1. Who we are
CESPRO Facilities Management Services LLC ("CESPRO", "we") is the controller of any personal data we process about you. We are registered in Dubai, United Arab Emirates. Our data protection officer can be reached at privacy@cespro.ae.
2. What we collect
We collect data you provide directly and data generated through your use of our services. Categories include:
- Identification and contact data (name, mobile, email, address)
- Property and unit information (size, AC count, access details)
- Booking and visit data (request, scope, photos taken on site, GPS location of the visit)
- Payment data (processed via PCI-compliant gateways — we never store full card numbers)
- Platform usage logs (login times, actions, device identifiers)
3. Legal basis and purposes
We process your data to deliver the services you booked (contract performance), to send service updates and invoices (legitimate interest), to comply with VAT and other regulatory obligations (legal obligation), and for product improvement and aggregated analytics (legitimate interest). Where we rely on consent — for example to share photos in marketing materials — we ask for it explicitly and you can withdraw it at any time.
5. How long we keep your data
Customer records are retained for the duration of our relationship plus seven years thereafter, to satisfy UAE VAT and commercial law record-keeping requirements. Visit photos are retained for five years for warranty purposes. Anonymised analytics are retained indefinitely.
6. Your rights under UAE PDPL
Under Federal Decree-Law No. 45 of 2021, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Restrict or object to certain processing
- Request deletion (subject to legal retention obligations)
- Receive a portable copy of your data
- Withdraw any consent you previously gave
Email privacy@cespro.ae to exercise any of these rights. We respond within 30 days. If we cannot resolve a complaint, you may escalate to the UAE Data Office (Federal Authority).
7. Security
Customer data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access to production systems is gated by single sign-on with hardware-key multi-factor authentication. Photos taken during visits are uploaded directly to encrypted storage and are never stored on the technician's device for more than 24 hours.
9. International transfers
Our primary cloud region is AWS Middle East (UAE). Some support tooling (e.g. our error-tracking platform) is hosted in the EU under EU Standard Contractual Clauses. We do not transfer personal data outside these jurisdictions.
10. Changes to this policy
We may update this policy from time to time. Material changes are announced 30 days in advance via the customer app, by email and on this page. Continued use after the effective date constitutes acceptance.
