1. Who We Are
The Drix is a company specializing in software development and digital solutions, based in Aleppo, Syria.
For the purposes of this Policy, The Drix is the controller of personal data collected through its website or communication channels, unless otherwise stated.
2. Scope of This Policy
This Policy applies to personal data we obtain through:
- The Drix website. - Contact forms and requests for consultations or quotations. - Communications with us by email, telephone, WhatsApp, or social media. - Advertising forms or lead-generation forms we publish through third-party platforms. - Transactions related to requesting or providing The Drix services. - Technical data generated through use of the website, to the extent such data is collected.
This Policy does not govern third-party websites or services, even where they are accessed through links available on our website.
3. Data We May Collect
Depending on how you interact with us, we may collect the following categories of data:
Data you provide directly
This may include:
- Your name. - Email address. - Telephone number or WhatsApp number when provided. - Company or business name when provided. - Information included in messages and inquiries. - Details of the project or service you wish to discuss with us. - Any other information you choose to provide while communicating with us.
Please do not send sensitive personal data unless it is clearly necessary for the purpose of the communication and its processing has been agreed upon.
Technical data
When you use the website, the website systems or technical service providers may record limited technical information, such as:
- IP address. - Device and browser type. - Operating system. - Date and time of visit. - Pages visited. - Referral or traffic source. - Technical information related to website performance and security.
Some of this information may be collected through cookies or similar technologies as described in this Policy.
4. Why We Use Your Data
We process personal data only for specific purposes related to our business, including:
- Responding to inquiries and messages. - Communicating with you regarding a service request or consultation. - Preparing quotations and proposals. - Taking steps requested by you before entering into a contract. - Delivering and managing services agreed with clients. - Providing technical support and post-delivery services. - Managing our commercial relationship with clients. - Protecting the website and systems and detecting unlawful use or security issues. - Diagnosing faults and improving website performance and user experience. - Complying with legal or regulatory requirements applicable to us. - Sending marketing communications only where a lawful basis and any required consent are available.
We will not use personal data for a new purpose that is materially incompatible with the purpose for which it was collected without taking the steps required by law.
5. Legal Basis for Processing
Depending on the nature of the processing, our processing of your personal data may rely on one or more legal bases permitted by applicable law, including:
- Your consent to processing for a specified purpose. - Taking steps at your request before entering into a contract. - Performance of a contract to which you are a party. - Compliance with legal or regulatory obligations. - Other circumstances permitted under applicable law.
Where processing is based on your consent, you may withdraw that consent in accordance with applicable law, without affecting the lawfulness of processing carried out before the withdrawal.
6. Cookies and Measurement Technologies
The website may use cookies and similar technologies to operate and protect the website, measure its performance, and understand how visitors use it.
These technologies may include:
- Cookies necessary for website operation and security. - Technologies used to measure performance and usage. - Analytics tools. - Measurement technologies associated with advertising campaigns, where enabled.
Where applicable law requires consent before non-essential cookies or technologies are used, such technologies will be used on the basis of the required consent.
You may also control cookies through your browser settings or tools made available on the website. Disabling certain essential technologies may affect the operation of some website features.
7. Marketing and Advertising Communications
We do not use contact information to send direct marketing communications except in accordance with conditions permitted by law, including obtaining consent where required.
You may request that marketing communications stop or withdraw your consent at any time through the unsubscribe method provided in the message or by contacting us.
Opting out of marketing communications does not affect communications that are necessary in connection with an existing contract or a service you have requested.
8. Sharing Data with Third Parties
The Drix does not sell or rent personal data.
We may make a limited amount of data available to third parties where necessary to provide services or operate our business, including:
- Hosting and technical infrastructure providers. - Email and communications service providers. - Technical and security service providers. - Analytics, performance measurement, or advertising services where used. - The Drix employees and authorized contractors who require access to perform their duties. - Legal or professional advisers where necessary. - Government, judicial, or regulatory authorities where disclosure is required by law.
We limit data sharing to what is necessary for the relevant purpose and seek to work with parties that provide an appropriate level of data protection.
9. Transfers of Data Outside Syria
Certain technical, hosting, or communications services may require personal data to be processed by service providers operating outside the Syrian Arab Republic.
Where this occurs, transfers are handled in accordance with applicable legal requirements relating to cross-border transfers of personal data, including any requirements relating to consent, authorization, or an adequate level of protection where applicable.
10. Data Retention
We do not retain personal data for longer than is necessary to achieve the purpose for which it was collected or processed, unless legitimate legal reasons require it to be retained for a longer period.
Retention periods vary depending on the nature of the data and the purpose for which it is used. For example:
- Inquiry data: until the inquiry and related follow-up have been completed, after which it is deleted when there is no longer a legitimate need to retain it. - Client, project, and contract data: for the duration necessary to deliver the service and then for any additional period required by legal, accounting, or contractual obligations. - Marketing data: until consent is withdrawn or the purpose for using the data ends. - Technical and security logs: for the period necessary for operation, security, and investigation of technical issues.
When there is no longer a legitimate need to retain personal data, we delete it or anonymize it where appropriate.
11. Data Security
We take appropriate technical and organizational measures to protect personal data against:
- Unauthorized access. - Unlawful use or disclosure. - Unauthorized alteration. - Accidental loss or destruction. - Breach or misuse.
Access to personal data is restricted according to business need and applicable permissions.
However, no method of transmitting or storing data over the Internet can be guaranteed to be completely secure. We therefore work to reduce risks by using safeguards appropriate to the nature of the data and processing.
12. Your Rights Regarding Your Data
Depending on the law applicable to your circumstances, you may have rights relating to your personal data, including:
- Knowing what data is being processed and the purpose of the processing. - Requesting access to your personal data. - Requesting a copy of the data available about you. - Knowing the retention period or the criteria used to determine it. - Requesting correction or updating of inaccurate data. - Requesting deletion of data where the legal conditions for deletion are met. - Withdrawing your consent where processing is based on consent. - Requesting restriction of processing or limiting it to a specific purpose or scope where permitted by law. - Objecting to certain processing activities in accordance with applicable law. - Receiving information about a personal data breach where the law requires that you be notified. - Lodging a complaint with the competent data protection authority where you have the right to do so.
We will handle requests relating to these rights within the periods and procedures established by applicable law.
We may request sufficient information to verify the identity of the person making the request before fulfilling a request relating to personal data, in order to protect the data from disclosure to an unauthorized party.
13. Children's Data
The Drix website and services are primarily directed toward businesses, business owners, and professionals, and we do not target the collection of children's data.
We do not knowingly process personal data relating to children where applicable law requires the consent of a parent or legal guardian without obtaining the required consent.
If we become aware that a child's data has been collected unlawfully, we will take appropriate steps to address it in accordance with applicable law.
14. Third-Party Websites and Platforms
The website may contain links to external platforms or services such as social networks or communication applications.
When you access an external service, processing carried out by that service is governed by its own privacy policy and terms, and The Drix does not control the independent privacy practices of those third parties.
Personal data that you send to us through such platforms and that is received and processed by The Drix is also subject to this Policy to the extent applicable.
15. Updates to This Privacy Policy
We may update this Policy as a result of changes to our services, our data-processing practices, or applicable legal and regulatory requirements.
The updated version will be published on this page together with the date of the latest update.
Changes take effect from the date they are published unless another effective date is stated.
16. Applicable Law
Personal data is processed by The Drix in accordance with applicable laws and regulations, including Law No. 12 of 2024 concerning the protection of personal data in the Syrian Arab Republic, together with any applicable instructions or regulatory decisions related to it.
Where another law applies to the processing of a particular user's data and grants additional rights, those rights will be observed to the extent that such law applies.
17. Contact Us
For questions relating to this Policy, information about how we process your personal data, or requests to exercise your data-protection rights, you may contact:
The Drix
Aleppo, Syrian Arab Republic
Email: [email protected]
Phone / WhatsApp: +963 940 301 530
Please include “Privacy Request / طلب خصوصية” in the subject line when contacting us about your personal data.
