1. Overview
Although aMedia is headquartered in Dubai, UAE, the EU General Data Protection Regulation (GDPR) applies to us when we process personal data of individuals located in the European Union (EU) or European Economic Area (EEA) — including visitors to our website, users of our free tools, or clients based in those regions.
We are committed to protecting your privacy, securing your data, and ensuring your rights under GDPR are respected.
2. Data Controller
For purposes of GDPR, aMedia acts as the data controller for personal data collected through our website (amedia.ae), our free tools (/tools/), and in the context of providing our services to EU/EEA-based clients.
- Company: aMedia
- Registered Address: in5 Tech, King Salman Bin Abdulaziz Al Saud Street, Dubai, UAE
- Contact Email: [email protected]
3. Lawful Basis for Processing
Under GDPR Article 6, we only process personal data when we have a lawful basis to do so:
| Data Activity | Lawful Basis | Purpose |
|---|---|---|
| Website analytics | Consent (Art. 6(1)(a)) | Improving website experience |
| Free tool usage data | Legitimate Interest (Art. 6(1)(f)) | Preventing abuse, improving tools |
| Contact form submissions | Legitimate Interest (Art. 6(1)(f)) | Responding to business enquiries |
| Marketing communications | Consent (Art. 6(1)(a)) | Sending newsletters or offers |
| Client onboarding & billing | Contract (Art. 6(1)(b)) | Providing contracted services |
| Retaining financial records | Legal Obligation (Art. 6(1)(c)) | Tax and accounting compliance |
4. Data Minimisation
We adhere to the principle of data minimisation (Art. 5(1)(c)). We only collect data that is strictly necessary for the intended purpose. We do not sell your personal data to third-party data brokers.
5. Cross-Border Data Transfers
As we are located outside the EU/EEA, data collected from EU individuals will be transferred to and processed in the UAE or other global server locations.
To ensure this transfer complies with GDPR Chapter V, we rely on appropriate safeguards:
- Adequacy Decisions: Transferring data to service providers in countries deemed "adequate" by the European Commission.
- Standard Contractual Clauses (SCCs): Using pre-approved EU SCCs in our agreements with global sub-processors (e.g., Google, Vercel, Stripe).
6. Your Rights Under GDPR
If you are located in the EU/EEA, you have specific rights regarding your personal data (Arts. 15-22):
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): You can request that we delete your data, provided we are not legally required to keep it.
- Right to Restrict Processing: You can ask us to pause processing your data in certain circumstances.
- Right to Data Portability: You can request your data in a structured, machine-readable format.
- Right to Object: You can object to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time.
To exercise any of these rights, please email [email protected]. We will respond to your request within 30 days without charge.
7. Data Security and Breach Notification
We maintain robust technical and organisational measures to secure your data (Art. 32), including HTTPS encryption, access controls, and secure payment gateways.
In the unlikely event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours, and notify affected individuals without undue delay (Arts. 33-34).
8. Free Tools and GDPR
Our free tools at /tools/ are designed with privacy in mind:
- Tool inputs (URLs, text) are processed in real time and are not stored unless you explicitly save output.
- No personal data is required to use free tools.
- Basic session analytics (non-identifying) may be collected under legitimate interest to improve tool performance.
- EU/EEA users may object to this analytics collection by contacting us.
9. Sub-Processors
To deliver our services, we use GDPR-compliant sub-processors. These may include:
- Google Workspace & Analytics: Email hosting, document storage, and site analytics.
- Stripe: Secure payment processing.
- Vercel / AWS: Cloud hosting and infrastructure.
10. Lodging a Complaint
If you believe our processing of your personal data infringes GDPR, you have the right to lodge a complaint with the supervisory data protection authority in your EU Member State of residence or work.
11. Updates to this Statement
We review our GDPR compliance practices regularly and will update this statement to reflect changes in the law or our data processing activities.