Twerlo FZ-LLC (“Twerlo”, “Azeer”, “we”, “us”, or “our”) respects your privacy and is committed to protecting it through compliance with this policy. Below you will find details of the information collected during your use of:
- Our website (
azeer.com) - Our web platform (Azeer dashboard / web app)
- Our mobile applications (iOS and Android)
- Our APIs and integrations
Users may be subject to different protection standards depending on their region. To learn more about applicability, refer to the relevant section in this document.
This policy contains dedicated sections for users in the European Union / United Kingdom, Saudi Arabia, United Arab Emirates, and Brazil.
This document can be printed for reference using the print command in your browser.
We may update this Privacy Policy from time to time to reflect new technologies, services, or legal changes. Material changes will be communicated to you in an appropriate manner.
A. Definitions
Personal Data — Any information relating to an identified or identifiable natural person (“data subject”). An identifiable person is one who can be identified directly or indirectly, particularly by reference to an identifier such as a name, identification number, location data, online identifier, or factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
Processing — Any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, alignment, restriction, erasure, or destruction.
Usage Data — Information collected automatically through the Service (or third-party services employed in the Service), including IP addresses, device identifiers, URI addresses, request times, request methods, file sizes received, server response codes, country of origin, browser features, operating system characteristics, session details, and navigation paths.
User / You — The data subject who is using Azeer (any of its surfaces: website, dashboard, mobile app, API).
Data Subject — The natural person to whom the personal data refers.
Data Processor — The natural or legal person, public authority, agency, or other body that processes personal data on behalf of the Controller.
Data Controller — The natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data. The Data Controller for Azeer is Twerlo FZ-LLC.
Service — The Azeer platform and its associated products, including website, web app, mobile apps, and APIs.
European Union (EU) — Unless otherwise specified, all references to the EU include current member states and the European Economic Area (EEA).
B. General Information on Data Processing
1. Data Controller
| Field | Detail |
|---|---|
| Legal Entity | Twerlo FZ-LLC |
| Brand | Azeer |
| Registered Address | Dubai, United Arab Emirates |
| Privacy Contact | privacy@azeer.com |
| Data Protection Officer | dpo@azeer.com |
| Website | https://azeer.com |
If you have any questions about this Privacy Policy, the information we hold about you, or wish to exercise your privacy rights, please contact us at the details above.
2. Legal Basis for Processing
We only process personal data when we have a valid legal basis. Generally, we may process your personal data if one of the following applies:
- You have given consent for one or more specific purposes
- Processing is necessary for the performance of a contract or pre-contractual measures
- Processing is necessary for compliance with a legal obligation
- Processing is related to a task carried out in the public interest
- Processing is necessary for legitimate interests pursued by us or a third party, where your rights do not override those interests
3. Data Processing for Users in the EU / EEA / UK
a) Legal Bases under GDPR / UK GDPR
We may process your personal data based on:
- Your consent — Article 6(1)(a), Article 7 GDPR / UK GDPR
- Contract performance — Article 6(1)(b)
- Legal obligation — Article 6(1)(c)
- Legitimate interest — Article 6(1)(f)
b) Your Rights under GDPR / UK GDPR
You may exercise the following rights free of charge:
- Right to withdraw consent (Article 7(3))
- Right of access (Article 15)
- Right to rectification and erasure (Articles 16, 17)
- Right to restriction of processing (Article 18)
- Right to data portability (Article 20)
- Right to object (Article 21)
- Right to lodge a complaint with a supervisory authority (Article 77)
To exercise your rights, contact us using an email address registered in our system so we can verify your identity.
4. Data Processing for Users in Saudi Arabia (PDPL)
For users residing in the Kingdom of Saudi Arabia, processing is governed by the Personal Data Protection Law (PDPL) issued by the Saudi Data & AI Authority (SDAIA).
Data Residency for Saudi Customers
For Saudi Arabian customers, personal data is stored within the Kingdom of Saudi Arabia in the Google Cloud Platform Dammam region (me-central2), in compliance with PDPL data residency requirements.
Your Rights under PDPL
- Right to be informed about processing
- Right to access your personal data
- Right to request correction of inaccurate data
- Right to request deletion
- Right to withdraw consent
- Right to object to processing
- Right to lodge a complaint with SDAIA
Cross-Border Transfers
We comply with PDPL Article 29 cross-border transfer rules and apply appropriate safeguards where required. Where Saudi customer data must leave the Kingdom (e.g., for operational support), we apply contractual safeguards and obtain consent where required.
5. Data Processing for Users in the UAE
For users residing in the UAE, processing is governed by UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. UAE residents may exercise rights similar to those listed under GDPR and may file complaints with the UAE Data Office.
6. Third-Country Transfers
Where we process data outside the EU/EEA/UK, KSA, or UAE, or in connection with third-party services, we rely on:
- Express consent or transfer required by contract or law
- Recognized adequacy decisions
- EU Standard Contractual Clauses (SCCs) and the UK Addendum
- The EU-US Data Privacy Framework (DPF) and UK Extension where applicable
- Saudi PDPL adequacy mechanisms
A current list of certified service providers under the Data Privacy Framework can be found at https://www.dataprivacyframework.gov.
7. Recipients and Linked Third-Party Websites
Data may be accessible to internal staff (administration, sales, marketing, legal, IT, customer success) and to external parties. We share data with hosting providers, security tools, billing and payment processors, telecommunications providers, public authorities (upon justified request), accountants, auditors, and legal counsel.
We use third-party services to ensure the Service is functional, secure, and continuously optimized. The Service may include links to third-party websites. We are not responsible for the data practices of those websites.
All processors act on our instructions, are carefully selected, and regularly monitored. They do not process data for their own purposes. An updated list is available at **https://azeer.com/sub-processors**.
8. Data Security
We use technical and organizational measures to protect personal data against accidental or unauthorized access, loss, or manipulation. Our security is continuously updated. We use TLS 1.3 encryption to secure data transfers and AES-256 encryption at rest.
In the event of a personal data breach, we will notify affected users and authorities within 72 hours as required by GDPR / PDPL.
9. Children
To use the Service, users must be at least 16 years old. We do not knowingly collect personal information from children under 16, and we do not allow anyone under 16 to use the Service.
10. Automated Decision-Making
We do not use automated decisions that have legal or similarly significant implications for you. We may use profiling techniques to analyze user behavior in order to predict and improve the reach of content distributed through the Service. AI/ML is used for fraud detection, content moderation, and smart suggestions — never for fully automated decisions with significant effect.
11. Retention Periods
In line with Articles 17 and 18 GDPR / UK GDPR, we delete or restrict processing when data is no longer needed for its intended purpose.
| Data Category | Retention |
|---|---|
| Account data | Until account deletion + 30 days backup purge |
| Chat / message content | While account is active, deleted on request or account closure |
| Billing records | 7 years (tax compliance — UAE / KSA / EU) |
| Server log files | 30 days |
| Crash reports | 90 days |
| Marketing consent records | Until consent is withdrawn |
Data may be retained beyond these periods only where required by law (e.g., tax and company law documentation).
C. Data Collection and Processing When Using Our Service
Data is either provided directly by you or collected automatically as you interact with the Service.
1. Data Collected Across All Surfaces
Automatically Collected
- Date and time of access
- Browser type and settings (web)
- Operating system (web and mobile)
- Last page visited (web)
- Amount of data transferred and access status
- IP address (anonymized where possible)
- Device identifiers (mobile)
- Crash logs and diagnostic data
We store log files with anonymized IP addresses for 30 days for security and threat detection. The legal basis is our legitimate interest.
Provided by You via Contact Forms
- First and last name
- Company size / number of employees
- Company name and website
- Work email address
- Phone number
Provided by You During Account Sign-Up
- First and last name
- Email address
- Password (hashed)
- Workspace and team configuration
- Communication content while using the Service (messages, attachments, contacts)
We do not evaluate this data on a personal basis for marketing without your explicit consent.
2. Data Collected on Our Mobile Applications (iOS & Android)
In addition to the above, the Azeer mobile apps may collect the following — only with your explicit permission through your device’s standard permission prompt:
| Permission | Purpose |
|---|---|
| Camera | Capture photos/videos for chat attachments and profile picture |
| Microphone | Record voice notes and voice calls |
| Photo Library | Attach images from your device to chats |
| Contacts | Import contacts into Azeer (optional) |
| Location | Only when you explicitly share location in a chat |
| Notifications | Deliver message and event notifications |
| Bluetooth | Headset/audio device support during calls |
You may revoke any of these permissions at any time through your device settings.
Mobile-Specific Data
- Device model and OS version
- Mobile carrier and connection type
- App version and unique device identifiers
- Push notification tokens
- Crash and performance data
3. Social Login
You can use Google Social Login to sign in instead of creating an account manually. Logging in via Google generates an account functionally identical to one created through manual registration.
When you select Google login, you will be redirected to Google to enter your credentials. Google then shares your name and email address with us. We never receive your Google password. If you choose to provide additional information, it will be linked to your account.
We use this service based on our legitimate interest under Article 6(1)(f) GDPR / UK GDPR to make access more convenient.
- Manage Google permissions: https://myaccount.google.com/permissions
- Google’s privacy policy: https://www.google.com/policies/privacy/partners/
4. Hosting and Infrastructure
The Azeer Service is hosted on Google Cloud Platform (Google Cloud EMEA Limited, Velasco, Clanwilliam Place, Dublin 2, Ireland).
Data Residency
We apply regional data residency to comply with local data protection laws:
| Customer Region | Hosting Region | GCP Location |
|---|---|---|
| Saudi Arabia (KSA) | Saudi Arabia | GCP Dammam region (me-central2) |
| GCC (UAE, Kuwait, Bahrain, Oman, Qatar) | GCC | GCP Dammam (me-central2) or GCP Doha (me-central1) |
| EU / UK | European Union | GCP EU regions |
| Rest of world | Default | GCP EU regions |
For Saudi Arabian customers, data is stored in the GCP Dammam region in compliance with Saudi PDPL data residency requirements and SDAIA guidelines.
When you visit the Service, GCP receives your IP address and browser/system information. Our use is based on Article 6(1)(b) GDPR (contract performance) and Article 28 GDPR (data processing agreement).
Where any data is transferred outside the customer’s primary region, this is done under appropriate safeguards: EU Standard Contractual Clauses, EU-US Data Privacy Framework, or explicit user consent.
Further information: https://cloud.google.com/privacy
5. Content Delivery Network
We use Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA) as our CDN and Web Application Firewall to optimize load times and protect the Service.
When you load our Service, Cloudflare may receive your IP address, browser, OS, referrer URL, session length, and request frequency. This is necessary to detect and defend against attacks. Cloudflare is DPF-certified.
Further information: https://www.cloudflare.com/privacypolicy/
6. Contact, CRM
When you contact us via our website forms, we collect:
- Company name and information
- First and last name
- Work email address
- Phone number
After processing your request, we delete it from our active systems unless legal retention or your consent permits further storage.
We may store your contact data in a customer relationship management system (CRM) if a business relationship exists or is anticipated. CRM contacts are reviewed every two years; if no further relationship or legal obligation exists, the data is deleted.
Our CRM is provided by Zoho Corporation Pvt. Ltd. (Estancia IT Park, Plot No. 140, 151, GST Road, Vallancherry Village, Chengalpattu Taluk, Kanchipuram District 603 202, India). For Saudi Arabian customers, Zoho operates a Saudi Arabia data center to comply with PDPL data residency requirements. For other regions, Zoho operates EU-based data centers and complies with GDPR.
Further information: https://www.zoho.com/privacy.html
7. Newsletter and Marketing Communications
We send newsletters and marketing communications only with your explicit opt-in consent. We use a double opt-in process: after submitting your email, you must confirm via a verification link.
Each marketing email contains an unsubscribe link. You may withdraw consent at any time without disadvantage.
We may use Zoho Campaigns and similar providers to deliver these communications.
8. Social Media
The Azeer website includes links to our social media profiles. Integration is via linked graphics — no automatic connection is made to social network servers when you load our website. A connection is only established when you click the link.
If you click while logged into your social media account, the network operator may associate the visit with your personal account.
The following social networks are integrated:
- X (Twitter) — X Corp., 1355 Market Street, San Francisco, CA 94103, USA — https://twitter.com/privacy
- YouTube — Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA — https://policies.google.com/privacy
- Meta (Facebook & Instagram) — Meta Platforms, Inc., 1 Hacker Way, Menlo Park, CA 94025, USA — https://www.facebook.com/about/privacy/
- LinkedIn — LinkedIn Corp., 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA — https://www.linkedin.com/legal/privacy-policy
9. Cookies
Our website uses cookies. A cookie is a small text file sent to your browser by our web server when you visit. You can manage cookies via your browser settings. Note that disabling cookies may affect website functionality.
We use a Cookie Consent Manager to obtain and document your cookie consent in accordance with applicable law.
10. Web Analytics and Tracking
We use the following analytics services on our website (with your consent via the cookie banner):
a) Google Analytics 4
Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
We use GA4 to analyze and optimize our website. IP anonymization is enabled by default. We have configured the following privacy settings:
- IP anonymization
- Advertising features disabled
- Personalized advertising disabled
- Remarketing disabled
- Data retention: 2 months
- Cross-device tracking (Google Signals) disabled
- Data sharing disabled
GA4 user data is automatically deleted after 14 months. Google is DPF-certified.
Further information: https://policies.google.com/privacy
b) Google Tag Manager
Provider: Google LLC.
Tag Manager allows us to manage tracking tags through a central interface. The Tag Manager itself does not use cookies but may trigger other tags that do.
11. Advertising and Retargeting
We use the following advertising services (with your consent):
a) Meta Pixel
Provider: Meta Platforms Ireland Ltd (parent: Meta Platforms, Inc., 1601 Willow Road, Menlo Park, CA 94025, USA).
Meta Pixel helps us identify target audiences for Meta advertising and measure campaign effectiveness. Meta is DPF-certified.
Further information: https://www.facebook.com/about/privacy/
b) Google Ads & Conversion Tracking
Provider: Google Ireland Limited (parent: Google LLC).
We use Google Ads with conversion tracking to measure the effectiveness of our advertising campaigns.
Further information: https://policies.google.com/privacy
c) LinkedIn Insight Tag
Provider: LinkedIn Ireland Unlimited Company (parent: LinkedIn Corp.).
We use the LinkedIn Insight Tag for B2B campaign measurement and audience building.
Further information: https://www.linkedin.com/legal/privacy-policy
12. Chat Widget
We offer a chat widget on our website to help you reach us. The chatbot is operated directly by our company through our own platform.
When you interact with the chat, we may process:
- Name
- Email address
- Other contact details
- Chat history
- IP address, log files, location, and metadata
Data is used solely to handle your inquiry and is not shared with third parties without consent. Processing is based on legitimate interest (Article 6(1)(f) GDPR) or contract performance (Article 6(1)(b) GDPR) for pre-contractual inquiries.
13. Payment Services
For paid plans, we use regional payment processors and Zoho Payments / Zoho Subscriptions (Zoho Corporation) to handle payments. When you make a payment, the following may be collected:
- Name and billing address
- Email address
- Payment information (credit card number, expiration, CVV) — handled directly by the licensed payment processor; we do not store full card numbers
- Transaction details
Our payment processors are PCI-DSS compliant and use industry-standard security. We do not share payment information with third parties beyond our payment processors and as required by tax / legal obligations.
Further information: https://www.zoho.com/privacy.html
14. Partner Referral Links
We may use partner referral links. If you click such a link and make a purchase, our partner receives a commission. This requires us to identify your visit and confirm the transaction via cookies or similar technologies.
D. Mobile Application Specific Provisions
1. App Tracking Transparency (iOS)
On iOS, we comply with Apple’s App Tracking Transparency (ATT) framework. We will request your permission before tracking your activity across other apps and websites for advertising purposes. You may decline; this will not affect core App functionality.
2. Push Notifications
We send push notifications via:
- Apple Push Notification service (APNs) for iOS
- Firebase Cloud Messaging (FCM) for Android
Push notification tokens are device identifiers required to deliver notifications. You may disable notifications anytime via your device settings.
We use push notifications for:
- New messages and chat events
- Account activity
- Service updates
- Marketing (only with opt-in consent)
3. Account & Data Deletion
In compliance with Apple App Store Review Guideline 5.1.1(v) and Google Play Data Deletion policy, you can delete your account and all associated personal data at any time:
- In-App: Settings → Account → Delete Account
- Web: https://azeer.com/delete-account
- Email: privacy@azeer.com
Deletion is permanent and processed within 30 days, except where retention is required by law.
4. Mobile Analytics & Crash Reporting
In our mobile apps, we may use:
- Firebase Analytics (Google LLC) — usage analytics
- Firebase Crashlytics (Google LLC) — crash diagnostics
- Sentry (Functional Software Inc.) — error monitoring
These tools collect technical data (device type, OS version, app version, crash logs) to help us improve stability and performance. They do not access message content.
5. Apple Sign In
Where Apple Sign-In is offered, we honor the “Hide My Email” preference. We never receive your real email if you choose this option.
6. Advertising ID (Android)
If used, you may reset or opt out of personalized ads via Android settings: Settings → Privacy → Ads.
E. Information for Users Residing in Brazil (LGPD)
This section integrates with and supplements the rest of this Privacy Policy. The provisions in this section apply to all users residing in Brazil under the Lei Geral de Proteção de Dados (LGPD). For such users, these provisions supersede any divergent or conflicting provisions in this policy.
Legal Bases for Processing
We process your personal information based on:
- Your consent
- Compliance with legal or regulatory obligations
- Performance of a contract or pre-contractual procedures
- Exercising rights in judicial, administrative, or arbitration procedures
- Protection of life or physical safety
- Our legitimate interests, where your fundamental rights do not prevail
Your Rights under LGPD
You have the right to:
- Confirm the existence of processing
- Access your personal information
- Correct incomplete or outdated data
- Anonymize, block, or delete excessive or unlawful data
- Receive information on consent and its consequences
- Know the third parties with whom we share data
- Data portability
- Delete data processed based on consent
- Withdraw consent at any time
- File a complaint with the ANPD (Autoridade Nacional de Proteção de Dados)
- Object to non-compliant processing
- Request information on automated decisions
- Request review of automated decisions affecting your interests
You will never be discriminated against for exercising these rights.
How to File a Request
Email privacy@azeer.com at any time, free of charge. We will respond within 15 days (or as required by LGPD).
International Transfers from Brazil
We transfer data outside Brazil only when permitted by LGPD: with adequate protection level, your consent, contract performance, legal obligation, or other legal grounds.
F. Your Rights and How to Exercise Them
| Right | How to Exercise |
|---|---|
| Access your data | privacy@azeer.com |
| Correct inaccurate data | privacy@azeer.com or in-account settings |
| Delete your account | https://azeer.com/delete-account or in-app/in-product |
| Export your data | privacy@azeer.com (we provide JSON/CSV export) |
| Withdraw consent | privacy@azeer.com or unsubscribe link |
| Object to processing | privacy@azeer.com |
We respond within 30 days under GDPR / PDPL (extendable to 60 days for complex requests) and 15 days under LGPD.
For verification, please email us from the address registered to your account.
G. Changes to This Privacy Policy
We may update this Privacy Policy. Material changes will be communicated via:
- In-app notification
- Email to your registered address
- Notice on https://azeer.com/privacy
Continued use of the Service after notification constitutes acceptance of the updated policy.
H. Contact Us
| Channel | Detail |
|---|---|
| privacy@azeer.com | |
| DPO | dpo@azeer.com |
| Postal Address | Twerlo FZ-LLC, Dubai, UAE |
| Website | https://azeer.com/privacy |
| Sub-processors List | https://azeer.com/sub-processors |
| Account Deletion | https://azeer.com/delete-account |
Effective Date: May 4, 2026 Version: 1.0