Legal

Privacy Policy

This policy explains what personal data we collect when you use our website, why we collect it, and what rights you have.

Last updated: 27 September 2026

Who is responsible

The controller responsible for processing personal data on this website is Hoti International FZCO, Dubai, United Arab Emirates. The controller’s full name, address and contact details are listed on our Legal Notice page.

We serve clients in the United Arab Emirates, Germany and the wider European Union, and internationally. This policy is written mainly around the EU General Data Protection Regulation (GDPR). Where the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, “PDPL”) applies, we handle your data in line with its principles as well: lawful and transparent processing, purpose limitation, data minimisation, accuracy, security and respect for your rights.

What data we collect

When you contact us

This website has no contact forms. If you contact us by email, WhatsApp or phone — for example to request an SEO audit, an AI visibility audit or to discuss an influencer campaign — we process the details you choose to share, typically your name, company, email address or phone number, website address and the content of your message.

Server log files

When you visit the website, our hosting provider automatically records technical information in server log files. This can include your IP address, the date and time of the request, the page requested, the referring URL, the browser and operating system used, and the HTTP status code. We need this data to deliver the website, keep it stable and protect it against misuse.

If you agree in our cookie banner, we collect usage data such as pages viewed, time on page, clicks and scrolling, approximate location, device type and how you arrived at the site. See “Analytics and cookies” below.

  • Answering audit requests and enquiries. We use the details you send us by email, WhatsApp or phone to prepare your audit, reply to your message and discuss a possible engagement. The legal basis is Art. 6(1)(b) GDPR (steps taken at your request before entering into a contract). Where no contract is being considered, the basis is Art. 6(1)(f) GDPR, our legitimate interest in answering enquiries addressed to us.
  • Operating and securing the website. Server log data is processed on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in delivering the website reliably and securely and in detecting and preventing attacks.
  • Analytics. We use analytics only with your consent, under Art. 6(1)(a) GDPR, and in line with the applicable rules on storing information on your device (for example § 25 TDDDG in Germany).

Hosting

Our website is hosted by an external hosting provider that processes server log data on our behalf under a data processing agreement. The provider may be based in the United States, so personal data may be transferred there. Such transfers rely on the EU Standard Contractual Clauses and, where applicable, the provider’s certification under the EU-US Data Privacy Framework.

Analytics and cookies

With your consent, we use Google Analytics 4, loaded through Google Tag Manager. Both are provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses cookies and similar technologies to help us understand how visitors use our website so we can improve content and structure. IP addresses are not logged or stored in Google Analytics 4.

With your consent, we also use Microsoft Clarity, provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Clarity shows us how visitors use our pages — for example clicks, scrolling and mouse movements — as aggregated heatmaps and session recordings, so we can find and fix usability problems. Clarity masks text you type and sensitive content by default. It uses cookies and similar technologies and may process data in the United States; such transfers rely on the EU-US Data Privacy Framework, under which Microsoft is certified, and on Standard Contractual Clauses. Clarity is only loaded after you accept analytics in our cookie banner. More information: Microsoft Privacy Statement.

We use Google Consent Mode. Until you give consent, Google Analytics does not set analytics cookies and does not collect analytics data. Data processed by Google may be transferred to Google LLC in the United States. Such transfers rely on the EU-US Data Privacy Framework, under which Google LLC is certified, and on Standard Contractual Clauses.

You can withdraw or change your consent at any time using the “Cookie settings” link in the footer of every page. Withdrawing consent does not affect whether processing carried out before the withdrawal was lawful.

We do not use advertising or remarketing cookies.

Fonts

All fonts on this website are hosted on our own infrastructure. Your browser does not connect to Google Fonts or any other external font service when you visit the site.

Contact by email, WhatsApp or phone

If you email us, we process your email address, the content of your message and any details you include so we can reply. The legal basis is Art. 6(1)(b) or (f) GDPR, as described above.

If you choose to contact us via WhatsApp, your messages and related data (such as your phone number and profile information) are also processed by WhatsApp Ireland Limited / Meta under its own terms and privacy policy, which may involve transfers outside the EU. We have no control over that processing. If you would prefer not to use WhatsApp, please contact us by email or phone instead.

Recipients

We only share your personal data where necessary for the purposes described in this policy. Recipients may include:

  • Our hosting provider
  • Google and Microsoft, if you have consented to analytics
  • IT and email service providers who support our business operations under data processing agreements
  • Public authorities, where we are legally required to disclose data

We do not sell your personal data.

International transfers

Some of the service providers named above process data outside the European Economic Area or outside the UAE. Where this happens, we make sure appropriate safeguards are in place, such as an adequacy decision, the EU-US Data Privacy Framework, or the EU Standard Contractual Clauses. We also comply with the cross-border transfer requirements of the UAE PDPL where they apply.

How long we keep data

  • Enquiries and audit requests are kept for as long as needed to handle your request. If no business relationship follows, we generally delete them within 24 months of our last contact with you.
  • Data from client engagements is kept for the duration of the engagement and then for any statutory retention periods, for example under commercial and tax law.
  • Server log files are kept by the hosting provider for a limited period, usually no more than 30 days, unless they are needed longer to investigate a specific security incident.
  • Analytics data is kept for no longer than 14 months.

Your rights

Subject to the legal requirements, you have the right to:

  • Access the personal data we hold about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Object to processing based on legitimate interests (Art. 21 GDPR)
  • Withdraw consent at any time with effect for the future (Art. 7(3) GDPR)
  • Lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live or work or where the alleged infringement took place. In the UAE, you may contact the competent data protection authority.

You can exercise your rights using the contact details on our Legal Notice page or through our contact page.

No automated decision-making

We do not make decisions based solely on automated processing, including profiling, that have legal or similarly significant effects on you.

Is providing data required?

You are under no legal or contractual obligation to give us your personal data. However, we cannot prepare an audit or reply to an enquiry without the details needed to do so.

Security

We use appropriate technical and organisational measures to protect your data. These include encrypted HTTPS connections for the whole website, limited access to personal data, and careful selection of our service providers. No transmission over the internet is completely secure, but we work to keep risks as low as reasonably possible.

Changes to this policy

We may update this privacy policy when our website, our services or the legal requirements change. The current version is always published on this page, and the date at the top shows when it was last updated.