Legal
Privacy Policy
How We Collect, Use and Protect Your Data
1. Introduction
This Privacy Policy describes how Zenway International FZ-LLC, operating under the brand name ZenVisa International ("Company," "we," "us," or "our"), collects, uses, stores, processes, protects, and discloses personal data when you access or use our website at https://www.zenvisa.net (the "Website") and when you engage our services (collectively, the "Services").
We are committed to protecting your privacy and ensuring that your personal data is handled in a safe and responsible manner, in compliance with all applicable laws and regulations. This Privacy Policy is designed to provide you with clear and comprehensive information about our data processing activities.
By accessing the Website, using our Services, or providing your personal data to us, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree with this Privacy Policy, you must not access the Website or use our Services.
This Privacy Policy should be read together with our Terms of Use, which are incorporated herein by reference. In the event of any conflict between this Privacy Policy and the Terms of Use, the Terms of Use shall govern with respect to liability limitations, indemnification, and dispute resolution.
2. Company Identity
The data controller responsible for the processing of your personal data is:
| Legal Name: | Zenway International FZ-LLC |
|---|---|
| Operating Name: | ZenVisa International |
| Registered Address: | Compass Building, Al Hulaila Industrial Zone-FZ, Ras Al Khaimah, UAE |
| RAKEZ License No.: | 47029828 |
| Email: | legal@zenvisa.net |
| Website: | https://www.zenvisa.net |
For the purposes of the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), we are the Data Controller in respect of personal data collected through the Website and the Services. Where we process personal data on behalf of our clients in connection with document clearing and related administrative services, we may act as a Data Processor in accordance with documented instructions.
For the purposes of the General Data Protection Regulation (EU) 2016/679 (GDPR) and the UK GDPR, we are the data controller in respect of personal data of individuals located in the European Economic Area and the United Kingdom.
3. Scope of this Policy
This Privacy Policy applies to all personal data collected by the Company through:
• The Website, including all subdomains, pages, features, and functionality;
• Direct communications with the Company, including email, telephone, WhatsApp, SMS, and in-person meetings;
• Service agreements, engagement letters, and related contractual documentation;
• Document submission portals, client intake forms, and online questionnaires;
• Social media platforms and professional networking sites where the Company maintains a presence;
• Marketing campaigns, surveys, promotional events, and business conferences.
This Privacy Policy does not apply to personal data processed by third-party websites, services, or platforms that are not owned or controlled by the Company, even if linked from our Website. We encourage you to review the privacy policies of any third-party services you use.
4. Definitions
The following terms, when used in this Privacy Policy with initial capital letters, shall have the meanings ascribed below:
"Applicable Law": means all laws, regulations, directives, and regulatory requirements applicable to the processing of personal data, including the PDPL, GDPR, UK GDPR, UAE Consumer Protection Law, and UAE Electronic Transactions Law.
"Automated Decision-Making": means a decision based solely on automated processing, including profiling, which produces legal effects concerning a data subject or similarly significantly affects them.
"Biometric Data": means personal data resulting from specific technical processing relating to the physical, physiological, or behavioral characteristics of a natural person, which allow or confirm the unique identification of that natural person, including facial images, fingerprints, and voice recognition data.
"Cookie": means a small text file placed on your device by a website that you visit, which stores information about your browsing activity.
"Data Controller": means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
"Data Processor": means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the Data Controller.
"Data Subject": means an identified or identifiable natural person to whom personal data relates.
"GDPR": means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
"Government Authority": means any federal, emirate, or local governmental, regulatory, or administrative body of the United Arab Emirates, including but not limited to GDRFA, ICA, MOHRE, DED, and RAKEZ.
"Personal Data": means any information relating to an identified or identifiable natural person, including name, identification number, location data, online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
"PDPL": means UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, as amended.
"Processing": means any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.
"Sensitive Personal Data": means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation, as well as financial data, personal credit data, and any other data designated as sensitive under Applicable Law.
"Services": means the administrative support, document preparation, document clearing assistance, translation services, editing and proofreading services, web media design and management services, and business events management services provided by the Company under its RAKEZ commercial licenses.
"Third-Party Service Provider": means any natural or legal person engaged by the Company to process personal data on its behalf or to provide services that involve the processing of personal data.
"User": means any natural person who accesses, browses, or uses the Website or Services.
5. Categories of Personal Data Collected
We collect personal data that you provide directly to us, that we collect automatically when you use the Website, and that we receive from third parties. The categories of personal data we collect include:
5.1 Identity and Contact Information
• Full name, including given name, family name, and any aliases;
• Date and place of birth;
• Nationality and citizenship status;
• Passport number, national ID number, and other government-issued identification numbers;
• Residential address, mailing address, and previous addresses;
• Email address, telephone number, mobile number, and fax number;
• Emergency contact information.
5.2 Professional and Employment Information
• Employment history, current employer, job title, and professional qualifications;
• Educational background, degrees, certificates, and professional licenses;
• Business name, trade license number, and commercial registration details;
• Professional membership affiliations.
5.3 Financial Information
• Bank account details, credit card information, and payment history;
• Billing address and invoicing preferences;
• Transaction records and payment confirmations.
5.4 Service-Related Information
• Service preferences, requirements, and specifications;
• Documents submitted for processing, translation, or clearing;
• Correspondence, communications, and instructions related to Services;
• Feedback, survey responses, and testimonials.
5.5 Technical Information
• IP address, browser type and version, operating system, and device identifiers;
• Cookies, web beacons, pixel tags, and similar tracking technologies;
• Website usage data, including pages visited, time spent, click patterns, and referral sources;
• Geolocation data, where enabled on your device.
6. Sensitive Personal Data
We may collect and process sensitive personal data only where permitted by Applicable Law and where such processing is necessary for the purposes described in this Privacy Policy. Categories of sensitive personal data we may process include:
• Biometric data, including facial photographs and fingerprints, where required for identity verification or government submissions;
• Health information, where required for visa applications, residency permits, or insurance purposes;
• Religious or philosophical beliefs, where disclosed in documents submitted for translation or processing;
• Racial or ethnic origin, where indicated in passport documents or government forms;
• Financial data and personal credit information, where required for payment processing or AML/KYC compliance.
We process sensitive personal data only with your explicit consent, or where another legal basis under the PDPL or GDPR applies, such as compliance with a legal obligation, protection of vital interests, or establishment, exercise, or defense of legal claims. Where explicit consent is required, we will obtain it through a clear affirmative action separate from general acceptance of this Privacy Policy.
7. Passport and Identity Documents
In connection with our document clearing, translation, and administrative support services, we collect and process passport copies, national identity cards, residence permits, driving licenses, and other government-issued identification documents.
The processing of passport and identity document data is necessary for:
• Preparing, reviewing, and organizing documents for submission to Government Authorities;
• Verifying your identity in accordance with our AML/KYC obligations;
• Translating identity documents into other languages where required;
• Coordinating with Government Authorities regarding the status of your applications;
• Maintaining records as required by Applicable Law.
We do not use passport or identity document data for any purpose other than providing the Services you have requested or as required by Applicable Law. We do not share such data with any third party except as set out in Clauses 23, 24, and 25 of this Privacy Policy.
Passport and identity documents are stored with enhanced security measures, including encryption at rest and restricted access controls. Original documents are returned to you upon completion of the Services unless you expressly request otherwise or retention is required by law.
8. Business and Corporate Information
Where you engage our Services on behalf of a corporate entity, partnership, or other organization, we collect and process the following business and corporate information:
• Company name, legal form, and trade name;
• Commercial license number, registration number, and tax identification number;
• Registered address, business address, and branch office locations;
• Names, titles, and contact details of authorized representatives, directors, officers, and beneficial owners;
• Corporate structure, ownership details, and shareholder information;
• Financial statements, audit reports, and banking references;
• Trade license copies, memorandum of association, and articles of association.
This information is processed for the purpose of providing corporate document clearing services, business setup assistance, compliance verification, and related administrative support. Where business information includes personal data of individuals (such as directors, officers, or beneficial owners), such personal data is processed in accordance with this Privacy Policy.
9. Technical Information
When you access the Website, we automatically collect certain technical information about your device and browsing activity. This information is collected through cookies, server logs, and other tracking technologies and includes:
• Internet Protocol (IP) address, including the approximate geographic location derived from it;
• Browser type, version, and language settings;
• Operating system and platform;
• Device type, model, and unique device identifiers;
• Date and time of access, duration of visit, and time zone setting;
• Pages visited, links clicked, scroll depth, and navigation patterns;
• Referral source, search terms, and traffic source;
• Download errors, page load times, and browser crash reports.
This technical information is used to analyze Website performance, improve user experience, detect and prevent security threats, and generate aggregate statistical data about Website usage. Where technical information is linked to your personal identifiers, it is treated as personal data and processed in accordance with this Privacy Policy.
10. Cookies and Tracking Technologies
The Website uses cookies and similar tracking technologies to enhance your browsing experience, analyze Website traffic, and understand visitor behavior. Cookies are small text files stored on your device that enable the Website to recognize your browser and capture certain information.
We use the following categories of cookies:
10.1 Strictly Necessary Cookies
These cookies are essential for the operation of the Website and cannot be disabled. They enable core functionality such as security, network management, session management, and accessibility. Without these cookies, certain features of the Website may not function properly. These cookies do not store any personally identifiable information.
10.2 Performance Cookies
These cookies collect information about how visitors use the Website, including which pages are visited most frequently, how visitors navigate between pages, and whether error messages are displayed. The information collected is aggregated and anonymized. These cookies help us improve the performance and functionality of the Website.
10.3 Functional Cookies
These cookies enable enhanced functionality and personalization, such as remembering your preferences, language selection, and previously entered information. They may be set by us or by third-party providers whose services we have integrated into the Website.
10.4 Targeting and Advertising Cookies
These cookies are used to deliver relevant advertisements and marketing communications, limit the number of times you see an advertisement, and measure the effectiveness of advertising campaigns. They may be placed by us or by our advertising partners with our permission. These cookies may track your browsing activity across different websites and build a profile of your interests.
You can manage your cookie preferences at any time by clicking the "Cookie Settings" link in the footer of the Website or through your browser settings. Most web browsers allow you to control cookies through their settings preferences. Please note that disabling certain categories of cookies may affect the functionality and user experience of the Website.
For more detailed information about the specific cookies we use, their purposes, and their retention periods, please refer to our Cookie Policy, which is incorporated into this Privacy Policy by reference.
11. Google Analytics and Similar Technologies
The Website uses Google Analytics, a web analytics service provided by Google LLC ("Google"), to analyze Website traffic and user behavior. Google Analytics uses cookies to collect information about your use of the Website, including your IP address, which may be transmitted to and stored by Google on servers in the United States.
Google Analytics collects data such as:
• How often users visit the Website and what pages they access;
• What other websites users visited prior to accessing the Website;
• What browser and device users access the Website from;
• User demographics and interests (where available).
We have enabled IP anonymization on Google Analytics, which truncates your IP address within the European Union or European Economic Area before transmission to Google. Google uses the collected information to evaluate Website usage, compile reports on Website activity, and provide other services relating to Website activity and internet usage.
Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf. Google will not associate your IP address with any other data held by Google.
You can prevent Google Analytics from collecting your data by installing the Google Analytics Opt-out Browser Add-on, available at https://tools.google.com/dlpage/gaoptout. You can also opt out of personalized advertising by visiting https://adssettings.google.com.
In addition to Google Analytics, we may use other analytics and tracking technologies, including but not limited to Facebook Pixel, LinkedIn Insight Tag, and heat mapping tools, for the purposes of marketing, advertising, and user experience optimization. Each such service operates under its own privacy policy and terms of use.
12. Legal Basis for Processing
We process personal data only where we have a valid legal basis under Applicable Law. The legal bases for our processing activities include:
12.1 Consent
Where you have given your explicit, informed, and freely given consent to the processing of your personal data for one or more specific purposes. You have the right to withdraw your consent at any time by contacting us using the details in Clause 49.
12.2 Contractual Necessity
Where processing is necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract. This includes processing necessary to provide the Services you have requested.
12.3 Legal Obligation
Where processing is necessary for compliance with a legal obligation to which we are subject. This includes our obligations under AML/KYC laws, tax laws, corporate record-keeping requirements, and regulatory compliance obligations.
12.4 Legitimate Interests
Where processing is necessary for the purposes of our legitimate interests or those of a third party, except where such interests are overridden by your fundamental rights and freedoms. Our legitimate interests include: improving our Services, fraud prevention, network and information security, direct marketing (where permitted), and asserting or defending legal claims.
12.5 Vital Interests
Where processing is necessary to protect your vital interests or those of another natural person. This may apply in emergency situations.
12.6 Public Interest
Where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us.
13. Purposes of Processing
We process personal data for the following purposes:
• To provide, maintain, and improve our Services, including document clearing, translation, and administrative support;
• To process your requests, applications, and submissions to Government Authorities;
• To communicate with you regarding your account, transactions, and Service-related matters;
• To verify your identity and comply with our AML/KYC obligations;
• To process payments, issue invoices, and manage billing;
• To prevent fraud, money laundering, terrorism financing, and other illegal activities;
• To comply with legal obligations, court orders, and regulatory requirements;
• To improve the Website, analyze usage patterns, and develop new features;
• To send marketing communications, newsletters, and promotional materials (with your consent where required);
• To respond to your inquiries, complaints, and feedback;
• To enforce our Terms of Use and protect our legal rights;
• To conduct internal audits, quality assurance, and compliance reviews;
• To train our staff and improve service delivery;
• To maintain records as required by Applicable Law.
14. AI-Assisted Processing and AI Chat Services
We may use artificial intelligence ("AI") technologies and machine learning algorithms to assist in providing our Services. These technologies may be used for:
• Automated document review, classification, and quality checking;
• Translation assistance and language processing;
• Customer service automation, including AI-powered chatbots;
• Data analysis and pattern recognition for service improvement;
• Risk assessment and fraud detection.
Our AI chat services may collect and process personal data that you voluntarily provide during chat interactions. This data is used to generate responses, improve the chat service, and escalate issues to human representatives where appropriate.
We do not use AI to make decisions that produce legal effects concerning you or similarly significantly affect you without human oversight, except where explicitly authorized by you or required by Applicable Law. AI-generated outputs are reviewed by qualified personnel before being relied upon for any decisions affecting your rights or interests.
AI processing is conducted in compliance with applicable UAE regulations, including guidelines issued by TDRA and NESA concerning AI governance, transparency, and data protection. We implement appropriate safeguards to ensure that AI systems operate fairly, transparently, and without unlawful bias.
You have the right to request that a decision based solely on automated processing, including profiling, be reviewed by a human. To exercise this right, please contact us at legal@zenvisa.net.
15. Automated Decision-Making
We generally do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. Where we do use automated decision-making, such decisions are subject to meaningful human review and oversight.
Circumstances in which automated decision-making may occur include:
• Preliminary fraud screening and risk assessment, where automated systems flag transactions or activities for human review;
• Document completeness checks, where automated systems identify missing information before human review;
• Creditworthiness assessments, where conducted in accordance with Applicable Law.
Where required by the GDPR or other Applicable Law, we will obtain your explicit consent before subjecting you to automated decision-making that produces legal or similarly significant effects. You have the right to contest any automated decision, request human intervention, express your point of view, and obtain an explanation of the decision.
16. Communication by Email, WhatsApp, SMS and Telephone
We communicate with you through various channels, including email, WhatsApp, SMS, and telephone, depending on your preferences and the nature of our communications.
By providing your contact information to us, you consent to receiving communications from us through these channels for the following purposes:
• Service-related communications, including updates on your applications, document submissions, and processing status;
• Administrative communications, including account notifications, billing information, and policy updates;
• Marketing and promotional communications (subject to your consent and opt-out rights);
• Customer support and inquiry responses;
• Compliance-related communications, including AML/KYC verification requests.
WhatsApp communications are subject to WhatsApp's own privacy policy and terms of service. We do not share your WhatsApp contact information with unrelated third parties for marketing purposes.
Standard messaging rates may apply to SMS communications, depending on your mobile service provider and plan. You may opt out of SMS marketing communications at any time by replying "STOP" to any marketing message.
Telephone calls may be recorded for quality assurance, training, and compliance purposes. Where required by Applicable Law, we will notify you at the beginning of any recorded call and obtain your consent.
17. Marketing Communications
With your consent where required by Applicable Law, we may send you marketing communications about our Services, special offers, industry updates, and events that we believe may be of interest to you.
Marketing communications may be sent by email, WhatsApp, SMS, or telephone. We will obtain your explicit consent before sending marketing communications where required by the PDPL, GDPR, or other Applicable Law.
You have the right to opt out of receiving marketing communications at any time by:
• Clicking the "unsubscribe" link in any marketing email;
• Replying "STOP" to any marketing SMS message;
• Contacting us at legal@zenvisa.net with the subject line "Opt-Out";
• Updating your communication preferences in your account settings on the Website.
Please note that even if you opt out of marketing communications, you will continue to receive transactional and administrative communications related to your use of our Services, as these are necessary for the performance of our contract with you.
We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
18. Payment Information
When you make payments for our Services, we collect payment information necessary to process the transaction. This may include:
• Credit card number, expiry date, and security code (CVV);
• Debit card details and bank account information;
• Billing name, billing address, and contact details;
• Transaction history and payment confirmation records.
Payment card data is processed by our third-party payment processors in accordance with the Payment Card Industry Data Security Standard (PCI DSS). We do not store your full credit card details on our servers. Our payment processors are contractually obligated to process payment data only for the purpose of completing your transaction and in compliance with Applicable Law.
We retain payment records, including invoices, receipts, and transaction confirmations, for accounting, tax compliance, and audit purposes in accordance with our data retention schedules set out in Clause 30.
19. Fraud Prevention
We implement fraud prevention measures to protect our business, our clients, and the integrity of our Services. As part of these measures, we may:
• Verify your identity using third-party identity verification services;
• Screen your information against fraud databases and watchlists;
• Analyze transaction patterns to detect suspicious activity;
• Share information with law enforcement and regulatory authorities where required by law or where necessary to prevent fraud;
• Retain fraud-related data for the periods required by Applicable Law.
Our fraud prevention activities are conducted in accordance with Applicable Law and are necessary for our legitimate interests in preventing financial crime and protecting our business.
20. Anti-Money Laundering and KYC Compliance
We are required by law to comply with anti-money laundering (AML) and know-your-customer (KYC) obligations under UAE Federal Decree-Law No. 20 of 2018 on Anti-Money Laundering and Combating the Financing of Terrorism, Cabinet Decision No. 10 of 2019, and related regulations.
To comply with these obligations, we may:
• Collect and verify your identity using government-issued identification documents;
• Collect and verify your residential address and contact details;
• Screen your information against sanctions lists, politically exposed persons (PEP) databases, and adverse media sources;
• Collect information about the source of funds and the purpose of the transaction;
• Collect and verify beneficial ownership information for corporate clients;
• Monitor transactions and report suspicious activities to the UAE Financial Intelligence Unit (FIU);
• Retain AML/KYC records for the periods required by Applicable Law.
The collection and processing of personal data for AML/KYC purposes is necessary for compliance with a legal obligation. You are required to provide accurate and complete information for these purposes. Failure to provide the requested information may result in our inability to provide Services to you.
We may share your personal data with the UAE FIU, the Executive Office for Control and Non-Proliferation, and other regulatory authorities as required by law. We may also share information with our AML compliance service providers and screening technology vendors, who are bound by data protection obligations.
21. Identity Verification
We verify the identity of our clients as part of our KYC procedures and to prevent fraud, identity theft, and financial crime. Identity verification may involve:
• Reviewing and validating government-issued identification documents;
• Comparing biometric data (such as facial photographs) against identification documents;
• Using third-party identity verification services and databases;
• Conducting liveness detection checks through video verification;
• Cross-referencing information against public and private databases.
Identity verification data is processed with enhanced security measures and is accessed only by authorized personnel who have undergone appropriate background checks and training. Verification results are retained in accordance with our AML/KYC record retention obligations.
22. Data Accuracy Responsibilities
You are responsible for ensuring that the personal data you provide to us is accurate, complete, and up to date. You must notify us promptly of any changes to your personal data, including changes to your name, address, contact details, employment status, or other relevant information.
We will take reasonable steps to ensure that the personal data we process is accurate and, where necessary, kept up to date. However, we rely on you to inform us of any changes to your personal data. We are not responsible for any losses, delays, or adverse outcomes resulting from inaccurate, incomplete, or outdated information provided by you.
Where we become aware that personal data we hold is inaccurate or incomplete, we will take reasonable steps to correct or complete it, either on our own initiative or at your request.
23. Sharing with Government Authorities
We may share your personal data with Government Authorities where necessary to provide our Services or as required by Applicable Law. Circumstances in which we may share personal data with Government Authorities include:
• Submitting applications, documents, and supporting information on your behalf to Government Authorities as part of our document clearing services;
• Responding to requests, inquiries, or directives from Government Authorities;
• Complying with legal obligations, court orders, subpoenas, or regulatory requirements;
• Reporting suspicious activities, fraud, or illegal conduct to law enforcement or regulatory bodies;
• Cooperating with investigations, audits, or inspections conducted by Government Authorities.
Government Authorities to whom we may disclose personal data include: the General Directorate of Residency and Foreigners Affairs (GDRFA), the Federal Authority for Identity and Citizenship (ICA), the Ministry of Human Resources and Emiratisation (MOHRE), the Department of Economic Development (DED), the Ras Al Khaimah Economic Zone Authority (RAKEZ), the Telecommunications and Digital Government Regulatory Authority (TDRA), the National Electronic Security Authority (NESA), and the UAE Financial Intelligence Unit (FIU).
We have no control over how Government Authorities process personal data once it has been disclosed to them. Government Authorities are independent data controllers for their own processing activities and are subject to their own privacy policies and data protection obligations.
24. Sharing with Immigration Authorities
Where you engage our Services for purposes related to visa applications, residency permits, entry permits, or other immigration-related matters, we may share your personal data with immigration authorities, including:
• The General Directorate of Residency and Foreigners Affairs (GDRFA) in each emirate;
• The Federal Authority for Identity and Citizenship (ICA);
• The Ministry of Foreign Affairs and International Cooperation;
• Relevant immigration authorities in other jurisdictions where you have requested our assistance.
The personal data shared with immigration authorities may include your name, date of birth, nationality, passport number, photograph, contact details, employment information, and other information required for the processing of your immigration application.
We share this data only for the purpose of facilitating your application or request and in accordance with your instructions. We do not share immigration-related personal data with any party not directly involved in the processing of your application, except as required by law.
Immigration authorities process your personal data as independent data controllers in accordance with their own legal frameworks and privacy policies. We are not responsible for the privacy practices of immigration authorities.
25. Third-Party Service Providers
We engage third-party service providers to perform functions and provide services on our behalf. These providers may have access to your personal data only to the extent necessary to perform their functions and are contractually obligated to process such data in accordance with this Privacy Policy and Applicable Law.
Categories of third-party service providers include:
• Payment processing providers;
• Cloud hosting and data storage providers;
• Customer relationship management (CRM) and business management software providers;
• Email and communication service providers;
• Analytics and website performance monitoring providers;
• Identity verification and AML screening providers;
• Translation and document processing service providers;
• Courier and postal service providers;
• Legal, accounting, and professional service providers;
• IT support and cybersecurity service providers.
We require all third-party service providers to implement appropriate technical and organizational measures to protect your personal data and to process it only for the specified purposes. We do not authorize our service providers to use your personal data for their own marketing purposes or to disclose it to unauthorized third parties.
26. International Data Transfers
We are based in the United Arab Emirates and process personal data primarily within the UAE. However, your personal data may be transferred to, stored in, or accessed from countries outside the UAE, including countries that may not provide the same level of data protection as the UAE.
International transfers of personal data may occur in the following circumstances:
• To our cloud hosting and data storage providers with servers located outside the UAE;
• To third-party service providers located outside the UAE who assist us in providing our Services;
• To Government Authorities or immigration authorities in jurisdictions outside the UAE where you have requested our assistance;
• To payment processing providers with operations outside the UAE;
• To analytics providers, such as Google, whose servers are located outside the UAE.
Where we transfer personal data outside the UAE, we implement appropriate safeguards to ensure an adequate level of data protection, including:
• Standard Contractual Clauses (SCCs) approved by the UAE data protection authority;
• Transferring data only to jurisdictions recognized by the UAE as providing adequate data protection;
• Implementing supplementary technical measures, such as encryption and pseudonymization;
• Conducting transfer impact assessments where required.
For transfers of personal data from the European Economic Area or the United Kingdom to the UAE, we rely on appropriate safeguards under the GDPR and UK GDPR, including Standard Contractual Clauses with supplementary technical and organizational measures where necessary.
By using our Services, you consent to the transfer of your personal data outside the UAE as described in this Clause, to the extent that such consent is required under Applicable Law.
27. Cloud Storage
We use cloud-based infrastructure and storage solutions to store and process personal data. Our cloud service providers are selected based on their security standards, compliance certifications, and data protection capabilities.
Our cloud storage providers may store data in multiple geographic locations, including data centers outside the UAE. All data stored in the cloud is encrypted at rest and in transit using industry-standard encryption protocols.
We have entered into data processing agreements with our cloud service providers that require them to:
• Process personal data only in accordance with our documented instructions;
• Implement appropriate technical and organizational security measures;
• Ensure the confidentiality of personal data and restrict access to authorized personnel;
• Notify us promptly of any data breaches or security incidents;
• Assist us in responding to data subject rights requests;
• Delete or return personal data upon termination of the agreement.
We regularly review our cloud storage arrangements to ensure ongoing compliance with Applicable Law and the security of your personal data.
28. Data Security Measures
We implement a comprehensive information security program designed to protect your personal data against unauthorized access, alteration, disclosure, or destruction. Our security measures include:
• Organizational security policies and procedures;
• Regular security risk assessments and vulnerability testing;
• Employee background checks and security awareness training;
• Physical security controls at our premises;
• Network security measures, including firewalls, intrusion detection, and prevention systems;
• Incident response and business continuity plans;
• Regular security audits and compliance reviews.
Our security program is designed to meet or exceed the requirements of the PDPL, GDPR, and industry best practices. However, no method of transmission over the internet or electronic storage is completely secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.
29. Encryption and Access Controls
We use encryption and access control technologies to protect your personal data:
29.1 Encryption
• Data in transit is encrypted using Transport Layer Security (TLS) 1.2 or higher;
• Data at rest is encrypted using Advanced Encryption Standard (AES) 256-bit encryption;
• Passwords and authentication credentials are hashed using industry-standard algorithms;
• Email communications containing sensitive personal data are encrypted where technically feasible.
29.2 Access Controls
• Access to personal data is restricted to authorized personnel on a need-to-know basis;
• Multi-factor authentication (MFA) is required for access to systems containing personal data;
• Role-based access controls (RBAC) ensure that employees can access only the data necessary for their job functions;
• Access logs are maintained and regularly reviewed for unauthorized access attempts;
• Physical access to servers and data centers is restricted and monitored.
30. Data Retention Periods
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, to comply with legal obligations, to resolve disputes, and to enforce our agreements. Our retention periods are determined based on the type of data, the nature of the processing, and applicable legal requirements.
30.1 General Retention Periods
• Identity and contact information: retained for the duration of our business relationship and for five (5) years thereafter, or as required by AML/KYC laws;
• Service-related documents and correspondence: retained for five (5) years from the date of last service or as required by applicable record-keeping laws;
• Financial and payment records: retained for seven (7) years from the date of transaction in accordance with tax and accounting requirements;
• Technical information and cookies: retained for the periods specified in our Cookie Policy, generally not exceeding thirteen (13) months;
• Marketing preferences and communication records: retained until you withdraw consent or opt out, and for two (2) years thereafter for compliance purposes.
30.2 Extended Retention
We may retain personal data for longer periods where: (a) required by Applicable Law; (b) necessary for the establishment, exercise, or defense of legal claims; (c) necessary for fraud prevention or ongoing investigations; or (d) required by our professional indemnity insurance obligations.
30.3 Destruction
Upon expiry of the applicable retention period, personal data is securely deleted, destroyed, or anonymized in accordance with our data destruction procedures. Paper records are shredded or incinerated, and electronic records are permanently deleted using secure erasure methods.
31. Record Keeping
We maintain comprehensive records of our processing activities in accordance with the requirements of the PDPL and other Applicable Law. Our records include:
• The purposes of processing;
• Categories of data subjects and categories of personal data;
• Categories of recipients to whom personal data has been or will be disclosed;
• Information about international transfers of personal data;
• Where possible, the envisaged time limits for erasure of different categories of data;
• A general description of technical and organizational security measures.
These records are maintained in a secure manner and are made available to the UAE data protection authority upon request.
32. Children's Privacy
Our Website and Services are not intended for children under the age of eighteen (18) years, and we do not knowingly collect personal data from children under 18. If we become aware that we have collected personal data from a child under 18 without verification of parental consent, we will take steps to delete that information as soon as possible.
If you believe that we may have collected personal data from a child under 18, please contact us immediately at legal@zenvisa.net.
For Users between the ages of 18 and 21, where required under UAE civil law, we may request evidence of parental or guardian consent for the processing of personal data.
33. International Users
The Website and Services are operated from the United Arab Emirates. If you access the Website or use our Services from outside the UAE, you acknowledge and agree that your personal data will be transferred to, stored in, and processed in the UAE and potentially other countries, as described in Clause 26.
Users accessing the Website from the European Economic Area, the United Kingdom, or other jurisdictions with applicable data protection laws are entitled to the rights set out in Clause 35. We process personal data of EEA and UK residents in accordance with the GDPR and UK GDPR to the extent required by Applicable Law.
Users from jurisdictions with mandatory data localization requirements should contact us to discuss data storage options before engaging our Services.
34. User Rights under PDPL
Under the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), you have the following rights in relation to your personal data:
• The right to know whether your personal data is being processed and to obtain information about the processing;
• The right to request access to your personal data;
• The right to request rectification of inaccurate or incomplete personal data;
• The right to request erasure of your personal data in certain circumstances;
• The right to request restriction of processing in certain circumstances;
• The right to object to processing based on legitimate interests or for direct marketing purposes;
• The right to withdraw your consent at any time;
• The right to lodge a complaint with the UAE data protection authority.
These rights are not absolute and may be limited by Applicable Law, including where processing is necessary for compliance with a legal obligation, for the establishment, exercise, or defense of legal claims, or for reasons of public interest.
35. User Rights under GDPR
If you are located in the European Economic Area or the United Kingdom, you have the following additional rights under the GDPR and UK GDPR:
• The right to be informed about the collection and use of your personal data;
• The right of access to your personal data;
• The right to rectification of inaccurate or incomplete personal data;
• The right to erasure ("right to be forgotten") in certain circumstances;
• The right to restrict processing of your personal data;
• The right to data portability;
• The right to object to processing, including objecting to direct marketing;
• The right not to be subject to a decision based solely on automated processing, including profiling;
• The right to withdraw consent at any time;
• The right to lodge a complaint with a supervisory authority in your country of residence, place of work, or place of the alleged infringement.
To exercise any of your rights, please contact us using the details provided in Clause 49. We will respond to your request within thirty (30) days of receipt, or within such other period as may be required by Applicable Law. We may request additional information to verify your identity before processing your request.
36. Right to Access
You have the right to request a copy of the personal data we hold about you. Your access request may include:
• Confirmation of whether we process your personal data;
• A copy of your personal data in a commonly used electronic format;
• Information about the purposes of processing;
• Information about the categories of personal data being processed;
• Information about the recipients or categories of recipients to whom your personal data has been or will be disclosed;
• The envisaged retention period or the criteria used to determine that period;
• Information about the existence of automated decision-making, including meaningful information about the logic involved.
We will provide the requested information free of charge, except where requests are manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse to act on the request.
37. Right to Rectification
You have the right to request the rectification of inaccurate or incomplete personal data we hold about you. If you believe that any personal data we hold about you is incorrect, out of date, or incomplete, please contact us at legal@zenvisa.net with details of the information you believe needs to be corrected and supporting documentation where appropriate.
We will rectify the inaccurate data within thirty (30) days of receiving your request, or within such shorter period as may be required for time-sensitive matters. Where we have shared your personal data with third parties, we will notify them of the rectification where possible and where required by Applicable Law.
38. Right to Erasure
You have the right to request the erasure of your personal data in the following circumstances:
• The personal data is no longer necessary for the purposes for which it was collected;
• You have withdrawn your consent and there is no other legal basis for the processing;
• You have objected to the processing and there are no overriding legitimate grounds for the processing;
• The personal data has been unlawfully processed;
• The personal data must be erased for compliance with a legal obligation.
We may refuse your erasure request where processing is necessary: (a) for compliance with a legal obligation; (b) for the establishment, exercise, or defense of legal claims; (c) for reasons of public interest; or (d) for archiving purposes in the public interest, scientific research, or historical research. We will inform you of the reasons for any refusal.
39. Right to Restrict Processing
You have the right to request the restriction of processing of your personal data in the following circumstances:
• You contest the accuracy of the personal data, for a period enabling us to verify the accuracy;
• The processing is unlawful and you oppose the erasure of the personal data and request the restriction of its use instead;
• We no longer need the personal data for the purposes of processing, but you require it for the establishment, exercise, or defense of legal claims;
• You have objected to processing pending the verification whether our legitimate grounds override yours.
Where processing has been restricted, we will only process the relevant personal data: (a) with your consent; (b) for the establishment, exercise, or defense of legal claims; (c) for the protection of the rights of another natural or legal person; or (d) for reasons of important public interest. We will inform you before the restriction of processing is lifted.
40. Right to Object
You have the right to object to the processing of your personal data where the processing is based on our legitimate interests or those of a third party. If you object, we will cease processing unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.
You have the absolute right to object at any time to the processing of your personal data for direct marketing purposes. If you exercise this right, we will cease processing your personal data for marketing purposes.
To exercise your right to object, please contact us at legal@zenvisa.net with the subject line "Objection to Processing."
41. Right to Data Portability
Where the processing of your personal data is based on your consent or on a contract, and the processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format. You also have the right to transmit that data to another controller without hindrance from us, or to have us transmit the data directly to another controller where technically feasible.
This right applies only to personal data that you have provided to us. It does not apply to personal data that we have generated or inferred. We will provide your data in JSON or CSV format unless you request another commonly used format.
42. Withdrawal of Consent
Where we process your personal data based on your consent, you have the right to withdraw your consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
You may withdraw your consent by:
• Contacting us at legal@zenvisa.net with the subject line "Withdrawal of Consent";
• Updating your preferences in your account settings on the Website;
• Clicking the unsubscribe link in any marketing communication.
Please note that withdrawing consent may affect our ability to provide certain Services to you. We will inform you of the consequences of withdrawal before processing your request.
43. Complaint Procedure
If you have a complaint about our processing of your personal data, you may submit a complaint using the following procedure:
• Step 1: Contact us at legal@zenvisa.net with the subject line "Data Protection Complaint," providing details of your complaint, including the nature of the issue, the personal data concerned, and your preferred resolution.
• Step 2: We will acknowledge receipt of your complaint within three (3) Business Days.
• Step 3: We will investigate your complaint and provide a substantive response within fifteen (15) Business Days of acknowledgment. If the investigation requires additional time, we will notify you of the delay and provide an estimated completion date.
• Step 4: We will provide a written final response setting out our findings and any remedial action taken.
If you are not satisfied with our response, you have the right to lodge a complaint with:
• The UAE data protection authority;
• The supervisory authority in your country of habitual residence, place of work, or place of the alleged infringement (for EEA and UK residents);
• The Ras Al Khaimah Economic Zone Authority (RAKEZ).
44. Data Breach Response
We have implemented procedures to detect, assess, and respond to personal data breaches in accordance with the requirements of the PDPL, GDPR, and other Applicable Law.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
• Take immediate steps to contain the breach and mitigate any damage;
• Assess the nature, scope, and potential impact of the breach;
• Notify the relevant data protection authority within seventy-two (72) hours of becoming aware of the breach, where required by law;
• Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms;
• Document the breach, including the facts, effects, and remedial actions taken.
Where we act as a Data Processor on behalf of a client, we will notify the Data Controller without undue delay upon becoming aware of a personal data breach.
Our breach notification to affected individuals will include: a description of the nature of the breach, the categories and approximate number of data subjects concerned, the likely consequences of the breach, and the measures taken or proposed to address the breach and mitigate its potential adverse effects.
45. Third-Party Websites
The Website may contain links to third-party websites, services, and applications that are not owned or controlled by the Company. This Privacy Policy does not apply to any third-party websites or services.
We are not responsible for the privacy practices, content, or security of any third-party websites or services. We encourage you to review the privacy policies of any third-party websites or services you access.
The inclusion of a link to a third-party website does not imply endorsement, sponsorship, or recommendation by the Company.
46. Business Transfers
In the event that the Company sells, transfers, or merges all or substantially all of its assets, or undergoes a change of control, your personal data may be transferred to the acquiring entity or successor organization.
In such circumstances, we will ensure that the receiving entity agrees to protect your personal data in a manner consistent with this Privacy Policy and Applicable Law. We will notify you of any such transfer and of any changes to the purposes for which your personal data is processed.
47. Corporate Reorganization
Your personal data may be disclosed and transferred in connection with a corporate reorganization, merger, acquisition, joint venture, assignment, transfer, or other disposition of all or any portion of our business, assets, or stock, including in connection with any bankruptcy, insolvency, or similar proceeding.
In such cases, the receiving entity will be required to use your personal data in accordance with the terms of this Privacy Policy or to provide you with notice of any material changes.
48. Changes to this Privacy Policy
We reserve the right to modify, amend, or update this Privacy Policy at any time to reflect changes in our practices, legal requirements, or business operations. Material changes will be notified to you by posting a prominent notice on the Website or by sending an email to the address associated with your account, at least fifteen (15) days before such changes take effect.
Your continued use of the Website and Services following the posting of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with the modified Privacy Policy, you must immediately discontinue all use of the Website and Services.
We encourage you to review this Privacy Policy periodically for any changes. The "Last Updated" date at the top of this Privacy Policy indicates when it was most recently revised.
49. Contact Details
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
| Email: | legal@zenvisa.net |
|---|---|
| Address: | Compass Building, Al Hulaila Industrial Zone-FZ, Ras Al Khaimah, UAE |
| Website: | https://www.zenvisa.net |
| Response Time: | Within five (5) Business Days |
We will use commercially reasonable efforts to respond to all inquiries within five (5) Business Days of receipt.
50. Governing Law
This Privacy Policy and any dispute, claim, or controversy arising out of or in connection with it shall be governed by and construed in accordance with the laws of the United Arab Emirates, as applied in the Emirate of Ras Al Khaimah, without regard to its conflict of law principles.
Where the GDPR or UK GDPR applies to our processing of your personal data, those regulations shall also govern our data protection obligations to the extent required by Applicable Law.
51. Jurisdiction
The courts of the United Arab Emirates, and specifically the courts of the Emirate of Ras Al Khaimah, shall have exclusive jurisdiction over any dispute arising out of or in connection with this Privacy Policy, subject to the arbitration provisions set out in our Terms of Use.
Nothing in this Privacy Policy shall prevent data subjects in the EEA or UK from lodging complaints with their local supervisory authority or seeking remedies available under the GDPR or UK GDPR.
52. Severability
If any provision of this Privacy Policy is held to be invalid, illegal, or unenforceable by a court of competent jurisdiction or arbitral tribunal, such provision shall be modified to the minimum extent necessary to make it valid and enforceable, or if modification is not possible, such provision shall be severed from this Privacy Policy.
The invalidity, illegality, or unenforceability of any provision shall not affect the validity, legality, or enforceability of the remaining provisions, which shall continue in full force and effect.
53. Entire Policy
This Privacy Policy, together with our Cookie Policy and any other data protection notices we may provide, constitutes the entire agreement between you and the Company with respect to the processing of your personal data through the Website and Services, and supersedes all prior or contemporaneous agreements, representations, warranties, and understandings, whether written or oral, with respect to the subject matter hereof.
This Privacy Policy is incorporated into and forms part of our Terms of Use. In the event of any conflict between this Privacy Policy and the Terms of Use, this Privacy Policy shall govern with respect to data protection matters, and the Terms of Use shall govern with respect to liability limitations, indemnification, and dispute resolution.
54. Official Contact Information
For formal data protection inquiries, legal notices, and regulatory correspondence, please use the following official contact information:
| Legal Entity: | Zenway International FZ-LLC |
|---|---|
| DPO Contact: | legal@zenvisa.net |
| Registered Office: | Compass Building, Al Hulaila Industrial Zone-FZ, Ras Al Khaimah, UAE |
| RAKEZ License Nos.: | 47029828 / 17008106 / 17008107 |
| RAKEZ Ref: | 1639588-9LXu-LBZR-80986483 |
We are committed to protecting your privacy and handling your personal data with the utmost care and professionalism.
--- END OF PRIVACY POLICY ---
ZenVisa International
Your Trusted Partner in Business Documentation
Zenway International FZ-LLC | Compass Building, Al Hulaila Industrial Zone-FZ, Ras Al Khaimah, UAE
<www.zenvisa.net> | legal@zenvisa.net
Licensed by Ras Al Khaimah Economic Zone Authority (RAKEZ)
© 2026 Zenway International FZ-LLC. All Rights Reserved.