Contents
- Scope & our roles
- Data we process on our website
- Data we process for business customers
- Data we process through the CDN & edge platform
- Data we process in the Player Software (apps)
- App-store disclosures at a glance
- Purposes & legal bases
- Sharing & sub-processors
- International transfers
- Retention
- Security
- Your rights
- Children
- Changes to this Policy
- Contact
We keep this Policy deliberately concrete: for each part of our service it says what data is involved, why, who is responsible for it, and how long it is kept. Terms written with a capital letter (Customer, Services, Player Software, Player App, End User, Customer Content) have the meaning given in our Terms of Service.
1.Scope & our roles
NagaOne is a business-to-business provider. Depending on the situation we act in one of two roles:
- Controller — for data about our own business Customers and their staff (account, billing and support data), for visitors to nagaone.ae, and for the technical and diagnostic data described in Sections 4 and 5 that we process to operate, secure and improve our own platform and software.
- Processor — for any personal data contained in Customer Content that passes through our network or is played through the Player Software, and for personal data of End Users that a Customer configures the Player Software to handle. In those cases the Customer is the controller, and we process the data only on the Customer's instructions under our Terms of Service and, where required, a data processing addendum.
2.Data we process on our website
Server logs
When you visit nagaone.ae, our web servers and CDN record technical access data: IP address, date and time, requested URL, referrer, browser type and version, operating system, and the response status. We use this data to deliver the site, to keep it secure (for example to detect attacks) and for aggregated, non-identifying statistics. Logs are kept for a short period (see Section 10) and are not combined with other data about you.
Contact form
If you use our contact form, we process the name, email address, topic and message you enter, together with the time of submission, in order to answer your request. Form submissions are delivered to us through the third-party form service Web3Forms, which acts as our processor and forwards the data to our mailbox. We keep correspondence for as long as needed to handle the request and any follow-up, and thereafter as required by law.
Fonts
Our pages load the typefaces "Sora" and "Space Grotesk" from Google Fonts. When a page loads, your browser requests the font files from Google's servers, which receive your IP address and browser details for that purpose. Google's privacy policy applies to that request.
Cookies & tracking
Our website does not set advertising or analytics cookies and does not use tracking pixels, fingerprinting or third-party analytics. Only technically necessary cookies or storage may be used where a feature requires it.
3.Data we process for business customers
When a company registers for an Account, places an order or communicates with us, we process the data of its representatives and staff: name, business email address, phone number, job title, company details and address, login credentials, billing and payment details (payments are handled by our payment provider; we do not store full card numbers), contract and order history, support tickets and correspondence, and usage and billing records for the Services. We use this data to set up and operate the Account, to provide, bill and support the Services, to meet our legal obligations (accounting, tax, sanctions screening under our Terms), and to send service notices. We send marketing communications to business contacts only where permitted and always with the option to opt out.
4.Data we process through the CDN & edge platform
To deliver Customer Content, our edge servers necessarily receive requests from End Users' devices and browsers. Each request carries technical data: IP address, requested URL and host, request headers such as user-agent and referrer, approximate location derived from the IP address (country/region), timestamps, bytes transferred, cache status and response codes. We process this data:
- to route, cache and deliver the content requested (this is the service itself);
- to protect the network and our Customers against attacks, abuse and fraud (DDoS mitigation, WAF, rate limiting, bot detection);
- to produce analytics for the responsible Customer about their own traffic; and
- to produce aggregated, anonymised statistics about network performance.
Raw request logs are retained for a limited period for security and troubleshooting and then deleted or aggregated. Any personal data contained in the Customer Content itself (for example a video a Customer streams, or files it stores in our edge storage) is processed on the Customer's behalf as processor; we do not look at it, analyse it or use it for our own purposes.
5.Data we process in the Player Software (apps)
The NagaOne Player Software is a content-neutral playback client for our business Customers. It contains no content of its own and offers no self-registration: an End User can only use a Player App with a configuration and credentials issued by a Customer. The following describes what data the apps handle and where it goes.
5.1Data that stays on the device
The Player App stores locally on the device: the Customer configuration (server endpoints, branding), the End User's login credentials or session token issued by the Customer, playback preferences (language, subtitles, volume, last channel, resume positions), favourites, and any cached media segments or time-shift buffers needed for playback. This data is stored only on the device, is protected by the operating system's app sandbox, and is removed when the app is uninstalled or its data is cleared.
5.2Data sent to the Customer's systems
To log in and to play content, the app connects to the systems configured by the Customer (its authentication service, playlist/EPG service and content endpoints). Those systems receive the End User's credentials, IP address, device information and requests for content. What the Customer does with that data — including viewing history, account management and retention — is governed by the Customer's own privacy notice, not by this Policy. NagaOne does not receive this data unless the Customer uses NagaOne's CDN for delivery, in which case Section 4 applies to the delivery requests only.
5.3Data sent to NagaOne
To keep the software working and secure, the app may send the following technical and diagnostic data to NagaOne:
- App and device diagnostics: app version, platform and operating-system version, device model and form factor (phone, tablet, TV), locale and time zone, screen resolution and supported codecs.
- Playback diagnostics: playback errors and error codes, start-up time, buffering and bitrate statistics, stream format and CDN response status — without the title of the content unless the Customer has enabled content-level diagnostics.
- Crash reports: stack traces and the device state at the time of a crash.
- Configuration and update checks: the Customer configuration identifier and app version, so the app can fetch the correct configuration and be notified of updates.
- IP address: received technically with every connection to our servers; used for routing, security and approximate country-level statistics, not for profiling.
We use this data solely to operate, debug, secure and improve the Player Software and the Services, to provide the responsible Customer with technical statistics about its deployment, and to respond to support requests from that Customer. We do not build profiles of End Users, do not use the data for advertising, and do not sell or rent it.
5.4What the apps do not do
- No advertising, no advertising SDKs, and no cross-app or cross-site tracking. The apps do not request the iOS App Tracking Transparency permission because they do not track.
- No access to contacts, photos, microphone, camera, precise location or health data. Any operating-system permission the app requests (for example local-network access for casting to a TV, or notifications) is used only for the feature it names.
- No self-registration and no NagaOne account for End Users. Credentials are issued, managed and revoked by the Customer; deleting an End User account is done through the Customer.
- No third-party analytics or attribution SDKs. Where a platform vendor's own crash-reporting service is used (for example Apple's or Google's crash reporting, which the End User controls through the operating-system settings), that vendor's privacy policy applies to it.
5.5Casting and Smart TV platforms
If an End User casts content to another device (for example Chromecast or AirPlay), the app discovers devices on the local network and hands the stream URL to the receiving device; the platform vendor's privacy policy applies to the cast session. Smart TV app stores and TV operating systems may collect their own usage data under the TV manufacturer's privacy policy, which is outside our control.
6.App-store disclosures at a glance
The table below summarises the data handled by the NagaOne Player Apps in the categories used by the Apple App Store privacy labels and the Google Play Data Safety section. "Linked to user" means associated with an identifiable person in our systems.
| Category | Collected by NagaOne? | Purpose | Linked to user | Used for tracking |
|---|---|---|---|---|
| Contact info (name, email, phone) | No | — | — | No |
| User credentials | No (sent to Customer only; stored on device) | Login to Customer service | No | No |
| Location | Approximate (country from IP) only | Delivery routing, security, statistics | No | No |
| Identifiers (device ID, user ID) | App-instance identifier only, no advertising ID | Configuration, diagnostics | No | No |
| Usage data (interactions) | No | — | — | No |
| Diagnostics (crash logs, performance) | Yes | App functionality, stability | No | No |
| Purchases / financial info | No (no in-app purchases) | — | — | No |
| Contacts, photos, health, sensitive info | No | — | — | No |
Data is transmitted to us over encrypted connections (TLS). End Users can request deletion of diagnostic data associated with their app instance through the Customer that provisioned the app or via our contact form (Section 15); because diagnostic data is not linked to an identified person, we may need the app-instance identifier shown in the app's settings to locate it.
7.Purposes & legal bases
We process personal data under the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and, where it applies to our Customers or End Users in the European Economic Area, the United Kingdom or Switzerland, the GDPR and equivalent laws. Our legal bases are:
- Performance of a contract — providing the Services and Player Software to our Customers, managing Accounts, billing and support.
- Legitimate interests — operating and securing our network and software, preventing abuse and fraud, producing diagnostics and aggregated statistics, and communicating with business contacts, balanced against the interests of the people concerned.
- Legal obligation — accounting and tax records, sanctions and compliance screening, responding to lawful requests from authorities.
- Consent — only where we ask for it explicitly (for example optional marketing), which can be withdrawn at any time.
- Processing on behalf of a Customer — for Customer Content and End User data, the Customer's instructions and the Customer's own legal basis apply.
8.Sharing & sub-processors
We do not sell personal data. We share it only with:
- Service providers (processors) acting on our instructions: data-centre and network providers on which our edge platform runs, cloud hosting for our control plane, our payment provider, the form service for our website, email and support tooling, and, where used, platform crash-reporting services. Each is bound by contract to process data only for our purposes and to protect it.
- The responsible Customer — technical statistics and diagnostics about that Customer's own deployment and End Users' use of its configuration.
- App-store operators and platform vendors — to the extent they receive data directly when an app is downloaded, updated or crashes, under their own policies.
- Authorities and advisers — where required by law, to enforce our Terms, to protect rights, safety or property, or in connection with a merger, acquisition or restructuring, subject to confidentiality.
A current list of sub-processors used for a Customer's Services is available to that Customer on request.
9.International transfers
NagaOne is established in the United Arab Emirates and operates a global edge network; by design, delivery requests are handled at the edge location nearest to the End User, and control-plane and diagnostic data are processed in the UAE and at our hosting providers in the European Union and other regions. Where data of persons in the EEA, UK or Switzerland is transferred to a country without an adequacy decision, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK Addendum) and additional technical measures. Where the UAE PDPL requires it, transfers outside the UAE are made only to jurisdictions with adequate protection or under appropriate contractual safeguards.
10.Retention
| Data | Typical retention |
|---|---|
| Website server logs | Up to 30 days, then deleted or anonymised |
| Contact-form messages and correspondence | For the duration of the enquiry and any resulting relationship; then as required by law |
| Customer account, contract and billing data | Term of the contract plus statutory retention periods (accounting and tax records, generally 5 years under UAE law) |
| CDN / edge request logs | Raw logs up to 30 days for security and troubleshooting (longer where a Customer has ordered extended log retention for its own traffic); aggregated statistics thereafter |
| Player Software diagnostics and crash reports | Up to 90 days, then deleted or aggregated |
| Customer Content cached at the edge | As long as the Customer's cache rules require; removed on purge, expiry or termination |
| Data stored on an End User's device by the Player App | Until the End User clears the app data or uninstalls the app |
11.Security
We protect personal data with technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.3 across the platform and between the apps and our servers), encryption at rest for control-plane data, access controls and least-privilege administration, logging and monitoring, DDoS and WAF protection, and secure development practices for the Player Software. No system is perfectly secure; if we become aware of a personal-data breach affecting you or your data, we will notify the responsible Customer and, where required, the competent authority and the persons concerned without undue delay.
12.Your rights
Depending on the law that applies to you, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to its processing, to receive it in a portable format, to withdraw consent, and to lodge a complaint with a supervisory authority (in the UAE, the UAE Data Office; in the EEA/UK, your local data protection authority). To exercise these rights, contact us as described in Section 15. We may need to verify your identity before acting on a request. Where we act as processor for a Customer, we will refer your request to that Customer and assist it in responding.
13.Children
Our website, platform and Player Software are business services and are not directed at children. We do not knowingly collect personal data from anyone under 18. A Customer that makes its content available to minors through the Player Software is responsible for the age-appropriateness of that content and for any parental-consent requirements that apply to it. If you believe a child has provided us with personal data, please contact us and we will delete it.
14.Changes to this Policy
We may update this Policy from time to time, for example when we add features to the Player Software or change our sub-processors. We will publish the revised version on this page with a new "Last updated" date and, for material changes affecting our Customers, make reasonable efforts to notify them. The version in force is always the one published here.
15.Contact
NagaOne FZCO
DSO-IFZA, Building A2, PO Box 342001
Dubai Silicon Oasis, Dubai, United Arab Emirates
For privacy requests, data-subject rights, or questions about this Policy, please use our contact form and select the topic "Legal", or write to the address above marked "Data Protection". If you are an End User of a player app, please contact the business that provided you with the app first; it is the controller of your account and viewing data.
