Geidea logo
Solutions
Segments
Merchant storiesResourcesAbout Us

SOLUTIONS

  • All Solutions
  • Payments
    • Payment Terminal
    • Payment Gateway
    • Payment Links
    • Geidea Mobile POS
  • Point of Sale
    • Point of Sale
    • Online ordering
    • Kiosk
    • Kitchen Display
    • Branded App
  • Promotions
    • Promotions & Loyalty
  • Management
  • Hardware

SEGMENTS

  • All Segments
  • Hospitality
  • Retail
  • Events
  • Services

MERCHANT STORIES

  • All Merchant stories

RESOURCES

  • Resources

ABOUT US

  • About Us
|
Contact Us:For general enquiries, feedback, or support:800434332GDMO@geidea.net
Whistleblowing:For confidential reporting of concerns related to misconduct or unethical behaviour:speakup.uae@geidea.net
Address:One Central, Offices 201 & 207,
The Offices 4, Trade Centre, Dubai
Geidea Logo

Geidea Payment LLC is licensed by the Central Bank of the UAE.

©2025 Geidea. All rights reserved

Terms & ConditionsPrivacy PolicyCookie Policy
Geidea Logo
  • All Solutions
  • Payment Terminal
  • Payment Gateway
  • Payment Links
  • Geidea Mobile POS
  • Point of Sale
  • Online ordering
  • Kiosk
  • Kitchen Display
  • Branded App
  • Promotions & Loyalty
  • Management
  • Hardware
  • All Segments
  • Hospitality
  • Retail
  • Events
  • Services
Merchant stories
Resources
About Us
|
Contact Us:For general enquiries, feedback, or support:800434332GDMO@geidea.net
Whistleblowing:For confidential reporting of concerns related to misconduct or unethical behaviour:speakup.uae@geidea.net
Address:One Central, Offices 201 & 207,
The Offices 4, Trade Centre, Dubai

©2025 Geidea. All rights reserved

Geidea Payment LLC is licensed by the Central Bank of the UAE.

Terms & ConditionsPrivacy PolicyCookie Policy

Privacy Notice

This is the Privacy Policy content in English for United Arab Emirates (UAE).

About this notice

This Privacy Notice explains how Geidea Payment collects, uses, stores, shares, transfers and protects personal data when you visit our UAE website, use our UAE products or services, represent or work for a merchant, contact us, or otherwise interact with us. It applies to information relating to an identified or identifiable natural person.

It is prepared with reference to UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the Federal PDPL) where that law applies, the Central Bank of the UAE (CBUAE) consumer-protection and payment-services requirements, and other applicable UAE laws and regulatory directions. Certain processing, including personal banking and credit data governed by sector-specific legislation, may fall outside the Federal PDPL but remains protected under applicable sector rules. Product-specific notices should be read with this Notice.

For general enquiries, feedback, customer support, or privacy requests, please use the contact details provided in this Notice.

Who We Are and How to Contact Us

Geidea Payment: The controller responsible for the processing described in this Notice is Geidea Payment, a Limited Liability Company. Its registered address is Unit 201 & 207, second floor, building 04, One Central Trade Center, Dubai, UAE.

Commercial Registration No.: 1790296

License No.: 643843

Who This Notice Covers

This Notice covers website visitors; merchant owners, sole proprietors, authorised signatories, directors and beneficial owners; merchant staff and account users; cardholders where Geidea processes their personal data; prospects; suppliers and their personnel; job applicants where no separate recruitment notice is provided; people who contact us; and visitors to our premises.

Personal Data We May Collect

We may collect the following categories of personal data, depending on the products, services and interactions involved:

  • ✓Identity and verification: name, date of birth, nationality, Emirates ID/passport details, image, signature, role, authorised-signatory and beneficial-owner information.
  • ✓Contact: business/home address where necessary, email, telephone, language and communication preferences.
  • ✓Merchant and professional: business activity, position, stores, contracts, licences, tax and registration information linked to an individual.
  • ✓Financial and payment: settlement/bank details, payment and transaction records, refunds, disputes, reconciliation, chargebacks, fraud/risk indicators and limited card/token data where necessary.
  • ✓Device, online and location: IP address, browser/device identifiers, login/security logs, cookie/analytics identifiers, terminal IDs, and location where enabled and necessary.
  • ✓Support and communications: calls, email, chat, complaints, service requests, survey responses and related evidence.
  • ✓Compliance: KYC/KYB, AML/CFT, sanctions, fraud-prevention, regulatory enquiries, audit trails and legally required evidence.
  • ✓Marketing: consent, campaign interaction and preference/opt-out records.
  • ✓Premises: CCTV or visitor logs where used with appropriate notice.
  • ✓Do not provide another person's data unless you are authorised and have given them any required notice.

Sensitive and Regulated Financial Data

Some information, including certain financial, biometric, health, criminal-record, religious-belief and family data, may require enhanced protection. Personal banking and credit data may be subject to sector-specific legislation. As a CBUAE-licensed payment-services provider, Geidea maps processing activities to the Federal PDPL, CBUAE requirements and other applicable sector rules and applies appropriate access, confidentiality, security, purpose-limitation and retention safeguards.

How We Collect Personal Data

We may collect personal data in the following ways:

Sources of Collection
  • ✓Directly from you through forms, contracts, onboarding, product use, support, complaints, surveys and other communications.
  • ✓From the merchant or organisation you represent or work for, including account administrators and authorised representatives.
  • ✓From banks, acquirers, settlement institutions, payment schemes and processors involved in providing payment services.
  • ✓From lawful identity, credit, fraud, sanctions, AML/CFT, government, public and regulatory sources.
  • ✓Automatically from websites, apps, terminals and devices through logs, cookies and similar technologies, subject to applicable consent rules.
  • ✓From Geidea group companies and approved providers where lawful, necessary and protected by appropriate safeguards.
Indirect / Automatic Collection
  • ✓Website, application, terminal and device logs.
  • ✓Cookies and similar technologies.
  • ✓Analytics and security technologies, subject to applicable consent requirements.

Why and on What Basis We Process Data

The purposes and legal bases/permissions for processing may include the following:

Consent is specific, informed and demonstrable where relied upon. You may withdraw consent through the UAE privacy contact or the mechanism provided. Withdrawal does not affect earlier lawful processing or processing supported by another legal permission. We will not use personal data for a materially incompatible purpose without appropriate notice and authority.

Products, Services and Payments: We process identity, contact, merchant, device, financial, payment and support data to provide, onboard and administer products and services, process payments, settlement, refunds, disputes and reports, based on contract or steps requested before contract, legal/regulatory duties, and other applicable permissions.

KYC/KYB, AML/CFT, Security and Compliance: We process identity, financial, compliance, device and transaction data for KYC/KYB, AML/CFT, sanctions, fraud prevention, security, audit and regulatory matters where required or permitted by applicable law, regulation or competent-authority request.

Support, Analytics and Marketing:

  • ✓Customer support, complaints, maintenance and quality: contact, merchant, device, location and communication data, based on contract, consent where required, and legal claims.
  • ✓Website security, analytics and improvement: device, online, cookie and interaction data, based on strict necessity/security duties and consent for non-essential analytics.
  • ✓Marketing and events: contact, preference and campaign data, with prior informed express consent where required and an available withdrawal/opt-out mechanism.

Regulatory, Judicial and Corporate Matters: We may process relevant records and evidence for regulatory, judicial and corporate matters based on legal/regulatory duties, court or authority requests, legal claims, or lawful transaction safeguards.

Data Minimisation

We keep processing proportionate to the stated purpose and apply purpose limitation and appropriate safeguards. We do not request or use another person's personal data unless you are authorised and any required notice has been provided.

When We Share Personal Data

We share only what is necessary for the stated purpose with appropriate recipients, which may include:

  • ✓Geidea group companies that lawfully support the UAE service.
  • ✓Banks, acquirers, settlement institutions, payment schemes, issuers, processors and other payment participants.
  • ✓KYC/AML, sanctions, fraud, credit, communications, cloud/hosting, cybersecurity, analytics, maintenance and customer-support providers.
  • ✓Auditors, lawyers, insurers and other professional advisers with a need to know.
  • ✓CBUAE, UAE courts, law-enforcement and other competent authorities where disclosure is required or permitted.
  • ✓A lawful purchaser, investor or successor in a corporate transaction, subject to purpose and confidentiality safeguards.
  • ✓We do not sell personal data. Processors must follow documented instructions, protect confidentiality and security, assist with rights and incidents, and delete or return data when authorised work ends, subject to law.

How Long We Keep Personal Data

We keep each category only as long as necessary for its purpose and any longer period required for payment services, AML/CFT, sanctions, tax, accounting, chargebacks, disputes, security, litigation or regulatory directions. Criteria include the transaction and contract life cycle, sensitivity, limitation periods, legal holds and regulator instructions. When retention ends, data is securely erased or anonymised.

International Transfers

Where personal data is transferred outside the UAE, Geidea will apply the safeguards and legal requirements applicable to the transfer, including any requirements under UAE data-protection, CBUAE or other sector-specific rules.

Security

  • ✓We use risk-based technical and organisational measures designed to preserve confidentiality, integrity and availability and prevent unauthorised access, loss, alteration, disclosure or misuse.
  • ✓Controls include role-based access, authentication, encryption where appropriate, secure development/configuration, logging, monitoring, vulnerability and incident management, continuity controls, staff training, supplier assurance and testing.
  • ✓Payment-card processing is subject to applicable CBUAE, payment-scheme and payment-security standards.
  • ✓No internet service is completely secure. Protect your credentials and contact us promptly if you suspect unauthorised access.

Cookies and Similar Technologies

We use strictly necessary technologies to operate and secure the website and, only with the required choice or consent, analytics, preference and advertising technologies. You can manage non-essential choices in the UAE cookie preference tool. The UAE Cookie Policy lists providers, purposes and durations: https://www.geidea.net/uae/en.

Direct Marketing

We use personal data for direct marketing only with the informed express consent required by applicable CBUAE and UAE rules. Messages identify Geidea and provide a clear, easy and free opt-out. We record consent and preference changes. Service, security, fraud and regulatory messages are not marketing and may continue where necessary.

Your Rights

  • ✓Right to Be Informed: Receive information about the types of data, purposes, sharing, safeguards, retention, incidents and complaint process.
  • ✓Right to Access and Portability: Obtain and transfer your personal data in the applicable structured, commonly used and machine-readable format.
  • ✓Right to Rectification: Correct inaccurate data and complete or update incomplete data.
  • ✓Right to Erasure: Request erasure where the legal conditions are met.
  • ✓Right to Restriction: Restrict processing in applicable circumstances.
  • ✓Right to Object: Object to and request stopping of processing in applicable circumstances, including qualifying direct marketing.
  • ✓Rights Regarding Automated Decisions: Object to decisions based solely on automated processing, including profiling, where they have legal consequences or seriously affect you, and request human review where applicable.
  • ✓Right to Withdraw Consent: Withdraw consent where processing is based on consent.
  • ✓Right to Complain: Complain through the routes described in this Notice.

Personal Data Breaches

We maintain incident-response procedures. Where required, Geidea will notify the UAE Data Office or another competent authority without undue delay and within any mandatory period, and will notify affected individuals when a breach is likely to prejudice privacy/confidentiality or pose a risk to their financial or personal security. We will provide the information and protective steps required by applicable law and CBUAE standards.

Children

Geidea's UAE merchant and payment services are not directed to children. Where we must process a child's data, we apply age-appropriate transparency, lawful authority, data minimisation and enhanced safeguards and comply with applicable UAE child-digital-safety and sector requirements.

Third-Party Sites and Services

Third-party sites and services linked from our website apply their own notices. Review those notices before providing personal data. Geidea is not responsible for independent third-party privacy practices.

How to Exercise Your Rights

Submit a request using the UAE privacy contact in the Contact Us section. State the right and provide enough information to locate the data. We may request proportionate identity or authority evidence to prevent unauthorised disclosure; never provide a password or payment-card security code. Geidea Payment will acknowledge and respond within the period required by applicable law and regulatory requirements. If additional time is permitted and reasonably required, we will explain the reason and revised date. The website must not describe an internal service target as a statutory UAE deadline.

Request Costs

Requests are generally free. If applicable law permits a fee in a particular case, we will explain it before proceeding.

Your Responsibilities

  • ✓Do not provide another person's personal data unless you are authorised and have given them any required notice.
  • ✓Protect your account credentials and contact Geidea promptly if you suspect unauthorised access.

Contact Us

For general enquiries, feedback, customer support, privacy requests, or requests to exercise your rights, please contact the Geidea Payment Privacy Office/DPO.

Geidea Payment Privacy Office / Data Protection Officer

Address: Unit 201 & 207, second floor, building 04, One Central Trade Center, Dubai, UAE.

Phone: 800434332

Email: GDMO@geidea.net

Complaints

Please first contact the Geidea Payment Privacy Office/DPO so we can investigate. Where applicable, you may submit a personal-data complaint to the UAE Data Office using the official route available at the time.

For an eligible complaint about a service or conduct of a CBUAE-licensed financial institution, you may contact Sanadak after first completing the required internal complaint step.

https://www.sanadak.gov.ae/en/make-a-complaint/

Disclaimer

  • ✓No internet service is completely secure. Protect your credentials and contact us promptly if you suspect unauthorised access.

Changes and Language

We may update this Notice to reflect legal, regulatory, service or processing changes. We will publish the updated date and provide additional notice or obtain consent where required. The English and Arabic versions are intended to be consistent. If they conflict, the Arabic version shall prevail.

Date of Last Update

The Privacy Notice may be updated from time to time to reflect legal, regulatory, service or processing changes.

Applicable Law and Regulatory Complaints

This Notice is prepared with reference to UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data where applicable, CBUAE consumer-protection and payment-services requirements, and other applicable UAE laws and regulatory directions. These complaint routes do not limit any other remedy available under applicable law.