خصوصية الموقع

سياسة الخصوصية

كيفية تعامل إشيل العقارية مع البيانات الشخصية عند تصفح العقارات أو إرسال استفسار أو الانضمام إلى حملة أو التواصل مع مستشارينا.

تاريخ السريان: 12 August 2026

آخر تحديث: 12 أغسطس 2026

تُنشر النسخة القانونية المعتمدة من هذا المستند باللغة الإنجليزية. تواصل معنا إذا احتجت إلى توضيح أي بند.

1. Overview and controller

This Privacy Policy explains how Eshel Properties L.L.C. collects, uses, discloses, stores, and protects personal data through eshelproperties.com, its localised pages, property listings, maps, contact and campaign forms, careers pages, communications, and connected client services. Eshel Properties L.L.C., Office 303, Empire Heights Tower B, Dubai, United Arab Emirates, generally acts as the controller because it decides why and how website visitor and enquiry information is processed.

The Policy applies to visitors, prospects, buyers, sellers, landlords, tenants, investors, applicants, campaign participants, representatives, and other people whose information enters our public website or client channels. A signed brokerage, property, campaign, recruitment, or service arrangement may include an additional privacy notice for a specific activity. Where another party independently decides how it uses data, that party is a separate controller under its own notice.

2. Our privacy principles

We aim to process personal data lawfully, fairly, and transparently; for clear and legitimate purposes; in a manner that is adequate, relevant, and not excessive; accurately and with reasonable correction processes; for no longer than necessary; and with security appropriate to the risk. Access should be limited to people and providers who need the information for an authorised purpose.

We do not treat public availability as unlimited permission to collect or reuse information. We do not sell visitor or client personal data. We distinguish requested service communication from optional marketing, and we do not describe a required transaction record as voluntary consent. High-risk uses, material new purposes, or new technologies should be assessed before deployment.

3. Personal data we collect

Depending on your interaction, we collect identity and contact data such as name, phone number, email, nationality where requested, preferred language, and professional or company details; property-interest data such as budget, property type, bedrooms, size, furnishing, preferred developer, location, buyer type, payment method, timeline, and selected listing; and communication data such as comments, enquiries, call or message history, meeting details, preferences, complaints, and consent or opt-out records.

For sellers, landlords, buyers, tenants, or transaction clients, we may later collect property ownership or occupancy information, identification, address, signature, source-of-funds or compliance documents, reservation and transaction records, payment references, and professional-adviser details where necessary and lawful. Do not submit sensitive documents through a general form unless requested through an approved secure process.

4. Technical, device, and usage data

When you use the website, servers and integrated services can process IP address, browser and device type, operating system, language, referring and exit pages, timestamps, requested URLs, approximate location derived from IP, network and security events, page interactions, scroll depth, clicks, performance, and diagnostic information. We use this information to deliver pages, protect forms and infrastructure, understand website performance, prevent abuse, and improve user journeys.

Our lead endpoint can record the submitted page URL, path, language, source, submission time, IP address, and approximate city, region, and country from an IP lookup. This helps identify the property or campaign connected with an enquiry, route it appropriately, measure source performance, and detect spam. Approximate IP location is not precise GPS tracking and may be inaccurate, particularly when using mobile networks, corporate gateways, proxies, or VPNs.

5. Sources of information

We receive information directly from you through forms, calls, email, WhatsApp, meetings, downloads, campaign entries, applications, and documents. Information is also generated through your website use and browser preferences. If you enquire about a listing, the website can attach public property and page context so our team understands what you viewed.

We may receive data from property owners, landlords, developers, brokers, portals, PixxiCRM, referral partners, marketing platforms, social networks, public registries, authorities, professional advisers, identity or compliance providers, and people authorised to act for you. We consider the source, purpose, accuracy, and authority before relying on data. If another person gives us your details for a genuine referral or transaction, we will handle them under this Policy and provide notice where required.

6. Why we use personal data

We use personal data to respond to enquiries; identify suitable properties and services; arrange calls, meetings, and viewings; communicate listing changes; support buying, selling, renting, letting, off-plan, campaign, and advisory journeys; prepare or administer requested documents; maintain client and transaction records; coordinate with authorised parties; deliver downloads; process careers interest; and provide customer support.

We also use data to authenticate or validate submissions, prevent duplicate or fraudulent activity, secure the website, troubleshoot, analyse service quality, understand campaigns and sources, train authorised teams, manage complaints, enforce terms, establish or defend claims, comply with real-estate and consumer rules, respond to authorities, and meet legal, accounting, sanctions, anti-money-laundering, recordkeeping, and regulatory obligations where applicable.

8. Forms, PixxiCRM, and lead management

Public forms send validated lead information through our server to PixxiCRM using a Company-controlled integration. Depending on the form, the record can include your contact details, comments, selected property, page context, source, approximate IP location, and structured preferences. Server-side credentials are not exposed to the browser. We use CRM records to allocate advisers, follow up, preserve history, avoid duplicate outreach, understand service status, and document consent or objections.

A form submission is not published. Access should be limited to authorised Eshel personnel and providers supporting the client journey. We expect users and staff to keep notes factual, relevant, and respectful. If you believe a lead was created without permission, provide the relevant phone or email so we can investigate, suppress unauthorised marketing, correct attribution, and determine whether records must be retained for security or legal reasons.

9. Google Ads and Microsoft Clarity

The website uses Google Ads tags to understand advertising interactions and conversions and Microsoft Clarity to understand how visitors use pages through interaction analytics such as clicks, scrolling, navigation, device context, and session-level usability signals. These providers may use cookies or similar identifiers and process technical and usage information under their own terms. Their processing locations can include countries outside the UAE.

Analytics helps us assess campaign effectiveness, find broken journeys, improve page design, and reduce irrelevant advertising. It should not be used to intentionally capture passwords or payment-card details, and visitors should not enter sensitive information into ordinary page elements. Where applicable law requires prior consent for non-essential analytics or advertising storage, those technologies should be controlled by an appropriate consent mechanism. You can also use browser controls and provider opt-out tools, although these may not stop essential server logs.

10. Cookies and browser storage

The website may use cookies, local storage, session storage, and similar technology to remember locale, currency, area unit, listing comparisons, campaign submission or access state, security settings, and other preferences. Essential technology supports requested functionality, security, routing, and continuity. Non-essential technology can support measurement or advertising. Browser storage is device-specific and may persist until expiry or deletion.

You can clear or block storage through browser settings. Doing so can reset preferences, comparisons, campaign state, or locale and may impair functionality. Clearing a local value does not necessarily delete a corresponding server, CRM, campaign, security, or transaction record. A dedicated cookie control, when provided, is the preferred way to manage optional categories without disabling necessary functions.

11. Direct marketing and telemarketing

We may send relevant property or service marketing where you have requested it, consented where required, or where another lawful basis permits. UAE telemarketing rules require controls including authorised Company numbers, identification, permitted calling times, training, call records, Do Not Call Registry screening, and respect for a consumer's choice. Marketing calls may be recorded with notice where required. We do not trade consumer phone data for other companies' telemarketing.

You may opt out of optional marketing by telling the caller, using an unsubscribe method, or contacting [email protected]. We may retain a minimal suppression record so your choice is respected. An opt-out does not prevent necessary messages about an active enquiry, viewing, document, transaction, security issue, or legal obligation. If an independent portal or developer markets to you, exercise choices with that party as well.

12. Sharing within Eshel

Information is shared internally according to responsibility and need. Authorised advisers and managers may access enquiries and property preferences; marketing personnel may access source, consent, suppression, and campaign information; operations may coordinate viewings and documents; finance may handle authorised payment or commission records; IT and security may access technical data; and legal, compliance, or management may handle complaints, investigations, regulatory obligations, and claims.

Internal access does not make information public or available for personal prospecting. Staff must not export client lists to private accounts, use information for an unauthorised competing business, or browse records out of curiosity. Role changes and departures should result in appropriate access review. Reports should use aggregated or minimised data where individual identification is unnecessary.

13. Service providers

We use providers for hosting, content delivery, databases, storage, CRM, email, security, bot prevention, analytics, advertising, maps, communications, forms, media, support, and professional advice. Current website architecture can involve PixxiCRM, Google, Microsoft Clarity, Cloudflare, Supabase, Resend, mapping services, social platforms, WhatsApp, property portals, and other approved providers. The exact provider can change as services evolve.

Providers receive information relevant to their function and should act under appropriate confidentiality, security, and data-processing terms. Some providers independently control data when you use their external service. We review material providers proportionately but cannot control an independent provider's entire platform. Provider names in this Policy describe the current service environment and are not a promise that every provider processes every visitor's data.

14. Owners, developers, portals, and transaction recipients

To progress a requested property journey, we may share relevant information with an owner, landlord, developer, master developer, broker, property portal, building or community manager, mortgage or finance contact, bank, conveyancer, trustee office, valuer, surveyor, insurer, utility provider, registration authority, or other transaction participant. Sharing depends on your request, the stage reached, professional duties, and applicable law.

We aim to disclose only what is reasonably necessary. A viewing may require name and contact details; a reservation or transaction can require identity, compliance, and financial evidence. Recipients can become independent controllers with their own legal obligations. Review their notices and agreements. We do not authorise a recipient to use your data for unrelated marketing merely because it participates in a transaction.

15. Legal disclosures and authorities

We may disclose information where reasonably necessary to comply with UAE or applicable law, a court order, regulatory request, licensing duty, audit, sanctions or anti-money-laundering requirement, consumer complaint, law-enforcement request, or to protect rights, safety, property, transactions, and systems. Relevant authorities can include the UAE Data Office, Dubai Land Department, RERA, telecommunications and consumer authorities, courts, police, and other competent bodies.

We assess requests for authority, scope, and proportionality where permitted. We may preserve information under a legal hold even if ordinary retention would otherwise end. We may also share information with lawyers, auditors, insurers, and professional advisers under duties of confidentiality for advice, disputes, investigations, or claims.

16. International transfers

Website and cloud providers may store, route, or remotely access information outside the UAE. International processing can occur through global analytics, communications, content delivery, security, storage, support, or CRM infrastructure. Before a material cross-border transfer, we seek to identify the recipient and destination, confirm a lawful mechanism, limit data, and use contractual, technical, or organisational safeguards appropriate to risk.

UAE data law provides mechanisms for transfers where an adequate level of protection is available and conditions or exceptions where it is not, including contractual safeguards and other legally recognised grounds. No transfer mechanism eliminates all risk. Contact us for information about the categories of safeguards relevant to your data, subject to confidentiality and security limitations.

17. Retention

We retain personal data for no longer than reasonably necessary for the purpose collected, the client relationship, legal and regulatory duties, transaction evidence, consent and suppression records, security, fraud prevention, accounting, limitation periods, disputes, and claims. Different records have different schedules. An unanswered general enquiry should not be kept as long as a completed property transaction or an active legal file merely because both contain a phone number.

Indicatively, routine web diagnostics may be retained for a short security and operational period; enquiry and CRM records for the active relationship and a reasonable follow-up or claims period; marketing consent and suppression evidence for as long as needed to demonstrate and respect choices; call records for the regulator-prescribed period; transaction, accounting, and compliance records for the applicable statutory and claims periods; and applicant data for the recruitment cycle and a proportionate follow-up period. A legal hold can extend retention. At expiry, data is deleted, anonymised, or made inaccessible according to controlled processes and backup cycles.

18. Security

We use measures intended to preserve confidentiality, integrity, and availability, which may include encrypted connections, server-side secrets, input validation, access controls, private storage, logging, backups, rate limits, bot controls, provider review, staff confidentiality, and incident response. Measures are selected according to the nature and risk of processing. No internet transmission or storage system can be guaranteed completely secure.

Protect yourself by verifying contact accounts and payment instructions, keeping devices and email secure, avoiding public Wi-Fi for sensitive exchanges, and not sending passwords or one-time codes. Tell us promptly if you suspect impersonation, a mistaken disclosure, compromised communication, or a document sent to the wrong recipient. Do not use a general enquiry form for unrequested identity or banking documents.

19. Personal-data incidents

A personal-data incident can include accidental loss, unauthorised access, mistaken email, exposed link, compromised account, unlawful disclosure, alteration, or destruction. We assess reported events, contain access, preserve relevant evidence, determine affected data and people, address the cause, and document decisions. Providers may assist where their systems are involved.

Where applicable law requires notification to the UAE Data Office, another authority, or affected individuals, we will make the notification in the required manner and timeframe based on risk and available facts. A report should be sent promptly to [email protected] with enough detail to investigate, but should not include further unnecessary sensitive data. Do not publicly distribute exposed information.

20. Your privacy rights

Subject to applicable law, verification, and exceptions, you may request information about processing; access to personal data; correction of inaccurate data; deletion; restriction or cessation of processing; objection to certain processing; transfer of data you provided in a structured machine-readable form where applicable; and review of decisions based solely on automated processing. You may withdraw consent for future consent-based processing and complain to the competent authority.

Rights are not absolute. We may retain or withhold information where necessary for legal duties, public interest, security, confidential business information, legal proceedings, another person's rights, or an applicable exemption. We may ask for identity verification and clarification and will explain a lawful refusal. We will not retaliate because you exercise a right in good faith.

21. How to exercise a right

Send a request to [email protected] with the subject Privacy Request, or write to Eshel Properties L.L.C., Office 303, Empire Heights Tower B, Dubai, United Arab Emirates. State the right, the contact details or interaction involved, and enough information to locate relevant records. Do not email a passport copy unless we request a secure verification method.

We will log the request, verify identity proportionately, search relevant systems and providers, consider third-party rights and legal restrictions, and respond within the period required by applicable law. If an opinion or transaction history cannot simply be overwritten, we may preserve the original audit record and add a correction or response. Complaints may also be made to the UAE Data Office or another competent authority where applicable.

22. Profiling and automated processing

We may use structured preferences, listing context, campaign source, CRM status, and website analytics to segment enquiries, prioritise follow-up, match property categories, understand marketing performance, or identify spam. These processes can be partly automated, but they are intended to support service operations rather than make a final legal decision about you without meaningful review.

Property matches, comparison indicators, campaign scores, lead routing, and analytics are based on available data and can be incomplete. You may provide corrected preferences or ask for human review of a material decision based solely on automated processing where applicable law provides that right. We do not use website analytics to determine creditworthiness, immigration eligibility, or legal entitlement.

23. External sites, social media, and portals

Links to WhatsApp, Google Maps, social media, developers, Property Finder, Bayut, Dubizzle, and other external services take you into environments controlled by those providers. They may collect account, device, cookie, location, and interaction data under their own policies. If you contact Eshel through a portal or social network, both that provider and Eshel may process the message for their respective purposes.

Use privacy settings and review the provider's notice before sharing information. Public comments, reviews, or social posts are visible according to the platform's controls. Do not publish identity documents, phone numbers, access codes, or transaction details in a public comment. Eshel cannot delete data held solely by an independent platform, but we can assist with records under our control.

24. Children and information about others

The website and real-estate enquiry services are intended for adults and are not designed to profile or market to children. We do not knowingly request a child's personal data through ordinary property forms. A parent or guardian who believes a child submitted information should contact us so we can investigate and delete it where appropriate, subject to legal preservation.

If you provide information about a co-buyer, spouse, owner, tenant, representative, referee, dependant, or other person, you must have a lawful reason and should tell that person how the information will be used. Provide only what is relevant. We may contact the person to verify authority or give privacy information.

25. Changes, questions, and complaints

We may update this Policy when the website, providers, services, legal requirements, or processing practices change. The current version and date will appear on this page. If a change materially affects how existing data is used, we will provide additional notice or seek consent where required rather than relying only on continued browsing.

Questions, objections, complaints, and requests may be sent to [email protected], +971 4 33 145 33, or Eshel Properties L.L.C., Office 303, Empire Heights Tower B, Dubai, United Arab Emirates. This Policy is informed by UAE Federal Decree by Law No. 45 of 2021 Concerning the Protection of Personal Data, consumer-protection rules, telemarketing rules, and applicable real-estate requirements. The original Arabic legislation prevails where legally relevant.

Appendix A. Detailed website data inventory

Identity and contact records can include name, telephone number, email address, preferred language, country or nationality where requested, company, role, and the identity of a representative. They support response, relationship management, appointment scheduling, document preparation, identity verification, consent and suppression, and transaction administration. The data usually comes from you, a representative, a referral source, a portal, or a transaction participant. Access is generally limited to authorised advisers, operations, managers, compliance functions, and necessary providers.

Property-preference and enquiry records can include listing reference, property type, budget, bedrooms, size, furnishing, preferred developer, community, payment method, buyer or tenant type, purpose, timeline, comments, selected page, comparison choices, and previous contact. They help us understand what you requested, match opportunities, avoid repeatedly asking the same questions, allocate an adviser, and document the history. Preferences can become outdated; tell us when they change or when you no longer wish to be contacted.

Seller, landlord, and property records can include address, ownership or authority evidence, occupancy, tenancy, mortgage, condition, access, price, media, floor plans, permits, service charges, keys, offers, viewing history, and transaction documents. Some data concerns tenants, occupants, co-owners, representatives, or prospective counterparties as well as the instructing client. Collection must remain relevant to the instruction, marketing authority, legal compliance, viewings, negotiation, and transaction execution.

Transaction and compliance records can include passport or identity information, address, signature, work or residency status where relevant, beneficial ownership, source-of-funds evidence, sanctions or risk checks, bank or payment references, reservation, contracts, title, developer forms, trustee or authority records, invoices, commission, and correspondence. These records require restricted access and may be retained for longer statutory, regulatory, accounting, fraud-prevention, and claims periods. General website forms are not the appropriate channel for unsolicited copies.

Communication records can include calls, recording where lawful and notified, email, SMS, WhatsApp, meeting notes, viewing arrangements, complaints, preferences, consent, objections, and unsubscribe events. Communications help deliver the requested service and preserve an accurate history. Staff should record objective, necessary facts rather than speculation. Marketing choices should be attached to the correct contact identity and shared with relevant systems so suppression is consistently respected.

Technical and security records can include IP address, request time, URL, user agent, browser, device, approximate IP-derived geography, referring page, errors, rate-limit events, bot or abuse signals, and server logs. These records support delivery, cybersecurity, diagnostics, form protection, capacity, investigation, and legal claims. Security records may be preserved when associated with an incident even if ordinary diagnostic retention would have ended.

Analytics and advertising records can include identifiers set by Google, Microsoft, or related technologies; campaign, referrer, conversion, page-view, click, scroll, device, and session interaction data; and aggregated reporting. These records help attribute advertising and improve usability. Provider-controlled identifiers and account data are governed by the provider's role and policy. Optional technology should follow applicable consent requirements and user choices.

Browser preference records can include locale, currency, area unit, compare list, saved display choices, and campaign state stored locally. They usually remain on the device rather than in a central Eshel profile, although a campaign submission or server request may create a separate record. Clearing the browser removes local state but does not erase CRM, security, transaction, or campaign information held for a separate purpose.

Campaign and event records can include entry identity, phone, answers, predictions, ticket code, timestamps, verification, scoring, ranking, prize, selection, attendance interest, brochure request, travel or eligibility information, and acceptance of specific rules. The applicable campaign notice and rules determine publication, deadlines, fraud checks, winners, and retention. A public leaderboard should use masking or minimisation where designed and must not be treated as consent for unrelated marketing.

Applicant records can include name, contact details, role interest, LinkedIn link, application responses, CV or portfolio through an approved channel, interview and assessment notes, references, credentials, work authorisation, and recruitment correspondence. Access should be limited to authorised recruitment decision-makers and providers. Applicant records are not mixed into property marketing merely because the same contact details appear in both contexts.

Appendix B. Retention schedule and deletion rules

Essential server, security, and anti-abuse logs should be retained for a short period calibrated to troubleshooting, attack detection, investigation, and infrastructure needs, unless a specific event requires preservation. Analytics platforms apply their configured retention and aggregation settings, which should be reviewed periodically. Raw technical identifiers should not be kept indefinitely merely because aggregated trends remain useful. Aggregation or anonymisation is preferred when individual-level detail is no longer needed.

General enquiries and property preferences are retained while the enquiry is active and for a reasonable follow-up, quality, fraud, and claims period. Dormant leads should be reviewed rather than contacted indefinitely. A person who opts out can still have a minimal suppression record retained to prevent renewed marketing. Duplicate CRM records should be merged or resolved carefully so consent, objections, notes, and transaction history are not misattributed.

Viewing and negotiation records may be retained for the active property journey and a reasonable period afterward to document access, offers, instructions, complaints, broker work, and potential commission or claims. A completed sale, lease, management, or other transaction can require materially longer retention under legal, regulatory, accounting, tax, title, anti-money-laundering, audit, and limitation obligations. The governing agreement and record category, not the mere presence of personal data, determine the schedule.

Marketing-consent evidence should be retained while relied upon and for a period sufficient to demonstrate compliance. Withdrawal and Do Not Call or unsubscribe status should be retained as a suppression record for as long as needed to respect the choice and address complaints. Telemarketing call and reporting records should follow the period specified by the competent authority. Marketing content itself may be archived without recipient-level data where no longer needed.

Campaign entries, competition records, event registrations, and gated-download submissions follow the published rules, administration period, prize or selection process, dispute period, fraud-prevention need, and applicable accounting or regulatory requirements. Public display should end when no longer justified even if a limited internal record remains. Test submissions, invalid entries, and unnecessary duplicates should be removed promptly unless retained as evidence of abuse.

Recruitment records should be retained for the vacancy and a proportionate period for follow-up, future opportunities where permitted, equality or process evidence, and legal claims. Identity or credential copies should not be retained merely because a CV remains relevant. If an applicant is hired, necessary information moves into the appropriate human-resources process under a separate notice; it should not remain indefinitely in an open recruitment folder.

A deletion event should cover the primary system, controlled exports, shared workspaces, provider instructions where applicable, and local copies under Company control. Backups may expire through protected rotation rather than immediate selective deletion, provided deleted data is not restored into active use except for disaster recovery and is removed again. Anonymised information may be retained where re-identification is not reasonably possible.

Legal holds override ordinary deletion for records relevant to a complaint, suspected fraud, regulator request, audit, litigation, payment dispute, or other anticipated claim. The hold should identify scope, owner, reason, start, review, and release. It is not authority to preserve unrelated data. When the hold ends, the ordinary schedule resumes. Retention decisions should be documented so the Company can explain the governing criteria rather than promise one universal period.

Appendix C. Privacy request and complaint procedure

Begin by identifying the person and the request without collecting excessive verification data. A request can concern access, information, correction, deletion, restriction, objection, portability, consent withdrawal, automated processing, marketing, or a complaint. Record the received date, contact channel, scope, identity steps, systems likely involved, deadline, owner, searches, decision, disclosures, response, and follow-up. A request made to an agent should be forwarded promptly to the authorised privacy channel rather than answered from memory.

Search scope depends on the interaction and may include website submissions, PixxiCRM, email, communications, call records, campaign systems, analytics identifiers where reasonably identifiable, property files, transaction records, complaints, security logs, storage, and relevant providers. Local browser preferences generally remain on the requester's own device and may not be linked to an identity. Search terms should include verified contact variations and relevant property or campaign references while avoiding access to unrelated people.

Before disclosure, review documents for another person's personal data, privileged advice, confidential commercial information, security detail, active investigation material, and legal restrictions. Redact or summarise where lawful rather than automatically refusing the entire request. Deliver information through a secure channel suitable for sensitivity. A machine-readable transfer applies only where legal conditions are satisfied and technical feasibility does not adversely affect others.

Correction should address objectively inaccurate or incomplete data. Historical transaction and audit records may need an appended correction rather than silent overwriting. An opinion may be disputed without becoming factually inaccurate; in an appropriate case, preserve the original and add the individual's response. Notify relevant recipients or processors of a correction or deletion where required and practicable.

Deletion is assessed against each purpose and legal ground. Remove data no longer necessary, but preserve what must remain for law, transaction integrity, accounting, suppression, fraud prevention, security, public interest, or claims. Explain the categories retained and the reason where lawful. Restriction may be used while accuracy, objection, or legal claims are assessed. Consent withdrawal applies prospectively and does not invalidate prior lawful processing.

A privacy complaint should be investigated impartially. Identify the processing, people, system, provider, disclosure, harm, and requested remedy; contain ongoing risk; preserve evidence; correct inaccurate data or access; and determine whether an incident assessment or notification is required. Communicate the outcome and escalation route. A person may complain to the UAE Data Office or another competent authority where applicable without first exhausting an internal process if the law permits.

اقرأ السياسة ذات الصلة

الشروط والأحكام