This page describes how Revi aligns its practices with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, "PDPL") and the rights it gives you over your personal data. Revi is operated by [Entity Name] FZCO, IFZA Licence No. [pending], Dubai, UAE. This page should be read alongside our full
Privacy Policy.
1. How we apply PDPL principles
The UAE PDPL sets out core principles for handling personal data. Here is how Revi applies each one:
- Lawfulness, fairness and transparency. We collect and process data only on a lawful basis (see Section 2), we are clear about how data is used, and we do not process data in ways you would not reasonably expect.
- Purpose limitation. We collect data for specific, explicit and legitimate purposes as set out in our Privacy Policy, and do not process it further in ways incompatible with those purposes.
- Data minimisation. We collect only the data we need to provide the Service. For Google-connected accounts we request the minimum API scopes required. Guest feedback collects only rating, optional comment, and optional name.
- Accuracy. Where we rely on data you provide, we encourage you to keep it up to date. You can update your account information at any time via the dashboard settings or by contacting us.
- Storage limitation. We retain data only for as long as necessary for the purposes described in our Privacy Policy. See our Retention and Deletion section for specific timeframes.
- Security. We implement appropriate technical and organisational measures — including TLS encryption in transit, encryption at rest, access controls and least-privilege principles — to protect personal data.
- Accountability. We maintain records of processing activities and sub-processors, conduct due diligence on processors, and provide Data Processing Agreements to business clients on request.
2. Our lawful bases for processing
Under the PDPL, we rely on the following lawful bases depending on the type of processing:
- Contractual necessity. Processing your account information, business review data, and billing information is necessary to perform our contract with you (the subscription agreement).
- Consent. Where we send marketing communications or where guests opt in to a business's newsletter via the Guest Care Portal, we rely on freely given, specific and informed consent. You may withdraw consent at any time.
- Legitimate interests. We process limited usage data to operate, secure and improve the Service, where this does not override your rights and interests.
- Legal obligation. We retain billing records and may disclose data to comply with UAE legal requirements.
3. Your rights under the PDPL
Subject to applicable law and exemptions, the UAE PDPL gives you the following rights:
Access
Request a copy of the personal data we hold about you, and information about how we use it.
Correction
Ask us to correct inaccurate or incomplete personal data about you.
Deletion
Request erasure of your personal data where we no longer have a lawful basis to retain it.
Objection
Object to processing of your data where we rely on legitimate interests as our lawful basis.
Portability
Receive your data in a structured, machine-readable format where processing is based on consent or contract.
Withdraw consent
Where processing relies on your consent, withdraw it at any time. Withdrawal does not affect prior lawful processing.
How to exercise your rights
Email hello@revi.ae with your request. We will respond within the timeframes required by the PDPL — generally within 30 days, extendable by a further 30 days where the complexity of the request requires it. We may ask you to verify your identity before processing your request.
There is no charge for exercising your rights, unless requests are manifestly unfounded or excessive.
4. Cross-border data transfers
Revi uses a small number of international sub-processors. Some processing therefore occurs outside the UAE:
- Anthropic (United States). Review text may be sent to Anthropic to generate AI-assisted responses. Anthropic processes data under a contractual arrangement consistent with PDPL Articles 22–23. Data is not retained by Anthropic beyond the processing request and is not used to train their models.
- Supabase (Singapore). Our primary database and application infrastructure is hosted on Supabase in the ap-southeast-1 (Singapore) region. Singapore has a recognised data protection framework and Supabase processes data under a Data Processing Agreement.
- Resend (United States). Transactional email delivery. Processes sender and recipient email addresses only; not used for profiling or marketing.
In each case, cross-border transfers are governed by contractual safeguards (standard contractual clauses or equivalent) to ensure your data receives an adequate level of protection. A copy of the applicable safeguards is available on request — email hello@revi.ae.
5. Data breach notification
In the event of a personal data breach that is likely to result in a risk to your rights or freedoms, Revi will:
- Notify the UAE Data Office without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in line with PDPL Article 9.
- Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights.
- Document all breaches, including those that do not require notification, and maintain an internal breach register.
Notification will describe the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, and the measures taken or proposed to address the breach.
6. Children's data
The Service is directed at businesses and their adult staff. We do not knowingly collect personal data from individuals under 18. If you believe we have inadvertently collected data from a minor, please contact us at hello@revi.ae and we will delete it promptly.
Guest feedback submitted via the Guest Care Portal is also intended for adult guests. Business clients using the portal are responsible for ensuring it is not used to collect data from children.
7. Data Processing Agreements
Business clients who process personal data through the Revi Service (for example, guest feedback data collected via their QR code) are data controllers in respect of that data. Revi acts as a data processor on their behalf.
A Data Processing Agreement (DPA) formalising this relationship and compliant with UAE PDPL requirements is available to all business clients on request. Email hello@revi.ae to request your DPA. It covers:
- Subject matter, duration, nature and purpose of processing.
- Types of personal data processed and categories of data subjects.
- Obligations and rights of the controller.
- Sub-processor list and change notification process.
- Security measures and breach notification procedures.
- Data return and deletion on contract termination.
For any PDPL-related question, to exercise your rights, or to raise a concern about how we process your data, contact us at:
Email: hello@revi.ae
Post: Revi, Dubai, United Arab Emirates
If you are not satisfied with our response, you have the right to lodge a complaint with the UAE Data Office (uaedataoffice.ae), the supervisory authority responsible for enforcing the PDPL.