Privacy Policy
Last Updated: 09/09/2026
On this page
- About this policy
- When we are the controller, and when we are not
- What information is involved
- Why we use it, and on what basis
- Your visit history
- Anonymised statistics, insights and artificial intelligence
- Who we share information with
- Where information is held, and transfers outside the UAE
- How long we keep information
- Your rights
- Children
- Cookies, analytics and advertising
- Marketing messages
- Security and personal data breaches
- Integrations, and decisions made automatically
- Which laws apply to us
- Changes to this policy
- Contact us
About this policy
MyGatePass FZ-LLC is a limited liability company registered under the Dubai Development Authority, company registration number 104344, with its registered office at In5 Tech, Dubai Internet City, Dubai, United Arab Emirates ("MyGatePass", "we", "us", "our").
This policy explains what happens to personal information when our services are used. It covers our websites, the Visitor App, the GateKeeper App, the Kiosk and Infopanel applications, the Admin Dashboard, our APIs and integrations, and the modules organisations enable, including visitor and contractor registration, permit management, gate and access management, automated number-plate recognition, notifications, reporting, and the school pick-up and dismissal module.
It sits alongside our Terms and Conditions, our Data Processing Agreement, which governs what we do with information on behalf of organisations, and our subprocessor list, which names every third party involved and the country in which each one operates.
The most important thing in this policy is the next section. Which of our two roles applies decides who you go to about your information, so it is worth thirty seconds.
When we are the controller, and when we are not
When an organisation uses MyGatePass at its site, that organisation decides what is collected about the people who come there, why, and for how long. In data protection terms it is the controller and we are its processor. We hold and handle that information on its documented instructions and we do not use it for our own purposes. Your rights over that information are exercised against the organisation, because it is the organisation that decides how the information is used, and it is responsible for telling you what it collects and on what legal basis. If you contact us about it, we will pass your request to the organisation and support it in responding. The terms on which we handle it are published in full in our Data Processing Agreement.
We are the controller in our own right for a narrower set of things: your MyGatePass account, your visit history in the Visitor App, your correspondence with our support team, our own security and platform monitoring, our billing and account records, and our marketing to people who have asked to hear from us. This policy governs those, and your rights in respect of them are exercised against us.
The distinction matters most in one situation. When you identify yourself at a site, two separate records are created. The organisation's record of your visit belongs to the organisation. Your own visit history, which the Visitor App keeps so that you can see where you have been, is held by us as controller in our own right. They are kept in separate systems, and deleting one has no effect on the other.
What information is involved
Held on behalf of an organisation, as its processor. What is collected depends on which modules and features are enabled for that organisation. It may include: your name and contact details, your employer, who you are visiting and why; an identity-document reference where that feature is enabled for the organisation; permit and contractor records; vehicle number plates, plate-to-person associations and, where number-plate recognition is used, the plate string read by the organisation's own recognition system and a read confidence score, but not vehicle or plate images, which we do not receive or store; entry and exit events with the time, the gate and the outcome; free-text notes written by the organisation's own staff; and audit records of changes. Where the school module is enabled it may also include student identity and class information, guardian records and authorisation to collect, release and dismissal records, and safeguarding flags and notes.
The full list is set out in Annex A of the Data Processing Agreement, which is exhaustive: anything not listed there is only processed if the organisation instructs it in writing.
Held by us, as controller. Your MyGatePass account name, email address and, if you provide one, mobile number. Your device and app information, including the push notification token used to deliver notifications to your device. Your visit history in the Visitor App. Technical information such as IP address, device identifier and session metadata. Support correspondence. Billing and account records for our customers. Where an optional location feature is enabled for an organisation, only the fact that a geofence was crossed, and never a location history.
Why we use it, and on what basis
For information we hold as a processor, the purpose and the legal basis are the organisation's, not ours, and it is responsible for both. We use that information only to provide the services, on the organisation's documented instructions.
For information we hold as controller:
| Purpose | Basis |
|---|---|
| Creating and running your MyGatePass account and providing the app | Performance of our contract with you, being our Terms and Conditions |
| Showing you your own visit history in the app | Performance of our contract with you, being our Terms and Conditions |
| Producing irreversibly anonymised, aggregated statistics and insights from visit histories, which we may publish or provide to others. We do not do this today, and we will update this page before we start | Our legitimate interests in understanding how our platform is used and in developing our services. You will be able to object at any time by emailing privacy@mygatepass.com, without deleting anything. The output of this process contains no personal information |
| Showing advertising in the Visitor App, and grouping accounts into broad audiences to decide which advertising is shown. The app carries no advertising today, and we will update this page before it does | Our legitimate interests in funding a service we give away, subject to every limit in the advertising section below: no sale, no sharing with advertising networks for their own purposes, no cross-app tracking, no individual targeting, no sensitive categories, and nothing we hold on behalf of an organisation. Applied identically to every account holder. You will be able to object, in which case advertising continues but is no longer chosen by reference to you. Where device identifiers or any third party are involved, your consent |
| Keeping the service secure, detecting and preventing abuse and fraud, and maintaining availability and reliability | Our legitimate interests in operating a secure service, and our obligations to the organisations we serve |
| Responding to your support requests | Performance of our contract with you, and our legitimate interests |
| Billing, accounting and company records | Compliance with UAE tax and company law |
| Sending you marketing messages | Your consent, withdrawable at any time and independently of anything else |
| Meeting a legal obligation, or responding to a lawful request from an authority | Compliance with law, on the terms in clause 8.6 of the Data Processing Agreement |
Your visit history
The Visitor App keeps a record of the places you have visited, so that you can see your own history. This is part of how the app works: it is created when you use MyGatePass to enter a site, and it is not something you have to switch on. We hold it as controller in our own right, separately from the organisation's own record of the same visit.
What it contains: the site you visited, the date and time, and your own MyGatePass account details.
What it does not contain: anything from the organisation's own record. No host, no reason for your visit, no permit or contractor detail, no vehicle plate, no record of whether you were admitted or refused, no notes written about you by anyone at the site, and no free text.
What we use it for today, and what we intend to use it for. Today your history is used for one thing: showing you your own history in the app. We intend to use it in two further ways, being anonymised aggregated statistics and, once advertising exists in the app, the broad audience groups described under "Cookies, analytics and advertising" below. Neither is running today, and we will update this page before either starts. When they do, you can tell us to stop, at any time, by emailing privacy@mygatepass.com. You will not need to give a reason, and you will not need to delete your profile, your history, or anything else in order to do it. We will stop and confirm within 30 days. Your history keeps working and entry to a site is unaffected either way.
Deleting it. You can delete your MyGatePass profile at any time in the app, and doing so deletes your visit history with it. Deleting yours has no effect on the organisation's own record of your visit, which is subject to that organisation's own retention decisions, and its record being deleted has no effect on yours.
Limits we hold ourselves to. Only account holders who have reached the age of majority have a visit history, because MyGatePass accounts are for adults. We do not attempt to re-identify anyone from the anonymised outputs, and we do not permit anyone else to.
Schools, and why none of this affects a pick-up record. Where a school uses our pick-up and dismissal module, the school's own record of every release is created and kept in the school's own account, as a complete and auditable trail. That record exists for safeguarding and audit, the school is its controller, and nothing in this section changes, limits, shortens or deletes it. This section is about the separate history we hold in our own right, which is a different thing.
Anonymised statistics, insights and artificial intelligence
Stated plainly, so that you can decide. We do not produce these statistics today. We intend to combine visit histories to produce statistics and insights, such as how busy sites are at different times of day, and we may publish those or provide them to others. This section sets out the limits that will apply when we do, and we will update this page before anything starts. Before anything leaves us it will be aggregated so that it does not identify you, does not identify any individual person, and does not describe any individual site. We apply minimum group sizes and suppress figures too small to publish safely. We do not attempt to re-identify anyone from those outputs, we do not permit anyone else to, and we require the same of anyone who receives them.
We do not sell your personal information.
An organisation's own record is never used commercially. We never use the information we hold on behalf of an organisation, being its own record of who came to its site, to produce statistics or insights or for any other commercial purpose. That applies to every organisation and every module equally, it is not something anyone has to ask for, and it is not something we will offer to vary.
And your own history is treated the same as everyone else's. We apply identical rules to every account holder, whatever kind of place you visited. We never group you by, or infer, anything sensitive from where you have been, meaning health, religion or belief, political opinion, racial or ethnic origin, sex life or sexual orientation, or trade union membership, and we keep any categorisation of places coarse enough that it cannot reveal one. That limit is absolute and we cannot vary it by agreement with anyone.
We do not use an organisation's own records for this at all. Those records belong to the organisation, and clause 5.2 of the Data Processing Agreement prohibits us from using them for market research, marketing or resale, from combining one organisation's data with another's, and from disclosing any insight from which an organisation or a person could be identified. An organisation can agree otherwise only by signing a separate addendum, and we will not offer one to a school.
Artificial intelligence. We use third-party AI services for our own internal work, such as triaging support tickets and engineering productivity, and in two product features. The first is the AI analysis panel in the administrator dashboard, which writes plain-language summaries of entry and visit activity for an organisation's own administrators. The second is document reading at the gate: where an identity document is presented and its machine-readable zone cannot be scanned, an image of the document is sent to an AI service so that its details can be read rather than typed in by hand. That image is used for that transaction and for nothing else, and the document may carry a photograph, which is read as part of the page rather than used to identify anyone. We perform no facial recognition, as set out below.
Where an organisation's information is involved, the AI service that receives it is named on our published subprocessor list, together with what it is used for, the categories of information it receives and the country in which it processes. We use an AI service for this only where we hold a written agreement with that provider which forbids training or improving models on the information and states how long the provider keeps it. The information sent is limited to what the analysis needs.
Some things are never sent to any AI service, and these cannot be varied by us, by notice, or by agreement with anyone: safeguarding and welfare notes; any information about a student or any other child; and any information belonging to a school using the pick-up and dismissal module.
We do not use anyone's information to train, fine-tune or improve any model, in any form, including in de-identified or aggregated form. That prohibition is absolute, applies to every provider we work with, and cannot be varied by agreement.
An organisation can switch it off. Any organisation can have all AI submission of its information disabled by asking us in writing, and that takes effect as a configuration change. Where a feature depends on an AI service, disabling it means the feature falls back to manual entry rather than disappearing.
Clause 5.3 of our Data Processing Agreement sets all of this out as a binding rule, and treats any submission outside it as a personal data breach.
We never use personal information to train, fine-tune or improve any machine-learning model, in any form, including de-identified or pseudonymised forms. That prohibition is absolute, is not limited in time, and cannot be varied by agreement.
Who we share information with
We share personal information with five categories of recipient, and no others.
The organisation whose site you are visiting. Where you identify yourself at a site, the record of that visit is the organisation's. It is not a disclosure by us so much as the organisation receiving its own information.
Our subprocessors, being the providers who help us run the service. Each one is named, with the country in which it processes information, the service it performs and the data it receives, in our subprocessor list, which is published. We give organisations notice before adding or replacing one, or before one changes the country in which it operates, with a right to object. Each is engaged under written terms no less protective than our own obligations, each is barred from using the information to train any model, and we remain liable to our customers for what they do.
Providers that help us run our own side of the service, meaning information we hold as controller rather than on an organisation's behalf. Today those are Sentry (Functional Software, Inc., United States), which receives crash and error diagnostics from our mobile applications with personal data masking enabled, and, on our websites only and only with your consent, Google Analytics 4, Google Ads, Meta Pixel and Microsoft Clarity. Those four are advertising and analytics providers which may also use what they receive for their own purposes under their own terms. That is precisely why they are set only if you consent, and why refusing costs you nothing. If we introduce advertising in the Visitor App, any provider involved will be named here before it starts.
Authorities, where the law requires it. We will not disclose information to any authority voluntarily. On receiving a request we require it to be in writing, legally valid and from an authority with jurisdiction, we review it with external counsel, we disclose only the minimum required, and we tell the affected organisation so that it can respond or challenge, unless we are legally prohibited from doing so. The one exception is a genuine and imminent threat to someone's life or safety, where we may disclose the minimum necessary immediately and will record it and inform the organisation as soon as we can. This is set out in clauses 8.6 and 8.7 of the Data Processing Agreement.
A buyer or successor, if our business or part of it is sold or reorganised, subject to the same protections continuing to apply.
We do not sell personal information. We never share what we hold on behalf of an organisation with anyone for advertising or analytics, and we do not share it with data brokers. On our own websites the advertising and analytics providers named above may use what they receive for their own purposes under their own terms, which is why none of them runs unless you consent.
Where information is held, and transfers outside the UAE
Personal information held on behalf of an organisation is stored in the United Arab Emirates, on enterprise cloud infrastructure, and the systems that process it are in the same country.
Some transfers outside the UAE do occur, and they are limited to specific supporting purposes: delivering push notifications to a device, sending transactional email, sending operational text messages to staff, support ticketing, crash diagnostics from our mobile applications, and the AI services described above, being the dashboard analysis panel and the reading of an identity document at the gate. The destinations include the European Economic Area, the United States and Australia. Where personal information is transferred outside the United Arab Emirates we rely on appropriate safeguards, which for organisations subject to the EU or UK GDPR are the Standard Contractual Clauses or the UK Addendum, incorporated in our Data Processing Agreement and taking effect without separate signature.
The detail is published, not rationed. Our subprocessor list names every party that processes personal information on our behalf, the country each processes in, what each receives and the minimisation applied. Organisations are notified in advance of any change, with a right to object.
Access to information held on behalf of an organisation is granted only to MyGatePass personnel whose normal place of work is the United Arab Emirates. Occasional access by an authorised person while travelling is from a managed device with multi-factor authentication and is logged. Before granting access to anyone whose normal place of work is outside the country, we give organisations at least 30 days' notice and they may object.
For transfers out of the UAE we rely on Article 23 of UAE Federal Decree-Law No. 45 of 2021, supported by contractual data protection clauses with each provider. Where an organisation is subject to the EU or UK GDPR, the transfer clauses in Annex F of the Data Processing Agreement apply, being the EU Standard Contractual Clauses and the UK Addendum, and they take effect without a separate signature.
How long we keep information
For information held on behalf of an organisation, the periods are set by us rather than left to discretion, and no category is held without a stated limit. They are not currently configurable by the organisation. Where a period runs from an event we are told about, such as the end of an enrolment or of a working relationship, we depend on the organisation telling us, and we say so rather than implying the platform always knows. The full schedule is Annex C of the Data Processing Agreement, and an organisation that needs a shorter period can ask us. The headline periods:
| Information | Default |
|---|---|
| Visitor and contractor records | 12 months |
| Vehicle or plate images | We do not receive or store them. Where an organisation's own cameras keep images, that is the organisation's own system and its own retention |
| Plate reads and geofence events | 30 days |
| Plate-to-person associations | Duration of the association, plus 30 days |
| Access and gate event records | Current calendar year plus 12 months |
| Free-text restriction and welfare notes | Duration of the underlying relationship. The organisation should review these at least annually and remove those no longer needed |
| Platform and telemetry logs | 90 days |
| Backups | Up to 90 days, after which residual copies expire |
For information we hold as controller:
| Information | Period |
|---|---|
| Your MyGatePass account | Until you close it, and in any event 12 months after last use |
| Your visit history in the Visitor App | Until you delete it or close your account, and in any event no longer than 24 months after each visit |
| Device push tokens | On uninstall or account closure, and in any event 180 days after last use |
| Technical data such as IP address and session metadata | 90 days |
| Support correspondence | 12 months |
| Billing and account records | As required by UAE tax and company law |
When a period expires the information is deleted rather than archived. Some audit records sit in an append-only store and cannot be deleted before their own period expires; where that applies we say so rather than implying otherwise.
Your rights
Depending on which of our two roles applies, and on the law that applies to you, you may ask to:
- access the personal information held about you, and receive a copy;
- have inaccurate information corrected;
- have information deleted;
- restrict or object to how information about you is used;
- receive information you gave us in a portable format;
- withdraw a consent you have given; and
- complain to a regulator.
Where to send the request. If it concerns information an organisation holds about your visit to its site, send it to that organisation, because the decisions are its own. If you send it to us we will pass it on and help the organisation answer, and we will not answer it ourselves beyond acknowledging it. If it concerns your MyGatePass account, your visit history, your support correspondence or our marketing, send it to us at privacy@mygatepass.com and we will respond within 30 days. Where a request is complex we may need longer, and we will tell you why and when to expect an answer.
Withdrawing consent. Where we rely on your consent you can withdraw it at any time, and withdrawing it is as easy as giving it. Withdrawing a consent and closing your account are different things, and you do not have to do one to achieve the other. You can withdraw a consent and carry on using the app, and you can close your account without withdrawing anything first. Withdrawal takes effect from the moment you withdraw and does not affect anything lawfully done before then. The same principle will apply to the right to object to the anonymised statistics and advertising audiences described above, once those exist. You exercise it by emailing us, not by deleting your account, and we will stop and confirm within 30 days. It does not affect statistics already produced, because those contain no personal information and cannot be traced back to you.
Where we no longer have your consent we may still keep or process some information where another basis requires or permits it, such as a legal obligation, the security of the service, or a record we must keep to show that you asked us to delete something. Where that applies we keep only what is needed, for only as long as it is needed.
Complaints. If you are not satisfied with how we have handled your information, please tell us first at privacy@mygatepass.com so that we have the chance to put it right. You can also complain to the UAE Data Office, established under UAE Federal Decree-Law No. 44 of 2021, or, where the EU or UK GDPR applies to you, to your own supervisory authority.
Children
MyGatePass accounts are not for children. You must have reached the age of majority in your country of residence to create one, and we do not knowingly collect personal information from a child through a MyGatePass account. We do not direct advertising to children and we do not use children's information for advertising or marketing.
Where an organisation records a visit by someone under the age of majority at its own site, or uses our school pick-up and dismissal module, that organisation is the controller of the information about that person. It decides what is collected, why, and on what basis, and it is responsible for any parental or guardian consent its own law requires. We handle that information only on its instructions, and our additional commitments for the school module are in Schedule 1 of the Data Processing Agreement.
If you believe a child has created a MyGatePass account, contact dpo@mygatepass.com and we will close it and delete the information.
Cookies, analytics and advertising
Our websites use cookies and similar technologies. Some are strictly necessary to make the site work and cannot be turned off. Others are used to understand how the site is used and to measure our advertising, and these are used only with your consent, which you give or refuse when you first visit and can change at any time.
The non-essential technologies currently in use on our websites are Google Analytics 4, Google Ads, Meta Pixel and Microsoft Clarity. Where you refuse consent, none of these is set and the site works normally.
The GateKeeper, Kiosk and Infopanel applications, used by our customers' staff and at their sites, carry no advertising and no advertising identifiers, and will not carry them in future.
The Visitor App carries no advertising today. We expect to introduce it, because advertising is how we intend to keep the app free, and we would rather set out now what that will and will not allow than describe it for the first time on the day it starts. Everything in this section is a commitment that applies if and when advertising begins, and we will update this page, and tell you in the app or by email, at least 30 days before it does.
What we may do, once it starts. Place your account in broad audience groups, based on things like the general kind of place you visit, the city or area you are in, how you use the app, and any interests you tell us about. Use those groups to decide which promotions or advertising you see inside our own app. Tell an advertiser how many people in a group saw something or responded to it.
What we will not do, then or now.
- We will not sell your personal information, and we will not pass it to advertising networks or data brokers for their own purposes.
- We will not track you across other apps or websites, and we do not use cross-app advertising identifiers.
- No advertiser receives anything that identifies you. They receive counts for a group. Never a name, a contact detail, an account, a device or a location.
- We will not build a group small enough to single you out. Every group has a minimum size, and we do not target an individual.
- We will not group you by, or target you on, anything sensitive: health, religion or belief, political opinion, racial or ethnic origin, sex life or sexual orientation, or trade union membership. Because the places a person visits can suggest those things, we keep the categories of place deliberately coarse and exclude any category that would reveal them.
- We will not touch what we hold on behalf of an organisation. That is the organisation's own record of who came to its site. It is not ours, and clauses 3.10 and 5.2 of our Data Processing Agreement forbid us using it commercially, for every organisation equally and with no ability to vary it.
- Everyone is treated the same. We apply these rules identically to every account holder, whatever kind of place you visited. We do not single anyone out, or exempt anyone, because of the organisation they went to see.
- We will not show targeted advertising to a child. A Visitor App account is for adults.
Using the app is a choice, and there is a way through the gate without it. A site's own staff can register you at the gate using the GateKeeper App, with no MyGatePass account, no visit history of your own, and none of the uses described in this section. It takes longer at the gate, and that is precisely what the Visitor App saves you. Once advertising exists, the convenience of the app will be funded by the information it holds about you being used as set out above. We would rather put that exchange in plain words now than present the app as free of any cost at all.
Once advertising exists, you can opt out of it being chosen by reference to you. Email privacy@mygatepass.com and we will stop within 30 days. You will still see advertising, chosen without reference to you. Nothing else changes: the app keeps working, your history is unaffected, and entry to any site is unaffected.
Our basis for it. For choosing what you see inside our own app, using the coarse first-party groups described above, we will rely on our legitimate interests in funding and improving a service we give away, balanced against every limit set out above, and we will complete and record that balancing exercise before anything starts. For anything that reads or stores identifiers on your device beyond what the app needs to function, or that involves any third party, we rely on your consent, and refusing costs you nothing. Under both UAE and European data protection law you have an unqualified right to object to processing for direct marketing, and we will always honour it.
Marketing messages
We send marketing messages, by email, SMS, WhatsApp or similar channels, only to people who have asked to receive them. Every message carries a way to stop them, and you can unsubscribe at any time in one step, without closing your account and without contacting us. Unsubscribing from marketing has no effect on service messages you need in order to use the app, such as a password reset, a security notice or a notification you have asked for.
Security and personal data breaches
We hold ISO/IEC 27001:2022 certification for our information security management system. A summary of the technical and organisational measures we operate is set out in Annex B of our Data Processing Agreement. Our certificate, scope statement, Statement of Applicability and the full Security Measures Description, which also names the controls we do not yet operate, are available to customers and prospective customers on request under an appropriate confidentiality arrangement. We do not publish that full description, because a detailed account of which controls are absent is of more use to an attacker than to a reader of this page.
If a personal data breach affects information we hold on behalf of an organisation, we notify that organisation without undue delay after becoming aware of it, and in any event within 72 hours. "Without undue delay" is the operative commitment; the 72 hours is an outer limit and not a period we are entitled to use. We make an initial notification as soon as we have enough information to be useful rather than waiting for a complete picture, we tell the organisation what we know and keep telling it as we learn more, and we assist it in meeting its own obligations. We do not notify a regulator or an affected individual about an organisation's information without that organisation's instruction, because that decision is the organisation's to make. Where we are the controller, we notify affected individuals and the regulator ourselves where the law requires it.
Integrations, and decisions made automatically
Integrations. Where an organisation connects MyGatePass to its own systems, we synchronise only the fields shown in the field mapping displayed in that organisation's account, and enabling the integration is the organisation's approval of that mapping. We do not add fields to a default mapping without notice. Integrations may include an organisation's own student information system, directory or calendar, and identity services where an organisation enables one, including UAE PASS, the UAE national digital identity service, from which we receive verified identity attributes when an individual authenticates. A system an organisation licenses directly is that organisation's own processor and not our subprocessor.
Automated decisions. Where an automated rule decides whether entry, access or a release is allowed, we version the rule set, we keep each version for as long as any decision made under it, and on request we can show which rule produced a given outcome and which version was in force. These decisions are deterministic and fail closed: if the system cannot confirm an authorisation, the answer is no. Where the decision concerns releasing a student, human verification at the gate and a staff override are permanent design features that we will not remove without the school's written consent. We will not introduce artificial intelligence or machine learning into any of these decisions without the organisation's prior written consent and a prior assessment shared with it.
We perform no facial recognition, no biometric identification or categorisation, no occupant or in-cabin imaging, no gait analysis and no emotion inference. Where a module reads number plates, it is designed to identify a vehicle rather than a person.
And if that ever changed. It could not happen quietly. We cannot enable any of it for an organisation by a configuration change, or by giving notice of a change to our agreement. It requires a separate agreement signed by us and by that organisation, which must record the lawful basis, a data protection impact assessment completed before anything is deployed, and an alternative for anyone who does not want to be enrolled, with further conditions where children are involved. We would update this policy before anything went live. The detailed conditions are set out in clause 5.4 of our Data Processing Agreement. We also do not use biometric data, images or templates to train or improve any model, and that prohibition cannot be varied by agreement with anyone.
Which laws apply to us
MyGatePass is established in the United Arab Emirates and is subject to UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. We are incorporated in the Dubai Development Authority free zone, which does not operate its own data protection regime, so the federal law applies rather than a DIFC or ADGM regime.
Where the EU GDPR or the UK GDPR applies to an organisation's own processing, our Data Processing Agreement is intended to satisfy the processor obligations of that instrument and includes the transfer clauses needed to support it. We apply the measures in Annex B of that agreement to every customer, whichever law applies to them.
Children and digital safety. UAE Federal Decree-Law No. 26 of 2025 on Child Digital Safety came into force on 1 January 2026 and applies to digital platforms operating in or directed at users in the United Arab Emirates. Its implementing Cabinet resolutions have not yet been issued. We have assessed how it reaches what we do. A MyGatePass account is for adults, we direct no advertising at children, and where a school uses our pick-up and dismissal module the school is the controller of the information about its students and decides what is collected and on what basis. We are following the implementing resolutions as they are published and will state here what changes for us.
Where our services are directed. MyGatePass is offered for use at sites in the United Arab Emirates, and the Visitor App exists to get you through a gate at one of them. We do not offer the service to people in the European Union or the United Kingdom in their own right. Where an organisation using MyGatePass is itself subject to the EU or UK GDPR, the position is as set out above.
We aim to state our position accurately rather than favourably. Where we have not yet done something, we say so.
Changes to this policy
We may update this policy. When we do, we will post the revised version on this page with a new date. Where a change materially affects your rights, we will give at least 30 days' notice before it takes effect, to organisations by notifying the account administrator and to app users in the app or by email. Amendments to the Data Processing Agreement are governed by its own clause 1.4 and its version archive at mygatepass.com/dpa-versions, rather than by this section.
Contact us
| Privacy and data protection requests | privacy@mygatepass.com |
|---|---|
| Data Protection Contact | dpo@mygatepass.com |
| Security and incident reports | security@mygatepass.com |
| Notices under the Data Processing Agreement | legal@mygatepass.com |
| General support | support@mygatepass.com |
| Post | MyGatePass FZ-LLC, In5 Tech, Dubai Internet City, Dubai, United Arab Emirates |