Privacy Policy

This Privacy Policy explains how DISO Group FZCO, a company registered in Dubai, United Arab Emirates, processes your personal data when you interact with our website or services. This is done in compliance with the UAE Federal Law No. 45 of 2021 on the Protection of Personal Data (“PDPL”) and, where applicable, the EU General Data Protection Regulation (“GDPR”).

1. Responsible Entity
DISO Group FZCO
Dubai, United Arab Emirates
E-Mail: [email protected]
Responsible for data protection:
Vincent Hahl, Managing Director

2. Legal Basis for Processing
We process personal data under the following lawful bases:
– Consent (Art. 6 PDPL / Art. 6(1)(a) GDPR)
– Contractual necessity (Art. 4(6) PDPL / Art. 6(1)(b) GDPR)
– Legal obligation (Art. 4(9) PDPL / Art. 6(1)(c) GDPR)
– Legitimate interest (Art. 4(10) PDPL / Art. 6(1)(f) GDPR)

3. Data We Collect
We collect the following categories of personal data:
– Name, email address, business name, telephone number
– Technical data (e.g. IP address, browser type, device data, access times)
– Information entered into contact forms or when scheduling appointments via Calendly
– Website usage data collected through cookies and analytics tools (e.g. Google Analytics)

We do not collect resumes or job application data directly on our website.

4. Purpose of Processing
We process your data for the following purposes:
– Operating and optimizing our website (WordPress CMS)
– Responding to inquiries submitted via contact form or email
– Scheduling meetings and calls (e.g. via Calendly)
– Analyzing website traffic and usage trends (e.g. via Google Analytics)
– Ensuring technical security and server stability (GoDaddy hosting)

5. Your Rights under UAE PDPL and EU GDPR
You have the following rights:
– Access: Know what personal data we hold about you
– Correction: Request correction of inaccurate data
– Erasure: Request deletion of your data
– Objection: Object to the processing of your data
– Restriction: Request limited processing
– Data portability: Request your data in machine-readable format
– Withdrawal of consent: Revoke your consent at any time
– Automated decision-making: Not to be subject to solely automated decisions

To exercise any of these rights, please contact: [email protected].

6. International Data Transfers
We use third-party service providers that may transfer personal data outside the UAE and EEA:
– Google LLC / Google Ireland (Analytics, Workspace – United States, EEA)
– Cloudflare Inc. (Security & CDN – United States)
– Calendly LLC (Appointment scheduling – United States)
– GoDaddy (Web hosting and domain services – global infrastructure)

All transfers are subject to EU Standard Contractual Clauses (SCCs) and Data Processing Agreements (DPAs) in line with PDPL and GDPR.

7. Data Retention
Your data is stored only as long as necessary for the purpose of its collection, or as required by law. Emails or contact form entries are retained no longer than needed to process your request.

8. Data Security
We use up-to-date technical and organizational security measures to protect your personal data. These include:
– SSL encryption (HTTPS)
– Secure infrastructure hosted by GoDaddy
– Strict internal access controls
– Google Workspace for secure email handling

9. Cookies and Tracking Tools
We use cookies and third-party scripts for site analytics, performance, and basic functionality. You can manage your preferences using our Usercentrics Cookie Banner. Non-essential cookies (e.g. analytics) are only activated with your consent.
Details on each cookie used, its purpose, storage duration, and third-party providers can be found in our Cookie Policy.

10. Supervisory Authority – UAE Data Office
If you believe your data has been handled unlawfully, you may contact the UAE Data Protection Authority:
UAE Data Office
Abu Dhabi, United Arab Emirates
Website: https://www.uaedataoffice.gov.ae

11. Updates to This Policy
This Privacy Policy may be updated to reflect legal, technical, or business changes. The latest version is always available on our website.