1. Who we are and what this policy covers
House of Tech FZ-LLC is a Free Zone Limited Liability Company in Ras Al Khaimah, United Arab Emirates, holding trade licence number 7007356 issued by Ras Al Khaimah Economic Zone (RAKEZ). Our registered address is FDCW1693, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates.
Our licence was issued on 2 May 2024. That is the licence issue date, not the effective date of this policy.
This policy explains how we handle personal information relating to our website, enquiries, business development and business relationships. We serve businesses in the UAE, but information identifying their owners, representatives, customers or other individuals may still be personal information.
We generally act as controller for our own enquiries and business administration, meaning we decide the purposes and means of that processing. When handling personal data on a client's instructions, we generally act as processor, as explained in clause 10.
Contact us about privacy or your information at connect@house-of-tech.com.
2. Information we handle
Depending on the interaction, we handle:
- Enquiries: name, email address, message and optional company, service-interest and budget details supplied through our contact form or correspondence.
- Business contacts: professional contact details, role, organisation, correspondence and relevant relationship history.
- Engagement records: proposals, contracts, project communications, approvals, support requests and relevant billing or payment records.
- Technical records: network addresses, request times, browser or device details and operational or security information processed by our website and infrastructure providers.
- Project information: material a client provides or authorises us to access, which may include personal information needed for the agreed work.
Please avoid sending passwords, identity documents, health information or other sensitive personal information through the general enquiry form. Where a project requires sensitive or specially regulated information, appropriate arrangements must be agreed first.
3. Sources of information
We receive information directly when you contact us or work with us, and may receive relevant business contact information from your organisation or a referral.
For business development, we research publicly available resources, such as business websites, directories and professional profiles, and use relevant business email addresses for email outreach. Information identifying an individual remains personal information even when it is publicly accessible. A public listing is not, by itself, consent to marketing.
Technical information is also generated when your device communicates with our website and its providers.
4. Purposes and legal grounds
We use information for the purposes below, with consent or another ground permitted by applicable UAE law. The relevant ground depends on the information, the person concerned and the purpose; we do not treat every activity as covered by a single general business interest.
- Enquiries and proposals: to respond to information you choose to provide and requests you make. We rely on the relevant consent or, where its conditions apply, steps requested before entering a contract with the individual concerned.
- Business relationships and services: to manage correspondence, deliver work and support an engagement. Contractual necessity is used only where it applies to the individual whose information is processed; a contract with a company does not automatically cover all information about its employees, customers or representatives. Other processing requires consent or a specifically applicable legal ground.
- Business research and email outreach: to identify relevant business needs and introduce our services. Where information identifies an individual, we use consent or an applicable legal exception. The public-data exception concerns information made public by that individual; information appearing on a third-party website does not automatically qualify. Where consent is required, it must be obtained before promotional processing.
- Accounting and legal records: to issue invoices, maintain accounts, meet applicable recordkeeping duties and establish, exercise or defend legal claims, relying on the relevant legal obligation or claims ground.
- Security and complaints: to operate and protect the site, address abuse and investigate concerns, using information necessary to fulfil applicable security obligations or pursue or defend legal claims. Any further use requires its own applicable ground.
Where we rely on consent, it must relate to the relevant purpose and you may withdraw it without affecting earlier lawful processing. If no lawful ground applies, the processing must not take place. This policy is a transparency notice: visiting the website or sending an enquiry does not provide blanket consent or subscribe you to promotional messages.
5. Website enquiries
When direct submission is offered, the contact form sends your details to our server for validation and email delivery. The current application uses Resend to deliver enquiries to House of Tech. Our mailbox provider then processes the message so we can receive, store and reply to it.
If the website instead offers an email-draft option, the information you enter stays in your browser until you choose to copy it or open your email application. Sending that draft involves your own email provider.
The enquiry endpoint uses a temporary in-memory hash derived from a network address to limit repeated submissions. Hashing does not necessarily make information anonymous. Our application limits the contents of its diagnostic logs, but hosting and delivery providers may maintain separate operational records.
Resend delivers our website enquiries, and Microsoft 365 hosts connect@house-of-tech.com and our business correspondence. Provider delivery logs and recoverable mailbox copies follow their applicable service and account settings; our own retention rules are set out in clause 11.
6. Business development and marketing choices
We use email for business development, including direct introductions to prospective UAE business clients identified from public resources. We do not use email-open pixels or click tracking in our outreach. Processing personal information for this purpose must meet the grounds described in clause 4; publicly available contact information is not blanket permission to send marketing.
You can stop promotional contact at any time by replying to our message or emailing connect@house-of-tech.com. There is no charge and you do not need to give a reason. We will stop promotional contact to that address and keep only the limited details needed to honour the objection. Our outreach process must check those suppression records before further contact.
Necessary communications about an active enquiry, engagement, invoice, security issue or support request may continue where appropriate. A request to stop marketing does not require us to delete records that we must retain for a different lawful purpose.
7. Cookies and website tracking
The current website application does not use analytics cookies, advertising pixels or other marketing trackers. It does not include an embedded chat service or meeting recorder, and the enquiry form does not subscribe you to a newsletter. Fonts are served locally.
The public website does not currently set application cookies or use browser storage to remember visitors or enquiry details. Vercel and other relevant infrastructure providers may process network addresses, request information, security logs and operational usage statistics to serve and protect the website. These server records are separate from advertising tracking.
If we introduce optional analytics, advertising or similar technologies, we will update this policy and provide any consent or choice controls required by law before activating them. Any necessary cookies or storage introduced by a security feature will be described with their purpose and duration when introduced.
8. Providers and disclosures
Information is handled by our owner/management and relevant service providers for the purposes described in this policy. We currently have no employees or subcontracted delivery personnel. Providers may use their own personnel and subprocessors to supply their services.
| Provider | Role |
|---|---|
| Vercel | Hosting, serving and protecting the public website; also an available hosting provider for agreed client projects. |
| Sevalla, a Kinsta service | Hosting and related infrastructure for agreed client projects. |
| Resend | Delivering website enquiry messages and processing delivery records. |
| Microsoft 365 | Receiving, storing and sending business email. |
| Zoho | Accounting, invoicing and related business records. |
| OpenAI and Anthropic | AI services used across business operations and agreed client work, subject to clause 10. |
The providers used for a particular client project, and their authorised access, are addressed in that engagement’s terms. Integrating with a client’s own systems does not give us or those systems permission to use information for unrelated purposes.
We may disclose relevant information to professional advisers where needed for advice or claims, and to authorities where required by law. A lawful business reorganisation or transfer may involve relevant records, subject to appropriate confidentiality and privacy protections.
Providers processing information on our instructions must be subject to the processing obligations required by applicable law. Some providers also act for their own service administration, security or legal responsibilities. We do not give them unrestricted permission to reuse information for unrelated purposes.
We do not sell personal information or disclose it to other businesses for their own independent advertising.
9. International processing
Our business is based in the UAE, but our providers may process information internationally, including in the United States. Resend stores its customer data, including enquiry and delivery records, in the United States. Other storage and processing locations depend on the provider, service, selected account region and relevant subprocessors; using a UAE client or a selected hosting region does not make all processing UAE-only.
Cross-border processing must meet applicable UAE requirements. Where an adequate level of protection or another permitted basis is required, that requirement must be met before the transfer. A provider contract or foreign standard clause is not by itself a blanket permission to transfer all categories of data.
For client projects, permitted providers, processing locations and necessary transfer arrangements are addressed before the relevant data is processed. Health, financial or other regulated information may have additional restrictions. Contact connect@house-of-tech.com for information about the arrangement relevant to your enquiry or engagement, subject to lawful security and confidentiality restrictions.
10. Client data and AI
When we process personal data on a client’s behalf, the client determines the purposes and lawful grounds. Its privacy notice explains that processing, and our duties are set out in the client agreement and applicable processing terms. If your request concerns information controlled by a client, please contact that organisation; we will assist it and route requests received by us as required.
We use AI across our business, including research, drafting, development, administration and agreed client work. Depending on the task, relevant inputs can include public business information, correspondence, project requirements, documents and source code. This does not authorise unrestricted submission of customer records or confidential information. Information must be limited to what is needed for a lawful purpose; sensitive, regulated or client-controlled information requires the appropriate arrangements first.
Our AI providers include OpenAI and Anthropic (Claude). Our policy excludes personal and client confidential information from provider model-training programmes, including voluntary training and feedback submissions. For that information, our required API configuration is no training and zero data retention for eligible content. We must confirm that the account, model and feature support the agreed controls before submission; otherwise we use information that does not identify individuals or disclose client confidences, or agree a different lawful arrangement before processing.
Provider zero-retention arrangements have defined scope and exceptions, including security or abuse investigations, legally required retention and features that require storage. They do not mean that every tool, stored feature or operational record has zero retention. We do not infer zero retention from paid access or no-training settings alone.
For our own business activities, we do not make solely automated decisions about individuals that produce legal or similarly significant effects. AI output is assistance, not a substitute for the human decisions and checks required for the task. Any client solution with consequential automated functions requires separate agreed safeguards and appropriate notices.
11. Retention
From this policy’s effective date, the following schedule governs records we control. These are our retention rules; provider defaults do not automatically carry out our review and deletion responsibilities. We retain less information where it is no longer needed and retain information longer only where a different lawful requirement or purpose justifies it.
| Record category | Retention rule |
|---|---|
| Enquiries that do not become engagements | Delete or anonymise within 12 months of the last meaningful contact, unless a documented legal obligation or claim requires retention. |
| Unresponsive prospect records | Delete or anonymise within six months of collection or the last genuine interaction. Sending another unsolicited message does not restart that period. A prospect who engages becomes an enquiry or business relationship under the relevant rule. |
| Marketing suppression records | Keep only the address, objection date and enough context to prevent recontact while we conduct outreach or could otherwise reimport the address. Review necessity at least annually; these records are not used for promotion. |
| Contracts, invoices and supporting accounting records | Keep records needed for UAE corporate-tax obligations for at least seven years after the end of the relevant tax period. Longer requirements, legal holds and necessary claims records take precedence. Other business records are reviewed for continuing necessity. Zoho is our accounting service. |
| Client project personal data | Return or delete according to the written processing agreement, lawful client instructions and applicable requirements. Retaining necessary billing or contract evidence does not authorise keeping the entire client dataset. |
| Hosting, email-delivery and security logs | Retained under the relevant provider’s service, plan and account settings for operation, security and applicable legal duties. Copies we export must be deleted when that purpose ends unless a documented hold applies. |
| Business email, backups and stored AI features | Email follows the rule for its contents, with deletion/recovery affected by Microsoft 365 settings and any applicable holds. Backup copies expire under the relevant service’s deletion cycle. AI content is subject to the controls and exceptions in clause 10; any separately agreed stored material needs an explicit deletion arrangement. |
We review records to apply this schedule. When retention is no longer justified, we delete or appropriately anonymise the information. Residual recoverable or backup copies remain subject to the relevant protection and expiry arrangements. A request to delete information does not require deletion of records subject to a lawful hold.
12. Security and incidents
The public website uses HTTPS. Its application includes input validation, abuse-prevention measures and limited diagnostic logging. Hosting and email providers also apply security measures to their services. This is not a claim that House of Tech holds a particular security certification or has implemented every available provider control.
We remain responsible for the safeguards required for information we handle, including business email and enquiry records. For client projects, access controls, hosting, backups, incident responsibilities and other appropriate safeguards must be addressed according to the scope and risks before processing begins. Mandatory protections are not optional or dependent only on a client requesting them.
Do not send passwords, identity documents, health records or other sensitive information through the general enquiry form. Projects requiring sensitive or regulated information need separate, appropriate arrangements first.
No transmission or storage method is completely secure. If an incident occurs, we will investigate, take appropriate action and make notifications required by applicable law and client agreements. Please contact us promptly if you believe information shared with us has been exposed or misused.
13. Your rights and complaints
Depending on the applicable law and circumstances, you may have rights to obtain information about processing, access your information, correct inaccuracies, request deletion, restrict or object to processing, obtain a portable copy, withdraw consent, or challenge certain automated decisions. These rights are subject to legal conditions and exceptions.
Send requests to connect@house-of-tech.com. We may request proportionate information to verify identity and understand the request. We will respond within the period required by the applicable law and explain any lawful limitation.
You may exercise any right to complain to the UAE Data Office or another authority competent under the law that applies to your information. The UAE Government’s data-protection information explains the federal framework. Contacting us does not restrict your right to approach an authority or court. You may ask us for assistance identifying the currently available complaint channel.
14. Children, external services and changes
Our business website and marketing are directed at professional audiences. We do not intentionally collect children's personal information through them. Contact us if you believe a child has submitted information that should be removed. A client project involving children requires appropriate separate arrangements and notices.
External services have their own privacy practices. Review their notices when providing information directly to them.
We may update this policy as practices or legal requirements change. We will show the actual revision date and provide additional notice or obtain consent where required. This version takes effect on the date stated above. It does not authorise retrospective processing or change the grounds on which information was originally collected.