Personal Data Processing Policy
1. General Provisions
This Personal Data Processing Policy (hereinafter referred to as the “Policy”) has been prepared in accordance with the legislation of the United Arab Emirates in the field of personal data protection, including Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (hereinafter referred to as the “PDPL”), and determines the procedure for the Processing of Personal Data and the measures taken by MYWAY SHIPPING LINE FZCO (hereinafter referred to as the “Controller”) to ensure the security of Personal Data.
The Controller considers the observance of the rights and freedoms of natural persons in the Processing of their Personal Data, including the protection of the right to privacy, personal and family confidentiality, as well as compliance with the requirements of the PDPL and other applicable acts of the United Arab Emirates, to be the most important purpose and condition for carrying out its activities.
This Policy of the Controller regarding the Processing of Personal Data applies to all information that the Controller may receive about visitors to the website https://my-market.mg/ (hereinafter referred to as the “Website”), as well as when providing services and interacting with customers through this Website.
For matters related to the Processing and protection of Personal Data, the User may contact the Controller’s Data Protection Contact by e-mail at: [email protected].
1.1. The Controller of Personal Data is: MYWAY SHIPPING LINE FZCO
COMPANY ADDRESS: 3E 107 FIRST FLOOR 3 EAST, DUBAI AIRPORT FREEZONE, DUBAI
Contact e-mail: [email protected]
Contact number: +9710585482986
For the purpose of protecting Personal Data, the Controller may take reasonable measures to verify the identity of the applicant before providing Personal Data or fulfilling the relevant request.
The Controller considers requests and provides responses in accordance with the procedure and within the time limits established by applicable legislation.
If the Controller is entitled to refuse to satisfy a request or to restrict its fulfillment on the basis of the PDPL, the relevant request shall be considered taking into account the grounds and restrictions provided for by law.
1.1.1. The Controller is a legal entity registered in the United Arab Emirates and carries out the Processing of Personal Data in accordance with the PDPL and other applicable legislation.
1.1.2. The Controller considers the privacy and confidentiality of Personal Data to be the most important purpose and condition for carrying out its activities.
1.1.3. This Policy determines the procedure and conditions for the Processing of Personal Data, as well as the rights of Data Subjects and the obligations of the Controller in such Processing.
1.1.4. By using the Website and providing the Controller with his/her Personal Data, the User confirms that he/she has read this Policy and, where required, gives his/her Consent to the Processing of Personal Data in accordance with the procedure provided for by the legislation of the UAE.
1.2. This Policy of the Controller regarding the Processing of Personal Data (hereinafter referred to as the “Policy”) applies to all information that the Controller may receive about visitors to the website https://my-market.mg/.
2. Key Terms Used in the Policy
2.1. Automated Processing of Personal Data means the Processing of Personal Data using computer technology.
2.2. Website means a set of graphic and informational materials, as well as computer programs and databases, ensuring their availability on the Internet at the network address https://my-market.mg/.
2.3. Anonymization of Personal Data means actions as a result of which it is impossible, without the use of additional information, to determine that Personal Data belongs to a specific User or another Data Subject.
2.4. Processing of Personal Data means any operation or set of operations performed on Personal Data using automated means or without the use of such means, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (distribution, provision, access), anonymization, blocking, erasure and destruction of Personal Data.
2.5. The Controller means MYWAY SHIPPING LINE FZCO, a legal entity that, independently or jointly with other persons, determines the purposes and means of Processing Personal Data.
2.6. Personal Data means any information relating directly or indirectly to an identified or identifiable User of the website https://my-market.mg/.
2.7. User means any visitor to the website https://my-market.mg/.
2.8. Destruction of Personal Data means any actions as a result of which Personal Data is irreversibly destroyed with no possibility of subsequently restoring the content of Personal Data in the Personal Data information system and/or the physical media containing Personal Data are destroyed.
3. Main Rights and Obligations of the Controller
3.1. The Controller has the right to:
- receive from the Data Subject accurate information and/or documents containing Personal Data;
- independently determine the set of measures necessary to fulfill the obligations provided for by the PDPL;
- continue the Processing of Personal Data without separate Consent of the Data Subject if such Processing is based on other lawful grounds provided for by the PDPL;
- engage third parties (service providers) in the Processing of Personal Data on the basis of concluded contracts.
3.2. The Controller shall:
- provide the Data Subject, at his/her request, with information concerning the Processing of his/her Personal Data;
- organize the Processing of Personal Data in accordance with the PDPL and other applicable legislation of the UAE;
- respond to communications and requests from Data Subjects and their legal representatives in accordance with the requirements of the legislation of the UAE;
- interact with the competent UAE authority for Personal Data protection (UAE Data Office);
- publish or otherwise provide unrestricted access to this Personal Data Processing Policy;
- take legal, organizational and technical measures to protect Personal Data against unlawful or accidental access, destruction, alteration, blocking, copying, provision, distribution of Personal Data, as well as against other unlawful actions in relation to Personal Data;
- cease the Processing of Personal Data upon achievement of the purposes of Processing or in the absence of grounds for further Processing.
4. Main Rights and Obligations of Data Subjects
4.1. Data Subjects have the right to:
- receive information on the purposes, legal grounds, categories of data, retention periods, recipients and Cross-Border Processing;
- require the Controller to clarify their Personal Data, block or destroy it if the Personal Data is incomplete, outdated, inaccurate, unlawfully obtained or is not necessary for the stated purpose of Processing, as well as to take measures provided for by law to protect their rights;
- withdraw Consent to the Processing of Personal Data;
- require the erasure of Personal Data in cases provided for by applicable legislation;
- submit a complaint to the UAE Data Office in the event of an alleged violation of the PDPL.
4.2. Data Subjects shall:
- provide the Controller with accurate data about themselves;
- notify the Controller of clarification (updating, modification) of their Personal Data.
4.3. People who have provided the Controller with inaccurate information about themselves or information about another Data Subject without the latter’s Consent shall be liable in accordance with the legislation of the UAE.
5. The Controller May Process the Following Personal Data of the User
- Surname, first name, patronymic (if any).
- E-mail address.
- Telephone numbers.
- Company name and position (if specified);
5.1. The above data are hereinafter collectively referred to in this Policy as Personal Data.
5.2. The Controller does not intentionally collect or process special categories of Personal Data (Sensitive Personal Data) through the Website, unless otherwise expressly communicated to the Data Subject and such Processing is carried out on a lawful basis in accordance with the PDPL.
6. Principles of Personal Data Processing
6.1. The Processing of Personal Data shall be carried out on a lawful and fair basis.
6.2. The Processing of Personal Data shall be limited to achieving specific, predetermined and lawful purposes. Processing of Personal Data incompatible with the purposes for which the Personal Data was collected shall not be permitted.
6.3. Combining databases containing Personal Data that are processed for mutually incompatible purposes shall not be permitted.
6.4. Only Personal Data that corresponds to the purposes of its Processing shall be subject to Processing.
6.5. The content and scope of the Personal Data processed shall correspond to the stated purposes of Processing. Excessive Processing of Personal Data in relation to the stated purposes of its Processing shall not be permitted.
6.6. When Processing Personal Data, the accuracy of Personal Data, its sufficiency and, where necessary, its relevance in relation to the purposes of Processing Personal Data shall be ensured. The Controller shall take the necessary measures and/or ensure that such measures are taken to erase or clarify incomplete or inaccurate data.
6.7. Personal Data shall be stored in a form that allows the Data Subject to be identified for no longer than required by the purposes of Processing Personal Data, unless the retention period for Personal Data is established by federal law or by a contract to which the Data Subject is a party, beneficiary or guarantor. Personal Data being processed shall be destroyed or anonymized upon achievement of the purposes of Processing or where the need to achieve such purposes ceases to exist, unless otherwise provided by federal law.
7. Purposes of Personal Data Processing
7.1. The purposes of Processing the User’s Personal Data are:
- informing, providing feedback and consulting the User by sending e-mails.
- registration and Processing of applications submitted by Users of the Website https://my-market.mg/.
7.2. The Controller also has the right to send the User notifications about new products and services, special offers and various events, including products, services and various events of the Controller’s partners. The User may always opt out of receiving informational messages by sending an e-mail to the Controller at [email protected] marked “Unsubscribe from notifications about new products and services and special offers”.
7.3. Anonymized User data collected through Internet statistics services is used to collect information about Users’ activities on the Website and to improve the quality of the Website and its content.
8. Legal Grounds for Personal Data Processing and Conditions for Personal Data Processing
8.1. The legal grounds for the Processing of Personal Data by the Controller are:
- The Controller processes Personal Data on the basis of the Consent of the Data Subject or without such Consent exclusively in the cases provided for by the PDPL and other applicable legislation of the UAE.
- The Controller has the right to process Personal Data without the Consent of the Data Subject exclusively where one of the grounds provided for in Article 4 of the PDPL applies, including where such Processing is necessary for entering into or performing a contract with the Data Subject or for taking procedures at the request of the Data Subject for the purpose of entering into, amending or terminating a contract, as well as in other cases expressly provided for by the PDPL.
- If several potential grounds are applicable to a particular Processing operation, the Controller determines and documents the applicable legal ground taking into account the purpose and nature of the relevant Processing.
- legitimate interests of the Controller (business development, ensuring security, improving the quality of service);
8.2. The Controller does not make decisions based solely on Automated Processing of Personal Data, including Profiling, which have legal consequences for the User or otherwise significantly affect his/her interests, unless such Processing is actually carried out by the Controller.
If the Controller begins to carry out such Processing, the Data Subject will be provided with information about the relevant Processing and the rights provided for by the PDPL.
In the cases provided for by the PDPL, the Data Subject has the right to object to the relevant decision and request human involvement in reviewing a decision made by means of Automated Processing.
8.3. The Data Subject independently decides whether to provide his/her Personal Data and gives Consent freely, of his/her own will and in his/her own interest.
8.4. Personal Data is processed with the Consent of the Data Subject to the Processing of his/her Personal Data.
8.5. Personal Data may be processed without separate Consent of the Data Subject if such Processing is necessary for: performance of a contract; fulfilment of the Controller’s legal obligations; protection of the vital interests of the Data Subject; pursuit of the legitimate interests of the Controller or other grounds provided for by the PDPL.
8.6. The Processing of Personal Data is necessary for the administration of justice, enforcement of a judicial act, an act of another authority or official subject to enforcement in accordance with the legislation of the UAE.
8.7. The Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is a party or under which the Data Subject is a beneficiary or guarantor, as well as for entering into a contract at the initiative of the Data Subject or a contract under which the Data Subject will be a beneficiary or guarantor.
8.8. The Processing of Personal Data is necessary for exercising the rights and legitimate interests of the Controller or third parties or for achieving socially significant purposes, provided that the rights and freedoms of the Data Subject are not violated thereby.
8.9. Processing is carried out using automated means and/or without such means.
9. Procedure for Collection, Storage, Transfer and Other Types of Personal Data Processing
9.1. The security of Personal Data processed by the Controller is ensured through the implementation of legal, organizational and technical measures necessary to fully comply with the requirements of the PDPL.
9.2. The Controller ensures the security of Personal Data and takes all possible measures to prevent unauthorized persons from accessing Personal Data.
9.3. The Controller has the right to engage third parties, including providers of IT infrastructure, hosting, CRM systems, analytics and other services, to process Personal Data on behalf of the Controller.
When engaging a Processor, the Controller takes reasonable measures to select a person providing sufficient guarantees for the implementation of appropriate technical and organizational measures for the protection of Personal Data.
The Processing of Personal Data by the Processor is carried out in accordance with the applicable requirements of the PDPL and on the basis of contractual terms defining the applicable obligations of the parties with respect to Processing, confidentiality, security and protection of Personal Data.
9.4. If inaccuracies in Personal Data are identified, the User may update such data independently by sending a notification to the Controller at the Controller’s e-mail address [email protected] marked “Updating Personal Data”.
9.5. The period of Personal Data Processing is determined by the achievement of the purposes for which the Personal Data was collected, unless another period is provided for by a contract or applicable legislation. The User may withdraw his/her Consent to the Processing of Personal Data at any time by sending a notification to the Controller by e-mail at the Controller’s e-mail address [email protected] marked “Withdrawal of Consent to the Processing of Personal Data”.
9.6. All information collected by third-party services, communication facilities and other service providers, is stored and processed by the said persons (Controllers) in accordance with their User Agreement and Privacy Policy. The Data Subject and/or User shall independently and in a timely manner familiarize himself/herself with the said documents. The Controller shall not be liable for the actions of third parties, including the service providers specified in this paragraph.
9.7. When Processing Personal Data, the Controller ensures the confidentiality of Personal Data.
9.8. The Controller stores Personal Data in a form that allows the Data Subject to be identified for no longer than required by the purposes of Personal Data Processing, unless the Personal Data retention period is established by federal law or by a contract to which the Data Subject is a party, beneficiary or guarantor.
9.9. A condition for terminating the Processing of Personal Data may be the achievement of the purposes of Personal Data Processing, expiration of the Data Subject’s Consent or withdrawal of Consent by the Data Subject, as well as identification of unlawful Processing of Personal Data.
9.10. In the event of a security incident capable of creating a significant risk to the rights of Data Subjects, the Controller organizes an assessment of such incident and, where necessary, notifies the UAE Data Office in accordance with the requirements of the PDPL.
9.11. In the event of an actual or suspected Personal Data Breach, the Controller takes the necessary measures to assess the nature, scope, causes and possible consequences of such breach, to limit its consequences and to prevent a recurrence.
In the cases provided for by the PDPL and other applicable legislation, the Controller notifies the competent authority and/or affected Data Subjects of the security breach and provides the information required by law.
The Controller documents and reviews security incidents in accordance with the applicable requirements of legislation and internal information security procedures.
10. List of Actions Performed by the Controller with the Personal Data Received
10.1. The Controller carries out the collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (distribution, provision, access), anonymization, blocking, erasure and destruction of Personal Data.
10.2. The Controller carries out Automated Processing of Personal Data with or without the receipt and/or transfer of the information received through information and telecommunications networks.
11. Cross-Border Processing of Personal Data
11.1. The Controller may carry out Cross-Border Processing of Personal Data to other states or international organizations if this is necessary for the operation of IT infrastructure, the use of cloud services or other lawful purposes, subject to compliance with the PDPL requirements for the protection of Personal Data.
11.2. The transfer of Personal Data to states that do not provide an adequate level of protection may be carried out subject to the availability of appropriate safeguards provided for by the PDPL.
12. Confidentiality of Personal Data
12.1. The Controller and other persons who have obtained access to Personal Data on the basis of contracts or law shall not disclose or distribute Personal Data to third parties without a lawful basis or the appropriate Consent of the Data Subject, except in cases expressly provided for by the legislation of the UAE.
12.2. The Controller may use and disclose anonymized or aggregated information for statistical, analytical, research, business development and other lawful purposes, provided that such information does not identify or allow identification of any Data Subject.
13. Cookies and Similar Technologies
13.1. The Website may use cookies and similar technologies necessary for the functioning of the Website, ensuring its security, saving User settings, analyzing the use of the Website and, where there is an appropriate lawful basis, for other purposes.
13.2. Before using analytical, marketing or other non-essential technologies, the Controller applies a mechanism for obtaining Consent in cases where such Consent is required by applicable legislation.
13.3. The User may manage the available cookie settings through the relevant cookie management tool on the Website and/or browser settings.
13.4. Up-to-date information on the cookies and similar technologies actually used, their providers, purposes and validity periods is specified in the Cookie Policy and/or cookie management interface.
14. Final Provisions
14.1. The User may obtain any clarifications on matters of interest concerning the Processing of his/her Personal Data by contacting the Controller by e-mail at [email protected].
14.2. This document will reflect any changes to the Controller’s Personal Data Processing Policy. The Policy shall remain in effect indefinitely until replaced by a new version.
14.3. The current version of the Policy is freely available on the Internet https://my-market.mg/.