01 Who we are

MD Capital Consultancy is a licensed business in Abu Dhabi, UAE, operating the VerifyCode technical verification service at verifycode.ae. "We", "us", "VerifyCode" refer to MD Capital Consultancy, the data controller.

  • Licence No.: CN-6421144
  • Unified Registration No.: 101-2026-200095711
  • Unified Licence No.: 501-2026-200066075
  • Activity: Banking Services Consultancy
  • Jurisdiction: Abu Dhabi, United Arab Emirates

Contact: submit privacy enquiries via the Request Verification form at verifycode.ae. We do not publish a direct email address as our primary contact channel.


02 What personal data we collect

We collect only the minimum personal data necessary to deliver the service:

  • Contact information: your name, corporate email, and company name, provided via the Request Verification form.
  • Repository access: a repository URL or access credential you provide, scoped exclusively to the agreed review and used solely to complete your report.
  • Payment information: handled exclusively by Stripe Inc. We do not store card numbers, CVV, or payment credentials — only a payment confirmation and invoice reference.
  • Usage data: anonymised web analytics (page views, browser type, referrer, general region). No fingerprinting or persistent cross-site tracking.

We do not collect sensitive personal data (e.g. biometric, health, or political data) as defined under UAE PDPL.


03 How we use your data

  • Service delivery: to conduct the verification and deliver your report. Basis: performance of contract.
  • Enquiry management: to respond to your enquiry and communicate about your engagement. Basis: performance of contract.
  • Financial administration: to issue invoices/receipts and retain records required by UAE law. Basis: legal obligation.
  • Service improvement: aggregated, anonymised usage analysis. Basis: legitimate interests.

We do not use your data for marketing, profiling, or automated decision-making without your explicit consent, and we do not engage in behavioural advertising.


04 Repository data — zero-retention commitment

24-Hour Deletion Commitment

All repository data — clones, extracted files, analysis artifacts, and intermediate outputs — is permanently and irreversibly deleted within 24 hours of report delivery. Deletion confirmation is available on request.

  • During review: stored in isolated, access-controlled environments restricted to the assigned analyst(s).
  • On delivery: all clones, extracted files, and artifacts are scheduled for immediate deletion.
  • Within 24 hours: deletion is confirmed and logged; the deletion log is kept as a tamper-evidence record.
  • What is retained: only the SHA-256 hash manifest — cryptographic hashes with no source code, logic, or proprietary information — as a tamper-evidence record.
  • Deletion confirmation: available on request via the contact form at verifycode.ae.

Access credentials for private repositories are invalidated and deleted concurrently with the repository data.


05 Data sharing

We do not sell, rent, trade, or share your personal data for commercial purposes. We share data only with the service providers required to operate VerifyCode:

Stripe Inc.
Payment processing — card transactions and payment confirmations. Independent data controller for payment data.
stripe.com/privacy ↗
Netlify Inc.
Website hosting — serves verifycode.ae. Standard access to web request logs only.
netlify.com/privacy ↗

No advertising networks, analytics platforms, data brokers, or marketing providers receive your personal data. We may disclose data where required by UAE law or a competent authority, disclosing only the minimum required.


06 Data retention schedule

We retain personal data only as long as necessary or as required by UAE law. This schedule matches our Data Handling page.

Data categoryRetention periodBasis
Request / verification form submissions90 daysOperational necessity; deleted on schedule
Repository data (clones, artifacts)24 hours post-deliveryZero-retention commitment (Section 4)
SHA-256 hash manifestRetained indefinitelyTamper-evidence integrity record (no source code)
Invoice & receipt records7 yearsUAE Commercial Transactions Law
NDA records5 years from executionContractual obligation
Anonymised web analyticsAggregated; no individual limitNo personal data — anonymised at collection

On expiry, data is deleted securely in a manner that prevents reconstruction or recovery.


07 Your rights under UAE PDPL

Under UAE Federal Law No. 45 of 2021, you have the right to:

Access your personal data
Correct inaccurate data
Request deletion of data
Object to specific processing
Data portability
Restrict processing

Some rights are subject to legal limits — e.g. deletion does not override our obligation to retain financial records for 7 years.

To exercise your rights: submit a request via the form at verifycode.ae; we respond within 30 days. To complain: contact the UAE Data Office at dataoffice.ae.


08 Security measures

Encrypted transit: all data in transit protected by TLS 1.2+.
Access control: restricted to authorised personnel on a need-to-know basis.
Isolated environments: repository data stored in isolated, access-controlled environments during review.
Audit logging: analyst actions logged to maintain an auditable chain of custody.

No system can guarantee absolute security. In the event of a personal-data breach likely to risk your rights, we will notify you and the relevant authorities as required by UAE PDPL.


09 Cookies

The website uses only essential functional cookies required to operate (e.g. session state).

  • No advertising cookies and no retargeting.
  • No tracking cookies or device fingerprinting.
  • No analytics cookies — any usage analytics are anonymised at collection.

Because we set no non-essential cookies, no cookie-consent banner is required. If that changes, this policy and the site will be updated and consent obtained beforehand.


10 International transfers

Our service is operated from Abu Dhabi, UAE. We do not transfer personal data outside the UAE except as strictly required:

  • Stripe Inc. (USA): payment processing requires transmitting payment data to Stripe, under its privacy policy and appropriate safeguards. Only the minimum required is transmitted.

We do not transfer repository data or request information outside the UAE except where you explicitly request and consent in writing. Transfers comply with UAE PDPL cross-border requirements.


11 Changes to this policy

  • Material changes: notified via a prominent notice on verifycode.ae and an updated Effective Date.
  • Non-material changes: minor corrections; the Last Updated date is revised, no separate notice issued.

Continued use of the service after a revised policy's effective date constitutes acceptance, to the extent permitted by law.


12 Contact & complaints

  • Primary channel: submit your enquiry via the Request Verification form at verifycode.ae — mark it "Privacy Enquiry".
  • Response: acknowledged within 5 business days; substantive response within 30 days.
  • Supervisory authority: UAE Data Officedataoffice.ae.

Questions about your data?

Submit a privacy enquiry via our form — we respond within 5 business days.

Submit an enquiry