While Aqaarix is a platform built for the Middle East, we recognize that our users may interact with data subjects from the European Union or may themselves be subject to the General Data Protection Regulation (GDPR). We are committed to maintaining the highest global standards of data privacy, which inherently aligns with the evolving data protection laws in the GCC, such as the KSA PDPL and UAE Data Protection Law.
1. Our Role as a Data Processor
For the majority of our services, Aqaarix acts as a Data Processor. Our clients (landlords and property managers) are the Data Controllers who determine the purpose and means of processing tenant data. We process this data strictly according to the controller's instructions and our Data Processing Agreement.
2. Data Subject Rights
We provide tools and processes to help our users comply with GDPR data subject requests, including:
- Right of Access: Users can export tenant and property data directly from the dashboard.
- Right to Rectification: Real-time editing capabilities ensure data accuracy.
- Right to Erasure ('Right to be Forgotten'): Protocols for permanent deletion of records upon request.
- Data Portability: Support for data exports in machine-readable formats (CSV/Excel).
GCC & GDPR Harmony
Our platform is designed to satisfy both GDPR and GCC regional requirements simultaneously. By adhering to GDPR's strict "Privacy by Design" principles, we automatically ensure a high level of compliance with the UAE and Saudi Arabian data protection frameworks.
3. Data Transfers and Sub-processors
We use a limited number of third-party sub-processors to provide our services (e.g., cloud hosting, email delivery). We ensure that all sub-processors are vetted for security compliance and that appropriate Data Transfer Agreements (such as Standard Contractual Clauses) are in place where required.
4. Data Breach Notification
In the unlikely event of a data breach, Aqaarix maintains a robust incident response plan. We commit to notifying our users without undue delay, allowing them to fulfill their own notification obligations to national authorities (such as the SDAIA in KSA or the UAE Data Office) and affected individuals.
5. Data Protection Officer (DPO)
Aqaarix has appointed a Data Protection Officer to oversee our privacy strategy and ensure ongoing compliance with both regional and international regulations.
6. Contact for Privacy Inquiries
If you have specific questions regarding our GDPR compliance or wish to exercise your data rights, please contact our privacy team:
Email: hello@aqaarix.com
Subject: Data Subject Request / GDPR Inquiry