Privacy Policy
Last updated: on launch (Version 1.1). Aunova Technologies Ltd, DIFC, Dubai, UAE.
About this policy
This policy explains how Aunova Technologies Ltd (“Aunova”, “we”, “us”) handles personal data collected through this website, aunova.ae. We are the controller of that data. Our privacy contact is our Data Protection Lead at [email protected].
aunova.ae is a static marketing site. We use no analytics, no advertising, no trackers, and no third-party cookies. The only way you share personal data with us is if you choose to use our contact form or our privacy request form.
What we collect
- Contact form. The details you choose to give us: your name, your work email, your company or role (optional), and your message. Your message is encrypted in your browser before it leaves your device, and only we can read it (see “How your contact message is protected” below).
- Privacy request form. Your name, contact details, and the details of your request, used only to handle that request.
- Server logs. When you visit any web page, our hosting provider automatically records technical data such as your IP address, the time of the request, the pages requested, and your browser and device type. This is standard and is used to keep the site secure and working.
We collect only what we need. Optional fields can be left blank, and you never need an account to use the site.
Why we use it, and our legal basis
- To respond to your enquiry and send you information you ask for - our legitimate interest in replying to you, and steps towards a possible agreement (GDPR Article 6(1)(f) and (b)).
- To handle privacy and rights requests - our legal obligations and legitimate interests (GDPR Article 6(1)(c) and (f)).
- To operate, maintain, and secure the website - our legitimate interest in a safe, working service (GDPR Article 6(1)(f)).
We do not use your data for analytics, profiling, or marketing.
How your contact message is protected
When you use the contact form, your message is encrypted in your browser before it is sent. It travels to us through independent relay servers that only carry the encrypted message - they cannot read what you wrote. Only we hold the key that can decrypt it. We do not use a third-party form-handling service, and your message is not stored on the website’s servers.
Cookies
The site uses strictly-necessary cookies only and sets no analytics, marketing, or tracking cookies - in fact it sets no cookies at all at launch. Because there are no non-essential cookies to consent to, we show no cookie banner. Full detail is in our Cookie notice.
Third parties
- Hosting - Cloudflare Pages. The site is hosted on Cloudflare Pages, which serves our pages worldwide and processes the technical server-log data above on our behalf as our hosting provider.
- Encrypted message delivery - relay servers. As above, relay servers carry your encrypted contact message to us. They only ever hold the encrypted message and cannot read it.
There is no analytics, advertising, or tracking provider on this site.
International transfers
Because our host, Cloudflare Pages, runs on a global network that includes locations outside the DIFC, the UAE, and the EEA (including the United States), and because your contact message travels through relay servers that may be located anywhere, your data may be transferred internationally.
- For hosting, we rely on the lawful transfer mechanisms recognised under DIFC Data Protection Law No. 5 of 2020 and, for EEA visitors, the appropriate safeguards under the GDPR (including our host’s data processing terms and standard contractual clauses where they apply).
- For your contact message, the safeguard is built in: it is end-to-end encrypted in your browser, so the relay servers that carry it only ever hold data they cannot read, and only we can decrypt it.
How long we keep it
We keep enquiries and form submissions only as long as we need them to deal with your request and for a reasonable follow-up period, then delete or archive them. Server logs are kept for 90 days, then deleted. We collect and retain no analytics data.
Your rights
You have the rights to access, correct, erase, restrict, port, and object to the processing of your personal data, and to withdraw consent where we rely on it, under DIFC Data Protection Law No. 5 of 2020 and, for EEA visitors, GDPR Articles 12 to 22. To exercise a right, use our privacy request form or email [email protected]. We aim to respond within 30 calendar days. You may also complain to the DIFC Commissioner of Data Protection or, if you are in the EEA, your local data protection authority.
Children
This site is for a business audience and is not directed at children. We do not knowingly collect children’s data.
Changes
We keep this policy under review and update the version and date when we change it. The current version always governs.
This notice is finalised for launch and is pending review by qualified counsel. It is not legal advice and does not evidence any held certification.