Skip to main content

UAE PERSONAL DATA PROTECTION LAW

Federal Decree-Law No. 45 of 2021 — ENOVAI Compliance Page

Last updated: 26 March 2026  |  [email protected]

⚠️
This page covers ENOVAI's compliance with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL), in force since 2023. It is intended for ENOVAI clients, their end-users, and any individual located in or resident of the United Arab Emirates. For ENOVAI's full Privacy & Cookie Policy, see enovaigroup.com/cookie-policy/

1. WHAT IS THE UAE PDPL?

The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) is the UAE's first comprehensive federal data protection law. It came into full force in 2023 and is enforced by the UAE Data Office. It establishes rules for how organisations collect, use, store, and transfer personal data of individuals located in the UAE — regardless of where the organisation processing that data is based.

ENOVAI is committed to respecting the rights of UAE residents and complying with the UAE PDPL across all its products and services.

2. HOW ENOVAI HANDLES UAE RESIDENT DATA

2.1 What data we process

When ENOVAI's Platform is used by a merchant whose customers are based in the UAE, the following categories of data may be processed:

  • Conversation data — messages exchanged between the end-user and the ENOVAI chatbot
  • Order and product data — order status, product availability, catalog queries (via Shopify API)
  • Contact information — name, email address (only if voluntarily provided by the end-user)
  • Technical data — session identifiers, timestamps, device type (aggregated, not individually tracked)

ENOVAI does not intentionally collect sensitive personal data as defined under UAE PDPL (financial data beyond transaction references, biometric data, health data, etc.). If you believe sensitive data has been inadvertently shared, contact [email protected] immediately.

ENOVAI processes personal data of UAE residents on the following legal bases:

  • Contractual necessity: to provide the SaaS service subscribed to by our merchant clients
  • Legitimate interests: fraud prevention, security, service improvement
  • Consent: for non-essential cookies and marketing communications, where applicable
  • Legal obligation: where required by applicable law

2.3 Data retention

Conversation data is retained according to the plan subscribed by the merchant:

  • LAUNCH plan : 30 days
  • ACCELERATE plan : 6 months
  • PERFORMANCE plan : 24 months

After expiry of the retention period, data is automatically deleted from ENOVAI systems.

3. CROSS-BORDER DATA TRANSFERS

ENOVAI's infrastructure and sub-processors may be located outside the UAE. Where personal data of UAE residents is transferred internationally, ENOVAI ensures appropriate safeguards are in place :

  • Standard contractual clauses (SCCs) or equivalent contractual protections with receiving entities
  • Transfer only to sub-processors who have accepted binding data protection obligations
  • Where required, explicit consent of the data subject

Our sub-processors include OpenAI (LLM infrastructure, USA), Shopify Inc. (API & billing, Canada/USA), Google Analytics (aggregated analytics, USA), Chatwoot (human handoff), and our cloud hosting provider. All are bound by contractual data protection obligations.

4. YOUR RIGHTS AS A UAE RESIDENT

Under the UAE PDPL, individuals located in or resident of the UAE have the following rights over their personal data:

  • Right to be informed: Know what data we collect, why, and how it is used — before or at the time of collection.
  • Right of access: Request a copy of the personal data ENOVAI holds about you.
  • Right to rectification: Request correction of inaccurate or incomplete personal data without undue delay.
  • Right to erasure: Request deletion of your personal data where there is no legitimate reason for continued processing.
  • Right to restrict processing: Request that ENOVAI ceases or limits processing of your data in certain circumstances.
  • Right to data portability: Receive your personal data in a structured, machine-readable format.
  • Right to object: Object to processing based on legitimate interests, including profiling.

5. HOW TO EXERCISE YOUR RIGHTS

To submit a data rights request, contact us at the address below. We will acknowledge receipt within 5 business days and provide a full response within the legal deadline.

Response deadline : 30 calendar days from receipt of your request, in accordance with Article 17 of the UAE PDPL. If additional time is required, we will notify you within the initial 30-day period.

  • Email: [email protected]
  • Entity: ENOVAI GROUP TEAM — E-NOVAI GROUP SARL
  • Address: 369 rue 017845 Bab Al Madina, Unit F2, Azzouzia, Marrakech, Morocco
  • ICE: 003055000000017

6. RIGHT TO LODGE A COMPLAINT

If you are not satisfied with how ENOVAI has handled your personal data or responded to your request, you have the right to lodge a complaint with the competent supervisory authority:

UAE Data Office — dataoffice.gov.ae

The UAE Data Office is the competent supervisory authority for data protection matters in the United Arab Emirates.

7. ENTERPRISE CLIENTS — UAE PDPL CONTRACTUAL DOCUMENTATION

ENOVAI clients based in the UAE who require specific contractual documentation for their own compliance needs (Data Processing Agreement adapted to UAE PDPL requirements, sub-processor lists, security documentation) can contact our team directly.

[email protected]

We will work with you to provide appropriate documentation upon request.