Privacy Policy
Last Updated: 09/09/2026
On this page
- About this policy
- When we are the controller, and when we are not
- What information is involved
- Why we use it, and on what basis
- Your visit history
- Anonymised statistics, insights and artificial intelligence
- Who we share information with
- Where information is held, and transfers outside the UAE
- How long we keep information
- Your rights
- Children
- Cookies, analytics and advertising
- Marketing messages
- Security and personal data breaches
- Integrations, and decisions made automatically
- Which laws apply to us
- Changes to this policy
- Contact us
About this policy
MyGatePass FZ-LLC is a limited liability company registered under the Dubai Development Authority, company registration number 104344, with its registered office at In5 Tech, Dubai Internet City, Dubai, United Arab Emirates ("MyGatePass", "we", "us", "our").
This policy explains what happens to personal information when our services are used. It covers our websites, the Visitor App, the GateKeeper App, the Admin Dashboard, our APIs and integrations, and the modules organisations enable, including visitor and contractor registration, permit management, gate and access management, automated number-plate recognition, notifications, reporting, and the school pick-up and dismissal module.
It sits alongside our Terms and Conditions, our Data Processing Agreement, which governs what we do with information on behalf of organisations, and our subprocessor list, which names every third party involved and the country in which each one operates.
The most important thing in this policy is the next section. Which of our two roles applies decides who you go to about your information, so it is worth thirty seconds.
When we are the controller, and when we are not
When an organisation uses MyGatePass at its site, that organisation decides what is collected about the people who come there, why, and for how long. In data protection terms it is the controller and we are its processor. We hold and handle that information on its documented instructions and we do not use it for our own purposes. Your rights over that information are exercised against the organisation, because it is the organisation that decides how the information is used, and it is responsible for telling you what it collects and on what legal basis. If you contact us about it, we will pass your request to the organisation and support it in responding. The terms on which we handle it are published in full in our Data Processing Agreement.
We are the controller in our own right for a narrower set of things: your MyGatePass account, your visit history in the Visitor App, your correspondence with our support team, our own security and platform monitoring, our billing and account records, and our marketing to people who have asked to hear from us. This policy governs those, and your rights in respect of them are exercised against us.
The distinction matters most in one situation. When you identify yourself at a site, two separate records are created. The organisation's record of your visit belongs to the organisation. Your own visit history, which the Visitor App keeps so that you can see where you have been, is held by us as controller in our own right. They are kept in separate systems, they are not linked to each other, neither can be reconstructed from the other, and deleting one has no effect on the other.
What information is involved
Held on behalf of an organisation, as its processor. What is collected depends on which modules and features are enabled for that organisation. It may include: your name and contact details, your employer, who you are visiting and why; an identity-document reference where that feature is enabled for the organisation; permit and contractor records; vehicle number plates, plate-to-person associations and, where number-plate recognition is used, plate reads and vehicle images; entry and exit events with the time, the gate and the outcome; free-text notes written by the organisation's own staff; and audit records of changes. Where the school module is enabled it may also include student identity and class information, guardian records and authorisation to collect, release and dismissal records, and safeguarding flags and notes.
The full list is set out in Annex A of the Data Processing Agreement, which is exhaustive: anything not listed there is only processed if the organisation instructs it in writing.
Held by us, as controller. Your MyGatePass account name, email address and, if you provide one, mobile number. Your device and app information, including the push notification token used to deliver notifications to your device. Your visit history in the Visitor App. Technical information such as IP address, device identifier and session metadata. Support correspondence. Billing and account records for our customers. Where an optional location feature is enabled for an organisation, only the fact that a geofence was crossed, and never a location history.
Why we use it, and on what basis
For information we hold as a processor, the purpose and the legal basis are the organisation's, not ours, and it is responsible for both. We use that information only to provide the services, on the organisation's documented instructions.
For information we hold as controller:
| Purpose | Basis |
|---|---|
| Creating and running your MyGatePass account and providing the app | Performance of our contract with you, being our Terms and Conditions |
| Showing you your own visit history in the app | Performance of our contract with you, being our Terms and Conditions |
| Producing irreversibly anonymised, aggregated statistics and insights from visit histories, which we may publish or provide to others | Our legitimate interests in understanding how our platform is used and in developing our services. You can object at any time by emailing privacy@mygatepass.com, and you do not have to delete anything to do it. The output of this process contains no personal information |
| Keeping the service secure, detecting and preventing abuse and fraud, and maintaining availability and reliability | Our legitimate interests in operating a secure service, and our obligations to the organisations we serve |
| Responding to your support requests | Performance of our contract with you, and our legitimate interests |
| Billing, accounting and company records | Compliance with UAE tax and company law |
| Sending you marketing messages | Your consent, withdrawable at any time and independently of anything else |
| Meeting a legal obligation, or responding to a lawful request from an authority | Compliance with law, on the terms in clause 8.6 of the Data Processing Agreement |
Your visit history
The Visitor App keeps a record of the places you have visited, so that you can see your own history. This is part of how the app works: it is created when you use MyGatePass to enter a site, and it is not something you have to switch on. We hold it as controller in our own right, separately from the organisation's own record of the same visit.
What it contains: the site you visited, the date and time, and your own MyGatePass account details.
What it does not contain: anything from the organisation's own record. No host, no reason for your visit, no permit or contractor detail, no vehicle plate, no record of whether you were admitted or refused, no notes written about you by anyone at the site, and no free text. It is not linked to the organisation's record, and neither record can be rebuilt from the other.
Stopping the commercial use. Your history is also used to produce anonymised, aggregated statistics, described in the next section. You can tell us to stop, at any time, by emailing privacy@mygatepass.com. You do not need to give a reason, and you do not need to delete your profile, your history, or anything else in order to do it. We will stop and confirm within 30 days. Your history keeps working and entry to a site is unaffected either way.
Deleting it. You can delete your MyGatePass profile at any time in the app, and doing so deletes your visit history with it. Deleting yours has no effect on the organisation's own record of your visit, which is subject to that organisation's own retention decisions, and its record being deleted has no effect on yours.
Limits we hold ourselves to. Only account holders who have reached the age of majority have a visit history, because MyGatePass accounts are for adults. We do not attempt to re-identify anyone from the anonymised outputs, and we do not permit anyone else to.
Schools, and why none of this affects a pick-up record. Where a school uses our pick-up and dismissal module, the school's own record of every release is created and kept in the school's own account, as a complete and auditable trail. That record exists for safeguarding and audit, the school is its controller, and nothing in this section changes, limits, shortens or deletes it. This section is about the separate history we hold in our own right, which is a different thing.
Anonymised statistics, insights and artificial intelligence
Stated plainly, so that you can decide. We combine visit histories to produce statistics and insights, such as how busy sites are at different times of day, and we may publish those or provide them to others. Before anything leaves us it is aggregated so that it does not identify you, does not identify any individual person, and does not describe any individual site. We apply minimum group sizes and suppress figures too small to publish safely. We do not attempt to re-identify anyone from those outputs, we do not permit anyone else to, and we require the same of anyone who receives them.
We do not sell your personal information.
Nothing from a school is ever used commercially. We never use anything connected with a school's pick-up and dismissal module, and never any student, parent or guardian data, to produce statistics or insights, or for any other commercial purpose. That applies whether the data sits in the school's own record or in an individual's history, it is not something a school or an individual has to ask for, and it is not something we will offer to vary.
We do not use an organisation's own records for this at all. Those records belong to the organisation, and clause 5.2 of the Data Processing Agreement prohibits us from using them for market research, marketing or resale, from combining one organisation's data with another's, and from disclosing any insight from which an organisation or a person could be identified. An organisation can agree otherwise only by signing a separate addendum, and we will not offer one to a school.
Artificial intelligence, precisely. We use third-party AI services for our own internal tooling. We do not submit personal information held on behalf of an organisation to any AI service, with one exception, which we disclose rather than leave to be found: text originating in a support ticket may be submitted for triage and summarising after an automated step has removed identifying information. An organisation can ask us in writing to switch that step off for its own tickets. We treat any submission of an organisation's personal information to an AI service as a personal data breach.
We never use personal information to train, fine-tune or improve any machine-learning model, in any form, including de-identified or pseudonymised forms. That prohibition is absolute, is not limited in time, and cannot be varied by agreement.
Who we share information with
We share personal information with four categories of recipient, and no others.
The organisation whose site you are visiting. Where you identify yourself at a site, the record of that visit is the organisation's. It is not a disclosure by us so much as the organisation receiving its own information.
Our subprocessors, being the providers who help us run the service. Each one is named, with the country in which it processes information, the service it performs and the data it receives, at mygatepass.com/subprocessors. We give organisations at least 30 days' notice before adding or replacing one, or before one changes the country in which it operates. Each is engaged under written terms no less protective than our own obligations, each is barred from using the information to train any model, and we remain liable to our customers for what they do.
Authorities, where the law requires it. We will not disclose information to any authority voluntarily. On receiving a request we require it to be in writing, legally valid and from an authority with jurisdiction, we review it with external counsel, we disclose only the minimum required, and we tell the affected organisation so that it can respond or challenge, unless we are legally prohibited from doing so. The one exception is a genuine and imminent threat to someone's life or safety, where we may disclose the minimum necessary immediately and will record it and inform the organisation as soon as we can. This is set out in clauses 8.6 and 8.7 of the Data Processing Agreement.
A buyer or successor, if our business or part of it is sold or reorganised, subject to the same protections continuing to apply.
We do not sell personal information, and we do not share it with data brokers or advertising networks for their own purposes.
Where information is held, and transfers outside the UAE
The platform is in the United Arab Emirates. All stores of personal information held on behalf of organisations, being the databases, file and image storage, backups, any image store and the audit store, are provisioned in Microsoft Azure UAE North, with backup replication to Microsoft Azure UAE Central. The compute that processes that information and the log workspace holding its telemetry are in the same regions.
Some supporting services operate outside the UAE, and we would rather say so than let you find out. Push notifications are delivered through Apple and Google infrastructure that is globally distributed, carrying only a device token and a message that contains an opaque reference and no personal content. Transactional email is processed in the European Union. Operational SMS and one-time passcodes to staff are delivered from Australia. Support ticketing is currently hosted outside the UAE by our provider as a temporary continuity measure following the regional cloud disruption in March 2026, and we are confirming the current region and the date of return in writing. Our own engineering environment, which holds our source code and no customer information, is in West Europe.
The subprocessor list states the country for each of these, and what each receives. Certain Microsoft Azure services also involve global control-plane and service-management processing that Microsoft operates across regions, and we cannot promise more about that platform layer than Microsoft does in its own data protection addendum.
No personal information held on behalf of an organisation is accessible to MyGatePass personnel located outside the United Arab Emirates.
For transfers out of the UAE we rely on Article 23 of UAE Federal Decree-Law No. 45 of 2021, supported by contractual data protection clauses with each provider. Where an organisation is subject to the EU or UK GDPR, the transfer clauses in Annex F of the Data Processing Agreement apply, being the EU Standard Contractual Clauses and the UK Addendum, and they take effect without a separate signature.
How long we keep information
For information held on behalf of an organisation, the periods are set by us and enforced automatically by deletion, so that nothing is retained without a limit. They are not currently configurable by the organisation, and we publish them rather than leaving them to discretion. The full schedule is Annex C of the Data Processing Agreement, and an organisation that needs a shorter period can ask us. The headline periods:
| Information | Default |
|---|---|
| Visitor and contractor records | 12 months |
| Vehicle images captured by number-plate recognition | 30 days, the shortest period of any category |
| Plate reads, plate-to-person associations, geofence events | 30 days |
| Access and gate event records | Current calendar year plus 12 months |
| Free-text restriction and welfare notes | Duration of the underlying relationship. The organisation should review these at least annually and remove those no longer needed |
| Platform and telemetry logs | 90 days |
| Backups | Up to 90 days, after which residual copies expire |
For information we hold as controller:
| Information | Period |
|---|---|
| Your MyGatePass account | Until you close it, and in any event 12 months after last use |
| Your visit history in the Visitor App | Until you delete it or close your account, and in any event no longer than 24 months after each visit |
| Device push tokens | On uninstall or account closure, and in any event 180 days after last use |
| Technical data such as IP address and session metadata | 90 days |
| Support correspondence | 12 months |
| Billing and account records | As required by UAE tax and company law |
When a period expires the information is deleted rather than archived, and deletions are logged. Some audit records sit in an append-only store and cannot be deleted before that store's period expires; where that applies we say so rather than implying otherwise.
Your rights
Depending on which of our two roles applies, and on the law that applies to you, you may ask to:
- access the personal information held about you, and receive a copy;
- have inaccurate information corrected;
- have information deleted;
- restrict or object to how information about you is used;
- receive information you gave us in a portable format;
- withdraw a consent you have given; and
- complain to a regulator.
Where to send the request. If it concerns information an organisation holds about your visit to its site, send it to that organisation, because the decisions are its own. If you send it to us we will pass it on and help the organisation answer, and we will not answer it ourselves beyond acknowledging it. If it concerns your MyGatePass account, your visit history, your support correspondence or our marketing, send it to us at privacy@mygatepass.com and we will respond.
Withdrawing consent. Where we rely on your consent you can withdraw it at any time, and withdrawing it is as easy as giving it. Withdrawing a consent and closing your account are different things, and you do not have to do one to achieve the other. You can withdraw a consent and carry on using the app, and you can close your account without withdrawing anything first. Withdrawal takes effect from the moment you withdraw and does not affect anything lawfully done before then. The same principle applies to the right to object to the anonymised statistics described above. You exercise it by emailing us, not by deleting your account, and we will stop and confirm within 30 days. It does not affect statistics already produced, because those contain no personal information and cannot be traced back to you.
Where we no longer have your consent we may still keep or process some information where another basis requires or permits it, such as a legal obligation, the security of the service, or a record we must keep to show that you asked us to delete something. Where that applies we keep only what is needed, for only as long as it is needed.
Complaints. If you are not satisfied with how we have handled your information, please tell us first at privacy@mygatepass.com so that we have the chance to put it right. You can also complain to the UAE Data Office, established under UAE Federal Decree-Law No. 44 of 2021, or, where the EU or UK GDPR applies to you, to your own supervisory authority.
Children
MyGatePass accounts are not for children. You must have reached the age of majority in your country of residence to create one, and we do not knowingly collect personal information from a child through a MyGatePass account. We do not direct advertising to children and we do not use children's information for advertising or marketing.
Where an organisation records a visit by someone under the age of majority at its own site, or uses our school pick-up and dismissal module, that organisation is the controller of the information about that person. It decides what is collected, why, and on what basis, and it is responsible for any parental or guardian consent its own law requires. We handle that information only on its instructions, and our additional commitments for the school module are in Schedule 1 of the Data Processing Agreement.
If you believe a child has created a MyGatePass account, contact dpo@mygatepass.com and we will close it and delete the information.
Cookies, analytics and advertising
Our websites use cookies and similar technologies. Some are strictly necessary to make the site work and cannot be turned off. Others are used to understand how the site is used and to measure our advertising, and these are used only with your consent, which you give or refuse when you first visit and can change at any time.
The non-essential technologies currently in use on our websites are Google Analytics 4, Google Ads, Meta Pixel and Microsoft Clarity. Where you refuse consent, none of these is set and the site works normally.
Our apps are different. The Visitor App and the GateKeeper App carry no advertising and no advertising identifiers, and we do not use them to build profiles for advertising.
Marketing messages
We send marketing messages, by email, SMS, WhatsApp or similar channels, only to people who have asked to receive them. Every message carries a way to stop them, and you can unsubscribe at any time in one step, without closing your account and without contacting us. Unsubscribing from marketing has no effect on service messages you need in order to use the app, such as a password reset, a security notice or a notification you have asked for.
Security and personal data breaches
We hold ISO/IEC 27001:2022 certification for our information security management system. Our certificate, scope statement and Statement of Applicability are available to customers on request. The technical and organisational measures we operate are set out in full in Annex B of the Data Processing Agreement, including, unusually for a published document, the measures we have not yet independently evidenced and the gaps we have not yet closed. We publish that because a customer finding out later is worse for everyone.
If a personal data breach affects information we hold on behalf of an organisation, we notify that organisation without undue delay after becoming aware of it, and in any event within 72 hours. "Without undue delay" is the operative commitment; the 72 hours is an outer limit and not a period we are entitled to use. We make an initial notification as soon as we have enough information to be useful rather than waiting for a complete picture, we tell the organisation what we know and keep telling it as we learn more, and we assist it in meeting its own obligations. We do not notify a regulator or an affected individual about an organisation's information without that organisation's instruction, because that decision is the organisation's to make. Where we are the controller, we notify affected individuals and the regulator ourselves where the law requires it.
Integrations, and decisions made automatically
Integrations. Where an organisation connects MyGatePass to its own systems, we synchronise only the fields shown in the field mapping displayed in that organisation's account, and enabling the integration is the organisation's approval of that mapping. We do not add fields to a default mapping without notice. Integrations may include an organisation's own student information system, directory or calendar, and and identity services where an organisation enables one, including UAE PASS, the UAE national digital identity service, from which we receive verified identity attributes when an individual authenticates. A system an organisation licenses directly is that organisation's own processor and not our subprocessor.
Automated decisions. Where an automated rule decides whether entry, access or a release is allowed, we version the rule set, we keep each version for as long as any decision made under it, and on request we can show which rule produced a given outcome and which version was in force. These decisions are deterministic and fail closed: if the system cannot confirm an authorisation, the answer is no. Where the decision concerns releasing a student, human verification at the gate and a staff override are permanent design features that we will not remove without the school's written consent. We will not introduce artificial intelligence or machine learning into any of these decisions without the organisation's prior written consent and a prior assessment shared with it.
We perform no facial recognition, no biometric identification or categorisation, no occupant or in-cabin imaging, no gait analysis and no emotion inference. Where a module reads number plates, it is designed to identify a vehicle rather than a person. We will not introduce any such capability without the organisation's prior written consent, and doing so would be a material breach of our own agreement.
Which laws apply to us
MyGatePass is established in the United Arab Emirates and is subject to UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. We are incorporated in the Dubai Development Authority free zone, which does not operate its own data protection regime, so the federal law applies rather than a DIFC or ADGM regime.
Where the EU GDPR or the UK GDPR applies to an organisation's own processing, our Data Processing Agreement is intended to satisfy the processor obligations of that instrument and includes the transfer clauses needed to support it. We apply the measures in Annex B of that agreement to every customer, whichever law applies to them.
We aim to state our position accurately rather than favourably. Where we have not yet done something, we say so.
Changes to this policy
We may update this policy. When we do, we will post the revised version on this page with a new date. Where a change materially affects your rights, we will give at least 30 days' notice before it takes effect, to organisations by notifying the account administrator and to app users in the app or by email. Amendments to the Data Processing Agreement are governed by its own clause 1.4 and its version archive at mygatepass.com/dpa-versions, rather than by this section.
Contact us
| Privacy and data protection requests | privacy@mygatepass.com |
|---|---|
| Data Protection Contact | dpo@mygatepass.com |
| Security and incident reports | security@mygatepass.com |
| Notices under the Data Processing Agreement | legal@mygatepass.com |
| General support | support@mygatepass.com |
| Post | MyGatePass FZ-LLC, In5 Tech, Dubai Internet City, Dubai, United Arab Emirates |