Nostrix ← Back to the website

Nostrix Marketing Services

Privacy Policy

This Privacy Policy explains how Nostrix Marketing Services collects, uses, shares and protects personal data when you visit nostrix.ae, contact us, submit a project enquiry or provide feedback.

Effective and last updated: 5 August 2026

Controller Nostrix Marketing Services
Location Dubai, United Arab Emirates
Privacy contact marketing@nostrix.ae

1. Who we are and when this policy applies

Nostrix Marketing Services ("Nostrix", "we", "us" or "our") is a marketing and creative-services business based in Dubai, United Arab Emirates. For personal data covered by this policy, Nostrix acts as the data controller and determines why and how that data is processed.

This policy applies to the Nostrix website, project enquiries, business correspondence, testimonial submissions and other direct communications with Nostrix. It does not govern websites, apps or services operated by third parties, even where we link to them.

This policy is intended to reflect the principles and rights in the UAE Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data and other applicable UAE requirements.

2. Personal data we collect

Information you provide to us

Depending on how you interact with us, you may provide:

  • Your name and contact details, including email address and telephone number.
  • Your company, brand, job title or professional role.
  • Project information, requested services, estimated budget, preferred timeline, goals and deliverables.
  • Messages, attachments and other information sent through email, WhatsApp, Instagram or other communication channels.
  • Client feedback, testimonial text, name, company details, optional Instagram username, logo, photograph and your permission to publish them.
  • Contract, billing and transaction information if you become a client.

Information generated when you use the website

Our hosting provider and the technical services used to deliver the website may automatically receive limited technical information, such as your Internet Protocol address, browser and device type, operating system, requested pages, date and time of access, referring page and security or error logs. This information is normally generated as part of delivering and securing a website.

Sensitive information

Please do not submit health information, government identification numbers, payment-card details, passwords or other sensitive personal data through the project-enquiry form unless we specifically request it through an appropriate secure channel.

3. How and why we use personal data

We may process personal data to:

  • Receive, assess and respond to project enquiries.
  • Prepare proposals, quotations, scopes of work and contracts.
  • Provide, manage and improve our marketing and creative services.
  • Communicate about projects, schedules, deliverables, payments and support.
  • Publish testimonials, names, roles, company names, optional Instagram usernames, logos or images where the relevant person or organisation has approved publication.
  • Operate, maintain, troubleshoot, secure and improve the website.
  • Maintain appropriate business, accounting, compliance and dispute records.
  • Comply with applicable laws, lawful requests and legal obligations, and establish, exercise or defend legal claims.

Our legal grounds

Depending on the circumstances, we rely on one or more of the following grounds:

  • Consent: for example, when you tick the form’s privacy checkbox, approve publication of a testimonial, or agree to optional analytics or marketing where applicable. You may withdraw consent, although this does not affect processing that occurred before withdrawal.
  • Steps requested before entering a contract and performance of a contract: for example, assessing an enquiry, preparing a proposal and delivering agreed services.
  • Legal obligations and legal claims: where processing is needed for accounting, compliance, regulatory requests or the establishment, exercise or defence of rights.
  • Other grounds permitted by applicable law: where relevant to a particular processing activity.
The current project form does not send data to a Nostrix website database. When you choose “Send on WhatsApp” or “Send by Email”, the website prepares a message and opens the selected application. Your enquiry reaches us only after you complete the send action in that application.

4. Who may receive personal data

We do not sell or rent personal data. We may disclose it only where reasonably necessary to:

  • Nostrix personnel and authorised contractors who need the information to handle an enquiry or deliver a project.
  • Website hosting, content-delivery, email, cloud-storage, security, analytics, communications and professional-service providers acting for us.
  • WhatsApp and Instagram, operated by Meta, when you choose to communicate through those services.
  • Your email provider when you choose “Send by Email”.
  • Google Fonts, Tailwind CSS and Phosphor Icons infrastructure used by the current website to load fonts, styling and icons; those providers may receive standard technical request data such as an IP address.
  • Accountants, auditors, insurers, lawyers and other professional advisers where needed.
  • Courts, regulators, law-enforcement bodies or other authorities where disclosure is required or permitted by law.
  • A buyer, investor or successor in connection with a genuine restructuring, financing, sale or transfer of all or part of the business, subject to appropriate confidentiality measures.

Providers that process data for us are expected to use it only for authorised purposes and to apply appropriate confidentiality and security safeguards.

5. International data transfers

Some external services used for website delivery, email, cloud hosting, WhatsApp, Instagram or other business operations may process data in countries outside the UAE. Where personal data is transferred internationally, we will take reasonable steps to use a transfer method and safeguards permitted by applicable UAE data-protection law, such as transferring to a jurisdiction with an appropriate level of protection or using suitable contractual and organisational safeguards.

By choosing to contact us through a third-party service, you should also review that service’s privacy information because its own international-transfer practices may apply independently of Nostrix.

6. Cookies, external resources and analytics

The current Nostrix website does not intentionally use first-party advertising cookies and Google Analytics is disabled in the supplied website code. Basic technical logs may still be created by the hosting provider when the website is requested.

The website currently loads some fonts, styling and icons from external content-delivery services. Requests to those services may include technical data such as your IP address, browser details and the page requesting the resource.

If optional analytics, advertising pixels or non-essential cookies are enabled later, we will update this policy and implement an appropriate notice or consent mechanism before using them where required.

7. How long we keep personal data

We retain personal data only for as long as reasonably necessary for the relevant purpose. Our normal retention approach is:

  • Enquiries that do not become projects: normally up to 12 months after the last meaningful contact, unless a longer period is reasonably needed for follow-up, consent records, disputes or legal requirements.
  • Client and project records: for the duration of the relationship and afterwards for the applicable contractual, accounting, tax, limitation and legal-compliance periods.
  • Published testimonials: until the testimonial is replaced, withdrawn or no longer relevant, subject to records needed to document the permission originally given.
  • Technical and security logs: according to the hosting or security provider’s normal operational retention period, unless required longer for investigation or legal compliance.
  • Privacy requests and consent records: for as long as needed to demonstrate how the request or consent was handled.

When data is no longer required, we will delete it, anonymise it or securely restrict its use, subject to technical backup cycles and legal retention requirements.

8. How we protect personal data

We use reasonable technical and organisational measures designed to protect personal data against accidental loss, misuse, alteration, unauthorised access or disclosure. Measures may include access controls, account security, secure devices, trusted service providers, confidentiality obligations, software updates and appropriate backup practices.

No internet transmission or storage system can be guaranteed completely secure. Please avoid sending confidential or sensitive information through ordinary email, social media or the public enquiry form unless we agree on a more suitable channel.

9. Your data-protection rights

Subject to applicable law and relevant exceptions, you may have the right to:

  • Receive information about the personal data we process and how it is used.
  • Request access to personal data relating to you.
  • Request correction or completion of inaccurate or incomplete data.
  • Request deletion where the data is no longer needed, consent is withdrawn or processing is otherwise unlawful.
  • Request restriction of processing in specified circumstances.
  • Object to or request that we stop certain processing, including direct marketing.
  • Receive or transfer certain data in a structured, machine-readable format where the legal conditions for portability apply.
  • Object to certain decisions based solely on automated processing and request human review. Nostrix does not currently use the website to make decisions that produce legal or similarly significant effects solely through automated processing.
  • Withdraw consent at any time where processing is based on consent.

To exercise a right, email marketing@nostrix.ae and describe your request. We may ask for information reasonably necessary to verify your identity and protect personal data from unauthorised disclosure. We will respond in accordance with applicable law.

You may also submit a complaint to the UAE Data Office or another competent supervisory authority where applicable. We encourage you to contact us first so we can try to resolve the concern directly.

10. Children’s privacy

Our services and website are intended for businesses and individuals seeking professional marketing or creative services. They are not directed to children under 13, and we do not knowingly collect personal data from children under 13 through the website. If you believe a child has provided personal data to us without appropriate authorisation, please contact us so that we can review and, where appropriate, delete it.

11. Changes to this policy

We may update this policy when our services, website technology, providers or legal obligations change. The current version will be posted on this page with a revised “last updated” date. Where a change materially affects how we use personal data, we will provide an additional notice where reasonably appropriate.

12. Contact us

For privacy questions, requests or complaints, contact:

Nostrix Marketing Services

Dubai, United Arab Emirates

Email: marketing@nostrix.ae

Telephone: +971 56 119 5226