| Category | Data collected | Purpose | Retention |
|---|---|---|---|
| Account data | Email address, organisation name, role | Authentication, account management | Until deletion |
| DNS query logs | Domain queried, verdict (allowed/blocked/cached), timestamp, client IP (last octet masked by default) | Filtering, analytics, threat detection | 30 days |
| Agent telemetry | Uptime, query counts, blocklist version, platform (Linux/Windows) | Dashboard health monitoring | 90 days |
| Session data | Session token, login timestamp | Authentication security | 7 days |
| Billing data | Subscription plan, payment status (via Dodo Payments — we do not store card numbers) | Subscription management | 7 years (legal) |
| Support communications | Email content, ticket history | Customer support | 3 years |
We do not collect: DNS query content (only the domain name, not full URLs or page content), passwords in plain text, or any data from devices beyond the agent telemetry listed above.
We do not serve advertising or share your data with ad networks.
We share data only with the following categories of sub-processors, all subject to Data Processing Agreements:
| Sub-processor | Purpose | Location |
|---|---|---|
| Railway (PaaS) | Application hosting and database | Singapore / EU |
| Hetzner | DNS resolver infrastructure | Germany (EU) |
| Zoho Mail | Transactional email delivery | EU |
| Dodo Payments | Payment processing (no card data stored by us) | EU |
| Groq (optional) | AI threat analysis (query patterns only, no PII) | US |
| Cloudflare | DNS proxy and DDoS protection | Global edge |
We do not share data with any other third parties. If a sub-processor changes, we will update this page and notify affected customers by email at least 14 days in advance.
Under UK GDPR, EU GDPR, and the Saudi PDPL, you have the right to:
To exercise any right, email [email protected]. We will respond within 30 days. Account deletion can also be self-served from the dashboard under Settings → Account.
If you believe we have handled your data unlawfully, you may lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or your local supervisory authority.
In the event of a data breach that is likely to result in risk to your rights, we will notify affected users and the relevant supervisory authority within 72 hours of becoming aware.
Our dashboard (dns.tareeq.one) uses no third-party cookies, analytics scripts, or tracking pixels. We use a single first-party session cookie to maintain your logged-in state. This cookie is:
HttpOnly and SecureThe marketing website (tareeq.one) does not use any tracking scripts. No Google Analytics, no Meta Pixel.
Our service is intended for business and adult personal use. We do not knowingly collect personal data from children under the age of 16. If you believe a child has provided us with personal data, please contact [email protected] and we will delete it promptly.
Note: Tareeq's DNS filtering service is commonly used by families to protect children's devices — in this context, the account holder (parent/guardian) is the data subject, not the child.
We may update this Privacy Policy from time to time. When we make material changes, we will:
Continued use of the service after the effective date constitutes acceptance of the updated policy.
Contact our privacy team at [email protected]. We aim to respond within 5 business days. For formal data subject requests, we respond within 30 days as required by law.
Tareeq Technologies Ltd · Registered in England and Wales · Data Processing Agreement →