Legal
Privacy policy
Last updated 5 October 2026
RAHWE is a business software platform (CRM, work management, people and finance apps) operated by DigiFalx, Dubai, United Arab Emirates. This policy explains what personal data RAHWE handles, why, where it is kept, and how you can have it deleted.
Who is responsible
For your own RAHWE account (your name, email address and sign-in details), DigiFalx decides how that data is used and is the controller.
For the records an organisation keeps in RAHWE (its leads, contacts, employees, tasks, messages and invoices), the organisation is the controller and DigiFalx processes that data on its behalf, only to provide the service. Questions about those records should go to the organisation first; we will help them answer.
What we collect
- Account data: name, email address, a one-way hash of your password, your role, the organisations you belong to, sign-in times, IP address and browser for your sessions.
- Records your organisation enters or imports: leads, contacts, companies, deals, activities, tasks and boards, employee profiles, attendance and leave, invoices and expenses.
- Attendance location: when your organisation uses punch in and out, the position your browser reports at that moment (latitude, longitude and accuracy) and your IP address are stored with the record, only if you allow location access. Location is not tracked at any other time.
- Connected mailboxes: if you connect a mailbox (Google, Microsoft or any IMAP provider), messages from it are stored so you can read and reply in RAHWE. They are visible only to you. Messages that involve one of your organisation’s leads or contacts are also filed on that record for your team.
- Messages and lead forms from connected channels: WhatsApp messages exchanged through your organisation’s WhatsApp Business number, answers submitted to your Facebook and Instagram Lead Ads forms, Google Ads lead forms and your website forms, including the name, email, phone number and any other answers the person gave.
Data from Meta (Facebook, Instagram and WhatsApp)
When an organisation connects its Facebook Page or WhatsApp Business number, RAHWE receives, through Meta’s official APIs, the lead form answers submitted on that Page’s ads and the WhatsApp messages sent to and from that number. We use this data only to create and update the organisation’s leads and conversations in RAHWE. We do not use Facebook Login, we do not read personal profiles, friend lists or posts, we do not sell or share this data, and we do not use it for advertising. Access tokens are encrypted on our server and can be revoked at any time by disconnecting the Page or number in RAHWE or in Meta’s settings.
How we use data
- To provide the service: sign-in, storing and showing your organisation’s records, assignments, notifications and reminders.
- To keep it secure: rate limits, audit logs of sensitive actions, and investigating misuse.
- To send service emails such as invitations and password resets.
We do not sell personal data, show advertising, or use customer records to train AI models.
Cookies
RAHWE uses one cookie to keep you signed in (and a separate one for DigiFalx staff using the platform console). Both are strictly necessary, are not readable by scripts, and are removed when you sign out. The app remembers in your browser’s local storage whether the sidebar is collapsed and which app you opened last. There are no analytics, advertising or tracking cookies.
Where data is stored and who processes it
RAHWE runs on a virtual server operated by Hostinger. Data is stored in a database on that server and is not shared with other customers: every record carries its organisation, and the database itself refuses to return another organisation’s records. Connector credentials are encrypted on the server.
Service providers that may handle personal data for us: Hostinger (hosting) and, only when your organisation connects them, Meta, Google, Microsoft and your own email provider, to exchange the messages and leads described above.
How long we keep data
Records stay in RAHWE until your organisation deletes them or closes its account. Archived records are hidden but kept until deleted; on request we erase them permanently. Deleted records are removed from the live database immediately and from backups when those backups are removed. Sign-in sessions expire after 7 days without activity and after 30 days at most.
Your rights
You can ask for a copy of your personal data, ask us to correct it, or ask us to delete it. For records an organisation holds about you, contact that organisation; you may also write to us and we will pass your request on and help them respond. See data deletion for the steps.
Contact
DigiFalx, Dubai, United Arab Emirates. Email info@digifalx.com. We reply within 30 days.
If this policy changes in a way that affects you, we will update the date above and, for material changes, tell account owners by email before the change takes effect.