1. Introduction
Welcome to TenancyDesk ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our property management platform and related services (the "Service").
TenancyDesk is a B2B SaaS platform designed for property management companies, real estate agencies, and property professionals in the United Arab Emirates. We process data on behalf of our business customers and their clients (tenants, property owners).
This Privacy Policy describes how we handle your personal data. We process most data based on contractual necessity and legitimate interests (see Section 5). Where we rely on consent, we will obtain it separately and explicitly.
2. Data Controller
For the purposes of UAE Federal Decree Law No. 45/2021 on Personal Data Protection (PDPL) and other applicable data protection laws, the data controller is the operator of TenancyDesk.
Data-protection contact: privacy@tenancydesk.com. Operator legal details are available upon written request to the same address.
When processing personal data on behalf of our business customers (property management companies), we act as a "Data Processor." Our customers remain the "Data Controllers" for their client data.
We provide a standard Data Processing Agreement (DPA) template available upon request. Business customers execute the DPA at onboarding to define the scope, purpose, and duration of data processing, and each party's obligations under UAE PDPL.
If you are a tenant or property owner whose data is managed through our platform by a property management company, that company is the data controller for your information. Please contact them directly for data protection requests related to their use of your data.
3. Data We Collect
We collect and process different categories of personal data depending on your relationship with us:
3.1 Account Information
When you register for TenancyDesk, we collect:
- Full name and contact details (email, phone number)
- Company name and business registration details
- Job title and role within the organization
- Login credentials (password stored in encrypted form)
3.2 Property & Transaction Data
In the course of using our Service, you may input:
- Property details (addresses, unit numbers, descriptions)
- Owner information (names, contact details)
- Tenant information (names, Emirates ID numbers, passport details, contact information)
- Lease terms and rental agreements
- Payment schedules and transaction records
3.3 Document Data
Our AI-powered document extraction feature processes:
- Emirates ID cards
- Passports and visas
- Tenancy contracts
- Title deeds and property documents
- Ejari certificates
Important: documents you upload are stored in your account so they remain available for your deals and compliance records, and we extract text data from them for the features you use. Uploaded images are not discarded after extraction. Identity-document images (Emirates ID, passport) are deleted within 90 days of account termination.
3.4 Usage Data
We automatically collect:
- Log data (IP address, browser type, device information)
- Feature usage patterns and interactions
- Performance metrics and error logs
- Session duration and navigation paths
3.5 Communication Data
When you use our WhatsApp notification feature:
- Phone numbers of message recipients
- Message content and delivery status
- Communication timestamps
WhatsApp notifications are sent via Meta's WhatsApp Business API. Recipients must opt-in to receive notifications. Meta may process message metadata in accordance with their own privacy policy. WhatsApp Business API messages are not end-to-end encrypted in the same manner as personal WhatsApp messages.
3.6 Sensitive Personal Data
Our Service processes government-issued identification numbers and identity-document images. Under the UAE PDPL, "Sensitive Personal Data" is a specific category defined in Article 1; government-issued identification numbers and identity-document images fall outside that statutory category and are treated as high-risk Personal Data. Regardless of the label, we apply enhanced safeguards to this data:
- Access restricted to authorized personnel only
- Encryption at rest via AWS storage-layer encryption (AES-256) and in transit (TLS 1.2+)
- Identity numbers (Emirates ID, passport, trade licence) additionally encrypted at the application layer before they are stored
- Shorter retention for saved identity-document images, which are deleted within 90 days of account termination
- Processing only when strictly necessary for the service you have requested
4. How We Use Your Data
We process your personal data for the following purposes:
4.1 Service Delivery
- Providing access to the TenancyDesk platform
- Processing property and tenancy transactions
- Generating documents, reports, and analytics
- Facilitating Ejari preparation and compliance tracking
- Sending notifications and reminders via email or WhatsApp
4.2 AI-Powered Processing
- Extracting information from uploaded documents
- Auto-classifying documents by type
- Analyzing contract terms for compliance risks
Your data is NOT used to train AI models. We rely on non-training API agreements with our AI service providers (Google and Anthropic). These providers process data under those terms and retain it only for a limited period, in accordance with each provider's own policy, for abuse-detection and operational purposes, after which it is purged. Document data is transmitted via encrypted channels. For details on each provider's retention, refer to their respective privacy policies.
4.3 Compliance & Security
- UAE regulatory compliance (RERA, DLD, Ejari)
- Fraud prevention and security monitoring
- Audit trail maintenance
- Legal obligation compliance
4.4 Service Improvement
- Analyzing usage patterns to enhance features
- Developing new functionality based on user needs
- Conducting research and analytics
4.5 Communication
- Customer support and technical assistance
- Service updates and announcements
5. Legal Basis for Processing
Under UAE PDPL and applicable data protection laws, we process your data based on:
| Purpose | Legal Basis |
|---|---|
| Service delivery | Contract performance |
| Account management | Contract performance |
| Compliance & regulatory | Legal obligation |
| Security & fraud prevention | Legitimate interest |
| Service improvement | Legitimate interest |
| Analytics & research | Legitimate interest |
| AI document processing | Contract performance / Legitimate interest |
Where we rely on legitimate interest, we conduct a balancing test to ensure our interests do not override your rights and freedoms. You may request details of our legitimate interest assessments by contacting us.
6. Data Sharing & Third Parties
We may share your personal data with the following categories of recipients:
6.1 Service Providers
- Cloud Infrastructure & Email:
- Payment Processing (Merchant of Record):
- WhatsApp Messaging:
- AI Processing:
- SMS:
- Network & Security:
- Error Monitoring:
- Email Failover:
We maintain an up-to-date list of sub-processors on this page. We will notify business customers in advance of material sub-processor changes where commercially reasonable, providing them the opportunity to object.
6.2 Business Customers
When acting as a data processor, we only process customer data according to their instructions and our Data Processing Agreement (DPA). Our business customers are the data controllers for their client information and are responsible for obtaining necessary consents from their clients.
6.3 Legal Requirements
We may disclose data when required to:
- Comply with UAE laws and regulations
- Respond to lawful requests from public authorities
- Protect our rights, privacy, safety, or property
- Enforce our terms of service
6.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity with appropriate safeguards.
7. International Data Transfers
TenancyDesk processes data on AWS managed cloud infrastructure with documented data flows. Some data is transferred to our service providers in other jurisdictions as detailed below.
When data is transferred outside the UAE, we rely on the safeguards permitted by UAE PDPL Articles 22-23:
- Where the recipient jurisdiction has been designated as providing an adequate level of protection, we rely on that designation (PDPL Article 22)
- Otherwise, we rely on a contract that binds the recipient to obligations equivalent to the PDPL, or on your explicit consent, as permitted by PDPL Article 23
- Appropriate technical and organizational measures are implemented for every transfer
- Each transfer is assessed and documented before it begins
| Provider | Data Transferred | Country | Safeguards |
|---|---|---|---|
| AWS (Hosting) | All platform data | Germany (eu-central-1, Frankfurt) | ISO 27001, SOC 2 (AWS infrastructure), contractual safeguards (PDPL Art. 23) |
| Paddle.com Inc. (Merchant of Record) | Subscription billing data, payment-method tokens, customer email and tax-residence indicator | United States (Paddle.com Inc.) / United Kingdom (Paddle.com Market Ltd.) | MoR arrangement, SOC 2, PCI DSS Level 1, contractual safeguards (PDPL Art. 23) |
| Google / Anthropic | Document text for AI processing | United States | Non-training API, contractual safeguards (PDPL Art. 23) |
| Meta (WhatsApp) | Phone numbers, message metadata | United States | Meta DPA, contractual safeguards (PDPL Art. 23) |
| Resend | Email addresses | United States | Contractual safeguards (PDPL Art. 23) |
| Sentry | Error logs, device info | United States | SOC 2, contractual safeguards (PDPL Art. 23) |
| Twilio | Phone numbers, message metadata | United States | ISO 27001, contractual safeguards (PDPL Art. 23) |
Transfers to providers outside the UAE are made on a basis permitted by UAE PDPL Articles 22-23 - an adequacy designation where one applies, otherwise a contract binding the recipient to obligations equivalent to the PDPL, or your explicit consent. These are supported by supplementary technical safeguards including encryption in transit (TLS 1.2+) and at rest (AES-256). We assess the legal framework of recipient countries on a risk basis and apply additional measures where necessary.
8. Data Retention
We retain your personal data for as long as necessary to fulfill the purposes outlined in this policy. Targets below are implemented to the extent technically feasible at our current operational scale; where automated purge is not yet in place, manual purge cycles apply on customer request or at account termination.
| Data Type | Retention Period |
|---|---|
| Business registration details | Duration of account + the applicable statutory retention period |
| Personal contact details | Duration of account + statutory limitation period |
| Commercial books and supporting records | At least 5 years (UAE Federal Decree-Law No. 50/2022, Article 29) |
| Identity documents (Emirates ID, passport) | Minimised; deleted within 90 days of account termination |
| Documents | As defined by customer + statutory limitation period |
| Usage logs | Up to 2 years |
Upon account termination, we provide a data export option and delete your data within 90 days, except where retention is required by law.
Identity documents (Emirates ID, passport) are minimised and deleted within 90 days of account termination. Commercial books and their supporting records are retained for at least 5 years under UAE Federal Decree-Law No. 50/2022, Article 29. Other records are retained for the period required by their own legal basis (for example tax and VAT obligations, or anti-money-laundering requirements) - there is no single blanket retention period for all data.
9. Your Rights
Under UAE PDPL and applicable data protection laws, you have the following rights:
9.1 Right to Access
You can request a copy of the personal data we hold about you.
9.2 Right to Rectification
You can request correction of inaccurate or incomplete data.
9.3 Right to Erasure
You can request deletion of your data. Exceptions include data we are required to retain by law (e.g., transaction records under UAE Commercial Transactions Law), data necessary for ongoing dispute resolution, or data needed to fulfill our contractual obligations.
9.4 Right to Restrict Processing
You can request limitation of how we process your data.
9.5 Right to Data Portability
You can receive your data in a structured, machine-readable format.
9.6 Right to Object
You can object to processing based on legitimate interests.
9.7 Right to Withdraw Consent
Where processing is based on consent, you can withdraw it at any time.
9.8 Rights Related to Automated Processing
You have the right not to be subject to decisions based solely on automated processing that produce significant effects. Our AI features assist in data extraction and analysis but do not make autonomous decisions about your tenancy or legal rights.
To exercise your rights, contact us at privacy@tenancydesk.com. We will respond within a reasonable timeframe as required by applicable law. To verify your identity, we may request additional information. If you are a tenant or property owner whose data is managed by one of our business customers, we may redirect your request to the appropriate data controller. You may also lodge a complaint with the UAE Data Office.
10. Security Measures
We implement comprehensive security measures to protect your data:
Technical Safeguards
- AES-256 encryption for data at rest (AWS managed)
- TLS 1.2+ encryption for data in transit
- Multi-factor authentication (MFA) support
- Continuous automated vulnerability scanning (Dependabot, pip-audit, npm-audit)
- Security audits on a risk-based cadence
- Secure development practices and code review
Organizational Safeguards
- Role-based access control (RBAC) across all user accounts
- Principle of least privilege for system access
- Audit logging for sensitive data access and administrative actions
Infrastructure Security
- AWS data centers with ISO 27001 certification (eu-central-1, Frankfurt)
- Single-region hosting with automated backups
- Continuous infrastructure monitoring (CloudWatch)
- DDoS protection via AWS Shield Standard
11. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the UAE Data Office - and, where required, the affected individuals - without undue delay and within any period set by the UAE PDPL (Federal Decree-Law No. 45/2021) and its Executive Regulations.
As an internal operational target - not a statutory deadline - we aim to notify the Data Office within 72 hours of becoming aware of a breach. Our notification will describe the nature of the breach, its likely consequences, and the measures taken to address it and mitigate its effects.
13. Children's Privacy
TenancyDesk is a B2B service intended for business use only. We do not knowingly collect personal data from individuals under 18 years of age. If you believe we have collected data from a minor, please contact us immediately at privacy@tenancydesk.com.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. For significant changes, we will notify you via email or in-app notification.
We encourage you to review this policy periodically to stay informed about how we protect your data.
15. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
Privacy contact
Email: privacy@tenancydesk.com
General: hello@tenancydesk.com
Dubai, United Arab Emirates
You also have the right to lodge a complaint with the UAE Data Office (dataoffice.ae) if you believe your data protection rights have been violated.