Privacy Policy.
Effective 26 July 2026 · AFSA FZE · United Arab Emirates
This is the notice required by Article 13 of the UAE Personal Data Protection Law. It tells you what we collect, why we are allowed to, how long we keep it, who else sees it, and what you can make us do about it.
01. Who Controls Your Data
AFSA FZE is the data controller for personal data collected through afsa.ae and its connected services. Our full identity and registered address are set out at the end of this page.
Our Data Protection Officer can be reached at privacy@afsa.ae. Use that address for any request under this policy — it is monitored specifically for data protection matters.
02. What We Collect
- Identity and contact data: Name, email address, mobile and WhatsApp number, and the emirate you are in.
- Account data: Login credentials (passwords are hashed — we never see them), your role on the platform, and your preferences.
- Order and booking data: What you bought or booked, when, the delivery address, and the order history attached to your account.
- Payment data: The last four digits and card type only. Full card numbers are captured by our payment provider and never reach or persist on our servers.
- Business and verification data: For partners and business accounts: trade licence, Tax Registration Number, and identity documents submitted for KYC.
- Content you submit: Assessment answers, calculator inputs, CVs and job applications, support messages, and anything you type into our AI-assisted tools.
- Technical data: IP address, device and browser type, and pages visited — collected in server logs.
We do not knowingly collect data from anyone under 18. If you believe a minor has given us data, tell us and we will delete it.
03. Why We Use It, and Our Legal Basis
The PDPL requires a lawful basis for every use. Ours are:
- To perform our contract with you: Creating your account, taking and fulfilling orders and bookings, processing payments and refunds, providing support.
- To comply with a legal obligation: Issuing tax invoices, keeping accounting records, retaining KYC evidence, and responding to lawful requests from UAE authorities.
- For our legitimate interests: Securing the platform against fraud and abuse, debugging, and improving our services — balanced against your rights, and never in a way you would not reasonably expect.
- With your consent: Marketing emails and any future analytics or advertising cookies. You can withdraw consent at any time, and withdrawing it is as easy as giving it — every marketing email carries a one-click unsubscribe.
04. Automated Processing and AI Tools
Parts of this platform generate assessments, scores, CV feedback and recommendations automatically. These are decision support tools: they inform a human, they do not by themselves decide whether you get hired, approved as a partner, or granted credit.
Under Article 21 of the PDPL you have the right to object to automated decision-making that produces legal effects for you, and to ask for a human to review it. Write to privacy@afsa.ae and a person will re-examine the outcome.
06. Transfers Outside the UAE
Some of the providers above operate infrastructure outside the United Arab Emirates. Articles 22 and 23 of the PDPL permit such transfers where the destination offers adequate protection, or where appropriate contractual safeguards are in place. We rely on standard contractual clauses with our processors, and we transfer only what the service actually needs.
07. How Long We Keep It
- Account data: For as long as your account is open, then 12 months after closure.
- Order, invoice and tax records: 5 years from the end of the tax period, as UAE tax law requires.
- KYC and verification documents: 5 years after the business relationship ends.
- Job applications: 12 months, unless you ask us to keep you on file for longer.
- Support correspondence: 24 months.
- Server and security logs: 12 months.
When a retention period ends we delete the data or irreversibly anonymise it.
08. How We Protect It
Data is encrypted in transit with TLS 1.3 and at rest with AES-256 on Google Cloud infrastructure. Access is role-based and limited to staff who need it, sessions are verified server-side, and administrative actions are logged. See our Data Protection Protocol for the technical detail.
09. If There Is a Breach
If personal data is compromised in a way that risks your privacy or security, we will notify the UAE Data Office without undue delay as Article 9 of the PDPL requires, and we will tell you directly where the risk to you is high — describing what happened, what it means for you, and what we are doing about it.
10. Your Rights
Under Articles 13 to 19 of the PDPL you may:
- Be informed: Know how your data is processed — that is this document.
- Access: Get a copy of the personal data we hold about you.
- Correct: Have inaccurate or incomplete data fixed.
- Delete: Ask us to erase your data, where no legal duty requires us to keep it.
- Restrict or object: Limit or object to certain processing, including direct marketing.
- Port: Receive your data in a structured, machine-readable format.
- Withdraw consent: Withdraw it at any time, without affecting what we did beforehand.
Email privacy@afsa.ae. We respond within 30 days and never charge for a first request. We may ask you to verify your identity before we act — that protects you, not us.
11. Complaints
If you are unhappy with how we have handled your data, tell us first so we can put it right. You also have the right to complain to the UAE Data Office — u.ae.
Who You Are Contracting With
AFSA FZE, trading as afsa at afsa.ae.
Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates
+971 54 595 9540 · hello@afsa.ae
Unresolved complaint? You may escalate to the UAE Ministry of Economy & Tourism — Consumer Protection Department on 600 522 225 or via moet.gov.ae.