Privacy Policy | Codelabs
Image
Image

Last updated: 19 July 2026

  • 1. Who we are

    CodeLabs LLC is a limited liability company licensed by Sharjah Media City Free Zone Authority (SHAMS) under trade licence number 2541506.01 and formation number 2541506, with its registered office at Sharjah Media City, Sharjah, United Arab Emirates (“Codelabs,” “we,” “us” or “our”).

    This Privacy Policy explains how we collect, use, disclose, store and protect personal data when we determine the purposes and means of processing. In that context, CodeLabs LLC is the controller of the personal data.

    Our privacy contact is:

    CodeLabs LLC
    Sharjah Media City, Sharjah, United Arab Emirates
    Email: [email protected]
    Telephone: +971 52 668 4165

  • 2. Scope of this Policy

    This Policy applies to personal data processed by Codelabs as controller in connection with:

    • codelabs.ae and webpages that link to this Policy (the “Website”);
    • inquiries, proposals, sales, contracts and client-relationship management;
    • events, demonstrations, surveys, newsletters and marketing;
    • supplier, partner and professional-adviser relationships;
    • recruitment and job applications; and
    • security, compliance, dispute management and business administration.

    This Policy does not replace a client's privacy notice. When Codelabs hosts, develops, supports or otherwise processes personal data only on a client's documented instructions, the client normally acts as controller and Codelabs acts as processor. In that situation, the client's privacy notice explains the processing, Codelabs processes the data under the applicable services agreement and Data Processing Addendum, and a rights request concerning that client-controlled data should normally be directed to the client — we will assist the client as required by contract and applicable law.

    An SOW, product-specific notice, applicant notice, Cookie Notice or just-in-time notice may provide additional information. If it conflicts with this general Policy for the specific processing it describes, the more specific notice applies.

  • 3. Personal data

    Personal data means information relating to an identified or identifiable natural person. It may include identifiers and information derived from or linked to them. Sensitive personal data may include biometric, health, genetic, criminal-record, religious, political, ethnic-origin, family and other specially protected information under applicable law.

    Anonymous information that cannot reasonably be linked to an identifiable person is not personal data. Aggregated or de-identified data will be treated as personal data if we retain the ability or means to re-identify it.

  • 4. Personal data we collect

    Depending on the relationship and service, we may collect the following categories:

    • Identity and contact information: Name, business title, employer, username, postal or business address, email address, telephone number, country, preferred language and communication preferences.
    • Inquiry, communication and relationship information: Contact-form content, emails, chat messages, meeting notes, call details, survey responses, support requests, complaints, feedback, proposal history and records of our relationship.
    • Commercial and transaction information: Services requested or purchased, SOW and contract details, billing contact, invoices, payment status, tax and accounting records, procurement information and business due-diligence records. Payment-card details are generally processed directly by the relevant payment provider and should not be sent through ordinary email or contact forms.
    • Account, authentication and security information: Account identifiers, role and permission information, authentication events, login history, security logs, fraud indicators and access-control records. We do not ask you to disclose passwords through ordinary email or Website forms.
    • Device, network and Website information: IP address, browser and device type, operating system, referring page, requested pages, timestamps, approximate location derived from IP, diagnostic events, consent choices and similar technical information.
    • Cookies and similar technologies: Cookie identifiers, pixels, tags, local identifiers and information about how the Website and communications are used. The specific tools, providers, purposes and durations are described in our Cookie Notice and preference centre.
    • Marketing information: Newsletter subscriptions, campaign engagement, event attendance, areas of interest, marketing source, opt-in records and opt-out or suppression records.
    • Recruitment information: CV or resume, work history, qualifications, portfolio, professional profiles, interview notes, references, right-to-work information and other information voluntarily supplied for recruitment. Government identification, background checks or sensitive data will be requested only when necessary and lawful.
    • Project and service information: Business requirements, system information, test data, project communications, authorised-user details, support logs and credentials or access information provided for a project. Where this information is controlled by a client, Codelabs processes it as processor rather than under its own purposes.
    • Images, video, voice, location and biometric information: Codelabs may encounter images, video, audio, vehicle or device identifiers, location data or biometric templates in a client project involving video analytics, IoT, communications or access systems. Codelabs does not process this data for its own unrelated purposes. Where Codelabs acts as processor, the client is responsible for establishing a lawful basis, providing required notices, applying access and retention controls, and obtaining any required consent or regulatory approval.
    • Sensitive personal data: Please do not submit sensitive personal data through a general inquiry, live-chat or marketing form. We process sensitive personal data only where necessary, specifically authorised and supported by an appropriate lawful basis and safeguards.
  • 5. Sources of personal data

    We may obtain personal data:

    • directly from you;
    • from your employer, organisation, representative or colleagues;
    • from a client that authorises you to use a service;
    • automatically through the Website, communications and security systems;
    • from service providers, business partners and event organisers;
    • from public professional profiles, company websites, public registers and other lawfully available sources; and
    • from authorities or advisers where permitted or required by law.

    If you provide personal data about another person, you must be authorised to do so and must provide any notice or obtain any consent required by law.

  • 6. Why and on what basis we process personal data

    We process personal data only for specified, clear and lawful purposes and limit it to what is reasonably necessary. Depending on the circumstances and applicable law, processing is based on consent or on another lawful ground, including the necessity to take requested pre-contract steps, perform a contract, comply with legal obligations, protect a person's interests, establish or defend legal rights, or another ground permitted by law.

    PurposeTypical dataLawful ground, as applicable
    Respond to inquiries, arrange meetings and prepare proposalsIdentity, contact, inquiry and relationship dataConsent; requested pre-contract steps; contract
    Enter into and manage client, supplier and partner relationshipsIdentity, contact, commercial, transaction and communication dataContract; legal obligations; consent where required
    Deliver, secure and support servicesAccount, project, device, log and support dataContract; client instructions where we are processor; legal obligations; protection of rights and security
    Operate, diagnose and secure the Website and systemsDevice, network, security and essential-cookie dataNecessary service operation; legal obligations; protection of rights, systems and users; consent where required
    Measure Website and campaign performanceCookie, device, usage and marketing dataConsent where required; another lawful ground where applicable
    Send newsletters, event invitations and service marketingContact, preference and engagement dataConsent or another direct-marketing basis permitted by applicable law; subject to the right to opt out
    Maintain business, accounting, tax and audit recordsContract, invoice, transaction and communication dataLegal obligations; contract; establishment or defence of rights
    Prevent fraud, misuse and unlawful conductIdentity, account, device, network, security and relationship dataLegal obligations; protection of public or private rights and security as permitted by law
    Manage disputes and comply with authoritiesRelevant records, communications and transaction dataLegal obligations; judicial or security procedures; establishment, exercise or defence of rights
    Assess job applicants and manage recruitmentIdentity, contact, CV, portfolio and interview dataRequested pre-contract steps; consent where required; employment-related legal grounds
    Plan, analyse and improve our business and servicesRelationship, service, usage and feedback dataConsent where required; de-identified or aggregated analysis; another lawful ground where applicable

    Where processing is based on consent, consent will be requested in a specific, clear and unambiguous manner where required. Consent may be withdrawn as described in Clause 15, without affecting processing already lawfully performed.

    We will not use personal data for a materially incompatible new purpose without providing further information and, where required, obtaining consent.

  • 7. When information is required

    Some information is necessary to respond to an inquiry, enter into a contract, create an account, provide a service, issue a compliant invoice or meet legal requirements. If required information is not provided, we may be unable to proceed. Fields that are optional are identified as such where practicable.

  • 8. Cookies and similar technologies

    The Website may use:

    • strictly necessary technologies for security, network management, form submission, consent storage and core functions;
    • functional technologies that remember choices or enable optional features;
    • analytics technologies that help measure visits and performance; and
    • advertising or social-media technologies if enabled to measure campaigns or provide embedded content.

    Non-essential technologies are used only in accordance with applicable consent requirements. Where a preference centre is available, you can accept, reject or change optional categories. Browser controls may block technologies, but blocking strictly necessary items may prevent parts of the Website from working.

  • 9. Marketing communications

    We may send service information, newsletters or event invitations where permitted by law. Marketing messages provide an unsubscribe method. You may also opt out by emailing [email protected].

    An opt-out stops the relevant marketing but does not stop necessary service, security, billing, legal or transactional messages. We may retain limited suppression information so that we can honour the opt-out.

    We do not use client-controlled project data for Codelabs' own marketing unless the controller has lawfully authorised that use and affected individuals have received any required notice.

  • 10. How we disclose personal data

    We may disclose personal data only where reasonably necessary and lawful to:

    • personnel and controlled affiliates who need it for their duties;
    • cloud hosting, infrastructure, communications, email, CRM, analytics, security, anti-spam, live-chat, support and collaboration providers;
    • payment, accounting, audit, insurance and business-administration providers;
    • subcontractors and professional advisers bound by appropriate confidentiality and data-protection duties;
    • a client, supplier, partner or platform where necessary for the requested service or transaction;
    • courts, regulators, law-enforcement, tax and government authorities where required or lawfully requested;
    • a prospective purchaser, investor, lender or transaction adviser in connection with a merger, financing, restructuring or sale, subject to appropriate safeguards; and
    • another person at your direction or with your consent.

    We require processors to provide appropriate data-protection and security commitments. They may process personal data only for authorised services, except where they independently determine purposes under law.

  • 11. No sale of personal data

    Codelabs does not sell personal data for monetary consideration. We do not permit service providers to use inquiry or client-relationship information for their own unrelated marketing.

    Some privacy laws define “sale,” “sharing” or targeted advertising more broadly than an exchange for money. Where such law applies and advertising or cross-context behavioural technologies are enabled, our Cookie Notice and preference centre will provide the required disclosure and choice.

  • 12. International processing and transfers

    Codelabs is established in the UAE, but our service providers, personnel, clients and technical infrastructure may be located in other countries. Personal data may therefore be accessed, hosted or processed outside the UAE, including in countries with different data-protection laws.

    Before a restricted transfer, we use a mechanism permitted by applicable law. Depending on the destination and circumstances, this may include:

    • transfer to a country recognised as providing an adequate level of protection;
    • a written agreement requiring appropriate privacy, security and data-subject protections;
    • explicit consent where legally valid and appropriate;
    • necessity for a contract, legal claim or another statutory exception; or
    • another measure approved by the competent authority.

    We assess the nature of the data, processing purpose, destination, recipient and available technical and contractual safeguards. You may request information about safeguards relevant to your personal data, subject to confidentiality and security restrictions.

  • 13. Retention

    We retain personal data only while reasonably necessary for the relevant purpose and thereafter where required for law, audit, tax, accounting, security, insurance, dispute management or legal claims. We consider the amount, nature, sensitivity, risk, purpose, relationship, applicable limitation periods and legal retention duties.

    Our typical target periods are:

    RecordTypical target period
    Unsuccessful general inquiryUp to 24 months after the last substantive interaction
    Client and supplier contracts, key approvals and project business recordsContract term and normally 7 years after it ends, or longer where law or a dispute requires
    Invoices, tax and accounting recordsPeriod required by applicable tax, accounting and commercial law, normally at least 7 years where applicable
    Website and security logsNormally up to 12 months, unless required for an active security event or claim
    Marketing recordsUntil opt-out, invalidity or prolonged inactivity; limited suppression data may be retained to honour the opt-out
    Recruitment records for an unsuccessful applicantNormally up to 12 months after the process, unless consent or law supports a different period
    Client-controlled project dataThe SOW, Data Processing Addendum and documented client instructions; backup deletion may follow a defined cycle
    Cookie and consent recordsThe duration stated in the Cookie Notice and as needed to demonstrate and respect choices

    These are target periods, not promises to retain every record for the maximum period. Data may be deleted earlier when no longer needed, or retained longer where a legal hold, investigation, unpaid account, complaint or claim applies. At the end of retention, data is deleted, securely destroyed or irreversibly anonymised.

  • 14. Security

    We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Depending on risk and scope, measures may include:

    • access controls, least-privilege permissions and authentication safeguards;
    • encryption or pseudonymisation where appropriate;
    • secure development, change management, logging and monitoring;
    • backups, recovery and availability measures where included in the relevant service;
    • vendor and subcontractor due diligence;
    • confidentiality duties and personnel awareness;
    • vulnerability, incident-response and continuity procedures; and
    • periodic review of relevant controls.

    No internet transmission or storage system is completely secure. You are responsible for using secure channels made available to you, safeguarding credentials, applying available security updates and notifying us promptly of suspected misuse.

    If a personal-data breach occurs, we will investigate, mitigate and notify the competent authority, affected controller or affected individuals where and within the period required by applicable law. Notification is based on the nature, impact and legal requirements of the event.

  • 15. Your privacy rights

    Subject to applicable law, identity verification and lawful exceptions, you may have the right to:

    • receive information about the types of personal data processed, purposes, recipients, retention criteria, safeguards and breach response;
    • request access to or a copy of personal data;
    • receive qualifying data in a structured and machine-readable format and request technically feasible transfer to another controller;
    • correct inaccurate data or complete incomplete data;
    • request erasure when the data is no longer required, consent is withdrawn, a valid objection applies or processing is unlawful;
    • restrict processing in qualifying circumstances;
    • object to and stop processing for direct marketing, related profiling, certain statistical surveys or unlawful processing;
    • withdraw consent at any time where processing is based on consent;
    • object to qualifying solely automated decisions and request human review; and
    • submit a complaint to the UAE Data Office or another competent data-protection authority.

    Rights are not absolute. A request may be limited or refused where permitted by law, including to protect another person's rights, information security, legal privilege, investigations, judicial procedures, legal retention duties or the establishment and defence of claims.

  • 16. How to exercise your rights

    Send a request to [email protected] with the subject “Privacy Request.” Please describe your relationship with Codelabs, the right you wish to exercise and enough information to locate the relevant records.

    We may request proportionate information to verify identity and authority. Do not send passports, Emirates ID documents or other sensitive identification by ordinary email unless we specifically request an approved secure method. An authorised agent may submit a request where permitted, but we may verify the agent's authority and the individual's identity.

    We will respond within the period required by applicable law. We generally do not charge for a valid request, but may charge or refuse where applicable law permits this for manifestly unfounded, excessive or repetitive requests. If Codelabs processes the data solely for a client, we may direct the request to that client or notify the client so it can respond.

    You may first raise a concern with us so we can investigate. This does not limit your right to complain to the UAE Data Office or another competent authority.

  • 17. Automated processing and AI

    Codelabs may use automation to route inquiries, detect spam, protect systems, assist support or analyse service performance. We do not use Website inquiry data to make solely automated decisions that produce legal or similarly significant effects on individuals unless the specific processing is separately disclosed and lawfully authorised.

    AI-assisted outputs may be probabilistic and are subject to appropriate human review for material decisions. We do not use client Confidential Information or client personal data to train a general-purpose AI model unless the relevant controller expressly authorises that use in writing and all required notices, grounds and safeguards are in place.

    For client video analytics, profiling or other automated systems, the client normally determines the purpose and deployment and is responsible for required impact assessments, notices, lawful grounds, human review and objection mechanisms. Codelabs provides contractual and technical assistance within the agreed scope.

  • 18. Children

    The general Website and sales channels are intended for adults and business representatives. We do not knowingly solicit personal data directly from children through general inquiry or marketing forms. If you believe a child has submitted data without appropriate authorisation, contact us so we can investigate and take appropriate action.

    Where Codelabs provides technology to an education or child-focused client, that client normally acts as controller and must establish the lawful basis, notices, consent or guardian authorisation and age-appropriate safeguards. Codelabs processes the data only under the applicable agreement and documented instructions.

  • 19. Third-party websites and services

    The Website may link to third-party websites, social networks, app stores or services. Their privacy practices are controlled by their respective operators. Review their notices before providing personal data. A link does not mean Codelabs controls or endorses the third party's privacy practices.

  • 20. Changes to this Policy

    We may update this Policy to reflect changes in law, services, vendors or processing. The updated version will be posted with a revised “Last updated” date. Where a change materially affects existing processing or consent, we will provide additional notice or request new consent where required. A new policy will not retroactively make previously unlawful processing lawful.

  • 21. Contact and complaints

    Questions, requests and complaints may be sent to:

    CodeLabs LLC
    Trade licence: 2541506.01; formation number: 2541506
    Licensed by: Sharjah Media City Free Zone Authority (SHAMS)
    Registered office: Sharjah Media City, Sharjah, United Arab Emirates
    Email: [email protected]
    Telephone: +971 52 668 4165

    You may also complain to the UAE Data Office or another competent authority where applicable. Please consult the relevant authority's official channel for current submission procedures.