Privacy Policy
This Privacy Policy explains how Personal Data is collected, used, disclosed, transferred, retained and protected when you visit or use the Lndmrk website, applications, dashboards, Account areas, Portfolio Tools and related services, or otherwise interact with either Lndmrk entity. It also explains your choices and legal rights.
The Lndmrk brand is used in connection with services provided by two separate legal entities. The entity responsible for your Personal Data depends on the service and purpose described below. References to 'Lndmrk', 'we', 'us' or 'our' mean the relevant Controller for that processing; they do not make the two entities one legal person or create joint responsibility where the law does not do so.
This Policy is a notice, not a request for consent and not a contract that waives your legal rights. Where consent is required, we will request it separately through a clear affirmative choice. You may withdraw consent as explained below without affecting processing that was lawful before withdrawal.
SCOPE OF THIS POLICY
This Policy applies to visitors, registered users, buyers and investors, sellers and owners, landlords, agents, developers, Listing Partners, business contacts and representatives, authorised Account users, persons requesting referrals, and other individuals whose Personal Data is processed through or in connection with the Services.
It covers the website at www.lndmrk.io, the mobile or web application at app.lndmrk.io related Account areas and APIs, Portfolio Tools, property-enquiry and Listing workflows, communications, events and support channels operated by or for a Lndmrk entity.
It does not govern an independent agent, developer, landlord, mortgage provider, conveyancer, lawyer, valuer, property manager, fund, payment provider, social platform or other third party when that third party determines its own purposes and means of processing. Its own privacy notice will apply to that processing.
If a separate Service-specific privacy notice conflicts with this Policy, the more specific notice applies to the affected processing. Mandatory rights under Applicable Law remain unaffected.
If we actively offer services to, or monitor individuals in, another jurisdiction, additional local notices or rights may apply. A country-specific supplement will be provided where required. The availability of the Platform worldwide does not itself mean every Service is offered in every country.
WHO IS RESPONSIBLE FOR YOUR PERSONAL DATA
A 'Controller' is the person that determines why and how Personal Data is processed. The Controllers covered by this Policy are identified below.
| Controller | Primary responsibilities | Applicable framework and contact |
|---|---|---|
| Lndmrk Technologies Ltd | Platform operation; registration and Accounts; authentication and security; Portfolio Tools; technology support; product analytics; and the digital-documentation, software and AI-enabled features that it determines. | DIFC Data Protection Law No. 5 of 2020 and Regulations. Privacy contact: privacy@lndmrk.io , Public rights form: www.lndmrk.io/privacy |
| Borderless Real Estate L.L.C | UAE Listing onboarding; property enquiries and leads; viewings; agency or brokerage administration; referral requests; commissions, invoices and transaction records; and identity, sanctions and anti-money-laundering checks that it determines. | Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and other applicable UAE laws. Privacy contact: privacy@lndmrk.io. |
Each entity ordinarily acts as an independent Controller for the purposes it determines. Each is responsible for complying with the law that applies to its processing and for responding to requests concerning that processing.
Where Lndmrk Technologies processes Personal Data only on documented instructions from Borderless, for example by hosting or transmitting a Borderless-controlled Listing, lead, due-diligence or transaction record, Borderless is the Controller and Lndmrk Technologies acts as its Processor for that activity. Lndmrk Technologies may remain an independent Controller for limited security, audit, legal-compliance and platform-integrity processing that it determines itself.
If the entities jointly determine the purposes and essential means of a particular activity, the relevant collection notice will identify them as joint Controllers. They will document their respective responsibilities, designate an accessible contact point and make the substance of their arrangement available on request, without limiting your ability to exercise rights against either Controller where Applicable Law permits.
The service allocation in Schedule 1 is the default position. A just-in-time notice shown on a form or feature may specify a different or additional Controller where the actual workflow requires it.
APPLICABLE DATA-PROTECTION FRAMEWORK
Lndmrk Technologies is incorporated in the Dubai International Financial Centre and is subject to DIFC Data Protection Law No. 5 of 2020 and the DIFC Data Protection Regulations for processing within their scope, including processing it conducts outside the DIFC.
Borderless is established in Dubai Mainland and is subject to Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data for processing within its scope, together with other applicable UAE laws governing consumer data, telemarketing, electronic communications, anti-money-laundering, real-estate and record keeping.
The UAE federal Personal Data Protection Law excludes companies located in financial free zones with their own data-protection laws. Accordingly, this Policy does not treat the federal law as the primary privacy law for Lndmrk Technologies. A particular transfer or shared workflow may nevertheless engage both regimes and must comply with each regime that applies.
In this Policy, 'Personal Data' means information relating to an identified or identifiable living individual. 'Processing' includes collecting, recording, organising, storing, accessing, using, analysing, sharing, transferring, restricting, deleting or otherwise handling Personal Data. Company information is not Personal Data by itself, but information about a director, employee, representative, beneficial owner or other individual is Personal Data.
Personal Data we collect
The categories collected depend on how you interact with us. We do not necessarily collect every category listed below about every person.
Identity and contact data: name, title, date of birth where required, nationality, residential or business address, email address, telephone number, photograph and preferred language.
Account and authentication data: username, password hash, multi-factor authentication details, account status, login history, authorised users, permissions, recovery information and security events.
Business and professional data: employer or organisation, role, professional contact details, licence or registration information, agency or developer details, authority to act, beneficial ownership and relationship to a property or transaction.
Property, Listing and ownership data: property address and identifiers, title or ownership evidence, tenancy or occupancy information, floor plans, photographs, Listing details, permit information, price, availability, service charges, development details, authority to advertise and associated documents.
Portfolio data: properties you add or import, acquisition details, valuation inputs, rental and expense information, mortgages and liabilities, documents, notes, performance or yield data, preferences, permissions and information you choose to share through the Portfolio Tools.
Enquiry and lead data: searches, saved properties, enquiries, viewing requests, property requirements, budget range, preferred location, communications with Listing Partners, lead source, referral source and progression status.
Transaction and referral data: offers, appointments, reservation or transaction milestones, service requests, selected provider, referral status, quotations, outcome information, commission or referral-fee records and documents required to administer the service.
Identity-verification and compliance data: copies or details of passports, Emirates ID or other identity documents, proof of address, corporate records, authorised signatories, ultimate beneficial owners, source of funds or wealth, sanctions and politically exposed person screening, adverse-media results, fraud indicators and records required by law.
Payment and billing data: billing address, invoice, tax and transaction references, payment status and limited payment-token or card metadata received from the payment provider. Unless expressly stated at the payment page, we do not store complete payment-card numbers or security codes.
Communications and support data: emails, chat messages, call or meeting notes, support requests, complaints, feedback, survey responses and recordings where a clear recording notice and valid basis have been provided.
Device, usage and location data: IP address, device and browser type, operating system, app version, language, time zone, identifiers, session activity, clickstream, referring URL, crash reports, approximate location derived from IP and precise location only where requested and permitted.
Cookie and tracking data: cookie identifiers, consent choices and information collected by technologies described in the Cookie Notice.
Marketing and preference data: communication choices, consent and objection records, preferred channels, campaign interaction and interests inferred from permitted activity.
Analytics, predictions and inferences: property matches, ranking signals, estimated values or yields, portfolio trends, recommendations, summaries, risk or fraud flags, lead priority and other outputs produced from permitted data and models.
Legal and governance data: rights requests, complaints, consents, audit records, incident records, litigation or regulatory correspondence and evidence required to establish, exercise or defend legal rights.
SENSITIVE AND HIGH-RISK INFORMATION
Identity documents, financial circumstances, source-of-funds material, sanctions or criminal-record information and detailed property-ownership records can create significant risk even where they are not classified identically under every applicable law. We apply access restrictions and additional controls appropriate to their sensitivity.
Do not upload health information, biometric identifiers, criminal-record information, religious or political information, genetic data or other Sensitive Personal Data unless the relevant Controller specifically requests it for a stated lawful purpose through an approved secure channel.
If an identity-verification feature uses a selfie, facial matching, liveness check or another biometric process to uniquely identify you, you will receive a specific notice before collection identifying the Controller, provider, purpose, basis, retention and available alternatives or rights.
We do not intentionally infer Sensitive Personal Data from ordinary Platform use for advertising or personalisation. If a future feature would do so, it will be subject to a separate assessment, lawful basis and notice before use.
HOW WE OBTAIN PERSONAL DATA
directly from you when you browse, register, create or administer an Account, add portfolio information, submit a Listing or enquiry, request a viewing or referral, communicate with us, complete due diligence, make a payment or exercise a right;
from your employer, organisation, Account administrator, agent, adviser or another person authorised to act for you;
from agents, developers, landlords, owners, Listing Partners, buyers, sellers, co-brokers and other transaction participants;
from B2B relationship partners and lead sources where they have represented that collection and disclosure are lawful;
from named mortgage, legal, conveyancing, valuation, property-management, fund, payment or other referral providers where needed to administer your request or record its outcome;
from public or official sources, including company, property, professional, licensing, sanctions and court registers, and information you have deliberately made public;
from identity-verification, fraud-prevention, sanctions, politically exposed person and adverse-media screening providers;
from property, market, mapping, valuation and analytics data suppliers;
automatically from devices, browsers, apps, cookies, logs and security systems; and
by generating predictions, scores, summaries, estimates or other inferences from information lawfully available to the relevant Controller.
Where Lndmrk Technologies obtains Personal Data from another source, it will provide the information required by DIFC law by the earliest applicable point, normally within 30 days, at first communication or before first disclosure, unless an exemption applies. This includes identifying the source or source category. Borderless will provide indirect-collection information in accordance with UAE law and, as a practical standard, at or before first material contact where reasonably possible.
PERSONAL DATA ABOUT OTHER PEOPLE
If you provide Personal Data about another person, including a co-owner, tenant, family member, employee, director, beneficial owner, client or authorised user, you must have a lawful basis and authority to do so. You must give that person this Policy and any relevant just-in-time notice unless an applicable legal exception permits otherwise.
You must not upload another person's identity document, financial information, private portfolio data or Sensitive Personal Data unless the relevant Service requires it and you are authorised to provide it through the designated secure channel.
We may contact the person to verify authority, provide privacy information or obtain information directly. We may restrict, segregate or delete third-party data if the required authority, notice or purpose cannot be established.
WHY LNDMRK TECHNOLOGIES USES PERSONAL DATA
Lndmrk Technologies relies on the lawful basis appropriate to each purpose under DIFC law. A basis is not used merely because it is convenient, and consent is requested separately where it is the appropriate basis.
Provide Accounts and Platform features: to register and authenticate users, administer permissions, provide Portfolio Tools, save settings, process requested functions and provide support. Basis: performance of a contract with you or steps you request before a contract; where a business customer is the contracting party, Lndmrk Technologies' legitimate interests in providing and administering the service for its authorised users.
Operate, secure and maintain the Platform: to prevent misuse, maintain availability, troubleshoot, log events, protect accounts, detect fraud and enforce Platform rules. Basis: legitimate interests in operating a safe, reliable service; compliance with legal obligations where applicable; and establishment, exercise or defence of legal claims.
Provide Portfolio analytics and digital tools: to organise user-provided information, calculate or display analytics, provide alerts, matching, summaries and other selected functions. Basis: performance of the requested service; legitimate interests in providing and improving relevant tools; consent where required for a particular input or technology.
Route a user-requested enquiry or referral: to collect the minimum details needed and transmit them to Borderless or the provider identified before submission. Basis: steps you request before a contract or performance of the requested service; consent where the disclosure or destination requires it.
Improve and evaluate products: to understand feature use, diagnose errors, measure performance, test changes and develop features using minimised, aggregated or de-identified information where reasonably possible. Basis: legitimate interests in improving products and service quality, balanced against your rights; consent for non-essential analytics where required.
Personalise content and communications: to remember preferences and, where enabled, tailor search ordering, suggestions or alerts. Basis: performance of requested settings; legitimate interests where the effect is limited and expected; consent for technologies or uses that require it.
Administer subscriptions, billing and records: to process orders, issue invoices, manage payment status and keep corporate and accounting records. Basis: contract and legal obligations.
Communicate and market: to send requested alerts, service notices and, subject to clause 13, promotional communications. Basis: contract or legitimate interests for necessary service communications; consent or legitimate interests for marketing only where permitted and with an effective objection mechanism.
Comply, investigate and defend: to respond to lawful requests, protect rights, investigate suspected wrongdoing, manage complaints, disputes and incidents, and comply with binding law. Basis: legal obligation, legitimate interests and legal claims, as applicable.
Where Lndmrk Technologies relies on legitimate interests, it considers the necessity and proportionality of the processing, the reasonable expectations of affected individuals, the nature of the data and safeguards such as minimisation, access controls, objection rights and de-identification. You may request further information about that assessment at privacy@lndmrk.io .
WHY BORDERLESS USES PERSONAL DATA
Under the UAE federal framework, Borderless relies on consent or another basis expressly permitted by UAE law. It does not use 'legitimate interests' as a generic fallback basis for Mainland processing.
Respond to your property request: to receive and respond to an enquiry, arrange a viewing, identify suitable properties, communicate with you and take steps you request toward a property or service agreement. Basis: performance of, or steps at your request to conclude, amend or terminate, a contract; consent where required.
Onboard and manage Listings and Listing Partners: to verify identity, authority, professional or business information, property information and advertising documentation; publish or route approved content; and administer the Listing relationship. Basis: contract or requested pre-contract steps; specific legal obligations; consent or information you have deliberately made public where appropriate.
Administer brokerage or transaction activity: to coordinate parties, record instructions and milestones, manage documents, commissions and communications, and perform a written appointment or transaction arrangement. Basis: contract and specific obligations under applicable UAE law.
Perform KYC, AML, sanctions and fraud controls: to identify customers and beneficial owners, understand the relationship or transaction, assess source of funds or wealth where required, screen sanctions and politically exposed persons, monitor activity, keep records and make legally required disclosures. Basis: specific legal obligations, public interest where applicable, and legal or security procedures. Consent is not the primary basis for mandatory compliance processing.
Make a requested referral: to identify the provider, collect only the information necessary to request an introduction, transmit it after notice, record the referral and administer a lawful fee. Basis: requested pre-contract steps or contract; consent where required for the disclosure or marketing.
Process invoices and commercial records: to issue invoices, reconcile payments, calculate lawful commissions or referral fees, keep tax and accounting records and prevent payment fraud. Basis: contract and specific legal obligations.
Handle support, complaints and legal matters: to respond, investigate, maintain evidence, establish or defend rights and comply with courts, regulators or law enforcement. Basis: specific legal obligations, legal claims and judicial or security procedures.
Communicate and market: to send necessary transaction or service messages and, subject to clause 13, promotional communications through permitted channels. Basis: contract or requested service for operational messages; specific, withdrawable consent or another expressly permitted basis for marketing.
Use professional contact data from B2B sources: to make a relevant business contact where the individual supplied the details, consented to the contact, deliberately made the details public, or another specific UAE legal basis has been documented. Borderless will not retain or use a sourced contact where it cannot establish a lawful basis.
WHEN INFORMATION IS REQUIRED
Some information is required by law, to enter into or perform a contract, to protect an Account, or to deliver a requested feature. A form will identify mandatory fields where reasonably possible.
If you do not provide required identity, authority, Listing, payment, compliance or transaction information, the relevant Controller may be unable to create the Account, publish the Listing, respond to the request, complete due diligence, enter into an agreement, process a payment or continue the Service.
Optional fields will be identified where practical. Choosing not to provide optional information may reduce personalisation or the accuracy of an analytic, but will not be used to deny an unrelated Service unless the information is genuinely necessary for that Service.
ANALYTICS, PROFILING, ARTIFICIAL INTELLIGENCE AND AUTOMATED DECISIONS
Depending on the features you activate, Lndmrk Technologies may use automated or semi-automated systems to organise or summarise documents, match or rank Listings, estimate property values or yields, identify portfolio trends, personalise alerts, detect security or fraud indicators, or prioritise support and leads. Borderless may use automated tools for fraud, sanctions, identity and transaction-risk screening where lawful.
The inputs may include Account settings, searches and saved items, property and portfolio information, Listing attributes, user instructions, historic and third-party market data, transaction or engagement signals, and device or security events. The outputs may affect the order or relevance of content, the information shown to staff for review, or whether additional verification is requested.
Property analytics, estimates, matches and rankings are informational tools. They do not verify title, determine legal rights, constitute a formal valuation, guarantee a transaction, decide mortgage or fund eligibility, or replace independent professional advice. A human remains responsible for any brokerage, compliance, transaction or provider decision unless a specific notice lawfully states otherwise.
Before first use of a material autonomous or semi-autonomous feature, the responsible Controller will provide information appropriate to the feature, including its purpose, non-human processing, important data or factors, output, likely effect, limits, safeguards and available human intervention. Where required, we will seek consent or provide an effective objection or opt-out.
We do not intend to make a decision based solely on automated processing that produces legal effects or a similarly serious adverse effect on you unless Applicable Law permits it, a valid basis is established and appropriate safeguards are provided. You may request human review, express your view and challenge a significant automated outcome by contacting privacy@lndmrk.io or using www.lndmrk.io/privacy
We will not permit a third-party general-purpose model provider to use identifiable Account, private portfolio, enquiry, KYC or transaction data to train its general-purpose models unless the relevant Controller has a valid legal basis and tells affected individuals before that use.
High-risk processing, including systematic significant profiling, large-scale Sensitive Personal Data or certain modern technologies, will be assessed before use. This may include a data-protection impact assessment, testing for accuracy and bias, access restrictions, human oversight, audit logging and appointment of a Data Protection Officer where the legal threshold is met.
COOKIES, SDKS AND SIMILAR TECHNOLOGIES
The website and app may use cookies, software development kits, pixels, local storage and similar technologies. A separate Cookie Notice at www.lndmrk.io/# will identify each material technology or provider, whether it is first or third party, its purpose, category, duration and relevant transfer information.
Strictly necessary technologies may be used to provide requested functionality, maintain security, remember privacy choices and operate the Service. Where consent is required, preference, analytics, advertising or other non-essential technologies will be off by default until you make an active, granular choice.
The consent interface will provide neutral options and allow you to reject or accept non-essential categories without pre-ticked boxes or reliance on silence. You can change or withdraw choices at any time through www.lndmrk.io/#. Withdrawal will be as easy as giving consent.
Blocking necessary technologies may prevent a requested function from working. Browser settings can also delete or block cookies, but they may not control every app SDK or server-side technology; use the preference controls provided for the Service.
The cookie inventory and current technologies must be confirmed before publication.
SERVICE COMMUNICATIONS AND DIRECT MARKETING
We may send operational communications that are necessary to administer an Account, Listing, enquiry, viewing, referral, security event, transaction or legal notice. These are not treated as promotional messages merely because they concern a Service you requested.
Promotional communications may include property alerts, market updates, product news, events or other offers through email, SMS, WhatsApp or another social-messaging service, telephone or push notification. The sending Controller and channel will be identified. Lndmrk Technologies relies on consent or another lawful DIFC basis; Borderless relies on specific consent or another basis expressly permitted by UAE law.
You can object to or opt out of direct marketing at any time by using the unsubscribe or preference control in the message, changing Account settings, using www.lndmrk.io/settings or contacting www.lndmrk.io/privacy. An objection also applies to profiling related to that direct marketing. We will act on the choice without requiring you to stop using unrelated Services.
Opting out of one Controller's marketing does not automatically change a separate preference you gave to the other Controller or to an independent provider, unless the preference centre expressly states that it covers them. The preference interface will allow separate choices where required.
Before transferring your details to a Listing Partner or referral provider for that party's own marketing, we will identify the intended recipient and obtain any choice required by Applicable Law. A request for a particular introduction does not constitute consent to unrelated marketing.
Where Borderless conducts telephone marketing, it will apply applicable caller-identification, permitted-hours, recording-notice, consent and do-not-call requirements. Consumer Personal Data will not be disclosed or traded for telemarketing without the consent required by UAE law.
We may retain a minimal suppression record after an opt-out so that we do not contact you again through the objected channel. This is not used to send marketing.
HOW WE SHARE PERSONAL DATA
We disclose only the information reasonably necessary for the stated purpose, subject to contracts and safeguards appropriate to the recipient's role. Depending on the Service, recipients may include the following.
the other Lndmrk entity, for the specific Platform, Listing, lead, transaction, compliance, support, security or administrative purpose identified in this Policy or at collection;
your organisation, Account administrator, authorised users or persons you invite, subject to the permissions you select;
agents, developers, landlords, owners, buyers, sellers, co-brokers and Listing Partners where needed to publish a Listing, respond to an enquiry, arrange a viewing or progress a requested transaction;
the named mortgage provider, conveyancer, lawyer, valuer, property manager, insurer, fund or other provider you ask to contact, after the referral disclosure described in clause 16;
hosting, cloud, backup, customer-management, identity, security, communications, support, analytics, mapping, property-data, AI, payment and other service providers acting under contract;
banks, payment processors and card networks to process a payment, prevent fraud or reconcile records;
auditors, lawyers, accountants, tax advisers, insurers and other professional advisers bound by legal or contractual duties;
courts, regulators, law-enforcement, tax, real-estate, anti-money-laundering and other competent authorities where a request is valid and disclosure is required or permitted by law;
a prospective buyer, investor, lender or successor in connection with a genuine financing, restructuring, merger, acquisition or sale, subject to confidentiality, due diligence and applicable notice or choice requirements; and
other recipients where you specifically request or authorise the disclosure, or where the law permits it after appropriate assessment.
A service provider that processes Personal Data only on a Controller's instructions is engaged under written terms addressing confidentiality, security, purpose, duration, assistance, deletion or return, subprocessing and audit or assurance requirements appropriate to the risk.
A recipient that determines its own purposes, such as a Listing Partner receiving an enquiry or a provider receiving a referral request, normally acts as an independent Controller. We will identify it or its category at the relevant point and provide or link to its privacy notice where reasonably available.
We do not sell Personal Data as a standalone data-broker product. Some jurisdictions define 'sale' or 'sharing' more broadly, including certain advertising disclosures; where such a rule applies, the relevant Controller will provide the legally required notice and choice.
We may disclose aggregated or genuinely anonymised information that does not identify an individual. Pseudonymised information remains Personal Data where it can be linked back using additional information and is treated accordingly.
ENQUIRIES, LEADS AND LISTING DISCLOSURES
Before you submit a property enquiry, viewing request or other lead, the form will identify the Controller receiving it and the Listing Partner or recipient to whom the information will be sent, or describe the recipient category where the exact recipient is determined by your selection.
We normally send the recipient your name, contact details, selected property or requirement, preferred time, message and information reasonably needed to respond. We will not send your complete private portfolio, identity documents, bank details or source-of-funds material merely to make an ordinary introduction unless you separately request it or the transaction stage lawfully requires it.
The recipient may contact you about the request and will process the lead under its own privacy notice where it is an independent Controller. Any unrelated marketing by that recipient requires its own lawful basis.
A Listing Partner that supplies contact data or a B2B lead must have a lawful basis, give required notices and comply with agreed use restrictions. The relevant Lndmrk entity remains responsible for its own decision to collect, use or disclose the information and may request evidence of lawful sourcing.
If lead details are imported from a B2B relationship rather than collected directly, the first communication should identify the source and link to this Policy or the relevant just-in-time notice, unless an applicable exemption permits otherwise.
REFERRALS TO INDEPENDENT PROVIDERS
The Platform may enable a request for an introduction to a mortgage provider, conveyancer, lawyer, valuer, property manager, insurer, fund or another independent provider. Before transfer, the interface or communication will identify the provider, the Controller making the referral, the categories of information to be sent, the purpose, the provider's role and privacy notice, and any material automated screening relevant to the request.
An ordinary referral will use staged, minimum information. Initial details may include contact information, the requested service and basic property or requirement data. Identity documents, detailed financial data, full portfolio information or source-of-funds material will not be sent unless the next stage requires it, the recipient is identified and a lawful basis has been established.
The provider ordinarily becomes an independent Controller when it receives the referral and decides how to assess, quote or provide its service. The provider is responsible for its own eligibility, advice, professional service, security, retention and rights handling. This does not limit either Lndmrk entity's responsibility for its own collection or disclosure.
A Lndmrk entity may receive a lawful referral or introduction fee. The existence or basis of that fee will be disclosed where required. A fee does not authorise use of Personal Data for an unrelated purpose.
A mortgage or fund referral is not permission for Lndmrk Technologies to provide a financial service and is not a guarantee that a provider will accept an application or make an offer. Any formal application is made to and processed by the identified provider under separate terms and privacy information.
INTERNATIONAL AND INTER-JURISDICTIONAL TRANSFERS
Personal Data may be accessed, hosted or processed in the UAE and in Americas, Australia & New Zealand. The protections available in a destination may differ from those in your location. We use a transfer mechanism and supplementary measures where required by the law applying to the exporting Controller.
For DIFC law, any jurisdiction outside the DIFC is a Third Country, including Dubai Mainland. A transfer by Lndmrk Technologies outside the DIFC may rely on an adequacy recognition under Article 26 or an Article 27 mechanism, such as appropriate contractual clauses, approved binding arrangements or a permitted derogation for a limited transfer.
The intended transfer of Personal Data from Lndmrk Technologies to Borderless will be covered by [DIFC STANDARD CONTRACTUAL CLAUSES AND TRANSFER DUE DILIGENCE] before the transfer begins. This safeguard does not change the Controller allocation described in clause 2.
Where Borderless transfers Personal Data outside the UAE, it will use a destination approved as sufficiently protective, an applicable international arrangement, contractual safeguards imposing legally required protections, explicit transfer consent where valid, contractual necessity, legal-claims necessity or another exception permitted by UAE law. A transfer will not rely on a broad, bundled consent where a more appropriate basis is required.
We assess the recipient, destination, purpose, necessity, data categories and available technical and contractual protections. Measures may include data minimisation, encryption, access restriction, localisation, separation, audit rights and restrictions on onward transfer or government access.
You may request information about the applicable transfer safeguard or a copy of relevant terms, subject to lawful redaction of confidential or security information, by contacting privacy@lndmrk.io or using www.lndmrk.io/privacy .
HOW LONG WE RETAIN PERSONAL DATA
We retain Personal Data only for a defined business or legal purpose. The period depends on the Service, Controller, relationship, legal duties, sensitivity, risk, technical backup cycle and whether the record is needed to establish, exercise or defend rights.
When the purpose ends, the relevant Controller will delete, anonymise, securely archive, restrict or put the information beyond active use, subject to a documented legal or claims hold. Backup copies are isolated from ordinary use and deleted or overwritten through the normal secure rotation unless restoration is required for continuity or law.
The table below is the intended retention framework and must be completed before publication. A shorter period may apply where the purpose is completed earlier; a longer period applies only where a documented legal, regulatory, security, dispute or enforcement need justifies it.
| Record category | Normal retention rule | Controller |
|---|---|---|
| Account and authentication records | While the Account is active and for maximum legally allowable retention period after closure, subject to security, dispute and legal-retention needs. | Lndmrk Technologies |
| Private Portfolio Tool content | While the relevant Account or portfolio is active and for maximum legally allowable retention period after deletion or closure, with limited backup rotation as described below. | Lndmrk Technologies |
| Enquiries, leads and viewing records | For maximum legally allowable retention period after the last meaningful interaction, or longer where a transaction, complaint, legal claim or regulatory duty requires it. | Usually Borderless |
| Listings, partner onboarding and authority records | For the life of the Listing or relationship and maximum legally allowable retention period afterwards, subject to property-advertising, contract and claims requirements. | Usually Borderless |
| Contracts, transaction, commission, invoice and tax records | For the statutory, accounting, tax and claims period applicable to the record, currently to be confirmed as maximum legally allowable retention period. | Relevant contracting entity |
| KYC, AML and transaction-monitoring records | At least five years from the end of the business relationship, completion of the transaction or other applicable statutory trigger, and longer where required by a competent authority or Applicable Law. | Borderless |
| Marketing choices and suppression records | Until consent is withdrawn or an objection is made; a minimal suppression record may then be retained for as long as needed to honour the choice and demonstrate compliance. | Relevant marketing controller |
| Cookies, device identifiers and analytics | For the period shown in the Cookie Notice, not exceeding maximum legally allowable retention period unless renewed or legally required. | Controller named in Cookie Notice |
| Security logs and incident records | Security logs for maximum legally allowable retention period, material incident and breach records for the applicable legal, audit and claims period. | Relevant controller |
| Support, complaints and rights requests | For maximum legally allowable retention period after closure, or longer where needed to establish compliance or resolve a dispute. | Relevant controller |
An erasure request does not require deletion of information that Applicable Law requires or permits us to retain, including certain AML, tax, accounting, transaction, fraud, security, litigation or regulatory records. We will restrict use to the continuing purpose where appropriate.
SECURITY AND CONFIDENTIALITY
We use technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures are selected in light of the nature, scope, context, purpose, cost and risk of the processing.
Measures may include encryption in transit and at rest where appropriate, pseudonymisation, access controls and least privilege, multi-factor authentication, secure development, environment separation, logging and monitoring, malware protection, backups and recovery testing, vulnerability management, vendor due diligence, confidentiality obligations, staff training and incident response.
Sensitive or high-risk material should be submitted only through the secure channel identified for the Service. Do not send passport copies, banking details, source-of-funds records or other high-risk information through an ordinary email or messaging channel unless expressly instructed and protected.
No internet transmission, system or storage method is completely secure. We cannot promise absolute security, but we maintain measures intended to provide a level of protection appropriate to the risk and review them as technology and threats change.
You are responsible for protecting Account credentials, using available security features, maintaining accurate contact details, controlling authorised-user access and notifying us promptly at security@lndmrk.io if you suspect unauthorised activity or disclosure.
PERSONAL DATA BREACHES
We maintain a process to identify, contain, assess, document and respond to suspected Personal Data breaches. Service providers are required to notify the relevant Controller promptly under their contract.
Where a breach meets the applicable legal threshold, the responsible Controller will notify the relevant regulator without undue delay and within any period required by Applicable Law. Under DIFC law, a reportable breach is notified to the DIFC Commissioner as soon as practicable in the circumstances; this Policy does not apply a universal 72-hour deadline where the law does not prescribe one.
Where the law requires notice to affected individuals, we will communicate the nature and likely consequences of the breach, relevant protective steps and a contact point as soon as practicable or within the applicable period. We may use direct communication, prominent Platform notice or another lawful method depending on the circumstances.
You should report a suspected compromise of your Account or Personal Data to security@lndmrk.io immediately. Do not include unnecessary Sensitive Personal Data in the initial report.
YOUR RIGHTS
Depending on the Controller, law and circumstances, you may have the rights listed below. Rights are subject to legal conditions, exemptions and the rights of other people.
Information and access: obtain information about the categories, purposes, recipients, transfers, retention and automated processing, and access or receive a copy of Personal Data held about you.
Correction and completion: correct inaccurate information and complete incomplete information without undue delay.
Erasure: request deletion where information is no longer needed, consent is withdrawn without another basis, a valid objection succeeds, or processing is unlawful, subject to legal-retention and claims exceptions.
Restriction: request that processing be limited while accuracy, legality or an objection is assessed, or where you need the information for a legal claim.
Objection or cessation: object to processing on grounds available under the applicable law, including an unconditional objection to direct marketing and related profiling.
Portability: receive eligible information you provided in a structured, commonly used and machine-readable form, or request transmission to another Controller where technically feasible and the legal conditions apply.
Withdraw consent: withdraw a consent at any time as easily as it was given. Withdrawal does not affect earlier lawful processing or processing based on another valid ground.
Automated decision safeguards: obtain information about applicable automated processing, object where the law permits, request human review of a legally or materially adverse automated outcome, express your view and challenge the result.
Non-discrimination: not be treated unlawfully or unfairly merely because you exercised a data-protection right.
Complain and seek redress: raise a complaint with the responsible Controller and, where applicable, the DIFC Commissioner, UAE Data Office or successor competent authority, or a competent court.
The scope of a right may differ between DIFC and UAE federal law. We will apply the law governing the relevant Controller and will explain any material limitation or refusal unless the law prevents that explanation.
HOW TO EXERCISE YOUR RIGHTS
You may submit a request without creating an Account by emailing www.lndmrk.io/privacy, using the free public form at www.lndmrk.io/privacy or writing to the responsible Controller at the address in clause 26. Please identify the relevant Service and, if known, the Controller. A central contact may route the request internally without changing which entity is responsible.
We may ask for information reasonably necessary to verify identity and authority. We will not request more information than needed. If an agent acts for you, we may require evidence of authority and may verify instructions directly where appropriate.
We ordinarily do not charge for a request. A reasonable fee or refusal may be permitted for a manifestly unfounded, excessive or repetitive request, but we will explain the basis where legally allowed.
For Lndmrk Technologies, DIFC access and correction requests are generally answered within 30 days. Particularly complex or numerous requests may be extended by up to two additional months where permitted, with notice and reasons within the initial period. Other rights are handled within the period required by DIFC law.
For Borderless, requests are handled without undue delay and within any period prescribed by applicable UAE law or implementing rules. We will update this Policy if a specific operational period becomes legally applicable.
A request may be limited where necessary to protect another person's privacy, information security, legal privilege, confidential risk controls, a regulatory or judicial process, legal claims, public interest, or a record we are required to retain. We may continue limited storage while a restriction or legal hold applies.
Where reasonably required and lawful, we will notify recipients of a correction, erasure or restriction. A separate independent Controller may require you to contact it directly for information it controls; we will identify it where possible and cooperate as required.
CHILDREN AND MINORS
The Platform and Services are intended for persons aged 18 or over and are not directed to children. A person under 18 must not create an Account, submit an enquiry or use the Services independently.
We do not knowingly use children's Personal Data for targeted advertising or unrelated commercial profiling. If we learn that Personal Data was collected from a child without the required authority or basis, we will restrict and delete it as appropriate.
A property or transaction may exceptionally involve a minor owner, beneficiary or family member. In that case, the relevant Controller will collect only what is legally necessary, verify guardian or representative authority and provide an appropriate specific notice. Additional parental or guardian consent and age-assurance controls will be used where required.
A parent or guardian who believes a child has provided information should contact www.lndmrk.io/privacy.
THIRD-PARTY WEBSITES, INTEGRATIONS AND SOCIAL FEATURES
The Platform may link to or integrate with third-party websites, maps, social sign-in, messaging, payment, document, analytics or other services. The third party may collect Personal Data directly and act as an independent Controller.
A link or integration is not an endorsement of the third party's privacy or security practices. Review its privacy notice and permissions before providing information or connecting an Account.
If you use social sign-in or another connected service, we receive only the data authorised by the relevant permission screen and use it for the disclosed purpose. You can manage the connection through the third-party service and, where available, Platform settings.
CHANGES TO THIS POLICY
We may update this Policy to reflect legal, regulatory, service, technology or data-practice changes. The latest version will show its effective date and version number at www.lndmrk.io/privacy.
If a change materially affects how Personal Data is used or an individual's rights, the relevant Controller will provide a proportionate notice through the Platform, email or another appropriate channel before the change takes effect where required.
A material new purpose will not be treated as accepted merely because you continue to use the Platform. We will establish an appropriate lawful basis and obtain fresh consent where the law requires it.
CONTACT AND COMPLAINTS
Lndmrk Technologies Ltd
Private Company; DIFC commercial licence CL13094GA-00-SZ-L1-RT-164, Level 1, Gate Avenue - South ZoneDubai International Financial Centre, Dubai, United Arab EmiratesPrivacy email: privacy@lndmrk.ioData Protection Officer, if appointed: Public rights form: www.lndmrk.io/privacy
Borderless Real Estate L.L.C
Limited Liability Company - Single Owner; DET licence 1625197; commercial register 2863931Office 18-3500, Al Saqer Property Management L.L.C, Dubai World Trade Centre 2, parcel 336-211, Dubai, United Arab EmiratesPrivacy email: privacy@lndmrk.ioData Protection Officer, if appointed: General business contact in supplied licence: colin@lndmrk.io; +971 54 548 5667
Please contact the responsible Controller first so that it can investigate and attempt to resolve your concern.
For processing by Lndmrk Technologies, you may complain to the DIFC Commissioner of Data Protection at commissioner@dp.difc.ae or through the Commissioner's official website. DIFC law may also provide a private right of action and remedies through the DIFC Courts where its conditions are met.
For processing by Borderless, you may complain to the UAE Data Office or its successor competent authority through complaints@lndmrk.io. You may also have rights before another competent UAE authority or court, depending on the subject matter.
If you are outside the UAE, you may also have the right to complain to a local data-protection authority where the relevant law applies.
LANGUAGE
This Policy will be made available in English and Arabic for UAE-facing use. The versions should be aligned and reviewed together before publication.
SCHEDULE 1 - DEFAULT CONTROLLER AND DATA-FLOW ALLOCATION
Public website browsing and necessary security logs: Lndmrk Technologies is normally Controller. If Borderless jointly determines UAE-Listing tracking, analytics or campaigns, assess and disclose joint controllership.
Account registration, authentication and Portfolio Tools: Lndmrk Technologies is Controller.
Private portfolio content: Lndmrk Technologies is Controller. It is not shared with Borderless or a Listing Partner by default; disclosure occurs only when the user initiates it or another disclosed lawful basis applies.
UAE agent, developer or landlord Listing onboarding: Borderless is normally Controller. Lndmrk Technologies may be Processor for hosting/transmission and a limited independent Controller for platform security.
UAE buyer enquiry, viewing or agency request: Borderless is normally Controller for the lead and brokerage workflow. Lndmrk Technologies may collect and route the request as Processor or Controller depending on the final form design; the submission notice must identify the actual roles.
Disclosure to an agent, developer or landlord: Borderless discloses the minimum necessary. The identified recipient normally becomes an independent Controller.
KYC, AML, sanctions, PEP and source-of-funds checks: Borderless is Controller. Lndmrk Technologies should host only under a compliant processor agreement, strict access and an appropriate DIFC transfer mechanism where applicable.
Mortgage referral: Borderless is normally Controller for the requested introduction within its permissions. The named provider is an independent Controller after transfer. A formal finance application is separate.
Conveyancing, valuation, property-management or fund referral: The form must identify whether Lndmrk Technologies or Borderless is the referral Controller. The named provider is normally an independent Controller after transfer.
Technology product marketing: Lndmrk Technologies is Controller for its own campaign and preference record.
UAE property or brokerage marketing: Borderless is Controller for its own campaign and preference record.
Central support or privacy inbox: The receiving entity triages the request and restricts access. The entity responsible for the underlying Service remains Controller for the substantive record.
Property services outside the UAE: The locally identified provider or contracting entity must be named. Neither Lndmrk entity should be represented as automatically providing regulated services worldwide.