1. Scope and Definitions
This policy applies to all website visitors, prospects, clients, and partners interacting with Octoox digital services.
- Personal Data means any information that identifies or can reasonably identify an individual.
- Processing means collection, use, storage, sharing, transfer, or deletion of Personal Data.
- Controller means Octoox where we determine how and why Personal Data is processed.
2. Data We Collect
Depending on your interaction with us, we may collect:
- Identity and contact data: name, email, phone number, company, job role.
- Service inquiry data: project requirements, requested services, budget ranges, timeline details.
- Technical and usage data: IP address, browser/device details, page interactions, referrer information.
- Communication data: messages sent through contact forms, email, calls, and partnership forms.
- Marketing preferences: consent choices and campaign interaction history.
3. Purposes of Processing
We process data to operate and improve our business and services.
- Respond to inquiries and provide requested services.
- Prepare proposals, manage onboarding, and fulfill contractual obligations.
- Maintain service quality, website performance, and cybersecurity protections.
- Perform analytics, reporting, and internal business planning.
- Comply with legal, regulatory, and law enforcement obligations.
4. Cookies and Tracking Technologies
We use cookies and similar technologies to improve website functionality and user experience.
- Essential cookies support website operation and security.
- Analytics cookies help us understand usage patterns and improve content.
- You may control cookies through browser settings; disabling some cookies may affect functionality.
5. Data Sharing and Disclosure
We do not sell personal data. We may share data only when necessary and lawful.
- With service providers and processors supporting hosting, analytics, communications, and operations.
- With professional advisers, auditors, and insurers where required for legitimate business purposes.
- With competent public authorities where legally required or to protect rights, safety, and security.
- As part of mergers, acquisitions, or restructuring, subject to confidentiality safeguards.
6. International Transfers
Where data is transferred outside your jurisdiction, we apply reasonable safeguards to protect confidentiality and integrity.
- Transfers are limited to business-necessary recipients.
- Contractual and technical safeguards are used where appropriate.
- Access is restricted to authorized personnel and providers.
7. Data Retention
We retain personal data only for as long as necessary for the purposes stated in this policy or as required by applicable law.
- Inquiry records are retained to respond and follow up on requests.
- Client records are retained for service delivery, support, and compliance obligations.
- Data is deleted, anonymized, or securely archived when no longer required.
8. Security Measures
We implement administrative, technical, and organizational controls to protect personal data from unauthorized access, loss, misuse, or alteration.
- Access controls and role-based permissions.
- Secure infrastructure and monitoring practices.
- Incident response procedures for suspected data security events.
9. Your Rights
Subject to applicable law, you may have rights regarding your personal data.
- Request access to personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion or restriction of processing in eligible circumstances.
- Object to certain processing activities and withdraw consent where processing is consent-based.
10. Children Privacy
Our services are not directed to children, and we do not knowingly collect personal data from children without appropriate legal basis and consent where required.
11. Third-Party Links and Services
Our website may contain links to third-party websites or tools. We are not responsible for their privacy practices.
- Please review third-party privacy notices before providing personal data.
12. UAE and Abu Dhabi Compliance
Octoox aims to process personal data in alignment with applicable privacy and data protection requirements in the UAE, including relevant requirements applicable in Abu Dhabi.
- Compliance practices are applied proportionately to the nature of services and processing activities.
- Where requirements evolve, we update controls and practices accordingly.
13. Policy Updates
We may update this Privacy Policy from time to time to reflect legal, operational, or service changes.
- Updated versions will be published on this page with a revised effective date.