INTRODUCTION
East & West International Group - Sole Proprietorship - L.L.C. (“EWIG”, “we,” “us,” or “our”) is a real estate company providing property leasing, property management, valuation, and related services. For the personal data described in this Privacy Policy, EWIG acts as the data controller unless another entity is specifically identified at the point of collection. This means EWIG determines why and how personal data is processed through EWIG Website and EWIG mobile application (the “App”).
This Privacy Policy explains how we collect, use, disclose, transfer, retain and protect personal data and how individuals may exercise their privacy rights. It is intended for tenants, potential tenants, authorized representatives, website and App users, visitors, applicants, vendors, and other external stakeholders.
This Privacy Policy is intended to describe EWIG’s privacy practices in general terms. It does not create contractual rights, obligations or guarantees beyond those required by applicable law, nor does it constitute legal advice. This Policy should be reviewed periodically against the applicable UAE federal laws, Abu Dhabi regulatory requirements, and any sector-specific obligations that apply to EWIG’s actual services, systems, vendors and processing activities.
Our principal place of business is at:
Office #703,
7th Floor, Dusit Thani Complex – Offices Building,
Al Nahyan, Abu Dhabi, U.A.E.
CONTACT: ewig@ccsupport.ae
PHONE: 600 511122
We are committed to protect the privacy and security of our stakeholders’ personal information. This Privacy Policy outlines how we collect, use, store, and protect stakeholder data in compliance with UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection, Abu Dhabi data protection regulations, and international privacy standards & ADGM or DIFC data protection laws where relevant.
By using our website (www.eastandwest.ae), or Mobile App and services, you expressly consent to the terms outlined in this Privacy Policy.
SCOPE
This Policy applies when an individual visits or uses www.eastandwest.ae, the EWIG App or another digital platform that links to this Policy; enquires about, views, reserves, leases or manages property; enters a leasing or related transaction; attends a viewing, event or EWIG office; contacts us by telephone, email, chat, social media or portal; participates in KYC verification; applies for a vacancy; or acts for a vendor, contractor or business partner.
PRIVACY PRINCIPLES
| Principle | EWIG Commitment |
|---|---|
| Lawfulness, Fairness & Transparency | Use personal data only on a valid ground, in a fair manner and with clear notice. |
| Purpose Limitation | Collect data for specified, explicit and legitimate purposes and avoid incompatible reuse. |
| Data Minimization | Collect only data reasonably necessary for the service, transaction, or legal requirement. |
| Accuracy | Take reasonable steps to keep data accurate and enable correction. |
| Storage Limitation | Retain identifiable data only for an approved and justified period. |
| Security & Confidentiality | Apply proportionate technical and organizational safeguards. |
| Accountability | Maintain records, contracts, risk assessments, approvals, training, and evidence of compliance. |
INDIVIDUALS COVERED
- Prospective and existing landlords, tenants, lessee, and potential tenants.
- Occupants, guarantors, beneficiaries, beneficial owners, authorized signatories, and representatives.
- Users of EWIG websites, the App, portals, social media pages, and customer-support channels.
- Visitors attending offices, properties, viewings, events, or managed premises.
- Job applicants, referees, and candidates.
- Representatives and personnel of vendors, agents, developers, banks, advisers, Service Providers, and business partners.
- Any other party not specified above.
PERSONAL DATA WE COLLECT
We generally do not collect sensitive data unless required for a specific purpose and lawfully justified. We do not store sensitive financial data such as credit card numbers, CVV codes, or banking details. All financial transactions are securely processed through a UAE Central Bank verified payment gateway that maintains compliance with Payment Card Industry (PCI) data security standard (DSS).
Where collected, we will apply enhanced safeguards and legal bases. However, we may collect the following information (also we understand that these data may be changed from time to time, however, it exists as of the day it is being collected):
| Category | Examples |
|---|---|
| Identity and civil status | Name, title, date of birth, nationality, photograph, signature, marital status where relevant, passport, Emirates ID, visa, and residency information. |
| Contact and account | Address, email, telephone, user ID, login and authentication records, communication preferences. |
| Property interests and activity | Preferred property type, location, budget, search criteria, saved listings, enquiries, viewing schedule, and feedback. |
| Property ownership and tenancy | Ownership records, title deeds, tenancy history, lease, owner/tenant information, move-in/out details, access-card information, and property-management records. |
| Transaction and contract | Reservations, offers, memoranda, agency agreements, sale and purchase documents, tenancy contracts, invoices, receipts, commission, service requests, and transaction status. |
| Financial and payment | Bank details for authorized payouts, payment status, tokenized payment reference, proof of funds, source of funds or wealth and financial capability information where legally required. Full card data should be handled by an approved payment provider and not stored by EWIG unless expressly disclosed (bank statement and Etihad credit bureau report). |
| KYC and screening | Identity verification, beneficial ownership, politically exposed person status, sanctions and adverse-media screening results, risk rating, source-of-funds evidence, and compliance case records. |
| Professional and corporate | Employer, role, trade license, incorporation documents, corporate structure, authorized signatories, beneficial owners, and power of attorney. |
| Technical and device | IP address, device and browser type, operating system, App version, language, identifiers, authentication events, crash logs, security alerts, and network information. |
| Usage and analytics | Pages or screens viewed, searches, clicks, feature use, session activity, referral source, campaign interaction, and performance diagnostics. |
| Location | Approximate location from IP; precise device location only when enabled for a clearly described App feature. |
| Communications | Emails, messages, chats, call recordings where notified, enquiries, complaints, feedback, files, and support history. |
| Images, media, and premises security | Profile image, documents uploaded or scanned, property photographs/video/3D tours, CCTV footage, and visitor records. |
| Recruitment | CV, qualifications, employment history, references, right-to-work information, and interview records. |
| Sensitive personal data | Such as biometric verification, face recognition, health/accessibility information, criminal-record information, or other legally sensitive information, with enhanced controls. |
HOW WE COLLECT PERSONAL DATA (SOURCES OF PERSONAL DATA)
- Directly from the individual through registration, forms, enquiries, uploads, agreements, viewings, payments, surveys, support, or privacy requests.
- From an authorized representative, family member, employer, corporate client, landlord, lessee, tenant, guarantor, developer, referring broker, or property manager.
- From listing portals, social media platforms and advertising channels used by the individual to contact EWIG.
- From banks, payment processors, valuers, inspectors, maintenance providers, and transaction counterparties.
- From identity verification, KYC, sanctions, fraud-prevention, and screening providers.
- From public records, land/property registers, corporate registers, courts and government or regulatory authorities, where lawful.
- Automatically from websites, the App, devices, cookies, logs, security systems, Software Development Kit (SDK), and analytics tools.
PURPOSES AND LAWFUL GROUNDS
| Purpose | Typical Data | Ground / Condition |
|---|---|---|
| Respond to enquiries and match property requirements | Identity, contact, preferences, budget, communications | Steps requested before a contract; consent for optional marketing. |
| Create accounts and authenticate users | Identity, contact, account, device, and security data | Provide requested digital service; consent where required. |
| Arrange viewings and site access | Contact, property interest, schedule, ID, and access data | Requested service, contract steps, legal/security requirements. |
| Broker leases | Identity, property, contract, transaction, and representative data | Contract steps, performance of contract and legal obligations. |
| Manage properties and tenancies | Owner/tenant, lease, maintenance, access, payments, and communications | Contract and legal obligations. |
| Process payments and payouts | Transaction, payment status, bank/payout, and invoice data | Contract and legal/accounting obligations. |
| Perform KYC and fraud controls | Identity, corporate, beneficial owner, financial, screening and risk data | Legal obligations, public interest and defence of legal rights. |
| Provide customer support and resolve complaints | Contact, account, communications, transaction, and case data | Contract, legal obligations and consent where applicable. |
| Maintain security and prevent misuse | Device, access, logs, CCTV, communications, and security events | Legal obligations, protection of rights and permitted security purposes. |
| Improve services and digital performance | Usage, analytics, diagnostics, feedback, and aggregated results | Consent where required or another permitted ground. |
| Send service communications | Contact, account, transaction, push token and preferences | Necessary service communication and contract. |
| Send property marketing and recommendations | Contact, property interests, marketing preferences, and engagement | Prior consent where required; withdrawal available at any time. |
| Recruit personnel | Identity, contact, CV, qualifications, references and right-to-work | Steps requested by applicants, consent, and legal obligations. |
| Comply with authority requests and legal claims | Data relevant to the request, duty, investigation, or dispute | Legal obligations and establishment, exercise or defence of claims. |
EWIG will not process personal data for a new, incompatible purpose without providing appropriate notice and establishing valid legal ground. Where processing relies on consent, the consent request will be clear and separate where appropriate, and the user may withdraw consent without affecting processing carried out before withdrawal.
REAL ESTATE AND PROPERTY-SPECIFIC PROCESSING
- Property enquiries and matching: search criteria, budget, preferred communities, and engagement history may be used to identify relevant listings.
- Viewings and access: names, contact information, attendance times and identity verification may be required for owner, developer, building-management, or community security requirements.
- Leasing: relevant data may be exchanged among transaction parties, authorized brokers, developers, banks, trustees, registration bodies, and advisers to progress the transaction.
- Property management: owner, tenant, occupant, lease, rent, maintenance, access, complaint, and contractor records may be used to administer managed properties.
- Photographs and virtual tours: listing content should avoid unnecessary display of people, identity documents, or unrelated personal possessions. Removal or redaction requests will be assessed where EWIG controls the content.
- Community and building operations: necessary data may be shared for move-in/out, access cards, permits, maintenance, inspections, safety, and community compliance.
- Records: signed mandates, MOU, lease agreements, title/tenancy documents, invoices, and related communications are retained according to legal and business requirements.
- Disclaimer of third-party information accuracy: EWIG may receive information from landlords, owners, developers, portals, brokers, tenants and third parties. EWIG does not guarantee and shall not assume liability for inaccuracies originating from third parties except where required by applicable law.
KYC AND SANCTIONS COMPLIANCE
For transactions subject to customer due diligence or other financial crime controls, EWIG may verify identity, authority to act, beneficial ownership, transaction purpose, and risk indicators. EWIG may request supporting documents, perform ongoing monitoring, retain compliance evidence, and make reports or disclosures to competent authorities where required or permitted by law.
Access to KYC records is restricted to authorized personnel and approved providers. EWIG will not disclose whether a suspicious activity report has been made where such disclosure is prohibited. Individuals who do not provide mandatory information may be unable to proceed with a transaction or business relationship.
WEBSITES, MOBILE APP, COOKIES AND SDKS
EWIG digital services may use cookies, local storage, pixels, tags and mobile SDKs for essential operation, authentication, security, preference storage, crash reporting, analytics, communications, maps, and other disclosed functions. Optional analytics or advertising technologies will be controlled according to applicable consent requirements.
| Technology Category | Purpose | Control |
|---|---|---|
| Strictly necessary | Login, session, security, load balancing, and requested features | Required for service; cannot always be disabled within the service. |
| Preferences | Language, location, or display settings | User controls and browser/App settings. |
| Analytics and performance | Understand use, diagnose faults, and improve performance | Consent or other permitted ground; aggregation and minimization where practicable. |
| Marketing and attribution | Measure campaigns or personalize promotions | Activated only with required consent and preference controls. |
| Third-party functions | Maps, portals, chat, payment, or media functions | Provider disclosure, contract review, and just-in-time notice where appropriate. |
EWIG will maintain a current register of cookies and SDKs identifying provider, purpose, data fields, identifiers, retention, hosting location, sub-processors, and transfer mechanism. Digital store privacy declarations must match actual App behavior.
DEVICE PERMISSIONS AND LOCATION
- Camera or photo library: to scan or upload identity, property or transaction documents, profile content or property media selected by the user.
- Location: to show nearby properties, support map/search functions or validate a user-selected location feature. Precise or background location will not be used without clear disclosure and appropriate permission.
- Notifications: for accounts, viewing, transaction, security and service updates and separately controlled marketing.
- Biometric login: where enabled, the device operating system may perform verification. EWIG should not receive the biometric template unless expressly disclosed.
- Microphone, contacts, Bluetooth, or storage: requested only if a live feature requires it and explained before access.
- Facial recognition: facial recognition may be used only for identity verification, secure login, access control, or another clearly described feature. Biometric templates or facial recognition data will not be collected, stored, shared, or processed unless necessary, lawful, clearly disclosed, and protected by appropriate security controls.
Permissions can normally be changed through device settings. Refusal may limit the related feature but should not prevent unrelated services.
COMMUNICATIONS AND MARKETING
EWIG may send service messages relating to enquiries, viewings, accounts, transactions, security, property management, and support. Marketing communications, including property opportunities, market updates and personalized recommendations, will be sent in accordance with applicable law and user preferences. Every eligible marketing message will provide an unsubscribe or preference-management method. Opting out of marketing does not stop essential service or legal communications.
CCTV, CALLS AND PHYSICAL SITE SECURITY
CCTV may operate at EWIG offices or managed premises for safety, access control, asset protection, incident investigation, and legal compliance. Signage should identify monitored areas. Cameras must not be placed in areas where there is a high expectation of privacy. Access is restricted, disclosures are controlled and footage is retained only for the approved period unless required for an incident or legal matter.
Calls may be recorded for quality, evidence, training, compliance, or dispute management where the caller is notified and a lawful ground applies. Call recordings will be access-controlled and retained according to the approved schedule.
SHARING AND RECIPIENTS
- Lessee, tenants, guarantors, owners, occupants, and authorized representatives as necessary to progress a transaction.
- Developers, master developers, property portals, other authorized brokers, and referral partners.
- Property managers, building/community management, maintenance vendors, inspectors, valuers, and facilities providers.
- Banks, payment processors, trustees, insurers, and financial institutions.
- KYC, sanctions, identity verification, fraud-prevention, and compliance providers.
- Government departments, land/property registration bodies, regulators, courts, and law-enforcement authorities where legally required or permitted.
- Legal, audit, tax, and other professional advisers.
- Companies providing authorized shared services under access, confidentiality, and data-governance controls.
- Cloud hosting, CRM, communications, analytics, cyber security, document management, and support providers acting under contract.
- A proposed lessee or successor in a corporate transaction, subject to confidentiality and lawful due diligence.
EWIG does not sell or rent personal data. Personal data is not disclosed to an independent third party for its own marketing unless a lawful basis and required consent are in place and the user is informed, except for disclosure to internal and external lawyers for the purpose of claiming and defending in disputes and litigation process.
PROCESSORS AND VENDOR GOVERNANCE
Service providers processing personal data for EWIG are selected through risk-based due diligence and bound by written terms covering documented instructions, confidentiality, security, personnel access, sub-processors, international transfers, incident notification, audit/evidence support, data-subject rights, retention, return, and deletion. EWIG remains accountable for selecting and overseeing processors within its responsibility. EWIG’s liability for selecting and overseeing processors is only limited to the extent required under applicable law. Each processor remains independently responsible and liable for its own acts, omissions, breaches of contract and violations of applicable data protection laws.
INTERNATIONAL TRANSFERS
EWIG aims to process and store data in approved locations. Where personal data is transferred outside the UAE, EWIG will identify the destination, recipient, and purpose; assess the availability of an applicable adequacy basis or other permitted transfer condition; implement contractual, organizational and technical safeguards; restrict onward transfers; and maintain records of the assessment and mechanism. Information about relevant safeguards may be requested through the privacy contact, subject to legal and confidentiality limitations and to the limits permitted by the applicable laws.
DATA RETENTION AND DELETION
EWIG retains identifiable personal data only for as long as necessary for the stated purpose and applicable legal, regulatory, tax, accounting, property, contractual, security, dispute, and limitation requirements. Retention is based on documented schedules rather than a single period for all data.
| Record Type | Retention Approach |
|---|---|
| Enquiries and leads | Approved period based on activity, consent, business need, and suppression requirements. |
| Customer, property, and transaction records | Contract life plus the applicable legal, regulatory and claims period. |
| KYC records | Period mandated by applicable financial-crime laws and supervisory requirements. |
| Payment and accounting records | Applicable tax, accounting, audit, and legal period. |
| CCTV and access records | Short, documented security period unless required for an incident or legal hold. |
| Recorded calls and support cases | Approved quality, evidence, complaint, and legal period. |
| Digital logs and security events | Period proportionate to security monitoring, investigation, and compliance. |
| Marketing preferences | Until withdrawal, opt-out, expiry or account closure, with suppression evidence retained as needed. |
| Recruitment records | Recruitment cycle plus approved legal/consent period. |
| Backups | Deleted or de-identified through controlled backup-expiry cycles. |
When retention ends, data is securely deleted, anonymized or isolated where continued retention is legally required. A legal hold overrides routine deletion only for the relevant records and duration. However, EWIG may retain personal data to comply with legal, regulatory, accounting, audit, or record-keeping obligations, to establish, exercise or defend legal claims, for regulatory investigations, litigation holds, dispute resolution proceedings, or where otherwise required or permitted by applicable law.
SECURITY MEASURES
EWIG uses risk-based technical and organizational controls designed to protect personal data against unauthorized or unlawful processing and accidental loss, destruction, alteration, or disclosure. Controls may include encryption in transit and at rest where appropriate, role-based access, multifactor authentication, least privilege, secure configuration and development, API security, secrets management, vulnerability assessment and penetration testing, logging and monitoring, endpoint and network protection, backup and recovery, supplier assurance, awareness training, incident response and access reviews. EWIG may disclose relevant records where reasonably necessary to detect, prevent or investigate fraud, misuse, cybersecurity incidents, unlawful activity, or breaches of EWIG’s contractual or legal rights, to the extent permitted, required, or otherwise preserved by applicable law.
No internet or mobile service is completely risk-free. Users should use strong credentials, protect one-time codes, enable device protection, keep software current and report suspected compromise promptly.
DATA SUBJECT RIGHTS
Subject to the UAE PDPL, verification, applicable conditions and exemptions, an individual may request information and access; correction or completion; deletion; restriction or cessation of processing; transfer of eligible data in a structured format; objection to certain processing; withdrawal of consent; and review of certain automated processing.
- Submit a request to ewig@ccsupport.ae or through the designated App/website privacy channel.
- Describe the request and the relevant account, property, transaction, or communication.
- EWIG may request proportionate verification and evidence of authority for representatives.
- EWIG will search relevant systems, assess exceptions, coordinate processors, and respond within the legally applicable period.
- If a request is refused or limited, EWIG will explain the reason where legally permitted and provide complaint information.
AUTOMATED DECISION-MAKING AND PROFILING
EWIG may use limited profiling to match property preferences, prioritize enquiries, detect fraud, or personalize marketing. EWIG does not intend to make decisions producing legal or similarly significant effects solely by automated means unless the feature is specifically disclosed, a permitted legal condition applies and appropriate safeguards are provided, including human review where required. Individuals may object to profiling used for direct marketing.
CHILDREN’S PRIVACY
EWIG services and the App are not directed to individuals under 18. EWIG does not knowingly establish property transactions or digital accounts with children without an authorized parent, guardian or legal representative and an appropriate lawful basis. If personal data relating to a child is received, EWIG will apply enhanced minimization, access and verification measures and delete it when there is no lawful reason to retain it.
PERSONAL DATA BREACHES
EWIG maintains procedures to detect, report, assess, contain, investigate, and remediate personal data breaches. Incidents are documented and evaluated for notification to the competent authority and affected individuals where required. Processors must notify EWIG promptly under contract and preserve relevant evidence. Suspected compromise should be reported to ewig@ccsupport.ae and the designated support channel.
THIRD-PARTY PLATFORMS AND LINKS
EWIG websites, the App and property listings may link to or integrate with portals, maps, social media, payment gateways, identity services, or other third-party platforms. Where a third party independently determines its processing, its own privacy notice applies. EWIG will identify material integrations where practical, but users should review the third party’s notice before providing data.
CHANGES TO THIS POLICY
EWIG may update this Policy to reflect changes in law, services, technology, vendors, or processing. The current version and effective date will be displayed on the relevant website and App. Material changes will be communicated through an appropriate channel and renewed consent will be obtained where required.
CONTACT, REQUESTS AND COMPLAINTS
| Item | Details |
|---|---|
| Controller | East & West International Group - Sole Proprietorship - L.L.C. (EWIG) |
| Address | Office #703, 7th Floor, Dusit Thani Complex – Offices Building, Al Nahyan, Abu Dhabi, U.A.E. |
| Telephone | 600 511122 |
| Website | www.eastandwest.ae |
Individuals should first contact EWIG, so the request or concern can be investigated. They may also complain to the competent data protection authority where entitled to do so. Do not send passwords, one-time codes / passwords, or unnecessary identity documents by ordinary email.
This Policy shall be governed by and construed in accordance with the laws of the United Arab Emirates. Any dispute arising from or relating to this Policy shall be subject to the exclusive jurisdiction of the competent courts of Abu Dhabi, unless otherwise required by applicable law.
