Effective: 22 July 2026 | Version: 2.0 | Supersedes: Version 1.x
KeyFlow Technology Ltd (trading as “KeyFlow”, “we”, “us”, “our”) — DIFC Commercial Licence CL-12435 · Unit GA-00-SZ-01-FX-07, Level 1, Gate Avenue South Zone, DIFC, Dubai, UAE. Data Protection Officer: Abdallah Alshaqra (interim) — privacy@keyflowae.com. Canonical location: keyflowae.com/privacy-policy (linked from all KeyFlow products).
KeyFlow Technology Ltd is a company incorporated in the Dubai International Financial Centre (“DIFC”). We are committed to processing Personal Data in accordance with the DIFC Data Protection Law, DIFC Law No. 5 of 2020 (as amended) (“the DP Law”) and the DIFC Data Protection Regulations. This Policy explains what Personal Data we collect, why we collect it, how we process, store, transfer and protect it, and the rights you have. Capitalised terms not defined here have the meanings given in the DP Law.
This Policy applies from its effective date to all of the following (“the Services”):
The first-generation product DealsFlow was discontinued on 15 July 2026 and held no Personal Data at discontinuation.
This Policy applies to everyone whose Personal Data we process through the Services, wherever in the world you are located: visitors to our website; staff of the real-estate agencies that use our platform (brokers, administrators, finance staff); the agencies' clients — tenants, landlords and property owners, buyers, sellers and prospective clients — including users of the Keys app; signatories to documents executed through the platform; and our business and supplier contacts.
KeyFlow processes Personal Data in two distinct capacities, and your rights are exercised through a different door depending on which applies:
Keys is the client app of the Keyflow platform. If your agency invites you to use it:
The Services are directed at adults engaged in real-estate business and transactions. We do not knowingly collect Personal Data from children, and no part of the Services is designed for or targeted at them.
Wherever possible we obtain identity data from official sources rather than asking you to type it in or upload scans:
Where you are a client or prospective client of a real-estate agency using our platform, the agency may record information about you in the Services (contact details, enquiry details, tenancy or transaction records). The agency is the Controller of that data (Section 1.2) and is responsible for informing you under Articles 29–30 of the DP Law; where required, notice is also given at our first communication with you through the platform.
We do not collect GPS or continuous location data through any of the Services.
We do not intentionally process Special Categories of Personal Data (such as data revealing racial or ethnic origin, beliefs, health or biometric identification data). UAE PASS performs any biometric verification inside its own service; we receive identity attributes only, not biometric data.
We use Personal Data, in each case with a documented lawful basis under Article 10 of the DP Law, to:
Where KeyFlow acts as Processor, we use agency-controlled data only as instructed by the agency and never for our own purposes.
All processing is conducted fairly, lawfully and transparently in accordance with the DP Law. Each processing activity, its purpose and its lawful basis are documented in our Record of Processing Activities, which is maintained under Article 15 of the DP Law and available to the Commissioner of Data Protection.
We do not make any decision based solely on automated processing that produces legal effects concerning you or otherwise significantly affects you. The platform's automations — such as lead-assignment and reminder rules — are deterministic, human-defined rules, and no such automation produces legal or similarly significant effects without human involvement. AI-assisted features are not currently active on the platform; if and when they are activated, they will be introduced only with the controls required by Regulation 10 of the DIFC Data Protection Regulations (including impact assessment, user notices at first use and human review), and this Policy will be updated before their introduction.
Every transfer jurisdiction is declared in our notification to the Commissioner of Data Protection. Any other transfer to a non-adequate jurisdiction would take place only under DIFC-approved safeguards (such as the DIFC Standard Contractual Clauses) or a specific derogation permitted by Article 27.
We keep Personal Data in identifiable form no longer than necessary, under a documented Retention & Erasure Schedule. The key periods:
| Data | Retention |
|---|---|
| Account and identity records | Life of the account; erased (by anonymisation) on account closure or an executed erasure request |
| Sessions and session metadata (IP, user agent) | Hard-deleted 30 days after session expiry |
| Audit log | 7 years (deleted automatically thereafter) |
| Signed contracts and signing events | 15 years from execution (regulated-document horizon) |
| Financial records (invoices, payments, cheques) | Minimum 5 years (UAE VAT), within a 15-year envelope for property-transaction documents |
| Leads and unconverted contacts (agency-controlled) | Default: 2 years after last activity, subject to the agency's instructions |
| Messages (agency-controlled) | Life of the agency–client relationship + 2 years, subject to the agency's instructions |
| Rights-request records | 7 years, as compliance evidence |
When a retention period ends, or the lawful basis for processing lapses, data is securely deleted, anonymised or — where neither is possible (for example, backup snapshots pending expiry) — archived beyond use in accordance with Article 22 of the DP Law. Our standard erasure method is irreversible anonymisation, which removes your identity while preserving the integrity of financial and legal records that the law requires us to keep.
Identity attributes anchored on UAE PASS and Dubai Land Department records are verified at the source. You may ask us — or, for agency-held records, your agency — to correct inaccurate or incomplete data at any time (Section 6.3), and corrections are passed on to recipients of the data where required.
Data you or your agency enter into the platform is visible to authorised users within that agency's workspace under its own access rules. Strict tenant isolation applies: no agency can see another agency's data. The only cross-boundary mechanism is client account linking in Keys, which requires both your UAE PASS-verified initiation and the agency's explicit approval.
We disclose Personal Data to service providers who process it on our documented instructions under written agreements meeting Article 24 of the DP Law:
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Infrastructure — compute, database, document storage, email delivery | Singapore (ap-southeast-1); legacy first-generation file storage in AWS UAE pending consolidation |
| Atlassian | Operational and support tooling | Cloud |
| Microsoft 365 | Corporate email | Cloud |
| Apple | Push-notification delivery | USA (device tokens and notification content only) |
| Lean Technologies | Payment initiation and account information services (currently sandbox/testing only) | UAE/ADGM |
| Meta Platforms | Lead Ads retrieval (where an agency connects its own account); WhatsApp messaging only when activated, with Article 27 safeguards in place first | USA |
UAE PASS / Digital Dubai and the Dubai Land Department are not our service providers. They are independent controllers of their own government services. You interact with UAE PASS directly when you authenticate or sign, under UAE PASS's own terms and privacy notice; we interface with the Dubai Land Department as a public authority under the procedure below.
Where a public authority requests disclosure of Personal Data, we follow a mandatory procedure aligned with Article 28 of the DP Law: every request is verified for identity and legal basis, assessed for proportionality, narrowed to the minimum data necessary, disclosed only with written confidentiality assurances where practicable, recorded, and — where the data is agency-controlled — notified to the agency unless the law prohibits it. Where the validity of a request is in doubt, we may consult the Commissioner of Data Protection before responding.
We may disclose Personal Data where required by Applicable Law (including fraud prevention), or in connection with a corporate transaction such as a merger or acquisition — in which case confidentiality protections apply and you will be notified where the law requires. We do not sell Personal Data, and we have no corporate group with which data is shared.
Marketing communications are sent only with your prior opt-in consent, which is never pre-ticked. You may withdraw consent at any time — via the unsubscribe link in any marketing message, your account settings, or by contacting us — and withdrawal is as easy as giving consent was. Transactional and service messages (for example, signing requests and payment notices) are not marketing and continue while you use the Services.
Under Articles 32–40 of the DP Law you have the right, at any time and for any reason, to:
Some records cannot be erased on request, and the DP Law requires us to tell you this clearly:
In each case, when your erasure request is executed you disappear from all live, operational systems by irreversible anonymisation; what remains is a sealed historical record kept solely as legal evidence, protected by the same security as live data, used for no decision about you, and deleted when its statutory period ends. Any partial refusal of an erasure request is given to you in writing with its legal ground.
Where your request concerns records controlled by a real-estate agency (Section 1.2), the agency is responsible for the decision and we assist it: we will route your request to the agency without undue delay, and the platform provides the agency with the tools to respond within the statutory deadline. You may also approach the agency directly.
Use any of the contact methods in the Contact Us section below, or the self-service request workflow in the Keys app. Requests made through any channel are honoured.
We protect Personal Data from the point of collection to the point of destruction with technical and organisational measures that include:
No transmission or storage system can be guaranteed 100% secure. While we apply the safeguards above and review them continuously, we cannot guarantee absolute security; you can help by keeping your UAE PASS credentials and devices secure and by telling us immediately at privacy@keyflowae.com if you suspect any misuse of your data or account.
Cookies are small files placed on your device by a website. Consistent with the DP Law's data-minimisation requirements, the Services collect the bare minimum necessary:
keyflow_cookie_consent).You can also control cookies through your browser settings, including deleting existing cookies and blocking new ones; blocking essential cookies will prevent parts of the Services from working. General guidance on cookies is available at aboutcookies.org.
The Services may contain links to third-party websites and services (for example, UAE PASS, government portals or an agency's own website). This Policy does not apply to those third parties, and we are not responsible for their content or privacy practices. Review the privacy notice of any third-party service before providing Personal Data to it.
We may update this Policy from time to time. The current version, with its effective date, is always published at keyflowae.com/privacy-policy, and every KeyFlow product links to it. If we make significant changes — including any change to the purposes of processing, the jurisdictions data is transferred to, or the introduction of AI-assisted features under Section 4.2 — we will give notice through the Services (website notice, in-app notice or email) before the change takes effect. This version 2.0, effective 22 July 2026, replaces all previous versions, including those published under a superseded domain.
You can contact us about this Policy, our processing of your Personal Data, or to exercise any of your rights, through any of the following methods (the DP Law requires us to offer at least two — we offer three):
Data Protection Officer (appointed under Article 16 of the DP Law): Abdallah Alshaqra (interim DPO) — privacy@keyflowae.com.
If you are not satisfied with our response, or wish to raise a concern directly, you have the right to lodge a complaint at any time with the Commissioner of Data Protection:
Commissioner of Data Protection
Dubai International Financial Centre Authority
Level 14, The Gate Building, DIFC, Dubai, UAE
Telephone: +971 4 362 2222
Email: commissioner@dp.difc.ae
KeyFlow Technology Ltd — Privacy Policy version 2.0, effective 22 July 2026. Read together with the Terms of Service at keyflowae.com/terms-of-service and the Data Processing Addendum at keyflowae.com/dpa.