
We have appointed a dedicated Data Protection Officer (DPO) responsible for coordinating privacy compliance management and responding to data-related inquiries and requests. Customers can reach the DPO via:
Email: dpo@smartdeer.com
- Storage Location: Data is stored by default in the customer's local region or on compliant international cloud server nodes (compliant regions).
- Compliance: Fully compliant with major global data protection regulations, including the GDPR, CCPA, and PDPA, ensuring that data processing workflows meet local legal requirements.
We are ISO 27001 certified and undergo annual regulatory audits to ensure continued compliance with international information security management system requirements.
Transmission Layer
Uses SSL/TLS 1.2+ encryption protocols to ensure all data is encrypted during transit.
Storage Layer
Data is encrypted at rest using the AES-256 algorithm, with regular backups and disaster recovery drills.
Access Control
Implementation of Multi-Factor Authentication (MFA), Role-Based Access Control (RBAC), and full audit logging of all operations.
Security Protection
Real-time intrusion detection, regular penetration testing, and vulnerability scanning/patching to defend against malicious attacks.
- Immediate Response: We instantly activate our emergency response mechanism to block the source of the leak and assess the scope and impact.
- Notification: We will notify affected parties within a reasonable timeframe, providing details of the leak, progress of the resolution, and protective recommendations (assisting with regulatory reporting where necessary).
- Support: We cooperate with customers to complete regulatory filings and assist in minimizing business impact.
We do not sell customer data, nor do we disclose customer business data to third parties without authorization. Relevant data will only be processed by bound service providers in accordance with the principle of minimum necessity under the following circumstances: when it is essential for the provision of our services, upon explicit authorization from the customer, or in compliance with legal and regulatory requirements. We exercise oversight over such processing through contractual agreements and security safeguards.
The platform adheres to multiple international privacy standards, including:
- DIFC Compliance: Adheres to data processing requirements and obligations within the Dubai International Financial Centre.
- PDPA Compliance: Processes and protects data in accordance with Personal Data Protection Act requirements.
- GDPR Compliance: Ensures the standardization and security of data processing workflows according to General Data Protection Regulation standards.


