IGFT For Computer Systems & Communication Equipment Software Design L.L.C.
OnCamp mobile application and platform
1.1. This Privacy Policy (the “Policy”) is issued in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “PDPL”) and describes how the OnCamp mobile application and web administration panel (collectively, the “Platform”) process personal data.
1.2. The data controller within the meaning of the PDPL is: IGFT For Computer Systems & Communication Equipment Software Design L.L.C., Address: 4-C-89, EMPIRE HEIGHTS A - 16F-A-04, Business Bay, Dubai, UAE, License number: 1125276 (the “Controller”). The Platform's server infrastructure and all databases are physically located on servers in the United Arab Emirates. No transfer of personal data outside the UAE takes place in the course of the Platform's operation, unless the data subject is located outside the UAE and accesses the Platform from abroad.
1.3. Where a user accesses the Platform from a jurisdiction whose data protection law applies extraterritorially, the Controller complies with the applicable requirements of that jurisdiction in respect of such user, in addition to this Policy.
1.4. By using the Platform, you acknowledge that you have read and understood this Policy. For users registered under Scenario 2 (clause 2.3), the terms of this Policy are accepted by ticking the acceptance box during registration, and the Controller is able to demonstrate such consent in accordance with Art. 6(1) PDPL.
2.1. The Platform implements two user registration scenarios, differing in the manner in which an account is created, the categories of data processed, and the resulting privacy implications.
2.2. Scenario 1: uninitiative registration
User accounts (for the customer's employees) are created in accordance with the agreement between the Controller and the employer. Only service-related information is entered into the Platform for the purpose of creating an account: a unique user account code, accommodation facility, shift schedule, meal allowance parameters and similar information required for the operation of the relevant Platform modules.
Information that would allow the employee to be identified (first name, last name, passport or other identification data, contact details) is not provided to the Controller by the employer and is not requested, recorded or processed by the Controller. All user actions within the Platform are performed under the account code; information about such actions is generated, stored and processed in a pseudonymised form that does not constitute personal data within the meaning of Art. 1 PDPL, provided it does not allow identification of the user.
2.3. Scenario 2: self (voluntary) registration.
Self-registration is carried out by completing the registration form in the mobile application. Upon self-registration, the Controller collects and subsequently processes the following categories of personal data: first name; last name; email address; telephone number; name of the user's employer organisation.
Processing of such personal data is based on the consent of the data subject (Art. 4, 6 PDPL), expressed by way of affirmative action: ticking the acceptance box for this Policy and pressing the registration confirmation button. Personal data under this clause are processed solely for the purposes set out in Section 4 and may not be processed for other purposes without separate consent.
2.4. The applicable scenario for each user is determined automatically based on the manner in which the account was created. A user whose account was created by the employer cannot independently supplement it with the personal data listed in clause 2.3, except by contacting the Controller in accordance with Section 8.
3.1. In the course of using the Platform, the following data about user actions are generated and processed: content of service requests, feedback submissions, survey and questionnaire responses, meal orders, service bookings, loyalty points accruals and redemptions. Such data is generated in a pseudonymised form and is linked to the user account, which contains no identification data (Scenario 1) or contains only the data listed in clause 2.3 (Scenario 2).
3.2. The Controller does not process the following categories of personal data: passport or other identity document data; health data, including meal plan and nutritional information (such information is processed solely in pseudonymised form and is not used to assess health status); biometric data; data revealing racial or ethnic origin, political opinions, religious beliefs; data concerning private life and the emotional-volitional sphere.
3.3. The Platform does not make decisions producing legal effects concerning the data subject or similarly significantly affecting the data subject based solely on automated processing, including profiling (Art. 18 PDPL).
4.1. The personal data listed in clause 2.3 are processed exclusively for the following purposes:
creating and maintaining the user account;
user identification upon login;
sending service notifications related to the operation of the Platform;
enabling the employer to contact the employee in the context of work-related matters.
4.2. Pseudonymised data (clauses 2.2, 3.1) are processed to operate the Platform's modules: accommodation, catering, service requests, notifications, surveys, loyalty programme, and to generate analytics and reporting for the employer and facility operator.
4.3. Processing is carried out on the basis of consent (Scenario 2) or as otherwise permitted under Art. 4 PDPL.
5.1. The Controller does not disclose personal data to third parties, except:
to the user's employer – limited to the data listed in clause 2.3 and only for users of Scenario 2, for the purpose of operating the Platform and work-related communication;
where required by applicable law of the United Arab Emirates (including responses to lawful requests of competent authorities).
5.2. Pseudonymised statistical information may be provided to the employer and facility operator in the form of aggregated reports that do not allow identification of any individual user.
6.1. Personal data of users of Scenario 2 are retained until the data subject withdraws consent or the account is deleted.
6.2. Pseudonymised data of users of Scenario 1 are retained for the term of the agreement between the Controller and the employer and for no more than 5 (five) years following its termination, unless a different period is set by that agreement.
6.3. Upon expiry of the retention period or withdrawal of consent, personal data are deleted or destroyed in accordance with the PDPL, unless a longer retention period is required by law.
7.1. The Controller implements appropriate technical and organisational measures to protect personal data against unauthorised or unlawful access, loss, destruction, damage, alteration or disclosure, including access privilege separation, encryption of data in transit (TLS), logging of user actions, and data backup.
7.2. Access to personal data is restricted to authorised personnel bound by confidentiality obligations.
7.3. In the event of a breach of personal data that results in damage, the Controller will notify the UAE Data Office (the Bureau) in accordance with Art. 9 PDPL and, where the breach is likely to result in a high risk to the data subject, will notify the affected data subjects without undue delay.
8.1. Under the PDPL you have the right to:
obtain confirmation and information as to whether your personal data are being processed and access to them (Art. 13 PDPL);
request rectification or completion of your inaccurate or incomplete personal data (Art. 15 PDPL);
request erasure of your personal data in the cases prescribed by the PDPL (Art. 15 PDPL);
request restriction of processing (Art. 16 PDPL);
object to and stop processing in the cases prescribed by the PDPL (Art. 17 PDPL);
object to decisions based solely on automated processing, including profiling (Art. 18 PDPL);
withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 6 PDPL);
lodge a complaint with the UAE Data Office (Art. 24 PDPL).
8.2. To exercise your rights, send a request to: info@igft.tech. The Controller will respond without undue delay and in any event within the timeframes set by the Executive Regulations to the PDPL.
8.3. Withdrawal of consent results in the inability to continue using the Platform under Scenario 2; accounts under Scenario 1 are not affected, as they contain no personal data.
9.1. The application uses technical storage on the user's mobile device (authorisation tokens, display preferences) to operate the Platform. No collection of IP addresses, geolocation data, device contacts, photographs or other media files occurs without an action initiated by the user.
9.2. Photographs and other materials attached by the user to requests and feedback submissions are used exclusively to handle the relevant submission and are not processed for other purposes.
10.1. The Controller does not transfer personal data outside the United Arab Emirates. Should a need for such transfer arise in the future, it will be carried out only in accordance with Art. 22 and 23 PDPL – to jurisdictions recognised as having an adequate level of protection, or on the basis of the data subject's consent or another lawful basis, with contractual safeguards where required by the Executive Regulations.
11.1. The Controller may amend this Policy from time to time. The current version is published at: https://igft.tech/oncamp/privacy. Material changes will be notified to users via an in-app notice.
11.2. This Policy is governed by the laws of the United Arab Emirates. Any disputes arising from it shall be resolved in accordance with applicable UAE law.