DAM Technology Solutions

Privacy Policy

How we collect, use, and protect information when you use this website or engage us on a project.

Last updated: 27 July 2026

This Privacy Policy explains how DAM Technology Solutions L.L.C-FZ (“we”, “us”) collects, uses, and protects information when you use this website or engage us to design, build, or support a digital product.

Information we collect

We collect only what we need to answer you and to deliver the work we have been engaged to do.

  • Information you give us. When you submit the contact form we receive your name, company, an email address or phone number, the project type you select, and the description of your challenge. If you write to us directly or start an engagement, we also receive whatever you choose to share in that correspondence.
  • Client and project data. While building or supporting a product we may process business data belonging to our clients: database contents, API payloads, documents submitted to an AI module, log files, or access credentials for systems we integrate with. We handle that data strictly on our clients' instructions and under the engagement agreement.
  • Technical information. Our hosting records standard server logs, including IP address, browser type, referring page, and request time. We also store the IP address of contact-form submissions briefly, in order to rate-limit automated abuse.

We do not collect special categories of personal data through this website, and we do not knowingly collect information from children. Where a client engagement requires us to touch sensitive data, for example patient records on a healthcare platform, the terms for that data are set in the engagement agreement before any access is granted.

How we use your information

  • To answer your enquiry and follow up on it.
  • To scope, deliver, and support the product we have been engaged to build.
  • To send communications tied to a project, such as sprint updates, demo invitations, or changes to our terms.
  • To keep this website and the contact form secure, including spam prevention and rate limiting.
  • To meet our legal, accounting, and regulatory obligations.

We do not sell personal data. We do not use information submitted through this website for automated decision-making or profiling, and we do not use it to train any machine learning model of our own.

AI processing

AI integration is part of what we build, so it deserves an explicit statement. Where an engagement involves connecting a model to client data, we agree in writing which data the model may access, whether any third-party model provider is involved, and whether that provider may retain prompts or outputs. Unless a client instructs otherwise, we configure integrations so that client data is not retained for provider-side training.

Legal basis for processing

Where the UK GDPR, the EU GDPR, or comparable UAE data protection law applies to our processing, we rely on the following bases:

  • Consent for optional cookies and for any marketing communications you ask to receive. You can withdraw consent at any time.
  • Performance of a contract when we process data in order to scope, agree, or deliver an engagement.
  • Legitimate interests when we answer enquiries, secure our systems, and run our business, balanced against your rights and freedoms.
  • Legal obligation when retention or disclosure is required by law.

Sharing and disclosure

We share personal data only where there is a clear reason, and only with recipients bound by confidentiality and appropriate data-protection terms:

  • Service providers that support our operations: website hosting, email delivery, spam protection, and the cloud platforms on which client products run.
  • Subprocessors named in an engagement, such as a model provider or an analytics service, disclosed to the client before they are used.
  • Professional advisers, including accountants, auditors, and lawyers, where necessary.
  • Authorities or third parties where disclosure is required by law, court order, or to establish or defend legal claims.
  • A successor entity in the event of a reorganisation, merger, or sale of the business.

International transfers

We are based in Dubai, United Arab Emirates, and work with clients, cloud providers, and subprocessors in several countries, so your information may be processed outside the country where you live. Where a transfer involves personal data protected by the UK or EU GDPR, we put appropriate safeguards in place, such as standard contractual clauses or a transfer to a jurisdiction recognised as providing adequate protection.

Data retention

We keep personal data only for as long as it serves the purpose it was collected for:

  • Contact-form enquiries that do not lead to an engagement: up to 24 months, then deleted.
  • Client records and project correspondence: for the duration of the engagement and for as long afterwards as we need them for contractual, tax, and legal purposes.
  • Client production data we hold in order to support a system: only while the support arrangement is live, then returned or deleted as the engagement agreement requires.
  • Server logs and rate-limiting records: short-term only, typically no more than 12 months.

When a retention period ends, we delete the data or anonymise it so that it can no longer be linked to you.

Security

Security by Design is one of our development standards, and it applies to our own systems as well as to what we build. We use encryption in transit, access on a need-to-know basis, authenticated email transport for form submissions, secret management rather than credentials in code, and confidentiality obligations for everyone who works with client data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we review our controls regularly.

Your rights

Subject to the law that applies to you, you may have the right to:

  • Request access to the personal data we hold about you.
  • Ask us to correct data that is inaccurate or incomplete.
  • Ask us to delete data where we no longer have grounds to keep it.
  • Object to, or ask us to restrict, processing based on our legitimate interests.
  • Receive a copy of data you provided to us in a portable format.
  • Withdraw consent at any time, without affecting processing carried out before you withdrew it.
  • Lodge a complaint with your local data protection authority.

To exercise any of these rights, write to info@dam-technology.com. We will respond within one month, and we may ask you to confirm your identity before acting on a request.

Where we process data on behalf of a client, for example while building or maintaining their platform, we act as a processor and the client is the controller. In that case please direct your request to that client, and we will support them in responding.

Cookies

See our Cookie Policy for details on cookies and similar technologies.

Changes to this policy

We may update this policy to reflect changes in our practices or in the law. The revised version takes effect when it is published on this page, and the date at the top will tell you when that happened. If a change materially affects how we use your personal data, we will take reasonable steps to notify you directly.

Contact

For privacy questions, contact info@dam-technology.com. DAM Technology Solutions L.L.C-FZ, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.