Personal data

Privacy policy

What this site actually does with your data, field by field and key by key, is read from the code, not copied from a template. Last updated: 29 September 2026.

In brief

You can read the whole of this site without sending us anything and without any third-party tracker being loaded. Nothing is sent to Google or Meta until you have clicked “Accept”. If you fill in a form, your details go to our team in Dubai and to our CRM, both located outside the European Union, and they are neither sold nor passed on to commercial third parties.

Who is responsible for this processing

The controller is the company that publishes the site, identified in the legal notice. No dedicated email address has been published to date: requests about your data are made through the contact form, with “personal data” as the subject. They are handled as such, and not as sales enquiries.

What you give us voluntarily

There are three forms on this site, and all three send their data to the same place, through the same server function.

  • The three-step contact form, on the contact page: first name, last name, email address, dialling code and phone number, country of residence, subject, free-text message, and the optional answer to the qualifying question asked at the first step.
  • The short form in the advice bands that close the main pages: first name, last name, email address, dialling code and number.
  • The newsletter sign-up, in the footer: first name and email address.

In all three cases, the acceptance box is never pre-ticked, and with your submission we record the fact that you ticked it, the time at which you did so and the version of the text you accepted. The number you enter is reformatted into international format before it is sent, under the name full_number, so that a call-back does not go to the wrong country code.

What the site adds to your submission without asking you

A request is only useful to us if we know its context. The following are therefore attached to your message:

  • The page context: the address of the page you submitted from, the address of the first page of your visit, the referring site, the browser language, the browser’s technical identifier (user agent), and a timestamp.
  • First-visit attribution, stored under the key di_attr: the five parameters utm_source, utm_medium, utm_campaign, utm_term and utm_content; the ad click identifiers gclid, fbclid, msclkid, ttclid and li_fat_id; and the free variables ref, topic, reference, project, agent, area and campaign_id when they appear in the address through which you arrived. It is the first touch that is kept, not the last.
  • Two technical identifiers: analytics_vid, copied from the rcrm_vid key if our CRM’s tracking tool has set it in your browser, and external_lead_id, a unique identifier created on submission so that a double click does not create two records.
  • Two anti-bot measures: an invisible trap field that must remain empty, and the time elapsed between the form being displayed and being submitted. Both are checked, then removed from the payload before it leaves our server: the CRM does not receive them.

The di_attr record is created from the first page you view, before you answer the consent band, because it is what links a later request to its origin. It contains no advertising identifier unless you arrived through a link that carried one, and it is only sent if you submit a form.

What our server adds on receipt

Submissions are received by a function hosted by Cloudflare. It completes your submission with what the network observes, rather than with what the browser declares: IP address, the country, city and region derived from that address, the data centre that handled the request, time zone, the browser’s technical identifier, the referring page and the time of receipt. If you have not given your country, the country derived from the IP address is used.

This serves two purposes: routing your request to the right person, and telling a genuine request apart from an automated submission.

What you can count on

  • You can browse the whole site with no account, no password and no online payment.
  • Tags, pixels and social media buttons are only loaded from a third-party server after you have given your consent.
  • The site’s two typefaces are hosted with it, with no call to a font on an external server.
  • When a page offers a video, the player script is only activated after a deliberate click on your part, and playback then takes place on the platform’s cookie-free domain.
  • Every record is managed by our own teams only, with no sale or transfer to commercial third parties.
  • Your requests are always read by a person, which rules out any automated decision producing a legal effect concerning you.

On what legal basis

  • Handling your request: steps taken at your request prior to entering into a contract, Article 6(1)(b) GDPR, together with the consent you give by ticking the box.
  • Sending you the newsletter: your consent, Article 6(1)(a). You can withdraw it at any time, through the unsubscribe link in every mailing or from the contact page, without having to give a reason.
  • Preventing automated submissions and protecting the service: our legitimate interest, Article 6(1)(f). This is what justifies the trap field, the minimum completion time and the limit on the number of submissions per IP address.
  • Measuring audience and campaign performance: your consent, Article 6(1)(a), collected through the band shown on your first visit.

Who receives your data, and where

Your requests are read by the team in Dubai and recorded in the firm’s CRM. They pass through Cloudflare, which hosts the site and the receiving function, and which processes your IP address for that purpose. Only after consent do Google and Meta receive audience measurement data, through the tag container.

This processing takes place mainly in the United Arab Emirates, and therefore outside the European Union, and that country is not the subject of an adequacy decision by the European Commission at the date of this page. The transfer of the request you send us relies on Article 49(1)(b) GDPR: it is necessary for the performance of steps taken at your request prior to entering into a contract. In other words, you are asking to be called back by a team based in Dubai, and your request has to reach that team for this to happen.

Audience measurement and consent

No more than one tag container is used on this site, and it is only loaded after a click on “Accept”. Google Analytics 4 and the Meta pixel are configured inside that container, never as separate scripts: if you decline, no request is sent to these services, and none of their cookies is set.

Accept and Decline are two buttons of the same size and weight, in the same place, and the Escape key counts as declining. There is no pre-ticked box, no second screen, no “continue without accepting” link in small print. Declining does not restrict access to the content in any way.

Changing your choice Your answer is recorded in your browser’s local storage, under the key di_consent, for 13 months. To change it before then, clear the site data for this domain in your browser settings: you will be asked again on your next visit, and the container will not be reloaded in the meantime.

The keys and cookies used, one by one

The first three rows are set by this site. The next three only exist if you have accepted audience measurement.

Storage keys and cookies used by dubai-investment.com
NameType and locationWhat it is forLifetime
di_consentBrowser local storage. It is not a cookie and is never sent to a server.Remembers your answer to the consent band, so that you are not asked again on every page.13 months (395 days). After that, the record is deleted and you are asked again.
di_attrBrowser local storage.Remembers the campaign, link or search through which you first arrived, so that we know which pages are useful to you and how to improve them.A rolling 30 days, then reset.
di_sidSession storage. Written only when you submit a form.Links the submissions made during the same visit and makes it possible to detect a duplicate submission.Deleted when the tab is closed.
rcrm_vidLocal storage, written by our CRM’s tracking tool when it is present.The CRM’s visitor identifier. This site reads it and attaches it to your request under the name analytics_vid; it never writes it itself.Set by the tool that writes it.
_ga, _ga_…Google Analytics 4 cookies, set by the tag container, only after consent.Audience measurement: pages viewed, where visitors come from, type of device.Set in the container’s configuration. None of these cookies exists if you decline.
_fbpMeta cookie, set by the tag container, only after consent.Links a visit to a Meta campaign, when this measurement is active in the container.Set in the container’s configuration. None of these cookies exists if you decline.

Scroll the table sideways to see every column.

How long your data is kept

  • An incoming request: for as long as it takes to handle the file, then three years from the last contact for a contact that went no further. This is the reference period we apply; it is reviewed with our legal adviser.
  • A newsletter subscription: until you unsubscribe.
  • Your consent choice: 13 months, then automatic deletion.
  • First-visit attribution: 30 days.
  • The host’s technical logs: according to Cloudflare’s own retention periods, as it acts as a processor.

How your submissions are protected

The site is served over HTTPS and applies a content security policy that forbids inline scripts from running, which closes the door on a whole family of injection attacks. The address of the service that receives requests is never exposed to the browser: it lives in the server function. A submission is capped at 64 KB, rejected if it is sent less than 2.5 seconds after the form is displayed, and limited to five submissions per ten-minute window per IP address. That address is hashed before it enters the counter, so that no address is kept in clear for this purpose.

Your rights, and how to exercise them

You have the right of access, rectification, erasure, restriction and objection, the right to portability of the data you have provided to us, and the right to withdraw your consent at any time, without affecting anything done before the withdrawal.

To exercise them, write to us from the contact page with “personal data” as the subject, stating the email address or phone number you gave us: without it, we cannot find your record. The GDPR gives us one month to reply. If you are not satisfied with the reply, you may lodge a complaint with the data protection supervisory authority of your country of residence.

Changes to this page

This policy describes how the site behaves on the date shown at the top. It is revised whenever that behaviour changes — a tracker added, a recipient changed, a retention period revised — and the update date is corrected the same day. An earlier version can be sent to you on request.

Page upkeep

Who maintains this policy

The practices described here are kept up to date by the desk responsible for the site’s compliance and reporting obligations, and reviewed whenever a code change affects data collection, audience measurement or the transmission of requests.

Related pages