Skip to content
RealEstateMena

Privacy

Last updated: 25 July 2026

How RealEstateMena handles personal data, written to describe what the software actually does.

Draft — needs legal review

Draft. This describes how the product actually handles data, but it has not been reviewed by a lawyer and is not yet a binding policy. It must be reviewed against UAE Federal Decree-Law 45 of 2021, Saudi PDPL and — where EU residents are involved — GDPR before the service is sold.

  • Identify the contracting legal entity, its jurisdiction and its registered address.
  • Confirm the controller/processor split: customers control their residents’ data, we process it on their instruction — this needs a data processing agreement.
  • Confirm hosting regions and whether any customer requires contractual data residency.
  • Set concrete retention periods per record type, including the seven-year default on audit records.
  • Confirm the lawful basis for processing resident data, which flows from the customer’s tenancy contract rather than from consent to us.

Two kinds of personal data

We handle personal data in two distinct roles, and the difference decides who you should contact about it.

Data about our CUSTOMERS — the property managers and landlords who subscribe — is data we control. That is a name, a work email address, the organisation name, and the sign-in records for that account.

Data about our customers’ RESIDENTS, OWNERS and CONTACTS is data we process on that customer’s instruction. We do not decide what is collected or why. A resident asking about their own data should contact the company that manages their building; we will support that company in answering.

What we collect about account holders

For someone who signs up and uses the dashboard:

  • Email address, name and organisation name, supplied at sign-up.
  • Sign-in records: the time a link was requested, the requesting IP address, and whether it was used. Retained briefly and then deleted automatically.
  • Activity records: which account acted, on what, when, and from which address. Retained as an audit trail.
  • We do not use advertising trackers, and we do not sell or share data with advertisers.

What customers store about their residents

A customer using the product to manage tenancies typically stores names, contact details, identity document details, tenancy terms, invoices, payments and cheque records for their residents, and bank details for the owners they act for.

Identity document numbers and bank account details are encrypted before they are written to the database, using keys held separately from it. A copy of the database on its own does not reveal them.

Separation between customers

Each customer’s data is isolated at the database level rather than by application code alone. A query that fails to scope itself to one account returns nothing rather than another customer’s records. This is described in detail on the security page and is verified automatically on every change to the software.

Sub-processors

The service runs on three suppliers, and no others:

  • Railway — application hosting and the database.
  • Netlify — hosting for this marketing site and the dashboard, and handling of the demo request form on this site.
  • Resend — delivery of transactional email, which is how sign-in links reach you.

Retention

Sign-in challenges are deleted within 24 hours of being used or expiring. Expired sessions are deleted after 30 days. Audit records are kept for seven years by default, reflecting the record-keeping periods that apply to property and tax records in the region.

Records deleted inside the product are recoverable rather than immediately destroyed, so that a mistaken deletion can be undone. Permanent erasure on request is handled separately and is possible at the database level.

Your rights

Depending on where you live, you may have the right to access, correct, export or erase your personal data, and to object to certain processing.

For data we control, write to hello@realestatemena.com. For data held by a property manager using our software, contact that company — they decide what happens to it, and we act on their instruction.

Contact

Questions about this policy: hello@realestatemena.com.