data only with the following third-party processors under strict data processing agreements:
- AWS (S3, SES) — storage and transactional email, UAE region.
- Anthropic — Claude AI processes invoice images for OCR extraction. Images are not retained by Anthropic for training.
- Stripe — payment processing. Subject to Stripe's own privacy policy.
If you link an accountant to your account, your VAT summary data is shared with that accountant within the platform.
6. Your Rights
Under UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and applicable regulations, you have the right to:
- Access — request a copy of your personal data.
- Correction — correct inaccurate or incomplete data.
- Deletion — request deletion of your account and associated data (subject to legal retention requirements).
- Portability — export your invoice data in a machine-readable format via Profile → Export Data.
- Objection — object to processing for purposes beyond service delivery.
To exercise any right, email privacy@scanvat.app. We respond within 30 days.
7. Data Retention
Account and invoice data is retained for the duration of your subscription plus 5 years, in compliance with UAE VAT record-keeping requirements (Federal Decree-Law No. 28 of 2022, Article 78). Real-estate-related records may be retained longer where the law requires.
You may request earlier deletion of non-VAT data by contacting us. VAT records cannot be deleted before the 5-year mandatory retention period expires.
8. Cookies
The ScanVAT web portal uses a single HTTP-only, Secure, SameSite=Lax session cookie named scanvat-session for authentication. We do not use advertising cookies, analytics cookies, or third-party tracking scripts.
9. Children
ScanVAT is a business service. We do not knowingly collect data from individuals under 18 years of age. If you believe a minor has registered, contact us immediately.
10. Changes to This Policy
We will notify registered users by email of any material changes to this policy at least 14 days before they take effect. The “Last updated” date at the top of this page reflects the current version.
11. Contact
For privacy enquiries: privacy@scanvat.app
For general support: hello@scanvat.app