Legal
Privacy Notice
What we collect when you use this site, why we collect it, where it is processed, and how long we keep it.
Draft — requires review before publication
This notice was written by reading what the software actually does. It has not been reviewed by a lawyer, and it is not yet a published legal document.
Everything below is factually true of the system as built. What it deliberately does not do is make legal determinations, and those are the parts that need a qualified answer before this page goes live: the lawful basis for each purpose, whether UAE PDPL and/or GDPR apply and to whom, the mechanism relied on for processing data outside the UAE, the statutory minimum retention for tax and commercial records, and who is named as the point of contact for a data-subject request.
Until then it is deliberately kept out of search engines. See the comment at the top of app/(public)/privacy/page.tsx for what to change when it is approved.
Who we are
Cohort is a software studio based in Dubai, United Arab Emirates. This notice covers cohort.ae and client.cohort.ae, the portal we give clients we are already working with.
For anything in this notice, write to us — the address is at the bottom of the page.
What this site collects
The contact form is the only thing that collects anything. If you fill it in we receive your name, email address, phone number (including the country code you select), your message, and your company name if you choose to give one.
One more value goes with it, and it is not a box you filled in. When you press send, the page works out where you arrived from and sends that along with the rest. If the link you followed carried campaign tags in its web address — utm_source, utm_medium, utm_campaign, the tags we put on our own links and listings — those are what is sent. If it did not, your browser tells the page which site linked you, and we keep the site’s name only: google.com, not the page or the search you typed. If there is neither, the value is the word “direct”.
It tells us which of our own links actually brings people here, which is the only thing we use it for. It is worked out once, at the moment you submit — not while you browse — and it is stored with your enquiry and kept for as long as the enquiry is.
We use all of it to reply to you and to work out whether we are a good fit for what you need. We do not sell it, we do not use it for marketing, and submitting the form does not sign you up to anything.
Nothing tracks you while you browse. No analytics, no advertising pixels, no session recording, no third-party scripts of any kind. Browsing cohort.ae sets no cookies at all, and nothing follows you from one page to the next.
The one exception is a map: if the contact page is showing an embedded map, that frame is loaded from Google, and Google will see your IP address and may set its own cookies. The rest of the page does not depend on it.
We say “while you browse” deliberately, because the flat claim would be easier to write than to keep. The referral value described above is the one thing here that a reasonable person would call tracking, and the honest description of it is narrow rather than absent: it is read once, when you submit the form, from the address of the page you are on and the referring site your browser volunteers, and it goes nowhere except into your enquiry.
Your IP address
We do not store your IP address alongside your enquiry. We use it for two narrow things, both about stopping abuse rather than about you:
The contact form allows five submissions per hour from one address. Doing that needs a counter, and the counter is keyed on your address. A nightly clean-up removes it once it is more than a day old, so it is gone within about forty-eight hours of your last submission. Repeated failed attempts against our sign-in pages record an address with a strike count; the same nightly job clears it once the last attempt is more than seven days old, so within about eight days.
If a submission is rate-limited or fails with an error, your address appears in our server logs, which our hosting provider keeps for a limited period.
If you want to work with us
This site does not accept job applications and has no way to receive a CV. There is no careers page, no application form and no upload — nothing here collects an employment history, an emirate, a salary expectation or a document about you.
If you write to us about a job through the contact form or by email, we hold what you chose to send us, on the same terms as any other enquiry described above: kept until we delete it, and removed if you ask.
If you are a client
The client portal holds what running a project needs: your name, email address, and phone number if you gave one; the projects, documents, invoices and payments belonging to your organisation; and any files we share with you or you send us.
Some actions are recorded as evidence, and this is worth knowing. When you sign an agreement, approve a preview or accept a delivery, we record the name you typed, the exact wording you were shown, the time, your IP address and your browser’s user-agent string. That is deliberate: it is what lets either of us prove later what was actually agreed. It is kept for that reason and not used for anything else.
We also keep a log of what happened on each project — documents shared, emails sent, invoices issued, sign-ins. Cohort itself cannot change or remove an entry once it is written: the database grants the application permission to add rows and read them, and no permission to alter or delete one. That is a real restriction rather than a habit, but it is not magic — someone with direct administrative access to the database could lift it, and we would rather say so than claim an impossibility. It exists so that a disagreement about what happened has an answer.
When we send you an email — an invitation, an invoice, a reminder — we keep a record of it: the address it went to, the subject, what kind of message it was, whether it was delivered, and when. We keep it so that “we never received that” is a question with an answer.
That record has no automatic expiry. Nothing deletes it on a schedule, so an address we have written to stays in it until we remove it by hand. Deleting a client unlinks their delivery records from them but does not remove the rows, and the recipient address is part of the row. Ask us and we will delete yours.
Email is sent through Resend, which keeps its own delivery log on its own schedule.
Where your data is processed
Cohort runs on DigitalOcean, in their Frankfurt, Germany region. The application, the database and the file storage are all there.
That means your data is processed outside the UAE. We say so plainly rather than leaving it to be inferred: DigitalOcean has no UAE region, and Frankfurt is the closest one that offers everything this system needs in a single place.
Who else sees it
We do not sell personal data and we do not share it for advertising. It reaches three companies, each for one job:
- DigitalOcean
- Hosting, the database, and storage for files and documents. Frankfurt, Germany.
- Stripe
- Card payments, for clients only. Payment details are entered on Stripe's own page — we never see or store a card number. Stripe holds its own record of every payment.
- Resend
- Sending email. It sees the recipient address and the contents of the message.
Google is a fourth, but only in one place: the embedded map on the contact page, if one is being shown.
Beyond that, we disclose personal data only where we are legally required to.
How long we keep things
Different records are kept for different lengths of time. Two are kept deliberately and indefinitely — client and financial records, and the activity log, for the reasons given below. Two more are kept indefinitely because nothing deletes them: contact enquiries, and the record of emails we sent. That is a gap rather than a decision, and it is stated here rather than left to be discovered.
The times below are ceilings, not averages: the job that does the deleting runs once a night, so a record goes at the first nightly run after its window has passed rather than at the instant it passes.
- Contact enquiries
- Kept until we delete them, including the referral value stored with them. There is no automatic expiry — ask us and we will remove yours.
- Records of emails we sent
- Kept until we delete them. There is no automatic expiry, and the recipient address is part of the record. Ask us and we will remove yours.
- Rate-limit counters
- Removed on the first nightly run once more than a day old — within about 48 hours.
- Abuse records against an IP
- Cleared on the first nightly run once the last attempt is more than 7 days old — within about 8 days.
- Sign-in codes
- Valid for 10 minutes, then unusable; the expired row is removed on the next nightly run, so within about a day of expiring.
- Client records, invoices and signed agreements
- Kept after a project ends. They are financial and legal records, and deleting them would destroy the evidence of what was agreed and paid.
- The project activity log
- Not deleted. It is append-only by design, because a log that can be edited proves nothing.
Asking us what we hold, or to delete it
Write to us and we will tell you what we hold about you, correct it if it is wrong, or delete it. There is no form to fill in.
Two honest limits on deletion, because a promise we cannot keep is worse than a clear one:
Some records we are not able to delete, and we will say which. Payments are held by Stripe under their own retention rules and our access to them does not include deleting them; email delivery logs are held by Resend the same way. When we delete a client or a project, we write down exactly what was left behind in those systems, so that this answer is a record rather than a recollection.
And some records we should not delete: an invoice, a signed agreement, or an entry in the activity log is evidence of a commercial relationship, and removing it would destroy something that protects both sides. We will tell you when that applies rather than quietly keeping it.
Cookies
This site sets no cookies. The client portal and the staff panel set one when you sign in, so that you stay signed in; it holds a signed session token and nothing else, is marked HttpOnly and Secure so no script can read it, and it expires. Signing out clears it and revokes the session.
Contact
Questions about this notice, or a request about your data:
Last updated 29 August 2026.