HBS PRIVÉ · PRIVACY
Privacy notice
This notice explains how HBS Privé collects, uses, shares and protects personal data when you visit our website, use your online client space, make an enquiry, book or rent a safe deposit box at one of our branches in Dubai. It is written to meet the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, the “PDPL”).
Version hbs-privacy-2026-v1 · Last updated 1 October 2026
Who is responsible for your data
The controller of your personal data is the HBS Privé company that operates the branch you contact, book with or rent from:
- JLT branch: HBS PRIVE DMCC, Goldcrest View 1, G/F, Unit R01B, Cluster V, Jumeirah Lake Towers, Dubai, United Arab Emirates (TRN 100575881600003).
- Business Bay branch: HBS PRIVE SAFETY DEPOSIT VAULTS RENTING L.L.C, Building No 8 Shop G03, Bay Square, Business Bay, Dubai, United Arab Emirates (TRN 104193932100003).
- Deira branch: HBS PRIVE SAFETY DEPOSIT VAULTS RENTING L.L.C (Branch), Emaar Towers, ET1-G-S6, Deira, Dubai, United Arab Emirates (TRN 104193932100003).
When you use the website or the client space before choosing a branch, HBS PRIVE SAFETY DEPOSIT VAULTS RENTING L.L.C is the controller. The HBS Privé companies use one shared platform and may use the same client record to serve you at more than one branch.
For any privacy question or request, write to [email protected].
The data we collect
- Identity data: full name, nationality, date of birth, Emirates ID or passport details and copies, and your photograph. We need them to verify who you are before you rent or access a safe.
- Contact data: email address, phone and WhatsApp number, postal address and preferred language.
- Rental and account data: branch, safe size and number, rental term and dates, signed agreements and forms, authorised persons, appointments, messages and requests.
- Payment data: invoices, receipts, payment status, amounts and references. Card payments are processed by Stripe; we do not see or store your full card number.
- Branch access and security records: visit and access logs, key handovers and, where the branch uses biometric entry, biometric data (such as a fingerprint template) used to control entry to the vault.
- CCTV images: our premises are monitored by CCTV for security.
- Technical data: sign-in and security events, device and browser information, and IP addresses in server logs, used to keep the service secure.
- Website analytics and campaign data: only with your consent (see “Cookies and analytics”).
We do not ask for, or keep, a list of what you store in your safe.
Why we use your data and our legal basis
- To enter into and perform your rental agreement: onboarding, reservations, invoices, payments, renewals, access to your safe, surrender and support (performance of a contract).
- To meet our legal obligations, including UAE anti-money laundering and counter-terrorist financing rules (customer due diligence and KYC, record keeping and reporting), tax (VAT) and accounting rules, and lawful requests from authorities (legal obligation).
- To protect our clients, staff and premises, prevent fraud and misuse, keep our systems secure, and establish or defend legal claims (our legitimate interests, balanced against your rights).
- To send you service messages such as invoices, payment confirmations and renewal reminders (performance of a contract and legitimate interests).
- To measure our campaigns and the use of our website, and to send you marketing messages (your consent, which you can withdraw at any time).
Identity and biometric data are used only to verify your identity and to control access at the branch.
Who receives your data
- Our staff, according to their role and branch. Their access is logged.
- Hosting: the platform runs on a server located in the United Arab Emirates.
- Stripe, which processes online card payments.
- Cloudflare, which delivers our emails and provides DNS and content delivery services that protect and deliver the website.
- Google (Google Tag Manager and Google Analytics), only if you consent to analytics.
- Professional advisers such as auditors, lawyers and insurers, who are bound by confidentiality.
- Government, regulatory, judicial and law enforcement authorities, when the law requires it.
We do not sell your personal data.
International transfers
Stripe, Cloudflare and Google may process some of your data outside the UAE. We only use providers that apply appropriate safeguards, such as contractual data protection commitments and security measures, and we share only what each service needs, as permitted by the PDPL.
How long we keep your data
- Identity (KYC) documents, rental agreements, and transaction and payment records: for at least 5 years after the end of our business relationship, as required by UAE anti-money laundering rules, or longer where the law or an ongoing claim requires it. Tax records are also kept for the period required by UAE VAT law.
- CCTV recordings and branch access logs: for the period set by the branch security policy, then deleted or overwritten, unless they are needed for an incident.
- Marketing and campaign-measurement data: until you withdraw your consent. A campaign-measurement consent lasts 90 days unless you renew it.
- Enquiries that do not lead to a rental: for as long as needed to answer and follow up, then deleted or anonymised.
How we protect your data
- Identity documents and identity numbers are encrypted at rest and kept in private storage, never behind public links.
- Staff sign in with multi-factor authentication; access depends on their role and branch, and is logged.
- Connections are encrypted (HTTPS) and uploaded files are checked for malware.
- Physical access to the vault requires identity checks at the branch.
Your rights
Under the PDPL, and subject to the conditions it sets, you may:
- access the personal data we hold about you and receive a copy;
- ask us to correct inaccurate or incomplete data;
- ask us to delete your data where we are not required to keep it (records that the law, such as AML or tax rules, requires us to keep cannot be deleted before the end of the retention period);
- ask us to restrict processing, or object to processing based on our legitimate interests or for marketing;
- withdraw your consent at any time, without affecting processing that took place before (use “Privacy preferences” in the website footer, or the unsubscribe link in our emails);
- complain to the UAE Data Office if you are not satisfied with our answer.
Write to [email protected]. We may ask you to confirm your identity before we act on a request, and we reply within the time limits set by law.
Cookies and analytics
We use a small number of cookies and similar technologies:
- Essential cookies to sign you in, keep your session secure and remember your privacy choice (hbs_measurement and hbs_measurement_sharing, 90 days). They are always on.
- A random design-test cookie (hbs_bucket, 90 days) so that you see a consistent version of a page. It does not identify you.
- Optional campaign measurement: with your consent, we record campaign labels, the referring website, your language and your branch of interest, and link them to enquiries, bookings and later payment or activation outcomes.
- Optional analytics: with your consent, we load Google Tag Manager and Google Analytics, which set their own cookies to measure visits. They are never loaded on the client space, booking, payment or staff pages.
Booking works without optional cookies. You can change your choice at any time through “Privacy preferences” in the footer.
Changes to this notice
We may update this notice. The version and date above show the current text. We will tell you about significant changes by email or on the website.