Политика конфиденциальности
Как IHGIZ Solutions FZ-LLC собирает, использует, передаёт и защищает персональные данные при использовании ihgiz.com, приложения и наших ботов WhatsApp и Telegram — составлено в соответствии с Законом ОАЭ о защите персональных данных и сверено с реальной работой платформы.
Полный текст на английском языке, который является основной версией. Это краткое изложение приводится на вашем языке для удобства.
IHGIZ Solutions FZ-LLC
Trade Licence No. 107946, Dubai Development Authority
Corporate Tax Registration Number (TRN) 105567073900001, Federal Tax Authority
Office HD27A, First Floor, in5 Tech, Dubai Internet City, Dubai, United Arab Emirates
1. Who we are
IHGIZ Solutions FZ-LLC ("IHGIZ", "we", "us") operates the ihgiz.com website, the IHGIZ web application, the IHGIZ WhatsApp and Telegram bots and the related application programming interfaces (together, the "Service"). We are a free-zone limited liability company licensed by the Dubai Development Authority (Trade Licence No. 107946, Dubai Development Authority) and registered for Corporate Tax with the UAE Federal Tax Authority (Corporate Tax Registration Number (TRN) 105567073900001, Federal Tax Authority). Our registered office is at Office HD27A, First Floor, in5 Tech, Dubai Internet City, Dubai, United Arab Emirates.
For any question about this policy or your personal data, contact us at support@ihgiz.com or in writing to IHGIZ Solutions FZ-LLC, Office HD27A, First Floor, in5 Tech, Dubai Internet City, Dubai, United Arab Emirates. We have not appointed a Data Protection Officer; the person responsible for data protection can be reached at the same address.
2. Scope and governing law
This policy explains how we collect, use, share and protect personal data when you use the Service, whether as an organiser (an account holder who publishes bookable schedules), as a contact (a person who books an appointment, replies to an invitation or messages us on a channel), or as a visitor to our website.
It is written to comply with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL") and its executive regulations, and with the laws and regulations of the Emirate of Dubai that apply to a company licensed in a Dubai Development Authority free zone. Where you access the Service from outside the UAE, we apply this policy as our standard and honour the additional rights your local law gives you where we are required to.
3. The personal data we process
We process only the data needed to provide the Service. In practice that is:
- Account data — name, email address, password (stored only as a salted hash by our authentication library), display name, time zone, language, phone number, and the profile and branding you choose to publish (logo, bio, social links, welcome message).
- Scheduling data — your schedules, availability, booking rules, appointments, their attendees and status, and the full audit history of every change to an appointment, including automated ones.
- Contact data — the name, email address, phone number, language and channel identifiers (WhatsApp number or identifier, Telegram identifier, Messenger or Instagram identifier) of the people an organiser invites, adds, or who book through an organiser's page or bot.
- Messages — every message sent or received on your behalf through the Service, on every channel, including messages we receive on the IHGIZ business number or bot from senders we cannot match to an account. We keep these deliberately: nothing sent to us is silently dropped, and unmatched messages are reviewed by our staff.
- Channel credentials and connected accounts — bot tokens, API keys, WhatsApp Business credentials, SMS provider credentials and OAuth tokens for Google, Microsoft or Zoom that you connect. These are encrypted at rest and used only to send or read what you configured.
- Billing data — your plan, and if you subscribe, the Stripe customer and subscription identifiers, status, price and period. We never receive or store card numbers; payment is taken on Stripe's hosted pages.
- Technical data — IP address, browser and device information, request logs, and the identifiers of the messaging provider that delivered a message to us. Our website uses Google Analytics for aggregate visitor statistics.
- Files you upload — a logo, or attachments to feedback you send us.
We do not knowingly process special categories of personal data (health, religion, biometrics, criminal record and the like). An organiser who collects such data in an intake field or a message does so as the controller of that data and must have a lawful basis for it.
4. Controller and processor
For account data, billing data, technical data and messages sent to the IHGIZ business number or bot, IHGIZ is the controller.
For contact data and appointment data that an organiser enters, imports or collects through their own schedules, pages and channels, the organiser is the controller and IHGIZ processes that data on the organiser's instructions, which are the settings the organiser chooses in the Service. A data processing agreement on those terms is available on request. Organisers are responsible for having a lawful basis, and where required consent, to add a contact and to notify them on the channels they choose.
5. Why we process it and on what basis
- To provide the Service you signed up for — creating and running schedules, taking bookings, sending confirmations, reminders and changes, and syncing busy times from calendars you connect (performance of a contract).
- To deliver notifications on the channels a contact or organiser has chosen, and to link a channel to an account after the owner has proved control of it with a verification code (consent, which can be withdrawn in Settings or by asking us).
- To keep the Service secure and to prevent abuse — verifying webhook signatures, rate-limiting, logging, reviewing unmatched inbound messages, and enforcing plan limits (legitimate interest).
- To bill subscriptions and keep the financial records UAE law requires (contract and legal obligation).
- To respond to lawful requests from courts, regulators and law enforcement, and to establish, exercise or defend legal claims (legal obligation and legitimate interest).
- To understand how the website is used, in aggregate, through analytics (consent, via your browser settings).
We do not sell personal data, and we do not use it for advertising.
7. Where the data is kept
Application data is stored in MongoDB Atlas. Following our incorporation in Dubai we are moving the database region to the United Arab Emirates; until that migration completes, data may be hosted in another Atlas region. Messaging, email, payment and calendar providers process data in the regions they operate in, which may be outside the UAE.
Where personal data leaves the UAE we rely on the mechanisms the PDPL permits: a destination with adequate protection as determined by the UAE Data Office, contractual safeguards with the recipient, or, where neither applies, your consent or the necessity of the transfer to perform the contract with you.
8. How long we keep it
- Account, scheduling, contact and message data — for as long as the account exists. When an account is deleted, its data is deleted with it, except what we must keep under the next two points.
- Financial records, invoices and the subscription mirror — for the period UAE tax and commercial law requires, currently seven years for Corporate Tax records.
- Records needed to establish, exercise or defend a legal claim, or preserved at the lawful request of an authority — for as long as that need lasts.
- Verification codes, bot conversation sessions and webhook de-duplication records — deleted automatically when they expire (minutes to hours).
- Server logs — rotated on a short cycle and not used to profile individuals.
9. How we protect it
- All traffic is encrypted in transit with TLS.
- Channel credentials, connected-account tokens and provider secrets are encrypted at rest with AES-256-GCM; a production deployment refuses to start without the encryption key.
- Passwords are stored only as salted hashes. API keys are shown once and stored only as SHA-256 hashes.
- Inbound webhooks from every messaging provider are verified (HMAC signatures or shared secrets) before anything is processed; unverified requests are rejected.
- Operator access is restricted to named platform administrators; every appointment change is written to an audit trail on the appointment itself.
- We hold no card data; payments are taken on Stripe's PCI-DSS certified pages.
No system is perfectly secure. If we become aware of a personal data breach that is likely to cause harm, we will notify the UAE Data Office and the affected persons within the timelines the PDPL sets.
10. Your rights
Under the PDPL you have the right to:
- access the personal data we hold about you and receive a copy of it — organisers can export their account from Settings at any time;
- have inaccurate or incomplete data corrected — most account data can be edited in Settings;
- have your data erased, subject to the retention we are required to keep — organisers can request account deletion, and contacts can ask the organiser who holds their data or ask us;
- restrict or object to processing, including withdrawing consent to a notification channel, which you can do in Settings or by telling us or the organiser;
- receive the data you provided in a portable, machine-readable form;
- not be subject to a decision based solely on automated processing that produces legal effects concerning you — the Service makes no such decisions;
- lodge a complaint with the UAE Data Office, or with the competent authority in your own jurisdiction.
To exercise any of these rights, contact support@ihgiz.com or in writing to IHGIZ Solutions FZ-LLC, Office HD27A, First Floor, in5 Tech, Dubai Internet City, Dubai, United Arab Emirates. We will respond within one month, and we may ask you to verify your identity before acting.
If a contact exercises a right against data an organiser controls, we will pass the request to that organiser and assist them in meeting it.
12. Messaging channels, the IHGIZ number, and lawful cooperation
The IHGIZ WhatsApp number and Telegram bot are business channels of IHGIZ Solutions FZ-LLC. Anything sent to them — a booking, a question, feedback, a report, or an unrelated message — is received by our systems, logged, and may be read by our staff so that we can respond, keep the Service safe and meet our obligations. Do not send us data you are not comfortable being read, and never send payment card details, passwords or identity documents over chat.
By messaging a channel you consent to receiving replies on that channel. You can stop at any time by telling us or the organiser, or by blocking the number or bot.
We comply fully with the laws of the United Arab Emirates and cooperate with the competent authorities — including the Telecommunications and Digital Government Regulatory Authority, the UAE Data Office, the Federal Tax Authority, the Dubai Development Authority, Dubai Police and the courts — in preventing, detecting and investigating anything unlawful. Where the law requires or permits, we will preserve and disclose account, message and technical data in response to a lawful order or request, and we may do so without notifying you where notice is prohibited or would prejudice an investigation.
13. Children
The Service is for adults and businesses. We do not knowingly create accounts for, or market to, anyone under 18. An organiser who takes bookings from minors (for example, a tutor) is responsible for obtaining a parent's or guardian's consent where the law requires it.
14. Changes to this policy
We will post any change here with a new effective date, and notify account holders by email of changes that materially affect their rights. Continued use of the Service after the effective date is acceptance of the change.
Первоначальная версия, составленная в соответствии с федеральным законодательством ОАЭ и законами эмирата Дубай и сверенная с кодом платформы. Ожидает официальной проверки юрисконсультом; проверенная версия заменит её здесь.
Последнее обновление: 16 сентября 2026 · 16 September 2026
Вернуться на главную