Privacy Policy
NOWMADE
Last updated: 14 July 2026
NOWMADE (“we,” “us,” or “our”) is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, disclose, and protect your personal information when you interact with us — whether you book accommodation, use our coworking or wellness facilities, hold a Smart Membership, visit our website, attend our events, or communicate with us in any mway.
This policy applies to all NOWMADE services. NOWMADE currently operates in Dubai, United Arab Emirates, with additional locations (including in Morocco, Europe, and other regions) planned as part of our international expansion. Because our website, marketing, and services are accessible to and directed at individuals in the European Union and elsewhere, this policy also reflects the requirements of the EU General Data Protection Regulation (GDPR), in addition to the UAE Personal Data Protection Law (PDPL) and other applicable local laws.
1. Data Controller
The data controller responsible for your personal data is:
NOWMADE VACATION HOMES RENTAL L.L.C
Office 501, RAG Tower Business Centre,
Al Barsha, Dubai, United Arab Emirates
Email: info@nowmades.com
Website: www.nowmades.com
NOWMADE currently operates from the United Arab Emirates. As we expand into new jurisdictions, a local operating entity may act as data controller for data processed at that location, and details will be made available at each location once operational.
EU Representative: NOWMADE is currently established outside the European Union. Before commencing operations within the EU, we will designate a representative in the EU in accordance with Article 27 GDPR, and this policy will be updated with their contact details.
2. What Personal Data We Collect & Why
2.1 Accommodation Bookings
Data collected: Full name, email address, phone number, postal address, date of birth, nationality, passport or ID number, payment card details, booking dates, room/bed type preferences, special requests (including dietary requirements, accessibility needs, or health-related information).
Purpose: To process and manage your reservation, facilitate check-in, provide the requested accommodation, process payment, and communicate with you about your stay.
Legal basis:
- EU guests (GDPR): Article 6(1)(b) — performance of a contract. For special categories of data (e.g., health information): Article 9(2)(a) — explicit consent.
- UAE guests (PDPL): Processing necessary for the performance of a contract to which the data subject is a party.
- Other jurisdictions: Applicable legal bases under local data protection law, typically contractual necessity or consent.
Retention: 2 years (730 days) after your last stay, unless longer retention is required by applicable law (e.g., tax or accounting obligations).
2.2 Registration Cards
Data collected: Full name, address, country of residence, date of arrival and departure, passport or national ID number, signature.
Purpose: Compliance with local hotel and tourism registration requirements, which vary by jurisdiction (e.g., UAE tourism law, EU national regulations, local municipal requirements).
Legal basis:
- GDPR: Article 6(1)(c) — legal obligation
- UAE/Other: Compliance with applicable local law.
Retention: As required by the applicable local law of the property location (typically 1–5 years).
2.3 Smart Membership
Data collected: Full name, address, country of residence, date of arrival and departure, passport or national ID number, signature.
Purpose: To create and manage your membership account, process payments, provide access to facilities, communicate membership benefits and updates, and improve our services.
Legal basis:
- GDPR: Article 6(1)(b) — performance of a contract; Article 6(1)(f) — legitimate interest (service improvement).
- UAE/Other: Contractual necessity and legitimate interest under applicable law.
Retention: Duration of active membership plus 2 years after membership ends.
2.4 Coworking & Facility Usage
Data collected: Name, membership or booking reference, membership card or digital access credential identifier, access logs (time of entry/exit to coworking spaces, gym, pool, content rooms, and other facilities), Wi-Fi connection logs (device MAC address, connection times, bandwidth usage), meeting room and phone booth booking records
Purpose: To manage facility access and capacity, verify membership validity, ensure security, maintain our network infrastructure, enforce fair-use policies, and improve our facilities based on usage patterns
Legal basis:
- GDPR: Article 6(1)(b) — performance of a contract; Article 6(1)(f) — legitimate interest (security, operations, and capacity management).
- UAE/Other: Contractual necessity and legitimate interest
Important: NOWMADE monitors network traffic for security and fair-use purposes only. We do not inspect the content of your communications or browsing activity. Users are responsible for their own data security when using shared Wi-Fi networks.
Retention: Access logs: 90 days. Wi-Fi connection logs: 90 days. Meeting room booking records: 1 year. Anonymised usage statistics may be retained indefinitely.
2.5 Content Creation Rooms & Podcast Studios
Data collected: Name, booking reference, booking times, equipment usage records.
Purpose: To manage bookings, ensure equipment accountability, and improve the service.
Legal basis: Contractual necessity.
Retention: 1 year after use.
2.6 Marketing & Communications
Data collected: Name, email address, phone number, cookie identifiers, device information, browsing behaviour, interaction with our emails and ads, social media profile information (where you interact with us on social platforms), preferences and interests.
Purpose: To send you newsletters, promotional offers, and personalised marketing communications; to create audience segments; to serve
relevant advertising on third-party platforms; to send abandoned booking reminders; to conduct market research.
Legal basis:
- GDPR: Article 6(1)(a) — consent (for newsletters, direct marketing, and all targeted advertising via third-party platforms such as Meta, Google, LinkedIn, and TikTok); Article 6(1)(f) — legitimate interest (limited to non-intrusive, service-related communications to existing customers).
- UAE/Other: Consent where required by applicable law; legitimate interest otherwise.
Marketing channels: Email newsletters, SMS (where consented), push notifications, targeted advertising via Google Ads, Meta (Facebook/Instagram), LinkedIn, TikTok, and other platforms.
Current status: We do not currently operate advertising or analytics tracking on our website. Targeted advertising and non-essential tracking will only be activated once our cookie consent management platform is live, and only for users who have given their consent.
Retention: Until you withdraw consent or unsubscribe. Suppression lists (to ensure we do not re-contact you) are maintained indefinitely.
2.7 Website & Digital Services
Data collected: IP address, browser type and version, operating system, device type, screen resolution, referring URL, pages visited, time on site, click behaviour, demographic data (where available through analytics), and booking/purchase history.
Purpose: To operate, maintain, and improve our website; to analyse user behaviour and site performance; to personalise your experience; to detect and prevent fraud or abuse.
Legal basis:
- GDPR: Article 6(1)(a) — consent (for non-essential cookies and tracking); Article 6(1)(f) — legitimate interest (for essential site functionality and security)
- UAE/Other: Consent where required; legitimate interest for essential operations.
Retention: Cookie duration varies — session cookies are deleted when you close your browser; persistent cookies are retained for the period specified (typically 30 days to 2 years). Details will be provided in our Cookie Policy once our cookie management platform is in place.
2.8 Guest Satisfaction Surveys
Data collected: Name, email, booking reference, property visited, survey responses.
Purpose: To gather feedback and improve our services.
Legal basis: Legitimate interest (service improvement).
Retention: 60 days in identifiable form; anonymised data may be retained indefinitely for analytical purposes.
2.9 CCTV & Security Cameras
Data collected: Video footage of common areas, entrances, reception, corridors, and other public-facing spaces within our properties.
Purpose: Safety and security of guests, staff, and property; prevention and detection of crime; investigation of incidents.
Legal basis:
- GDPR: Article 6(1)(f) — legitimate interest (security).
- UAE/Other: Legitimate interest and compliance with applicable law.
Important: CCTV is never placed in private accommodation areas (rooms, capsule pods, bathrooms). Signage is displayed at all monitored locations.
Retention: Typically 5–30 days, depending on the property and applicable local law.
2.10 Customer Enquiries & Support
Data collected: Name, email, phone number, and the content of your communication (via email, phone, contact forms, social media, or inperson).
Purpose: To respond to your enquiry and provide customer support.
Retention: 2 years after the enquiry is resolved, unless the enquiry relates to an ongoing legal matter.
Note: Please avoid sending sensitive personal information (e.g., health data, financial details beyond what is required) via unencrypted email
or social media
2.11 AI-Powered Services & Chatbots
Data collected: Content of your interactions with our chatbot or AI-powered tools, including questions asked and information provided.
Purpose: To respond to enquiries, provide booking assistance, and improve our AI services.
Legal basis: Legitimate interest (customer service) and consent where required.
Important: Our AI tools do not make automated decisions that produce legal effects or similarly significant effects on you without humanoversight. If automated decision-making is used, you will be informed and given the right to request human review
Retention: Conversation logs: 30 days (anonymised data may be retained longer for service improvement).
2.12 Community Events & Activities
Data collected: Name, email, event registration details, and photographs or video taken at events.
Purpose: To manage event registration, communicate event details, and use event photography/video for NOWMADE promotional materials.
Legal basis: Contractual necessity (registration); legitimate interest and/or consent (photography/video).
Retention: Event registration data: 1 year. Photography/video: retained for ongoing marketing use unless you request removal.
2.13 Job Applicants
Data collected: Name, contact details, CV/resume, cover letter, qualifications, work history, references, and any other information provided in your application
Purpose: To evaluate your application and manage the recruitment process.
Legal basis: Pre-contractual measures (GDPR Art. 6(1)(b)); consent; or legitimate interest.
Retention: Unsuccessful applications: 6 months after the recruitment process ends (or longer with your consent for future opportunities). Successful applications: retained as part of your employee file
2.14 Business Partners, Brokers, Landlords & Investors
Data collected: Full name, company or agency name, email address, phone number, country/region, and information relevant to the partnership — for brokers and landlords: property details (type, location, number of units, availability); for prospective investors: investor profile (e.g., individual, angel investor, family office, institutional), indicative investment range, and any information you provide in your message. We do not request or store sensitive financial account details through these forms
Purpose: To assess and respond to partnership, property, and investment enquiries; to evaluate potential broker, landlord, and investment opportunities; to communicate with you about a possible business relationship; and to maintain records of our commercial contacts.
Legal basis:
- GDPR: Article 6(1)(b) — steps taken at your request prior to entering into a contract; Article 6(1)(f) — legitimate interest (evaluating and developing business relationships).
- UAE/Other: Pre-contractual measures and legitimate interest under applicable law.
Internal use only: Information submitted through our broker, landlord, and investor forms is used internally by NOWMADE only. We do not sell it or share it with third parties for their own marketing purposes.
Important (investors): Information submitted through the investor form is collected solely to evaluate mutual interest. It does not constitute an offer of, or a solicitation to buy, any securities or financial product, and does not create any investment relationship. Any future investment would be subject to separate documentation and applicable financial regulations.
Retention: 2 years from your last interaction with us, unless a business relationship is established (retained for the duration of that relationship plus applicable legal retention periods) or you ask us to delete your data earlier.
3. Profiling & Personalisation
We may use your personal data to create audience segments and personalise your experience. This includes:
- Tailoring marketing communications based on your booking history and preferences
- Creating custom audiences on advertising platforms (e.g., Meta, Google) to reach people with similar interests
- Sending abandoned booking reminders if you start but do not complete a reservation
- Personalising website content based on your browsing behaviour
You can opt out of profiling for marketing purposes at any time (see Section 6). Profiling activities do not produce legal effects or similarly significant effects on you.
4. Disclosure & Data Sharing
We may share your personal data with the following categories of recipients:
- Service providers: IT and hosting providers, payment processors, booking engine providers (e.g., Cloudbeds), email and marketing platforms, analytics providers, customer support tools
- Advertising partners: Meta (Facebook/Instagram), Google, LinkedIn, TikTok — for targeted advertising and audience creation (based on consent where required)
- Legal and regulatory authorities: Where required by law, regulation, or legal process (e.g., tourism registration, tax authorities, law nenforcement)
- Professional advisors: Legal, accounting, and insurance advisors as necessary
- Business partners: Event partners, excursion providers, and other third parties who provide services at or through NOWMADE, where necessary to deliver the service you have requested
- Group entities: Other NOWMADE entities for internal administrative purposes and to provide a consistent experience across locations
All service providers and partners who process personal data on our behalf do so under written data processing agreements that require them to protect your data to standards at least equivalent to this policy.
5. International Data Transfers
Given NOWMADE’s international operations, your personal data may be transferred to and processed in countries other than the one where it was collected. This includes transfers between NOWMADE properties and to service providers located in different jurisdictions
For transfers of personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to countries that do not benefit from an adequacy decision by the European Commission, we implement appropriate safeguards, including:
- EU Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules (where applicable)
- Other legally recognised mechanisms under applicable data protection law
For transfers from the UAE, we comply with the requirements of the UAE Personal Data Protection Law (PDPL) and any implementing regulations.
You may request a copy of the safeguards in place by contacting us at info@nowmades.com.
6. Your Rights
Depending on your location and applicable law, you may have the following rights regarding your personal data:
All Guests
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your personal data (subject to legal retention obligations)
- Withdraw consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing
- Opt out of marketing: Unsubscribe from marketing communications at any time via the link in our emails or by contacting us
Additional Rights for EU/EEA Guests (GDPR)
- Restriction: Request restriction of processing in certain circumstances
- Portability: Receive your data in a structured, commonly used, machine-readable format
- Objection: Object to processing based on legitimate interest, including profiling
- Automated decisions: Not be subject to solely automated decision-making with legal or similarly significant effects
- Complaint: Lodge a complaint with your local data protection authority (e.g., CNIL in France, ICO in the UK, Datainspektionen in Sweden)
Additional Rights for UAE Guests (PDPL)
- Rights as provided under the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its implementing regulations
- Complaint: Lodge a complaint with the UAE Data Office, the supervisory authority under the PDPL
To exercise any of your rights, contact us at info@nowmades.com. We will respond within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before processing your request.
7. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS/SSL) and at rest
- Access controls, role-based permissions, and multi-factor authentication for staff systems
- Regular security assessments, vulnerability scanning, and monitoring
- Staff training on data protection, privacy, and security awareness
- Incident response and data breach notification procedures
- Physical security measures at our properties (key card access, CCTV, secure server areas)
- Secure payment processing compliant with PCI DSS standards
- Regular review and update of data processing agreements with third-party service providers
While we take reasonable steps to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
8. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, NOWMADE will:
- Notify the relevant data protection authority within the timeframe required by applicable law (72 hours under GDPR, or as required by UAE PDPL or other local law)
- Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms
- Document the breach, its effects, and the remedial actions taken
If you believe your personal data has been compromised, please contact us immediately at mailto:info@nowmades.com.info@nowmades.com.
9. Third-Party Links
Our website and communications may contain links to third-party websites, applications, or services that are not operated by NOWMADE. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal data.
10. Cookie Policy
Our website uses cookies and similar tracking technologies. A separate, detailed Cookie Policy will be published on our website once our cookie consent management platform is implemented. In the meantime, our website uses only strictly necessary cookies required for basic functionality. No marketing or analytics cookies are placed without your consent.
11. Children's Privacy
Our website and digital services are not directed at children under 16. We do not knowingly collect personal data from children under 16 without parental consent. If you believe we have inadvertently collected data from a child under 16, please contact us at info@nowmades.com and we will delete it promptly.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, legal requirements, or for other operational reasons. The updated policy will be posted on our website with a revised “Last updated” date. For material changes, we will notify registered guests and members via email. We encourage you to review this policy periodically.
13. Contact & Data Protection Enquiries
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about how we handle your personal data, please contact us:
NOWMADE VACATION HOMES RENTAL L.L.C — Data Protection
Office 501, RAG Tower Business Centre, Al Barsha, Dubai, United Arab Emirates
Email: info@nowmades.com
Website: www.nowmades.com
For EU/EEA residents, if you are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority. A list of EU data protection authorities can be found at https://edpb.europa.eu/about-edpb/about-edpb/members_en. For UAE residents, you may also contact the UAE Data Office if you are not satisfied with our response.