Privacy Policy
In effect from 2 August 2026
This policy explains what personal data Encoded Agency collects, why we collect it, who we share it with, and what you can ask us to do about it. It is written to meet Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the UAE PDPL).
Short version: we collect what we need to answer your enquiry and deliver the work you buy, we do not sell it, and you can have it back or have it deleted by writing to us.
1.Who we are
Encoded Agency is the trading name of Encoded Agency FZ-LLC, a company licensed in Sharjah Media City (Shams) under trade licence TODO-OWNER: licence number, with its registered address at TODO-OWNER: office/building, Sharjah Media City, Sharjah, UAE. In this policy “we”, “us” and “our” mean that company.
For personal data described in this policy we act as the controller — we decide why and how it is processed — except where “Websites we build for clients” below says otherwise.
Privacy questions and requests go to legal@encodedagency.com. General enquiries go to lars@encodedagency.com or +971 55 531 6676.
2.What this policy covers
This policy covers personal data we handle through this website, our enquiry channels, our sales process, and the delivery of our services to clients.
It does not cover the websites we build and host for clients. On those sites the client is the controller and their own privacy policy applies — see “Websites we build for clients” below.
3.What we collect
Information you give us
- Enquiry form. Your name, business name, phone number, and the message you write. These four fields are required; the form sends nothing else.
- WhatsApp, email and calls. Your phone number or email address, and the content of the conversation. WhatsApp messages are also processed by WhatsApp under its own terms.
- Client onboarding. If you engage us: contact details for the people we work with, business and trade licence details, billing details, brand assets, website content, and access credentials for systems we are asked to work in.
- Payments. Card details are entered directly with our payment provider and never reach our systems. We receive the outcome, the amount, and the last four digits.
Information collected automatically
- Server and security logs. Our hosting provider records IP address, browser and device type, pages requested, and timestamps. We also count enquiry submissions per IP address for a rolling ten-minute window to block automated abuse.
- Analytics and advertising. Where you consent, we use Google Analytics and the Meta advertising pixel to understand how the site is used and to measure and target advertising. What these set, and how to refuse them, is in our Cookie Policy.
Information from other sources
- Publicly listed business contact details. We compile business names, business phone numbers, business email addresses, websites and social profiles from public sources in order to approach businesses about our services. See “How we approach businesses” below.
- Referrals. Contact details passed to us by a client or partner who recommends you.
What we do not collect
We do not ask for and do not want health or medical information, government identification numbers beyond what a trade licence or invoice legally requires, or any other sensitive personal dataas defined by the PDPL. Do not send it through this website. Where we build sites for regulated clients such as clinics, enquiry forms are configured to route to the client's own systems and are not stored by us.
4.Why we use it, and our lawful basis
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the UAE PDPL) requires a lawful basis for every use of personal data. Ours are set out below.
| What we do | Lawful basis |
|---|---|
| Reply to your enquiry and quote for work | Steps taken at your request before entering a contract |
| Deliver, host, support and maintain the services you buy | Performance of our contract with you |
| Invoice, take payment and chase unpaid amounts | Performance of our contract, and our legitimate interest in being paid |
| Keep accounting, tax and VAT records | Compliance with a legal obligation in the UAE |
| Protect the site from abuse, spam and fraud | Our legitimate interest in the security of our systems |
| Approach businesses about our services | Our legitimate interest in direct business-to-business marketing, subject to “How we approach businesses” below |
| Analytics, and advertising measurement and targeting | Your consent, withdrawable at any time |
| Establish, exercise or defend a legal claim | Our legitimate interest, and compliance with a legal obligation |
We do not sell personal data, and we do not use automated decision-making that produces legal effects for you.
7.Transfers outside the UAE
Several of the providers above operate outside the UAE, so your personal data may be processed abroad — in practice, mainly in the European Union and the United States.
Where the destination country has not been recognised by the UAE Data Office as offering an adequate level of protection, we rely on the safeguards permitted by the PDPL: contractual clauses that bind the provider to protect the data, obtained before any transfer begins.
You can ask us which providers we currently use and where they process data by writing to legal@encodedagency.com.
8.How long we keep it
We keep personal data only as long as it serves the purpose it was collected for, then delete or anonymise it.
| Data | Kept for |
|---|---|
| Enquiries that do not become clients | 24 months from last contact |
| Client records and correspondence | Duration of the engagement, then 5 years |
| Invoices, contracts and accounting records | At least 5 years, as UAE tax law requires |
| Server and security logs | Up to 12 months |
| Analytics and advertising data | As set out in the Cookie Policy |
| Business contact details used for outreach | Until you opt out; opt-outs are kept permanently so we do not contact you again |
9.How we approach businesses
We contact UAE businesses directly about our services, by email, phone and messaging apps, using contact details that the business has published for that purpose. Sometimes we build a sample website for a business before contacting it, so the approach shows finished work rather than a proposal.
- We use business contact details, not personal ones, and we identify ourselves in every message.
- Every message carries a way to opt out. One request is enough, through any channel.
- An opt-out is recorded on a permanent suppression list and we do not contact that business again.
- We do not sell, rent or share our outreach list, and sample sites built for outreach are taken down on request.
To be removed immediately, write to legal@encodedagency.com with the business name, or simply reply to the message you received.
10.How we protect it
- The site is served over HTTPS, and forms post over encrypted connections.
- Access to client data is limited to the people who need it, and credentials are held in a password manager — never in email or chat.
- Accounts that support multi-factor authentication have it enabled.
- Enquiry submissions are rate-limited and screened for automated abuse.
No system is perfectly secure. If a breach occurs that is likely to prejudice your privacy or confidentiality, we will notify the UAE Data Office and, where the PDPL requires it, you — without undue delay.
11.Your rights
Under the PDPL you may ask us to:
- Access — give you a copy of the personal data we hold about you, and explain how it is processed.
- Correct — fix data that is inaccurate or incomplete.
- Delete — erase your data, unless we are required to keep it or need it for a legal claim.
- Restrict or object — stop or limit processing, including processing for direct marketing, which we always stop on request.
- Port — receive data you gave us in a structured, machine-readable format, or have it sent to another controller where technically feasible.
- Withdraw consent — where we rely on consent, at any time, without affecting what was done before.
Write to legal@encodedagency.com. We respond within 30 days. We may ask for enough information to confirm who you are, and we exercise these rights free of charge unless a request is manifestly excessive or repetitive.
If you are not satisfied with our response, you may complain to the UAE Data Office.
12.Websites we build for clients
When we build, host or maintain a website for a client, that client decides what personal data the site collects and why. The client is the controller; we act as a processor on their documented instructions, under the terms of our engagement.
If you submitted your details on a website we built for someone else, direct your privacy request to that business. Send it to us and we will pass it on, but we cannot action it ourselves.
13.Children
Our services are sold to businesses and this website is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, write to legal@encodedagency.com and we will delete it.
14.Links to other sites
This site links to sites we do not control, including client websites and social platforms. We are not responsible for their content or their privacy practices. Read their policies before giving them your data.
15.Changes to this policy
We update this policy when our practices or the law change. The date at the top always reflects the current version. If a change materially affects how we use your personal data, we will make that clear on this page and, where we hold your contact details and the change requires it, tell you directly.
16.Contact
Encoded Agency FZ-LLC
TODO-OWNER: office/building, Sharjah Media City, Sharjah, UAE
Trade licence TODO-OWNER: licence number, Sharjah Media City (Shams)
Privacy and data requests: legal@encodedagency.com
General enquiries: lars@encodedagency.com · +971 55 531 6676
Read alongside our Terms of Use, Cookie Policy and Client Service Terms.