This Privacy Policy explains how Kodfolio ( "Kodfolio", "we", "us", or "our") collects, uses, stores, shares, and protects personal information when you do any of the following:
By using our website or voluntarily providing your information, you acknowledge that your information may be handled as described in this Privacy Policy.
This Privacy Policy should be read together with our Terms and Conditions and any additional notice presented when information is collected.
Visit or use kodfolio.ae and its related pages;
Submit a contact, audit, consultation, quotation, or enquiry form;
Communicate with us by email, telephone, WhatsApp, social media, or another communication channel;
Request information about our services;
Become, or consider becoming, a client, supplier, contractor, or business partner; or
Otherwise interact with Kodfolio.
2. Who We Are
Kodfolio is a digital agency operating in the United Arab Emirates.
For personal information collected through our website and for our own business purposes, Kodfolio generally acts as the party responsible for determining why and how that information is processed.
The information we collect depends on how you interact with us.
3.1 Information You Provide
We may collect information that you voluntarily provide, including:
Please avoid submitting confidential, sensitive, or unnecessary personal information unless we specifically request it and there is a legitimate reason for providing it.
Your name;
Email address;
Mobile or telephone number;
Company or business name;
Job title;
Website address;
Details about your business, project, requirements, objectives, or budget;
Information contained in messages, documents, briefs, files, or forms you submit;
Billing, payment, invoicing, and contractual information;
Communication and marketing preferences; and
Any other information you choose to provide.
3.2 Information Collected Automatically
When you access our website, certain technical information may be collected automatically, including:
This information may be collected through server logs, cookies, analytics technologies, hosting services, or similar tools.
Internet Protocol address;
Browser type and version;
Device type;
Operating system;
Approximate location derived from your IP address;
Referring website or source;
Pages visited;
Time and date of access;
Website interaction and performance data; and
Security, error, and diagnostic logs.
3.3 Information From Other Sources
Where lawful and appropriate, we may receive information from:
Your employer, employee, representative, or business partner;
Publicly available business and professional sources;
Social media and professional networking platforms;
Referral partners;
Clients in connection with an authorised project;
Contractors and service providers; and
Government, regulatory, fraud-prevention, or compliance sources.
4. How We Use Information
We may use personal information to:
Respond to enquiries and communications;
Provide consultations, audits, proposals, quotations, and requested information;
Assess whether our services are suitable for your requirements;
Enter into and perform contracts;
Deliver, manage, improve, and support our services;
Communicate with clients, prospective clients, suppliers, contractors, and partners;
Manage projects, accounts, invoices, and payments;
Maintain business, accounting, tax, and compliance records;
Verify information and prevent fraud, abuse, spam, or security incidents;
Operate, maintain, troubleshoot, and secure our website and systems;
Analyse website performance and general usage;
Improve our services, content, user experience, and internal processes;
Establish, exercise, or defend legal claims;
Enforce our Terms and Conditions and contractual rights;
Comply with applicable laws, regulations, court orders, and lawful authority requests; and
Send marketing communications where legally permitted and where any required consent has been obtained.
5. Legal Grounds for Processing
Depending on the circumstances and applicable law, we may process personal information on one or more of the following grounds:
You have provided valid consent;
Processing is necessary to respond to your request or take steps before entering into a contract;
Processing is necessary to perform or manage a contract;
Processing is necessary to comply with a legal or regulatory obligation;
Processing is necessary to protect our systems, business, clients, users, or legal rights;
Processing is necessary for the establishment, exercise, or defence of legal claims; or
Another lawful ground or exception applies under applicable data-protection law.
6. Client Data and Our Role as a Service Provider
When Kodfolio processes information belonging to or controlled by a client solely to provide contracted services, we may act as a service provider, processor, or sub-processor on behalf of that client.
6.1 Examples of Processing
Examples may include information processed during:
Website development or maintenance;
Customer relationship management configuration;
Marketing campaign management;
Lead-processing services;
Analytics implementation;
Email or messaging campaigns;
Advertising account management; or
Other digital agency services.
6.2 Our Obligations
In those circumstances:
The client generally determines the purpose and instructions for processing;
The client is responsible for ensuring it has the necessary authority, notices, permissions, and lawful basis;
We process the information according to the relevant agreement and documented instructions; and
Requests concerning client-controlled information may need to be submitted directly to the relevant client.
6.3 Scope of This Policy
This public Privacy Policy primarily applies where Kodfolio processes personal information for its own business purposes.
7. Cookies and Similar Technologies
Our website may use cookies, local storage, tags, scripts, pixels, analytics tools, or similar technologies.
These technologies may be used for:
7.1 Strictly Necessary Purposes
These are required to:
Operate the website;
Maintain security;
Prevent misuse;
Remember essential settings;
Manage forms or sessions; and
Provide features requested by the user.
7.2 Preferences and Functionality
These may remember choices and improve website functionality.
7.3 Analytics and Performance
These may help us understand general website usage, identify technical issues, and improve performance.
7.4 Advertising and Social Media
We may introduce advertising, remarketing, conversion-measurement, or social-media technologies in the future. Where consent is legally required, such technologies should not be activated before valid consent is obtained.
7.5 Managing Your Preferences
You may be able to manage optional cookies through our website's cookie settings or through your browser. Disabling certain technologies may affect parts of the website.
Details of the technologies actually used may be provided through our cookie banner, cookie settings tool, or a separate Cookie Policy.
8. Marketing Communications
We may send marketing or promotional communications only where permitted by applicable law.
Where consent is required, we will request it separately. You can opt out at any time by using an unsubscribe option included in the communication or by contacting us at info@kodfolio.ae.
After an opt-out, we may retain limited information on a suppression list to ensure that your preference continues to be respected.
Opting out of marketing will not prevent us from sending necessary service, project, contractual, payment, security, or administrative communications.
9. When We May Share Information
We do not sell or rent personal information.
We may share information where reasonably necessary with:
Website hosting, infrastructure, cloud, and content-delivery providers;
Email, communication, CRM, customer-support, and project-management providers;
Analytics, performance, security, and fraud-prevention providers;
Payment processors, accountants, auditors, banks, insurers, and professional advisers;
Employees, authorised team members, consultants, freelancers, and contractors who require access for legitimate business purposes;
Clients, where the information relates to services performed on their behalf;
Business partners involved in an authorised service or project;
Government bodies, regulators, courts, law-enforcement authorities, or other parties where disclosure is legally required;
Parties involved in investigating or preventing fraud, misuse, threats, or security incidents;
A purchaser, investor, successor, or adviser in connection with a merger, restructuring, financing, transfer, acquisition, or sale of all or part of our business or assets; and
Other parties where you have authorised the disclosure.
9.1 Service Provider Standards
Service providers are expected to use personal information only for authorised purposes and to apply appropriate confidentiality and security measures.
We do not share personal information for unrelated third-party marketing without appropriate permission or another lawful basis.
10. International Processing and Transfers
Some of our service providers, cloud systems, contractors, or technology partners may operate from countries outside the United Arab Emirates.
As a result, personal information may be stored, accessed, supported, or processed outside the UAE or outside the country where you are located.
Where international transfers occur, we will take reasonable steps appropriate to the circumstances and applicable law. These may include:
Using providers that maintain recognised data-protection and security standards;
Entering into contractual confidentiality, security, or data-processing obligations;
Limiting access to information;
Applying technical and organisational safeguards;
Relying on legally recognised transfer mechanisms; or
Obtaining consent where consent is required for a particular transfer.
10.1 Transfer Disclaimer
No international transfer mechanism or electronic system can provide absolute protection. However, we take reasonable steps intended to reduce relevant risks.
11. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected and for legitimate legal, contractual, financial, operational, security, and evidentiary requirements.
Our typical retention approach is:
Unsuccessful or inactive general enquiries may normally be retained for up to 12 months after the last meaningful communication;
Client, project, contract, invoicing, accounting, and transaction records may normally be retained for up to 7 years after the relevant relationship or transaction, or longer where legally required;
Technical and security logs may normally be retained for up to 90 days, unless a longer period is necessary for an investigation, security incident, legal hold, or dispute;
Marketing information may be retained until consent is withdrawn, an objection is received, or the information is no longer reasonably required;
Opt-out and suppression records may be retained for as long as necessary to respect the relevant preference; and
Information connected with a complaint, dispute, investigation, or legal claim may be retained until the matter and relevant limitation periods have ended.
11.1 Retention Changes and Disposal
Retention periods may be shortened or extended depending on legal requirements, the nature of the information, operational necessity, disputes, regulatory enquiries, backup schedules, or security considerations.
When information is no longer required, we may delete, anonymise, overwrite, or securely archive it.
12. Information Security
We use reasonable technical and organisational safeguards designed to protect personal information against accidental or unlawful:
Loss;
Misuse;
Unauthorised access;
Disclosure;
Alteration;
Destruction; or
Other improper processing.
12.1 Security Measures
Measures may include:
Access restrictions;
Password controls and multi-factor authentication;
Encryption in transit where appropriate;
Secure hosting and cloud services;
Confidentiality obligations;
Backups;
Logging and monitoring;
Software and system updates;
Vendor review;
Staff access controls; and
Incident-response procedures.
12.2 Security Limitations
However, no website, storage system, cloud platform, transmission method, or security process is completely secure. We cannot guarantee absolute security or that an unauthorised third party will never defeat available safeguards.
You are responsible for using secure devices, protecting your own accounts and passwords, and avoiding the transmission of unnecessary sensitive information.
13. Data Breaches
If we become aware of a personal-data breach, we may:
Investigate and contain the incident;
Take reasonable remediation measures;
Preserve relevant evidence;
Notify affected clients, users, service providers, regulators, or authorities where required; and
Provide affected individuals with relevant information where notification is legally required or reasonably appropriate.
13.1 Breach Notification
The timing and content of any notification will depend on applicable law, available facts, the type of information involved, and the level of risk.
14. Your Rights
Depending on applicable law and your circumstances, you may have the right to:
Request information about how your personal information is processed;
Request access to personal information held about you;
Request correction of inaccurate or incomplete information;
Request deletion of information in certain circumstances;
Request restriction or suspension of certain processing;
Object to certain processing;
Withdraw consent where processing is based on consent;
Object to direct marketing;
Request the transfer or portability of information where applicable;
Request human review of certain significant automated decisions, if applicable; and
Submit a complaint to a competent data-protection or regulatory authority.
14.1 Limitations on Rights
These rights are not absolute. We may refuse, restrict, or delay a request where permitted or required by law, including where:
We cannot reasonably verify the requester's identity or authority;
The request affects the rights or privacy of another person;
Information must be retained for legal, financial, security, contractual, or evidentiary purposes;
The request is manifestly unfounded, excessive, repetitive, or abusive;
The email address or other contact information associated with your interaction with us;
A clear description of your request; and
Any information reasonably necessary to locate the relevant records.
15.1 Request Processing
We may request additional information to verify your identity or confirm that an authorised representative is entitled to act for you.
We will aim to respond within the period required by applicable law. Complex requests, identity-verification issues, legal restrictions, or unusually large requests may require additional time where legally permitted.
16. Automated Decision-Making
We do not ordinarily use personal information to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.
We may use ordinary automation for functions such as:
Spam filtering;
Form routing;
Security monitoring;
Analytics;
Message categorisation; or
Workflow management.
16.1 Future Automated Decisions
If we introduce significant automated decision-making in the future, we will provide any additional notice and rights required by applicable law.
17. Children's Information
Our website and services are intended primarily for businesses and adults and are not directed toward children.
We do not knowingly collect personal information from children through our ordinary website and business activities.
If you believe a child has submitted personal information without appropriate permission, contact us at info@kodfolio.ae. We will review the matter and take reasonable action, including deletion where required.
18. Third-Party Websites and Services
Our website may contain links to third-party websites, platforms, applications, social-media pages, or services.
We do not control the privacy, content, availability, security, or data-handling practices of third parties. This Privacy Policy does not apply to information collected independently by those third parties.
You should review the relevant third party's privacy policy before providing information or using its services.
The inclusion of a link does not necessarily mean that we endorse or accept responsibility for the third party.
19. Social Media and Messaging Platforms
When you communicate with us through WhatsApp, Instagram, LinkedIn, Facebook, or another third-party platform, both Kodfolio and the platform provider may process information relating to that interaction.
Your use of such platforms is also subject to the platform provider's own privacy terms and settings. We are not responsible for the platform's independent processing activities.
Information submitted through messaging or social-media services may be transferred or stored outside the UAE by the relevant provider.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
Changes to our services;
New website features;
New technologies or service providers;
Changes to our data-handling practices;
Legal or regulatory developments; or
Security and operational requirements.
20.1 Notice of Changes
The updated version will be published on this page with a revised "Last updated" date.
Where a change materially affects how personal information is used, we may provide additional notice where reasonably appropriate or legally required.
Your continued use of the website after publication of an updated policy does not replace consent where applicable law specifically requires new consent.
21. Complaints
If you have a concern about how we process personal information, contact us first at info@kodfolio.ae so that we can review and attempt to resolve the issue.
You may also have the right to complain to the competent data-protection authority or regulator under the law applicable to your circumstances.
22. Contact Us
For questions, requests, or complaints concerning this Privacy Policy or our handling of personal information, contact: