سياسة الخصوصية
Privacy Policy — Rahati Home Services
Last updated: 11 August 2026 Website: www.rahatics.com
1. Introduction
This Privacy Policy ("Policy") explains how RAHATI FOR BUILDING CLEANING SERVICES ("Rahati", "we", "us", "our"), a company licensed in Dubai, United Arab Emirates under commercial licence number 1739728, collects, uses, shares, and protects your personal data.
Rahati provides building and home cleaning and related services, delivered at your address by our own employed and trained personnel, and bookable through our website and mobile applications. Every person who attends your address works under Rahati's supervision, holds a valid Rahati work permit issued by the UAE Ministry of Human Resources and Emiratisation, and is paid by Rahati through the Wages Protection System. This Policy applies to:
- the Rahati website at www.rahatics.com;
- the Rahati mobile applications (Customer app and Service Team app);
- the Rahati Zone Team and administration web panels;
- the Rahati AI assistant connectors; and
- our related customer-support, messaging, and communication services.
Throughout this Policy, "Services" means both the booking platform and the cleaning and home services delivered to you. "Service Team" means the Rahati personnel who attend your address. Rahati organises its operations into geographic service areas, each covered by a "Zone Team" — a Rahati team assigned to that area and to no other.
This Policy covers the personal data of our customers. Personal data relating to our employees and partner personnel is handled under a separate internal staff privacy notice.
We are the data controller for the personal data described in this Policy, and we process it in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its implementing regulations. Where this Policy is read alongside our Terms and Conditions at https://www.rahatics.com/terms-and-conditions, capitalised terms have the meanings given there.
2. Personal data we collect
| Category | Examples |
|---|---|
| Account information | Name, email address, mobile number, country code, password (stored hashed), profile photo |
| Address & location information | Service address, building and unit details, access directions, emirate/area, geographic coordinates used for dispatch and routing |
| Booking & transaction information | Booking history, scheduling preferences, subscriptions, packages, vouchers, wallet balance, ratings and reviews you submit |
| Payment information | Payment-card tokens generated by our PCI-DSS-certified payment processor. We do not store full card numbers, CVV codes, or expiry dates |
| Refund account details | Where a cash payment is refunded by bank transfer, the account holder name, bank name, and IBAN you provide for that transfer |
| Device & usage information | IP address, device identifiers, device type, app version, browser type, operating system, referral source, in-app and website interactions, crash reports, diagnostics |
| Communications information | Support emails, in-app chat, WhatsApp messages, SMS, and IVR interactions. We do not record support calls |
| Marketing preferences | Newsletter subscriptions, push-notification and SMS opt-ins, communication preferences |
Aggregated data. We also produce aggregated and anonymised statistical data. This is not personal data, because it cannot identify you. If we ever re-combine it with personal data so that you become identifiable, we treat the result as personal data under this Policy.
Sensitive data. We do not seek to collect health data, biometric data, religious or political information, or data revealing your ethnic origin. Please do not submit such information in free-text fields.
If you decline to provide data. Where we need personal data to perform our contract with you or to comply with law, and you do not provide it, we may be unable to deliver the Services and may have to limit or close your account.
3. Cookies and tracking technologies
We use cookies, SDKs, log files, and similar technologies for authentication, security, fraud prevention, analytics, performance monitoring, service improvement, and marketing measurement.
| Cookie type | Purpose | Can you disable it? |
|---|---|---|
| Strictly necessary | Login, session management, security, fraud prevention | No — the platform cannot function without these |
| Functional | Remembering language, area, and display preferences | Yes |
| Analytics | Understanding how the platform is used, in aggregate | Yes |
| Marketing / attribution | Measuring campaign performance, showing relevant offers | Yes |
You can manage non-essential cookies through our cookie banner at any time, or through your browser and device settings. Blocking non-essential cookies will not prevent you from using the Services.
We use Google Analytics 4, Google Tag Manager, and Firebase Authentication for phone-number sign-in. Data generated through these tools is processed by the relevant provider under its own privacy policy — for Google, see https://policies.google.com/privacy.
Our AI assistant connectors do not set cookies; they authenticate using OAuth 2.0.
4. How we use your personal data and our lawful basis
We only process personal data where we have a lawful basis to do so.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Register you and verify your identity | Account information | Performance of a contract |
| Create, manage, and fulfil bookings | Account, address, booking, payment data | Performance of a contract |
| Assign and dispatch a Service Team to your address | Name, address, contact number, booking details, access instructions | Performance of a contract |
| Process payments, refunds, and wallet credit | Payment tokens, transaction records, refund account details | Performance of a contract |
| Provide customer support and resolve disputes | Communications history, booking history | Performance of a contract |
| Fraud prevention, security, and abuse detection | Device data, authentication data, security logs | Legitimate interests |
| Improve the platform and develop new features | Usage analytics, diagnostics, operational logs | Legitimate interests |
| Operate AI assistant connectors | Connector inputs and outputs, booking and account context | Performance of a contract; consent for connection |
| Send transactional notifications about your bookings | Account and booking data | Performance of a contract |
| Send marketing and promotional communications | Contact details, marketing preferences | Consent |
| Tax, accounting, and regulatory compliance | Transaction records | Legal obligation |
| Establish, exercise, or defend legal claims | As relevant to the claim | Legitimate interests; legal obligation |
We do not use your personal data for automated decision-making that produces legal effects for you, other than automated fraud screening — and you may request human review of any such decision.
We do not use your content, including content submitted through AI assistant connectors, to train generalised or publicly available AI models.
5. AI assistant connectors
Rahati offers integrations that allow third-party AI assistants (such as OpenAI's ChatGPT or Anthropic's Claude) to interact with Rahati on your behalf, using OAuth 2.0 authentication and connector technologies such as the Model Context Protocol (MCP).
Data sent to Rahati
| Connector action | Data sent |
|---|---|
| Service search | Service type, scheduling preferences |
| Booking creation | Selected service, date, time, service attributes, optional instructions |
| Booking lookup | Booking reference or account-linked booking information |
| Pricing request | Service selections and booking attributes |
Data returned to the assistant
| Response type | Examples |
|---|---|
| Availability | Available time slots |
| Pricing | Service pricing, wallet-credit usage, currency |
| Booking | Booking reference, scheduled date and time, frequency |
| Status | Booking status and booking summaries |
Data minimisation. Unless strictly required to complete a requested action, our connectors do not transmit payment-card information, government-issued identifiers, property access codes, health information, exact unit or villa numbers, or precise latitude and longitude coordinates.
Please do not include sensitive personal information, payment details, access credentials, health information, or information about children in free-text instructions submitted through a connector.
Authentication. Connectors use OAuth 2.0 with scoped permissions and short-lived access tokens. Your Rahati password is never shared with the AI assistant provider.
Third-party processing. Connector traffic passes through the assistant provider's infrastructure in order to complete the requested action, and is subject to that provider's own privacy policy and terms. Please review the applicable provider policy before using a connector.
Revoking access. You can revoke an assistant's access to your Rahati account at any time from the assistant's own settings or integrations page. Once revoked, it can no longer access your account or call Rahati tools on your behalf.
6. Who we share personal data with
| Recipient | Purpose |
|---|---|
| The Zone Team covering your area, and its Service Team members | To attend your address and deliver the booked service. These are Rahati personnel bound by employment contracts and confidentiality obligations — internal use, not disclosure to a third party |
| Payment processors | To process payments, refunds, and chargebacks |
| Communications providers | To send SMS, push notifications, email, WhatsApp, and IVR messages |
| Maps and address providers | Address validation, routing, and dispatch |
| Cloud, hosting, and infrastructure providers | Hosting, storage, monitoring, and operational systems |
| Analytics and attribution providers | Usage analytics and marketing measurement |
| AI assistant providers | To process connector requests and responses |
| Professional advisers | Legal, audit, insurance, and accounting purposes |
| Regulators, courts, and authorities | Where required by applicable UAE law or valid legal process |
No external service company receives your data. We do not outsource service delivery to other companies, and your booking details are never passed to a separate business to fulfil. Where we require additional capacity, personnel are assigned to Rahati under a work permit issued by the Ministry of Human Resources and Emiratisation and work under our own supervision and confidentiality obligations. Your data stays within Rahati.
Limits on internal access. Access to your data inside Rahati is role-based and restricted by geographic area: a Zone Team account can see only the bookings within its own assigned area and nothing outside it, and an individual Service Team member sees only the jobs assigned to them. A Service Team member receives your name, service address, contact route, and booking details — nothing more, and no payment information.
Limits on processors. All third-party processors listed above are bound by written agreements requiring them to protect your data, process it only on our instructions, and not use it for their own purposes.
We do not sell, rent, or lease your personal data to third parties.
Contact masking. Where technically available, calls and messages between you and a Service Team member are routed through masked numbers so that your personal mobile number is not disclosed. Records of these communications may be retained for safety, quality, and dispute-resolution purposes.
7. International data transfers
Your personal data may be transferred to and processed in countries other than the one you are in, including the United Arab Emirates, the United States, and European Union member states — the locations of the service providers we use for hosting, payments, analytics, and authentication.
Where we transfer personal data outside the UAE, we rely on one or more of the safeguards permitted under Federal Decree-Law No. 45 of 2021:
- transfer to a jurisdiction recognised as providing an adequate level of protection;
- contractual protections, including standard contractual clauses, binding the recipient to standards equivalent to UAE law; or
- your explicit consent, where no other safeguard is available.
You may request details of the safeguards applying to a specific transfer by contacting us at the address in Section 13.
8. Security
We apply technical and organisational measures appropriate to the risk, including:
- encryption of data in transit (TLS) and at rest;
- hashed and salted password storage;
- role-based access control and least-privilege internal access;
- multi-factor authentication for administrative accounts;
- firewalls, network segmentation, and intrusion monitoring;
- operational logging and audit trails;
- tokenised payment handling through a PCI-DSS-certified processor;
- masked contact routing between customers and Service Team members;
- OAuth 2.0 with scoped, short-lived tokens for AI assistant connectors; and
- periodic security review and vulnerability assessment.
Your responsibilities. You are responsible for keeping your password confidential and for activity carried out under your credentials. Notify us immediately at info@rahatics.com if you believe your account has been compromised.
Breach notification. If a personal data breach occurs that is likely to prejudice your privacy, confidentiality, or security, we will notify you and the UAE Data Office without undue delay, as required by applicable law.
No method of transmission or storage over the internet is completely secure, and we cannot guarantee absolute security.
9. Data retention
We retain personal data only as long as necessary for the purposes in this Policy, or as required by law.
| Data category | Retention period |
|---|---|
| Account information | Until account deletion, plus 30 days |
| Booking records | Until account deletion, plus 30 days |
| Financial, tax, and accounting records | 7 years from the end of the relevant tax period, as required by UAE tax and commercial law — retained even after account deletion |
| Refund account details (IBAN) | Deleted once the refund has cleared, other than the record retained in the accounting entry |
| Customer-support tickets — general enquiries | 3 months from closure |
| Customer-support tickets — damage, missing items, or any financial claim | 24 months from closure, so that both you and we have a record if a claim is raised later |
| Web and app analytics, device data | 6 months |
| Fraud and security logs | 90 days |
| Marketing preferences and suppression lists | Until you withdraw consent; suppression records kept indefinitely so we can honour your opt-out |
| AI connector tool-call logs (timestamps, tool name, client ID, error context) | 15 days |
| OAuth refresh tokens | Until revoked or expired |
After these periods, data is deleted or irreversibly anonymised. We may retain anonymised, aggregated information indefinitely for analytics and research.
10. Your rights and choices
Subject to applicable law, you have the right to:
- access the personal data we hold about you and receive a copy;
- correct inaccurate or incomplete data;
- request deletion of your data;
- restrict or object to certain processing, including processing based on legitimate interests;
- withdraw consent at any time, without affecting the lawfulness of processing already carried out;
- request portability — receive your data in a structured, machine-readable format;
- not be subject to significant decisions made solely by automated means; and
- complain to the UAE Data Office or another competent data-protection authority.
How to exercise a right. Email privacy@rahatics.com. We will verify your identity and respond within 30 days, extendable once by a further 30 days for complex requests, with notice to you. Exercising your rights is free unless a request is manifestly excessive or repetitive.
Marketing controls. Opt out at any time by using the unsubscribe link in marketing emails, replying STOP to marketing SMS, adjusting notification settings in the Rahati app, or emailing privacy@rahatics.com. Marketing emails are sent from noreply@rahatics.com, which is an unmonitored address — please do not reply to it; write to info@rahatics.com or info@rahatics.com instead. We may still send you essential transactional messages about your account and bookings.
AI connector controls. Revoke an assistant's access at any time from that assistant's settings or integrations page, as described in Section 5.
Account deletion. Email privacy@rahatics.com with the subject line "Data deletion request", or use the in-app delete-account option. Verified requests are actioned within 30 days. Note that deleting your account ends your access to the Services, and that transaction, tax, and fraud records are retained for the periods in Section 9 as required by law.
11. Additional provisions
Age limit. The Services are intended for adults aged 18 and over. We do not knowingly collect personal data from children under 18, except information provided by a parent or guardian as necessary to deliver a requested service. If you believe we hold a child's data inappropriately, contact privacy@rahatics.com and we will delete it.
Content you publish. Reviews, ratings, comments, and images you post may be visible to other users and to the public. Do not include information you would not want disclosed. You are responsible for the lawfulness of content you submit, and we may remove content that breaches our Terms or applicable law.
Business transitions. If Rahati is involved in a merger, acquisition, restructuring, financing, or sale of assets, your personal data may be transferred as part of that transaction. Any recipient will remain bound by protections no less protective than this Policy, and we will notify you where required by law.
Third-party services. The platform may link to or embed third-party websites and services, including payment providers, mapping services, AI assistant providers, and social platforms. We do not control and are not responsible for their privacy practices. Please review their policies before submitting information to them.
12. Updates to this Policy
We may update this Policy from time to time. Where changes are material, we will notify you by email, in-app notice, connector notification, or a prominent notice on the website before the changes take effect. The "Last updated" date above reflects the current version. We encourage you to review this Policy periodically.
13. Contact us
Privacy Contact Name: Ali Abu Atteyh Title: Chief Executive Officer Email: privacy@rahatics.com
General enquiries Email: info@rahatics.com
Customer Support Email: info@rahatics.com
Registered entity RAHATI FOR BUILDING CLEANING SERVICES Commercial licence number: 1739728 Al Kazim Building, 26 — 28th Street, Hor Al Anz East, Deira Floor 3, Office 302 Dubai, United Arab Emirates
If you are not satisfied with our response, you may lodge a complaint with the UAE Data Office or with the data-protection authority in your jurisdiction.
Governing law. This Policy is governed by the laws of the United Arab Emirates as applied in the Emirate of Dubai.
