Privacy Policy
Last updated: 25 August 2026
PETPOOJA TECHNOLOGIES L.L.C (Registration No.: 2879659), a company established under the laws of the United Arab Emirates, having its registered office at Office No. 233F-1, Malik Khalid Mohammed Abda Al Zahed Building, Hor Al Anz, Dubai, United Arab Emirates (“we”, “us”, “our”), respects your privacy and is committed to protecting the Personal Information we handle in connection with the Petpooja point-of-sale software and related services (the “Services” as specified in Terms and Conditions of Services mentioned on insert link of TnC that we provide to Outlets in the United Arab Emirates.
This Privacy Policy explains how we collect, use, store, share and protect Personal Information in connection with the Services, and the rights available to individuals. It is issued in compliance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its Executive Regulations (the “PDPL”). This Privacy Policy forms part of, and should be read together with, our Terms and Conditions of Service (the “Terms”). Capitalised terms used but not defined here have the meaning given in the Terms.
By accessing or using the Services, or by providing Personal Information to us, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Services.
1. DEFINITIONS
In this Privacy Policy, unless the context requires otherwise:
- “Bureau / UAE Data Office” means the UAE Data Office established under Federal Decree-Law No. 44 of 2021, being the federal authority responsible for Personal Information protection in the United Arab Emirates.
- “Controller” means the person who, alone or jointly with others, determines the purposes and means of Processing Personal Information.
- “Cross-Border Processing” means the transmission, use, display, transfer, storage, sharing or Processing of Personal Information outside the United Arab Emirates.
- “Data Subject” means the identified or identifiable natural person to whom Personal Information relates.
- “Outlet Customer” means a customer, guest or other individual of an Outlet whose Personal Information is provided to, or captured through, the Services by the Outlet.
- “Personal Information” means any data relating to an identified natural person, or a natural person who can be identified directly or indirectly (for example, by reference to a name, voice, image, identification number, electronic identifier, location, or physical, physiological, economic, cultural or social characteristics). It includes Sensitive Personal Information.
- “Processing” means any operation performed on Personal Information, including collection, storage, recording, organisation, adaptation, alteration, retrieval, use, disclosure, transfer, restriction, erasure or destruction.
- “Processor” means the person who Processes Personal Information on behalf of, and under the instructions of, the Controller.
- “Sensitive Personal Information” means Personal Information that directly or indirectly reveals a person's family, racial or ethnic origin, political or philosophical opinions, religious beliefs, criminal record, biometric data, or data relating to health or physical, psychological, mental, genetic or sexual condition.
2. SCOPE OF THIS PRIVACY POLICY
- This Privacy Policy applies to Personal Information we Process in connection with the Services in the United Arab Emirates. It does not apply to the websites, applications or services of any third party, even where the Services link to or integrate with them.
- The PDPL does not apply to certain categories of data and entities (for example, data held by government or security and judicial authorities, and companies established in certain free zones that have their own Personal Information protection legislation).
3. PERSONAL INFORMATION WE COLLECT
We limit our collection of Personal Information to what is necessary for the purposes described in this Privacy Policy. Depending on how you use the Services, we may collect:
- Outlet account and identity data: name, email address, phone number, address, and login credentials (including username and password).
- Billing and subscription data: transaction and invoice records relating to the Subscription Fees and Paid Services you purchase from us. Please see the section titled “We Do Not Store Card Data” below.
- Usage and device data: information about how you access and use the Services, including IP address, device type and identifiers, browser type and language, operating system, log data, date/time stamps, and usage and performance analytics.
- Communications: records of your communications with us, including support queries, surveys, reviews and feedback.
- Outlet Customer data (processed on the Outlet's behalf): where an Outlet uses the Services, the Outlet may input or capture Personal Information relating to its Outlet Customers (for example, names, contact numbers, order history and reservation details). We Process such data only as a Processor on the Outlet's instructions, as explained below.
- Cookies and similar technologies: we and our service providers use cookies and similar technologies as described in our Cookie Policy (see the section titled “Cookies” below).
4. LEGAL BASIS FOR PROCESSING
We Process Personal Information only where we have a lawful basis under the PDPL. Depending on the circumstances, our lawful basis may be one or more of the following:
- Consent: where you have given consent to the Processing (which you may withdraw at any time, as described below);
- Performance of a contract: where Processing is necessary to perform the Terms or to take steps at your request before entering into them;
- Legal obligation: where Processing is necessary to comply with a legal obligation to which we are subject (for example, tax or record-keeping obligations); and
- Other lawful grounds: any other case permitted under Article 4 of the PDPL where Processing may be carried out without consent.
Where our Processing is based on your consent, you may withdraw that consent at any time by contacting us using the details in the “Contact Us” section. Withdrawing consent does not affect the lawfulness of Processing carried out before withdrawal, and may mean we are unable to continue providing some or all of the Services.
5. OUR ROLES: CONTROLLER AND PROCESSOR
- We are the Controller of the Personal Information relating to Outlets and the individuals who register for or administer an Outlet account (for example, names, phone numbers, email addresses and login credentials). For that data, we determine the purposes and means of Processing, and we are responsible for it under the PDPL as described in this Privacy Policy.
- We are a Processor in respect of the Personal Information of Outlet Customers that an Outlet inputs into, captures through, or otherwise Processes using the Services. For that data, the Outlet is the Controller and we Process it only on the Outlet's documented instructions and to provide the Services.
- Outlet responsibilities as Controller. Where an Outlet acts as Controller of Outlet Customer data, the Outlet is solely responsible for: (a) establishing a lawful basis for the Processing; (b) providing all required privacy notices to its Outlet Customers; (c) obtaining and maintaining all necessary consents (including for sharing that data with us and for any Cross-Border Processing); and (d) responding to Outlet Customer rights requests. The Outlet must not provide us with any Outlet Customer Personal Information unless it has obtained the appropriate consents and provided the appropriate notices required under the PDPL.
- Our obligations as Processor. When acting as a Processor, we will: Process Outlet Customer data only on the Outlet's instructions and for the purpose of providing the Services; apply appropriate technical and organisational measures to protect it; not disclose it except as authorised or required by law; and assist the Outlet, so far as reasonably practicable, in responding to Data Subject requests and meeting its PDPL obligations. On expiry or termination, or at the Outlet's request, we will erase or return Outlet Customer data in accordance with the Terms and this Privacy Policy, except where retention is required by law.
6. WE DO NOT STORE CARD DATA
We do not collect, store or retain full payment card numbers, card verification values (CVV/CVC) or other complete card credentials. Card payments are processed by third-party payment gateways and payment service providers, and your card data is captured and stored directly by those providers in accordance with their own terms and privacy policies and applicable card-scheme security standards. We receive only limited transaction information (such as confirmation of payment and reference details) necessary to administer your subscription. Your use of a payment gateway is subject to that provider's privacy policy, and we encourage you to review it. We are not liable for how such third party Processes your Personal Information.
7. HOW WE USE PERSONAL INFORMATION
As Controller, we use Personal Information for the following purposes:
- to register, administer and provide the Services to you, and to give effect to the Terms;
- to process your subscription, verify payments, and maintain transaction and invoice records;
- to provide customer and technical support and respond to your communications, queries and requests;
- to operate, maintain, secure, improve and develop the Services, including analytics and performance monitoring;
- to communicate with you about the Services, including service, security and administrative notices;
- to send you newsletters or promotional materials where you have opted in; you may unsubscribe at any time using the link in such communications or by contacting us;
- to comply with our legal and regulatory obligations, including for audit, record-keeping, tax and law-enforcement purposes; and
- to establish, exercise or defend legal claims, and to protect our rights, property and safety and those of others.
We may generate and use aggregated and/or anonymised data (which does not identify any individual) for analytics, benchmarking and to understand general market and usage trends. Once data is anonymised in accordance with the PDPL, it is no longer Personal Information.
8. HOW WE SHARE PERSONAL INFORMATION
We do not sell, rent or lease your Personal Information. We will not share or transfer your personally identifiable information to third parties, except as described in this Privacy Policy. We may share Personal Information with the following categories of recipients, subject to appropriate safeguards and only as permitted by the PDPL:
- Our group. Our parent company, Prayosha Food Services Private Limited (India), and our affiliates, which host and support the POSS Software and Services (see “Cross-Border Transfer of Personal Information” below).
- Service providers and sub-processors. Third parties that provide hosting, cloud storage, IT support, analytics, communications and customer-support tools, and payment processing, engaged to help us deliver the Services. Where they Process Personal Information on our behalf, we require them to apply appropriate protection consistent with the PDPL.
- Third-party integrations you enable. Where you choose to use or integrate a third-party service through the Services (for example, online ordering, delivery, loyalty or reservation providers), Personal Information may be shared with that third party. Such third parties act under their own privacy policies, over which we have no control, and we are not responsible for their Processing. You should review their privacy policies before enabling the integration. We are not responsible for the privacy policies of websites or services to which the services link. If you provide any information to such third parties, different rules regarding the collection and use of your personal information may apply. You should contact these entities directly if you have any questions about their use of the information that they collect.
- Legal and regulatory. Courts, regulators, government authorities or law-enforcement bodies, where disclosure is necessary to comply with Applicable Law, a legal process or an enforceable governmental request, or to protect our rights, property or safety.
- Corporate transactions. A successor entity or acquirer in connection with a merger, acquisition, reorganisation or sale of assets, subject to this Privacy Policy.
9. CROSS-BORDER TRANSFER OF PERSONAL INFORMATION
The POSS Software is hosted and maintained by our parent company, Prayosha Food Services Private Limited, in India. As a result, Personal Information (including Outlet account data and, where applicable, Outlet Customer data) may be transferred to, stored in and Processed in India, and may also be Processed by our service providers located outside the United Arab Emirates.
- We carry out such Cross-Border Processing only in accordance with Articles 22 and 23 of the PDPL. Where the destination country does not provide an adequate level of protection recognised by the Bureau, we rely on one or more of the following:
- Contractual safeguards: we put in place contracts or agreements that oblige the recipient to adopt the measures, controls and requirements set out in the PDPL; and/or
- Explicit consent: your explicit consent to the transfer of your Personal Information outside the United Arab Emirates, provided the transfer does not conflict with the public or security interest of the State; and/or
- Contractual necessity: where the transfer is necessary to perform the Terms between us and you, or a contract concluded in your interest.
- Where we act as Processor for Outlet Customer data, the Outlet, as Controller, is responsible for obtaining any explicit consent required from its Outlet Customers for such Cross-Border Processing. By using the Services, you consent to the Cross-Border Processing described in this section for the purpose of providing the Services to you.
10. RETENTION OF PERSONAL INFORMATION
We keep Personal Information only for as long as necessary to fulfil the purposes described in this Privacy Policy and to comply with our legal, regulatory, tax, accounting and record-keeping obligations or for the period which you have consented to. When Personal Information is no longer required, we will delete it or anonymise it in accordance with the PDPL. Retention, dormancy, suspension and deletion of Outlet Data are also governed by the Terms.
11. YOUR RIGHTS AS A DATA SUBJECT
- Subject to the conditions and exceptions in the PDPL, you have the following rights in respect of your Personal Information:
- Right to information and access: to be informed about, and to obtain, the categories of your Personal Information we Process, the purposes of Processing, recipients, retention criteria, and how to exercise your rights.
- Right to rectification: to have inaccurate Personal Information corrected and incomplete data completed.
- Right to erasure: to request deletion of your Personal Information where it is no longer necessary, where you withdraw consent, where you object to the Processing, or where it has been Processed unlawfully, subject to the exceptions in the PDPL.
- Right to restrict Processing: to request that we restrict Processing in certain circumstances while retaining the data.
- Right to data portability: to receive your Personal Information in an organised, machine-readable format, and to request its transfer to another Controller where technically feasible.
- Right to stop Processing: to object to and stop Processing carried out for direct marketing, statistical surveys, or in breach of the PDPL.
- Rights relating to automated Processing: to object to decisions based solely on automated Processing, including profiling, that have a legal or serious effect on you, subject to the exceptions in the PDPL.
- Right to withdraw consent: to withdraw consent at any time where Processing is based on consent.
- To exercise any of these rights, please contact us using the details in the “Contact Us” section. We will respond in accordance with the PDPL. In some cases we may be unable to fully action a request (for example, where we have a legal obligation or a statutory or contractual requirement to continue Processing). If you are an Outlet Customer, please direct your request to the relevant Outlet, which is the Controller of your data; we will support the Outlet in responding as required. You also have the right to lodge a complaint with the UAE Data Office.
12. SECURITY OF PERSONAL INFORMATION
We implement appropriate technical and organisational measures designed to protect Personal Information against loss, misuse, unauthorised access, disclosure, alteration and destruction, taking into account the nature of the data and the state of technology. These measures may include access controls, encryption or pseudonymisation where appropriate, secure hosting, firewalls and monitoring. We take appropriate steps to ensure data privacy and security, including through various hardware and software methodologies. However, we cannot guarantee the security of any information that is disclosed online. You agree that no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential and for all activity under your account, and you must notify us promptly of any suspected unauthorised use. Where a Personal Information breach occurs, we will notify the Bureau and affected Data Subjects where and to the extent required by the PDPL.
13. MINORS
The Services are intended for businesses and their authorised representatives. We do not knowingly collect Personal Information from individuals under the age of 18. If we become aware that we have inadvertently collected Personal Information from a minor, we will delete it promptly. If you believe a minor has provided us with Personal Information, please contact us.
14. COOKIES
We and our service providers use cookies and similar technologies to operate, secure and improve the Services, to authenticate users, and to understand usage. For details of the cookies we use, their purposes, and how you can manage your preferences, please see our separate Cookie Policy, available at https://www.petpooja.com/ae/cookie-policy. Our Cookie Policy forms part of this Privacy Policy.
15. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in the law, our practices, or the Services. We will post the updated version at https://www.petpooja.com/ae/privacy-and-policy and update the “Last updated” date above. Where changes are material, we will provide notice by email or through notifications or announcements on dash board/ website of Petpooja POS Software. Your continued use of the Services after the changes take effect constitutes your acknowledgement of the updated Privacy Policy. These Policies may be changed or updated occasionally to meet the requirements and standards. You are therefore encouraged to frequently visit these sections in order to be updated about the changes. Modifications will be effective on the day they are posted.
16. GOVERNING LAW
This Privacy Policy is governed by and construed in accordance with the laws of the United Arab Emirates as applied in the Emirate of Dubai, and the courts of Dubai shall have jurisdiction, subject to any dispute-resolution mechanism set out in the Terms.
17. CONTACT US
If you have any questions, concerns or requests regarding this Privacy Policy or your Personal Information, or to contact our Data Protection Officer, please use the details below:
Data Protection Officer / Privacy Contact: Apurv Patel
Email: compliance@petpooja.com
Address: Office No. 233F-1, Malik Khalid Mohammed Abda Al Zahed Building, Hor Al Anz, Dubai, United Arab Emirates
You also have the right to contact and lodge a complaint with the UAE Data Office (the Bureau).