Privacy Policy
Effective date: September 22, 2026
HappyTenant DMCC, a free-zone company registered with the Dubai Multi Commodities Centre, of Al Worood 3 Street, JLT, Dubai, United Arab Emirates (“HappyTenant”, “we”, “us”) operates the HappyTenant property management platform, our websites and our mobile applications (the “Service”). This policy explains what personal data we handle, why, and what rights you have.
One distinction runs through this policy and determines most of what follows. For some personal data we decide how it is used — for example, the details of a prospect who fills in our contact form. For other personal data we act purely on the instructions of a customer who uses our platform — for example, records about that customer's tenants. In data protection terms, we are the controller in the first case and a processor in the second.
1.Who we are to you
| If you are… | Our role | What this means |
|---|---|---|
| A visitor to our website, or someone who contacts us or requests a demo | Controller | We decide how your data is used, and this policy governs it directly. |
| An administrator or staff user at a customer organisation | Controller (account data) and processor (portfolio data) | We control your account and login records; the property and tenant records you work with belong to your organisation. |
| A tenant, property owner, vendor or inspector using HappyTenant because a property manager gave you access | Processor | The property management company that manages your property decides what data is held and why. Contact them first for access, correction or deletion — we will support them in responding to you. |
2.Personal data we handle
Data you give us directly
- Contact and enquiry data: first and last name, work email, phone number, country, company name, portfolio size and the content of your message, when you contact us or request a demo.
- Account data: name, email, phone number, role and permissions, and authentication records for users of the Service.
- Billing data: the organisation's billing contact, billing address, unit counts and invoice history. Card details are handled by our payment providers and are not stored by us.
Portfolio data placed in the Service by our customers
Customers use the Service to manage properties, and in doing so place records about other people into it. Depending on how a customer configures their account, this can include names, email addresses, phone numbers, postal addresses, lease and tenancy details, payment and cheque records, maintenance and service requests, inspection photographs and notes, visitor records, and documents the customer uploads such as contracts and identification.
We process this data on the customer's instructions, for the purpose of providing the Service to them. We do not use it for our own purposes, do not sell it, and do not use it to market to the individuals it describes.
Data collected automatically
- Usage and device data: IP address, browser type and version, operating system, device identifiers, pages viewed, time and date of access, and diagnostic data.
- Cookies and similar technologies, as described in the cookies section below.
3.Why we use it, and our lawful basis
| Purpose | Data | Lawful basis |
|---|---|---|
| Providing, maintaining and supporting the Service | Account, portfolio, usage | Performance of a contract; for portfolio data, the customer's instructions |
| Responding to enquiries and demo requests | Contact and enquiry | Legitimate interests, or consent where required |
| Billing, collections and accounting | Billing, account | Performance of a contract; legal obligation |
| Securing the Service, preventing abuse, investigating incidents | Usage, account | Legitimate interests; legal obligation |
| Improving and developing the Service | Aggregated and de-identified usage | Legitimate interests |
| Sending service notices you cannot opt out of, such as security or billing notices | Account, billing | Performance of a contract; legitimate interests |
| Marketing communications about our products | Contact | Consent, or legitimate interests where permitted; opt out at any time |
| Meeting legal, tax and regulatory obligations | Billing, account | Legal obligation |
We do not sell personal data, and we do not use portfolio data belonging to our customers to train AI models for our own purposes.
4.Sub-processors and third parties
We use carefully selected providers to run the Service. They act on our instructions under contract, may only use data to perform their service for us, and must protect it appropriately. The categories are:
| Category | Providers | Purpose |
|---|---|---|
| Cloud hosting and file storage | Amazon Web Services | Hosting the Service and storing uploaded files and documents |
| Mobile data synchronisation | Google Firebase / Firestore | Syncing inspection data to and from the Snaglist mobile app, including offline capture |
| Email delivery | Mailgun | Sending transactional and notification email |
| Messaging | Twilio | Sending SMS and messaging notifications where enabled |
| Payments | Stripe, Telr | Processing subscription and tenant payments |
| Direct Debit | Direct Debit System (directdebit.ae) | Creating and collecting UAE Direct Debit mandates where enabled |
| AI providers | OpenAI | Powering AI-assisted features, including RiaAI, document handling and summarisation |
| Voice assistance | VAPI | Voice interaction features where enabled |
| Booking distribution | Channex | Synchronising availability, rates and reservations with booking channels |
| Accounting integrations | QuickBooks | Syncing invoices and financial records where you connect them |
| Property portals and CRM | Property Finder, Dubizzle, Bayut, Berto | Importing leads and listing data where you connect them |
| Productivity integrations | Google (Gmail), Dropbox, Meta | Email, file and messaging integrations where you connect them |
| Security | Google reCAPTCHA | Protecting forms from automated abuse |
| Analytics | Vercel Analytics | Understanding website usage |
Integrations marked “where you connect them” only receive data if a customer chooses to enable that integration. A current list of sub-processors is available on request, and customers under a data processing agreement will be notified of material changes.
We may also disclose personal data to professional advisers, or where we believe in good faith that disclosure is necessary to comply with a legal obligation, to enforce our terms, to protect our rights or property, to prevent or investigate wrongdoing, or to protect the safety of users or the public. If we are involved in a merger, acquisition or sale of assets, data may transfer as part of that transaction, and we will give notice before it becomes subject to a different privacy policy.
5.International transfers
We are based in the United Arab Emirates and process data there. Some of our sub-processors operate in other countries, which means personal data may be transferred outside the country in which you are located, including to jurisdictions whose data protection laws differ.
Where we transfer personal data internationally, we do so on a recognised legal basis and put appropriate safeguards in place, such as standard contractual clauses with the receiving party, together with technical measures including encryption in transit.
6.How long we keep it
| Data | Retention |
|---|---|
| Portfolio data in a customer account | For the life of the account. After termination we make it available for export for 30 days, then delete or de-identify it, subject to backup cycles and any longer period required by law |
| Account and login records | For the life of the account, then up to 12 months |
| Billing and invoice records | As required by applicable tax and company law, typically at least 5 years |
| Enquiry and demo-request data | Up to 24 months from last contact, unless you become a customer or ask us to erase it sooner |
| Security and audit logs | Typically up to 12 months |
| Marketing preferences, including opt-outs | For as long as needed to honour your choice |
| Google Account connection tokens, where a user connects Gmail | Until the user disconnects the account, at which point we ask Google to revoke them and remove them from our systems |
| Email imported from a connected Gmail account, including attachments | Kept as part of the customer's records, on the same basis as other portfolio data above. Disconnecting stops further import; it does not delete email already imported |
| Inspection data and media synced to Google Firebase for the Snaglist app | For the life of the inspection record in the customer account |
Where a customer instructs us to delete specific records within their account, we act on that instruction. Backups are overwritten on a rolling cycle, so deleted data may persist briefly in backup before being removed.
7.Google user data
This section applies in addition to the rest of this policy, and covers data we access from a user's Google Account. It is written to meet Google's API Services User Data Policy, including its Limited Use requirements.
What we access, and why
A HappyTenant user can choose to connect their Google Account so that email about a property, a lease or a work order is captured in HappyTenant instead of being copied across by hand, and so that replies can be sent from their own address. The connection is optional, is started by the user, and is never enabled on a user's behalf.
When a user connects, Google asks them to grant the scope https://mail.google.com/, together with their Google Account email address. That Gmail scope is broad because the connection both reads the mailbox and sends mail as the user. If it is not granted, the connection is refused and no credentials are kept.
What we do with it
- Read messages in the connected mailbox on a recurring basis, and match them to properties, leases, work orders and contacts in the customer's account.
- Store the subject, message body, date, sender and recipients, the Gmail message identifier, and any attachments, as a note or a support ticket against the matching record.
- Send email from the connected Gmail address when a user sends a message from inside HappyTenant.
- Read the Google Account email address, to identify which mailbox is connected.
The first import after connecting reads the existing contents of the mailbox, so that earlier correspondence can be matched to the right records. After that, only messages received since the previous import are read.
Limited use
We use Google user data only to provide and improve the features described above. We do not use it for advertising, we do not sell it, and we do not transfer it to anyone other than the sub-processors listed in this policy who host or operate the Service on our instructions, except where it is necessary for security or where the law requires it. We do not allow our staff to read Google user data except where a user asks us to in order to support them, where it is necessary to investigate a security issue or fix a fault, or where the law requires it.
How long we keep it
The credentials for the connection are kept until the user disconnects, at which point we ask Google to revoke them and remove them from our systems.
Email that has already been imported is kept as part of the customer's own records. It sits as a note or a ticket against a property, lease or contact, and is retained for the life of that record and of the account, on the same basis as the other portfolio data in the retention table above. Disconnecting a Google Account stops any further email being imported. It does not, by itself, delete email that was imported before.
How to withdraw access and delete the data
- Disconnect in HappyTenant, from the integrations page. This asks Google to revoke our access and removes the stored credentials.
- Revoke at Google, from the permissions page of your Google Account at myaccount.google.com/permissions. This withdraws our access whether or not you also disconnect in HappyTenant.
- Delete imported email. Notes and tickets created from a mailbox can be deleted in HappyTenant like any other record, by the customer or their administrator.
To ask us to delete Google user data rather than doing it yourself, email info@happytenant.ae from the address of the connected account. We will confirm the request and act on it within the period the applicable law requires.
8.Your rights
Subject to the law that applies to you, including UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and, where it applies, the EU and UK General Data Protection Regulation, you may have the right to:
- ask what personal data we hold about you and receive a copy;
- have inaccurate data corrected;
- ask for data to be deleted where there is no continuing basis to keep it;
- restrict or object to processing, including objecting to direct marketing at any time;
- receive data you gave us in a portable format;
- withdraw consent where we rely on it, without affecting processing already carried out; and
- complain to the relevant data protection authority.
To exercise these rights with us, email info@happytenant.ae. We will respond within the period the applicable law requires, and may need to verify your identity first.
If your data is in the Service because a property management company placed it there, that company decides how it is used, and you should contact them first. If you contact us instead, we will refer you to them and support them in responding.
10.Security
We maintain administrative, technical and organisational measures designed to protect personal data, including role-based access control, encryption of data in transit, separation of each customer's data, and restricted internal access on a need-to-know basis.
No method of transmission over the internet or of electronic storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting personal data, we will notify affected customers and, where required, the relevant authority, without undue delay.
11.AI-assisted features
Some features use AI to answer questions, summarise activity and assist with documents. Where a feature sends data to an AI provider acting as our sub-processor, it is sent only to produce the result requested, and our agreements prohibit the provider from using it to train their models.
AI output is generated automatically and may be incomplete or incorrect. It is intended to assist your team rather than to make decisions, and no legal or financial decision about an individual is made solely by automated means without human involvement.
12.Children
The Service is a business tool and is not directed at children under 18. We do not knowingly collect personal data directly from children. Records about a minor may appear in a customer's portfolio data — for example as an occupant named on a tenancy — and that data is the customer's responsibility as controller.
If you believe a child has provided personal data to us directly, contact us and we will take steps to remove it.
13.Links to other sites
The Service may link to sites we do not operate. We have no control over their content or practices and accept no responsibility for them. We recommend reviewing the privacy policy of any site you visit.
14.Changes to this policy
We may update this policy from time to time. We will post the updated version on this page and change the effective date above. Where a change materially affects how we use personal data, we will give notice by email or a prominent notice in the Service before it takes effect.
15.Contact us
- By email: info@happytenant.ae
- By post: HappyTenant DMCC, Al Worood 3 Street, JLT, Dubai, United Arab Emirates
- Through the contact page on this website
Customers who require a data processing agreement, our current sub-processor list, or security documentation for a procurement review can request these using the same address.