Legal

Privacy notice.

What we collect, why we collect it, who it is shared with and what you can ask us to do about it.

Last updated 30 September 2026 · Questions: info@avanorconsulting.com

1. Who this notice is from

Shikara is an e-invoicing platform for businesses in the United Arab Emirates, and is a product of Avanor Consulting Services, a consultancy based in Ajman, United Arab Emirates (“Avanor”, “we”, “us”). Avanor Consulting Services is the entity responsible for the personal data described here. This notice covers the shikara.co website and the Shikara application.

For the personal data inside the invoices our customers issue, the customer is the controller and Avanor acts as a processor on their instructions. For account, billing and website data we are the controller ourselves. Where a customer is the controller, their own privacy notice governs how that data may be used, and requests about it are best sent to them — though we will always help.

2. What we collect

Account data

Name, work email address, phone number where you give it, role and permissions, the organisations you belong to, and authentication data. Passwords are stored only as salted hashes; we never see them.

Organisation data

Legal and trading name, tax registration number, trade licence details, emirate, address and bank details you enter for invoicing.

Document data

The invoices, credit notes, payments, customer and product records you create or import, including any personal data they contain — typically a contact name, email address or phone number for a buyer.

Usage and technical data

Log records of actions taken in the application (who issued or amended which document, and when), IP address, browser and device type, and timestamps. Audit logs of document actions are a compliance requirement and cannot be switched off.

Communications

Emails and support messages you send us, and the demo or enquiry details you provide.

We do not knowingly collect data from children, and the service is not directed at them. We do not collect special categories of personal data, and ask that you do not put any into invoice fields.

3. Why we use it, and on what basis

  • To provide the service — creating, validating, issuing and exchanging your documents, and keeping your records available to you. Necessary for the performance of our contract with you.
  • To meet legal and tax obligations — retaining issued documents and audit trails for the periods UAE tax law requires. Necessary for compliance with a legal obligation.
  • To keep the service secure — detecting and investigating unauthorised access, abuse and fraud. Our legitimate interest, and yours.
  • To support and improve the product — answering your requests and understanding which features are used. Our legitimate interest, using aggregated data wherever it will do.
  • To tell you about the service — changes to validation rules, mandate deadlines, downtime and releases. Necessary for the contract; product marketing is sent only with consent and every message can be unsubscribed from.

We do not sell personal data. We do not use your document data to train machine-learning models, and we do not share it with anyone for their own purposes.

4. Who we share it with

  • Your invoice recipients and their access points — issuing a document over the Peppol network means transmitting it to the buyer’s access point. This is the point of the service.
  • The Federal Tax Authority and other authorities — where the mandate or the law requires reporting or disclosure.
  • Service providers — cloud hosting and storage, email delivery, error monitoring, payment processing and customer support tooling. Each is bound by a written agreement, may process data only on our instructions, and may not use it for anything else.
  • Professional advisers and acquirers — auditors and lawyers under confidentiality, and, in a merger or acquisition, the counterparty under equivalent obligations. You would be told before any such transfer took effect.

A current list of our processors is available from info@avanorconsulting.com on request.

5. Where it is held

We host customer data in the United Arab Emirates where our providers offer it, and otherwise in a region with an equivalent standard of protection. Some of our service providers operate outside the UAE; where data is transferred abroad we rely on the safeguards permitted by UAE data protection law, including contractual protections with the recipient.

6. How long we keep it

Issued tax documents and their audit trails are retained for the period UAE tax legislation requires, which currently runs to several years after the end of the relevant tax period, and we cannot delete them earlier on request. Account data is kept while your account is active and for a limited period afterwards. Support correspondence is kept for two years. Security logs are kept for twelve months. Anything no longer needed is deleted or irreversibly anonymised.

7. Your rights

Subject to UAE data protection law and the retention obligations above, you may ask us to give you access to the personal data we hold about you, correct it if it is wrong, delete it, restrict or object to a particular use, provide it in a portable format, or withdraw a consent you gave.

Write to info@avanorconsulting.com. We respond within 30 days, and will ask you to verify your identity first. If your data reached us through a customer of ours, we will pass your request to them as the controller and tell you we have done so. If you are not satisfied with our answer, you may complain to the UAE Data Office.

8. Cookies and analytics

This website uses no advertising or tracking cookies and embeds no third-party trackers. Fonts are served from Google Fonts, which receives your IP address in order to deliver them. The application sets a session cookie that is strictly necessary to keep you signed in, and stores your interface preferences locally in your browser.

9. Security

Data is encrypted in transit with TLS and at rest. Access to production systems is restricted to named staff, over multi-factor authentication, on the principle of least privilege, and is logged. Passwords are hashed, never stored in a recoverable form. Backups are encrypted and tested. Each organisation’s data is isolated, and every document action is written to an immutable audit trail.

If a breach affects your personal data we will notify you and the relevant authority as required by law, without undue delay.

Suspected vulnerabilities should be reported to info@avanorconsulting.com. We acknowledge reports within one business day, will not pursue researchers who act in good faith and give us reasonable time to fix an issue, and ask that you do not access or alter data belonging to anyone else.

10. Changes to this notice

We update this notice when the service or the law changes. The date at the top always reflects the current version, and material changes are announced in the application or by email before they take effect.

11. Contact

Privacy questions and data requests: info@avanorconsulting.com. Anything else: get in touch.