SwaedUAE
Privacy policy
How we collect, use, and protect personal data across the SwaedUAE website and mobile apps under UAE PDPL.
Last updated: 30 July 2026
SwaedUAE Association for Culture and Community Empowerment (“SwaedUAE”, “we”, “us”, or “our”) is committed to protecting your privacy. This policy explains how we collect, use, share, and safeguard personal data when you use the SwaedUAE website at swaeduae.ae and the SwaedUAE volunteer mobile apps for Android and iOS (together, the “Platform”).
We process personal data in line with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) and other applicable UAE laws, including child-protection requirements under Federal Law No. 3 of 2016 (Wadeema’s Law) and, where applicable, Federal Decree-Law No. 26 of 2025 regarding Child Digital Safety.
Who we are
- Controller: SwaedUAE Association for Culture and Community Empowerment, affiliated with the Ministry of Community Development (MoCD), United Arab Emirates.
- Website: https://swaeduae.ae
- Privacy & data-rights contact: [email protected]
- General enquiries: [email protected]
What this policy covers
This policy applies to the SwaedUAE website, the SwaedUAE volunteer mobile apps, and related services — including browsing opportunities, registering as a volunteer or organisation, GPS attendance check-in, volunteering minutes, certificates, contact forms, and institutional pages.
Information we collect
- Account and profile data — name, email address, mobile number, password (stored hashed), preferred language, and profile details you provide. If you sign in with Google, we receive your basic Google profile (name and email).
- Volunteer participation data — opportunities you view, save, apply to, or join; attendance records; verified volunteering minutes; waitlist status; and certificates issued to you.
- Location data — when you check in or out of a volunteering activity, the app collects your device’s GPS location at that moment to verify presence at the event site. We do not track your location continuously or in the background.
- Camera data — the mobile app uses your camera only to scan event QR codes for attendance. Scanned images are not stored as a photo gallery of attendees.
- Device and technical data — device model, operating system, app version, IP address, and diagnostic/log data needed to operate and secure the Platform.
- Push notification token — if you enable notifications, we process a device push token (via Firebase Cloud Messaging and Apple Push Notification service).
- Communications — messages sent through contact and support forms, and emails exchanged with us (email operated through Zoho Mail).
- Cookies and similar technologies — see our Cookie policy.
- Payment / membership data — if you use paid membership or donation features when enabled, we process the data needed to complete the transaction through our payment provider(s); card details are typically handled by the payment processor, not stored in full by SwaedUAE.
How we use your data
- Create and manage your account and volunteer profile
- Show and manage volunteering opportunities, applications, and waitlists
- Verify attendance (GPS / QR) and calculate volunteering minutes
- Issue and verify certificates
- Send service messages and reminders; with your consent, push notifications
- Respond to contact, support, and data-rights requests
- Maintain safety and security; prevent fraud or abuse
- Comply with legal obligations and cooperate with competent authorities, including MoCD and child-protection bodies where required
- Improve and develop the Platform (using aggregated or consented analytics where applicable)
We do not sell personal data. We do not use children’s personal data for targeted advertising or commercial profiling.
Legal bases (PDPL)
Depending on the activity, we rely on:
- Consent (for example location at check-in, non-essential cookies, push notifications, certain optional profile fields)
- Performance of a contract / requested service (account, volunteering, certificates)
- Legitimate interest in operating a secure community platform (balanced against your rights)
- Legal obligation (retention, lawful requests, child-protection reporting)
You may withdraw consent where processing is consent-based, without affecting prior lawful processing.
How we share data
- Verified organisations and event organisers — when you join or attend an opportunity, the host can see participation and attendance details for that activity
- Service providers (processors) — hosting/infrastructure, Zoho (email), Google and Apple (sign-in / push), analytics providers (only if consented), and payment processors when used — under our instructions
- Competent authorities — where required by UAE law or for legitimate community-programme oversight, including MoCD and child-protection / law-enforcement bodies
International transfers
Some processors may process data outside the UAE. Where this occurs, we take steps consistent with the UAE PDPL to ensure an adequate level of protection.
Data retention
We keep personal data while your account is active and as needed to provide services, issue/verify certificates, meet legal and record-keeping obligations, and resolve disputes. When no longer needed, we delete or anonymise data.
Your rights (UAE PDPL)
You may request to access, correct, export, restrict, or delete personal data, and to withdraw consent, subject to legal limits.
- Self-service: when logged in, review/update your profile and request export or account deletion from Profile (website or app).
- Contact: [email protected] — or Contact & support with topic related to data rights.
We will respond within a reasonable period consistent with the PDPL and operational capacity.
Children and young volunteers
Youth participation is part of our mission. Where a volunteer is below the age required for independent consent under UAE law or platform rules:
- Parent/guardian (custodian) consent is required
- Organisers must apply appropriate safeguarding
- For children under 13, we process personal data only with explicit custodian consent and with purpose limitation consistent with the Child Digital Safety framework and our Child safety standards
Mobile app permissions
- Location — attendance verification at check-in
- Camera — QR check-in
- Notifications — volunteering updates (optional)
Manage or revoke permissions in device settings. Some features will not work without them.
Security
We use technical and organisational measures including HTTPS, hashed passwords, and access controls. No system is completely secure; we cannot guarantee absolute security.
Changes
Material changes will update the “Last updated” date and may be communicated via the Platform.
Contact us
[email protected] — SwaedUAE Association for Culture and Community Empowerment, United Arab Emirates (affiliated with MoCD).