Skip to content
PRIVACY · UAE PDPL

Privacy Policy

Effective 20 May 2026

This policy explains what personal data Propora.ae collects, why we collect it, how long we keep it, and the rights you have under the UAE Personal Data Protection Law (Federal Decree-Law 45/2021).

1. Who we are

Propora FZ-LLC ("Propora", "we") operates the property intelligence platform at propora.ae. We are the data controller for personal data described in this policy. You can contact our data protection officer at privacy@propora.ae.

2. Personal data we collect

Depending on how you use the platform, we collect the following categories of personal data:

  • Account dataName, email address, phone number (E.164 format), hashed password, profile photo, role (buyer / renter / advisor / landlord / vendor), preferred language and currency.
  • Identity & verification documentsWhere you choose to upload them: mortgage pre-approval letters (PDF), tenant verification documents, agent RERA broker card, agency trade licence, title deeds. Stored encrypted at rest and visible only to you and Propora staff with a verified business need.
  • Search & browsing dataSearches you run, listings you view, save, hide or compare, saved searches and alert preferences, filters applied, lifestyle preferences (commute, schools), recently viewed history.
  • Engagement dataListing views, viewing requests, enquiries sent to advisors, valuation requests, mortgage calculator usage, AI search conversations, content you publish (reviews, building Q&A answers).
  • Device & technical dataIP address, user-agent string, referrer URL, language and timezone headers, approximate country derived from IP, session identifiers, anonymised device fingerprint used by analytics + fraud detection.
  • Payment dataWhen you transact (gift orders, agency subscription, vendor onboarding) Stripe collects card details directly; Propora stores only the Stripe customer / payment intent identifier and the transaction amount.
  • Cookies & analyticsSee Section 7 on cookies and tracking technologies.

3. Why we collect it (lawful bases)

We collect data on the lawful bases defined by Article 5 of the UAE PDPL:

  • Performance of a serviceTo show you relevant listings, run AI search, calculate mortgage estimates, run property valuations, schedule viewings, process gift orders, and connect you with licensed third-party advisors.
  • Legitimate interestTo detect fraud, prevent abuse, run platform analytics on aggregated data, score listing quality, and improve the product.
  • ConsentFor non-essential analytics cookies, marketing emails, WhatsApp broadcasts, and any optional features clearly described as opt-in. Consent can be withdrawn at any time via your account settings.
  • Legal obligationTo comply with UAE law, RERA permit verification (Federal Law 6/2010 and Dubai Trakheesi requirements), DLD reporting, and Federal Tax Authority record-keeping where applicable.

4. How long we keep it

Retention periods reflect operational need + UAE legal minima:

  • Account data — until you delete your account, then erased within 30 days.
  • Enquiries and viewing requests — 24 months from creation (operational + dispute window). After 24 months the buyer's PII is anonymised; the agent's response-time metrics survive in pseudonymised form.
  • Saved searches, saved listings, hidden listings, recently viewed — until you delete them or your account.
  • Search & browsing telemetry — 18 months on a rolling basis, then aggregated into anonymous community-level metrics.
  • Mortgage pre-approval & tenant verification documents — 12 months from upload, encrypted at rest, deletable on request.
  • Audit and consent logs — 24 months (PDPL Article 12 records-of-processing obligation).
  • Tax invoices, agency subscription billing, transaction commission records — 5 years (Federal Decree-Law 8/2017, UAE Federal Tax Authority).

5. Who we share it with

Propora does not sell personal data. We share data only with:

  • Licensed UAE real estate agents you explicitly enquire with — limited to the contact + enquiry data needed to respond to you.
  • Mortgage lenders you request a quote from — limited to data you provide in the quote form.
  • Sub-processors we engage to run the platform, each bound by data-processing agreements: NextAuth identity providers (Google, LinkedIn) when you sign in via OAuth · Stripe (payments, Connect marketplace payouts, Stripe Tax) · Anthropic (Claude AI inference — listing insights, AI search, content moderation; no training on your data) · Cloudflare R2 (encrypted document + image storage) · Resend / SendGrid (transactional email) · Twilio / 360dialog (SMS, WhatsApp Business API) · Mixpanel and PostHog (product analytics, only with your opt-in consent) · Sentry (server error monitoring, scrubbed of personal data).
  • Vendors fulfilling an order you placed (Moving Day Gifts, Listing Media Services) — limited to the delivery and product information necessary for fulfilment.
  • Authorities and regulators when required by UAE law or a binding court order (RERA, DLD, FTA, UAE Data Office).

6. Where we store it

Personal data is hosted in the GCC region — primarily AWS me-south-1 (Bahrain), the closest available AWS region to the UAE. Encrypted backups are replicated to a second AWS region in the same compliance zone. A limited subset of operational data (e.g. Stripe payment metadata, NextAuth session tokens) may be processed by sub-processors in the EU or US under standard contractual clauses and the safeguards each provider is contractually bound to.

7. Cookies and tracking

We use two categories of cookies, with granular opt-in for the non-essential category (PDPL Article 7):

  • Strictly necessarySign-in session, currency preference, language preference, search context, consent record. Always active; you cannot opt out without breaking core platform functionality.
  • Analytics & product improvementMeasures aggregated, pseudonymised behaviour to improve search relevance and detect bugs. OFF by default; only activated if you opt in via the cookie banner. Provided by Mixpanel + PostHog.

Your consent decision is recorded in the propora_cookie_consent localStorage key on your device and is audit-logged server-side. You can change your choice at any time using the cookie reset link in the page footer.

You can change your choice at any time by clicking .

8. Your rights under UAE PDPL

As a data subject you can exercise these rights at any time, free of charge:

  • Article 7 — AccessRequest a copy of the personal data we hold about you.
  • Article 13 — CorrectionRequest that we fix any inaccurate or incomplete data.
  • Article 14 — Deletion (erasure)Request permanent deletion of your personal data. Available in-product via your account settings (which calls DELETE /api/account), or by emailing privacy@propora.ae. Pseudonymised audit records may be retained under Article 12 where required.
  • Article 16 — Data portabilityRequest your data in a structured, commonly used, machine-readable format (JSON export).
  • Article 17 — Objection to processingObject to processing based on legitimate interest, including profiling and personalised recommendations.
  • Withdraw consentAt any time, for any processing that relies on your consent.

We respond to verified requests within 30 days. If you are dissatisfied with our response you can complain to the UAE Data Office.

9. AI processing

Propora uses Anthropic's Claude family of models to generate listing insights, parse natural-language search queries, score listing quality, and translate buyer-to-agent enquiries. We never use your personal data to train Anthropic's models, and Anthropic does not retain prompts beyond the inference window. AI output is informational only and is not investment, legal or financial advice — see the Terms of Service.

10. Children

We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided personal data to Propora, contact us and we will delete it.

11. Security

Personal data is encrypted in transit (TLS 1.3) and at rest. Access to production data is limited to a small number of named engineers and is logged. Two-factor authentication is required for all advisor and admin accounts on paid subscription tiers. We do not disclose specific security controls publicly to reduce attack surface; high-level details are available on request to enterprise customers under NDA.

12. Changes to this policy

We may update this policy as the product evolves or the law changes. Material changes will be communicated by email to registered users at least 14 days in advance. The effective date at the top of this page always reflects the current version.

13. Contact

Data protection officer: privacy@propora.ae. Postal address: Propora FZ-LLC, Dubai Internet City, Dubai, UAE. The English version of this policy is the canonical legal text; localised versions are provided for accessibility and any conflict will be resolved in favour of the English text.