Legal

Privacy Policy

IGFT For Computer Systems & Communication Equipment Software Design CO. L.L.C

Regarding the processing of personal data of users of the “OnCamp” product

Website: igft.tech/oncamp Effective Date: June 14, 2026 UAE Federal Decree-Law No. 45 of 2021 (PDPL)

1. General Provisions

1.1. This Privacy Policy (hereinafter — the “Policy”) sets out the terms and conditions under which IGFT For Computer Systems & Communication Equipment Software Design CO. L.L.C (hereinafter — the “Company”, “Controller”, “we”, “us”, or “our”) collects, stores, processes, uses, and protects the personal data of users (hereinafter — “User”, “Data Subject”, “you”) of the “OnCamp” product (hereinafter — the “Product” or “Service”).

1.2. The Company is registered in the United Arab Emirates. The General Director is Vasilev Vasilii Anatolyevich, acting on the basis of Memorandum of Association No. 7913462 dated 06/12/2022.

1.3. The “OnCamp” product is a mobile application and web-based system designed for check-in management (accommodation), food and meals management, and loyalty program administration at facilities. The Service is used by organizations to manage accommodation, dining, and rewards for shift-based workers and guests.

1.4. This Policy has been developed in accordance with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and its implementing regulations. Where applicable, the Company also takes into account the principles of the EU General Data Protection Regulation (GDPR) to ensure a high standard of data protection for all users.

1.5. By using the Service, you acknowledge that you have read and understood this Policy and consent to the collection, processing, and use of your personal data as described herein. If you do not agree, you must discontinue use of the Service.

2. Definitions

TermDefinition
Personal DataAny data relating to an identified or identifiable natural person, whether directly or indirectly, by reference to an identifier such as a name, identification number, location data, online identifier, or factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
ProcessingAny operation or set of operations performed on personal data, whether by automated or non-automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, erasure, or destruction.
Data SubjectA natural person whose personal data is being processed; in the context of this Policy, the User of the OnCamp product.
ControllerA natural or legal person that determines the purposes and means of processing personal data; in the context of this Policy, the Company.
ConsentAny freely given, specific, informed, and unambiguous indication of the Data Subject's wishes signifying agreement to the processing of personal data relating to him or her.
Cross-Border Data TransferThe transfer of personal data to a jurisdiction outside the United Arab Emirates.
Data BreachA breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.

3. Personal Data We Collect

3.1. Data provided directly by the User

  • Full name (first name, last name, and patronymic where applicable);
  • Date of birth;
  • Email address;
  • Mobile phone number;
  • Job title and employer (where applicable);
  • Photograph (when using the photo identification feature);
  • Check-in and check-out data (dates, facility name, room/block number);
  • Dietary preferences and restrictions (allergies, dietary requirements).

3.2. Data collected automatically when using the Service

  • IP address;
  • Cookie data;
  • Device type and version (model, operating system);
  • Browser type and version;
  • Geolocation data (only with the User's explicit permission).

3.3. Analytics data

To improve the quality of the Service, the Company uses web analytics services such as Google Analytics. These services collect anonymized data about user behavior (pages viewed, session duration, referral sources) without the ability to identify a specific individual. The processing of data by analytics services is governed by their respective privacy policies.

4. Purposes of Processing

The Company processes personal data exclusively for the following purposes:

PurposeLegal Basis
Registration and identification of the User in the ServiceConsent (PDPL Art. 4); performance of a contract
Check-in and check-out management at accommodation facilitiesPerformance of a contract
Food and meals management, including dietary preferencesPerformance of a contract
Administration of loyalty programs, including accrual and redemption of rewardsConsent (PDPL Art. 4); legitimate interest
Provision of technical support and customer serviceLegitimate interest of the Controller
Security and fraud preventionLegitimate interest; legal obligation
Analytics and service improvement (based on anonymized data)Legitimate interest of the Controller
Marketing and informational communicationsConsent (PDPL Art. 4) — User may withdraw at any time

5. Legal Grounds for Processing

The Company processes personal data on the following legal grounds in accordance with the UAE PDPL:

Consent of the Data Subject (PDPL Article 4). The User provides consent upon registration by means of an affirmative action. Consent is freely given, specific, informed, and unambiguous.
Performance of a Contract (PDPL Article 4). Processing is necessary for the performance of a contract to which the Data Subject is a party, including provision of accommodation management, food services, and loyalty program administration.
Legitimate Interest (PDPL Article 4). Processing is necessary for the legitimate interests of the Controller — including security, fraud prevention, service improvement, and technical support — provided such interests do not override the fundamental rights and freedoms of the Data Subject.
Legal Obligation. Processing is necessary for compliance with a legal obligation under the laws of the United Arab Emirates, including responding to lawful requests from competent government authorities.

For international users, including those in the European Economic Area, the Company aligns its data protection practices with the principles of the EU GDPR to ensure a consistent and high standard of data protection.

6. Data Storage, Retention, and Security

6.1. Personal data is stored on servers located in the United Arab Emirates and may be replicated to other international server locations for the purposes of redundancy, backup, and ensuring service availability.

6.2. Retention periods:

Data CategoryRetention Period
Active account data3 years following account deletion or cessation of use
Accommodation and meal records5 years from the end of the relevant service period
Access logs and technical logs1 year from the date of creation
Anonymized analytics dataNo time limit (data does not permit identification)

6.3. Upon expiration of the applicable retention period, personal data shall be securely deleted or anonymized, unless a longer retention period is required by applicable law.

6.4. Technical and organizational security measures

  • Encryption of data in transit using TLS/SSL protocols;
  • Role-based access control to personal data systems;
  • Regular backup of databases and critical systems;
  • Firewall protection and intrusion detection/prevention systems;
  • Audit logging of access to information systems containing personal data;
  • Regular software updates and vulnerability assessments;
  • Staff training and awareness programs on data protection and information security.

7. Disclosure of Data to Third Parties

7.1. The Company may share personal data with the following categories of third parties, strictly to the extent necessary to achieve the processing purposes set out in Section 4:

  • Clients of the Company (organizations operating accommodation facilities) — within the scope of the service agreement for check-in management, food services, and loyalty program administration.
  • IT service providers and hosting providers — processing is governed by data processing agreements ensuring adequate data protection.
  • Analytics service providers (Google Analytics) — only anonymized data is shared, which does not permit identification of individual users.
  • Competent government authorities of the UAE — disclosed only when required by applicable law, on the basis of a lawful and duly authorized request.

7.2. The Company does not sell, trade, or otherwise commercially transfer personal data to third parties for purposes unrelated to the provision of the Service.

8. Cross-Border Data Transfers

8.1. The Company primarily processes and stores personal data within the UAE. However, personal data may be transferred to jurisdictions outside the UAE for the purpose of technical service provision, backup, and business continuity.

8.2. Any cross-border transfer is carried out in compliance with Article 22 of the PDPL, which requires that the receiving jurisdiction provides an adequate level of protection. Where adequacy has not been formally established, the Company implements appropriate safeguards, including contractual clauses.

8.3. The Company takes all reasonable measures to ensure that personal data transferred outside the UAE is treated securely and in accordance with this Policy and applicable law.

9. Rights of the Data Subject

In accordance with the UAE PDPL, the User has the following rights as a Data Subject:

Right of Access. Request information about whether the Company processes personal data and obtain access to such data, including the purposes of processing, categories of data, and recipients.
Right to Rectification. Request the correction or update of personal data if it is inaccurate, incomplete, or outdated.
Right to Withdraw Consent. Where processing is based on consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
Right to Erasure. Request deletion of personal data where it is no longer necessary for the purposes collected, where consent has been withdrawn, or where processing is otherwise unlawful.
Right to Object. Object to processing based on legitimate interest where grounds exist relating to the particular situation.
Right to Data Portability. Receive a copy of personal data in a structured, machine-readable format and transmit it to another controller where technically feasible.

To exercise any of the above rights, please contact us at info@igft.tech. The Company will respond within 14 business days of receipt.

10. Cookies

The Service uses the following types of cookies:

Cookie TypeDescription and Purpose
Strictly NecessaryEssential for basic functionality of the Service, including user authentication and session security. Cannot be disabled without loss of core functionality.
AnalyticsCollect anonymized statistical data about how users interact with the Service (pages visited, session duration, referral sources). Processed by Google Analytics to improve the Service.
FunctionalStore user preferences (e.g., language settings, display options) to enhance the user experience.

The User may disable or restrict the use of cookies through browser settings. Disabling strictly necessary cookies may impair the functionality of the Service.

11. Data Breach Notification

11.1. In accordance with the UAE PDPL, the Company is obligated to notify the competent authority (the UAE Data Office) of any data breach likely to result in a risk to the rights and freedoms of Data Subjects.

11.2. The Company shall notify the competent authority without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach. The notification shall include: the nature of the breach, categories and approximate number of affected Data Subjects, likely consequences, and measures taken or proposed.

11.3. Where a breach is likely to result in a high risk to Data Subjects, the Company shall notify affected individuals without undue delay — via email to the address provided during registration and/or through in-app notifications.

11.4. The Company maintains an internal data breach register documenting all incidents, their effects, and remedial actions taken.

12. Liability

12.1. The Company is responsible for:

  • Ensuring that the processing of personal data complies with the UAE PDPL and other applicable legislation;
  • Implementing appropriate technical and organizational measures to protect personal data against unauthorized access, destruction, alteration, loss, or disclosure;
  • Timely notification of the competent authority and affected Data Subjects in the event of a data breach.

12.2. The Company shall not be held liable for:

  • Information voluntarily disclosed by the User to third parties or made publicly available at the User's own initiative;
  • Processing of personal data by third parties with which the User interacts independently and outside the scope of the Service;
  • Unauthorized access resulting from the User's failure to maintain the security of their account credentials;
  • Personal data processed on external websites or platforms linked from within the Service.

13. Amendments to this Policy

13.1. The Company reserves the right to amend this Policy at any time. The current version shall be published at: igft.tech/oncamp/privacy

13.2. Any amended version shall take effect upon its publication at the above URL, unless otherwise specified.

13.3. Your continued use of the Service following any changes constitutes your acceptance of such changes. We encourage you to review this Policy periodically.

14. Contact Information

Full company name: IGFT For Computer Systems & Communication Equipment Software Design CO. L.L.C

General Director: Vasilev Vasilii Anatolyevich

Authority: Memorandum of Association No. 7913462 dated 06/12/2022

Email: info@igft.tech

Website: igft.tech/oncamp

For any questions regarding the processing of personal data, or to exercise the rights set out in Section 9 of this Policy, please contact us at the email address provided above.