Effective: 22 February 2026 | Version: 1.2
Keyflow Technology Ltd (“Keyflow”, “we”, “us”, or “our”) values your security and privacy. Keyflow is a company registered in the Dubai International Financial Centre (DIFC License No. CL-12435, Reference SR-661431) and is required to comply with the DIFC Data Protection Law, DIFC Law No. 5 of 2020 (the “DP Law”), the DIFC Data Protection Regulations 2020, and may, for certain types of personal data processing, be subject to laws from other jurisdictions including UAE Federal Decree-Law No. 45 of 2021 (the “Federal Data Protection Law”) and the EU General Data Protection Regulation (GDPR) where applicable.
It is the policy of Keyflow to respect the privacy of its users across all products and services. In accordance with the DP Law and, as applicable, our Terms of Service (TOS-2026-001), Keyflow collects information about you when you use or access our products and services, including:
(collectively, the “Services”), as well as through other interactions and communications you have with us.
This data protection policy (the “Policy”) sets out the basis on which any information, including any personal data, we collect from you, or you provide to us, will be processed by Keyflow. Each time you access or use the Services or provide us with information, by doing so you acknowledge the practices described in this Policy. For use of specific services, you may be asked to provide your affirmative opt-in consent to our use of the information you submit. Your rights described herein apply in these instances as well.
This Policy applies to persons anywhere in the world who access or use any of Keyflow's Services (“Users”), including but not limited to:
This is personal data you give us by providing information or filling in forms on our Services, or by corresponding with us (for example, by telephone, email, WhatsApp, or any other digital or electronic form). It includes information you provide when you register for an account, create or manage lease contracts, submit lead inquiries, communicate through Connect, or report a problem with any of our Services.
The personal data you give us may include the following categories:
Identity and Contact Data:
Property and Lease Data:
Financial Data:
Lead and Inquiry Data:
Communication Data (Connect):
Photographs and Profile Pictures:
Staff and Agent Data:
Each time you use our Services we may automatically collect the following information:
We receive personal data from third-party services that integrate with our platform:
Keyflow does not process special categories of personal data as defined in Article 9 of the DP Law.
Clarification on Face Detection: We use AWS Rekognition (DetectFaces API) within LeaseFlow to detect and crop the facial region from Emirates ID photographs for use as client profile pictures. This is standard image processing for photo extraction — it does NOT constitute biometric data processing under Article 9 because:
We do not process data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, data concerning health, or data concerning a person's sex life or sexual orientation.
Children's Data: Our Services are not targeted at, intended for, or expected to be of use to children under the age of 18. We do not knowingly collect personal data from children.
Keyflow operates a business-to-business-to-consumer (B2B2C) model:
We use personal data which you provide to us or we collect from you for the following purposes:
The following processing activities are conducted only with your explicit consent, which you may withdraw at any time:
Keyflow uses artificial intelligence services provided by AWS to enhance the Services:
None of these AI services make automated decisions with legal effects on data subjects. AI assists real estate agents in their work — all significant decisions are made by human operators.
Your personal data is primarily stored in the AWS Middle East (UAE) region (me-central-1), which is the local AWS region in the UAE. This includes our databases (AWS RDS PostgreSQL), file storage (AWS S3), and application hosting (AWS ECS Fargate).
In order to conduct our operations, we transfer personal data to processors outside the DIFC:
| Processor | Location | Purpose | Safeguards |
|---|---|---|---|
| Amazon Web Services (AWS) | UAE (me-central-1) primary; certain services may route through US/global endpoints | Infrastructure, database, storage, email, AI processing, OCR, face detection | AWS Data Processing Addendum with Standard Contractual Clauses |
| Meta Platforms (WhatsApp Business API) | US/EU | WhatsApp messaging (Connect only) | Meta Data Processing Terms with Standard Contractual Clauses |
Neither the United States nor the UAE (outside DIFC) currently holds a DIFC adequacy designation. Accordingly, we rely on Standard Contractual Clauses (SCCs) incorporated into our Data Processing Agreements with each processor, as permitted under Article 27(1) of the DP Law.
We take appropriate security measures to protect your personal data in connection with all international transfers, in accordance with the DP Law and this Policy.
Keyflow does not rely solely on automated decision-making when processing your personal data. While we use AI tools to assist with document analysis, OCR, and profile photo extraction, all consequential decisions are made or reviewed by human operators.
Your personal data may be shared across Keyflow products (LeaseFlow, LeadsFlow, Connect) to provide integrated services. For example, a contact's information may be linked across LeadsFlow and Connect to enable unified communications. This sharing is governed by your agency's configuration and is necessary for the performance of the services you have requested.
We share personal data with the following categories of processors who assist us in delivering the Services:
All processors are bound by Data Processing Agreements that require them to process data only on our instructions, maintain appropriate security measures, and comply with applicable data protection laws.
Real estate agencies using our Services may configure integrations that share data with:
We may share personal data:
In some circumstances we may be legally obliged to share information with public authorities or law enforcement. In any such scenario, we will satisfy ourselves that we have a lawful basis on which to share the information and document our decision-making process.
We retain personal data for the following periods:
| Data Category | Retention Period | Basis |
|---|---|---|
| Audit logs | 7 years minimum from creation | DIFC regulatory requirement |
| Consent records | 7 years from consent date | DIFC accountability requirement (Article 14) |
| Lease and property data | Duration of agency subscription + 7 years | Legal obligation (RERA, Ejari) and audit retention |
| Lead data | Duration of agency subscription + 30 days | Contractual necessity |
| Communication data (messages) | Duration of agency subscription + 7 years | Audit trail requirement |
| User accounts | Duration of subscription + 30 days grace period | Contractual necessity |
| Profile photos (extracted from Emirates ID) | Duration of agency subscription + 7 years | Retained with client record |
| Identity document images | Duration of agency subscription + 7 years | Legal obligation (tenant verification records) |
After the applicable retention period, personal data is either securely deleted or anonymized so that no individual can be identified from the remaining data.
We are not responsible for the accuracy of the information you provide, and will modify or update your personal data in our databases when you provide updated information or upon your request, as further outlined below.
Under the DP Law, you have the following rights in respect of your personal data:
| Right | Description | DP Law Reference |
|---|---|---|
| Right of Access | The right to obtain confirmation of whether we process your personal data and to receive a copy of that data | Article 32 |
| Right to Rectification | The right to have inaccurate personal data corrected or incomplete data completed | Article 33 |
| Right to Erasure | The right to have your personal data deleted in certain circumstances | Article 34 |
| Right to Restriction | The right to restrict processing of your personal data in certain circumstances | Article 35 |
| Right to Data Portability | The right to receive your personal data in a structured, commonly used, machine-readable format | Article 36 |
| Right to Object | The right to object to processing based on legitimate interests or for direct marketing | Article 37 |
| Right to Withdraw Consent | Where processing is based on consent, the right to withdraw that consent at any time | Article 10 |
Method 1 — Self-Service (where available):
/dashboard/settings/privacy in LeaseFlow or LeadsFlow)Method 2 — Contact Us Directly:
Any access request is generally free of charge. We will respond within 30 days of receiving your request, unless the DP Law provides otherwise. We may, where permissible, impose a reasonable fee to meet any extraordinary administrative costs.
You have the right to opt out of receiving marketing communications from us at any time. You may:
Please note that we may continue to send you transactional and service-related communications (e.g., lease reminders, payment confirmations, account notifications) even if you opt out of marketing communications, as these are necessary for the performance of the services you have requested.
As set out in Article 39 of the DP Law, we will not discriminate against you for exercising your rights by denying services or changing prices or quality of service.
Keyflow implements appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
Technical Measures:
Organizational Measures:
Sub-Processor Security:
If you have any questions about our security practices, please contact us at privacy@keyflowae.com. To the extent permitted by applicable law, Keyflow expressly disclaims any liability that may arise should any third party obtain personal data through fraud or other means that are no fault of Keyflow.
A cookie is a small text file stored on your device by your web browser, used to retain user preferences and enhance your browsing experience.
Essential Cookies:
Analytics Cookies (with consent):
Communication Cookies:
In accordance with the DP Law, our default privacy settings collect only the minimum necessary cookies to operate the Services. Non-essential cookies require your opt-in consent.
You can manage your cookie preferences through your browser settings. Please refer to your browser's help documentation for instructions on how to modify cookie settings. You may also visit www.aboutcookies.org for general information about cookies and how to manage them.
Altering cookie settings may limit your ability to use certain features of the Services.
The Services may contain links to other websites on the Internet that are owned and operated by third parties (the “External Sites”). These links are provided solely as a convenience to you and not as an endorsement by Keyflow of the contents or reliability of such External Sites.
If you decide to access linked third-party websites, you do so at your own risk. Keyflow does not accept liability, and shall not be liable to you for any loss or damage arising from or as a result of your acting upon the content of another website to which you may link from the Services.
Keyflow may change this Policy from time to time. If we make significant changes in the way we treat your personal data, or to this Policy, we will provide you notice through the Services or by other means, such as email.
Material changes to the purposes for which we process your data may require us to request your re-consent.
Your continued use of the Services after such notice constitutes your acknowledgment of the changes. We encourage you to periodically review this Policy for the latest information on our privacy practices.
This Policy is accessible through:
If you have any questions, comments, or requests related to this Policy, or if you have any complaints related to how Keyflow processes your personal data, please contact us using any of the following methods:
Data Protection Officer
Abdallah Al Shaqra (Interim DPO)
Method 1 — Email: privacy@keyflowae.com
Method 2 — Post: Data Protection Officer, Keyflow Technology Ltd, Level 14, The Gate, Dubai International Financial Centre, P.O. Box 74777, Dubai, United Arab Emirates
Method 3 — Phone: +971 56 754 0655
Method 4 — DPO Direct: privacy@keyflowae.com
If you are not satisfied with our response to your complaint or believe that our processing of your personal data does not comply with the DP Law, you have the right to lodge a complaint with the DIFC Commissioner of Data Protection:
DIFC Commissioner of Data Protection
Dubai International Financial Centre Authority
Level 14, The Gate Building, Dubai, UAE
Phone: +971 4 362 2222
Email: commissioner@dp.difc.ae
Keyflow has appointed a Data Protection Officer in accordance with Article 16 of the DP Law, as Keyflow conducts High Risk Processing involving AI-powered document analysis, OCR of identity documents, and systematic processing of considerable amounts of personal data.
The DPO may be contacted using the details provided in Section 13 above, or directly via email at privacy@keyflowae.com.
The DPO is responsible for:
| Processing Activity | Lawful Basis | DP Law Reference |
|---|---|---|
| Lease contract management | Contract performance | Article 10(1)(b) |
| Tenant data management | Contract performance | Article 10(1)(b) |
| Ejari registration | Legal obligation | Article 10(1)(c) |
| RERA rental index compliance | Legal obligation | Article 10(1)(c) |
| AI lease document analysis (Bedrock) | Legitimate interest | Article 10(1)(f) |
| OCR of identity documents (Textract) | Contract performance | Article 10(1)(b) |
| Profile photo extraction (Rekognition DetectFaces) | Contract performance | Article 10(1)(b) |
| Audit logging | Legal obligation | Article 10(1)(c) |
| Transactional emails | Contract performance | Article 10(1)(b) |
| Marketing communications | Consent | Article 10(1)(a) |
| Processing Activity | Lawful Basis | DP Law Reference |
|---|---|---|
| Lead data management | Contract performance | Article 10(1)(b) |
| Lead distribution to agents | Contract performance | Article 10(1)(b) |
| Lead analytics and conversion tracking | Legitimate interest | Article 10(1)(f) |
| Portal lead ingestion (Bayut, PF, Dubizzle) | Contract performance | Article 10(1)(b) |
| Meta Lead Ads ingestion | Contract performance | Article 10(1)(b) |
| Transactional emails | Contract performance | Article 10(1)(b) |
| Marketing communications | Consent | Article 10(1)(a) |
| Audit logging | Legal obligation | Article 10(1)(c) |
| Processing Activity | Lawful Basis | DP Law Reference |
|---|---|---|
| WhatsApp messaging | Contract performance | Article 10(1)(b) |
| Email communications | Contract performance | Article 10(1)(b) |
| Contact management | Contract performance | Article 10(1)(b) |
| Cross-product contact linking | Legitimate interest | Article 10(1)(f) |
| Message delivery tracking | Contract performance | Article 10(1)(b) |
| Audit logging | Legal obligation | Article 10(1)(c) |
| Processing Activity | Lawful Basis | DP Law Reference |
|---|---|---|
| Contact form submissions | Consent | Article 10(1)(a) |
| Essential cookies | Legitimate interest | Article 10(1)(f) |
| Analytics cookies | Consent | Article 10(1)(a) |
Keyflow uses the following sub-processors as part of its engagement with primary processors:
| Sub-Service | Purpose | Data Processed | Region |
|---|---|---|---|
| RDS (PostgreSQL) | Database hosting | All database records | me-central-1 (UAE) |
| S3 | File storage | Documents, images, uploads | me-central-1 (UAE) |
| SES | Email delivery | Recipient emails, email content | me-central-1 (UAE) |
| SNS | Notifications | Bounce/complaint notifications | me-central-1 (UAE) |
| Bedrock (Claude Haiku) | AI document analysis | Lease documents, property data | us-east-1 (Virginia) |
| Textract | OCR processing | Emirates IDs, contracts | ap-south-1 (Mumbai) |
| Rekognition | Face detection (DetectFaces only) | Emirates ID images for profile photo extraction | ap-south-1 (Mumbai) |
| ECS (Fargate) | Application hosting | All data in-memory during processing | me-central-1 (UAE) |
| CloudFront | CDN | Request/response data in transit | Global edge locations |
| WAF | Security | Request metadata | Global |
| Sub-Service | Purpose | Data Processed | Region |
|---|---|---|---|
| WhatsApp Business API | Messaging | Phone numbers, message content, contact names, delivery status | US/EU |
| Version | Date | Author | Changes |
|---|---|---|---|
| 1.0 | 22 February 2026 | Abdallah Al Shaqra (Interim DPO) | Initial version covering all 4 products |
| 1.1 | 22 February 2026 | Abdallah Al Shaqra (Interim DPO) | Reclassification: Rekognition usage updated from biometric identity verification to profile photo extraction. Removed special category data classification. Added B2B2C data processing model section. Updated lawful bases. |
| 1.2 | 22 February 2026 | Abdallah Al Shaqra (Interim DPO) | Updated “Terms of Use” references to “Terms of Service” (TOS-2026-001) to align with the unified Terms of Service document covering all Keyflow products. |
Review Schedule: Annually at minimum, or when processing activities change materially.
Next review date: 22 February 2027
This Policy was last updated on 22 February 2026.
Keyflow Technology Ltd, DIFC License CL-12435, Unit GA-00-SZ-01-FX-07, Level 1, Gate Avenue - South, DIFC, Dubai, UAE