Privacy Policy

Effective Date: 01 July 2025

Welcome to Nestr, a digital platform operated by Nestaway Proptech MENA Real Estate LLC (“Nestaway”, “we”, “us”, or “our”). At Nestaway, we are committed to protecting your personal data and privacy in line with applicable laws and regulations.


This Privacy Policy outlines how we collect, use, store, share, and safeguard your personal data through the Nestr website, mobile application, and services (collectively, the “Platform”). It is drafted in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and other applicable data protection regulations, including Cabinet Decision No. 6 of 2022 and global best practices under the EU General Data Protection Regulation (GDPR) where relevant.

1. Who We Are

Nestaway Proptech MENA Real Estate LLC
Registered Office: Nestaway Proptech MENA Real Estate LLC, Office No. 2002, Aspect Tower, Business Bay, Dubai, UAE
Email: info@nestr.ae


We operate the Platform and act as the Data Controller of your personal data, determining the purpose and means of processing, except where we act on behalf of another party.

2. Legal Framework and Scope

This Policy is issued pursuant to:

  • Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) – UAE
  • Cabinet Resolution No. 6 of 2022 on the Executive Regulations of the PDPL
  • Federal Law No. 15 of 2020 on Consumer Protection (where applicable)
  • Best practices from the EU General Data Protection Regulation (GDPR)

This policy applies to all individuals whose personal data we collect in connection with their use of the Platform, including tenants, landlords, users browsing the platform and vendors.

3. Information We Collect

We may collect the following categories of personal data:

a. Data You Provide Voluntarily

  • Full name, date of birth, email address, contact number
  • Government-issued ID (e.g., Emirates ID, passport, visa copy)
  • Address and property-related details
  • Financial or bank account details for payment/refund processing
  • Communication preferences and user feedback

b. Data Collected Automatically

  • IP address and device identifiers
  • Browser type and settings
  • Usage and interaction data (pages viewed, buttons clicked, timestamps)
  • Location data (if enabled)
  • Cookies and similar technologies

c. Data from Third Parties

  • Background or identity verification data from third-party KYC providers
  • Referral or marketing partners
  • Government databases (where permitted)

4. Purpose and Legal Basis of Processing

We process your personal data based on lawful grounds, as per Article 4 of the PDPL:

PurposeLegal Basis
To create and manage your user profilePerformance of a contract
To verify identity, perform KYC, and comply with AML obligationsCompliance with legal obligations
To list or rent propertiesContractual necessity
To process payments and refundsLegitimate interest and/or contract
To provide customer support and resolve issuesLegitimate interest
To analyze and improve Platform performanceLegitimate interest
To send service updates, alerts, or marketing (with consent)Consent (as per Article 6 of PDPL)
To respond to legal requests or enforce rightsCompliance with law

5. Data Sharing and Disclosure

We may share your personal data with:

  • Aurum PropTech (our parent organization, for platform support and analytics)
  • Payment processors (e.g., Stripe, PayTabs)
  • Landlords or tenants to facilitate communication and transactions
  • Identity verification or background check providers
  • Third-party service providers (e.g., cloud storage, analytics, customer support)
  • Regulatory and government authorities, as required by UAE law

We do not sell your personal data under any circumstance. All third parties are contractually bound to handle your data in accordance with applicable data protection laws and only for the intended purpose.

6. International Data Transfers

Where data is processed or stored outside the UAE (e.g., in the EU or India), we ensure:

  • Transfers are permitted under Articles 23 and 24 of the PDPL.
  • Appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs), data transfer agreements,or data localization measures.
  • You will be notified where legally required if your data is transferred abroad.

7. Your Rights Under UAE PDPL

Under the UAE PDPL, you have the following rights, which you can exercise at any time:

  • Right to access – Obtain confirmation and a copy of your personal data
  • Right to correction – Rectify inaccurate or incomplete personal data
  • Right to erasure – Request deletion under certain conditions
  • Right to restrict processing – Temporarily halt processing under specified grounds
  • Right to data portability – Receive your data in a structured format
  • Right to object – Object to processing based on legitimate interest or direct marketing
  • Right to withdraw consent – Where processing is based on consent

To exercise your rights, contact us at info@nestr.ae. We will respond within the timeframe specified under PDPL i.e. 30 days

8. Data Security

We take appropriate organizational, technical, and procedural safeguards to protect your personal data:

  • Secure Sockets Layer (SSL) encryption
  • Firewalls, data loss prevention (DLP) and endpoint protection
  • Access controls and role-based access
  • Employee data protection training
  • Regular penetration testing and system audits

Despite our efforts, no security system is completely foolproof. We advise you to protect your login credentials and report suspicious activity.

9. Data Retention

We retain personal data:

  • For the duration of the user’s relationship with us
  • For as long as required to fulfill the purposes for which it was collected
  • For the duration required by UAE legal, accounting, or regulatory obligations

After this period, data is either deleted or anonymized in a secure manner.

10. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Maintain user sessions
  • Remember your preferences
  • Analyze traffic and usage
  • Improve platform performance

You may manage cookie preferences through your browser or through the cookie consent banner available on our Platform.

11. Children’s Privacy

The Platform is not intended for children under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected data from a child without verified parental consent, we will take steps to delete that data immediately.

12. Third-Party Links and Services

Our Platform may include links to third-party websites, plug-ins, or applications. Clicking on those links or enabling connections may allow third parties to collect or share data about you. We are not responsible for their privacy practices and encourage you to read their privacy policies.

13. Updates to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Effective Date” and notify users where required by law. We recommend reviewing this policy periodically to stay informed.

14. Contact Us

For any questions, concerns, or to exercise your data rights, please contact:

Data Protection Officer (DPO)

Nestaway Proptech MENA Real Estate LLC

Email: info@nestr.ae

Address: Nestaway Proptech MENA Real Estate LLC, Office No. 2002, Aspect Tower, Business Bay, Dubai, UAE