Back to main page
PRIVACY POLICY

This Privacy Policy (hereinafter — the "Policy") constitutes an agreement between Reelly Tech Ltd and any Visitor or User of the website (hereinafter jointly — the "User") governing the relationship arising from the collection, processing, storage, protection, and disclosure of Users' personal data.

This Policy constitutes a public offer addressed to a person having full legal capacity.

By registering on the website https://www.reelly.ai/, or by visiting the Site without registering, the User grants consent to the collection and processing of their personal data and grants the Site Operator the right to take other actions with respect to Personal Data as provided for in this Policy.

The fact of acceptance of this Policy (the unconditional acceptance of all terms and conditions contained in this document, effected by visiting the Site or by registering) is recorded by the Site Operator in electronic form. Information recorded by the Site Operator regarding acceptance of the offer may be used as evidence before any authority, including in court.

This Privacy Policy forms an integral part of the Platform's Terms and Conditions of Use. Terms used in this Policy shall have the meanings assigned to them in the Platform's Terms and Conditions of Use.

ATTENTION!IF YOU DO NOT AGREE WITH ANY PROVISIONS OF THIS POLICY, PLEASE STOP USING THE SITE AND, IF NECESSARY, SUBMIT A REQUEST TO THE SITE OPERATOR FOR THE DELETION OF ANY PERSONAL INFORMATION OBTAINED BY IT IN CONNECTION WITH YOUR VISIT TO THE SITE.

If you have any questions or require clarification of the terms and individual provisions of this Policy, please contact our support service at support@reelly.io.

1. GENERAL PROVISIONS

1.1.
The controller of personal data is REELLY Tech Ltd, a private company registered in the Dubai International Financial Centre (DIFC), United Arab Emirates, holding Commercial License No. CL6648, with its registered office at: Unit 208, Level 1, Gate Avenue — South Zone, Dubai International Financial Centre, Dubai, United Arab Emirates (hereinafter — the "Operator", "Reelly", "we").

1.2. This Policy governs the processing of personal data in connection with the use of the following Reelly services:
- the web platform
- CRM modules
- AI analytics tools
- functionality for agents and developers
- mobile and web applications (where applicable)
- API and integrations with external services


1.3. The Reelly Platform is a SaaS platform for real estate agents and developers that includes CRM tools, user-behavior analytics, and marketing tools facilitating communication between agents and developers. The Platform also includes CRM and BRM (Broker Relationship Management) tools, analytics of user interaction with developers' projects, and other services facilitating interaction among real estate market participants.

1.4. Personal data is processed in accordance with:
- the DIFC Data Protection Law 2020 (Law No. 5 of 2020);
- the DIFC Data Protection Regulations;
- the principles of transparency and fair processing of data, including the provisions of Regulation 10 applicable to the use of analytical AI tools. The Platform's AI modules do not perform automated decision-making capable of producing legal effects or otherwise significantly affecting the User.

1.5. The following terms are used in this Policy:
- Personal Data — any information relating to an identified or identifiable natural person.
- Processing — any operation performed on Personal Data (collection, storage, analysis, transfer, etc.).
- User — a natural person using the Reelly Platform as an agent, developer representative, or other individual.
- Operator (Controller) — the person determining the purposes and means of processing personal data.
- Processor — the person processing data on behalf of the Operator.
- AI Tools — automated data-analysis algorithms used by Reelly to improve service quality, which do not make decisions that significantly affect the User.
- Third Parties — service providers, partner agencies, developers, as well as external technical, marketing, and analytics services.

2. CATEGORIES OF PERSONAL DATA PROCESSED

2.1.
Reelly processes only those categories of personal data that are necessary for the operation of the Platform, the performance of contractual obligations, ensuring security, and improving service quality.

2.2.
The data processed falls within the following categories.

2.2.1. Data provided directly by the User. This category includes data that the User provides upon registration, when completing their profile, when interacting with Platform functionality, or that they upload to confirm their professional qualifications:
- surname, first name, and patronymic (where applicable);
- contact details (phone number, email address, social media links);
- photograph (avatar);
- professional information (position, company, role — agent, broker, developer, etc.);the number, issue date, and validity period of a license/permit;
- uploaded documents (license, certificates, proof of professional experience, etc.);
- information about work experience and qualifications;
- financial information necessary for the operation of the services (e.g., subscription status, account balance top-up transactions);
- text messages and attachments provided via support chat or the Platform's built-in communication modules.

2.2.2. Data collected automatically. When using the Platform, the following technical and analytical data is collected:
- IP address, device type, and operating system;
- browser language and hardware settings;unique device identifiers;
- dates and times of visits, referral URLs;
- cookies and similar technologies;event data (errors, failures, delays);
- technical logs (log files).
This data is used to monitor Platform performance, for analytics, and to ensure the stability and security of the services.

2.2.3. Behavioral data. Reelly collects extended information about User behavior on the Platform, including:
- history of actions (clicks, page views, page transitions);
- activity within CRM modules;
- interactions with sales and analytical tools;
- statistics on visits to properties and listings;
- status, priority, and tag markers;
- records of interaction between agents and developers (e.g., contact requests);
- information on activity time and visit frequency;
- internal analytical indicators (e.g., activity, effectiveness, accuracy of profile completion).
Behavioral data is used exclusively for analytical purposes and does not result in automated decision-making.

2.2.4. Professional data. The following data may be processed:
- the number and status of the license or other permit;
- the issuing authority;
- the issue date and validity period of the permit;
- confirmation of the permit's existence via third-party sources (e.g., public registries);
- the name of the employing company;
- years of professional experience;
- information about previous properties, visits, and results of work;
- confirmed verification, e.g. "crosschecked in DLD" or similar parameters.

2.2.5. Financial data. In the course of using the Platform, the following may be processed:
- subscription status (free/paid);
- account balance top-up transactions;
- applicable rates/tariffs;
- transaction history within the Platform (where applicable).
Reelly does not store bank card data; such data may be processed exclusively by payment providers.

2.2.6. Data obtained from third parties. Reelly may receive additional data from external sources, including:
- partner agencies and developers (e.g., confirmation of cooperation);
- public registries (e.g., verification of agent licenses);
- analytics and marketing communication services;
- AI and technical tool providers.

2.2.7. Data relating to professional qualifications. In rare cases, a User may upload documents containing:
- an image of an identity document;
- documents evidencing professional status or accreditation;
- other data required to confirm the User's role in the real estate sector.
Such data is processed using strictly limited methods and is not used for any purpose other than verifying the User's competence.

2.2.8. Data of minors. Reelly does not process the personal data of persons under 18 years of age. Where such data is discovered, it is deleted.

3. PURPOSES OF PROCESSING PERSONAL DATA AND LEGAL BASES

3.1.
Reelly processes personal data only where necessary for the operation of the Platform, the performance of obligations to Users, or compliance with applicable law. Under the DIFC Data Protection Law 2020, data may be processed only where one or more lawful bases exist.

3.2. Purposes and legal bases for processing:
Purpose of ProcessingData UsedLegal Basis
User registration on the Platformname, phone, email, company, rolePerformance of a contract
Creation of an agent's or developer's profileprofile data, photo, permit, professional informationPerformance of a contract
Providing access to Platform functionalityall necessary User dataPerformance of a contract
Operation of CRM and analytical modulesbehavioral data, profile data, action historyLegitimate interests of the Operator, provided there is no detriment to the User's rights
AI analytics of behavior (without automated decision-making)behavioral data, activity, interactionsLegitimate interests (service-quality analytics)
Improving Platform performancetechnical data, logs, User actionsLegitimate interests
Verification of professional information (e.g., checking licenses or registries)permit data, verification dataPerformance of a contract with the User; legitimate interests of the Operator relating to Platform operation and facilitating interaction between agents and developers
Communication with the User (support, notifications)email, phone, messagesPerformance of a contract with the User; legitimate interests of the Operator relating to Platform operation and facilitating interaction between agents and developers
Sending informational messagescontact detailsLegitimate interests
Marketing messagescontact details, activityUser consent (opt-in), where required
Processing payments, tariffs, and subscriptionstransactional dataPerformance of a contract with the User; legitimate interests of the Operator relating to Platform operation and facilitating interaction between agents and developers
Platform analytics and statistics (in anonymized form)technical and behavioral dataLegitimate interests
Compliance with law; responding to requests from authoritiesany necessary dataPerformance of a contract with the User; legitimate interests of the Operator relating to Platform operation and facilitating interaction between agents and developers
Protection of Reelly's rights; investigation of misuseaction history, User behaviorLegitimate interests
Operation of BRM (Broker Relationship Management), including providing developers with analytical information on Users' interaction with projectsUser profile data, contact details, professional data, behavioral data, project-interaction history, activity analyticsPerformance of a contract; legitimate interests of the Operator relating to Platform operation and provision of services to Users
3.3 Description of the main legal bases

3.3.1.
Performance of a contract is relied upon where data processing is necessary for:
- registering the User;
- providing services and access;
- operating the CRM;
- facilitating communication between agents and developers.

3.3.2.
Legitimate interests. Reelly relies on this legal basis where the processing:
- does not infringe the User's rights and freedoms;
- is necessary for the Platform's operation;
- serves to improve service quality;
- is used for analytics, performance monitoring, and preventing misuse.
Reelly carries out a balancing-of-interests assessment to ensure that no processing infringes User rights.

3.3.3. Consent is relied upon where the law requires separate User consent, including for marketing communications, the transfer of data to third parties outside the Platform's standard functionality, or other cases expressly provided for by applicable law.

3.3.4. Legal obligation. Applied in situations where Reelly must transfer or process data in order to:
- comply with DIFC requirements;
- respond to requests from government authorities;
- fulfil AML/KYC obligations (where applicable).

3.3.5. Processing of children's data. Reelly does not process the data of persons under 18. Where such data is identified, it is subject to immediate deletion.

3.4. Restriction of processing. The User has the right to request a restriction of processing where:
- the data is inaccurate;
- the processing is unlawful;
- Reelly no longer needs the data;
- the User has objected to the legitimate interests relied upon.

4. USE OF AI TOOLS

4.1.
Reelly uses data-analysis technologies and machine-processing algorithms to improve the quality of service to Users, increase the Platform's operational efficiency, and provide analytical recommendations. These algorithms do not make automated decisions capable of producing legal effects or otherwise significantly affecting the User.

4.2.
Purpose of AI tools. AI at Reelly functions solely as an auxiliary analytical mechanism, not as a decision-making system. Reelly's AI tools are applied to the following tasks:
- analyzing User behavior on the Platform;
- identifying interests and preferences relating to properties and CRM activity;
- generating analytical reports;
- providing recommendations to the User or developer within the interface;automating certain technical functions (e.g., processing messages or system prompts);
- improving user experience and service quality.

4.3. Categories of data used by AI.

4.3.1. The following data may be used to operate the algorithms:
- behavioral data (history of Platform actions, activity);
- professional data (agent's or developer's profile);
- technical data (device type, system events);
- User profile data;
- anonymized statistical data.

4.3.2. AI algorithms are not used to analyze or process special categories of data unless such data is required for the service to function.

4.4. Absence of automated decision-making. Any decisions of significance are made exclusively by humans, based on business processes and agreements between Users and developers. Reelly does not use AI to:
- assign legally significant statuses;
- decide on access to services;
- impose blocks, sanctions, or restrictions on functionality;
- make determinations affecting the User's rights;
- select one User over another based on the results of automated analysis.

4.5. The User may request an explanation of any action displayed on the Platform and receive a response from a competent employee. Reelly ensures:
- human review of AI conclusions where applicable;
- the User's ability to clarify, request correction of, or dispute analytical conclusions;
- that AI's influence is limited to recommendations and prompts.

4.6. The Platform ensures transparency regarding the operation of AI:
- analytical results are displayed in a clear and accessible form;
- Reelly provides the User with information about the logic underlying recommendations, where technically feasible;
- the User may request further clarification regarding analytical results.

4.7. Reelly conducts internal risk assessments to ensure that the use of AI does not infringe User rights. To protect data used by AI:
- data is encrypted in transit and at rest;
- access to data is restricted by roles and access levels;
- algorithms are trained on anonymized data wherever possible;
- AI results are not used to make decisions without human involvement;
- internal model-quality controls are applied.
External technology providers (e.g., Google Cloud and OpenAI) may be used in connection with the operation of AI tools, and data fragments may be shared with them solely to perform technical operations: processing requests, generating prompts, providing analytics. In doing so: the providers do not make decisions regarding Users, do not gain access to data beyond what is required for technical processing, do not use the data to train their own models unless expressly agreed otherwise, and agreed protection mechanisms and SCCs (for cross-border transfers) are applied.

5. PROFILING AND ANALYTICS

5.1.
Reelly applies data-analysis tools and evaluation mechanisms to improve service quality, increase the effectiveness of interaction between Users and developers, and optimize the Platform's operation. Profiling does not result in automated decision-making capable of producing legal effects or otherwise significantly affecting the User.
5.2. Profiling means the analysis of a User's personal and behavioral data to derive analytical indicators, including: activity statistics, analysis of visits to properties or listings, analysis of interaction with CRM functionality, assessment of profile completeness and accuracy, analysis of login and communication frequency, and determination of the User's level of engagement with the Platform.
5.3. These indicators are used to: provide the User with analytical reports and recommendations; support the operation of CRM, BRM (Broker Relationship Management), and other Platform analytical tools; display to developers information about Users' interaction with the relevant developer's projects via the Platform's functionality; generate statistical, analytical, and informational indicators; improve the quality of recommendations; improve the Platform's performance; and ensure effective interaction between agents, brokers, and developers.
5.4. Profiling is carried out to ensure the operation of the Platform, provide Users with CRM, BRM, and analytical-tool services, improve service quality, generate recommendations, and ensure effective interaction between agents, brokers, and developers.
5.5. Any decisions leading to specific actions (e.g., selection of a partner) are made by humans, not algorithms.
5.6. Analytical indicators are provided for informational purposes only. Profiling does not produce legal effects, does not affect the User's rights, is not used to decide on access, blocking, or restrictions, and is not used for discriminatory analysis.
5.7. The User's right to object to profiling. If an objection is raised, some Platform functionality may be limited. The User has the right to: object to profiling; request an explanation of profiling methods; request correction of data where the analytics are based on erroneous information; and restrict the use of behavioral data (to the extent technically feasible).
5.8. In most cases, Reelly uses behavioral data in aggregated or anonymized form, except where the use of personalized data is necessary and proportionate for the operation of the Platform's services, including CRM, BRM, and other tools facilitating interaction between Users and developers.5.9. Security measures relating to profiling. Reelly ensures access control over analytical data, maintains activity logs, processes sensitive analytical data on EU-based servers, uses secure cloud services, and limits the volume of information collected in accordance with the data-minimization principle.

6. COOKIES AND TRACKING TECHNOLOGIES

6.1.
Reelly uses cookies and similar technologies (including web beacons, pixel tags, browser local storage, and SDKs) to ensure the proper functioning of the Platform, improve user experience, conduct analytics, and support marketing functions.
6.2. Cookies may be used for the following purposes: enabling authorization and saving user settings; analyzing user behavior and improving the interface; supporting marketing and advertising tools; and ensuring security and preventing fraud.
6.3. Detailed information about the types of cookies used, their retention periods, the tracking technologies applied, and the third parties using cookies on the Platform is set out in a separate Cookie Policy, available at: https://www.reelly.ai/terms/cookie-policy
6.4. The User may manage their cookie settings or disable specific categories via their browser interface or system functionality, in accordance with the instructions set out in the Cookie Policy.

7. DISCLOSURE OF PERSONAL DATA TO THIRD PARTIES

7.1.
Reelly discloses personal data to third parties only where necessary for the operation of the Platform, the functioning of the services, the performance of contractual obligations to Users, or where such disclosure is provided for by the Platform's functionality and is necessary to provide Users with the relevant services. Data is disclosed in accordance with the DIFC Data Protection Law 2020 and the principles of data minimization and secure processing.

7.2.
Reelly may disclose data to the following categories of recipients:

7.2.1. Technical service providers
- Google Cloud (hosting and data processing)
- Google Analytics / GA4
- OpenAI API (processing user requests within analytics)
- Meta (Meta Pixel)
- Telegram / Manychat (communications)
- other services ensuring the Platform's technical operation

7.2.2. Development and support tool providers
- contractors providing technical support for the Platform
- logging and monitoring services

7.2.3. Partner agencies and companies involved in user service
- real estate agencies
- brokerage companies

7.2.4. Reelly may provide developers with access to Users' personal data relating to such Users' interaction with the relevant developer's projects, where such disclosure forms part of the Platform's functionality and is necessary for the operation of CRM, BRM (Broker Relationship Management), and other services facilitating interaction between agents, brokers, and developers. Such data may include, in particular: User profile information, contact details, professional information, information on the User's interaction with the relevant developer's projects, and analytical indicators of User activity generated by the Platform. Disclosure is made solely to the extent necessary for the operation of the relevant Platform service and to achieve the processing purposes set out in this Policy.

7.2.5. Advertising and marketing providers:
- analytics services
- advertising platforms
- newsletter and communication providers

7.2.6. Government authorities and regulators. In cases provided for by law.

7.2.7. By using the Platform and interacting with developers' projects, the User agrees that information about such interaction may be provided to the relevant developer via the Platform's functionality, to the extent necessary for the operation of CRM, BRM (Broker Relationship Management), and other Platform services. Such disclosure of information does not constitute a transfer of data for purposes incompatible with the processing purposes stated in this Policy and is carried out solely within the scope of providing the User with the Platform's functionality.

7.2.8. AI tools are used by Reelly in a limited and controlled manner. Operating these tools may require the transfer of data to the following providers:
- OpenAI API
- Google Cloud AI

7.2.9. Data is transferred to these services only to the extent necessary to perform the technical function in question (e.g., analyzing a request), without transferring data not required for processing, without the provider using the data to train its own models (unless expressly permitted by the User), and without the providers making automated decisions.

7.3. Transfer of data to analytics and marketing services. Within the scope of analytics and marketing, Reelly may share technical and anonymized data with:
- Google Analytics (GA4);
- Meta Pixel;
- Telegram/Manychat;
- other analytical tools.

7.4. Transfer of data to technical and cloud providers. Such providers act as Processors and are not entitled to use the data outside the purposes specified by Reelly. To support the operation of the Platform, Reelly may transfer data to technical providers:
- cloud services;
- CDN services;
- log storage services;
- communication APIs.

7.5. Transfer of data in cases provided for by law. Disclosure is made only to the minimum extent necessary to comply with the law. Reelly may disclose data:
- at the request of a court or regulator;
- in the performance of a legal obligation;
- to investigate misuse or violations of the service terms;
- to protect Reelly's rights and legitimate interests.

7.6. Restrictions on data disclosure. Reelly does not disclose:
- data to third parties without a legal basis;
- data for automated decision-making;
- data relating to an agent's licenses or documents without necessity, except where such disclosure is provided for by the Platform's functionality or is made at the User's initiative.

8. CROSS-BORDER TRANSFER OF PERSONAL DATA

8.1.
The Reelly Platform carries out cross-border transfers of personal data only where necessary for the operation of the services and where appropriate legal safeguards exist, as provided for under the DIFC Data Protection Law 2020.

8.2. Personal data is primarily stored on servers located in the European Union (EU). The cloud providers used by Reelly ensure a level of protection consistent with DIFC requirements and applicable EU law.

8.3. Transfer of data to third countries (the United States and other jurisdictions). Such transfers are carried out only to the extent necessary to perform specific technical operations and are not used by providers for their own independent purposes. In the course of the Platform's operation, data may be transferred to services located outside the EU and DIFC, including:
- OpenAI (USA);
- Meta (USA) — Meta Pixel and advertising tools;
- Google (USA / global data centers);
- Telegram (globally distributed infrastructure);
- and other services supporting the Platform's technical operation.

8.4. Legal protection mechanisms (SCCs and other tools). These measures ensure a level of protection for personal data comparable to DIFC and European legal requirements. Transfer of data to third countries is carried out only where appropriate safeguards exist, including:
- Standard Contractual Clauses (SCCs), approved by the European Commission and recognized by DIFC as a safeguard mechanism;
- additional technical measures (encryption, data minimization, pseudonymisation);
- contractual restrictions on external providers (DPAs) preventing the use of data for unrelated purposes;
- limiting the volume of data transferred to countries with an inadequate level of protection to what is strictly necessary to perform technical functions.

8.5. Transfer of data to developers and partners in other countries. Where the User uses Platform functionality involving interaction with developers, agencies, or partners located outside the EU or DIFC, personal data may be transferred to such parties within the scope of the Platform's functionality, to the extent necessary to provide the relevant services and achieve the processing purposes set out in this Policy.

8.6. Exceptional cases of transfer. Personal data may be transferred to third countries without additional protection mechanisms only in cases provided for by law, for example: at the request of government authorities or a court, to protect the vital interests of the User, or to fulfil Reelly's obligations to regulatory authorities.

8.7. Additional security measures. To protect data during cross-border transfers, Reelly applies:
- encryption of data in transit and at rest;
- segregation of access roles;
- security monitoring;
- restriction of external providers' access to data.

9. PERSONAL DATA RETENTION PERIODS

9.1.
Reelly retains personal data only for as long as necessary to achieve the purposes of processing, perform contractual obligations, comply with legal requirements, and protect the rights and legitimate interests of Reelly or Users. Once the processing purposes have been achieved, the data is deleted or anonymized, unless further retention is required by law or to protect the rights of the parties.
9.2. Retention periods by data category:
Data CategoryRetention PeriodBasis
Profile data (name, contacts, company)for as long as active + 12 months, or until deleted at the User's requestPerformance of a contract / Legitimate interests
Professional data (licenses, documents)for as long as active + 12 months, or until deleted at the User's requestPerformance of a contract
Behavioral data (action logs, activity)for as long as active + 12 months, or until deleted at the User's requestLegitimate interests (analytics and security)
Technical data (logs, error information)for as long as active + 12 months, or until deleted at the User's requestEnsuring service security and stability
Financial data (transactions, balance)for as long as active + 12 months, or until deleted at the User's requestLegal obligation
Support correspondencefor as long as active + 12 months, or until deleted at the User's requestPerformance of a contract
Data disclosed to developers via the Platform's functionalityfor as long as active + 12 months, or until deleted at the User's requestNot limited
Anonymized dataUnlimited (not considered personal data)Cell
9.3. Criteria for determining retention periods. The following criteria are used when setting retention periods:
- the necessity of the data for providing Reelly's services;
- contractual obligations to the User;
- Reelly's legitimate interests, including defense against claims;
- requirements of DIFC, EU, or other applicable jurisdictions;
- technical needs (e.g., backups);
- data minimization and access restriction.

9.4. Deleted data cannot be restored and is no longer used by Reelly. Once the established retention periods expire, data is deleted using one of the following methods:
- complete removal from active systems;
- anonymization, precluding the identification of the User;
- removal from backups as the backup cycle is updated.

9.5. Certain data may be retained for a longer period where necessary to comply with tax, accounting, or other legal requirements, where an open investigation into a violation of the Platform's terms of use exists, where it is needed to protect the rights of Reelly or the User in judicial or administrative proceedings, or where required by regulatory authorities (e.g., the DIFC Commissioner of Data Protection).

10. USER RIGHTS

10.1.
A User whose personal data is processed by Reelly holds all rights provided for under the DIFC Data Protection Law 2020. Exercising these rights is free of charge (except in strictly defined cases prescribed by law, e.g., abuse of requests).

10.2. Reelly ensures transparency of data processing, timely responses to user requests, and fulfilment of its obligations under applicable law. The User may send requests to: support@reelly.io.

10.3. Right of access to personal data. The User has the right to obtain:
- confirmation that personal data is being processed;
- a list of the data processed;
- the purposes of processing;
- categories of data;
- categories of third parties to whom the data is disclosed;
- retention periods;
- information about the mechanisms used for cross-border data transfer.

The request is processed within a period of up to 1 month.

10.4. Right to rectification of data. The User has the right to request the correction of inaccurate or outdated data and the completion of incomplete data. Reelly makes the changes within a reasonable period.

10.5. Right to erasure of data. The User may request the deletion of personal data if: the data is no longer needed for the purposes of processing; the processing is based on consent, and consent has been withdrawn; the data has been processed unlawfully; or the User has successfully objected to the processing. Exceptions apply where retention is required by law or is necessary to protect Reelly's rights.

10.6. Right to restriction of processing. The User may require the restriction of data processing if: the data is inaccurate; the processing is unlawful, but the User does not wish for the data to be deleted; Reelly no longer needs the data, but the User needs it to establish, exercise, or defend legal claims; or the User has objected to the legitimate interests relied upon. Where processing is restricted, the data is: not used, and is retained only for storage purposes or to protect rights.

10.7. Right to object to processing. The User has the right to object to processing based on: Reelly's Legitimate Interests, direct marketing, or behavioral analytics. Reelly will cease processing unless it can demonstrate legitimate grounds that override the User's interests. Exercising this right may result in certain Platform functions becoming unavailable or restricted.

10.8. Right to data portability. The User may receive their data in a structured, commonly used, machine-readable format, and/or transfer it to another controller. This applies to data: provided by the User themselves, and processed on the basis of consent or a contract.

10.9. Right to withdraw consent. Where processing is based on consent, the User may withdraw it at any time, without giving reasons. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.

10.10. Rights related to AI and profiling. Since Reelly does not use automated decisions that: create legal effects, or significantly affect the User, the User has the following guarantees:
- the right to request an explanation of the logic underlying the analytical tools;
- the right to request human review of analytical conclusions;
- the right to object to the use of profiling;
- the right to restrict the use of behavioral data (to the extent technically feasible).

10.11. Right to lodge a complaint. The User may:
- submit a complaint to Reelly at support@reelly.io;
- lodge a complaint with the Commissioner of Data Protection (DIFC) if they believe their rights have been violated.

10.12. Response times for requests. Reelly responds to User requests:
- within 1 month of receipt;
- this period may be extended by a further 1 month for complex requests (with mandatory notice to the User).

11. MARKETING COMMUNICATIONS

11.1.
Reelly may use the User's contact details to send informational and marketing messages, as well as to display personalized recommendations within the Platform. Marketing activities are carried out strictly in accordance with the requirements of the DIFC Data Protection Law 2020 and the principles of transparency.

11.2. Types of marketing communications. Depending on the User's interaction with the Platform, Reelly may send:
- notifications about new Platform features;
- recommendations for improving the profile and CRM performance;
- news about projects, properties, and opportunities in the real estate sector;
- messages about special offers and promotions;
- reminders about subscription status or available tariffs;
- educational materials and content aimed at improving the effectiveness of agents' and developers' work.

11.3. Bases for sending marketing messages. Marketing messages are sent on one of two legal bases:

11.3.1. User consent. The User gives consent voluntarily and may withdraw it at any time. Used for:
- email newsletters,
- SMS notifications (where applicable),
- advertising communications outside the Platform.

11.3.2. Reelly conducts a balancing-of-interests assessment and ensures that such messages do not infringe the User's rights and freedoms. Used for:
- notifications within the Platform,
- recommendations based on the User's actions,
- messages necessary to improve service quality.

11.4. Disclosure of data to advertising and analytics services. To implement marketing functions, Reelly may transfer technical or anonymized data to the following services:
- Meta (Facebook/Instagram Pixel);
- Google Analytics / GA4;
- Telegram / Manychat;
- newsletter services;
- advertising platforms.
Data is transferred:
- only to the minimum extent necessary;
- without transferring sensitive data;
- using protection mechanisms (including SCCs for transfers to the USA).

11.5. Personalized recommendations. Such recommendations do not constitute automated decision-making and do not produce legal effects. Reelly may display personalized recommendations and offers to the User based on:
- their activity;
- their interests within the Platform;
- their professional profile;
- their interaction with properties and CRM tools.

11.6. Opting out of marketing communications. The User may at any time:
- unsubscribe from email newsletters via the "Unsubscribe" link in the email;
- disable push notifications (where applicable);
- change notification settings within the Platform;
- send a request to support@reelly.io.
Opting out of marketing messages:
- does not affect access to the Platform;
- does not restrict the functionality of the services.

11.7. Restrictions on marketing activities. Reelly undertakes:
- not to use the User's personal data without a legal basis;
- not to disclose data to third parties for marketing purposes without the User's consent;
- not to use profiling for discriminatory or aggressive marketing practices.

12. SECURITY MEASURES

12.1.
Reelly takes technical and organizational measures to protect Users' personal data from unauthorized access, alteration, disclosure, or destruction. These security measures comply with the requirements of the DIFC Data Protection Law 2020 as well as international security standards.

12.2. Organizational security measures. Reelly ensures:
- allocation of access levels depending on employee role;
- restriction of access to only those employees who require it to perform their job duties;
- confidentiality of employees and contractors (NDAs and mandatory policies);
- regular employee training on information security and data protection fundamentals;
- appointment of a person responsible for data protection (Data Protection Lead/Manager);
- internal regulations governing the handling of personal data;
- procedures for responding to data-subject requests and regulator inquiries.

12.3. Technical security measures. The following are used to protect data:
- encryption of data in transit (TLS/HTTPS);
- encryption of data at rest (where applicable);
- protection of servers and infrastructure using modern security tools;
- systems for detecting anomalies and intrusion attempts;
- multi-factor authentication (MFA) for administrative panels;
- audit logging of actions;
- real-time system monitoring.

12.4. Data protection when using cloud services. Since data is stored in the EU (EU data centers):
- cloud providers (Google Cloud, etc.) are required to comply with EU security standards;
- access to data is governed by contractual restrictions (Data Processing Agreements);
- data is transferred in the minimum volume necessary;
- SCC mechanisms are used when interacting with services located outside the EU.

12.5. Restriction of data access. Reelly applies the principle of minimum necessary access (need-to-know), including:
- role-based segregation of employees;
- strict control of rights and permissions;
- regular audits of access rights;
- automatic revocation or narrowing of rights when an employee's role changes.

12.6. Data protection when processed by AI tools. AI tools are used within strict limits:
- data transferred to external AI providers is minimized;
- personal data is not used to train models unless expressly permitted by the User;
- secure API keys and protocols are used;
- algorithms operate in isolated environments;
- AI results are reviewed by humans (human oversight);
- the accuracy and quality of analytics is monitored.

12.7. Data protection when agents and developers interact. When a User's data is disclosed to other Platform participants:
- data is disclosed via the Platform's functionality, including when the User uses CRM, BRM, and other tools facilitating interaction between agents and developers;
- secure transmission channels are used;
- access is granted only to authorized representatives of developers or agents.

12.8. Protection of data from external threats. Reelly applies:
- continuous monitoring of unauthorized access attempts;
- intrusion detection systems (IDS/IPS);
- regular updates of security systems and libraries;
- control over API security;
- restriction of external integrations and access keys.

12.9. Backups
- data is backed up on a schedule ensuring business continuity;
- backups are stored in secure environments;
- backups are regularly updated and deleted once their retention period expires.

12.10. Risk assessment and security audits. Reelly conducts:
- regular internal security reviews;
- automated vulnerability analyses;
- risk assessments;
- audits of compliance with data protection controls.

13. DATA SECURITY BREACHES1

3.1.
Reelly takes all reasonable measures to protect Users' personal data. Nevertheless, in the event of a security incident, a response procedure applies, developed in accordance with the requirements of the DIFC Data Protection Law 2020.

13.2. In the event of a leak, unauthorized access, or other incident that may result in damage to, destruction, alteration, disclosure, or loss of personal data, Reelly undertakes to notify the Commissioner of Data Protection (DIFC) within 72 hours of becoming aware of the incident, where such incident poses a risk to the rights and freedoms of data subjects. The notification includes:
- a description of the nature of the incident;
- the categories of data affected;
- the number of Users affected;
- measures taken or proposed to address the consequences;
- measures taken to prevent similar incidents.

13.3. Reelly notifies Users where the incident is likely to cause them significant harm, creates a high risk to their rights and freedoms, or requires the User to take action (e.g., changing a password). Notification is sent:
- by email,
- via the Platform interface,
- by other available means, if required.

13.4. Internal response procedures. Reelly has internal procedures including:
- immediate detection and containment of the incident;
- analysis of scope and causes;
- blocking unauthorized access;
- restoring system integrity;
- coordination with technical providers;
- recording all actions in an incident log.

13.5. Incident log. Records are retained in accordance with DIFC Regulations. Reelly maintains a log of all data security incidents, including:
- date and time of detection;
- description of the incident;
- categories of data affected;
- response measures taken;
- information on notification of the regulator and Users.

13.6. Accountability and prevention of recurrence. Once an incident has been resolved, Reelly conducts:
- an internal security audit;
- an analysis of causes and vulnerabilities;
- an update of procedures and technical measures;
- employee training;a review of access rights and infrastructure configurations.

14. PROCESSING OF MINORS' DATA

14.1.
Reelly is intended for use by adult users — agents, brokers, developer representatives, and other professional real estate market participants. The Platform is not directed at children or minors.

14.2.
Prohibition on processing data of persons under 18. Reelly does not knowingly process the personal data of persons under 18 years of age. Registration, profile creation, use of the Platform, or the provision of data by minors is not permitted.

14.3. Age verification. Where necessary, Reelly may take reasonable measures to verify that a User is an adult, including:
- analyzing the data provided;
-verifying professional information (e.g., broker's license, agency employee data);
- requesting additional information in case of doubt.

14.4. Actions upon discovery of minors' data. If Reelly becomes aware that data of a person under 18 has been provided upon registration, uploaded to a profile, or disclosed due to a User's error, Reelly will: immediately delete such data, block the profile (if one was created), notify the person who provided the data (where possible), and take measures to prevent recurrence of similar cases.

14.5. User obligations. The User confirms that they:
- are at least 18 years of age;
- use the Platform for professional purposes;
- do not provide the personal data of minor third parties.

15. AMENDMENTS TO THIS POLICY

15.1.
Reelly reserves the right to update or amend this Policy at any time in order to:
- reflect changes in legislation (including the DIFC Data Protection Law);
- reflect new Platform features or updates;
- adapt to changes in the technologies used;
- ensure greater transparency and protection for Users.

15.2. Notification procedure for changes. Reelly notifies Users of material changes to the Policy by one or more of the following means:
- publishing the updated version on the website;
- notification within the Platform;
- sending an email to the address provided at registration;
- displaying a pop-up notification upon logging into the service.

15.3. Cases requiring renewed consent. In these cases, the Platform may request confirmation of consent before continuing processing. Renewed consent or an explicit action by the User may be required where the changes:
- materially change the purposes of data processing;
- expand the categories of data collected by the Platform;
- concern the disclosure of data to third parties for new purposes;
- affect data transferred outside the EU or DIFC;
- change the legal bases for processing that are based on consent.

15.4. Effect of the Policy after amendments. Continued use of the Platform following the publication of amendments constitutes the User's agreement to the updated Policy, unless explicit confirmation is otherwise required. The User is entitled to:
- stop using the Platform;
- delete their profile;
- seek clarification by emailing support@reelly.io.

16. CONTACT INFORMATION

16.1.
The User may contact Reelly with any questions relating to the processing of personal data, the exercise of their rights, or requests concerning this Policy. Contact details of the personal data Operator:

REELLY Tech Ltd
Unit 208, Level 1, Gate Avenue — South Zone
Dubai International Financial Centre
Dubai, United Arab Emirates
Commercial License No.: CL6648
Email for requests: support@reelly.io
Requests are reviewed within the period established by the DIFC Data Protection Law 2020.

16.2. The Company is not required to appoint a Data Protection Officer (DPO) under the DIFC Data Protection Law 2020 and has not currently appointed one. All matters relating to the processing of personal data may be directed to: support@reelly.io

16.3. Regulator's contact details — Commissioner of Data Protection (DIFC). The User has the right to lodge a complaint directly with the regulatory authority if they believe their rights have been violated.
Commissioner of Data Protection
Dubai International Financial Centre
The Gate, Level 14
P.O. Box 74777
Dubai, United Arab Emirates
Official website: https://www.difc.ae/business/registrars-and-commissioners/commissioner-of-data-protection/
Email: dpo@difc.ae

16.4. Complaint procedure. Reelly recommends contacting us first so that the matter can be resolved as quickly as possible. The User may:
1. Contact Reelly directly: support@reelly.io
2. If the resolution is not satisfactory, lodge a complaint with the Commissioner of Data Protection:
- via the online form on the DIFC website, or
- by email, as indicated above.
Back to main page