MAJ LeadsMAJ Leads
PrivacyTermsCookiesDPA
MAJ Leads · Dubai, United Arab Emirates · hello@majleads.com

Privacy Policy

Last updated: 28 May 2026

MAJ Leads (“MAJ Leads”, “we”, “us”) operates the MAJ Leads Console at console.majleads.com for clients of our AI voice agent services in the United Arab Emirates. This policy explains what data we collect, why, where it lives, and how to exercise your rights under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, where applicable, the EU General Data Protection Regulation (GDPR).

1. Data we collect

  • Account data — email, name, hashed password, role, organisation. Provided by you or by the MAJ Leads administrator who provisions your account.
  • Voice agent telemetry — for calls placed or received by AI agents we operate on your behalf: call timestamps, durations, costs, outcomes, transcripts, and (where the caller did not opt out) audio recordings. Lead phone numbers and names supplied by you for outbound campaigns are also stored.
  • Operational data — bug reports you submit, calendar bookings, invoices, webhook events, and audit logs of admin actions taken on your account.
  • Technical data — session cookie, IP address (logged for abuse prevention and webhook source validation), basic device and browser information for error reporting.

We do not use third-party advertising trackers, Google Analytics, Meta Pixel, or any cross-site marketing pixels on the Console.

2. Why we collect it

  • To deliver the contracted voice agent service and keep your account working.
  • To meet UAE Telecommunications and Digital Government Regulatory Authority (TDRA) record-keeping requirements for outbound calling.
  • To bill you accurately for usage and to share monthly invoices.
  • To detect abuse, fraud, and security incidents.
  • To debug and improve the platform when you report an issue.

3. Where your data lives

  • Application database: Supabase (PostgreSQL), hosted in the ap-southeast-2 (Sydney, Australia) region — not in the UAE or EU. See section 9 for the data-residency and cross-border transfer implications.
  • File storage: Cloudflare R2 (primary) for call recordings and media files.
  • Hosting and edge: Vercel, with serverless functions executed in the region closest to the request.
  • Voice agent platform: Vapi (AI voice infrastructure), call recordings mirrored from Vapi to Cloudflare R2 subject to your retention setting.
  • Transcript scoring: Anthropic Claude API — transcripts are submitted for automated quality scoring.
  • Operational messaging: Green API (WhatsApp gateway) for sending you reports and invoices.
  • Automation: Make.com for orchestrating workflows you authorise.
  • Error tracking: Sentry, with all text masked and all media blocked in session replays.

The full list of sub-processors, their locations, and the data categories they receive is in section 10 below. Each processor is bound by a Data Processing Agreement or equivalent contractual safeguard.

4. How long we keep it

  • Account data — for the lifetime of your account, deleted within 30 days of closure.
  • Call transcripts and recordings — per the retention window configured on your account (default 45 days for transcripts, longer windows available for TDRA compliance). Automatic pruning runs daily.
  • Audit logs — retained for 24 months for fraud and dispute resolution.
  • Invoices — retained for 5 years to comply with UAE tax record-keeping requirements.

5. Your rights

Under UAE PDPL and, where applicable, GDPR, you have the right to access, correct, delete, restrict, port your data, and to withdraw consent. To exercise any of these rights, email hello@majleads.com. We respond within 30 days. Internally these are tracked as Data Subject Access Requests (DSAR) by our admin team.

6. Security

Data in transit is encrypted with TLS 1.2+. Data at rest is encrypted by our cloud providers. Access is role-gated and audited. Passwords are hashed with bcrypt by Supabase Auth. Webhook callbacks are signed with per-client HMAC secrets and verified with timing-safe comparison.

7. Contact

Questions, complaints, or data requests: hello@majleads.com. You may also lodge a complaint with the UAE Data Office or your local supervisory authority.

8. Changes

We may update this policy. Material changes will be notified by email or in-app banner at least 7 days before they take effect.

9. Data residency

Our primary database is not hosted in the UAE. MAJ Leads uses Supabase PostgreSQL deployed in the ap-southeast-2 (Sydney, Australia) region (AWS infrastructure). This means that account data, call metadata, transcripts, lead records, audit logs, and invoices are stored and processed in Australia.

Call recordings are stored in Cloudflare R2, whose global edge network means recordings may traverse and be cached in multiple countries. Voice calls are processed in real-time by Vapi (US infrastructure), and call transcripts are submitted to the Anthropic Claude API (US infrastructure) for automated quality scoring.

We are aware that this architecture constitutes cross-border personal data transfers under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021). The legal basis and safeguards for those transfers are described in section 11 below.

10. Sub-processors

The following third-party processors handle personal data on our behalf. We maintain a Data Processing Agreement or equivalent contractual safeguard with each.

ProcessorPurposeLocationData categories
Supabase (PostgreSQL)Managed relational database — stores all account data, call records, transcripts, lead lists, audit logs, and invoices.ap-southeast-2 (Sydney, Australia) — AWS infrastructure
  • Account data (email, name, organisation, role)
  • Call metadata (timestamps, duration, cost, outcome)
  • Transcripts
  • Lead phone numbers and names
  • Audit logs
  • Billing records
Cloudflare R2Object storage for call recordings and media files. Recordings are mirrored from Vapi and stored here per client retention settings.Cloudflare global network (primary bucket region configured per deployment)
  • Call audio recordings
  • Media attachments
VapiAI voice infrastructure — handles inbound and outbound call routing, real-time speech-to-text, LLM turn-taking, and post-call webhooks.United States (Vapi infrastructure)
  • Caller phone numbers
  • Call audio (in-flight, during the call)
  • Real-time transcripts
  • Post-call summaries
Green APIWhatsApp Business API gateway — sends clients automated reports, invoices, and campaign summaries via WhatsApp.Germany (Green API infrastructure)
  • Client WhatsApp numbers
  • Report contents (call summaries, lead counts)
Make.comNo-code automation platform — orchestrates workflows authorised by clients, such as CRM pushes, lead routing, and scheduled reports.European Union (Make.com infrastructure, EU region)
  • Workflow trigger payloads (may contain lead data or call outcomes)
  • API credentials scoped to client integrations
SentryApplication error and performance monitoring. Session replay is configured with all text masked and all media blocked.United States (Sentry infrastructure)
  • Error stack traces
  • Anonymised session identifiers
  • IP address (for abuse context, not stored long-term)
Anthropic (Claude API)AI model provider — transcripts are sent to Claude for automated quality scoring and conversation analysis.United States (Anthropic infrastructure)
  • Call transcripts (submitted for scoring)
  • Conversation text
Nodemailer / SMTP providerTransactional email delivery — password resets, account notifications, and invoice emails.Depends on configured SMTP relay (e.g., AWS SES eu-west-1 or equivalent)
  • Recipient email address
  • Email body content (notification text)

To request the current DPA with any sub-processor, email hello@majleads.com.

11. International transfers & Schrems II considerations

Transfers of personal data from the UAE (or from the EU/EEA for any European data subjects) to third countries are governed as follows:

  • UAE PDPL basis: Cross-border transfers under Federal Decree-Law No. 45 of 2021 (Article 22) require that the destination country provides an adequate level of protection, or that appropriate safeguards are in place (such as standard contractual clauses or binding corporate rules). We rely on contractual safeguards with each sub-processor listed in section 10 as our transfer mechanism.
  • Australia (Supabase): Australia has a comprehensive privacy framework (Privacy Act 1988, Australian Privacy Principles). We have a Data Processing Agreement with Supabase Inc. Supabase complies with GDPR standard contractual clauses for EU data subjects.
  • United States (Vapi, Sentry, Anthropic): The US does not hold a UAE or EU adequacy decision. Transfers to these processors rely on Standard Contractual Clauses (SCCs) under GDPR and equivalent contractual commitments under UAE PDPL. We have carried out a transfer impact assessment (TIA) for each US-based processor and assessed that, given the nature of the data (business operational data, not sensitive special-category data), the contractual and technical safeguards are sufficient.
  • EU (Make.com, Green API): Make.com operates within the EU and is subject to GDPR. Green API operates from Germany under GDPR. Both provide adequate protection for EU data subjects; contractual safeguards also apply for UAE-origin data.
  • Your rights regarding transfers: You may request a copy of the transfer impact assessment or the relevant SCCs by emailing hello@majleads.com. You may also object to the transfer of your personal data to a third country by exercising your rights under section 5, noting that doing so may make it impossible to continue providing the Service (which depends on the infrastructure above).

We monitor legal developments affecting cross-border data transfers (including post-Schrems II SCCs and any UAE adequacy decisions) and will update this section as the regulatory landscape evolves. The DPA page (legal/dpa) sets out the contractual framework in more detail.