Last Updated: March 2026
Zimyo Technologies Limited (“Zimyo”, “we”, “us”, or “our”) is committed to protecting the privacy and security of visitors and users of our UAE website and HRMS platform (the “Platform” or “Site”).
This Privacy Policy explains how we collect, use, process, store, disclose, and safeguard Personal Data in accordance with applicable laws, including the data protection laws and regulations applicable in the Dubai International Financial Centre (DIFC) and other relevant data protection requirements.
By accessing or using our Site, you agree to the practices described in this Privacy Policy.
1. Personal Data We Collect
We may collect personal data when you visit our website, request a demo, register for events, contact us, subscribe to communications, apply for employment, or use our HRMS platform.
Categories of Personal Data may include:
- Identity Information: Full name, nationality, date of birth (where applicable)
- Contact Information: Email address, phone number, business address
- Professional Information: Job title, employer details, employment information, salary/HR data (when processed on behalf of customers)
- Technical Information: IP address, browser type, device identifiers, operating system
- Usage Information: Website interactions, preferences, survey responses
- Sensitive Personal Data (where applicable): Health information, biometric data, government identification details.
Such data is processed strictly in accordance with applicable law and customer instructions.
2. How We Use Personal Data
We use personal data for the following purposes:
- Providing access to our HRMS platform and website features
- Delivering customer support and responding to inquiries
- Managing employment and payroll functions (as a data processor for customers)
- Improving our products, services, and user experience
- Ensuring system security and fraud prevention
- Complying with legal and regulatory obligations
- Sending marketing communications (where legally permitted)
- Conducting internal audits and analytics
Where required by law, we rely on appropriate lawful bases such as consent, contractual necessity, legal obligation, or legitimate interest. Where Zimyo processes personal data on behalf of customer organizations, such processing is carried out strictly under a binding Data Processing Agreement and in accordance with documented instructions from the customer, who remains the Data Controller.
Zimyo processes personal data only where there is a lawful basis under applicable law, including consent of the data subject, necessity for performance of a contract, compliance with a legal obligation, protection of vital interests, or legitimate business interests that do not override fundamental rights.
3. Zimyo as Data Controller and Data Processor
Depending on the circumstances:
- Zimyo acts as a Data Controller when collecting personal data directly from website visitors, prospects, or employees.
- Zimyo acts as a Data Processor when processing employee data on behalf of customer organizations using our HRMS platform.
In such cases, data is processed strictly in accordance with customer agreements and data processing terms.
4. Use of Artificial Intelligence (AI)
Zimyo may use AI-driven technologies to:
- Automate HR workflows
- Enhance analytics and reporting
- Improve employee engagement insights
- Personalize user experiences
Such processing is conducted transparently, proportionately, and with appropriate safeguards to ensure fairness and data protection compliance.
5. Cookies and Tracking Technologies
We use cookies, web beacons, and similar technologies to:
- Improve website functionality
- Analyze traffic and usage trends
- Enhance user experience
- Support marketing and advertising efforts
You may disable cookies via browser settings; however, some features of the Site may not function properly.
We may use third-party analytics services (e.g., Google Analytics) to understand user interaction. These services collect anonymized statistical information.
6. Disclosure of Personal Data
We may share personal data with:
- Cloud hosting providers
- IT service providers
- Payment processors
- Marketing service providers
- Regulatory authorities (where legally required)
- Professional advisors (legal, audit, compliance)
All third parties are contractually bound to maintain confidentiality and implement adequate security safeguards.
In case of a merger, acquisition, or business restructuring, personal data may be transferred as part of the transaction, subject to confidentiality protections. Zimyo reserves the right to disclose personal data where required to comply with applicable law, regulatory inquiry, court order, or lawful government request.
7. Data Retention & Account Deletion
Zimyo Technologies Limited established in the Dubai International Financial Centre (DIFC) processes Personal Data in accordance with DIFC Data Protection Law No. 5 of 2020 and applicable regulatory requirements.
Upon termination or expiry of a Customer’s subscription, access to the platform will be disabled. Personal Data may be retained for up to thirty (30) days solely to facilitate data retrieval, unless otherwise agreed in writing. Following this period, Personal Data will be securely deleted or irreversibly anonymized, except where continued retention is required for statutory, regulatory, audit, dispute resolution, or legal compliance purposes.
Zimyo acts as a Data Processor and processes Personal Data strictly on documented instructions from the Customer, who acts as the Data Controller.
Data Subjects may exercise their statutory rights, including rights of access, rectification, erasure, restriction of processing, and data portability, through the relevant Data Controller. Zimyo will provide reasonable assistance to Customers in fulfilling such obligations as required under applicable DIFC law.
8. Data Retention
We retain personal data only for as long as necessary to:
- Fulfill contractual obligations
- Comply with legal and regulatory requirements
- Resolve disputes
- Enforce agreements
Upon expiry of retention periods, data is securely deleted or anonymized in accordance with our internal data retention and deletion policies.
9. Data Security Measures
Zimyo implements industry-standard technical and organizational measures, including:
- End-to-end encryption of sensitive data
- Role-based access controls
- Multi-factor authentication
- Secure cloud infrastructure
- Periodic vulnerability assessments
- Security audits and monitoring
To the maximum extent permitted by applicable law, Zimyo shall not be liable for any indirect, incidental, consequential, or special damages arising from unauthorized access to personal data, except where such liability arises from Zimyo’s gross negligence or willful misconduct.
10. Data Breach Notification
In the event of a personal data breach, Zimyo will take appropriate remedial actions and notify affected customers without undue delay in accordance with applicable data protection laws and contractual obligations. Where required by law, notifications will be made to competent regulatory authorities
11. Payment Information
Zimyo does not store full credit/debit card details on its servers. Payment information is processed through secure, PCI-compliant third-party payment gateways.
We do not sell, rent, or trade personal payment information.
12. Your Rights Under Applicable Law
Subject to applicable data protection laws, individuals may have the right to:
- Request access to their personal data
- Request correction of inaccurate data
- Request deletion of personal data
- Restrict or object to certain processing
- Withdraw consent (where applicable)
- Request data portability
To exercise these rights, please contact us using the details below.
13. Children’s Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If such data is identified, it will be promptly deleted.
14. Third-Party Websites
Our Site may contain links to third-party websites. Zimyo is not responsible for the privacy practices of external websites. We encourage users to review their respective privacy policies.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, technical, or business developments. Updates will be posted on this page with a revised “Last Updated” date.
Continued use of the Site after updates constitutes acceptance of the revised Privacy Policy.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact:
ZimyoEmail: support@zimyo.com
Website: www.zimyo.me