Version 2026-09-07 · in effect from 7 September 2026
What we hold, why, who else can see it, and what you can ask us to do about it. Anything unclear, ask us at support@raabta.agency.
This policy explains what personal data Raabta handles, why, who else can see it, how long it is kept, and what you can ask us to do about it. It applies to raabta.agency and to the Raabta application.
It sits alongside our Terms of Service. Where the Terms describe the agreement, this describes the data.
This is the distinction the rest of the policy rests on, and it is the one most privacy policies blur.
The first kind is data about the people who USE Raabta — an agency owner, an admin, an agent. We decide what we collect and why, so for that data we are the controller.
The second kind is data about the people your agency DEALS WITH — leads, buyers, tenants, landlords, contacts. You decide what to collect, why, and how long to keep it. For that data you are the controller and we are only your processor: we hold it and show it back to you on your instructions, and we do nothing else with it.
When you create an account and use it, we hold:
This is your clients' data, held under your instructions: names, phone numbers, email addresses, budgets, areas, requirements, the notes your agents write, call outcomes, the text of messages sent through the product, viewings, deals and any documents you upload.
We do not decide what goes in here. If you collect something you should not have, that is a decision made on your side of the line — see section 11 of the Terms.
Directly from you and your team as you work. From your public enquiry form, when somebody fills it in. From a portal or another tool you connect to the lead webhook. From an integration you switch on, such as BedFlow, where you have connected it yourself.
We do not buy data, we do not scrape it, and we do not enrich your records from third-party sources.
For data where we are the controller:
Some of this is worth saying plainly, because a privacy policy that only lists permissions tells you very little.
Inside your agency, access is decided by role and enforced by the database itself, not by the interface: an agent sees the leads assigned to them, a manager sees the desk, and the mailbox and integration secrets are readable only by the owner.
Outside your agency, only the sub-processors below, each under contract and each doing one job:
| Who | What they do | Where |
|---|---|---|
| Google (Firebase) | Database, authentication and file storage | Google Cloud, multi-region |
| Vercel | Application hosting and delivery | Global edge network |
| Stripe | Subscription payments and card storage | Ireland and the United States |
| Anthropic | The AI writing and summarising features, when used | United States |
| Your own mail provider | Sending and receiving email you connect | Wherever you host it |
On Google Cloud infrastructure through Firebase, and delivered through Vercel. This means personal data may be stored or processed outside the United Arab Emirates, including in the European Union and the United States.
Those transfers rely on the safeguards those providers operate, including standard contractual clauses where they apply. By using Raabta you agree to this transfer.
While your account is active, your data is kept so you can use it — a CRM whose history quietly expires is not a CRM.
Access rules run on the server on every read and every write, so what somebody can see is decided by the database and cannot be changed from a browser. One agency can never read another's records.
Traffic is encrypted in transit with HTTPS and HSTS; data at rest is encrypted by our infrastructure providers. Mailbox passwords and integration keys are readable only by the agency owner. Card numbers never reach us.
Section 11 of the Terms sets out the part of this only you can do — passwords, two-factor authentication, and removing people the day they leave. Most incidents in systems like this start there rather than in the software.
Under the UAE Personal Data Protection Law, and under the GDPR where it applies to you, you can ask us to:
If a real estate agency holds your details in Raabta and you want to see, correct or delete them, contact that agency. They decided to collect your data and they are the controller of it; we hold it for them and are not permitted to change or release it on our own initiative.
If you do not know which agency it is, or they do not respond, write to support@raabta.agency and we will do what we can to identify them and pass your request on.
Raabta is a business tool and is not directed at children. Accounts require you to be at least 18. If we learn we hold a child's personal data without a lawful basis, we will delete it.
If a security incident affects personal data, we will tell you without undue delay, say what we know and what we are doing, and give you what you need to meet your own notification duties.
Where you are the controller — your clients' data — deciding whether to notify the UAE Data Office or the individuals is your call and your deadline.
We may update this policy. The version and date are at the top, and the version current on the day you signed up is recorded against your profile. For material changes we will give reasonable notice in the product, by email, or both.
For any question about this policy, to exercise a right, or to report a security problem: support@raabta.agency. Security reports are answered first.
If you are not satisfied with our answer you can complain to the UAE Data Office, or to your local data protection authority where the GDPR applies to you.
Version 2026-09-07. The version current on the day you created your account is the one recorded against your profile.