Privacy and data protection
Maddict FZ LLC Privacy Policy
This policy explains how we collect, use, disclose, protect, and retain personal and location data, together with the privacy rights available to you.
Effective:
Overview
This Privacy Policy describes Our policies and procedures on the collection, use, and disclosure of Your information when You use the Service. It also explains Your privacy rights and how the law protects You.
We use Your Personal Data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.
Interpretation and definitions
Capitalized words have the meanings defined below. These meanings apply whether the words appear in singular or plural form.
- Company
- Maddict FZ LLC, DMC Building 10, Office 303, Dubai, United Arab Emirates, also referred to as the “Company”, “We”, “Us”, or “Our”.
- Territories
- The United Arab Emirates, Kuwait, Qatar, Bahrain, Oman, and the Kingdom of Saudi Arabia.
- Data Controller
- The legal person that, alone or jointly with others, determines the purposes and means of processing Personal Data. For GDPR purposes, the Company is the Data Controller.
- Device
- Any device that can access the Service, including a computer, mobile phone, or digital tablet.
- Personal Data
- Information relating to an identified or identifiable individual, including identifiers, location data, online identifiers, or factors relating to physical, physiological, genetic, mental, economic, cultural, or social identity.
- PDPL
- Applicable data-protection and privacy laws governing the collection, processing, and storage of personal or device data, including the UAE, KSA, and Bahrain laws identified below.
- Service Provider
- A natural or legal person that processes data on the Company's behalf to facilitate, provide, support, or analyze the Service. For GDPR purposes, Service Providers are Data Processors.
- Usage Data
- Data collected automatically through use of the Service or generated by the Service infrastructure, such as the duration of a page visit.
- You
- The individual accessing or using the Service, or the company or other legal entity on whose behalf that individual acts. Under GDPR, You may also be referred to as the Data Subject or User.
Applicable PDPL legislation
- UAE Federal Decree-Law No. 45 of 2021 regarding the Protection of Personal Data.
- The Kingdom of Saudi Arabia Personal Data Protection Law issued under Royal Decree and published on September 24, 2021.
- Bahrain Law No. 30 of 2018 with respect to Personal Data Protection and its implementing authority.
Collecting and using Your Personal Data
Personal Data
While using Our Service, We may ask You to provide personally identifiable information that can be used to contact or identify You. This may include Your email address, first and last name, and Usage Data.
Usage Data
Usage Data is collected automatically and may include Your Device's IP address, browser type and version, pages visited, visit time and date, time spent on pages, unique device identifiers, and other diagnostic data.
Location Data
We process pseudonymized or anonymized location signals from trusted data partners, including mobile app partners, SDK or location-service providers, aggregated mobility providers, and third-party data aggregators.
These signals typically include GPS coordinates, Wi-Fi or cell tower signals, an observation timestamp, and hashed or pseudonymized device-level identifiers. We do not receive directly identifiable information such as names, phone numbers, or email addresses with this data.
Reliability and security data
To maintain product reliability and security, We may process device type, operating system, network information, and IP addresses. IP addresses are anonymized or truncated where required.
How We use Personal Data
Advertising and marketing analytics
- Build audience segments.
- Provide advertisers with anonymized insights.
- Deliver contextual and interest-based advertising.
Measurement and reporting
- Analyze footfall and mobility trends.
- Measure campaign effectiveness.
- Provide aggregated reports to clients.
Security, operations, and compliance
- Prevent fraud or misuse, monitor and secure Our systems, and conduct audits and incident response.
- Maintain processing records, respond to Data Subject requests, and conduct impact assessments.
- Manage Your account, Service registration, requests, and access to available functionality.
- Perform contracts for products or services purchased through the Service.
- Contact You about Service functionality, contracted services, updates, and necessary security notices.
- Analyze data and usage trends and improve Our Service, products, marketing, and Your experience.
Business transfers and consent
We may use or share information when evaluating or completing a merger, financing, acquisition, restructuring, reorganization, dissolution, or sale of all or part of Our business or assets. We may also disclose information for another purpose with Your consent.
Retention of Personal Data
The Company retains Personal Data only for as long as necessary for the purposes described in this Privacy Policy. We may retain and use Personal Data as needed to comply with legal obligations, resolve disputes, and enforce Our legal agreements and policies.
Transfers, sharing, and disclosure
International transfers
Personal Data is processed at the Company's operating offices and other locations where the parties involved in processing are located. It may therefore be transferred to and maintained on systems outside Your country, where data-protection laws may differ.
The Company takes reasonably necessary steps to ensure data is handled securely and in accordance with this policy. Transfers will not take place unless adequate controls protect Your data and other personal information.
Aggregated insights and partners
We may share aggregated insights with advertisers, agencies, DSPs, SSPs, DMPs, publishers, out-of-home media owners, and measurement or analytics partners.
Business and legal disclosures
Personal Data may be transferred as part of a merger, acquisition, or asset sale. We will provide notice before transferred Personal Data becomes subject to a different privacy policy.
We may disclose Personal Data in response to valid requests by public authorities or where We believe in good faith that disclosure is necessary to comply with a legal obligation, protect the Company's rights or property, investigate wrongdoing, protect Users or the public, or protect against legal liability.
Security and data minimization
Security of Personal Data
The security of Your Personal Data is important to Us. No method of Internet transmission or electronic storage is completely secure, and while We use commercially acceptable safeguards, We cannot guarantee absolute security.
You may access and, where appropriate, update, correct, or delete Your personally identifiable and location information. We take reasonable steps to verify identity before granting profile access. You are responsible for maintaining the confidentiality of Your password and account information.
Service Providers
Service Providers may have access to Personal Data where required to support the Service. They collect, store, use, process, and transfer information about Service activity in accordance with their privacy policies and applicable contractual obligations.
Data minimization and anonymization
Before modeling or segmentation, We apply transformation layers that include:
- Removing directly identifiable information.
- Pseudonymizing and hashing device identifiers.
- Applying spatial and temporal aggregation.
- Using downsampling or noise addition where appropriate.
- Enforcing strict limitations designed to prevent re-identification.
Storage and security on GCP
Our infrastructure is hosted on Google Cloud Platform (GCP). Our technical and organizational safeguards include:
- Encryption in transit using TLS and at rest using AES-256.
- VPC-level network segmentation.
- Identity and access management with role-based access control.
- Audit logging and monitoring.
- Secret rotation and key management using GCP KMS.
- Regular security testing and vulnerability management.
GCP maintains compliance with major standards, including ISO 27001 and SOC 2, and supports GDPR-aligned processing.
GDPR privacy
Legal bases for processing
- Consent: You have given consent for processing Personal Data for one or more specific purposes.
- Performance of a contract: Personal Data is necessary to perform an agreement with You or related pre-contractual obligations.
- Legal obligations: Processing is necessary for compliance with a legal obligation to which the Company is subject.
- Vital interests: Processing is necessary to protect Your vital interests or those of another natural person.
- Public interests: Processing relates to a task carried out in the public interest or in the exercise of official authority vested in the Company.
- Legitimate interests: Processing is necessary for the legitimate interests pursued by the Company.
The Company will help clarify the legal basis that applies to a specific processing activity, including whether providing Personal Data is a statutory, contractual, or pre-contractual requirement.
Your GDPR rights
If You are within the European Union, You may have the right to:
- Request access to, update, or delete the Personal Data We hold about You, and receive a copy of that data.
- Request correction of incomplete or inaccurate Personal Data.
- Object to processing based on legitimate interests or for direct marketing.
- Request erasure where there is no good reason for Us to continue processing the data.
- Request transfer of eligible Personal Data in a structured, commonly used, machine-readable format.
- Withdraw consent where consent is the basis for processing. This may affect access to specific Service functionality.
Exercising Your rights
Contact Us to exercise rights of access, rectification, cancellation, or opposition. We may ask You to verify Your identity before responding and will aim to respond as soon as possible.
If You are in the European Economic Area, You also have the right to complain to Your local Data Protection Authority about Our collection and use of Personal Data.
Regional PDPL privacy rights
This section supplements the rest of the Privacy Policy for residents of the UAE, the Kingdom of Saudi Arabia, and Bahrain.
United Arab Emirates
Legal bases for processing under the UAE PDPL
- Consent: You have given explicit and clear consent for processing.
- Contractual necessity: Processing is necessary to perform a contract or take requested pre-contractual steps.
- Legal obligation: Processing is required to comply with UAE law.
- Protection of public interest: Processing is necessary for purposes such as national security or public health.
- Legitimate interests: Processing is necessary for the legitimate interests of the Data Controller or a third party, provided those interests do not override Your rights.
- Vital interests: Processing is required to protect the life or safety of the Data Subject or another person.
- Judicial and security requirements: Processing is required by authorities for judicial or law-enforcement purposes.
Your rights under the UAE PDPL
- Access Your Personal Data held by the Company.
- Correct inaccurate or incomplete Personal Data.
- Request deletion under applicable conditions.
- Restrict processing in specific circumstances.
- Receive eligible Personal Data in a structured, commonly used, machine-readable format.
- Object to processing, including direct marketing.
- Withdraw consent, where consent is the basis for processing.
- Lodge a complaint with the UAE Data Office.
Kingdom of Saudi Arabia
Legal bases for processing under the KSA PDPL
- Explicit consent: You have given clear, specific, and unambiguous consent.
- Contractual necessity: Processing is required to fulfill a contract or take requested pre-contractual steps.
- Legal or regulatory obligation: Processing is necessary to comply with Saudi laws or regulatory requirements.
- Vital interests: Processing is required to protect the life or health of the Data Subject or another person.
- Public interest: Processing is necessary for public-interest reasons, including national security, public health, or law enforcement.
Your rights under the KSA PDPL
- Request and obtain a copy of Your Personal Data.
- Correct or update inaccurate or incomplete Personal Data.
- Request deletion in applicable circumstances, including where the purpose of processing has been fulfilled.
- Restrict processing in specific cases.
- Object to processing, including direct marketing or automated decision-making.
- Withdraw consent at any time where processing is consent-based.
- File a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA).
Bahrain
Legal bases for processing under Bahrain's Data Protection Law No. 30 of 2018
- Consent: The Data Subject has provided informed and freely given consent.
- Contractual necessity: Processing is required to perform a contract or take requested pre-contractual steps.
- Legal obligation: Processing is necessary to comply with Bahrain's laws.
- Vital interests: Processing is needed to protect the life or health of the Data Subject or another person.
- Legitimate interest: Processing is necessary for the Data Controller's legitimate interests, provided those interests do not override the Data Subject's rights.
- Public interest or official authority: Processing is required for tasks carried out in the public interest or by an official authority.
Your rights under Bahrain's Data Protection Law
- Be informed about how Your Personal Data is processed.
- Access Your Personal Data.
- Correct inaccurate Personal Data.
- Request erasure where processing is no longer necessary.
- Object to processing, particularly for direct marketing.
- Receive eligible Personal Data in a structured format.
- Restrict processing in applicable cases.
- Withdraw consent at any time where processing is consent-based.
- Lodge a complaint with Bahrain's Personal Data Protection Authority.
Children's privacy
Our Service is not directed to anyone under the age of 15. We do not knowingly collect personally identifiable information from anyone under 15. If You are a parent or guardian and believe a child has provided Us with Personal Data, please contact Us.
If We learn that We collected Personal Data from someone under 15 without verified parental consent, We will take steps to remove it from Our systems. Where a country requires parental consent, We may request that consent before collecting or using a child's information.
Other websites and policy changes
Links to other websites
The Service may link to websites We do not operate. We recommend reviewing the privacy policy of every site You visit. We do not control and are not responsible for third-party content, privacy policies, or practices.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page, revise the effective date, and, where appropriate, provide advance notice by email or a prominent Service notice. Changes take effect when posted.