1. Legal Entity & Data Controller Identification
This Privacy Policy governs the processing of personal data by Tech Labs FZ LLC ("Tech Labs", "we", "us", "our"), operating the domain tech-labs.me. As an enterprise systems integrator incorporated in the United Arab Emirates, we act as the Data Controller responsible for personal data processed through our web properties and inquiry channels. For any inquiries regarding personal data processing or to exercise statutory data subject rights, contact our Data Protection Office at [email protected].
2. Governing Law & Applicable Regulatory Frameworks
Our data governance practices comply strictly with the statutory laws of the United Arab Emirates and international privacy standards, including:
- UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (UAE PDPL): Governing personal data processing across the UAE mainland as referenced on the UAE Government Data Portal.
- DIFC Data Protection Law No. 5 of 2020: Regulating data processing activities conducted within or targeting entities in the Dubai International Financial Centre.
- ADGM Data Protection Regulations 2021: Regulating data controller obligations within the Abu Dhabi Global Market.
- Regulation (EU) 2016/679 (GDPR): Standard enforced where processing involves personal data belonging to data subjects residing within the European Economic Area.
3. Personal Data Categories We Collect
We process personal data provided directly by business representatives, enterprise technology officers, and prospective clients when initiating technical inquiries, submitting architecture briefs, or subscribing to industry publications. Categories collected include:
- Identity & Contact Information: Full name, professional title, corporate email address, contact telephone number, and employer business name.
- Technical System Context: Enterprise ERP platform in use (e.g., SAP, Oracle, Microsoft, Odoo, Salesforce), deployment model, emirate location, and operational process scope.
- Communication Records: Written inquiry submissions, email correspondence, mutual non-disclosure agreement metadata, and discovery meeting records.
- Automated Telemetry & Server Logs: Anonymized IP addresses, browser agent headers, referrer URLs, and HTTP request telemetry processed at the CDN edge for security firewall enforcement.
4. Lawful Bases for Processing
Under Article 6 of the UAE PDPL and equivalent provisions in DIFC, ADGM, and GDPR, every processing operation relies on an explicit lawful basis:
- Consent (Article 6(1) UAE PDPL): Given explicitly when submitting technical briefing forms via mandatory consent checkboxes. Consent can be revoked at any time.
- Pre-Contractual Steps (Article 6(2) UAE PDPL): Processing necessary to review enterprise system requirements, deliver custom ROI models, and prepare Discovery proposals upon your request.
- Legal Obligation (Article 6(4) UAE PDPL): Processing required to maintain statutory accounting records, tax documentation under UAE Federal Tax Authority rules, and anti-money laundering compliance.
- Legitimate Interests: Protecting site security, preventing automated bot abuse, and defending against cybersecurity threats.
5. Data Processors & Cloud Infrastructure Sub-Processors
We utilize trusted third-party cloud infrastructure providers acting as Data Processors under strict Data Processing Agreements (DPAs) with mandatory encryption in transit and at rest:
- Cloudflare, Inc.: Global Content Delivery Network (CDN), web application firewall (WAF), edge static hosting, and form submission proxy infrastructure.
- Brevo (Sendinblue SAS): ISO 27001-certified transactional email delivery infrastructure for processing architecture brief notifications and customer support routing.
We never sell, rent, monetise, or trade personal data to third-party marketing brokers, advertising networks, or unauthorized external entities.
6. International Data Transfers & In-Country Data Sovereignty
In accordance with Article 22 of the UAE PDPL, personal data collected from UAE entities is processed with strict adherence to cross-border data transfer controls. Where personal data is transferred outside the UAE, we ensure appropriate safeguards are enforced—including Standard Contractual Clauses (SCCs), adequacy decisions, or processing within certified in-country cloud regions (such as AWS Middle East UAE or Azure UAE Central).
7. Data Retention & Archival Policies
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected. Technical briefing form inquiries are retained for a maximum of 24 months from the date of last communication unless a formal commercial contract is executed. After expiration of the retention threshold, personal data is permanently destroyed using secure electronic deletion protocols.
8. Data Subject Statutory Rights
Under UAE PDPL (including Article 18 on automated decisions and right to object), DIFC, ADGM, and GDPR, you possess the following enforceable rights regarding your personal data:
- Right to Access: Request a formal copy of all personal data held about you.
- Right to Rectification: Request immediate correction of inaccurate or incomplete personal data.
- Right to Erasure ("Right to be Forgotten"): Request complete deletion of personal data where processing lacks statutory justification.
- Right to Object to Automated Processing (Article 18 UAE PDPL): Object to decisions produced solely by automated processing or profiling.
- Right to Data Portability: Obtain your personal data in a structured, machine-readable format.
To exercise any statutory right, submit a written request to [email protected]. We respond to all verified data subject requests within 30 calendar days.