Home/Privacy Policy

Privacy Policy.

ZFM Trading is a brand of WILDADS - FZCO, a free zone company licensed in Dubai, United Arab Emirates. This is a static information website for business customers: we operate no user accounts, no advertising networks and no cross-site tracking, and we do not sell personal data. We measure how the site is used with a cookieless analytics service that stores nothing on your device and identifies no individual visitor. This policy explains the limited processing that does take place, the law we apply to it, and how you can exercise your rights.

Who is responsible.

The controller of your personal data is WILDADS - FZCO, DSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai, United Arab Emirates (trade licence no. 50066, issued by the Dubai Integrated Economic Zones Authority). Full company details are in the Legal Notice. Because we are established in a non-financial free zone of Dubai, we are subject to the federal data protection regime of the United Arab Emirates — Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) — and not to the separate regimes of the DIFC or ADGM. Since we also offer our products to business customers in the European Union, the EU General Data Protection Regulation applies in parallel to that activity under its Article 3(2), and this policy is written to meet both.

What we process, and why.

Hosting and server logs

The site is delivered from Vercel infrastructure in the Frankfurt (Germany) region. Standard access logs — IP address, date and time, the page requested, the referring address and a browser identifier — are processed to keep the site available and secure. Basis: our legitimate interest in operating and protecting the site (PDPL Art. 5; GDPR Art. 6(1)(f)). Logs are kept for no more than 30 days and are not combined with other data. From the same provider we also use Vercel Web Analytics, a cookieless measurement service. It records aggregate page views and a small number of interaction events — for example that the questionnaire was completed, the booking calendar was opened, or a WhatsApp or e-mail link was clicked — together with coarse technical data such as country, referring site, browser and device type. It sets no cookies, stores nothing on your device, builds no visitor profile and never follows you to other websites; the results are aggregated and cannot be traced back to you. Basis: our legitimate interest in understanding and improving the site (PDPL Art. 5; GDPR Art. 6(1)(f)). Because nothing is stored on or read from your device, § 25 TDDDG requires no consent for it.

Meeting bookings (Calendly)

Our Book a Meeting page and the final step of the distributor questionnaire embed the scheduling service Calendly LLC (United States). The calendar stays switched off until you actively click to load it. When you book, the details you provide — your name, your company name, your e-mail address, the time and time zone you choose, together with the answers you gave in the questionnaire (business type, target market, product categories and starting volume) — are transmitted to and processed by Calendly under its own privacy policy, and are received by us in Dubai. Basis: performance of a contract or steps taken at your request before entering one (PDPL Art. 5; GDPR Art. 6(1)(b)). We use these details solely to prepare and hold the meeting.

Direct contact

If you reach us by e-mail or WhatsApp, the information you share is used only to answer your request. Basis: steps taken before entering a contract, or our legitimate interest in responding to enquiries (PDPL Art. 5; GDPR Art. 6(1)(b) and (f)). Business correspondence is kept while the enquiry is being dealt with and afterwards for the periods required by the commercial record-keeping rules that apply to us. WhatsApp messages are processed by WhatsApp / Meta Platforms under its own terms.

Preferences

Your language choice and your acknowledgement of the storage notice are saved in your browser's localStorage. These values never leave your device and are not transmitted to us. They are strictly necessary to provide a function you asked for, so no consent is required — for visitors in Germany, § 25(2) TDDDG.

The law we apply.

We process personal data only where the law permits it. Under the UAE PDPL we rely on the grounds in Article 5 that allow processing without separate consent — performance of a contract to which you are a party, and our legitimate interests — and on your consent where we ask for it. For visitors in the European Union the corresponding GDPR bases are Article 6(1)(b) for contract and pre-contractual steps, Article 6(1)(f) for legitimate interests, and Article 6(1)(a) for consent. We ask for consent before the Calendly calendar is loaded; you can withhold it simply by not clicking, and withdraw it by leaving or reloading the page without loading the calendar.

How long we keep data.

Server access logs: no more than 30 days. Meeting bookings: held by Calendly for as long as our account with it exists, and by us for as long as the business relationship or the enquiry requires. E-mail and WhatsApp correspondence: while the enquiry is being handled and thereafter for the commercial record-keeping periods that apply to us. Local storage on your device: until you clear it in your browser. We do not keep personal data longer than the purpose for which it was collected requires.

How we protect data.

We apply technical and organisational measures proportionate to the limited data we handle: the site is served only over encrypted HTTPS connections with strict transport security; a restrictive content security policy limits what a browser may load; the site holds no database and runs no server-side code of its own; and access to our e-mail and booking accounts is limited to the people who need it. No transmission over the internet can be guaranteed absolutely secure, so we deliberately keep the amount of personal data we hold as small as possible.

Data breaches.

If a breach of personal data occurs that would prejudice your privacy, confidentiality or security, we will notify the UAE Data Office and, where the law requires it, the persons affected, without undue delay, in accordance with Article 9 of the PDPL. For visitors in the European Union the corresponding duties under Articles 33 and 34 GDPR apply.

Transfers of data across borders.

We are established in Dubai, so the personal data you send us — booking details and correspondence — is received and accessed in the United Arab Emirates. Calendly LLC and WhatsApp / Meta Platforms are established in the United States. Under the PDPL, personal data may leave the United Arab Emirates where the destination offers an adequate level of protection as determined by the UAE Data Office (Article 22), or, in the absence of such a determination, on one of the grounds in Article 23 — including where the transfer is necessary to conclude or perform a contract with the data subject. The UAE Data Office has not published a list of adequate jurisdictions, so we rely on that contractual ground, and we transfer only the data needed for the meeting you asked for. For visitors in the European Union these are transfers to third countries under Chapter V GDPR: there is no EU adequacy decision covering the United Arab Emirates, and we rely on Article 49(1)(b) GDPR, which permits an occasional transfer necessary for the performance of a contract concluded at the data subject's request. Where a recipient offers standard contractual clauses or an equivalent instrument, we use it. You may ask us at any time which safeguard applies to a particular recipient.

What we don't do.

We do not sell personal data, we do not run advertising or cross-site tracking, we do not build personal profiles of our visitors, and we do not carry out automated decision-making or profiling of the kind addressed by Article 18 of the PDPL and Article 22 GDPR.

Children.

This website is addressed to businesses — retailers, wholesalers and distributors — and not to children, even though part of the range we distribute is aimed at younger consumers. We do not knowingly collect personal data from children. If you believe a child has sent us personal data, write to us and we will delete it.

Your rights.

Under the UAE PDPL (Articles 13 to 18) you may ask us what personal data we hold about you and how we process it, ask for it to be corrected or erased, ask us to restrict or stop processing, object to processing, and ask for your data to be transferred to you or to another controller. Where processing rests on your consent, you may withdraw it at any time with effect for the future. Write to Fareed@mahaini.com and we will answer within the period required by the law and any regulations issued under it. If you are not satisfied with our response, you may complain to the UAE Data Office. Visitors in the European Union have the equivalent rights under Articles 15 to 21 GDPR and may also lodge a complaint with a data protection supervisory authority in their member state — in Germany, the authority of the federal state in which they live.

Our position in the European Union.

Article 27 GDPR requires a controller outside the European Union that offers goods or services to persons in the Union to designate a representative there, unless the processing is occasional, does not involve special categories of data on a large scale, and is unlikely to result in a risk to individuals. Our processing consists of short-lived server logs and the business contact details of people who ask us for a meeting. We consider that this falls within that exemption and have therefore not designated a representative. We keep the assessment under review and will designate one and name it here if the nature or scale of our processing changes. Until then, please address all data protection matters to Fareed@mahaini.com.

Changes.

We may update this policy as the website or legal requirements evolve. The current version is always published on this page.

Last updated: 13 August 2026