01Site Operator and privacy responsibility
The Site Operator is Marcin Działowski, established in Poland at ul. Dziewanny 25/2, 20-539 Lublin, Poland. Privacy questions and data-rights requests can be sent to support@mylegaldocsai.ae. Where Federal Decree-Law No. 45 of 2021 or a special-jurisdiction privacy regime applies, the statutory role and duties control regardless of the contractual label.
02Data categories
- contact, order and account information
- matter descriptions, uploaded files, scans, images and file metadata
- payment status, transaction identifiers and anti-fraud indicators
- generated drafts, revision instructions, complaint and recovery records
- technical logs, security events, device/browser information and public-site analytics when configured
03Purposes
Data is used to identify the requested document, prepare and deliver the Draft, process or verify payment, provide support, recover failed orders, handle revisions and complaints, prevent abuse, secure the Service, maintain accounting records and comply with legal obligations. Customer matter data is not sold to advertisers and is not used to build advertising profiles. Public-page analytics or advertising technologies are kept separate from confidential order materials and are activated only subject to applicable consent and platform requirements.
04Federal UAE data framework
Where Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data applies, processing is handled with regard to lawful processing, purpose limitation, minimisation, accuracy, security, data-subject rights and applicable transfer requirements.
05DIFC, ADGM and sector regimes
DIFC, ADGM and sector-specific privacy regimes can apply separately and are not assumed to be identical to the federal framework. The applicable regime depends on the relevant establishment, processing activity, location and subject matter.
06AI and processors
Necessary portions of Customer Materials may be transmitted to contracted hosting, AI, document-processing, email, analytics, payment and security providers acting under their own or contractual data-protection obligations. The Service is designed to send only data reasonably required for the relevant processing step.
07International transfers
Because the Service uses international cloud and technology providers, data may be processed outside the UAE. Transfers are handled subject to the applicable legal mechanism and safeguards required by the governing data-protection regime.
08Payment data
Payment-card data is handled by the payment provider. The operator does not intentionally store the complete card number or card security code. The Service stores only the transaction information reasonably needed for order status, accounting, fraud prevention, refunds and dispute handling.
09Retention
Matter files and operational records are kept only for periods reasonably necessary for fulfilment, revision, technical recovery, complaints, security, fraud prevention, accounting and legal obligations. Different categories may have different retention periods. Data may be deleted, anonymised or archived when no longer required.
10Security
Reasonable technical and organisational measures include access controls, logging, restricted secrets, encrypted transport, backups, incident handling and provider controls. No internet system can guarantee absolute security. Customers should not upload unnecessary passwords, full payment credentials or unrelated confidential records.
11Customer rights
Depending on the applicable regime, a person may have rights of access, correction, deletion, restriction, objection, portability, withdrawal of consent where consent is relied upon, or complaint to a competent authority. Rights can be subject to statutory exceptions and identity verification.
12Children and highly sensitive data
The Service is not designed for children to place paid legal-document orders independently. If a matter necessarily concerns a child or other sensitive category, only information required for the requested document should be provided and the adult Customer must have a lawful basis to provide it.
13Analytics and cookies
Public-site analytics and security technologies may be used when configured to understand reliability, traffic, abuse and conversion. The Service does not sell Customer legal-matter data for advertising. Cookie or consent controls are applied where legally required.
14Incident handling
If a personal-data incident occurs, the operator will assess scope, containment, recovery and any notification duty under the applicable regime. Affected Customers may be contacted where notification is legally required or materially useful for protection.
15Contact and complaints
Privacy questions and rights requests: support@mylegaldocsai.ae. Service complaints: support@mylegaldocsai.ae. A request should identify the relevant order or email address where necessary to locate records, but should not include unnecessary additional sensitive data.