Business Systems & Digital Solutions

Client Login

Legal

Privacy Policy

Last updated: 29 September 2026

This policy explains what information DGT.MNG processes through its business systems and digital services, why we process it, and the choices available. DGT.MNG provides Business Systems & Digital Solutions, and operates an internal company-management platform (the “Platform”) used by our team to manage clients, projects, communications and business records.

Who this policy covers

It applies to DGT.MNG and the Platform, and to personal data processed when we communicate with clients, leads, suppliers and other contacts. It does not replace the terms of any separate agreement between DGT.MNG and a client; where a client agreement allocates data-protection responsibilities differently, that agreement governs for the services it covers.

Contact for any privacy question: info@dgtmng.ae.

Categories of data we process

  • Business contact details — names, work email addresses, phone numbers (including WhatsApp numbers), company names, job titles and relationship context (client, lead, supplier).
  • Commercial records — clients, leads, projects, tasks, milestones, subscriptions, invoices, payments and related notes.
  • Communications — emails exchanged with our connected business mailbox (info@dgtmng.ae), WhatsApp business messages exchanged through the WhatsApp Business Platform, their content, recipients, timestamps, attachments and delivery/read status.
  • Documents and attachments — files our team stores or exchanges for business purposes, and email/WhatsApp attachments.
  • Operational data — calendar events, task and renewal records, approval records for sensitive actions, and audit logs recording who did what and when inside the Platform.
  • Account data — for team members: sign-in email, name, role, and authentication records.

Where the data comes from

Data is entered by our team, received through the business communication channels we operate (email and WhatsApp), imported from services we have connected — such as our business Gmail mailbox, Google Calendar and the Meta WhatsApp Business Platform — or generated inside the Platform by our team and by automated assistants (“agents”) that draft, summarise, classify or propose actions on our records. Agents operate under human approval for anything sensitive; they do not create data sources beyond those described here.

Why we process data

  • To run our business: managing client and project work, invoicing, renewals, tasks and internal operations.
  • To communicate: answering enquiries, conducting business conversations by email and WhatsApp, and keeping shared message threads with the people we work with.
  • To provide the services we have agreed to provide to clients, including coordinating work and exchanging documents.
  • To keep the Platform secure: access control, approval records for sensitive actions, and audit trails.
  • To comply with legal and accounting obligations, such as retaining financial records.

We process this data as part of our legitimate business activities — performing and preparing to perform our contracts, running our operations, and keeping records. Where we process data on behalf of a client as part of delivering services, we act on that client’s instructions for that processing.

WhatsApp / Meta integration

Our Platform connects to the WhatsApp Business Platform (Cloud API) operated by Meta so that we can exchange business messages with clients, leads and suppliers over WhatsApp. In this connection:

  • We process message content, phone numbers, names where available, delivery status and timestamps so that conversations appear in one place and replies can be managed by our team.
  • We use WhatsApp for service and business conversations with people who contact us or whom we have agreed to communicate with. We do not use it for bulk marketing or unsolicited mass outreach, and the Platform contains no bulk-messaging feature.
  • Where WhatsApp requires a pre-approved message template outside the 24-hour customer-service window, we only send templates that Meta has approved for our WhatsApp Business Account.
  • Meta processes WhatsApp messages under its own terms and privacy policy, available from Meta. Their handling of your WhatsApp data, and your choices under Meta's policies, are independent of ours.
  • Incoming WhatsApp content is treated as untrusted input: it is never used to widen access to stored documents or other clients' records.

Service providers

We use a small number of providers to operate these services. They process data only to deliver their function for us:

  • Google — our business Gmail mailbox and Google Calendar (email exchange, calendar synchronisation).
  • Meta — the WhatsApp Business Platform (WhatsApp messaging and message status).
  • Hosting and data-platform providers — the Platform runs on managed cloud infrastructure and a managed database, including storage of business documents in private, access-controlled storage.
  • Artificial-intelligence services — used to draft, summarise and classify content to help our team; outputs are reviewed by our team before anything sensitive happens.

What we do not do

  • We do not sell personal data, and we do not share it for advertising.
  • We do not use your data to build advertising profiles.
  • We do not send automated marketing through WhatsApp or email without an existing business relationship or your request.
  • We do not keep your WhatsApp or email credentials; provider connections and access tokens are held by the platform infrastructure, encrypted at rest and not exposed in the browser or logs.

Retention

We keep business and communication records for as long as they are needed for the purposes above, including minimum periods required by accounting and commercial law, and delete or anonymise them when they are no longer needed. If you ask us to delete your data, we follow the process described in our User Data Deletion Instructions, and we tell you what, if anything, we must keep and why.

Security

  • Access to the Platform is by authenticated accounts only, with role-based permissions.
  • Sensitive or destructive actions — external messages, financial changes, deletions — require approval by an authorised person, and are recorded in an audit log.
  • Business documents are stored privately with expiring, authorised access links; there are no permanent public file URLs.
  • Provider secrets and tokens are held server-side only, never in the browser.
  • Access is limited to authorised DGT.MNG team members who need it for their work.

Your rights and choices

You can ask us what data we hold about you, ask for corrections, ask for deletion, or object to a particular use, by emailing info@dgtmng.ae. You can also ask us not to contact you over a given channel. We respond to reasonable requests within a reasonable time, and explain anything we cannot do.

Depending on where you are, you may have additional rights under local law, including under data-protection laws applicable to you. Nothing in this policy limits those rights.

Changes to this policy

We may update this policy as our services or providers change. The “Last updated” date above shows the current version, and the current version is always published at this address.

Contact

DGT.MNG — Business Systems & Digital Solutions. Email: info@dgtmng.ae.