Privacy
Policy
Last updated: 09.07.2026
See previous version
See previous version
PERSONAL DATA PROCESSING POLICY
This Privacy Policy explains how and why we, Meera Group FZ-LLC., a company incorporated and existing under the laws of United Arab Emirates, having its registered office at Dubai, United Arab Emirates, Dubai Internet City, building 1 (“Data Controller“ or “We”), process Personal Data we collect or receive from or about you when you:
- Browse or visit our website https://meera.me/ (“Website”);
- Make use of, or interact with, our mobile application (“Application”) account according to our User Agreement https://meera.me/terms/ (“User Agreement”);
- Create an Account and when you log in the Application;
- Contact us (e.g., customer support, need help, submit a request);
- Subscribe to our newsletter(s) / blog(s) / social community(s).
Please note that your use of our Application and Website is subject to our User Agreement.
This Privacy Policy is issued in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL") and its implementing regulations (Cabinet Resolution No. 33 of 2024), as well as the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), to the extent each instrument applies to the respective category of users and processing activities. Where the PDPL and the GDPR impose different requirements, we apply the standard most protective of your rights in each applicable context.
If you have any questions of understanding or other queries about data protection, you are welcome to contact our Data Protection Officer or the other contact details provided in the Policy below:
Controller
The controller for the processing of your personal data is Meera Group FZ-LLC
Email: help@meera.me
Identification number: 101897
Address: Dubai, United Arab Emirates, Dubai Internet City, building 1
Email: help@meera.me
Identification number: 101897
Address: Dubai, United Arab Emirates, Dubai Internet City, building 1
Data Protection Officer
Controller has appointed a data protection officer in accordance with Art. 37 GDPR. You can contact our data protection officer, Evgenii Tabakov, via the following channels:
Email: e.tabakov@meera.me
Email: e.tabakov@meera.me
Role of the Data Protection Officer
The Data Protection Officer ("DPO") acts independently in accordance with Article 38 GDPR. The DPO is involved in all matters relating to the protection of Personal Data from the earliest possible stage, including data protection impact assessments (where applicable), monitors compliance with applicable data protection legislation, advises the Controller on its obligations under the GDPR and applicable laws, cooperates with supervisory authorities and serves as a contact point for data subjects and supervisory authorities.
The DPO performs their tasks independently, receives no instructions regarding the exercise of those tasks, reports directly to the highest management level of the Controller and is not dismissed or penalised for performing the duties of the DPO.
We do not have an establishment in the European Union but offer the Application and Website to users in the EU. We have appointed a representative in the EU pursuant to Article 27 GDPR:
Contact details of the EU representative: Alonzov Sergey, s.alonzov@meera.me
Contact details of the EU representative: Alonzov Sergey, s.alonzov@meera.me
The EU Representative has been designated pursuant to Article 27 GDPR solely for the purposes of facilitating compliance with the GDPR. The appointment of the EU Representative does not constitute an establishment of the Controller in the European Union.
The EU Representative acts as a contact point for supervisory authorities and data subjects regarding all issues related to the processing of Personal Data under the GDPR.
Content Safety Officer
The Controller has designated a Content Safety Officer responsible for overseeing compliance with applicable laws and internal policies relating to user-generated content.
The Content Safety Officer is responsible for:
- supervising content moderation procedures;
- coordinating the review of reports concerning illegal or harmful content;
- ensuring timely implementation of measures required under applicable law;
- coordinating interaction with competent governmental authorities where required by applicable law;
- overseeing internal procedures relating to the prevention of unlawful content and user safety.
Reports relating to illegal or prohibited content may be submitted to: e.tabakov@meera.me
UAE Data Protection Compliance:
As a company registered in Dubai Internet City, UAE, we process Personal Data in accordance with the PDPL. For matters relating specifically to the processing of Personal Data of UAE residents or processing activities taking place within the UAE, you may also contact us at: help@meera.me or the postal address above.
UAE Data Protection Regulator:
The competent authority overseeing compliance with the PDPL is the UAE Data Office (Office of the UAE Data Commissioner). UAE residents may file a complaint with the UAE Data Office at: www.uaedataoffice.ae
TABLE OF CONTENTS
- OUR PRINCIPLES AND PROCESSING OF PERSONAL DATA
- PERSONAL DATA WE DO NOT PROCESS
- WHERE DO WE GET YOUR PERSONAL DATA FROM?
- HOW AND WHY DO WE PROCESS YOUR PERSONAL DATA?
- PROCESSING OF LOCATION DATA
- PRIVACY AND VISIBILITY CONTROLS
- COOKIES
- USER-GENERATED CONTENT
- HOW LONG DO YOU STORE MY PERSONAL DATA?
- CROSS-BORDER TRANSFERS
- WHO DO YOU SHARE MY PERSONAL DATA WITH?
- DELETING YOUR ACCOUNT
- MARKETING EMAILS
- YOUR RIGHTS UNDER DATA PROTECTION LAW
- SECURITY OF YOUR PERSONAL DATA
- CHANGES TO THE POLICY
1. OUR PRINCIPLES AND PROCESSING OF PERSONAL DATA
1.1.
We process your personal data only when this is necessary and only for specific purposes explained in this Policy.
1.2.
We process personal data in accordance with the principles of lawfulness, fairness, transparency, data minimisation, accuracy, storage limitation, and security.
1.3.
Our Website and Application may contain links to third-party websites. If you follow such a link, the privacy practices of that third party apply. We do not control and are not responsible for how third-party websites process your personal data.
1.4.
We may enable you to interact with third party websites, mobile software applications and products or services that are not owned or controlled by us (each a “Third Party Service”). We are not responsible for the privacy practices or the content of such Third Party Services. Please be aware that Third Party Services can collect personal data from you. Accordingly, we encourage you to read the terms and conditions and privacy policies of each Third Party Service.
1.5.
The Application and Website are offered to users in multiple jurisdictions and are not specifically directed at any single jurisdiction. Payments for subscriptions and in-app purchases are processed in EUR through authorized app store providers.
1.6.
We process Personal Data of UAE residents in accordance with the principles established under the UAE PDPL, including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. We do not process Personal Data for purposes incompatible with those for which it was originally collected without a new lawful basis under the PDPL.
2. PERSONAL DATA WE DO NOT PROCESS
2.1.
Data of children.
The Application is not intended for children below the minimum age required to provide valid consent under applicable data protection laws. If We become aware that We have collected Personal Data from a child without appropriate consent where required by law. We will take steps to delete such information.
We do not knowingly collect personal data from children. If we become aware that Personal Data of a child has been collected, we will delete it without undue delay.
In the event that we become aware that you provide personal data in violation of applicable privacy laws, we reserve the right to delete it.
Under UAE law, a child is a person under the age of eighteen (18) years. Under EU law, the minimum age for valid consent to information society services is sixteen (16) years, unless a lower age (not less than thirteen (13) years) has been established by the law of the applicable EU Member State. We apply the age threshold required by the law applicable to the relevant user's jurisdiction.
2.2.
Special categories of personal data.
For UAE residents, special categories of Personal Data under the UAE PDPL include: health data, genetic data, biometric data processed for identification purposes, data relating to criminal convictions or offences, financial account data, data revealing ethnic or racial origin, religious or philosophical beliefs, and any other category designated as sensitive by the UAE Data Office. For EU residents, special categories are defined in Article 9 GDPR. We do not intentionally collect any of the foregoing categories.
We do not intentionally collect or process special categories of personal data as defined under applicable data protection laws.
If you voluntarily provide such information (for example, within user-generated content), We will process it only as necessary to provide the requested service and in accordance with applicable law.
You may optionally upload a photo or create an avatar. We process the photo and related technical data solely to provide the feature you requested. You can use the Application without uploading a photo. We do not use your photo for biometric identification or to verify your identity.
2.3.
No sale of Personal Data.
We do not sell your personal data for money.
We also do not rent or trade your personal data to third parties.
2.4.
If you believe that we have collected such information, please directly contact Us immediately help@meera.me in order to delete this information and resolve issues.
3. WHERE DO WE GET YOUR PERSONAL DATA FROM?
3.1.
We collect personal data from the following sources:
3.1.1.
Directly from you, when you voluntarily provide information through the contact form on the Website, by email, or through other direct communications with us;
3.1.2.
Automatically, when you access and use the Application or Website, through technical means such as server logs, cookies, and similar technologies, as described in this Privacy Policy and our Cookie Policy;
3.1.3.
From third parties, only where necessary for the purposes set out in this Privacy Policy, and in User Agreement and in accordance with applicable law (for example, from service providers involved in Website or Application hosting, analytics, or business communications);
3.1.4.
From third-party communication or verification delivery providers, where verification codes or service-related messages are delivered through such providers;
3.1.5.
From app stores and platform providers: where you make in-app purchases, we receive purchase confirmations and transaction-related identifiers from the relevant app store (e.g., Apple App Store, Google Play) to enable access to purchased content and handle refunds/support requests.
4. HOW AND WHY DO WE PROCESS YOUR PERSONAL DATA?
4.1.
Some personal data is required for us to provide the Application and related services (for example, to create and secure your Account). If you do not provide such mandatory data, we may be unable to provide certain features of the Application. Other data is optional (for example, uploading a photo to create a realistic avatar or contacting us via support channels). You can always choose not to use optional features.
4.2.
Certain information contained in your Account may be visible to other users of the Application depending on your privacy settings. You can control the visibility of your profile information, including your profile details and location data, through the Application settings. Where you choose to make your profile or specific information publicly available (including precise or approximate location), such information may be accessible to other users of the Application.
The list below explains why and how we process your Personal Data and which legal bases apply:
4.3.
Registration, creation and management of user Account
We process personal data to allow you to create and manage an Account, authenticate users, provide access to Account-related functionalities, and administer the contractual relationship with you.
What personal data do you process?
- Username;
- full name;
- date of birth;
- gender;
- profile photo;
- country;
- email address;
- phone number;
- login and password;
- one-time password (OTP) verification data;
- country or region (approximate location);
- precise location data (optional);
- vehicle information (optional);
- device and security logs.
What is your legal basis to process my personal data?1
Performance of a contract or for taking steps prior to entering into a contract.
We process your personal data to perform the contract you have entered with Us by accepting our User Agreement.
4.4.
Provision of access to the Website and Application to you
Providing with access to the Website, Application, information and/or materials contained on the Website.
Ensuring quality and stable operation of the Website and Application
What personal data do you process?
- IP address;
- technical identifiers necessary for establishing a connection;
- cookie data required for the functioning of the Website;
- session identifiers;
- browser type and version;
- operating system and device type, used Application version;
- request and response metadata;
- diagnostic data (e.g. crash reports, system or application logs, error reports and technical failure data, user reports).
What is your legal basis to process my personal data?1
Legitimate interests of the Data Controller in ensuring the secure, stable and proper operation of the Website and Application.
4.5.
Location-based functionality and displaying events and other location-based content
What personal data do you process?
- Precise location,
- map interaction data;
- privacy settings relating to location sharing.
What is your legal basis to process my personal data?1
Consent of data subject.
4.6.
Age eligibility, preventing unlawful use of the Application by underage users and ensuring age-appropriate access
What personal data do you process?
- Date of birth or age confirmation (self-declared);
- country/region (where needed to apply local age rules).
What is your legal basis to process my personal data?1
Legitimate interests (compliance and child protection).
4.7.
Account authentication and security
We process personal data to authenticate users, prevent unauthorized access, detect suspicious activity, and ensure the security of Accounts.
What personal data do you process?
- Login and password;
- IP address;
- device and browser information;
- one-time password (OTP) verification data;
- security logs;
- records of suspicious activity;
- device and security logs.
What is your legal basis to process my personal data?1
Legitimate interests in ensuring the security of user accounts and preventing fraud.
4.8.
In-app purchases and billing support
Payments for in-app purchases in the Application (for example Meera Plus subscription) are processed by third-party app stores or payment providers (such as Apple App Store or Google Play). We do not receive or store full payment card details.
What personal data do you process?
- purchase history;
- purchase/transaction identifiers;
- purchase status;
- receipts/confirmation from app stores or payment providers;
- customer support data related to billing.
What is your legal basis to process my personal data?1
Performance of a contract.
4.9.
Customer support and inquiries, Support Chat
We are committed to providing support and addressing any questions or concerns you may have. To respond to your inquiries efficiently when you contact us, we need to process your Personal data. If you use our support chat, we process your messages, any information you choose to provide.
What personal data do you process?
- Username;
- full name;
- E-mail address;
- subject of your inquiry, date of your inquiry, content of your inquiry;
- attachments to your inquiry;
- support messages;
- voice messages;
- attached images;
- technical details related to your request, and any other information you choose to provide.
- reply to your inquiry, information provided by you.
What is your legal basis to process my personal data?1
Legitimate interests to improve support quality and prevent abuse.
4.10.
Provision and improvement of relevant recommendations in Application for you
We use Cookies to help us show ads and to make recommendations to people who may be interested in the products, or services.
We may use recommendation technologies to suggest content, events, or other users that may be relevant or interesting to you.
These recommendation systems are designed to improve the user experience and help users discover relevant content and connections.
What personal data do you process?
- cookie identifiers;
- information about interactions with marketing content;
- information about the source of traffic;
- preferences and settings stored via cookies;
- shared connections, such as mutual friends or followers;
- interactions within the Application;
- engagement with content.
What is your legal basis to process my personal data?1
Consent of data subject in case of Cookies.
Our legitimate interests in improving user experience and helping users discover relevant content within the Application in case of recommendation technologies.
4.11.
Analytics and statistical insights
We collect your data for use in research, analytics, and performance monitoring.
These data processing activities support analysis and insights designed to enhance your experience in the Application and drive the development of new services.
What personal data do you process?
- Information about pages visited on the Website;
- date and time of visits;
- duration of sessions;
- interaction data (clicks, scrolling, navigation paths);
- referrer URL;
- anonymized or aggregated analytics data collected via cookies.
What is your legal basis to process my personal data?1
Consent of data subject.
4.12.
Compliance with legal requirements and defense of our rights and interests.
If you enter into a contract with us, we’ll keep your data for as long as the law requires. We also need to hold onto some of your information for legal requirements like accounting and record-keeping.
What personal data do you process?
- Username, full name;
- email address;
- contracts, legally binding documents and data;
- correspondence, legal documents, pleadings, annexes, court documents;
- investigative information,
- logs;
- transactional data (e.g., billing, payment information);
- contractual data (e.g., subscription information).
What is your legal basis to process my personal data?1
Legal obligation (where is applicable by national law) or
Legitimate interest in defending our rights and interests.
4.13.
Direct advertising
When you subscribe to our newsletter(s) / blog(s) / social community(s)
What personal data do you process?
- Username, full name;
- Phone number;
- Email address;
- Usernames.
What is your legal basis to process my personal data?1
Consent of data subject.
1For UAE users: consent is collected in accordance with Articles 4-5 of Cabinet Resolution No. 33 of 2024 and must be freely given, specific, informed, and unambiguous. Consent may be withdrawn at any time without detriment.
4.14. Additional Account statuses
4.14.1.
We may process additional information provided by users in order to verify their identity or confirm the authenticity of a profile. Users may request the status of “Verified Profile” by contacting our moderation team via the in-app support chat or by email at help@meera.me. During this process, moderators may request additional information necessary to verify the identity of the user. We process such information solely for verification purposes and to maintain the integrity and trust of the Application community. The verification decision is made manually by our moderation team. Verified status may be revoked if the submitted information is found to be inaccurate.
4.14.2.
The "Interesting Author" status is assigned manually by our moderation team based on an assessment of the user's publication activity, audience engagement, and content quality within the Application. This status is visible to other users of the Application. The legal basis for this processing is our legitimate interest in highlighting quality contributors and improving the user experience. You may contact us to request more information about how this assessment is made.
4.15.Recommendation features
4.15.1.
The Application uses automated systems to personalize the content, events, and users shown to you. This processing constitutes profiling within the meaning of Art. 4(4) GDPR. It does not produce legal effects or similarly significant effects for you — it only affects what content is shown within the Application.
4.15.2.
These recommendations may take into account signals such as user interactions, connections between users, engagement with content, and other contextual factors related to activity within the Application.
4.15.3.
The recommendation system analyses the following signals to generate suggestions: content you have viewed or interacted with (likes, comments, shares); users you follow or who follow you; content you have created or posted; your approximate location (if enabled); the time and frequency of your activity in the Application. Based on these signals, the system identifies patterns and uses them to surface content or users it predicts may be relevant to you.
4.15.4.
The profiling carried out by the Application is intended solely to personalize the content displayed to users and does not involve decisions producing legal effects or similarly significant effects within the meaning of Article 22 GDPR. Users may object to profiling based on legitimate interests and may disable certain personalization features through the Application settings where available.
4.15.4.
The profiling carried out by the Application is intended solely to personalize the content displayed to users and does not involve decisions producing legal effects or similarly significant effects within the meaning of Article 22 GDPR. Users may object to profiling based on legitimate interests and may disable certain personalization features through the Application settings where available.
4.16.
The Controller periodically reviews processing operations that involve profiling, location tracking or behavioural monitoring in order to assess whether they continue to comply with the principles of necessity, proportionality and data minimisation and whether a Data Protection Impact Assessment is required.
4.17.
In case you do not want to provide us with the personal data where we need to collect personal data by law and you fail to provide that data when requested, we may not be able to provide you with, or have to cancel a product or service and, in some cases, it can cause termination of services.
5. PROCESSING OF LOCATION DATA
5.2.
We may process the following location data:
- Precise location (including GPS coordinates);
- Approximate location (city, region, country);
- Location displayed on an interactive map.
5.3.
Location sharing is optional and is based on your explicit consent. You can enable, disable, or restrict location sharing at any time via your device settings and Application settings.
5.4.
Where enabled, your location may be visible to other users depending on your selected privacy settings. You are solely responsible for configuring your visibility preferences.We do not collect location data when you disable location permissions on your device.
6. PRIVACY AND VISIBILITY CONTROLS
6.1.
The Application provides you with tools to control how your personal data is shared with other users.
6.2.
You can:
- Make your profile public or private;
- Restrict visibility of specific profile information;
- Enable or disable sharing of your location;
- Control the level of detail of your location visibility.
6.3.
We encourage you to review and configure these settings according to your preferences.
7. COOKIES
7.1.
Cookies are small text files that are stored on your device when you visit website. They may be used to enable core website functionality, remember preferences, and collect analytics information. For more information, please refer to our Cookie Policy.
7.2.
You can manage cookies:
- Via the cookie banner (if available);
- Through your browser settings.
7.3.
Please note that by deleting cookies or disabling future cookies you may be unable to access certain areas or features of our Website.
7.4.
If you use the Application, similar technologies may be used for analytics, performance monitoring, and advertising. Where required, we will request your consent before enabling non-essential analytics or personalized advertising.
7.5.
Detailed information regarding the categories of cookies and similar technologies used, their providers, purposes, retention periods and legal bases is available in our Cookie Policy, which forms an integral part of this Privacy Policy.
8. USER-GENERATED CONTENT
8.1.
The Application allows users to create, upload, or submit content, including text, images, and other materials.
8.2.
We process user-generated content in order to:
- Display and manage user contributions;
- Enforce our User Agreement and community rules;
- Prevent fraud, abuse, or unlawful activity;
- Comply with legal obligations or valid requests from authorities.
8.3.
Where necessary to protect legal rights (including intellectual property rights), we may disclose limited relevant data to affected rights holders or authorities.
8.4.
Users remain responsible for ensuring that submitted content does not violate applicable laws or the rights of third parties.
8.5.
The Application also enables direct communication between users, including:
- Text messages;
- Voice messages;
- Images and other media shared in chats.
8.6.
We process such data to enable communication between users, ensure service functionality, and maintain security and integrity of the Application.
8.7.
Please note that content you share with other users may be accessible to them and may be further shared by those users.
8.8.
We do not routinely monitor private communications, but may access or review limited content where necessary to investigate abuse, enforce the User Agreement, comply with law, or respond to security incidents.
9. HOW LONG DO YOU STORE MY PERSONAL DATA?
9.1.
We retain Personal Data only for as long as necessary to achieve the purposes described in Section 4 of this Privacy Policy, unless a longer retention period is required or permitted by applicable law (including for the establishment, exercise, or defence of legal claims). We apply data minimisation and storage limitation principles and delete or anonymise Personal Data when it is no longer needed.
9.2.
How we determine retention periods. Retention periods depend on:
- The purpose of processing (Section 4);
- Statutory retention obligations (e.g., accounting/tax, consumer protection);
- Security, fraud prevention, and enforcement needs; and
- Applicable limitation periods for potential claims.
9.3.
The retention periods are determined primarily based on the purpose of processing, as follows:
9.3.1.
Account data (clause 4.3).
We keep data related to your Account (such as username, profile information and account settings) for as long as your account remains active.
If you delete your account, we delete or anonymise this data within 30 days, unless we must keep certain information:
- to comply with legal obligations;
- to investigate fraud or abuse;
- to resolve disputes or enforce our agreements.
9.3.2.
Technical and access data (clause 4.4).
Technical data used to operate the Website and Application (such as IP address, session identifiers and device information) is normally stored only for the duration of the session or for a short period afterwards.
9.3.3.
Location data (clause 4.5).
Location data is processed only when you enable location services.
Precise location data is typically processed in real time and is not stored longer than necessary to provide the feature.
Where location data is temporarily stored for security purposes, it is retained only for a limited period and then deleted or anonymized.
9.3.4.
Age verification data (clause 4.6).
Data is retained for the duration of the user's account and deleted within 30 days of Account deletion, unless retention is required to demonstrate compliance with applicable law.
9.3.5.
Security and authentication logs (clause 4.7).
We retain security and authentication logs where needed to investigate incidents, up to the term required for an ongoing investigation or legal claim.
9.3.6.
Purchase and billing records (clause 4.8).
Transaction-related information received from app stores is retained:
- for as long as necessary to provide access to purchased features;
- for the period required by accounting, tax or consumer protection laws.
If no specific legal period applies, we generally keep such records for up to 3 years after the transaction to handle disputes or refunds.
9.3.7.
Support communications data (clause 4.9).
Messages and attachments sent to customer support are typically kept for 3 years after the issue is resolved.
We may keep certain records longer where necessary for legal claims or security investigations.
9.3.8.
Recommendation systems (clause 4.10).
Data used to improve recommendations (such as interaction data and engagement with content) is retained only for a limited period.
Where possible, we convert this data into anonymised or aggregated statistics.
9.3.9.
Analytics data (clause 4.11).
We store analytics data according to the retention periods described in our Cookie Policy. Where possible, we store it in anonymised or aggregated form.
9.3.10.
Legal obligations and disputes (clause 4.12).
We may retain certain information longer when necessary:
- to comply with legal obligations;
- to establish, exercise or defend legal claims;
- to cooperate with regulators or law enforcement.
9.3.11.
Direct advertising (clause 4.13).
If you subscribe to marketing communications, we retain data for as long as you remain subscribed.
If you withdraw consent we stop sending communications promptly and delete or anonymise related data immediately.
9.4.
Upon expiry of the applicable retention period, Personal Data is securely deleted, anonymized, or otherwise rendered inaccessible, unless further retention is required or permitted by applicable law.
10. CROSS-BORDER TRANSFER
10.1.
Personal Data processed through our Application and Website is stored and processed within the EU
10.2.
Transfers of Personal Data of users located in the UAE to our servers in the European Union are carried out on the basis of one or more of the following mechanisms under Article 23 of the UAE PDPL: (a) Standard Data Transfer Agreements (SDTAs) - contractual safeguards ensuring that Personal Data receives a level of protection comparable to that required under the UAE PDPL; (b) the explicit consent of the data subject to the transfer, provided at the time of registration; and/or (c) the necessity of the transfer for the performance of the contract between us and the data subject. As of the date of this Policy, the UAE Data Office has not published an official adequacy list under the federal PDPL. Should the European Union be recognised as an adequate jurisdiction by the UAE Data Office in the future, we will rely on Article 22 of the UAE PDPL and update this Policy accordingly.
10.3.
Where Personal Data of EU residents is processed, it remains within the EU/EEA and is not transferred to countries outside the EEA.
10.4.
Should any transfer outside the EEA become necessary, we ensure that such transfer is carried out in accordance with Chapter V of the GDPR.
This may include:
- Transfers to countries recognised by the European Commission as providing an adequate level of protection;
- The use of Standard Contractual Clauses approved by the European Commission, together with supplementary technical, contractual and organisational measures where required; or
- Another transfer mechanism permitted under applicable data protection law.
In such cases, we will also ensure compliance with the applicable cross-border transfer requirements under the UAE PDPL, including the use of appropriate contractual safeguards under Article 23 of the UAE PDPL.
10.5.
In exceptional cases, where necessary to report confirmed CSAM or respond to imminent risks to a child's safety, we may transfer limited Personal Data to NCMEC or competent authorities located outside the EEA. Such transfers are carried out in reliance on Article 49(1)(d) GDPR (important reasons of public interest) or, where applicable, Article 49(1)(f) GDPR (protection of vital interests), and are limited to what is strictly necessary for that specific purpose.
10.6.
We take reasonable technical and organisational measures designed to protect Personal Data during international transfers, including access controls, data minimisation, confidentiality obligations, and security measures proportionate to the risks involved.
10.7.
You may contact us using the details in this Policy if you would like more information about the safeguards we use for international transfers, where such information can be provided. You may request a copy of the applicable SCCs or further information about the safeguards we apply by contacting our DPO.
10.8.
For further details about categories of recipients and purposes of processing, please see Section “Who do you share my Personal Data with?”.
11. WHO DO YOU SHARE MY PERSONAL DATA WITH?
11.1.
We do not sell or rent out your data.
11.2.
We may share your personal data with:
| Third party | Purpose of transfer |
| Hosting, cloud, infrastructure and database providers; | Specified in clauses 4.3, 4.7 |
| Analytics and performance monitoring providers. | Specified in clauses 4.5, 4.10 |
| Communication and verification delivery providers, email delivery providers; | Specified in clause 4.3 |
| Security, fraud prevention and abuse detection providers; | Specified in clauses 4.7 |
| App store operators and payment-related platform providers (such as Apple and Google) in connection with subscriptions, in-app purchases, refunds, and account-related services; | Specified in clauses 4.8 |
| Professional advisers, auditors, legal counsel, courts, regulators, law enforcement bodies and other public authorities where required or permitted by law; | Specified in clauses 4.12 |
| Service providers (developers) assisting us in operating, maintaining and improving the Application and Website. | Specified in clauses 4.10, 4.11 |
| Marketing platforms, advertising networks, and marketing service providers engaged in delivering advertising and promotional content. | Specified in clause 4.10, 4.11 |
11.3.
Some of these recipients act as our processors, while others may act as independent controllers depending on the service they provide and the applicable law.
11.4.
Please note that if we share any portion of your personal data with third persons, we will endeavor to secure such transfer using appropriate legal, organizational, and technical measures.
11.5.
For authentication purposes, one-time verification codes (OTP) may be delivered via third-party communication services (such as messaging platforms).
11.6.
Please note that Apple and Google may act as independent controllers in relation to payment processing and account authentication within their platforms. Their processing of personal data is governed by their respective privacy policies. Such providers may process your phone number and related metadata to deliver verification messages.
11.7.
We use third-party analytics tools to better understand how users interact with the Application, improve its functionality, and analyze usage trends. In particular, we may use analytics services provided by Amplitude, AppMetrica, and Google Analytics.
These services may collect certain technical and usage information, such as device information, application events, interaction with features of the Application, and approximate location derived from IP address.
These analytics providers process data on our behalf and may act as independent controllers depending on their role and the applicable legal framework. Their processing of personal data is governed by their respective privacy policies.
11.8.
We may use third-party infrastructure providers, including cloud hosting and storage services to host and process application data. These providers process data on our behalf and are contractually required to implement appropriate security and confidentiality measures.
11.9.
Where required by applicable law, all processors acting on behalf of the Controller process Personal Data under written data processing agreements containing the safeguards required by Article 28 GDPR and applicable UAE data protection legislation.
12. DELETING YOUR ACCOUNT
12.1.
Should you ever decide to delete your account, you may do so in the Application. If you delete your account, your account profile will be deleted or anonymized without undue delay during 30 days.
12.2.
However, certain information may be retained for a limited period where required:
- To comply with legal obligations (e.g., accounting or tax requirements);
- To resolve disputes or enforce our agreements;
- To prevent fraud or abuse;
- To maintain security logs.
Such retained data will be stored only for the duration required by law or legitimate interests and will be securely deleted thereafter.
13. MARKETING EMAILS
13.1.
When creating an Account, you will have the option to subscribe to our newsletter to receive our latest news and updates by email.
13.2.
Such communications will only be sent where permitted by applicable law and, where required, based on your consent.
13.3.
You may opt out of receiving such communications at any time by contacting us at help@meera.me or through the support chat in the Application. Please note that the email must come from the email Account you wish to block.
14. YOUR RIGHTS UNDER DATA PROTECTION LAW
14.1.
Your right to object (Art. 21 GDPR; Art. 17 UAE PDPL):
Where we process your personal data on the basis of our legitimate interests (Art. 6(1)(f) GDPR, Art. 7 UAE PDPL), you have the right to object to such processing at any time. Upon receiving your objection, we will stop processing your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or where the processing is necessary for the establishment, exercise or defence of legal claims.
Where your personal data is processed for direct marketing purposes, you have an unconditional right to object at any time, without giving reasons. Upon objection, we will immediately stop processing your data for that purpose.
To exercise this right, contact our DPO: e.tabakov@meera.me
Right of access:
(Art. 15 GDPR; Art. 13 UAE PDPL)
You have the right to request confirmation of whether we process Personal Data about you and, if so, to obtain a copy of that data together with information about the purposes of processing, the categories of data processed, recipients or categories of recipients, the envisaged retention period, and the existence of any automated decision-making. The provision of this information is free of charge.
Right to rectification:
(Art. 16 GDPR; Art. 14 UAE PDPL)
You have the right to obtain from us, without undue delay, the rectification of inaccurate Personal Data concerning you and the completion of incomplete Personal Data.
Right to erasure:
(Art. 17 GDPR; Art. 15 UAE PDPL)
You have the right to request that we erase your Personal Data without undue delay where:
(a) the data is no longer necessary for the purposes for which it was collected;
(b) you withdraw consent and no other legal basis applies;
(c) you object to processing and there are no overriding legitimate grounds; (d) the data has been unlawfully processed; or
(e) erasure is required to comply with a legal obligation.
A right to erasure does not exist insofar as:
- the data may not be deleted due to a legal obligation or must be processed due to a legal obligation;
- the data processing is necessary for the assertion, exercise or defence of legal claims.
Where erasure is not possible, we will restrict the processing of the personal data.
Right to restrict processing:
(Art. 18 GDPR; Art. 16 UAE PDPL)
You have the right to request that we restrict the processing of your personal data in the following circumstances:
(a) you contest the accuracy of the data, for the period needed to verify it;
(b) the processing is unlawful but you oppose erasure and request restriction instead;
(c) we no longer need the data but you require it for the establishment, exercise or defence of legal claims; or
(d) you have objected to processing based on legitimate interests, pending verification of whether our grounds override yours.
During the period of restriction, we will only store your data and will not carry out any other processing without your consent, except for legal claims or to protect the rights of others.
Right to data portability:
(Art. 20 GDPR; Art. 14 UAE PDPL)
You have the right to receive from us the data you have provided in a structured, common and machine-readable format, as well as the right to have this data transferred to another controller.
This right only exists if:
- you have provided us with the data on the basis of consent or on the basis of a contract concluded with you;
- the processing is carried out by automated means.
Right to lodge a complaint with a supervisory authority
(Art. 77 GDPR; Art. 24 UAE PDPL)
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes data protection law.
You can contact the supervisory authority of your habitual residence, place of work, or place of the alleged infringement.
If you are a UAE resident and the UAE PDPL applies to the processing of your Personal Data, you may lodge a complaint with the UAE Data Office (the competent supervisory authority under the UAE PDPL) at www.uaedataoffice.ae. You also have the right to seek judicial remedies available under UAE law.
Right to withdraw consent:
(Art. 7(3) GDPR; Art. 6 UAE PDPL)
Where processing is based on your consent, you have the right to withdraw it at any time without detriment. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal and will not result in any negative consequences for your access to the Application's core features that do not depend on consent.
Right not to be subject to solely automated decision-making
(Art. 22 GDPR; Art. 18 UAE PDPL)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significant effects on you, unless such processing is based on your explicit consent, is necessary for a contract, or is authorised by applicable law. Where automated decision-making applies, you have the right to obtain human intervention, to express your point of view, and to contest the decision.
14.3.
To exercise any of the rights set out in this section, please contact our Data Protection Officer using the contact details provided at the beginning of this Policy. We will respond to your request within the timeframe required by applicable law: within one month for EU residents (extendable by a further two months in complex cases, with prior notification), and within 30 calendar days for UAE residents (extendable by a further 30 days in complex cases, with prior notification).
14.4.
Data subjects located in the European Union may also exercise their rights by contacting our EU Representative using the contact details provided at the beginning of this Privacy Policy.
15. SECURITY OF YOUR PERSONAL DATA
15.1.
We implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data, in accordance with applicable law.
15.2.
These measures include, in particular:
- Access controls and authorization mechanisms;
- Data minimisation and confidentiality safeguards;
- Encryption and secure communication protocols where appropriate;
- Regular review and improvement of security measures;
- Procedures for detecting, investigating, and responding to security incidents.
15.3.
The level of security is appropriate to the risk, taking into account the nature, scope, context, and purposes of processing, as well as the likelihood and severity of potential risks for the rights and freedoms of individuals.
15.4.
We regularly review our technical and organisational measures taking into account technological developments, the risks associated with our processing operations and the recommendations of our Data Protection Officer.
15.5.
Personal data breach (UAE residents):
15.5.1.
In the event of a personal data breach that is likely to result in a risk to your rights and interests, we will notify the UAE Data Office within 72 hours of becoming aware of the breach, in accordance with Article 25 of the UAE PDPL and Cabinet Resolution No. 33 of 2024.
15.5.2.
Where the breach is likely to result in a high risk to your rights, we will also notify affected data subjects without undue delay, including information about the nature of the breach, the categories of data affected, and the measures taken or proposed to address it. For EU residents, breach notification obligations under Article 33 and Article 34 of the GDPR apply in parallel.
15.6.
Personal data breach (EU residents):
15.6.1.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent EU supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR.
15.6.2.
Where notification is not made within 72 hours, it will be accompanied by reasons for the delay. The notification will include, to the extent available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the name and contact details of the Data Protection Officer, the likely consequences of the breach, and the measures taken or proposed to address it.
15.6.3.
Where the breach is likely to result in a high risk to the rights and freedoms of natural persons, we will also communicate the breach to the affected data subjects without undue delay, in accordance with Article 34 of the GDPR, unless an exemption under Article 34(3) applies (including where the personal data affected was rendered unintelligible through encryption or other appropriate technical protection measures). The competent supervisory authority for notification purposes is determined by the location of our EU representative and/or the habitual residence or place of work of the affected data subjects.
15.7.
In accordance with Article 10 of the UAE PDPL and applicable implementing regulations, controllers that process Personal Data of UAE residents may be required to register with the UAE Data Office. We maintain our registration status in accordance with applicable UAE law. If you would like information about our registration status, please contact us using the details provided in this Policy.
16. Data Protection Impact Assessments (DPIA)
Where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons, the Controller conducts a Data Protection Impact Assessment ("DPIA") prior to commencing such processing in accordance with Article 35 GDPR.
DPIAs may be carried out, in particular, where processing involves:
- large-scale processing of precise location data;
- systematic monitoring of individuals;
- profiling or recommendation systems;
- processing operations involving innovative technologies or presenting elevated risks.
Where a DPIA indicates that processing would result in a high risk in the absence of measures to mitigate that risk, the Controller consults the competent supervisory authority before commencing such processing where required under Article 36 GDPR.
17. CHANGES TO THE POLICY
17.1.
We may update this Policy from time to time to reflect changes in our processing activities, legal requirements, or the functionality of the Application and Website.
17.2.
Material changes and notifying you:
17.2.1.
Where changes materially affect how we process your Personal Data, we will take appropriate measures to inform you of such changes in advance.
17.2.2.
Where changes materially affect how we process your Personal Data (including changes to the purposes of processing, the identity of recipients, or the exercise of your rights), we will notify you at least 30 days before such changes take effect.
17.2.3.
Notification will be sent by email to the address associated with your Account and/or displayed as a prominent notice within the Application. The notification will explain what is changing, why, and what practical effect the change will have on you.
17.2.4.
We encourage you to review this Privacy Policy periodically. However, we will not rely on a general notice to "check for updates" as a substitute for individual notification of material changes — such references are not considered sufficient under applicable data protection law.
17.3.
Minor or non-material changes (such as corrections of typographical errors, clarifications of wording, or stylistic improvements) may be made without individual notification.
17.4.
The updated version of this Privacy Policy will always be made available on the Website and within the Application. The “Last updated” date at the top of the Policy indicates when the most recent changes were made.
CONTACT US
For questions, concerns, or to exercise your rights under this Policy, please contact us:
MEERA GROUP FZ-LLC.
Email:
help@meera.me
help@meera.me
Identification number:
101897
101897
Address:
Dubai, United Arab Emirates, Dubai Internet City, Building 1
Dubai, United Arab Emirates, Dubai Internet City, Building 1
DPO