Privacy Policy
Last updated: March 9, 2026
This Privacy Policy describes how Al Manar Systems ("Company," "we," "us," or "our"), headquartered in Dubai, United Arab Emirates, collects, uses, stores, and discloses personal data when you use the Sila CRM platform and related services (collectively, the "Service"). By accessing or using the Service you acknowledge that you have read and understood this Privacy Policy.
We are committed to compliance with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL") and any implementing regulations issued thereunder.
1. Information We Collect
1.1 Account and Profile Data
When your organization registers for Sila CRM, we collect information necessary to create and manage accounts, including:
- Organization name, industry, and business details
- User full name, email address, and role within the organization
- Authentication credentials (managed through our authentication provider, Supabase)
- Billing contact information
1.2 Operational and CRM Data
In the course of using the Service, your organization and its authorized users may submit:
- Facility and account records (names, addresses, categories, contact details)
- Visit logs and field activity reports
- Schedules and calendar entries
- Invoices, inventory records, and sales data
- Notes, attachments, and other content created within the Service
1.3 Location Data
With user consent, our mobile application collects precise geolocation data to support field visit verification, route planning, and proximity-based facility discovery. Location data is associated with visit records and may be used to display facilities on an interactive map. You may disable location services through your device settings at any time, though this may limit certain Service features.
1.4 Device and Usage Data
We automatically collect technical information when you access the Service, including:
- Device type, operating system, and browser version
- IP address and approximate geographic location derived from IP
- Pages visited, features used, and interaction patterns
- Performance metrics and error logs
We use Vercel Web Analytics and Vercel Speed Insights to collect aggregated, anonymized usage and performance data. These services do not use cookies for tracking and do not collect personally identifiable information.
1.5 Cookies and Similar Technologies
We use essential cookies to maintain authentication sessions and protect against cross-site request forgery. For full details, please refer to our Cookie Policy.
2. How We Use Your Information
We process personal data for the following purposes:
- Service delivery: To provide, operate, and maintain Sila CRM, including user authentication, data storage, and feature functionality
- Account management: To create and manage organization accounts, assign user roles, and administer subscriptions and billing
- Communication: To send service-related notifications, respond to inquiries, and provide customer support
- Product improvement: To analyze usage patterns, diagnose technical issues, and improve Service performance and features
- Security: To detect, prevent, and address fraud, unauthorized access, and other harmful activities
- Legal compliance: To comply with applicable laws, regulations, and legal processes, including the PDPL
We process personal data on the legal bases of contractual necessity (to perform our agreement with your organization), legitimate interest (to improve and secure the Service), consent (where specifically obtained, such as for location data), and legal obligation (where required by law).
3. Data Sharing and Disclosure
We do not sell personal data. We may share information in the following limited circumstances:
- Within your organization: Data entered into the Service is accessible to authorized users within your organization in accordance with role-based access controls
- Service providers: We engage trusted third-party providers who process data on our behalf to deliver the Service, including Supabase (database and authentication infrastructure) and Vercel (web hosting and analytics). These providers are contractually bound to protect your data and use it only for the purposes we specify
- Legal requirements: We may disclose data when required by law, court order, regulatory authority, or governmental request, or when necessary to protect our rights, safety, or property
- Business transfers: In connection with a merger, acquisition, or sale of all or a portion of our assets, personal data may be transferred to the acquiring entity
4. Data Retention
We retain personal data for as long as your organization maintains an active subscription, plus a reasonable period thereafter to fulfill legal, accounting, or reporting obligations. Specifically:
- Active account data: Retained for the duration of the subscription
- Post-termination: CRM and operational data is retained for up to 90 days following account termination to allow for data export, after which it is permanently deleted
- Billing records: Retained for the period required by applicable tax and commercial laws in the UAE
- Usage and analytics data: Retained in aggregated, anonymized form and not subject to deletion requests
5. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS) and at rest
- Multi-tenant architecture with row-level security ensuring strict data isolation between organizations
- Role-based access controls within each organization
- Secure authentication with session management via Supabase Auth
- Regular security assessments and infrastructure monitoring
- Access logging and audit trails
While we strive to protect your data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security but are committed to promptly addressing any security incidents in accordance with applicable law.
6. Your Rights
Under the UAE PDPL and applicable data protection regulations, you have the following rights with respect to your personal data:
- Right of access: You may request a copy of the personal data we hold about you
- Right to correction: You may request that we correct inaccurate or incomplete personal data
- Right to deletion: You may request the deletion of your personal data, subject to legal retention obligations
- Right to data portability: You may request that we provide your data in a structured, commonly used, machine-readable format
- Right to withdraw consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing
- Right to object: You may object to the processing of your personal data in certain circumstances
- Right to lodge a complaint: You may file a complaint with the UAE Data Office or other competent authority
To exercise any of these rights, please contact us at support@sila-crm.app. We will respond to verified requests within 30 days. Note that organization administrators may also access, export, or delete data through the Service's administrative controls.
7. International Data Transfers
Your data may be processed and stored on servers located outside the United Arab Emirates, including through our infrastructure providers Supabase and Vercel, which may operate servers in the United States and other jurisdictions. Where data is transferred outside the UAE, we ensure that appropriate safeguards are in place in accordance with the PDPL, including contractual protections and reliance on adequacy determinations where available.
8. Children's Privacy
Sila CRM is a business-to-business service designed for use by professionals in the medical sales industry. The Service is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a person under 18, we will take steps to delete that information promptly.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will notify affected users by email or through a prominent notice within the Service. The "Last updated" date at the top of this page indicates when the policy was most recently revised. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
10. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Company: Al Manar Systems
- Location: Dubai, United Arab Emirates
- Privacy inquiries: support@sila-crm.app
- General inquiries: sales@sila-crm.app