Supplier Portal Privacy Policy

Introduction

We are committed to protecting and respecting your privacy. This Privacy Notice (the “Notice”) governs the collection and use of personal data by Dubai Holding LLC. It explains how and why we use your personal data and applies to the personal data that you provide us directly, or which we may obtain from other sources.

We may use your personal data for any of the purposes described in this Notice, or as otherwise stated at the point of collection. For more information about Dubai Holding LLC please see www.dubaiholding.com.

References to "our", "us" or "we" within this Notice are to Dubai Holding LLC, Umm Suqeim Road
P.O. Box 66000, privacyoffice@dubaiholding.com.

Who We Are

The Dubai Holding LLC is the data controller of your personal data. We decide how and why your personal data is processed, either alone or jointly with others.

If you supply us with facilities and services, the entity which manages the relevant facility or service will also be a data controller in respect of your personal information. The data controllers of the following entities compose the ‘Data Controller List’ of Dubai Holding LLC: Dubai Holding Commercial Operations Group LLC, Dubai Holding Asset Management LLC, Dubai Holding Real Estate LLC, Dubai Holding Entertainment LLC, Dubai Holding Hospitality LLC. Further details of the ‘Data Controller List’ of each entity are available on the privacy notices of their respective websites. This will enable you to identify the relevant Dubai Holding LLC entity that holds, processes, and secures your personal data and is the data controller in relation to your personal data.

If you have any questions about this Notice, the use of your data, or would like to be directed to our Data Protection Officer, please contact privacyoffice@dubaiholding.com.

Information Covered By This Privacy Notice

In this notice we refer to “processing” your “personal data”.

Processing is taken to mean anything that is done to or with personal data (including simply collecting, storing, or deleting that data).

Personal data is any information relating to an identified or identifiable living person.  When “you” or “your” are used in this statement, we are referring to the relevant individual who is the subject of the personal data.

Cookies Policy

Where we use cookies, you can also control the data stored by cookies and withdraw consent to cookies by using the browser-based cookie controls described in our Cookie Policy available on our website https://dubaiholding.com/en/supplier-portal-cookie-policy/.

What We Collect From You And How We Use It

We process different categories of personal data to enable us to provide services to you, and as further described below.

Contact Details: Includes, but is not limited to, address, mobile number and email address, emergency contact number.

Identification data: Includes but is not limited to name, your photo, citizenship, nationality, passport data, Visa information, drivers' licence information, the resident country's ID, and education certificates, national/social insurance number (if applicable), health insurance, and tax reference/ID (if applicable) and digital signature.

Web Data: Includes, but is not limited to, cookies, user activity logs, and website visitor interaction data.

Financial Data: Includes, but is not limited to, card details and bank details.

Other Personal Information: Includes but is not limited to date and place of birth, emergency contact details, (if applicable

The reason these categories of personal data are processed, along with our lawful basis for doing so, are set out in the table below:

Personal Data Directly Obtained from You

Description of Processing Purpose for Processing Category of Personal Data Lawful Basis
We process your personal data for

procurement purposes, such as vendor

management and contract management.

Supporting Services Identification Data,

Contact Details, Financial

Data

Contract
We process your personal data for invoicing purposes Account Management

 

Identification data, Contact details, Financial data Legal Obligation
We process your personal data for management and audit of our business operations including accounting Financial Management, Operations,

Supporting Service

Identification data, Contact details, Financial data Legitimate Interests
We process your personal data for internal audit and risk management purposes Audit Purposes

 

Identification data, Contact details Legitimate Interests
We process your personal data to comply with legal requirements and exercise or defend legal claims. Audit Purposes,

Business Development,

Governance,

Litigation & Disputes,

Operations,

Supporting Service

Identification data, Contact details Legal Obligation
We process your personal data for security purposes and to ensure secure backup and archival of IT Systems Security Purposes

 

Identification data, Contact details Legitimate Interests
We process personal data for disaster recovery purposes Governance

 

Identification data, Contact details Legitimate Interests
We process your personal data for identifying, investigating, and mitigating incidents, such as if a personal data breach occurred Governance,

Security Purposes

Identification data, Contact details, Web data Legitimate Interests
We process your personal data for whistleblowing purposes Governance

 

Identification data, Contact details Legitimate Interests

Personal Data Indirectly Obtained from Others

To the extent necessary, we will also receive your personal data from other entities within the Dubai Holding LLC group of companies, including the Dubai Holding LLC subsidiaries and holding companies.

Legitimate Interest

Where we rely upon legitimate interest as a lawful basis, we have balanced your rights and freedoms against our interests, or those of any third parties, and determined your rights are not infringed. Legitimate Interest is where your personal data is processed for either our own interests or the interests of third parties. This can include commercial interests, individual interests, or broader societal benefits.

How Long Do We Keep Your Personal Data?

Your personal data will not be kept longer than necessary to meet the purposes detailed above. The criteria that we use to determine how long we will keep your personal data includes the period during which we have an ongoing relationship with you, and whether we have a legal obligation to store it (for example, for accounting purposes or for litigation, or regulatory investigations purposes).

Should retention of your personal data no longer be required we will remove it from our systems and records and/or take steps to properly anonymise it so that you can no longer be identified from it.

Who Do We Share Your Personal Data With?

Where necessary to fulfil the purposes described in this Notice, we shall disclose your personal data to certain third-parties, vendors and service providers or affiliated employees, contractors and entities as described below.

To the extent necessary, and where we have a lawful basis to do so, we will also share your personal data with other entities within Dubai Holding LLC’s group of companies, including Dubai Holding LLC’s subsidiaries and holding companies.

Where we share personal data, we do so with the following parties for the following purposes:

Category of Third-Party Purpose for Disclosure
Legal and Professional Advisers Audits, Invoicing, Legal Requirements
Finance, Insurance and Credit Providers Invoicing, Payment Processing
Government Bodies, Regulators Audits, Invoicing, Legal Requirements, Improving our Service
IT, Digital, Technology and Telecoms Audits, Analytics, Application Security and Support, Marketing

Where We Store/Transfer Your Personal Data

When processing your personal data, we may transfer this to third parties based in other countries, to the extent necessary to fulfil the purposes described in this Notice. Your personal data may be transferred within the Dubai Holding LLC’s group of companies, including the Dubai Holding LLC’s subsidiaries, and holding companies. Such transfers shall always be done in compliance with relevant data protection laws.

For transfers of personal data from the UK and European Economic Area (“EEA”) we transfer personal data to entities outside the EEA, under the EU Standard Data Protection Clauses. Further information about transfers can be obtained by contacting us using the following email address privacyoffice@dubaiholding.com.

To the extent required, we will also transfer your personal data to third parties in connection with a reorganization, restructuring, merger, acquisition, or transfer of assets, provided that the receiving party agrees to treat your personal data in a manner consistent with applicable laws and requirements.

Security of Personal Data

Dubai Holding LLC has implemented technology and operational security measures to protect personal data from loss, misuse, alteration, or destruction. Only authorised persons are provided access to personal data; such individuals have agreed to maintain the confidentiality of this personal data.

Your Rights

You have certain rights relating to your personal data. However, these rights can differ depending upon the country in which you are located. That country’s law will determine which rights apply and in what instances.

Right to withdraw consent

Where you have provided your consent to us, you will always have the right to withdraw this at any time. You can do this by either following the information provided at the time you provided your consent, or by contacting us using the following email address privacyoffice@dubaiholding.com. The withdrawal of consent will not affect any processing that was based on consent before its withdrawal.

Right to request correction of your personal data

You will always have the right to request that we correct any personal data that we process about you that is inaccurate or incomplete. You can do this by contacting us privacyoffice@dubaiholding.com

Right to request access to information

You have the right to be informed about what data is being processed and how it is being processed. You can do this by contacting us privacyoffice@dubaiholding.com

Right to restrict the processing of your personal data

You have the right to ask us to restrict, suspend or stop the processing of your data. You can do this by contacting us privacyoffice@dubaiholding.com

Right to request deletion of your personal data

You have the right to request for your personal data to be deleted. You can do this by contacting us privacyoffice@dubaiholding.com

It is important to understand that these rights are not absolute (e.g., their application may depend upon the Lawful basis we rely upon to process your personal data) and that we may require further information from you (e.g., to confirm your identity) to action your request.

European data protection rights

Where the General Data Protection Regulation applies, you are also provided with additional rights. This allows you, subject to certain conditions, to:

  • Upon request, be provided access to, or copies of, your personal data that we process;
  • Object to our processing of your personal data

You also have the right to lodge a complaint with the supervisory authority in your country of residence, place of work or the country in which an alleged infringement of data protection law has occurred within the EU.

Contacting Us

If you want to exercise any of the rights set out above or have any questions or concerns about how we treat your personal data, please contact us at privacyoffice@dubaiholding.com or by writing to us at: P.O. Box 66000, Dubai, United Arab Emirates. Please include your reply address when you write to us.

Changes To This Privacy Notice

We keep this Notice under regular review. We reserve the right, at our discretion, to change, modify, add, or remove sections of this Notice at any time. You are also encouraged to review this Notice from time to time for updates. We will notify you of any changes (including when they will take effect) if we are required to do so by data protection laws.