Legal

Privacy Policy.

Last updated: 10 June 2026

Last updated: 10 June 2026

Effective date: 10 June 2026.

ContentsShow

1. Introduction

This Privacy Policy explains how Kodfolio ( "Kodfolio", "we", "us", or "our") collects, uses, stores, shares, and protects personal information when you do any of the following:

By using our website or voluntarily providing your information, you acknowledge that your information may be handled as described in this Privacy Policy.

This Privacy Policy should be read together with our Terms and Conditions and any additional notice presented when information is collected.

  • Visit or use kodfolio.ae and its related pages;
  • Submit a contact, audit, consultation, quotation, or enquiry form;
  • Communicate with us by email, telephone, WhatsApp, social media, or another communication channel;
  • Request information about our services;
  • Become, or consider becoming, a client, supplier, contractor, or business partner; or
  • Otherwise interact with Kodfolio.

2. Who We Are

Kodfolio is a digital agency operating in the United Arab Emirates.

For personal information collected through our website and for our own business purposes, Kodfolio generally acts as the party responsible for determining why and how that information is processed.

For privacy-related enquiries, contact: Kodfolio

Email: info@kodfolio.ae

3. Information We May Collect

The information we collect depends on how you interact with us.

3.1 Information You Provide

We may collect information that you voluntarily provide, including:

Please avoid submitting confidential, sensitive, or unnecessary personal information unless we specifically request it and there is a legitimate reason for providing it.

  • Your name;
  • Email address;
  • Mobile or telephone number;
  • Company or business name;
  • Job title;
  • Website address;
  • Details about your business, project, requirements, objectives, or budget;
  • Information contained in messages, documents, briefs, files, or forms you submit;
  • Billing, payment, invoicing, and contractual information;
  • Communication and marketing preferences; and
  • Any other information you choose to provide.

3.2 Information Collected Automatically

When you access our website, certain technical information may be collected automatically, including:

This information may be collected through server logs, cookies, analytics technologies, hosting services, or similar tools.

  • Internet Protocol address;
  • Browser type and version;
  • Device type;
  • Operating system;
  • Approximate location derived from your IP address;
  • Referring website or source;
  • Pages visited;
  • Time and date of access;
  • Website interaction and performance data; and
  • Security, error, and diagnostic logs.

3.3 Information From Other Sources

Where lawful and appropriate, we may receive information from:

  • Your employer, employee, representative, or business partner;
  • Publicly available business and professional sources;
  • Social media and professional networking platforms;
  • Referral partners;
  • Clients in connection with an authorised project;
  • Contractors and service providers; and
  • Government, regulatory, fraud-prevention, or compliance sources.

4. How We Use Information

We may use personal information to:

  • Respond to enquiries and communications;
  • Provide consultations, audits, proposals, quotations, and requested information;
  • Assess whether our services are suitable for your requirements;
  • Enter into and perform contracts;
  • Deliver, manage, improve, and support our services;
  • Communicate with clients, prospective clients, suppliers, contractors, and partners;
  • Manage projects, accounts, invoices, and payments;
  • Maintain business, accounting, tax, and compliance records;
  • Verify information and prevent fraud, abuse, spam, or security incidents;
  • Operate, maintain, troubleshoot, and secure our website and systems;
  • Analyse website performance and general usage;
  • Improve our services, content, user experience, and internal processes;
  • Establish, exercise, or defend legal claims;
  • Enforce our Terms and Conditions and contractual rights;
  • Comply with applicable laws, regulations, court orders, and lawful authority requests; and
  • Send marketing communications where legally permitted and where any required consent has been obtained.

6. Client Data and Our Role as a Service Provider

When Kodfolio processes information belonging to or controlled by a client solely to provide contracted services, we may act as a service provider, processor, or sub-processor on behalf of that client.

6.1 Examples of Processing

Examples may include information processed during:

  • Website development or maintenance;
  • Customer relationship management configuration;
  • Marketing campaign management;
  • Lead-processing services;
  • Analytics implementation;
  • Email or messaging campaigns;
  • Advertising account management; or
  • Other digital agency services.

6.2 Our Obligations

In those circumstances:

  • The client generally determines the purpose and instructions for processing;
  • The client is responsible for ensuring it has the necessary authority, notices, permissions, and lawful basis;
  • We process the information according to the relevant agreement and documented instructions; and
  • Requests concerning client-controlled information may need to be submitted directly to the relevant client.

6.3 Scope of This Policy

This public Privacy Policy primarily applies where Kodfolio processes personal information for its own business purposes.

7. Cookies and Similar Technologies

Our website may use cookies, local storage, tags, scripts, pixels, analytics tools, or similar technologies.

These technologies may be used for:

7.1 Strictly Necessary Purposes

These are required to:

  • Operate the website;
  • Maintain security;
  • Prevent misuse;
  • Remember essential settings;
  • Manage forms or sessions; and
  • Provide features requested by the user.

7.2 Preferences and Functionality

These may remember choices and improve website functionality.

7.3 Analytics and Performance

These may help us understand general website usage, identify technical issues, and improve performance.

7.4 Advertising and Social Media

We may introduce advertising, remarketing, conversion-measurement, or social-media technologies in the future. Where consent is legally required, such technologies should not be activated before valid consent is obtained.

7.5 Managing Your Preferences

You may be able to manage optional cookies through our website's cookie settings or through your browser. Disabling certain technologies may affect parts of the website.

Details of the technologies actually used may be provided through our cookie banner, cookie settings tool, or a separate Cookie Policy.

8. Marketing Communications

We may send marketing or promotional communications only where permitted by applicable law.

Where consent is required, we will request it separately. You can opt out at any time by using an unsubscribe option included in the communication or by contacting us at info@kodfolio.ae.

After an opt-out, we may retain limited information on a suppression list to ensure that your preference continues to be respected.

Opting out of marketing will not prevent us from sending necessary service, project, contractual, payment, security, or administrative communications.

9. When We May Share Information

We do not sell or rent personal information.

We may share information where reasonably necessary with:

  • Website hosting, infrastructure, cloud, and content-delivery providers;
  • Email, communication, CRM, customer-support, and project-management providers;
  • Analytics, performance, security, and fraud-prevention providers;
  • Payment processors, accountants, auditors, banks, insurers, and professional advisers;
  • Employees, authorised team members, consultants, freelancers, and contractors who require access for legitimate business purposes;
  • Clients, where the information relates to services performed on their behalf;
  • Business partners involved in an authorised service or project;
  • Government bodies, regulators, courts, law-enforcement authorities, or other parties where disclosure is legally required;
  • Parties involved in investigating or preventing fraud, misuse, threats, or security incidents;
  • A purchaser, investor, successor, or adviser in connection with a merger, restructuring, financing, transfer, acquisition, or sale of all or part of our business or assets; and
  • Other parties where you have authorised the disclosure.

9.1 Service Provider Standards

Service providers are expected to use personal information only for authorised purposes and to apply appropriate confidentiality and security measures.

We do not share personal information for unrelated third-party marketing without appropriate permission or another lawful basis.

10. International Processing and Transfers

Some of our service providers, cloud systems, contractors, or technology partners may operate from countries outside the United Arab Emirates.

As a result, personal information may be stored, accessed, supported, or processed outside the UAE or outside the country where you are located.

Where international transfers occur, we will take reasonable steps appropriate to the circumstances and applicable law. These may include:

  • Using providers that maintain recognised data-protection and security standards;
  • Entering into contractual confidentiality, security, or data-processing obligations;
  • Limiting access to information;
  • Applying technical and organisational safeguards;
  • Relying on legally recognised transfer mechanisms; or
  • Obtaining consent where consent is required for a particular transfer.

10.1 Transfer Disclaimer

No international transfer mechanism or electronic system can provide absolute protection. However, we take reasonable steps intended to reduce relevant risks.

11. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected and for legitimate legal, contractual, financial, operational, security, and evidentiary requirements.

Our typical retention approach is:

  • Unsuccessful or inactive general enquiries may normally be retained for up to 12 months after the last meaningful communication;
  • Client, project, contract, invoicing, accounting, and transaction records may normally be retained for up to 7 years after the relevant relationship or transaction, or longer where legally required;
  • Technical and security logs may normally be retained for up to 90 days, unless a longer period is necessary for an investigation, security incident, legal hold, or dispute;
  • Marketing information may be retained until consent is withdrawn, an objection is received, or the information is no longer reasonably required;
  • Opt-out and suppression records may be retained for as long as necessary to respect the relevant preference; and
  • Information connected with a complaint, dispute, investigation, or legal claim may be retained until the matter and relevant limitation periods have ended.

11.1 Retention Changes and Disposal

Retention periods may be shortened or extended depending on legal requirements, the nature of the information, operational necessity, disputes, regulatory enquiries, backup schedules, or security considerations.

When information is no longer required, we may delete, anonymise, overwrite, or securely archive it.

12. Information Security

We use reasonable technical and organisational safeguards designed to protect personal information against accidental or unlawful:

  • Loss;
  • Misuse;
  • Unauthorised access;
  • Disclosure;
  • Alteration;
  • Destruction; or
  • Other improper processing.

12.1 Security Measures

Measures may include:

  • Access restrictions;
  • Password controls and multi-factor authentication;
  • Encryption in transit where appropriate;
  • Secure hosting and cloud services;
  • Confidentiality obligations;
  • Backups;
  • Logging and monitoring;
  • Software and system updates;
  • Vendor review;
  • Staff access controls; and
  • Incident-response procedures.

12.2 Security Limitations

However, no website, storage system, cloud platform, transmission method, or security process is completely secure. We cannot guarantee absolute security or that an unauthorised third party will never defeat available safeguards.

You are responsible for using secure devices, protecting your own accounts and passwords, and avoiding the transmission of unnecessary sensitive information.

13. Data Breaches

If we become aware of a personal-data breach, we may:

  • Investigate and contain the incident;
  • Take reasonable remediation measures;
  • Preserve relevant evidence;
  • Notify affected clients, users, service providers, regulators, or authorities where required; and
  • Provide affected individuals with relevant information where notification is legally required or reasonably appropriate.

13.1 Breach Notification

The timing and content of any notification will depend on applicable law, available facts, the type of information involved, and the level of risk.

14. Your Rights

Depending on applicable law and your circumstances, you may have the right to:

  • Request information about how your personal information is processed;
  • Request access to personal information held about you;
  • Request correction of inaccurate or incomplete information;
  • Request deletion of information in certain circumstances;
  • Request restriction or suspension of certain processing;
  • Object to certain processing;
  • Withdraw consent where processing is based on consent;
  • Object to direct marketing;
  • Request the transfer or portability of information where applicable;
  • Request human review of certain significant automated decisions, if applicable; and
  • Submit a complaint to a competent data-protection or regulatory authority.

14.1 Limitations on Rights

These rights are not absolute. We may refuse, restrict, or delay a request where permitted or required by law, including where:

  • We cannot reasonably verify the requester's identity or authority;
  • The request affects the rights or privacy of another person;
  • Information must be retained for legal, financial, security, contractual, or evidentiary purposes;
  • The request is manifestly unfounded, excessive, repetitive, or abusive;
  • Legal privilege or confidentiality applies; or
  • Another lawful exception applies.

15. How to Submit a Privacy Request

To submit a privacy request, contact:

info@kodfolio.ae

Please include:

  • Your full name;
  • The email address or other contact information associated with your interaction with us;
  • A clear description of your request; and
  • Any information reasonably necessary to locate the relevant records.

15.1 Request Processing

We may request additional information to verify your identity or confirm that an authorised representative is entitled to act for you.

We will aim to respond within the period required by applicable law. Complex requests, identity-verification issues, legal restrictions, or unusually large requests may require additional time where legally permitted.

16. Automated Decision-Making

We do not ordinarily use personal information to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.

We may use ordinary automation for functions such as:

  • Spam filtering;
  • Form routing;
  • Security monitoring;
  • Analytics;
  • Message categorisation; or
  • Workflow management.

16.1 Future Automated Decisions

If we introduce significant automated decision-making in the future, we will provide any additional notice and rights required by applicable law.

17. Children's Information

Our website and services are intended primarily for businesses and adults and are not directed toward children.

We do not knowingly collect personal information from children through our ordinary website and business activities.

If you believe a child has submitted personal information without appropriate permission, contact us at info@kodfolio.ae. We will review the matter and take reasonable action, including deletion where required.

18. Third-Party Websites and Services

Our website may contain links to third-party websites, platforms, applications, social-media pages, or services.

We do not control the privacy, content, availability, security, or data-handling practices of third parties. This Privacy Policy does not apply to information collected independently by those third parties.

You should review the relevant third party's privacy policy before providing information or using its services.

The inclusion of a link does not necessarily mean that we endorse or accept responsibility for the third party.

19. Social Media and Messaging Platforms

When you communicate with us through WhatsApp, Instagram, LinkedIn, Facebook, or another third-party platform, both Kodfolio and the platform provider may process information relating to that interaction.

Your use of such platforms is also subject to the platform provider's own privacy terms and settings. We are not responsible for the platform's independent processing activities.

Information submitted through messaging or social-media services may be transferred or stored outside the UAE by the relevant provider.

20. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • Changes to our services;
  • New website features;
  • New technologies or service providers;
  • Changes to our data-handling practices;
  • Legal or regulatory developments; or
  • Security and operational requirements.

20.1 Notice of Changes

The updated version will be published on this page with a revised "Last updated" date.

Where a change materially affects how personal information is used, we may provide additional notice where reasonably appropriate or legally required.

Your continued use of the website after publication of an updated policy does not replace consent where applicable law specifically requires new consent.

21. Complaints

If you have a concern about how we process personal information, contact us first at info@kodfolio.ae so that we can review and attempt to resolve the issue.

You may also have the right to complain to the competent data-protection authority or regulator under the law applicable to your circumstances.

22. Contact Us

For questions, requests, or complaints concerning this Privacy Policy or our handling of personal information, contact:

Kodfolio

Email: info@kodfolio.ae

Location: Dubai, United Arab Emirates