Privacy Policy

Version 2.0 — Last updated: 30 April 2026

DXB Property Match — Privacy Policy

DXB Property Match ("we", "our", "us") is committed to protecting your privacy and personal data. This policy explains how we collect, use, store, and protect your information in compliance with the EU General Data Protection Regulation (GDPR), UAE Personal Data Protection Law (PDPL), and applicable real estate regulations.

1. Information We Collect

Personal Information: When you register, we collect your name, email address, phone number, and profile details you provide.

Property Preferences: Budget range, preferred locations, property types, and search criteria you submit.

KYC Documents: Identity documents (Emirates ID, passport), financial documents (proof of funds, mortgage pre-approval) uploaded for buyer verification. These are processed securely and stored with encryption.

Communication Data: Messages exchanged with agents, booking details, and proposal interactions.

Usage Data: Pages visited, features used, and interaction patterns to improve our platform. This data is anonymised where possible.

Device Information: Browser type, device type, IP address, and operating system for security and platform optimisation.

2. How We Use Your Data

Property Matching: To match you with suitable properties based on your stated preferences and budget.

Communication: To facilitate communication between buyers and agents, send booking confirmations, proposal updates, and viewing reminders.

AI-Powered Features: To provide AI-generated property recommendations, market insights, lead scoring, and automated follow-ups.

Platform Improvement: To analyse usage patterns (in aggregate) and improve platform features and performance.

Legal Compliance: To comply with UAE real estate regulations, AML/KYC requirements, and RERA guidelines.

Security: To detect and prevent fraud, unauthorised access, and other security threats.

3. Legal Basis for Processing (GDPR)

Consent: For marketing communications, analytics cookies, and AI-powered recommendations. You can withdraw consent at any time.

Contractual Necessity: Processing required to provide our property matching and booking services.

Legitimate Interest: Platform security, fraud prevention, and service improvement using anonymised data.

Legal Obligation: KYC/AML compliance as required by UAE law and RERA regulations.

4. Data Sharing

We share your data only in the following circumstances:

With Agents/Brokers: Your property preferences and contact details are shared with agents you choose to interact with (e.g., when booking a viewing or receiving a proposal).

Within Your Organisation: If you belong to a brokerage, authorised team members may access shared leads and properties.

Service Providers: We use trusted third-party services for email delivery, payment processing (Stripe), and AI processing. These providers are bound by data processing agreements.

Legal Requirements: When required by UAE law, court order, or regulatory authority.

We do not sell your personal data to third parties.

5. Data Retention

Active Accounts: Your data is retained for as long as your account is active.

Inactive Accounts: Data is retained for 24 months after last activity, then anonymised or deleted.

KYC Documents: Retained for the legally required period (typically 5 years) as per UAE AML regulations, then securely destroyed.

Communication Logs: Retained for 12 months for dispute resolution, then archived or deleted.

Analytics Data: Aggregated and anonymised data may be retained indefinitely for platform improvement.

6. Your Rights (GDPR & UAE PDPL)

You have the following rights regarding your personal data:

Right of Access: Request a copy of all personal data we hold about you.

Right to Rectification: Correct any inaccurate or incomplete data.

Right to Erasure: Request deletion of your personal data (subject to legal retention requirements).

Right to Data Portability: Receive your data in a structured, machine-readable format.

Right to Restrict Processing: Limit how we use your data while a concern is being resolved.

Right to Object: Object to processing based on legitimate interests or for direct marketing.

Right to Withdraw Consent: Withdraw previously given consent at any time.

To exercise any of these rights, visit your Account Settings > Data & Privacy section or contact our Data Protection Officer.

7. Data Deletion & Account Closure

You can request complete deletion of your account and associated data at any time through your account settings.

Upon deletion request, we will:

• Remove your profile, preferences, and communication history within 30 days

• Anonymise any data required for legal compliance (KYC records)

• Remove your data from all active processing and backups within 90 days

• Send you a confirmation email once deletion is complete

8. International Data Transfers

Your data may be processed outside the UAE and European Economic Area (EEA) by trusted third-party services. Specifically:

Payment Processing: Stripe, Inc. (United States) — processes subscription payments under Standard Contractual Clauses (SCCs) and is certified under the EU-US Data Privacy Framework.

AI Processing: AI-powered features (property matching, lead scoring, market insights) may be processed on servers located outside the UAE/EEA. All data is encrypted in transit and at rest.

Cloud Infrastructure: Platform hosting and data storage uses industry-standard cloud providers with ISO 27001 certification and appropriate data processing agreements.

We ensure all international transfers are protected by at least one of the following safeguards: Standard Contractual Clauses (SCCs), adequacy decisions, or binding corporate rules, in accordance with GDPR Chapter V and UAE PDPL Article 22.

9. Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we are committed to the following response protocol:

Regulatory Notification: We will notify the relevant supervisory authority within 72 hours of becoming aware of a qualifying breach, as required by GDPR Article 33.

User Notification: If the breach is likely to result in a high risk to your rights, we will notify affected individuals without undue delay via email and in-app notification, as required by GDPR Article 34.

Breach Record: All breaches, including those not requiring notification, are documented in our internal breach register with details of the incident, its effects, and remedial actions taken.

Mitigation: We maintain an incident response plan that includes immediate containment, impact assessment, root cause analysis, and preventive measures to reduce the likelihood of recurrence.

10. Data Processing Agreements

We maintain formal Data Processing Agreements (DPAs) with all third-party service providers who process personal data on our behalf, as required by GDPR Article 28. These agreements ensure:

Processing Limitations: Sub-processors may only process data in accordance with our documented instructions and for the specific purposes outlined in our agreement.

Security Obligations: All sub-processors are contractually required to implement appropriate technical and organisational security measures.

Audit Rights: We retain the right to audit sub-processor compliance with data protection obligations.

Sub-processor Transparency: A list of our current sub-processors is available upon request by contacting our Data Protection Officer.

11. Policy Versioning & Consent Records

This privacy policy is version-controlled to ensure transparency and regulatory compliance:

Current Version: 2.0 — Effective 30 April 2026

Change Notifications: Material changes to this policy will be communicated via email and a prominent in-app notice at least 14 days before taking effect.

Consent Tracking: When you accept our cookie preferences or agree to data processing, we record the policy version, timestamp, and specific consents granted. This record is retained for the duration of your account plus 24 months.

Previous Versions: Prior versions of this policy are retained internally and can be provided upon request to our Data Protection Officer.

12. Contact & Data Protection Officer

For any privacy-related questions or to exercise your data rights:

Email: privacy@dxbpropertymatch.com

Data Protection Officer: Available via the email above

Response Time: We will acknowledge your request within 48 hours and provide a substantive response within 30 days, as required by GDPR Article 12(3).

Supervisory Authority: If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.

© 2026 DXB Property Match. All rights reserved.