Legal 0.5 — Data Governance
Data Governance Policy
Effective date: 4 July 2026
This Data Governance Policy explains how the alawadi.cloud platform governs the data you entrust to it — your applications, container images, managed databases, and the traffic they process (“Your Data”). It complements the Terms of Service and the Privacy Policy: where the Privacy Policy covers personal data about you as an account holder, this policy covers how we handle the operational data you run on the platform.
The Services are provided by Alawadi Cloud & DataCenters Colocation Services LLC (“alawadi.cloud,” “we,” “us,” or “our”), the operator of the alawadi.cloud platform.
1. Your ownership of the data
You own Your Data. We claim no ownership of it and act only as a processor on your behalf, using Your Data solely to operate the Services you have provisioned — for example to store, run, transmit, back up, and display it within your account.
You are responsible for having the rights to Your Data and for the lawfulness of what you process on the platform.
2. Tenant isolation
Every customer's workloads run in a dedicated, isolated namespace with its own network policy, resource quotas, and access controls. By default, a workload cannot reach another tenant's data or network. Managed databases are provisioned per customer and are not shared between tenants.
3. Access control and staff access
Access to production systems is granted on a least-privilege basis and limited to the personnel who need it to operate and support the platform, and administrative actions are logged. We do not access the contents of Your Data except as needed to deliver the Services, to investigate a security or abuse incident, or when you ask us to in the course of support.
4. Encryption, backups, and recovery
Data is encrypted in transit using TLS. Where a service includes off-site backups, those backups are encrypted at rest before leaving the platform. Managed Postgres and MySQL include backup and point-in-time recovery controls; managed Redis and Basin object storage do not currently carry the same backup or PITR commitment.
Availability and durability commitments are set out in the Service Level Agreement. As with any provider, please keep your own copies of anything critical.
5. Sub-processors
We rely on a small set of service providers to operate the platform — an authentication provider for Google sign-in, infrastructure and content-delivery providers, and storage providers for eligible off-site backup copies — each acting on our instructions. Card top-ups are unavailable, so we do not currently use a card-payment processor. If one is introduced later, we will identify it before that method is available. We do not sell Your Data, and we share it only with these processors or where required by law.
6. AI data handling
Prompts and completions sent to the AI inference API are processed only to return a response and to meter usage. We do not use Your Data, or your AI prompts and completions, to train models without your explicit instruction.
7. Data location and cross-border processing
Customer workloads and primary service data run in our live UAE region today. Syria and Jordan are planned regions only and do not currently process customer workloads. Some service providers may process limited account or operational data outside the UAE; when an eligible service includes off-site backups, encrypted copies may be stored with its storage provider outside the live region. Where a transfer is required, we rely on appropriate safeguards.
8. Retention and deletion
We keep Your Data for as long as your account is active. When you delete a resource — or after suspension and a grace period for non-payment, as described in the Terms — the resource and its data are deleted, and backups age out on their retention cycle. Specific retention windows for account, billing, and audit records are set out in the Privacy Policy.
9. Data portability and export
Your Data is yours to take with you. While your account is active you can export your container images, database contents, and files using standard tools before you delete resources or close your account.
10. Security incidents
If we become aware of a security incident affecting Your Data, we will investigate and contain it and notify affected customers without undue delay, describing what happened, what we are doing about it, and any steps you should take.
11. Your responsibilities
You are responsible for securing your own application code, secrets, credentials, and access, for configuring your workloads correctly, and for complying with the laws that apply to the data you process on the platform.
12. Changes to this policy
We may update this policy as the platform evolves and will post the revised version with a new effective date.
Contact
Questions about this document or formal legal notices may be addressed to Alawadi Cloud & DataCenters Colocation Services LLC at [email protected].
This document is governed by the laws of the United Arab Emirates, without regard to conflict-of-law rules. Any dispute will be resolved before the competent courts of the Emirate of Dubai.