How Earnflow Technologies Ltd. collects, uses, and protects your personal data.
Last updated: 22 April 2026
Earnflow Technologies Ltd. ("Earnflow", "we", "us", or "our") is a company registered in the Dubai International Financial Centre (DIFC), UAE, operating under DIFC Law No. 5 of 2020 (the Data Protection Law, "DIFC DPL"). We act as a Data Controller in respect of personal data collected through our platform at earnflowtec.com and associated mobile applications.
This Privacy Policy explains what personal data we collect, why we collect it, how we use it, with whom we share it, and what rights you have in relation to it. By using our platform, you acknowledge that you have read and understood this policy.
We collect the following categories of personal data:
| Category | Examples | Purpose |
|---|---|---|
| Identity | Full name, date of birth, nationality, government-issued ID | KYC onboarding, AML compliance |
| Contact | Email address, phone number, postal address | Account management, notifications |
| Financial | Bank account details, wallet addresses, transaction history, earnings data | Payment processing, settlement |
| Platform | Social media handle, platform earnings statements, content category | Eligibility verification, corridor routing |
| Technical | IP address, device type, browser, session tokens, usage logs | Security, fraud prevention, analytics |
| Compliance | Sanctions screening results, PEP status, risk classification | AML/CFT obligations under DIFC law |
Under the DIFC DPL, we process your personal data on the following legal bases:
We use your personal data to:
We share your personal data only in the following circumstances:
We do not sell your personal data to third parties.
Your data may be transferred to and processed in countries outside the DIFC, including Kenya, Somalia, Ethiopia, Uganda, Ghana, and Djibouti, in connection with payment processing. Where such transfers occur, we ensure appropriate safeguards are in place, including standard contractual clauses or adequacy decisions recognised under the DIFC DPL.
We retain your personal data for as long as your account is active and for a minimum of five (5) years after account closure, in accordance with DIFC AML/CFT record-keeping requirements. Transaction records and compliance documentation may be retained for up to ten (10) years where required by applicable law.
Under the DIFC DPL, you have the following rights in respect of your personal data:
| Right | Description |
|---|---|
| Access | Request a copy of the personal data we hold about you. |
| Rectification | Request correction of inaccurate or incomplete data. |
| Erasure | Request deletion of your data, subject to legal retention obligations. |
| Restriction | Request that we limit processing of your data in certain circumstances. |
| Portability | Receive your data in a structured, machine-readable format. |
| Objection | Object to processing based on legitimate interests. |
| Withdraw consent | Where processing is based on consent, withdraw it at any time. |
To exercise any of these rights, email [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the DIFC Commissioner of Data Protection.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These include TLS encryption in transit, AES-256 encryption at rest, role-based access controls, and regular security audits. In the event of a personal data breach that is likely to result in a high risk to your rights, we will notify you and the DIFC Commissioner of Data Protection without undue delay.
For any privacy-related queries, contact our Data Protection Officer: