Privacy policy
Last updated: 4 October 2026
This policy explains what personal data MAFSAN handles, why, who it is shared with, how long it is kept, and what choices you have. It covers our website, our AI assistant Nyla, and the messaging services we run for business clients.
1. Who we are
The data controller for our own website and enquiries is:
MAFSAN GLOBAL SOLUTIONS FZC LLCCWS-2V-226580, 26th Floor, Amber Gem Tower, Ajman, United Arab Emirates
Phone: +971 54 495 6324
Email: contact@mafsan.ae
For any privacy question or request, write to contact@mafsan.ae.
2. Two different roles
- Our own website and enquiries. When you use our website, talk to Nyla or send us a brief, MAFSAN decides why and how your data is used.
- Messaging for business clients. MAFSAN also provides a customer-relationship and messaging system to other businesses, for example property developers and brokers. If one of those businesses contacts you by email or WhatsApp, that business decides why your data is used and MAFSAN processes it on that business's behalf. Section 8 explains how to reach them or us.
3. What we collect
- What you type into Nyla. Processed to produce the next question or answer. The conversation is not stored unless you choose to send a brief.
- A brief or enquiry you send. The details you enter (such as name, email, phone number, company, your goals) and a summary of the conversation, so our team can respond. Your permission to be contacted is recorded.
- Business gap check answers. If you complete the assessment, your answers and any contact details you add.
- Anonymous website activity. Counts of pages viewed, buttons used and sections reached. This uses no cookies, stores no IP address and records none of the text you type. Browsers that send Do Not Track or Global Privacy Control are not counted.
- Email and WhatsApp conversations with you, where you have written to us or a client of ours has contacted you: your name, email address or phone number, the messages, delivery status, and your opt-in or opt-out choices.
- Security signals. Forms use a bot check (Cloudflare Turnstile) which reads browser signals needed to tell people from automated traffic.
4. Why we use it, and our legal basis
- To reply to you, understand your business problem and suggest how we can help (your request, and our legitimate interest in running the business).
- To contact you by email or WhatsApp only where you have given permission or have contacted us first (consent or your request). Every message can be stopped by replying STOP.
- To keep the website and systems secure and to prevent abuse (legitimate interest).
- To understand, in aggregate and anonymously, how the website is used and to improve it (legitimate interest).
- To meet legal obligations and to keep records of opt-outs so we do not contact you again.
We apply the principles of the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and, where it applies to you, the EU and UK GDPR.
5. AI assistance
Nyla is an AI assistant and says so. To answer in your language, the text you send in an exchange is passed to a third-party AI model provider acting on our instructions. Please do not share sensitive details (such as identity document numbers, passwords or payment card numbers) in chat. Nyla does not make pricing, legal or investment decisions; anything important is handed to a person on our team or the client's team.
6. WhatsApp and email messaging
- We use the WhatsApp Business Platform provided by Meta. Messages sent through it are also processed by Meta under Meta's own terms and privacy policy.
- We send business-initiated WhatsApp messages only to people who have opted in to hear from the business concerned. Opening or follow-up messages use templates approved by WhatsApp.
- Reply STOP (or tell us in your own words) at any time and we stop. An opt-out always takes priority over any scheduled message.
- Email conversations are sent and received through our email provider and carry an unsubscribe route.
7. Who we share data with
We do not sell personal data. We share it only with service providers that run our systems for us and may use it only on our instructions:
- Supabase: database, sign-in and file storage (hosted in India, Mumbai).
- Vercel: website hosting and scheduled jobs (India, Mumbai).
- Resend: sending and receiving email.
- An AI model provider: writing assistant replies (current exchange only).
- Meta (WhatsApp Business Platform): delivering WhatsApp messages.
- Cloudflare: bot protection on forms.
- Sentry: error tracking, designed not to include message text or contact details.
Because these providers operate outside the UAE, your data may be transferred internationally. We use contractual safeguards and choose regions deliberately. We may also disclose data where the law or a competent authority requires it.
8. How long we keep it
- Anonymous website activity: 180 days, then deleted automatically.
- Briefs, enquiries and conversations: for as long as needed to respond and follow up, and reviewed at least every 12 months; deleted sooner on request.
- Opt-out records: kept so we never contact you again. After an erasure request this record holds only a one-way hash, not your details.
- Backups: erased data disappears from backups as they age out.
9. Your rights and how to use them
Subject to the law that applies to you, you may ask to access, correct, delete or move your data, to object to or restrict its use, to withdraw consent, and to stop being contacted. Email contact@mafsan.ae from the address or number concerned, or see how to delete your data. We aim to respond within 30 days. If your data is held for a client of ours, we will pass the request to that client or carry it out on their instruction. You may also complain to the relevant data protection authority.
10. Security
Data is encrypted in transit, access is limited by role and by client, databases enforce separation between clients, actions are logged without personal content, and contacts who ask to be erased are removed from our systems. No system is perfectly secure; we will notify you and the relevant authority where the law requires if a breach affects you.
11. Children
Our services are for businesses and adults. We do not knowingly collect data from children under 18.
12. Changes
We will post any change on this page with a new date. If a change is significant we will tell you directly where we can.
