Zimyo HRMS
Legal

Privacy Policy

Last Updated: March 2026

Zimyo Technologies Limited (“Zimyo”, “we”, “us”, or “our”) is committed to protecting the privacy and security of visitors and users of our UAE website and HRMS platform (the “Platform” or “Site”).

This Privacy Policy explains how we collect, use, process, store, disclose, and safeguard Personal Data in accordance with applicable laws, including the data protection laws and regulations applicable in the Dubai International Financial Centre (DIFC) and other relevant data protection requirements.

By accessing or using our Site, you agree to the practices described in this Privacy Policy.

1. Personal Data We Collect

We may collect personal data when you visit our website, request a demo, register for events, contact us, subscribe to communications, apply for employment, or use our HRMS platform.

Categories of Personal Data may include:

  1. Identity Information: Full name, nationality, date of birth (where applicable)
  2. Contact Information: Email address, phone number, business address
  3. Professional Information: Job title, employer details, employment information, salary/HR data (when processed on behalf of customers)
  4. Technical Information: IP address, browser type, device identifiers, operating system
  5. Usage Information: Website interactions, preferences, survey responses
  6. Sensitive Personal Data (where applicable): Health information, biometric data, government identification details.

Such data is processed strictly in accordance with applicable law and customer instructions.

2. How We Use Personal Data

We use personal data for the following purposes:

Where required by law, we rely on appropriate lawful bases such as consent, contractual necessity, legal obligation, or legitimate interest. Where Zimyo processes personal data on behalf of customer organizations, such processing is carried out strictly under a binding Data Processing Agreement and in accordance with documented instructions from the customer, who remains the Data Controller.

Zimyo processes personal data only where there is a lawful basis under applicable law, including consent of the data subject, necessity for performance of a contract, compliance with a legal obligation, protection of vital interests, or legitimate business interests that do not override fundamental rights.

3. Zimyo as Data Controller and Data Processor

Depending on the circumstances:

In such cases, data is processed strictly in accordance with customer agreements and data processing terms.

4. Use of Artificial Intelligence (AI)

Zimyo may use AI-driven technologies to:

Such processing is conducted transparently, proportionately, and with appropriate safeguards to ensure fairness and data protection compliance.

5. Cookies and Tracking Technologies

We use cookies, web beacons, and similar technologies to:

You may disable cookies via browser settings; however, some features of the Site may not function properly.

We may use third-party analytics services (e.g., Google Analytics) to understand user interaction. These services collect anonymized statistical information.

6. Disclosure of Personal Data

We may share personal data with:

All third parties are contractually bound to maintain confidentiality and implement adequate security safeguards.

In case of a merger, acquisition, or business restructuring, personal data may be transferred as part of the transaction, subject to confidentiality protections. Zimyo reserves the right to disclose personal data where required to comply with applicable law, regulatory inquiry, court order, or lawful government request.

7. Data Retention & Account Deletion

Zimyo Technologies Limited established in the Dubai International Financial Centre (DIFC) processes Personal Data in accordance with DIFC Data Protection Law No. 5 of 2020 and applicable regulatory requirements.

Upon termination or expiry of a Customer’s subscription, access to the platform will be disabled. Personal Data may be retained for up to thirty (30) days solely to facilitate data retrieval, unless otherwise agreed in writing. Following this period, Personal Data will be securely deleted or irreversibly anonymized, except where continued retention is required for statutory, regulatory, audit, dispute resolution, or legal compliance purposes.

Zimyo acts as a Data Processor and processes Personal Data strictly on documented instructions from the Customer, who acts as the Data Controller.

Data Subjects may exercise their statutory rights, including rights of access, rectification, erasure, restriction of processing, and data portability, through the relevant Data Controller. Zimyo will provide reasonable assistance to Customers in fulfilling such obligations as required under applicable DIFC law.

8. Data Retention

We retain personal data only for as long as necessary to:

Upon expiry of retention periods, data is securely deleted or anonymized in accordance with our internal data retention and deletion policies.

9. Data Security Measures

Zimyo implements industry-standard technical and organizational measures, including:

To the maximum extent permitted by applicable law, Zimyo shall not be liable for any indirect, incidental, consequential, or special damages arising from unauthorized access to personal data, except where such liability arises from Zimyo’s gross negligence or willful misconduct.

10. Data Breach Notification

In the event of a personal data breach, Zimyo will take appropriate remedial actions and notify affected customers without undue delay in accordance with applicable data protection laws and contractual obligations. Where required by law, notifications will be made to competent regulatory authorities

11. Payment Information

Zimyo does not store full credit/debit card details on its servers. Payment information is processed through secure, PCI-compliant third-party payment gateways.

We do not sell, rent, or trade personal payment information.

12. Your Rights Under Applicable Law

Subject to applicable data protection laws, individuals may have the right to:

To exercise these rights, please contact us using the details below.

13. Children’s Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If such data is identified, it will be promptly deleted.

14. Third-Party Websites

Our Site may contain links to third-party websites. Zimyo is not responsible for the privacy practices of external websites. We encourage users to review their respective privacy policies.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect legal, technical, or business developments. Updates will be posted on this page with a revised “Last Updated” date.

Continued use of the Site after updates constitutes acceptance of the revised Privacy Policy.

16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact:

Zimyo
Email: support@zimyo.com
Website: www.zimyo.me