2. Collection and processing
4. Transfer and cross-border transfer
5. Deletion and withdrawal of consent
1.1 These Regulations are governed by the PDPL (Decree-Law No. 45 of 2021) and internal privacy standards.
1.2. Compliance is mandatory for all employees with access to guests' personal data.
2.1. Data is collected directly from the client (at the front desk, via online form, or by phone).
2.2. Processing includes: collection, systematization, storage, use, anonymization, and deletion.
2.3. Processing is conducted solely for the provision of services or as required by law.
3.1. Only employees who have signed a confidentiality agreement have access to the data.
3.2. Data is protected by passwords, encryption, and storage on closed servers.
3.3. Paper documents are stored in locked cabinets.
4.1. We guarantee no data transfer except in the following cases:
- Legal obligation under UAE law;
- Necessity of service provision (e.g., payment processing through providers).
4.2. When transferring outside the UAE, it is verified whether the receiving country provides adequate data protection (in accordance with PDPL, Article 22).
The client may request data deletion or withdraw consent at any time. A response will be provided within 10 business days.
6.1. Staff are responsible for complying with data handling rules.
6.2. All complaints are reviewed by the internal data protection officer within 15 days.
6.3. In case of violation, the client may contact the UAE Data Office.