←

Privacy Policy

Last updated: 5 September 2026

Controller

Ali Talebpoor Amirhandeh, trading as Ahura, [آدرس قابلِ‌ابلاغ / Postal address]. Privacy contact: [ایمیل / email]. This notice covers bidar.ahura.cloud and the related Bidar services.

Data we process

Account and sign-in data (such as email and session identifiers), support requests, submitted contributions and sources, language and accessibility settings, technical and security data, and—when you buy—transaction and entitlement status. Bidar does not store full payment-card details.

Purposes and legal bases

We process data to provide accounts, the book and requested features under Art. 6(1)(b) GDPR; protect the service and prevent abuse under legitimate interests, Art. 6(1)(f); send an optional newsletter or optional analytics with consent, Art. 6(1)(a); and retain required financial records under Art. 6(1)(c).

AI features and submitted content

Only when you invoke an AI feature is the text needed for the response sent to the configured model provider. Private content is not sold for advertising. Do not enter confidential or highly sensitive information into AI fields.

Payments

If Paddle is shown at checkout, the Paddle entity identified there acts as merchant of record and processes payment and tax data under its own privacy notice. Bidar normally receives only email, customer/transaction identifiers, product, amount, currency, and payment or refund status.

Cookies and analytics

Essential cookies support sessions, language and security. Google Analytics and Ahura's aggregate portfolio counter activate only after explicit consent. The aggregate counter records page path, acquisition channel and high-level usage events; it stores no IP address, email, user ID, search query or user content. Consent may be withdrawn through the privacy settings at any time. Device preferences may be stored locally in localStorage.

Recipients and international transfers

We share data only with hosting, email, payment, database and AI providers needed to deliver the service. Where processing occurs outside the EEA, we use a valid safeguard such as an adequacy decision or Standard Contractual Clauses.

Retention

Account data is kept while active and normally deleted within 30 days after account closure; backups cycle out within 90 days; security logs are normally kept for 90 days; support correspondence for up to 24 months; and financial records for the statutory period. Necessary records may be held longer for an active dispute or abuse investigation.

Your rights

You may request access, correction, deletion, restriction, portability or object, and may withdraw consent, by emailing [ایمیل / email]. You may also complain to a data-protection authority, including the Hamburg Commissioner for Data Protection and Freedom of Information.

Security, children and changes

We use access controls, encryption in transit and security logging. Purchases are for people aged 18 or over. Material changes are dated on this page and do not reduce mandatory rights.