Last updated: 10 October 2026
This Privacy and Compliance Policy (the "Policy") explains how Viva Viajes FZC LLC ("Viva Viajes", "the Company" or "we") processes personal data in relation to its website, corporate enquiries and B2B services for technology consultancy, process automation, marketing, communications, operational management and commercial agency.
The Company applies this Policy in accordance with the Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), its Executive Regulations, applicable decisions and other relevant mandatory rules. The official UAE Government portal describes the PDPL as a federal framework for confidentiality, privacy, data governance, and the rights and duties of the parties.
1. Controller and scope
The controller is Viva Viajes FZC LLC, Commercial Licence No. 4311805.01, TRN 104859148900001, with registered address at Business Center, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates.
This Policy applies to personal data processed through the website, forms, commercial communications, procurement processes and the performance of B2B services. It is not intended to replace a data processing agreement when Viva Viajes acts as a processor on behalf of a corporate client; in that case, the documented instructions and the applicable contract shall prevail.
2. Categories of data we may process
- Identification and contact details, such as name, position, corporate email, telephone and organisation.
- Information about the enquiry, requirement, area of interest, communications and documentation that the data subject chooses to share.
- Limited technical data, such as IP address, browser, device, security logs and events necessary to operate and protect the site.
- Contractual, billing and compliance information of the client entity, where necessary to deliver services.
We do not request sensitive data for ordinary enquiries. The data subject must not submit via the form health, biometric or personal financial data, credentials, full card numbers or other unnecessary sensitive information.
3. Purposes and bases of processing
We process personal data only to the extent necessary, lawfully, transparently and for specified purposes. The purposes may include:
- Responding to corporate enquiries, preparing proposals and taking requested pre-contractual steps.
- Entering into, administering and performing consultancy and automation contracts.
- Managing communications, support, project coordination and the professional relationship.
- Protecting the security, availability and integrity of systems, users and digital assets.
- Complying with legal, regulatory, tax, accounting or audit obligations, or valid requests from authorities.
- Establishing, exercising or defending rights and claims.
- Sending marketing communications where there is a legal basis, and consent where required; the data subject may object or withdraw consent easily.
Where processing is based on consent, such consent must be specific, clear, informed and demonstrable. Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before its withdrawal. Withdrawal may limit the ability to provide a functionality or respond to a request.
4. Cookies and similar technologies
The site may use technologies that are strictly necessary for its operation, security, preferences and aggregated measurement, in accordance with the applicable configuration. Non-essential cookies will only be used where there is a valid basis and, where applicable, consent. The user may manage cookies from the browser; disabling them may affect some functions.
5. Service providers and limited disclosure
We may share data with providers that deliver hosting, infrastructure, security, communications, support, limited analytics, professional services or payment processing, always under instructions, contracts and appropriate confidentiality and security measures. We may also disclose information where necessary to comply with the law, respond to a competent authority, protect rights, or prevent fraud and abuse.
The Company does not sell personal data nor use it for purposes incompatible with those stated in this Policy.
6. Payments and card data
If in future online payment processing is enabled via a secure gateway, such as Stripe, payment data will be entered and processed within the infrastructure of the relevant provider, not in Viva Viajes' own systems. The Company will not store sensitive bank card data, such as the full number, security code or PIN.
Transmission and processing will be carried out under encrypted controls and international security standards applicable to the payment provider. The provider may process the data as an independent controller in accordance with its own terms and policies. Before enabling a payment flow, this Policy will be updated and the information required for that operation will be presented.
7. International transfers
Due to the international nature of technology infrastructure and providers, some data may be processed outside the UAE. Viva Viajes will carry out cross-border transfers only where there is an adequate level of protection or where a basis and safeguard permitted by the PDPL applies, such as an appropriate contractual arrangement, explicit consent, contractual necessity or the establishment, exercise or defence of rights, as applicable.
Reasonable measures will be applied to limit access, protect confidentiality and document relevant transfers. Information about recipients or categories of recipients may be requested via the contact channel indicated in this Policy.
8. Information security
The Company applies technical and organisational measures that are reasonable and proportionate to the risk, which may include access controls, minimisation, segregation, encryption or pseudonymisation where appropriate, backup and recovery, event logging, supplier management, confidentiality and control reviews.
No system connected to the internet is completely invulnerable. The user must protect their own devices, credentials and communication channels. If a data breach occurs that may affect privacy or security, Viva Viajes will act in accordance with the PDPL and the applicable requirements on assessment, notification, mitigation and cooperation.
9. Retention and deletion
We will retain data only for as long as necessary for the stated purpose, the contractual relationship, the management of claims and the fulfilment of legal obligations. When no longer necessary, it will be deleted, anonymised, or retained in a restricted manner only where a legal obligation or the defence of rights justifies it.
10. Rights of the data subject
Subject to the scope, exceptions and conditions of the PDPL and other applicable rules, the data subject may request information about their data and purposes, access, correction or completion of inaccurate data, transfer in a structured format where applicable, deletion, restriction or objection to processing, as well as withdraw their consent and object to direct marketing communications.
To exercise a right, send a clear request via the corporate contact form, identifying the request and providing reasonable information to verify it. We may request clarifications or supporting proofs of identity. We will respond within the timeframe required by applicable law or, where no specific period exists, within a reasonable time.
11. Processors, Data Protection Officer and complaints
Where Viva Viajes appoints processors, it will select providers with sufficient guarantees and will set out in writing the subject-matter, purpose, duration, categories of data, instructions and applicable measures. The designation of a Data Protection Officer will be made when required by the PDPL or by applicable regulation, taking into account the nature, volume and risk of the operations.
If you consider that the processing infringes the PDPL, you may lodge a complaint with Viva Viajes via the indicated channel and, without prejudice to other rights, with the competent UAE data protection authority in accordance with its procedures.
12. Changes to this Policy
We may update this Policy to reflect legal, regulatory, operational, technological or service changes. The current version will be published on this page and will display its update date. If a change is material, we will take reasonable steps to communicate it where required by law.
13. Governing law and jurisdiction
This Policy and any dispute relating to data processing, the website or corporate services shall be governed by the laws of the United Arab Emirates and the Emirate of Sharjah, without prejudice to the mandatory rights to which the data subject is entitled.
Any dispute, claim or controversy shall be submitted to the exclusive jurisdiction of the Sharjah Courts, to the extent permitted by law.
14. Official reference sources
The regulatory information in this Policy has been structured with reference to the official text of the Federal Decree by Law No. (45) of 2021 and the explanation of the official UAE Government portal.