Dubai Autism Center — Data Protection & Child Safety Commitment
*A public commitment to the families, educators, clinicians, and regulators we serve.*
---
Why we publish this
Most child-focused platforms rely on borrowed US or generic GDPR language and treat UAE data law as an afterthought. We do the opposite. This document is our public, plain-language commitment to how we handle data on the platform — particularly for children, particularly for children of determination, and particularly under UAE law as it stands today.
If anything here ever drifts out of step with the laws or practices it describes, that is a defect we will fix. Please contact our Data Protection Officer at `dpo@drashidalameri.com` *(replace with the real domain at publish time)*.
---
The frameworks we follow
We design and operate the platform to comply with — at minimum — the following UAE federal and emirate-level frameworks:
1. **Federal Decree-Law No. 45 of 2021** on the Protection of Personal Data (UAE PDPL)
2. **UAE Child Digital Safety Federal Law** (effective 1 January 2026, with full implementation by January 2027) for users under the age of 13
3. **Federal Law No. 3 of 2016** on the Rights of the Child (Wadeema's Law), with particular attention to Articles concerning privacy, dignity, and children with disabilities
4. **Federal Law No. 29 of 2006** on the Rights of People of Determination (as amended), covering accessibility, dignity, and non-discrimination in services
5. **Federal Decree-Law on Nurseries** and the data-handling controls determined by the **Federal Agency for Early Education (FAEE)**
6. **Emirate-level education and inclusion regulators**, including:
- Knowledge and Human Development Authority (KHDA) — Dubai, including the Inclusive Education Policy Framework
- Department of Education and Knowledge (ADEK) — Abu Dhabi
- Sharjah Private Education Authority (SPEA)
- Ministry of Education (MOE) for other emirates
7. **DIFC Data Protection Law No. 5 of 2020** and **ADGM Data Protection Regulations 2021** where applicable to free-zone-based partner institutions
We do not invoke COPPA or FERPA. Those are US laws and irrelevant to a UAE platform serving UAE families. We follow the UAE frameworks that actually apply.
---
Children's data — our hard rules
For any user under the age of 18, and most strictly for users under 13:
- **No commercial use of child data.** We do not use a child's data, behaviour, observations, or interactions for any form of marketing, advertising, advertising profiling, look-alike modelling, or upsell targeting. Ever. This is consistent with the UAE Child Digital Safety Law's prohibition on commercial use beyond authorised purpose.
- **Explicit, documented parental consent.** Before any child's data enters the platform, a parent or legal guardian provides documented consent. Consent is recorded with timestamp, scope, and consent version.
- **One-tap withdrawal.** A parent can withdraw consent at any time from the parent dashboard. On withdrawal, we cease processing within 48 hours and delete the child's record within 30 days unless a specific legal obligation requires retention.
- **No behavioural advertising on child surfaces.** No third-party ad pixels, no behavioural cookies, no session-replay tools (Hotjar, Microsoft Clarity, FullStory or equivalents), no social-media tracking pixels on any page or surface where a child's data is rendered.
- **No tracking beyond authorised purpose.** Analytics on child surfaces is limited to first-party operational telemetry strictly required to keep the service running. We do not use Google Analytics, HubSpot, or marketing-automation tools on these surfaces.
- **No transfer of identifiable child data outside in-region storage** without an explicit additional parental consent for the specific transfer purpose.
---
Data of children of determination — additional protections
We treat data relating to a child of determination — including diagnosis indicators, sensory profiles, communication preferences, motor profiles, M-CHAT or screener responses, therapy notes, and any data about additional needs — as **sensitive personal data** under PDPL Article 5 and as protected information under Wadeema's Law and Federal Law No. 29 of 2006.
This means:
- **Explicit, separate consent** is required to process any of this data — distinct from general account consent.
- **Data minimisation by default.** We collect only what is strictly necessary to deliver a specific feature or assessment, and never "just in case."
- **No diagnostic claims.** The platform does not diagnose. Tools like the M-CHAT screener are explicitly framed as awareness and screening prompts, not clinical diagnoses, and always direct families to a licensed UAE clinician for follow-up.
- **No medical-grade claims without medical-grade licensing.** If at any point we offer a feature that crosses into medical, therapeutic, or telehealth territory, we will obtain the relevant authorisation from the UAE Department of Health (DoH Abu Dhabi), Dubai Health Authority (DHA), or Ministry of Health and Prevention (MOHAP) before launching it. We will not market clinical or therapeutic benefits we are not regulated to deliver.
- **No automated decision-making on a child.** No assessment, score, or AI output is used to make a consequential decision about a child without a qualified human reviewer in the loop.
---
Our AI — what it does and what it doesn't
We use Anthropic's Claude family of models, accessed via the Anthropic API, to power **NOUR**, the platform's AI assistant. NOUR exists to answer parent and educator questions, surface resources, and assist clinicians with summarising notes — never to act as a clinician or a decision-maker.
**Concrete commitments:**
- **No training on customer data.** Anthropic does not train its models on data sent through the API. We additionally apply the API's data-retention controls and do not opt into any feedback loop that would expose customer prompts to training.
- **No retention of child PII in prompts beyond the session.** We strip identifiable child data from prompts where possible and never log raw child PII to long-term AI logs.
- **Sub-processor named.** Our AI sub-processor is Anthropic, PBC. If we change provider, we will update this document and notify users at least 30 days in advance.
- **No AI on under-13 surfaces without parental consent.** NOUR is available to parents and educators by default. AI features that interact directly with a child are gated behind explicit, separate parental consent.
- **No AI-generated diagnoses.** NOUR will not return a diagnostic statement. If a parent or clinician asks for one, NOUR will direct them to a licensed UAE clinician.
- **Transparency.** Any AI-generated text presented to a parent or educator is labelled as AI-assisted.
---
Data we collect, and why
We collect the **minimum** data necessary to deliver each feature. The full inventory:
| Category | Examples | Purpose | Lawful basis (PDPL) |
|---|---|---|---|
| Account data | Parent name, email, phone | Account creation, communication | Contractual necessity |
| Child profile | Name or alias, date of birth, gender, language, child of determination indicator (Yes/No only at signup) | Personalising the experience, age-appropriate content gating | Explicit parental consent |
| Sensitive child data | Diagnosis indicators, sensory profile, communication preferences, screener responses | Personalised support and resource matching | Explicit, separate consent under PDPL Art. 5 |
| Operational telemetry | Page views, error logs, session duration | Keeping the service running | Legitimate interest, limited to first-party |
| Payment data | Card data via a UAE-licensed PSP | Subscription processing | Contractual necessity |
We do not collect: webcam video, biometric data, voice recordings of children, geolocation beyond country level, social-media identifiers, or device-fingerprint data.
---
Where data lives
- **Primary data residency:** UAE, with EU (Frankfurt) as a secondary region for redundancy under PDPL-compliant cross-border transfer terms.
- **No data is processed in jurisdictions without an adequacy basis** under UAE PDPL Articles 22–23.
- **Backups** are encrypted at rest (AES-256) and retained for 90 days. Older backups are securely destroyed.
- **Logical tenant isolation** for any institutional client (school, clinic, nursery) so that one centre cannot access another's data.
---
Sub-processors
We name our sub-processors. The current list:
| Sub-processor | Purpose | Region | Legal basis for transfer |
|---|---|---|---|
| Anthropic, PBC | AI / NOUR | US | DPA + standard contractual safeguards |
| Vercel | Web hosting | EU (Frankfurt) | EU-based, no transfer concern |
| Supabase | Database, auth, storage | EU (Frankfurt) | EU-based, no transfer concern |
| \[UAE-licensed PSP, e.g. Network International or Telr\] | Payment processing | UAE | In-region |
| Anthropic-supported transactional email \[provider\] | Account emails | EU | EU-based |
We do not currently use Google Analytics, HubSpot, Microsoft Clarity, Mixpanel, Bugsnag, or Hotjar on child-data surfaces. We commit to publish any future change to this list with at least 30 days' advance notice.
---
Your rights as a parent or guardian
Under UAE PDPL Articles 13–22, parents have the right to:
- Access — see what we hold about your child
- Rectification — correct inaccuracies
- Erasure — delete your child's record
- Restriction — pause processing
- Portability — get a machine-readable export
- Object — to processing based on legitimate interest
- Withdraw consent — at any time, for any consented purpose
- Complain — to the UAE Data Office or to us directly
We respond to all requests within **15 business days**, faster than the PDPL maximum where possible. To exercise any of these rights, contact `dpo@drashidalameri.com` or submit the request from your parent dashboard.
---
How we handle a security incident
If we detect a security incident affecting child data, we will:
1. Contain and investigate within 24 hours of detection
2. Notify the UAE Data Office in accordance with PDPL Article 9 and any executive regulations in force
3. Notify affected parents directly within 72 hours of confirmation, plainly and without legalese
4. Publish a post-incident summary on this page once remediation is complete
We do not claim that incidents are impossible. We claim that we have a documented response plan, regular tabletop exercises, and a public commitment to transparency when something goes wrong.
---
Governance
- **Data Protection Officer:** \[name to be appointed before launch\] reachable at `dpo@drashidalameri.com`. The DPO is independent of product and engineering leadership.
- **Data Processing Impact Assessment (DPIA):** Conducted before launch and re-run annually or whenever a material change is made to data processing (new feature, new sub-processor, new data category).
- **Child-safety review:** Every feature involving a child surface is reviewed against this commitment before release. We document the review and retain records.
- **Regulator engagement:** We will proactively engage with KHDA, ADEK, FAEE, and MOH-linked authorities as features evolve, rather than waiting to be asked.
---
Document control
- **Version:** 1.0
- **Effective:** \[date at publish\]
- **Last reviewed:** \[date\]
- **Next scheduled review:** \[date + 12 months\]
We will publish any material change to this commitment at least 30 days before it takes effect, and we will email every parent account with a plain-language summary of what has changed and why.