This is the Privacy Policy content in English for United Arab Emirates (UAE).
This Privacy Notice explains how Geidea Payment collects, uses, stores, shares, transfers and protects personal data when you visit our UAE website, use our UAE products or services, represent or work for a merchant, contact us, or otherwise interact with us. It applies to information relating to an identified or identifiable natural person.
It is prepared with reference to UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the Federal PDPL) where that law applies, the Central Bank of the UAE (CBUAE) consumer-protection and payment-services requirements, and other applicable UAE laws and regulatory directions. Certain processing, including personal banking and credit data governed by sector-specific legislation, may fall outside the Federal PDPL but remains protected under applicable sector rules. Product-specific notices should be read with this Notice.
For general enquiries, feedback, customer support, or privacy requests, please use the contact details provided in this Notice.
Geidea Payment: The controller responsible for the processing described in this Notice is Geidea Payment, a Limited Liability Company. Its registered address is Unit 201 & 207, second floor, building 04, One Central Trade Center, Dubai, UAE.
Commercial Registration No.: 1790296
License No.: 643843
This Notice covers website visitors; merchant owners, sole proprietors, authorised signatories, directors and beneficial owners; merchant staff and account users; cardholders where Geidea processes their personal data; prospects; suppliers and their personnel; job applicants where no separate recruitment notice is provided; people who contact us; and visitors to our premises.
We may collect the following categories of personal data, depending on the products, services and interactions involved:
Some information, including certain financial, biometric, health, criminal-record, religious-belief and family data, may require enhanced protection. Personal banking and credit data may be subject to sector-specific legislation. As a CBUAE-licensed payment-services provider, Geidea maps processing activities to the Federal PDPL, CBUAE requirements and other applicable sector rules and applies appropriate access, confidentiality, security, purpose-limitation and retention safeguards.
We may collect personal data in the following ways:
The purposes and legal bases/permissions for processing may include the following:
Consent is specific, informed and demonstrable where relied upon. You may withdraw consent through the UAE privacy contact or the mechanism provided. Withdrawal does not affect earlier lawful processing or processing supported by another legal permission. We will not use personal data for a materially incompatible purpose without appropriate notice and authority.
Products, Services and Payments: We process identity, contact, merchant, device, financial, payment and support data to provide, onboard and administer products and services, process payments, settlement, refunds, disputes and reports, based on contract or steps requested before contract, legal/regulatory duties, and other applicable permissions.
KYC/KYB, AML/CFT, Security and Compliance: We process identity, financial, compliance, device and transaction data for KYC/KYB, AML/CFT, sanctions, fraud prevention, security, audit and regulatory matters where required or permitted by applicable law, regulation or competent-authority request.
Support, Analytics and Marketing:
Regulatory, Judicial and Corporate Matters: We may process relevant records and evidence for regulatory, judicial and corporate matters based on legal/regulatory duties, court or authority requests, legal claims, or lawful transaction safeguards.
We keep processing proportionate to the stated purpose and apply purpose limitation and appropriate safeguards. We do not request or use another person's personal data unless you are authorised and any required notice has been provided.
We share only what is necessary for the stated purpose with appropriate recipients, which may include:
We keep each category only as long as necessary for its purpose and any longer period required for payment services, AML/CFT, sanctions, tax, accounting, chargebacks, disputes, security, litigation or regulatory directions. Criteria include the transaction and contract life cycle, sensitivity, limitation periods, legal holds and regulator instructions. When retention ends, data is securely erased or anonymised.
Where personal data is transferred outside the UAE, Geidea will apply the safeguards and legal requirements applicable to the transfer, including any requirements under UAE data-protection, CBUAE or other sector-specific rules.
We use strictly necessary technologies to operate and secure the website and, only with the required choice or consent, analytics, preference and advertising technologies. You can manage non-essential choices in the UAE cookie preference tool. The UAE Cookie Policy lists providers, purposes and durations: https://www.geidea.net/uae/en.
We use personal data for direct marketing only with the informed express consent required by applicable CBUAE and UAE rules. Messages identify Geidea and provide a clear, easy and free opt-out. We record consent and preference changes. Service, security, fraud and regulatory messages are not marketing and may continue where necessary.
We maintain incident-response procedures. Where required, Geidea will notify the UAE Data Office or another competent authority without undue delay and within any mandatory period, and will notify affected individuals when a breach is likely to prejudice privacy/confidentiality or pose a risk to their financial or personal security. We will provide the information and protective steps required by applicable law and CBUAE standards.
Geidea's UAE merchant and payment services are not directed to children. Where we must process a child's data, we apply age-appropriate transparency, lawful authority, data minimisation and enhanced safeguards and comply with applicable UAE child-digital-safety and sector requirements.
Third-party sites and services linked from our website apply their own notices. Review those notices before providing personal data. Geidea is not responsible for independent third-party privacy practices.
Submit a request using the UAE privacy contact in the Contact Us section. State the right and provide enough information to locate the data. We may request proportionate identity or authority evidence to prevent unauthorised disclosure; never provide a password or payment-card security code. Geidea Payment will acknowledge and respond within the period required by applicable law and regulatory requirements. If additional time is permitted and reasonably required, we will explain the reason and revised date. The website must not describe an internal service target as a statutory UAE deadline.
Requests are generally free. If applicable law permits a fee in a particular case, we will explain it before proceeding.
For general enquiries, feedback, customer support, privacy requests, or requests to exercise your rights, please contact the Geidea Payment Privacy Office/DPO.
Geidea Payment Privacy Office / Data Protection Officer
Address: Unit 201 & 207, second floor, building 04, One Central Trade Center, Dubai, UAE.
Phone: 800434332
Email: GDMO@geidea.net
Please first contact the Geidea Payment Privacy Office/DPO so we can investigate. Where applicable, you may submit a personal-data complaint to the UAE Data Office using the official route available at the time.
For an eligible complaint about a service or conduct of a CBUAE-licensed financial institution, you may contact Sanadak after first completing the required internal complaint step.
We may update this Notice to reflect legal, regulatory, service or processing changes. We will publish the updated date and provide additional notice or obtain consent where required. The English and Arabic versions are intended to be consistent. If they conflict, the Arabic version shall prevail.
The Privacy Notice may be updated from time to time to reflect legal, regulatory, service or processing changes.
This Notice is prepared with reference to UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data where applicable, CBUAE consumer-protection and payment-services requirements, and other applicable UAE laws and regulatory directions. These complaint routes do not limit any other remedy available under applicable law.