Privacy Policy
Effective date: 28 September 2026
This Privacy Policy explains how Hyssopia L.L.C-FZ (“Hyssopia”, “we”, “us”) handles personal data when you visit hyssopia.com (the “Site”) or contact us. It covers the Site only. Each of our apps will have its own privacy policy.
We process personal data in accordance with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (“PDPL”) and, where they apply to you, the EU General Data Protection Regulation (“GDPR”) and the UK GDPR.
1. Who we are
Hyssopia L.L.C-FZ is the controller of your personal data.
Hyssopia L.L.C-FZ Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E. Business license no. 2651389.01 Email: hello@hyssopia.com
2. What we collect and why
We keep data collection to a minimum.
| What | When | Why | Legal basis (GDPR / UK GDPR) |
|---|---|---|---|
| Technical data: IP address, browser type, device type, pages requested, date and time | Automatically when the Site is loaded, by our hosting provider | To deliver the Site, keep it secure and fix errors | Legitimate interests (running a secure website) |
| Correspondence: your email address, name if you give it, and the content of your message | When you email hello@hyssopia.com | To reply, provide support and keep a record of the conversation | Legitimate interests (responding to enquiries); where the email relates to a contract, performance of that contract |
Under the PDPL, we process this data without your consent only where the law allows it: to respond to a request you make, to perform a contract with you, or to comply with UAE law.
We do not use analytics, advertising, retargeting or cross-site tracking on the Site.
We do not knowingly collect special categories of data (e.g. health data) through the Site. Please don’t send us such information by email unless it is necessary.
3. Who we share it with
We don’t sell your personal data or share it for advertising.
We use a small number of service providers who process data on our behalf, under contracts that require them to protect it:
- Hosting and content delivery: Cloudflare, provided by Cloudflare, Inc. (United States); Cloudflare serves the Site from data centres around the world, so technical data may be processed in the country nearest to you
- Email: Google Workspace, provided by Google LLC (United States); Google may process data in other countries where it or its subprocessors operate
We may also disclose data where required by law, or to establish, exercise or defend legal claims.
4. International transfers
We are based in the United Arab Emirates, and our service providers may process data in other countries. If you are in the EU/EEA or the UK, your data will be transferred outside those regions. Where a transfer is not covered by an adequacy decision, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum). You can request a copy by contacting us.
When personal data is transferred outside the UAE, we rely on the grounds the PDPL allows, in particular contracts with our service providers that require them to protect the data to the standard the PDPL sets.
5. How long we keep it
- Technical data: we don’t keep server logs ourselves. Our hosting provider, Cloudflare, processes this data to deliver and protect the Site and keeps it only as long as needed for those purposes, under its data processing terms.
- Emails and other correspondence, including enquiries, support and correspondence relating to a contract or transaction: 5 years after our last exchange, after which we delete it.
- Accounting and tax records: for as long as UAE tax law requires, currently 7 years.
- Any data needed to establish, exercise or defend legal claims: until the claim is resolved.
6. Your rights
Under the PDPL and, depending on where you live, the GDPR or UK GDPR, you may have the right to:
- access the personal data we hold about you;
- have it corrected or completed;
- have it erased;
- restrict or object to our processing, including processing based on legitimate interests;
- receive it in a portable format;
- withdraw consent at any time, where we rely on consent.
To exercise any of these rights, email hello@hyssopia.com. We may need to verify your identity. We will respond within the period required by the PDPL and its implementing regulations, and in any case within one month where the GDPR or UK GDPR applies.
You also have the right to complain to a data protection authority:
- in the UAE, the Artificial Intelligence and Data Authority, which has taken over the functions of the UAE Data Office;
- in the EU/EEA, the supervisory authority where you live or work;
- in the UK, the Information Commissioner’s Office (ico.org.uk).
We’d appreciate the chance to address your concern first, so please contact us before going to a regulator.
7. Security
We use reasonable technical and organisational measures to protect personal data, including encrypted connections (HTTPS) and restricted access to our systems. No method of transmission over the internet is completely secure.
8. Children
The Site is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has sent us personal data, contact us and we will delete it.
9. Changes to this policy
We may update this policy from time to time. The effective date at the top shows when it was last changed. If the changes are significant, we will highlight them on the Site.
10. Contact
Questions about this policy or your data: hello@hyssopia.com