iMicro Information Technology Co. LLC, trading as NexaFix ("NexaFix", "we", "us" or "our"), is a device repair and IT services provider registered and operating in Dubai, United Arab Emirates, with its registered office at Al Moosa Tower 2, Sheikh Zayed Road, Trade Center First, Dubai, United Arab Emirates. This Privacy Policy explains how we collect, use, disclose, store and protect Personal Data when you visit nexafix.ae, contact us by phone, WhatsApp or email, book a repair, or otherwise engage with our repair, data recovery, IT support, networking, or CCTV and access-control services (together, the "Services").
This Policy is issued in accordance with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its Executive Regulations (together, the "UAE PDPL"), Federal Decree-Law No. 34 of 2021 on Combating Rumours and Cybercrimes, Federal Decree-Law No. 26 of 2025 on Child Digital Safety, the regulations of the Telecommunications and Digital Government Regulatory Authority ("TDRA") on unsolicited electronic communications, and other applicable UAE federal and Dubai laws. As a mainland Dubai establishment, NexaFix is subject to the UAE PDPL rather than the data protection regimes of the DIFC or ADGM free zones.
Please read this Policy carefully. By using the Site or the Services, you acknowledge that your Personal Data will be processed as described below. If you do not agree with this Policy, please do not use the Site or provide us with your Personal Data.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person (a "Data Subject").
- "Processing" means any operation performed on Personal Data, including collection, recording, storage, use, disclosure, or erasure.
- "Controller" means the entity that determines the purposes and means of Processing — in most contexts described in this Policy, NexaFix.
- "Processor" means an entity that Processes Personal Data on behalf of a Controller — for example, NexaFix acting on behalf of a business client when installing or maintaining that client's CCTV or IT systems.
- "UAE Data Office" means the federal supervisory authority responsible for enforcing the UAE PDPL.
2. Personal Data We Collect
We collect only the Personal Data reasonably necessary to provide the Services. Depending on how you interact with us, this may include:
Identity and contact data: Full name, phone number, email address, and delivery/pickup address. Emirates ID or trade licence details, where required for invoicing, warranty, or business IT contracts.
Booking and service data: Device make, model, and serial/IMEI number; description of the fault; repair and diagnostic history; warranty records. Appointment, pickup, and delivery details, and communications exchanged via our booking form, phone, or WhatsApp.
Data recovery and device-content data: Where you engage our data recovery, software, or hardware repair services, our technicians may incidentally access files, photos, contacts, messages, application data, or other content stored on your device in order to diagnose the fault, complete the repair, or recover your data. This may include special category data (for example, health information within a health app, or biometric data such as fingerprint/face-unlock templates) if such data happens to reside on the device. Where such data includes personal health information, it may also be subject to separate UAE health-data legislation in addition to the UAE PDPL. We do not review, copy, use, or disclose the substantive content of your files for any purpose beyond performing the requested repair or recovery, and we apply the minimisation, confidentiality, and security measures described in Sections 6 and 8 to this data.
Business IT support, networking, and CCTV/access-control data: Where we provide business IT support, network and security services, or install and maintain CCTV and access-control systems for a corporate client, NexaFix typically acts as a Processor on that client's instructions. This may involve limited access to the client's network logs, device inventories, employee user accounts, or CCTV footage solely to deliver the contracted service. Such data is handled under the terms of our agreement with the client, who remains the Controller responsible for that data and for providing appropriate notices to its own staff, customers, or visitors.
Payment data: Payment card details are processed directly by our licensed payment gateway/bank partner; NexaFix does not store full card numbers. We retain only transaction references, amounts, and invoicing records.
Website and technical data: IP address, browser and device type, pages visited, referring URL, and approximate location, collected automatically through cookies and similar technologies. Information you submit through contact forms, live chat, or WhatsApp Business messaging.
Marketing and feedback data: Your marketing preferences, and any reviews, ratings, or feedback you choose to share (including on Google Reviews).
3. How We Collect Personal Data
- Directly from you, when you book a repair, complete a form, call, WhatsApp, email us, or visit our office.
- Automatically, through cookies and analytics tools when you browse the Site.
- From third parties, such as couriers who facilitate pickup/delivery, payment processors, or, in a business IT/CCTV engagement, from our corporate client acting as Controller.
4. Purposes and Legal Bases for Processing
Under the UAE PDPL, we process your Personal Data only where we have a valid legal basis. In most cases this is your consent or the necessity of processing to perform a contract with you; in limited cases, we rely on our legitimate business interests (balanced against your rights) or a legal obligation. Our main purposes are:
- To provide the Services: booking, diagnosing, repairing, upgrading, or recovering data from your device, necessary to perform our contract with you.
- Customer communication: appointment confirmations, status updates, warranty notices, and responding to enquiries, contractual necessity / legitimate interest.
- Payments and invoicing: processing payment and maintaining financial records, contractual necessity and legal obligation.
- Business IT, networking, and CCTV/access-control services: performing the specific tasks instructed by our corporate client, contractual necessity, as Processor.
- Marketing: sending offers, promotions or newsletters, your consent, which you may withdraw at any time.
- Website functionality, analytics and advertising: operating and improving the Site, and showing relevant ads, consent (for non-essential and advertising cookies) or legitimate interest.
- Legal and security compliance: preventing fraud, enforcing our Terms & Conditions, and complying with UAE law, including requests from UAE courts, regulators or law-enforcement authorities, legal obligation.
5. Consent and Your Right to Withdraw It
Where we rely on your consent, for example, for marketing communications or non-essential cookies — you may withdraw that consent at any time, free of charge, with effect for future Processing. Withdrawing consent does not affect the lawfulness of Processing carried out before withdrawal. You may withdraw consent using the contact details in Section 15, the unsubscribe link in our emails, or your cookie preference settings.
7. Cross-Border Data Transfers
Some of our service providers (for example, cloud hosting, communication platforms, or advertising and analytics providers) may store or process Personal Data outside the United Arab Emirates. In line with Articles 22–23 of the UAE PDPL, we transfer Personal Data outside the UAE only where the destination country or territory is recognised as providing an adequate level of protection, or where appropriate safeguards are in place, such as standard contractual clauses, binding corporate rules, or your explicit consent to the specific transfer. We take reasonable steps to ensure any such transfer maintains a level of protection consistent with the UAE PDPL.
8. Data Retention
We retain Personal Data only for as long as necessary to fulfil the purposes described in this Policy, including:
- Repair, warranty, and invoicing records: for the duration of the warranty period plus the period required by UAE commercial and tax record-keeping rules (generally up to 5 years).
- Device content accessed during data recovery/repair: deleted from our systems and diagnostic devices as soon as the repair or recovery job is completed and the device is returned or the recovered data is delivered to you, unless you request otherwise.
- Business IT support and CCTV data: retained in accordance with the retention period agreed with the relevant corporate client, or as required by law.
- Marketing data: until you withdraw consent or opt out.
- Website analytics/cookie/advertising data: as set out in the Cookie Table below, or for the default retention period set by the relevant provider (for example, Google Analytics and Google-served advertising cookies are generally retained for up to 13 months, unless you clear them sooner).
When Personal Data is no longer required, we securely delete, anonymise, or destroy it.
10. Data Security
We implement technical and organisational measures appropriate to the nature and sensitivity of the Personal Data we hold, including:
- Access controls restricting Personal Data (including device content) to trained technicians and staff on a need-to-know basis.
- Encryption of data in transit and, where appropriate, at rest.
- Secure wiping or deletion of diagnostic tools and temporary storage after each job.
- Physical security at our premises and secure handling of devices in transit.
- Confidentiality obligations for all staff and contractors, and vetting of third-party service providers.
No method of transmission or storage is completely secure. If we become aware of a Personal Data breach that is likely to result in a risk to your rights, privacy, confidentiality, or security, we will notify the UAE Data Office and affected Data Subjects without undue delay, in accordance with the UAE PDPL and its Executive Regulations.
11. Children's Privacy
Our Services are directed at businesses and adult consumers and are not intended for children. We do not knowingly collect Personal Data from individuals under 18 years of age. Where a minor's device is brought in by a parent or guardian for repair, we rely on the parent or guardian to provide any necessary consent and to supervise the process, consistent with Federal Decree-Law No. 26 of 2025 on Child Digital Safety. If we become aware that we have inadvertently collected a child's Personal Data without appropriate consent, we will take steps to delete it.
12. Marketing Communications
We will only send you marketing messages (SMS, WhatsApp, email, or calls) if you have opted in, in accordance with TDRA regulations on unsolicited electronic communications. You can opt out at any time by using the "unsubscribe" link in our emails, replying "STOP", messaging us on WhatsApp, or contacting us using the details in Section 15. We will still send you essential service communications (for example, repair status updates) even if you opt out of marketing.
13. Your Rights as a Data Subject
Subject to the conditions and exceptions set out in the UAE PDPL, you have the right to:
- Right to information: be informed about how your Personal Data is Processed.
- Right of access: request confirmation of, and a copy of, the Personal Data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete Personal Data.
- Right to erasure: request deletion of your Personal Data in certain circumstances.
- Right to restrict Processing: request that we limit how we use your Personal Data in certain circumstances.
- Right to object: object to Processing based on legitimate interests or for direct marketing.
- Right to data portability: receive certain Personal Data you provided to us in a structured, commonly used, machine-readable format.
- Right to withdraw consent: at any time, where Processing is based on consent.
- Right to stop automated decision making: request human review where a decision producing legal or similarly significant effects is made solely by automated means.
To exercise any of these rights, contact us using the details in Section 15. We will respond within the timeframe required by the UAE PDPL and its Executive Regulations. We may need to verify your identity before actioning a request, and certain rights may be limited where an exception under the UAE PDPL applies.
14. Complaints
If you are unhappy with how we handle your Personal Data, please contact us first so we can try to resolve your concern. You also have the right to lodge a complaint directly with the UAE Data Office, the federal supervisory authority for data protection in the United Arab Emirates.
15. Contact Us
NexaFix / iMicro Information Technology Co. LLC
Address: Al Moosa Tower 2, Sheikh Zayed Road, Trade Center First, Dubai, United Arab Emirates
Phone / WhatsApp: +971 54 151 0618
Email: support@nexafix.ae
Business hours: Mon–Sat 10:00–20:00, Sun 12:00–18:00
16. Third-Party Links
Our Site may contain links to third-party websites (for example, Google Maps or social media pages). We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies separately.
17. Do Not Track Signals
Some browsers offer a "Do Not Track" setting. Because there is currently no common industry standard for how to respond to such signals, our Site does not currently respond differently based on a detected "Do Not Track" signal, and instead relies on the cookie consent controls described in Section 9.
18. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or in UAE law. The "Last updated" date at the top of this Policy indicates when it was last revised. Material changes will be notified through the Site or by other appropriate means. Your continued use of the Site or Services after an update constitutes acceptance of the revised Policy.
19. Governing Law and Jurisdiction
This Privacy Policy is governed by the laws of the United Arab Emirates, including the UAE PDPL, and, where applicable, the laws of the Emirate of Dubai. Any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the competent courts of Dubai, United Arab Emirates.
Questions or Concerns?
If you have any questions regarding our terms or privacy practices, please reach out to our team: