مقدمة

We are committed to protecting and respecting your privacy. This Privacy Notice (this “Notice”) governs the collection and use of personal data by Dubai Holding Investments, its affiliates or any company it controls. It explains how and why we use your personal data and applies to the personal data that you provide us directly, or which we may obtain from other sources.

We may use your personal data for any of the purposes described in this Notice, or as otherwise stated at the point of collection. For more information about Dubai Holding Investments please see www.dubaiholding.com.

References to "our", "us" or "we" within this Notice are to Dubai Holding Investments, Dubai, United Arab Emirates, P.O. Box 66000, privacyoffice@dubaiholding.com.

من نحن؟

We are the data controller of your personal data. We decide how and why your personal data is processed, either alone or jointly with others. For further details on your personal data we process jointly with others, please see the "Joint Controllers" heading below.

If you visit our venues or use our facilities and services, the entity which manages the relevant venue, facility or service will also be a data controller in respect of your personal information. You can access a ‘Data Controller List’ here, which sets out all of our different entities and their contact details. This will enable you to identify the relevant entity that holds, processes, and secures your personal data and is the data controller in relation to your personal data.

 المعلومات التي يغطيها هذا الإشعار

In this Notice we refer to “processing” your “personal data”.

Processing is taken to mean anything that is done to or with personal data (including simply collecting, storing or deleting that data).

Personal data is any information relating to an identified or identifiable living person (for example, name, email address, telephone number).  When “you” or “your” are used in this Notice, we are referring to the relevant individual who is the subject of the personal data. Relevant individuals may include Investors (including prospective investors), Employees (including company directors), Contractors, and other stakeholders.

Investor: Any individual or entity who has invested, or is considering investing in any part of our investment portfolio.

Employee: Any individual, who is employed by us, our investment partners or the relevant investment entity.

Contractor: Any individual who is contracted to perform services for us, our investment partners or the relevant investment entity.

Sensitive Data: Includes data that reveals racial or ethnic origin, political opinions, religious and philosophical beliefs, trade union membership, genetic data, biometric data for uniquely identifying a natural person, and data concerning health.

 استخدامنا لملفات تعريف الارتباط

Where we may use cookies, you can also control the data stored by cookies and withdraw consent to cookies by using the browser-based cookie controls described in our Cookie Policy available on our websites.

What personal data do we collect from you and how do we use it?

To provide services to you, we may process different categories of personal data whilst adhering to the data minimization and purpose limitation principles in accordance with the applicable data protection law. As described below:

Contact Details: Includes, but is not limited to, home address, home/personal mobile number, personal email address, and emergency contact number.

Identification Data: Includes, but is not limited to, name, title, company, individual physical description, photo, citizenship, nationality, passport data, visa information, driver’s license information, resident country's ID, marriage certificate, birth certificate, education certificates, national/social insurance number (if applicable), health insurance, government retirement plan information, and tax reference/ID (if applicable).

Sensitive Data: Includes data that reveals racial or ethnic origin, political opinions, religious and philosophical beliefs, trade union membership, genetic data, biometric data for uniquely identifying a natural person, and data concerning health.

Web Data: Includes, but is not limited to, cookies, user activity logs, IP address, social media profile, and website visitor interaction data.

Employee Related Data: Includes, but is not limited to, annual leave, cv, employee id, employment history, exit forms / interview, qualifications / grades, salary, test result (verbal, logical, numerical, psychometric), disclosure information (e.g., conflicts of interest), employee training information, employment information (including performance), grievance information, pension details, reference information and sick leave details.

Financial Data: Includes, but is not limited to, card details and bank details.

Other Personal Data: Includes, but is not limited to, date of birth, age, gender, voice recording, religion, languages spoken, place of birth, marital status, country of residence, family, signature and driving license number.


The reason these categories of personal data are processed, along with our lawful basis for doing so, are set out in the table below:

Description of Processing Purpose for Processing Category of Personal Data Lawful Basis Storage Period
Operations relating to our investment portfolio
We process your personal data for the purposes of board meetings (for example, personal data contained within board packs) Operations Contact Details, Employee Related Data, Financial Data We process personal data in line with our contractual obligations. We may also rely upon legitimate interest to process your personal data. DH to complete
We process your personal data to support approving salary increments and bonuses Operations Contact Details, Employee Related Data, Financial Data We process personal data in line with our contractual obligations. We may also rely upon legitimate interest to process your personal data. DH to complete
We process your personal data to conduct due diligence on an investment or investor (e.g., 'Know Your Customer' checks) Operations Identification Data, Contact Details, Employee Related Data, Sensitive Data We process personal data in line with our legal obligations and for reasons of substantial public interest (in the case of Sensitive Data). DH to complete
We process your personal data to support investigations relating to serious fraud or other mismanagement Operations Identification Data, Contact Details, Sensitive Data We process personal data in line with our legal obligations and for reasons of substantial public interest (in the case of Sensitive Data). DH to complete
We process your personal data in relation to the use of any annual or ESG reports (e.g., diversity reporting) Operations Contact Details, Employee Related Data, Sensitive Data We process personal data in line with our legal obligations and for reasons of substantial public interest (in the case of Sensitive Data). DH to complete
We process your personal data for the selection, appointment and renumeration of senior management of an investment Operations Identification Data, Contact Details, Employee Related Data, Financial Data We rely upon legitimate interest to process your personal data. DH to complete
We process your personal data to support decision-making required in relation to any day-to-day operations of a particular investment Operations Contact Details, Employee Related Data We rely upon legitimate interest to process your personal data. DH to complete
Internal Business Operations (note to DH: We have stripped out the non-applicable internal business operations below)
We process your personal data for procurement purposes, such as partner management and contract management. Supporting Services Identification Data, Contact Details, Financial Data We process personal data in line with our contractual obligations. 15 years from the date of last transaction.
We process your personal data for invoicing and payment purposes. Account Management Identification data, Contact details, Financial data We process personal data in line with our legal obligations. 15 years from the date of last transaction.
We process your personal data for management and audit of our business operations including accounting. Financial Management Identification data, Contact details, Financial data We rely upon legitimate interest to process your personal data. 15 years from the date of last transaction.
We process your personal data to comply with legal requirements and exercise or defend legal claims. Litigation & Disputes Identification data, Contact details We process personal data in line with our legal obligations. 15 years from the date of last transaction.
We process your personal data for security purposes and to ensure secure backup and archival of IT Systems. Security Purposes Identification data, Contact details We rely upon legitimate interest to process your personal data. 15 years from the date of last transaction.
We process your personal data for application management and support purposes, and to respond to requests. Security Purposes Identification Data, Contact Details, Financial Data, Web Data, Other Personal Data We rely upon legitimate interest to process your personal data. 15 years from the date of last transaction.
We process your personal data for identifying, investigating, and mitigating incidents, such as if a personal data breach occurred. Governance, Security Purposes Identification data, Contact details, Web data We rely upon legitimate interest to process your personal data. 15 years from the date of last transaction.
We process your personal data for whistleblowing purposes. Governance Identification data, Contact details We rely upon legitimate interest to process your personal data. 15 years from the date of last transaction.
We process personal data for disaster recovery purposes. Governance Identification data, Contact details We rely upon legitimate interest to process your personal data. 15 years from the date of last transaction.
We process your personal data for internal audit and risk management purposes. Audit Purposes Identification data, Contact details We rely upon legitimate interest to process your personal data. 15 years from the date of last transaction.
We process your personal data to facilitate application integration within our systems. Security Purposes Identification Data, Contact Details, Financial Data, Web Data, Other Personal Data We rely upon legitimate interest to process your personal data. 15 years from the date of last transaction.
We process your personal data in relation to incidents and accidents. Health & Safety Identification data, Contact details, Sensitive data As appropriate, we will process your personal data in reliance upon explicit consent provided by you or for vital interests. 15 years from the date of last transaction.
We process your personal data in order to provide medical care where required. Health and Safety Contact Details, Identification Data, Other Personal Data and Web Data. Consent, Vital Interest and Legal obligation 15 years from the date of last transaction.
We process your personal data for operations including building relationships through leads and on boarding new investors. Business Development Identification Data, Contact Details, Financial Data We rely upon legitimate interest to process your personal data. 15 years from the date of last transaction.
We process your personal data for market research purposes. Strategy Identification Data, Contact Details We rely upon legitimate interest to process your personal data. 15 years from the date of last transaction.
We process your personal data in line with our corporate social responsibility commitments. Corporate Social Responsibility Identification Data, Contact Details We rely upon legitimate interest to process your personal data. 15 years from the date of last transaction.


Personal Data Indirectly Obtained from Others

We may also receive some information about you from third parties. These are further detailed below:

Medical Service Providers: As necessary, we obtain your personal data from medical service providers when accidents and incidents occur, as well as in order to provide medical care when required.

Financial Service Providers: As necessary, we obtain your personal data from financial service providers for membership information purposes and to fulfill contracts or services.

To the extent necessary, we will also receive your personal data from other entities within the Dubai Holding Corporate LLC group of companies, including our subsidiaries and holding companies.

Legitimate Interest

Where we rely upon legitimate interest as a lawful basis, we have balanced your rights and freedoms against our interests, or those of any third parties, and determined your rights are not infringed. Legitimate Interest is where your personal data is processed for either our own interests or the interests of third parties. This can include commercial interests, individual interests, or broader societal benefits.

Joint controllers

For some investments in our portfolio, we jointly decide how and why we process your personal data with other parties. This means that we are joint controllers of your personal data outlined below for the following investments:

Investment Joint controllers - Entity names Purpose of joint Processing Category of Personal Data jointly processed Lawful basis
Smart City Malta Dubai Holding Investments, [DHI to insert JV partner full entity name] We, along with our joint controller partner, process your personal data to support approving salary increments, bonuses and promotions; and in association with any other board level decisions (to the extent this is applicable) Contact Details, Employee Related Data, Financial Data We process personal data related to salary increments, bonuses and promotions in line with our contractual obligations. For processing activities related to board level decisions, we rely upon legitimate interest to process your personal data.
MPC Dubai Holding Investments, [DHI to insert JV partner full entity name] We, along with our joint controller partner, process your personal data to support approving salary increments, bonuses and promotions; and in association with any other board level decisions (to the extent this is applicable) Contact Details, Employee Related Data, Financial Data We process personal data related to salary increments, bonuses and promotions in line with our contractual obligations. For processing activities related to board level decisions, we rely upon legitimate interest to process your personal data.
Waste to Energy Dubai Holding Investments, [DHI to insert other JV partner full entity names] We, along with our joint controller partner(s), process your personal data for the selection, appointment and renumeration of senior management; to support investigations relating to serious fraud or other mismanagement; and in association with any other board level decisions (to the extent this is applicable) Identification Data, Contact Details, Employee Related Data, Sensitive Data For the selection, appointment and renumeration of senior management and activities related to board level decisions,we rely upon legitimate interest to process your personal data. For investigations into serious fraud or other mismanagement, we process personal data in line with our legal obligations and for reasons of substantial public interest (in the case of Sensitive Data).
Merex Dubai Holding Investments, [DHI to insert JV partner full entity name] We, along with our joint controller partner, process your personal data associated with appointing or approving tenants; to conduct due diligence on a tenant or potential tenant (e.g., 'Know Your Customer' checks); and in association with any other board level decisions (to the extent this is applicable) Identification Data, Contact Details, Employee Related Data, Sensitive Data For the appointing or approving tenants, we rely upon legitimate interest to process your personal data. For conducting due diligence, we process personal data in line with our legal obligations and for reasons of substantial public interest (in the case of Sensitive Data).
Aurora Dubai Holding Investments, [DHI to insert JV partner full entity name] We, along with our joint controller partner, process your personal data for the selection, appointment and renumeration of senior management; to support investigations relating to serious fraud or other mismanagement; and in association with any other board level decisions (to the extent this is applicable) Identification Data, Contact Details, Employee Related Data, Sensitive Data For the selection, appointment and renumeration of senior management and activities related to board level decisions, we rely upon legitimate interest to process your personal data. For investigations into serious fraud or other mismanagement, we process personal data in line with our legal obligations and for reasons of substantial public interest (in the case of Sensitive Data).
Arady Dubai Holding Investments, [DHI to insert JV partner full entity name] We, along with our joint controller partner, process your personal data for the selection, appointment and renumeration of senior management; to support investigations relating to serious fraud or other mismanagement; and in association with any other board level decisions (to the extent this is applicable) Identification Data, Contact Details, Employee Related Data, Sensitive Data For the selection, appointment and renumeration of senior management and activities related to board level decisions, we rely upon legitimate interest to process your personal data. For investigations into serious fraud or other mismanagement, we process personal data in line with our legal obligations and for reasons of substantial public interest (in the case of Sensitive Data).
Dubai Hills Estate Dubai Holding Investments, [DHI to insert JV partner full entity name] We, along with our joint controller partner, process your personal data associated with interested parties or purchasers; to conduct due diligence on interested parties or purchasers (e.g., 'Know Your Customer' checks); and in association with any other board level decisions (to the extent this is applicable) Identification Data, Contact Details, Employee Related Data, Sensitive Data For the activities relating to interested parties or purchasers and activities related to board level decisions, we rely upon legitimate interest to process your personal data. For conducting due diligence, we process personal data in line with our legal obligations and for reasons of substantial public interest (in the case of Sensitive Data).
Rove Dubai Holding Investments, [DHI to insert JV partner full entity name] We, along with our joint controller partner, process your personal data for the selection, appointment and renumeration of senior management; to support investigations relating to serious fraud or other mismanagement; and in association with any other strategic decisions of the investment (e.g., exploring new markets or office locations, considering strategic partnerships, etc.) Identification Data, Contact Details, Employee Related Data, Sensitive Data For the selection, appointment and renumeration of senior management and activities related to other strategic decisions, we rely upon legitimate interest to process your personal data. For investigations into serious fraud or other mismanagement, we process personal data in line with our legal obligations and for reasons of substantial public interest (in the case of Sensitive Data).
D-Marin Dubai Holding Investments, [DHI to insert JV partner full entity name] We, along with our joint controller partner, process your personal data for the selection, appointment and renumeration of senior management; to support investigations relating to serious fraud or other mismanagement; and in association with any other board level decisions (to the extent this is applicable) Identification Data, Contact Details, Employee Related Data, Sensitive Data For the selection, appointment and renumeration of senior management and activities related to board level decisions, we rely upon legitimate interest to process your personal data. For investigations into serious fraud or other mismanagement, we process personal data in line with our legal obligations and for reasons of substantial public interest (in the case of Sensitive Data).

Where we rely upon legitimate interest as a lawful basis, we have balanced your rights and freedoms against our interests, or those of any third parties, and determined your rights are not infringed. Legitimate Interest is where your personal data is processed for either our own interests or the interests of our partners. This can include commercial interests, individual interests, or broader societal benefits. All other details related to this joint processing, including how long we keep your personal data, and who we share your personal data with, are contained within this privacy notice.

Where you wish to exercise your rights in relation to personal data we process jointly with other parties, please contact us using the following email address privacyoffice@dubaiholding.com.

If you wish to request further information relating to any personal data we process jointly with other parties, including how we have designated our respective duties under data protection law, please contact us at privacyoffice@dubaiholding.com.

كيف نستخدم بياناتك الشخصية؟
استخدام البيانات الشخصية
ما المدة التي نحتفظ فيها ببياناتك الشخصية؟

Your personal data will not be kept longer than necessary to meet the purposes detailed above. The criteria that we use to determine how long we will keep your personal data includes the period of time during which we have an ongoing relationship with you, and whether we have a legal obligation to store it (for example, for accounting purposes or for litigation, or regulatory investigations purposes). For the storage period please refer to the section titled "What do we collect from you and how do we use it ?" above.

Should retention of your personal data no longer be required we will remove it from our systems and records and/or take steps to properly anonymise it so that you can no longer be identified from it (unless we need to keep your information to comply with legal or regulatory obligations to which we are subject).

مع من نشارك بياناتك الشخصية؟

Where necessary to fulfil the purposes described in this Notice, we shall disclose your personal data to certain third-parties, vendors and service providers or affiliated employees, contractors and entities as described below.

To the extent necessary, and where we have a lawful basis to do so, we will also share your personal data with other entities within Dubai Holding Corporate LLC’s group of companies, including our subsidiaries and holding companies.

Where we share personal data, we do so with the following parties for the following purposes:

Category of Third-Party Purpose for Disclosure
Joint venture partners Day-to-operations relating to a particular investment.
Legal and Professional Advisers Audits, Invoicing, Legal Requirements, Transaction processing, Accident and Incidents, Comply with legal requirements and exercise or defend legal claims, Competition and events and IT security.
Health Providers Accident and Incidents, Comply with legal requirements and exercise or defend legal claims and Medical care
Finance, Insurance and Credit Providers Invoicing, Payment Processing, Insurance, Valuation
Government Bodies, Regulators Audits, Customer Queries, Invoicing, Legal Requirements, Improving our Service, Progress the Transaction
IT, Digital, Technology and Telecoms Audits, Customer Queries, Application Security and Support, Improving our Service, Analytics, Marketing and Memberships
Membership Associations IT security, Marketing and Memberships
كيف نحمي بياناتك الشخصية؟
الذكاء الاصطناعي والتعلم الآلي
تقييم الجوانب الشخصية

Where we have a lawful basis to do so, we will use your personal data to evaluate certain personal aspects about you, such as to analyse or predict aspects concerning your economic situation, personal preferences, interests, reliability, behaviour, location, or movements. This is known as “Profiling”. We undertake Profiling, which can involve the use of artificial intelligence, to tailor our services and marketing efforts, or to improve our offerings. By using Profiling, you or individuals with similar profile characteristics as you, may receive a more personalised experience with us or offers from us. You have the right to object to Profiling where we have used it to conduct direct marketing or where it is based on our legitimate interests. Please see section on “Your rights” for further information.

تفاصيل محددة حول التوصيف والقرارات الآلية المتعلقة بالمرشحين
 أين نقوم بتخزين/نقل بياناتك الشخصية؟

When processing your personal data, we may transfer this to third parties based in other countries, to the extent necessary to fulfil the purposes described in this Notice. Your personal data may be transferred within the Dubai Holding Corporate LLC’s group of companies, including to our subsidiaries and holding companies. Such transfers shall always be done in compliance with relevant data protection laws. The majority of personal data processed by us is stored in the United Arab Emirates, where the appropriate data protection measures are in place.

For transfers of personal data from the UK and European Economic Area (“EEA”) we transfer personal data to entities outside the EEA, under the EU Standard Data Protection Clauses. Further information about transfers can be obtained by contacting us using the following email address privacyoffice@dubaiholding.com.

To the extent required, we will also transfer your personal data to third parties in connection with a reorganization, restructuring, merger, acquisition, or transfer of assets, provided that the receiving party agrees to treat your personal data in a manner consistent with applicable laws and requirements.

 أمن بياناتك الشخصية

We have implemented technology and operational security measures in order to protect personal data from loss, misuse, alteration, or destruction. Only authorised persons are provided access to personal data; such individuals have agreed to maintain the confidentiality of this personal data.

مواقع وتطبيقات الغير
حقوقك

You may have certain rights relating to your personal data. However, these rights can differ depending upon the country in which you are located. That country’s law will determine which rights apply and in what instances.

Right to withdraw consent

Where you have provided your consent to us, you will always have the right to withdraw this at any time. You can do this by either by following the information provided at the time you provided your consent, or by contacting us using the following email address privacyoffice@dubaiholding.com. The withdrawal of consent will not affect any processing that was based on consent before its withdrawal.

Right to request correction of your personal data

You will always have the right to request that we correct and update any personal data that we process about you that is inaccurate or incomplete. You can do this by contacting us at privacyoffice@dubaiholding.com.

Additional Data Protection Rights

Certain Data Protection Regulation also provide you with additional rights which may allow you to:

- upon request, be provided access to, or copies of, your personal data that we process;

- upon request, restrict the processing of your personal data;

- upon request, delete your personal data which we process;

- object to our processing of your personal data; or

- upon request, obtain a copy of your personal data which we process in a commonly used and machine-readable format.

- lodge a complaint with the supervisory authority in your country of residence, place of work or the country in which an alleged infringement of data protection law has occurred

It is important to understand that these rights are not absolute (e.g. their application may depend upon the lawful basis we rely upon to process your personal data) and that we may require further information from you (e.g. to confirm your identity) to action your request. You can enquire whether these rights apply to you by contacting us using the following email address at privacyoffice@dubaiholding.com.

 آثار الذكاء الاصطناعي

Artificial Intelligence (AI) Systems:

We use AI Systems that process personal data to enable us to improve our services and user experiences. We remain vigilant when using AI to protect personal data, ensuring customer privacy, and preventing unauthorised or fraudulent activity. Our customers and stakeholders shall remain confident that personal data is adequately protected with us, especially in cases where AI is used to deliver the product or service, as this may infer heightened protection where AI is deployed.

How we use AI Systems

This notice gives you information on how we protect your personal data in our use of the AI System.

Personal data may be processed within our AI Systems. We remain the data controller for your personal data when it is processed while using our AI Systems. We process personal data in accordance with the relevant data protection laws. In the case where we have engaged a processor, we have mandated contracts that uphold our standards in compliance with the relevant data protection laws.

We will sometimes process customers' personal data when using AI Systems. We have regulated the use of AI internally, weighed the opportunities and risks in advance of our use of AI and ensured appropriate human supervision where important matters are concerned. Where we offer dialogues with an AI, we will make this evident and, if necessary, point out potential errors.

Personal Data Processed by AI Systems

We may collect personal data either directly from you, third parties or public sources. We process your personal data using AI Systems to improve the efficiency, quality, and speed of our business processes and for the purpose of providing services. When using AI systems, we may process various types of personal data. For more information, please refer to the section titled "What do we collect from you and how do we use it?".

In limited circumstances, we may process sensitive data through the AI System, but we will ensure that we have the necessary lawful basis in place before doing so. Where we process your existing personal data we will continue to rely on the appropriate lawful basis for that processing activity. In certain instances, we engage data processors; however, they are unable to access any of your personal data entered in the AI Systems. We have mandated contracts with data processors to ensure that your personal data is protected.

اتصل بنا

If you want to exercise any of the rights set out above or have any questions or concerns about how we treat your personal data, please contact us at privacyoffice@dubaiholding.com or by writing to us at: Dubai Holding Corporate LLC, P.O. Box 66000, Dubai, United Arab Emirates. Please include your reply address when you write to us.

 التغييرات في هذا الإشعار

We keep this Notice under regular review. We reserve the right, at our discretion, to change, modify, add, or remove sections of this Notice at any time. You are also encouraged to review this Notice from time to time for updates. We will notify you of any changes (including when they will take effect) if we are required to do so by data protection laws.