Privacy Policy — What We Collect, Keep, and Delete (UAE PDPL 45/2021)

Privacy Policy — What We Collect, Keep, and Delete (UAE PDPL 45/2021)

We collect less than you expect, because we process no applications. No case file and no document archive, ever. This page names every data type we touch, sets a retention period against each, and gives you a deletion path with real steps. Every period here is a promise we make, checked and dated 20 July 2026.

What we collect and the lawful basis (PDPL 45/2021)

We collect three things: your messages to the desk, the source and date you attach to a correction, and aggregated website analytics. That is the entire scope of personal data collected here. The UAE Personal Data Protection Law — Federal Decree-Law 45/2021, the full citation being Federal Decree-Law No. 45 of 2021 — sets the rules, and consent is the basis we rely on most.

You message us, so you consent to us reading and answering. That is the lawful basis for the WhatsApp thread and for any email. The law also lets us process what is necessary to answer your question. We rely on nothing broader than that. We do not build a profile of you and we run no advertising trackers that follow you off this site. We do not sell data.

We ask for as little as the answer needs. The contact page tells you to send a profile block: passport type, residency and tenure, salary basis, bank position, travel history. Passport type, never passport number. That request is data minimisation on purpose. The shape of your profile lets us answer; your document numbers would only sit here as a liability.

Passport and Emirates ID documents: handling, storage, deletion

We store your passport scan for zero days. We do not ask for one, we do not need one, and if a scan arrives we delete it within one business day. The desk keeps no case file, because it files no applications. So there is no folder your Emirates ID could live in, and no reason for it to.

This is the honest gap between us and an agency. An agency that files your visa must hold your passport scan, your Emirates ID and your bank statement to do the job. We do not do that job. The PDPL points one way here: do not accept document uploads until a compliant process exists, and none is live in this cycle. Until it is, the safe assumption is simple. Anything you send beyond the profile block gets deleted, not saved.

If document handling ever launches here, this page changes first, with a dated note, before a single upload is accepted. We will not quietly start keeping documents and update the policy afterwards.

WhatsApp Business: what happens to documents you send us

A WhatsApp Business thread lives 90 days here, then we delete it. Your messages travel through Meta’s own servers, not ours, so treat the channel as not private. If you send a bank statement, an Emirates ID or a salary certificate we never asked for, we delete it within one business day. We also ask you to remove it from your side of the chat.

The transport matters, and it is worth one honest paragraph. The WhatsApp Business App and the WhatsApp Business Platform handle encryption differently. On the hosted Platform, Meta processes your messages on its own servers. We cannot promise end-to-end privacy on a channel we do not own. The exact WhatsApp product this desk uses is set at launch. The rule holds either way: send the profile block, not your documents.

This market forwards receipts and refusal letters over WhatsApp by reflex. We understand why. But a screenshot of your refusal letter is enough for us to help; the passport page under it is not. Crop it out before you hit send.

Retention periods, by data type

Nothing here is kept beyond 90 days in a form that identifies you. One exception: a correction we publish. We keep that anonymised for as long as the page stands. The table sets a concrete period against each data type. A generic policy states one blanket period, or none. This one states the period that actually applies, line by line.

Data typeWhat it isWe keep itThen
WhatsApp Business chat.Your messages to the desk.90 days from your last message.Deleted.
Correction or press email.Your email, plus the source and date you sent.12 months.The correction stays, anonymised; your email is deleted.
Passport scan, Emirates ID, bank statement, salary certificate.Sent unprompted. We never ask.Not stored.Deleted within one business day.
Your name, if you give it.An email signature, a chat display name.90 days, with the thread.Deleted with the thread.
Website analytics.Aggregated page counts, no direct identifiers.14 months, in aggregate.Rolled off.

A conversation that stops halfway follows the same clocks. You ask a question, send a document, then go quiet. The thread runs on its 90-day timer. The document is deleted within one business day of us seeing it. There is no abandoned case, because there is no case. Silence does not turn into a file we hold.

On cookies and analytics, we keep it short. We set what analytics needs and nothing that tracks you across other sites. Session cookies clear when you close the tab; the analytics cookie expires inside 14 months. You can block both in your browser and the site still works.

How to request deletion — the actual steps

Send one message that says “delete my data”, name the channel you used, and we confirm within two business days and delete within 30. That is the entire path. PDPL 45/2021 sets out your data subject rights: the right to erasure, the right to see what we hold and the right to correct it. Here is how to make an access and erasure request without a form and without waiting on a vague promise.

The deletion path, dated.
Request received: Day 0 — message the corrections inbox or WhatsApp, say "delete my data", and tell us which channel and roughly when you contacted us, so we can find the thread.
Confirmed: within 2 business days — we reply that we have the request and that deletion is under way.
Deleted: within 30 days — the thread, your email and anything in them are removed.
Done: one line back confirming it is finished.

Two limits, stated plainly. A correction we already published carries no personal data, so there is nothing in it to erase; the fix stays public and dated. If the law requires us to hold something, we keep only that. We tell you which item, and delete the rest. There is no other exception. To exercise the access or correction right instead, use the same message and say which one you want.

EU consulate flows: the GDPR clause

GDPR, Regulation (EU) 2016/679, reaches this desk only when we handle the personal data of a person located in the EU. Most readers are UAE residents, so the PDPL governs. Say you apply at a Schengen or EU consulate through VFS Global or TLScontact. Those bodies and the consulate are the data controllers for your application. We are not in that flow at all.

That boundary is the useful part. Your appointment booking, your biometrics and your submitted documents sit with VFS, TLScontact or the consulate, under their privacy notices and GDPR. When you book that slot, your data makes a cross-border transfer out of the UAE to their systems, under their notice, not ours. Read theirs before you upload; we cannot see, hold or delete anything on their systems. Where GDPR does apply to us, the same rights carry over — access, erasure, portability, objection — plus the right to complain to an EU supervisory authority.

One caution that touches your documents, not ours. We do not write your cover letter or your itinerary, and we store none, because we produce none. Consulates now flag recognizably AI-generated cover letters and travel itineraries, and a flagged file works against you. The document least likely to trip that check is the one you wrote yourself.

How this policy was verified. Every retention period on this page is a commitment this desk makes, and each was set and dated on 20 July 2026. The legal references are to the published text of Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and to Regulation (EU) 2016/679 (GDPR); we name each law by title rather than link a page we did not open in this run. Verify the PDPL against u.ae's "Personal Data Protection Law" page and the UAE Data Office. One finding we will not paper over: we could not confirm the PDPL Executive Regulations as published on our check date, so we assert no breach notification deadline in days. If a personal-data breach affects you, we will notify you and the UAE Data Office without undue delay, and we will publish a dated note. The data controller contact for this site is the editorial desk, reached at /en/ae/contact/; our sourcing rules sit at /en/ae/editorial-policy/.

Found a period that reads wrong, or handled data we did not name here? Write to us at /en/ae/contact/. We will check it and publish a dated correction.

Our scope limits and the not-affiliated terms sit on the terms page. Who verifies this and why cycle 1 carries a desk byline is on the editorial-team page. Definitions of entry permit, Amer centre and typing centre live in the glossary.

We are not affiliated with the UAE Government, u.ae, ICP, GDRFA, MOFA, any Amer centre, VFS Global, TLScontact or any consulate. We are a Dubai-based visa information publisher. We quote no price of our own, we take no case, and we process no applications. For how a consulate or VFS handles your application data, read their own privacy notice.

Found a figure that's out of date, or a receipt that contradicts us?

WRITE TO US