Data Protection
Learn about our commitment to protecting your personal data and your rights under applicable data protection laws.
1. Our Commitment
LimeworkTechnologies LLC is committed to protecting the personal data of all users, agents, and stakeholders who interact with RateAgent.io. This document outlines our comprehensive approach to data protection.
2. Regulatory Framework
We comply with:
- UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021)
- Cabinet Decision No. 34 of 2022 (Executive Regulations)
- DIFC Data Protection Law No. 5 of 2020
- ADGM Data Protection Regulations 2021
3. Data Protection Principles
We adhere to the following principles:
3.1 Lawfulness, Fairness, and Transparency
We process data lawfully with a valid legal basis, fairly without deception, and transparently with clear communication about our practices.
3.2 Purpose Limitation
We collect data only for specified, explicit, and legitimate purposes and do not process data in ways incompatible with those purposes.
3.3 Data Minimisation
We collect only data that is adequate, relevant, and necessary for our stated purposes.
3.4 Accuracy
We take reasonable steps to ensure personal data is accurate and kept up to date. Inaccurate data is corrected or deleted promptly.
3.5 Storage Limitation
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected.
3.6 Integrity and Confidentiality
We implement appropriate security measures to protect against unauthorised access, loss, destruction, or damage.
4. Technical Security Measures
4.1 Encryption
- Data in transit: Protected using TLS 1.3
- Data at rest: Encrypted using AES-256
- Password storage: Securely hashed using industry-standard algorithms
4.2 Access Controls
- Role-based access permissions
- Multi-factor authentication for sensitive operations
- Regular access reviews and audits
4.3 Infrastructure Security
- Secure cloud hosting with redundancy
- Regular security assessments and penetration testing
- 24/7 monitoring and intrusion detection
5. Your Data Rights
Under applicable data protection laws, you have specific rights regarding your personal data:
Right to Access
You can request a copy of the personal data we hold about you.
Right to Rectification
You can request correction of any inaccurate or incomplete data.
Right to Erasure
You can request deletion of your personal data in certain circumstances.
Right to Restrict Processing
You can request that we limit how we use your data.
Right to Data Portability
You can request your data in a structured, machine-readable format.
Right to Object
You can object to certain types of processing, including direct marketing.
To exercise any of these rights, contact us at privacy@rateagent.io.
6. Data Breach Response
In the event of a personal data breach, we have established procedures to:
- Detect and contain the breach promptly
- Assess the risk to individuals
- Notify relevant regulatory authorities within required timeframes (typically 72 hours for high-risk breaches)
- Notify affected individuals when there is a high risk to their rights and freedoms
- Document the breach and remediation actions
- Implement measures to prevent recurrence
If you believe your data has been compromised, please contact us immediately at security@rateagent.io.
7. Data Protection Officer
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our data protection strategy and ensuring compliance with applicable laws.
The DPO's responsibilities include:
- Monitoring compliance with data protection laws
- Advising on data protection impact assessments
- Cooperating with regulatory authorities
- Serving as a point of contact for data subjects
You can contact our DPO at dpo@rateagent.io.
8. Complaints
If you have concerns about how we handle your personal data, we encourage you to contact us first so we can address your concerns directly.
If you are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection authority. In the UAE, this includes:
- UAE Data Office: For matters related to the Federal Personal Data Protection Law
- DIFC Commissioner of Data Protection: For data processed within DIFC
- ADGM Registration Authority: For data processed within ADGM
9. Contact Us
For any questions, concerns, or requests related to data protection, please contact us:
RateAgent.io Data Protection Team
Data Protection Officer: dpo@rateagent.io
For more information about how we collect and use your data, please see our Privacy Policy.
