Privacy Policy

Last Updated: January 15, 2025

1. Introduction

UAE Cultural Map ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website located at [your website URL] (the "Service").

By using our Service, you agree to the collection and use of information in accordance with this policy. This Privacy Policy complies with the laws of the United Arab Emirates (UAE) and international data protection standards.

2. Information We Collect

2.1 Personal Information

We may collect personal information that you voluntarily provide to us when you:

  • Register for an account or create a user profile
  • Contact us through our contact form, email, or phone
  • Subscribe to our newsletter, updates, or marketing communications
  • Participate in surveys, feedback forms, or user research
  • Submit content, comments, reviews, or user-generated content
  • Request information about cultural destinations or events
  • Download or access our guides, maps, or analytical reports
  • Participate in promotional activities or contests
  • Interact with our customer support team

This information may include:

  • Identity Information: Full name, username, title, and any other identifiers you choose to provide
  • Contact Information: Email address, phone number, mailing address, and postal code
  • Account Information: Password (encrypted), account preferences, and profile settings
  • Communication Data: Messages, inquiries, feedback, and any correspondence with us
  • Content Data: Reviews, comments, photos, videos, or other content you submit
  • Preference Data: Interests, preferences, location preferences, and subscription choices
  • Marketing Data: Your preferences for receiving marketing communications and your communication preferences
  • Any other information: You voluntarily provide in forms, surveys, or communications

2.2 Automatically Collected Information

When you visit our Service, we may automatically collect certain information about your device, browsing behavior, and usage patterns, including:

  • Device Information: IP address, device type, device model, unique device identifiers, and mobile network information
  • Browser Information: Browser type, version, language settings, and browser plugins
  • Operating System: Operating system type and version
  • Usage Data: Pages visited, time spent on pages, click patterns, scroll behavior, search queries, and navigation paths
  • Referral Information: Referring website addresses, search engines, and marketing campaigns
  • Location Data: General geographic location based on IP address (country, city, region)
  • Technical Data: Screen resolution, color depth, time zone, and connection speed
  • Timestamp Data: Date and time of access, session duration, and frequency of visits
  • Error Logs: Error messages, crash reports, and performance data

This automatically collected information helps us understand how users interact with our Service, identify technical issues, improve functionality, and enhance user experience.

2.3 Cookies and Tracking Technologies

We use cookies, web beacons, pixel tags, local storage, and similar tracking technologies to track activity on our Service, store certain information, and enhance your browsing experience. Cookies are small text files placed on your device that may include an anonymous unique identifier.

Types of tracking technologies we use:

  • Session Cookies: Temporary cookies that expire when you close your browser
  • Persistent Cookies: Cookies that remain on your device for a set period or until deleted
  • First-Party Cookies: Cookies set directly by our Service
  • Third-Party Cookies: Cookies set by third-party services we use (e.g., Google Analytics)
  • Local Storage: Data stored locally in your browser for functionality and preferences
  • Web Beacons: Small invisible images used to track email opens and page views

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service, and certain features may not function properly.

For more detailed information about our use of cookies, including how to manage your cookie preferences, please refer to our Cookie Policy.

2.4 Information from Third Parties

We may receive information about you from third-party sources, including:

  • Social Media Platforms: If you connect your social media accounts or interact with our content on social platforms
  • Public Databases: Publicly available information from government records or public databases
  • Partners and Affiliates: Information shared by our business partners or affiliates
  • Service Providers: Information provided by third-party service providers who assist us in operating our Service
  • Analytics Providers: Aggregated and anonymized data from analytics services

We combine this information with data we collect directly to provide you with a better experience and more relevant content.

3. How We Use Your Information

We use the information we collect for various purposes, including:

3.1 Service Provision and Operation

  • To provide, maintain, operate, and improve our Service and its features
  • To process your registrations, requests, and transactions
  • To create and manage your account and user profile
  • To deliver content, guides, maps, and analytical reports you request
  • To personalize your experience and show relevant content
  • To enable features such as saved preferences, favorites, and bookmarks
  • To facilitate communication between users and our platform

3.2 Communication and Support

  • To respond to your inquiries, questions, and requests
  • To provide customer support, technical assistance, and troubleshooting
  • To send you service-related communications (e.g., account updates, security alerts)
  • To notify you about changes to our Service, terms, or policies
  • To send you newsletters, updates, and marketing communications (with your consent)
  • To conduct surveys, gather feedback, and improve our services

3.3 Analytics and Improvement

  • To analyze usage patterns, user behavior, and engagement metrics
  • To understand how users interact with our Service and content
  • To identify trends, preferences, and areas for improvement
  • To conduct research and develop new features and services
  • To measure the effectiveness of our content and marketing efforts
  • To optimize website performance, speed, and functionality

3.4 Security and Legal Compliance

  • To detect, prevent, and address technical issues, security threats, and fraud
  • To protect our rights, property, and the safety of our users
  • To enforce our Terms of Service and other policies
  • To comply with legal obligations under UAE law and international regulations
  • To respond to legal requests, court orders, and government inquiries
  • To investigate potential violations of our terms or applicable laws
  • To maintain records as required by law or for business purposes

3.5 Marketing and Advertising

With your consent, we may use your information for:

  • Marketing communications about our services, events, and promotions
  • Personalized advertising and content recommendations
  • Targeted marketing campaigns based on your interests and preferences
  • Promotional offers, discounts, and special events
  • Partnership announcements and collaborative content

You can opt-out of marketing communications at any time by clicking the unsubscribe link in our emails or contacting us directly.

4. Data Sharing and Disclosure

We respect your privacy and only share your information in the circumstances described below:

4.1 Third-Party Service Providers

We may share your information with third-party service providers who perform services on our behalf. These providers are contractually obligated to protect your information and use it only for the purposes we specify. Categories of service providers include:

  • Hosting and Infrastructure: Cloud hosting providers, server management, and data storage services
  • Analytics and Data Analysis: Google Analytics, data analytics platforms, and business intelligence tools
  • Email and Communication: Email delivery services, SMS providers, and communication platforms
  • Customer Support: Help desk software, ticketing systems, and customer relationship management tools
  • Payment Processing: Payment gateways and financial service providers (if applicable)
  • Content Delivery: Content delivery networks (CDNs) and media hosting services
  • Security Services: Security monitoring, fraud detection, and threat prevention services
  • Marketing Tools: Marketing automation platforms, email marketing services, and advertising networks
  • Mapping Services: Google Maps API and other mapping service providers

All service providers are required to maintain appropriate security measures and are prohibited from using your information for any purpose other than providing services to us.

4.2 Business Partners and Affiliates

We may share aggregated, anonymized, or de-identified information with business partners, affiliates, or collaborators for research, analytics, or business development purposes. This information cannot be used to identify you personally.

4.3 Legal Requirements and Law Enforcement

We may disclose your information if required to do so by law or in response to:

  • Valid requests by public authorities, courts, or government agencies in the UAE
  • Legal processes, subpoenas, warrants, or court orders
  • Regulatory investigations or compliance requirements
  • Protection of rights, property, or safety of our users or the public
  • Enforcement of our Terms of Service or other agreements
  • Prevention of fraud, security threats, or illegal activities

We will attempt to notify you of such disclosures when legally permitted, unless doing so would compromise the investigation or violate legal requirements.

4.4 Business Transfers

In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, your information may be transferred to the acquiring entity or successor organization. The acquiring entity will be subject to the same privacy protections and obligations as outlined in this Privacy Policy. We will notify you of any such transfer through prominent notice on our Service or via email.

4.5 With Your Consent

We may share your information with third parties when you explicitly consent to such sharing. For example, if you choose to share content on social media platforms or participate in co-marketing activities with our partners.

4.6 Public Information

Any information you choose to make public on our Service (such as public reviews, comments, or profile information) may be visible to other users and the general public. Please exercise caution when sharing personal information publicly.

5. Data Security

We take the security of your personal information seriously and implement comprehensive technical and organizational security measures to protect your data against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

5.1 Technical Security Measures

Our technical security measures include:

  • Encryption: SSL/TLS encryption for data in transit and encryption at rest for sensitive data
  • Secure Infrastructure: Secure server infrastructure with firewalls, intrusion detection, and prevention systems
  • Access Controls: Multi-factor authentication, role-based access controls, and least privilege principles
  • Network Security: Secure network architecture, VPN access, and network segmentation
  • Data Backup: Regular automated backups with encrypted storage and disaster recovery procedures
  • Security Monitoring: Continuous monitoring, logging, and alerting for suspicious activities
  • Vulnerability Management: Regular security assessments, penetration testing, and vulnerability scanning
  • Patch Management: Timely application of security patches and updates

5.2 Organizational Security Measures

Our organizational security measures include:

  • Employee Training: Regular security awareness training for all staff members
  • Access Management: Strict access controls, background checks, and confidentiality agreements
  • Incident Response: Established incident response procedures and breach notification protocols
  • Data Minimization: Collection and retention of only necessary data
  • Privacy by Design: Privacy considerations integrated into our development processes
  • Third-Party Assessments: Regular security audits and assessments of third-party service providers

5.3 Data Breach Notification

In the event of a data breach that may affect your personal information, we will:

  • Investigate the breach immediately and take steps to contain and remediate it
  • Notify affected users and relevant authorities as required by UAE law
  • Provide information about the nature of the breach and steps taken to address it
  • Offer guidance on protective measures users can take

We will notify you of any data breach affecting your personal information within 72 hours of becoming aware of it, unless notification would compromise ongoing investigations or is otherwise prohibited by law.

6. Your Rights Under UAE Law

As a user of our Service, you have the following rights regarding your personal information:

6.1 Right to Access

You have the right to request access to your personal information we hold. This includes:

  • Confirmation that we are processing your personal information
  • Access to a copy of your personal information
  • Information about the purposes of processing, categories of data, and recipients
  • Information about the retention period and your rights

We will provide this information within 30 days of your request, free of charge, unless the request is excessive or repetitive.

6.2 Right to Correction

You have the right to request correction of inaccurate or incomplete personal information. You can:

  • Update your account information directly through your account settings
  • Request correction of any inaccurate data we hold about you
  • Request completion of incomplete information

We will correct your information promptly and notify any third parties to whom we have disclosed the incorrect information.

6.3 Right to Deletion

You have the right to request deletion of your personal information in certain circumstances, including when:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw consent and there is no other legal basis for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed
  • The data must be deleted to comply with legal obligations

We may retain certain information if required by law, for legitimate business purposes, or to protect our legal rights. We will inform you if we cannot delete your information and explain the reasons.

6.4 Right to Object

You have the right to object to processing of your personal information for:

  • Direct marketing purposes (you can opt-out at any time)
  • Processing based on legitimate interests (we will stop unless we have compelling legitimate grounds)
  • Processing for research or statistical purposes

6.5 Right to Withdraw Consent

Where we process your personal information based on consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing that occurred before withdrawal.

You can withdraw consent by:

  • Updating your account preferences
  • Clicking unsubscribe links in marketing emails
  • Contacting us directly

6.6 Right to Data Portability

You have the right to receive a copy of your personal information in a structured, commonly used, and machine-readable format. You can also request that we transfer this data directly to another service provider where technically feasible.

6.7 Right to Restrict Processing

You have the right to request restriction of processing of your personal information in certain circumstances, such as when you contest the accuracy of data or object to processing while we verify your request.

6.8 How to Exercise Your Rights

To exercise any of these rights, please contact us using the information provided in the "Contact Us" section below. We may need to verify your identity before processing your request to ensure the security of your information.

We will respond to your request within 30 days. If your request is complex or we receive multiple requests, we may extend this period by an additional 60 days, and we will inform you of the extension and reasons for it.

If you are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection authority in the UAE.

7. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

7.1 Retention Periods

Our data retention periods are based on:

  • Account Data: Retained for the duration of your account plus 2 years after account closure
  • Contact Information: Retained for 3 years after last contact or until you request deletion
  • Marketing Data: Retained until you unsubscribe or request deletion
  • Transaction Records: Retained for 7 years as required by UAE financial regulations (if applicable)
  • Legal Records: Retained as required by law or for the duration of legal proceedings
  • Analytics Data: Aggregated and anonymized data may be retained indefinitely
  • User Content: Retained until you delete it or request removal

7.2 Deletion and Anonymization

When we no longer need your information, we will securely delete or anonymize it using industry-standard methods. Anonymized data may be retained for statistical, research, or analytical purposes and cannot be used to identify you.

7.3 Exceptions

We may retain your information for longer periods if:

  • Required by law, regulation, or legal process
  • Necessary for establishing, exercising, or defending legal claims
  • Necessary for legitimate business purposes (e.g., fraud prevention)
  • You have requested that we retain it for a specific purpose

8. International Data Transfers

Your information may be transferred to and processed in countries other than the UAE, including countries that may have different data protection laws than your country of residence.

8.1 Transfer Mechanisms

When transferring data internationally, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses: EU-approved standard contractual clauses with data processors
  • Adequacy Decisions: Transfers to countries with adequate data protection laws
  • Binding Corporate Rules: Internal policies ensuring consistent data protection standards
  • Certification Programs: Third-party certifications demonstrating compliance with data protection standards

8.2 Third-Party Transfers

Some of our service providers may be located outside the UAE. We ensure that all third-party service providers maintain appropriate security measures and comply with applicable data protection laws. By using our Service, you consent to the transfer of your information to these service providers.

8.3 Your Rights Regarding Transfers

You have the right to be informed about international transfers of your data and the safeguards in place. If you have concerns about international data transfers, please contact us using the information provided in the "Contact Us" section.

9. Children's Privacy

Our Service is not intended for children under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

10. Google Services and Analytics

We use Google Analytics and other Google services to analyze website traffic and user behavior. Google may use cookies and collect information about your use of our Service. For more information about how Google uses data, please visit Google's Privacy Policy.

You can opt-out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.

12. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:

13. Data Protection Officer

We have designated a Data Protection Officer (DPO) to oversee compliance with data protection laws and address privacy concerns. You can contact our DPO at:

14. Updates and Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational, legal, or regulatory reasons. We will notify you of any material changes by:

  • Posting the updated Privacy Policy on this page with a new "Last Updated" date
  • Sending an email notification to registered users (for significant changes)
  • Displaying a prominent notice on our Service

Material changes will become effective 30 days after notification, unless a shorter period is required by law. Your continued use of our Service after the effective date of changes constitutes acceptance of the updated Privacy Policy.

We encourage you to review this Privacy Policy periodically to stay informed about how we collect, use, and protect your information.

15. Additional Information for Specific Jurisdictions

15.1 European Economic Area (EEA) Users

If you are located in the EEA, you have additional rights under the General Data Protection Regulation (GDPR), including the right to lodge a complaint with your local data protection authority. Our legal basis for processing your data includes consent, contract performance, legal obligations, and legitimate interests.

15.2 California Residents

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete personal information, and the right to opt-out of the sale of personal information (we do not sell personal information).

16. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of the United Arab Emirates, including:

  • UAE Federal Law No. 2 of 2019 on the Use of Information and Communication Technology in Health Fields
  • UAE Federal Law No. 5 of 2012 on Combating Cybercrimes
  • Dubai International Financial Centre (DIFC) Data Protection Law (if applicable)
  • Any other applicable UAE data protection and privacy laws

Any disputes arising from or related to this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of Dubai, United Arab Emirates. If any provision of this Privacy Policy is found to be invalid or unenforceable, the remaining provisions will continue in full force and effect.