1. Overview
Diwan ("the App", "we", "our") is an enterprise Unified Communications application made available exclusively to employees and authorised users of organisations that have subscribed to the Diwan UCaaS service.
This Privacy Policy explains what information we collect when you use the App, why we collect it, how it is used, and your rights in relation to it.
2. Information We Collect
2.1 Account credentials
When you sign in, your username and password are transmitted securely to your organisation's UCaaS server for authentication. Credentials are stored in the device's encrypted secure storage solely to enable automatic re-authentication and are never sent to our servers.
2.2 Call data
- Voice audio captured by your microphone during active calls.
- Call metadata: caller/callee identifiers, call duration, timestamps, call direction.
- Voicemail audio files streamed from your organisation's PBX server.
Audio is transmitted point-to-point over encrypted WebRTC/SIP channels directly to your organisation's infrastructure. We do not record or store call audio.
2.3 Device & network information
- Device type and operating system version (for compatibility purposes).
- Push notification tokens (Firebase Cloud Messaging) used to deliver incoming-call alerts when the App is in the background.
- Network connectivity state (Wi-Fi / mobile data) used to manage the VoIP connection.
2.4 Contacts Optional
If you grant access, the App may read your device contacts to assist with dialling. Contact data is used locally on your device only and is never uploaded to our servers.
2.5 Information we do NOT collect
- Location data.
- Camera or photos.
- Browsing history or any data unrelated to communication.
- Any analytics or advertising identifiers.
3. How We Use Your Information
- Authenticate you with your organisation's UCaaS server.
- Establish and maintain VoIP calls over your organisation's SIP infrastructure.
- Deliver incoming-call push notifications via Firebase Cloud Messaging.
- Display your organisation's directory and call history.
- Maintain the background SIP connection so you do not miss calls.
We do not use your information for advertising, profiling, or any purpose outside the core communication functionality described above.
4. Data Sharing
We do not sell, rent, or trade your personal information. Data is shared only in the following limited circumstances:
- Your organisation: All call and account data is processed by your employer's UCaaS server, which is governed by your organisation's own data policies.
- Firebase (Google LLC): Used solely to deliver push notifications. Firebase processes device tokens in accordance with Google's Privacy Policy.
- Legal requirements: We may disclose information if required by applicable law or a valid legal process.
5. Data Retention
Credentials stored on-device are deleted when you sign out or uninstall the App. Call history and voicemail data reside on your organisation's servers and are subject to your organisation's retention policies. We do not independently retain call records.
6. Security
All data in transit is protected using TLS/HTTPS and SRTP for media streams. Credentials are stored in the device's OS-level encrypted keychain (iOS Keychain / Android Keystore). We apply industry-standard practices to protect your information, though no method of transmission over the internet is 100% secure.
7. Permissions
| Permission | Why it is needed |
|---|---|
| Microphone | Capturing audio during voice calls |
| Contacts | Looking up names when dialling (optional) |
| Notifications | Incoming call alerts and missed-call notifications |
| Bluetooth | Routing audio to Bluetooth headsets |
| Foreground Service | Keeping the SIP connection active while the App is in the background |
8. Children's Privacy
The App is intended exclusively for use by adults in an enterprise context. We do not knowingly collect information from anyone under the age of 16.
9. Your Rights
Depending on your jurisdiction you may have the right to access, correct, or request deletion of personal data we hold about you. Because most data is processed by your organisation's infrastructure, requests relating to call history, voicemail, or account data should be directed to your organisation's IT administrator. For any data held by us, contact us using the details below.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of the App after an update constitutes acceptance of the revised policy.
11. Contact Us
If you have any questions or concerns about this Privacy Policy, please contact:
Email: ccsupport@ejadtech.sa