1. Data Controller Information
Holistique Harmony Training
Office 214, 2nd Floor, Pyramid Center, Oud Metha, Dubai, UAE
Phone: +971 4 284 7744
Holistique Harmony Training is not currently registered for UAE VAT. A TRN will be issued upon registration.
Trade Licence: DED-1026968 (Dubai Department of Economic Development)
KHDA Training Permit: 630361
Data Protection Officer: Saleh Elhalik, Head of Operations
DPO contact: [email protected] (regulator + data-rights queries)
General contact: [email protected]
2. Data We Collect
We collect the following categories of personal data, on the lawful bases identified:
- Account information (name, email, phone, role) — Contract
- Identity documents (Emirates ID, passport, visa) — Contract + KHDA legal obligation
- Payment data (invoice records, last-4 + brand only) — Contract
- Academic data (enrolments, grades, attendance, certificates) — Contract
- Behavioural analytics (page views, quiz interactions) — Legitimate interest + consent
- Marketing preferences (newsletter subscriptions, opt-in toggles) — Consent
- Device / network (IP address, user-agent, locale) — Legitimate interest (security)
We collect limited health information (allergies, medications, conditions, blood type) on the registration form because some practical sessions involve chemicals, fragrances, and physical activity. This information is treated as sensitive personal data and is restricted to the operations team and the practical-session tutor for the courses you enrol in.
We do not collect biometric data. The Platform is intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us personal data, contact us at [email protected] and we will delete it promptly.
3. Why We Collect It
- Provide vocational training services
- Issue regulated certifications (CIBTAC, KHDA, DHA, City & Guilds)
- Process payments and issue VAT-compliant invoices
- Communicate about classes, schedules, and results
- Comply with KHDA / DHA / FTA regulatory obligations
- Defend the platform from abuse (rate-limiting + audit logging)
- Improve performance + UX (anonymous Web Vitals analytics)
4. Data Subject Rights
You have the following rights under UAE PDPL (Federal Decree-Law No. 45 of 2021) and GDPR (where applicable):
- Access — via /portal/student/profile → "Export Data", OR email [email protected] (SLA: 30 days)
- Rectification — edit your profile directly, OR email [email protected] (SLA: 7 days)
- Erasure — self-serve via /portal/student/profile → "Account Erasure" (4-step workflow) (SLA: 30 days)
- Restriction — email [email protected] (SLA: 7 days)
- Portability — via /api/v1/auth/me/export OR email [email protected] (SLA: 30 days)
- Objection — one-click "Unsubscribe" in marketing emails, OR portal toggles (SLA: immediate)
- Withdraw consent — same as above for marketing (SLA: immediate)
Erasure workflow (4 steps): (1) Request from your profile → (2) Confirm via email link → (3) Our DPO reviews → (4) On approval, your personal data is anonymised. Tax-relevant records are retained for 5 years per UAE FTA Article 78. After erasure, those records contain no name, email, phone, or address.
5. Retention Periods
Code-enforced floor-guarded retention:
- Audit logs / Tax invoices / Backups — 5 years (UAE FTA Article 78, mandatory)
- Analytics events — 90 days (PDPL Art. 9 + GDPR Art. 5(1)(e) data minimisation)
- Health snapshots — 30 days (operational)
- Newsletter subscribers — Until unsubscribe + 30-day compliance hold
- Student records — 7 years post-graduation (KHDA + CIBTAC)
- Employment applications — 1 year if rejected, 7 years if hired (UAE Labour Law Art. 10)
After the retention period expires, rows are automatically deleted by daily scheduled jobs.
6. International Data Transfers
Personal data is stored on servers in the European Union (Falkenstein, Germany — Hetzner Cloud). The following processors receive limited data outside the EU:
- Stripe (US) — payment processing, EU-US Data Privacy Framework
- Tabby / Tamara — buy-now-pay-later, UAE/GCC-internal
- Zoho Books — accounting sync, EU SCCs
- Google (Workspace + OAuth + Maps) — EU-US Data Privacy Framework
- Cloudflare — CDN + DNS + DDoS, EU-US Data Privacy Framework
- Gmail SMTP — transactional email, Google EU-US Data Privacy Framework
We use self-hosted infrastructure for error tracking and uptime monitoring — no telemetry sent to third-party SaaS providers.
7. Security Measures
Technical and organisational measures:
- Encryption at rest: PostgreSQL data volume + uploads on encrypted disk
- Encryption in transit: TLS 1.3 + auto-Let's-Encrypt + HSTS preload
- Authentication: JWT HS256, MFA via TOTP, Google OAuth2
- Authorisation: 6-role role-based access control with fail-secure defaults
- Audit trail: Every mutation logged with IP + user-agent (5-year retention, append-only)
- Rate limiting: Tiered preset bands with memory-bounded store
- Webhook signature verification: Constant-time comparison
- PII minimisation: Error tracking strips passwords, tokens, IDs, payment fields
- Backup encryption: Daily + monthly backups with cloud-storage upload
8. Cookies
- Strictly necessary — session, locale, CSRF — required
- Analytics — Web Vitals, page-view tracking — optional (cookie banner "Reject")
- Marketing — none currently in use
A cookie banner appears on first visit; preferences are persisted in our consent log.
9. Data Breach Notification
SLA: within 72 hours of becoming aware of a breach (GDPR Art. 33) or "promptly" (UAE PDPL Art. 9 — interpreted as no later than 72 hours).
Notifications go to: affected data subjects, the UAE Data Office, and (if EU-located subjects are affected) the relevant supervisory authority.
10. Children's Data
The Platform is intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us personal data, contact us at [email protected] and we will delete it promptly.
11. Escalation and Complaints
If you are not satisfied with our response to a request:
- Reply to the email response and set out your concerns. Our Data Protection Officer will re-review the request.
- Regulator: File a complaint with the UAE Data Office at https://www.uaedataoffice.gov.ae. EU-located subjects may complain to their national supervisory authority.
- Judicial remedy: Seek a remedy in the Dubai mainland courts (the contractually agreed forum) or in another competent court.
12. Updates to This Policy
We update this policy when our data practices change. Material updates trigger an in-app notification + email to active users. Continued use after an update constitutes acceptance.
Version history:
- v3 (2026-05-01) — 4-step erasure workflow, [email protected] routing, retention floors, self-hosted error tracking, DPO appointment, corrected trade licence
- v2 (2026-04-15) — Initial PDPL-aligned version
- v1 (2025-12-01) — Pre-PDPL platform launch
13. Contact
Data protection / regulator-facing queries (rights requests, breach notifications, regulator correspondence):
- Email: [email protected] (Data Protection Officer mailbox — Saleh Elhalik)
General queries (admissions, programmes, billing, support):
- Email: [email protected]
- Postal: Office 214, 2nd Floor, Pyramid Center, Oud Metha, Dubai, UAE
- Phone: +971 4 284 7744