Skip to main content

Domesta privacy policy

Version: v2.6

Effective Date: August 30, 2026

Last Updated: August 30, 2026

Controller: Domesta ("Domesta", "we", "us", "our")

Website: domesta.com

Contact (Support): info@domesta.com

Data Protection Officer (DPO): dpo@domesta.com

Registered Address: 3229 Greenpoint Ave, Suite 308, Long Island City, NY 11101, United States

This Policy explains how we collect, use, share, transfer, and protect personal data for households seeking domestic worker services ("Households," previously "Customers"), domestic workers ("Helpers," previously "Workers"), and licensed agencies ("Agents"). It is designed to comply with GDPR/UK-GDPR, GCC PDPLs (Bahrain, UAE, KSA, Oman, Qatar), and applicable Middle East laws (including Jordan, Egypt, Lebanon, and free-zones DIFC/ADGM), and to provide required notices to US residents (including CPRA/CCPA and other state laws). This Policy is governed by the laws of Delaware, USA, without prejudice to your mandatory rights under applicable local data-protection laws and without limiting the competence of local supervisory authorities.

Layered Summary (Highlights)

  • Who we are: Domesta is a marketplace connecting employers, workers, and agents. We act as the main data controller. Agents may independently process data for their own regulatory purposes.
  • What we collect: Contact details, ID documents, profiles, communications, payments, device data, cookies. Sensitive data only with explicit consent.
  • How we use it: Accounts, profiles, matching, messaging, payments, trust & safety, analytics. Marketing only with opt-in.
  • Your rights: Depending on your jurisdiction: access, correction, deletion, portability, objection, and withdrawal of consent.
  • How long we keep it: Billing data (7 years), account data (life + 24 months), ID images (30-90 days), logs (12 months).
  • Who we share with: Service providers only (hosting, payments, analytics). We do not sell personal information.
  • Cookies: Essential cookies always used. Analytics/optional cookies require consent. Manage via Cookie Preferences Center.
  • AI & Matching: Algorithms may rank or recommend profiles but do not make legally significant decisions without human input.
  • Children: Service is not for under-18s.
  • Contact: dpo@domesta.com.

1) What We Are & Roles

Domesta operates a marketplace connecting Households, Helpers, and Agents. Domesta is the data controller for platform operations (accounts, profiles, matching, trust & safety, payments). We engage processors (hosting/CDN, cloud storage, identity verification, payments, analytics, communications).

Agents may act as independent controllers for their own purposes (e.g., recruitment, visa processing). Domesta is not responsible for how Agents independently use or disclose data outside the platform. Agents must provide their own privacy notices.

Where required (e.g., EEA/UK), we will appoint local representatives under Article 27 GDPR/UK-GDPR and publish their contact details at domesta.com/legal/reps.

2) Notice at Collection (California/US)

We collect categories of personal information defined by CPRA, from specific sources and for defined purposes. Retention is limited to necessity, and disclosures are to service providers or other users only where relevant.

We do not sell personal information or share for cross-context behavioral advertising. If this changes, we will update this Policy, honor Global Privacy Control (GPC) signals, and provide a "Do Not Sell or Share My Personal Information" link.

3) Data We Collect

  • Account & Profile: name, email, phone, role, nationality, skills, experience, availability, photos/video, salary expectations.
  • Identity & Licensing: government-ID images, selfies/biometric comparisons, license documents (Agents).
  • Payments: billing identifiers and tokens (no full card numbers stored).
  • Communications: messages, scheduling, support requests.
  • Technical/Usage: IP, device/browser/OS, timestamps, events, coarse location, cookies, SDKs.
  • Sensitive Data: processed only if voluntarily provided, with explicit consent.

Sources: you (forms/uploads), your device (cookies/SDKs), trusted third parties (ID verification, payments, analytics).

4) Purposes & Legal Bases

  • Service delivery (accounts, matching, messaging): contract necessity.
  • Trust & safety (ID/license checks, fraud prevention): legitimate interests & legal obligation.
  • Payments & billing: contract necessity & legal obligation.
  • Support & communications: contract & legitimate interests.
  • Marketing: consent.
  • Analytics & improvement: legitimate interests, with opt-out/consent where required.
  • Compliance & enforcement: legal obligation & legitimate interests.

5) Sharing of Personal Data

We share limited data with service providers under contract (hosting, CDN, storage, ID verification, payments, analytics, communications). Information is disclosed to other users only to facilitate bookings (e.g., Helper profiles to Households). When a Helper applies to a Household's job post, their contact details are shared with that Household as part of the application, by their consent; withdrawing the application withdraws that consent. We may disclose to authorities as required or during corporate transactions.

We do not sell or share personal information for cross-context behavioral advertising.

6) Cookies & Preferences

We use necessary cookies for login and security. Non-essential cookies (analytics, personalization) require your consent in the Cookie Preferences Center, where you can view vendors, categories, and manage settings. If unavailable, contact us to have preferences honored manually.

We honor GPC and similar opt-out preference signals.

7) International Transfers

Your data may be processed in the US and other countries. We use appropriate safeguards for cross-border transfers, including:

  • EU/UK: SCCs and IDTA (or successor mechanisms).
  • KSA: SDAIA-approved SCCs or other permitted safeguards, with risk assessments where required.
  • DIFC/ADGM: local data-protection laws (DIFC DP Law 2020; ADGM DPR 2021).
  • Bahrain, Qatar, Oman, Egypt, Jordan: transfer conditions and adequacy/permit requirements as required.

8) Security & Breach Notice

We implement technical and organizational measures (encryption in transit, access controls, logging, least-privilege). No system is 100% secure. If a breach occurs, we will notify affected users and regulators without undue delay and within required timelines (e.g., 72 hours under GDPR; jurisdiction-specific timelines elsewhere).

9) Retention & Minimization

  • Billing/tax records: 7 years
  • Accounts/profiles: account life + 24 months of inactivity.
  • Messages/support tickets: account life or 24 months after closure
  • Server logs: 12 months
  • ID images/selfies: deleted in 30-90 days; verification results retained as needed
  • Dispute/chargeback records: 6 years
  • Marketing consents: 3 years from last contact
  • Biometric data: retention schedule at domesta.com/biometric-retention

10) Your Rights

Depending on jurisdiction, you may have rights to access, correct, delete, port, object, restrict processing, and withdraw consent. Requests can be made via dpo@domesta.com or in-product forms. We may verify your identity. We respond within 30-45 days (appeals within 45 days where required).

11) Biometric Information

If we use biometric identifiers (e.g., facial geometry for verification), we will obtain explicit consent, use only for verification and fraud prevention, not sell, publish a retention schedule, and destroy biometric data when the purpose is satisfied or as required by law.

12) Automated Decision-Making & AI Profiling

We do not make solely automated decisions with legal or significant effects.

However, algorithms may be used to rank or recommend worker profiles and job matches. These support efficiency but do not replace human decision-making. If fully automated decision-making is introduced in the future, we will provide additional disclosures, controls, and opt-out rights.

13) Children

The Service is not for under-18s. We do not knowingly collect children's data. Contact dpo@domesta.com if you believe we have.

14) Changes

Updates will be published here with a new effective date. Material changes will be notified via product notices or email.

15) Contact & Governing Law

  • DPO: dpo@domesta.com
  • Support: info@domesta.com
  • Post: Domesta, 3229 Greenpoint Ave, Suite 308, Long Island City, NY 11101, USA.
  • Governing law: Delaware, USA, subject to local mandatory rights and supervisory authorities.

16) Jurisdiction-Specific Notices (GCC & Middle East)

  • Bahrain: PDPL Law No. 30/2018, regulator PDPA. Consent/legal bases, 72-hour breach notice, transfer restrictions.
  • UAE: Federal Decree-Law No. 45/2021, regulator UAE Data Office. Free zones: DIFC DP Law 2020 and ADGM DPR 2021.
  • KSA: PDPL, regulator SDAIA. Effective September 2023, with updated transfer rules and DPO registration obligations.
  • Oman: PDPL Royal Decree 6/2022, in force February 2023. Consent-centric regime and transfer restrictions.
  • Qatar: Law No. 13/2016 PDPPL. Consent, rights of access/correction, breach notice.
  • Kuwait: CITRA Data Privacy Protection Regulation No. 26/2024 (sectoral scope for CITRA-licensed providers).
  • Jordan: Personal Data Protection Law No. 24 of 2023. Rights, duties, and oversight structures developing.
  • Egypt: Law No. 151 of 2020. Licensing requirements, 72-hour breach notice, transfer rules.
  • Lebanon: Law No. 81/2018 on Electronic Transactions & Personal Data. Sectoral enforcement framework.
  • Turkey (if targeted): KVKK Law No. 6698, including VERBIS registration.

Contact Information

For questions about our privacy practices or to exercise your rights, contact:

Data Protection Officer (DPO): dpo@domesta.com