Dunes Discovery Tourism L.L.C is committed to safeguarding the personal privacy of our guests and portal visitors. This Privacy Policy details our data collection, processing, storage, and retention practices pursuant to UAE Federal Decree-Law No. 45/2021 on Personal Data Protection (PDPL), the EU General Data Protection Regulation (GDPR), UK GDPR, and international privacy benchmarks.
Legal entity responsible for customer data privacy
-
The data controller for personal data collected via this portal is Dunes Discovery Tourism L.L.C, Trade License 1430583, Dubai, UAE.
-
Data Protection Officer Contact: privacy@dunesdiscoverytourism.com or info@dunesdiscoverytourism.com.
-
Telephone and WhatsApp Data Desk: +971 50 245 6056 (Customer Privacy & Data Rights Desk).
-
This policy applies to all customer data collected online through https://dunesdiscoverytourism.com, WhatsApp booking channels, and field operations.
Explanation of terms used in this Privacy Policy
Personal identification, booking details, logistics and technical telemetrics
-
Personal Identification: Full passenger name, title, preferred language, and nationality.
-
Contact Details: Primary email address, mobile telephone number, and WhatsApp chat handle.
-
Logistics & Booking Preferences: Hotel name, room number, pickup address, party size, dietary requirements, and tour dates.
-
Opt-in Precise Geolocation: With explicit user consent, browser GPS coordinates (latitude, longitude, horizontal accuracy) to resolve pickup addresses.
-
Financial Transaction Records: Payment transaction identifiers, payment method (card, Apple Pay, cash), and amount paid in AED. (Note: Credit card numbers are never stored locally).
-
Technical & Analytics Telemetry: IP address, device model, browser user-agent, operating system, UTM marketing source tags, and session timestamps.
Types of personal data collected from users
Contractual necessity, legal compliance, legitimate interest and consent
-
Contractual Performance: Processing is indispensable to process booking requests, issue travel vouchers, dispatch chauffeurs, and fulfill excursion contracts.
-
Legal Obligation: Retaining transactional invoices for UAE Federal Tax Authority (FTA) auditing and furnishing passenger lists to Dubai DET when mandated.
-
Legitimate Interests: Defending our platform against fraudulent card transactions, managing server workloads, and optimizing tour package offerings.
-
Explicit Consent: Sending opt-in promotional WhatsApp offers, collecting exact browser GPS telemetrics, and setting optional marketing tracking cookies.
Why personal data is processed
Payment processors, analytics engines, advertising networks and cloud hosts
-
Ziina Payment Gateway: Licensed by the Central Bank of the UAE and certified PCI-DSS Level 1 for secure card tokenization and Apple Pay / Google Pay processing.
-
Google LLC: Google Analytics 4 (GA4), Google Tag Manager (GTM), Google Ads Conversion Tracking (AW-17859624049), and reCAPTCHA Enterprise bot defense.
-
Meta Platforms Inc: Meta Pixel and Meta Conversions API (CAPI) for privacy-conscious server-side advertising attribution and audience measurement.
-
OpenStreetMap Nominatim: Used for client-side reverse geocoding to resolve street names from coordinates without storing persistent user identifiers.
-
Emergency Transport & Rescue: Disclosing emergency contact details and pickup locations to Dubai Police, Dubai Ambulance, or civil defence during rescue operations.
Legal grounds under UAE law, GDPR, and international standards
TLS 1.3 encryption, AES-256 database protection and cross-border safeguards
-
Encryption in Transit: All communications between your browser and our servers are encrypted using high-grade Transport Layer Security (TLS 1.3).
-
Encryption at Rest: Sensitive database records, authentication tokens, and booking archives are stored with AES-256 cryptographic encryption.
-
Restricted Access: Internal access to customer booking records is strictly restricted to licensed dispatch personnel and authenticated administrators.
-
Cross-Border Compliance: Any transfer of customer data outside the UAE complies with Chapter 5 of the UAE PDPL and European Standard Contractual Clauses.
Statutory tax archiving, booking history and automated data purging
-
Completed Booking Records: Retained for 5 calendar years to satisfy commercial accounting and UAE Federal Tax Authority VAT audit mandates.
-
Customer Inquiries & WhatsApp Leads: Retained for up to 24 months from the last interaction to assist recurring guests, after which records are depersonalized.
-
Ephemeral Verification Codes: Email OTP codes and temporary draft tokens are automatically purged within 24 hours of generation.
-
Server Web Access Logs: Retained for 90 days for cybersecurity analysis, DDoS mitigation, and intrusion detection auditing.
How long data is stored and deletion
Access, rectification, erasure, restriction and data portability rights
-
Right to Access: You may request confirmation of whether we process your data and receive a readable copy of your booking history.
-
Right to Rectification: You may request correction of inaccurate contact numbers, passenger spellings, or hotel pickup information.
-
Right to Erasure: You have the right to request deletion of your personal data where retention is no longer mandated by UAE tax and accounting laws.
-
Right to Withdraw Consent: You may revoke marketing or GPS tracking consent at any time without affecting the lawfulness of prior processing.
-
Submitting a Data Rights Request: Send an email with verified proof of identity to privacy@dunesdiscoverytourism.com. Requests are handled within 30 days.
Website tracking and cookies
Rights of users regarding their data
How personal data is protected
Policy regarding data from children
Transferring data outside UAE
Updates and revisions to the policy
Applicable laws and courts
Company contact details for data inquiries
تلتزم شركة ديونز ديسكفري للسياحة ذ.م.م بحماية الخصوصية الشخصية لضيوفنا وزوار منصتنا الإلكترونية. توضح هذه السياسة ممارسات جمع البيانات ومعالجتها وتخزينها والاحتفاظ بها وفقاً للمرسوم بقانون اتحادي رقم 45 لسنة 2021 بشأن حماية البيانات الشخصية في دولة الإمارات، واللائحة العامة لحماية البيانات في الاتحاد الأوروبي (GDPR).
الكيان القانوني المسؤول عن خصوصية بيانات العملاء
-
الجهة المسؤولة عن معالجة البيانات الشخصية عبر هذه المنصة هي شركة ديونز ديسكفري للسياحة ذ.م.م، رخصة تجارية 1430583، دبي، الإمارات.
-
مسؤول حماية البيانات: privacy@dunesdiscoverytourism.com أو info@dunesdiscoverytourism.com.
-
هاتف وواتساب مكتب خصوصية البيانات: 6056 245 50 971+ (مكتب حقوق وخصوصية العملاء).
-
تسري هذه السياسة على كافة بيانات العملاء التي يتم جمعها عبر الموقع الإلكتروني وقنوات الواتساب والعمليات الميدانية.
Explanation of terms used in this Privacy Policy
البيانات الشخصية وتفاصيل الحجز واللوجستيات والمؤشرات التقنية
-
بيانات الهوية الشخصية: الاسم الكامل للراكب، اللقب، اللغة المفضلة، والجنسية.
-
بيانات الاتصال: عنوان البريد الإلكتروني الأساسي، رقم الهاتف المحمول، ومعرّف تطبيق الواتساب.
-
بيانات الحجز واللوجستيات: اسم الفندق، رقم الغرفة، عنوان نقطة التجمع، عدد الأفراد، التفضيلات الغذائية، وتواريخ الرحلات.
-
الموقع الجغرافي الدقيق بموافقة مسبقة: إحداثيات GPS (خط العرض وخط الطول والدقة) بموافقة صريحة لتحديد عنوان اصطحاب الضيف.
-
سجلات المعاملات المالية: معرف المعاملة، طريقة الدفع (بطاقة، أبل باي، نقداً)، والمبلغ المدفوع بالدرهم (مع العلم أن أرقام البطاقات لا تُخزن لدينا).
-
البيانات التقنية والتحليلية: عنوان IP، طراز الجهاز، متصفح الإنترنت، نظام التشغيل، وسوم مصادر التسويق UTM، وتوقيت الجلسة.
Types of personal data collected from users
الضرورة التعاقدية والامتثال القانوني والمصالح المشروعة والموافقة الصريحة
-
تنفيذ العقد: تعتبر المعالجة ضرورية لتأكيد الحجوزات وإصدار قسائم السفر وتوجيه السائقين وتنفيذ خدمات الرحلات المتفق عليها.
-
الامتثال للالتزامات القانونية: حفظ السجلات الضريبية للامتثال للهيئة الاتحادية للضرائب وتقديم قوائم الركاب لدائرة الاقتصاد والسياحة عند الطلب.
-
المصالح المشروعة: حماية منصتنا من المعاملات الاحتيالية، وإدارة ضغط الخوادم، وتحسين باقات الرحلات وجودة الخدمة.
-
الموافقة الصريحة: إرسال العروض الترويجية الاختيارية عبر الواتساب، وجمع إحداثيات GPS الدقيقة، وتفعيل ملفات تعريف الارتباط التسويقية.
Why personal data is processed
بوابات الدفع ومحركات التحليلات والشبكات الإعلانية وخدمات الاستضافة السحابية
-
بوابة دفع زينة (Ziina): مرخصة من مصرف الإمارات المركزي ومعتمدة بمعيار PCI-DSS Level 1 لمعالجة البطاقات وApple Pay وGoogle Pay بأعلى درجات الأمان.
-
شركة جوجل: تحليلات Google Analytics 4، ومدير الوسوم GTM، وتتبع تحويلات Google Ads، وحماية reCAPTCHA Enterprise ضد الروبوتات.
-
شركة ميتا: بكسل ميتا وواجهة تحويلات CAPI لتتبع التحويلات الإعلانية وقياس تفاعل الجمهور وفق أفضل معايير الخصوصية.
-
خدمة OpenStreetMap Nominatim: تُستخدم لتحديد أسماء الشوارع من إحداثيات GPS دون تخزين أي معرفات مستمرة للمستخدم.
-
خدمات الطوارئ والإنقاذ: مشاركة بيانات الاتصال ومواقع التجمع مع شرطة دبي أو إسعاف دبي أو الدفاع المدني عند حالات الطوارئ الطبية.
Legal grounds under UAE law, GDPR, and international standards
تشفير TLS 1.3 وحماية قواعد البيانات بمعيار AES-256 وضمانات نقل البيانات
-
التشفير أثناء النقل: يتم تشفير كافة الاتصالات بين متصفحك وخوادمنا باستخدام بروتوكول أمان طبقة النقل المتطور (TLS 1.3).
-
التشفير أثناء التخزين: تُحفظ سجلات قواعد البيانات الحساسة ورموز المصادقة وأرشيف الحجوزات بتشفير تشفيري متقدم AES-256.
-
صلاحيات وصول مقيدة: يقتصر الوصول الداخلي لسجلات الحجوزات على موظفي التوجيه الميداني المصرح لهم والمسؤولين المعتمدين.
-
الامتثال لنقل البيانات عبر الحدود: يتوافق أي نقل لبيانات العملاء خارج الدولة مع أحكام الفصل الخامس من قانون حماية البيانات الإماراتي والبنود التعاقدية القياسية.
الأرشفة الضريبية القانونية وسجل الحجوزات والإتلاف الآلي للبيانات المؤقتة
-
سجلات الحجوزات المكتملة: يتم الاحتفاظ بها لمدة 5 سنوات ميلادية للامتثال لمتطلبات التدقيق الضريبي والمحاسبي للهيئة الاتحادية للضرائب.
-
استفسارات العملاء والواتساب: يتم الاحتفاظ بها لمدة تصل إلى 24 شهراً من تاريخ آخر تواصل لخدمة الضيوف المتكررين ثم تُحذف الهوية عنها.
-
رموز التحقق المؤقتة: تُحذف رموز OTP للبريد الإلكتروني ومسودات الحجز المؤقتة تلقائياً خلال 24 ساعة من إنشائها.
-
سجلات الدخول للخادم: يتم الاحتفاظ بسجلات الوصول التقنية لمدة 90 يوماً لأغراض الأمن السيبراني ومكافحة الهجمات الرقمية.
How long data is stored and deletion
حقوق الوصول والتصحيح والمحو والتقييد ونقل البيانات الشخصية
-
حق الوصول: يحق لك طلب تأكيد حول معالجة بياناتك والحصول على نسخة واضحة من سجل حجوزاتك الشخصية.
-
حق التصحيح: يحق لك طلب تعديل أي أرقام اتصال غير دقيقة أو تصحيح أسماء المسافرين أو تفاصيل الفندق.
-
حق المحو (حق النسيان): يحق لك طلب حذف بياناتك الشخصية عندما لا يكون الاحتفاظ بها مطلوباً بموجب قوانين الضرائب والمحاسبة.
-
حق سحب الموافقة: يمكنك سحب موافقتك على الرسائل التسويقية أو تتبع الموقع الجغرافي في أي وقت دون التأثير على قانونية المعالجة السابقة.
-
تقديم طلب ممارسة الحقوق: يُرجى إرسال بريد إلكتروني مع إثبات الهوية إلى privacy@dunesdiscoverytourism.com، وتتم معالجة الطلبات خلال 30 يوماً.
Website tracking and cookies
Rights of users regarding their data
How personal data is protected
Policy regarding data from children
Transferring data outside UAE
Updates and revisions to the policy
Applicable laws and courts
Company contact details for data inquiries