Qotbox

Legal

Terms of ServicePrivacy Policy
عEN

On this page

  1. 1. Introduction
  2. 2. Identity of the data controller
  3. 3. Scope of the Policy
  4. 4. Minimum age and eligibility
  5. 5. Categories of personal data we may collect
    1. 5.1. Account and contact data
    2. 5.2. Company, establishment, and verification data
    3. 5.3. Identity and individual verification data
    4. 5.4. RFQ and offer data
    5. 5.5. Chats, attachments, reports, and support
    6. 5.6. Service Credits, payment, and billing data
    7. 5.7. Technical, usage, and security data
    8. 5.8. Geolocation
    9. 5.9. Cookies and tracking technologies
    10. 5.10. Data from other sources
  6. 6. Protection of verification documents
  7. 7. Sensitive data and data not required
  8. 8. Data of other persons
  9. 9. How and why we use data
  10. 10. Legal bases for processing
  11. 11. What other Users can see
  12. 12. Direct marketing
  13. 13. Automated processing and matching
  14. 14. Data sharing
  15. 15. Service providers, SDKs, and third-party technologies
  16. 16. Mobile application permissions
  17. 17. Transfer of data outside the UAE
  18. 18. Data retention
  19. 19. Information security
  20. 20. Data breaches
  21. 21. Data protection impact assessment and Data Protection Officer
  22. 22. Data subject rights
  23. 23. How to exercise privacy rights
  24. 24. Account closure and data deletion
  25. 25. User responsibility for information they share
  26. 26. External links and services
  27. 27. Changes to the Privacy Policy
  28. 28. Relationship with the Terms and Conditions
  29. 29. Applicable law
  30. 30. Contact and complaints

Qotbox

Privacy Policy and Personal Data Protection

Version
2.0.0
Last updated
10 August 2026
Effective date
10 August 2026
On this page▾
  1. 1. Introduction
  2. 2. Identity of the data controller
  3. 3. Scope of the Policy
  4. 4. Minimum age and eligibility
  5. 5. Categories of personal data we may collect
    1. 5.1. Account and contact data
    2. 5.2. Company, establishment, and verification data
    3. 5.3. Identity and individual verification data
    4. 5.4. RFQ and offer data
    5. 5.5. Chats, attachments, reports, and support
    6. 5.6. Service Credits, payment, and billing data
    7. 5.7. Technical, usage, and security data
    8. 5.8. Geolocation
    9. 5.9. Cookies and tracking technologies
    10. 5.10. Data from other sources
  6. 6. Protection of verification documents
  7. 7. Sensitive data and data not required
  8. 8. Data of other persons
  9. 9. How and why we use data
  10. 10. Legal bases for processing
  11. 11. What other Users can see
  12. 12. Direct marketing
  13. 13. Automated processing and matching
  14. 14. Data sharing
  15. 15. Service providers, SDKs, and third-party technologies
  16. 16. Mobile application permissions
  17. 17. Transfer of data outside the UAE
  18. 18. Data retention
  19. 19. Information security
  20. 20. Data breaches
  21. 21. Data protection impact assessment and Data Protection Officer
  22. 22. Data subject rights
  23. 23. How to exercise privacy rights
  24. 24. Account closure and data deletion
  25. 25. User responsibility for information they share
  26. 26. External links and services
  27. 27. Changes to the Privacy Policy
  28. 28. Relationship with the Terms and Conditions
  29. 29. Applicable law
  30. 30. Contact and complaints

1. Introduction

Qotbox respects its Users’ privacy and is committed to processing personal data lawfully, fairly, and transparently, and only to the extent appropriate and necessary for the purposes set out in this Policy. This Policy explains how personal data are collected, used, disclosed, protected, and retained, and how related rights may be exercised when using the Qotbox website, applications, portals, or services.

This Policy is to be read with the Terms and Conditions and any privacy notice or special terms displayed when using a specific service. In all cases, the mandatory requirements of applicable law prevail.

In accordance with law, Qotbox observes the principles of purpose limitation, data minimisation, accuracy, security, and not retaining data after the purpose is exhausted except where retention is required or permitted by law, and applies data-protection measures in the design and configuration of services to the extent appropriate to the risks.

2. Identity of the data controller

The controller of personal data relating to Qotbox services is:

Full legal name: Qot Box FZC

Licence / registration number: 4431951.01

Licensing authority: Sharjah Publishing City - Free Zone Authority

Emirate / free zone: Sharjah - Sharjah Publishing City Free Zone

Registered address: Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates

Privacy email: privacy@qotbox.com

Legal email: legal@qotbox.com

Support email: support@qotbox.com

If appointment of a Data Protection Officer is required by law or Qotbox decides to appoint one, their contact details will be published or made available to Users in an appropriate manner.

3. Scope of the Policy

This Policy applies to personal data processed by Qotbox in operating the Platform, including data of Buyers, Suppliers, company representatives, authorised Users, website visitors, persons who contact support, and any person whose data appear lawfully in a document, message, request, or offer linked to Platform services.

This Policy does not govern the independent practices of Buyers, Suppliers, or external service providers when they process data for their own purposes as independent controllers. Each party bears its own legal responsibility for such processing.

4. Minimum age and eligibility

No person under 18 years of age may create a Qotbox account or use contractual services independently. As the Platform is primarily intended for commercial and professional use, the User must be legally eligible to use the account and conduct transactions, or be authorised by the entity they represent.

If Qotbox becomes aware that it has collected data of a person below the permitted age or without an appropriate legal basis, it will take the steps necessary to address the situation, including restriction or deletion where required.

5. Categories of personal data we may collect

5.1 Account and contact data

Name, trade name, and username.

Phone number and email address.

Country, emirate, address, and contact details.

Account language and communication preferences.

Data of authorised Users within an establishment account.

5.2 Company, establishment, and verification data

Establishment name, legal form, and business activity.

Licence or registration number, issuing authority, and expiry date.

Tax number when requested or needed.

Business address and establishment representative details.

Images or copies of documents submitted for verification purposes.

Outcome, status, and date of verification procedures, and document-validity indicators.

Carrying out verification or displaying a “Business Verified” or “Verified Account” badge does not mean that Qotbox guarantees the User, their financial solvency, products, or transactions; the badge indicates the status of verification of data or documents in accordance with Qotbox’s procedures.

5.3 Identity and individual verification data

Qotbox may collect identity data or additional verification information when necessary to verify an account, the authority of an establishment representative, prevent fraud, or comply with law. Qotbox does not request more data than it considers appropriate and necessary for the specified legitimate purpose.

5.4 RFQ and offer data

RFQ details, specifications, quantities, categories, locations, and timelines.

Offers, prices, delivery terms, warranty, and notes.

Attachments and documents linked to the request or offer.

Request and offer statuses and acceptance, rejection, or cancellation actions.

Electronic records of actions taken through the account.

5.5 Chats, attachments, reports, and support

Business messages and chats conducted through Qotbox.

Images, files, and attachments sent within chats.

Reports, complaints, and information provided for investigation.

Support correspondence, replies, and request-handling records.

Chats are intended for commercial purposes related to requests, offers, products, services, and transactions. Chat content and attachments may be processed to the extent necessary to provide messaging, handle reports, prevent fraud, protect Users and the Platform, enforce the Terms, protect rights, and comply with law. This does not mean Qotbox is obliged to pre-screen or continuously monitor all chats.

5.6 Service Credits, payment, and billing data

Service Credits and related ledger movements.

Value, date, and status of credit purchases, usage, or reversals.

Transaction references and payment-provider identifiers needed for reconciliation, support, and fraud prevention.

Invoice and tax data where applicable.

If payment is made through an external payment provider, that provider may process card or payment-method data directly in accordance with its legal role, terms, and privacy policy. The financial data Qotbox receives depend on the actual integration method with the payment provider, and Qotbox limits processing to data necessary to confirm the transaction, reconcile, bill, provide support, prevent fraud, and comply with law.

5.7 Technical, usage, and security data

IP address.

Device type, operating system, and application version.

Device or application identifiers permitted for use.

Date, time, sessions, and login logs.

Pages and features used and technical events.

Error, crash, and performance logs.

Security data, login attempts, and unusual activities.

Technical information needed to diagnose faults, prevent fraud, and protect the account.

5.8 Geolocation

Qotbox may process an approximate location inferred from an IP address or from data the User chooses to enter in the account or RFQ. Qotbox does not collect precise device location unless a feature requires it and the appropriate permission has been requested from the User through the device system and in accordance with law.

5.9 Cookies and tracking technologies

The website or application may use cookies, local storage, or similar technologies to operate the service, maintain sessions and preferences, protect the service, measure and analyse usage, and, where applicable, for marketing.

Where law requires consent for a non-essential technology, Qotbox requests consent before activating it and provides an appropriate means to manage choices or withdraw consent. The cookie notice and preference centre must match the tools and SDKs actually used.

5.10 Data from other sources

Qotbox may receive data from a company representative, authorised User, verification provider, payment provider, or security service, or from a lawful public or official source. Where Qotbox lawfully uses such channels, this may include a verification or KYC report issued by an official platform or authorised provider, with the data subject’s consent when required. This is done only to the extent necessary for verification, service operation, Platform protection, or compliance.

5.1. Account and contact data

Name, trade name, and username.

Phone number and email address.

Country, emirate, address, and contact details.

Account language and communication preferences.

Data of authorised Users within an establishment account.

5.2. Company, establishment, and verification data

Establishment name, legal form, and business activity.

Licence or registration number, issuing authority, and expiry date.

Tax number when requested or needed.

Business address and establishment representative details.

Images or copies of documents submitted for verification purposes.

Outcome, status, and date of verification procedures, and document-validity indicators.

Carrying out verification or displaying a “Business Verified” or “Verified Account” badge does not mean that Qotbox guarantees the User, their financial solvency, products, or transactions; the badge indicates the status of verification of data or documents in accordance with Qotbox’s procedures.

5.3. Identity and individual verification data

Qotbox may collect identity data or additional verification information when necessary to verify an account, the authority of an establishment representative, prevent fraud, or comply with law. Qotbox does not request more data than it considers appropriate and necessary for the specified legitimate purpose.

5.4. RFQ and offer data

RFQ details, specifications, quantities, categories, locations, and timelines.

Offers, prices, delivery terms, warranty, and notes.

Attachments and documents linked to the request or offer.

Request and offer statuses and acceptance, rejection, or cancellation actions.

Electronic records of actions taken through the account.

5.5. Chats, attachments, reports, and support

Business messages and chats conducted through Qotbox.

Images, files, and attachments sent within chats.

Reports, complaints, and information provided for investigation.

Support correspondence, replies, and request-handling records.

Chats are intended for commercial purposes related to requests, offers, products, services, and transactions. Chat content and attachments may be processed to the extent necessary to provide messaging, handle reports, prevent fraud, protect Users and the Platform, enforce the Terms, protect rights, and comply with law. This does not mean Qotbox is obliged to pre-screen or continuously monitor all chats.

5.6. Service Credits, payment, and billing data

Service Credits and related ledger movements.

Value, date, and status of credit purchases, usage, or reversals.

Transaction references and payment-provider identifiers needed for reconciliation, support, and fraud prevention.

Invoice and tax data where applicable.

If payment is made through an external payment provider, that provider may process card or payment-method data directly in accordance with its legal role, terms, and privacy policy. The financial data Qotbox receives depend on the actual integration method with the payment provider, and Qotbox limits processing to data necessary to confirm the transaction, reconcile, bill, provide support, prevent fraud, and comply with law.

5.7. Technical, usage, and security data

IP address.

Device type, operating system, and application version.

Device or application identifiers permitted for use.

Date, time, sessions, and login logs.

Pages and features used and technical events.

Error, crash, and performance logs.

Security data, login attempts, and unusual activities.

Technical information needed to diagnose faults, prevent fraud, and protect the account.

5.8. Geolocation

Qotbox may process an approximate location inferred from an IP address or from data the User chooses to enter in the account or RFQ. Qotbox does not collect precise device location unless a feature requires it and the appropriate permission has been requested from the User through the device system and in accordance with law.

5.9. Cookies and tracking technologies

The website or application may use cookies, local storage, or similar technologies to operate the service, maintain sessions and preferences, protect the service, measure and analyse usage, and, where applicable, for marketing.

Where law requires consent for a non-essential technology, Qotbox requests consent before activating it and provides an appropriate means to manage choices or withdraw consent. The cookie notice and preference centre must match the tools and SDKs actually used.

5.10. Data from other sources

Qotbox may receive data from a company representative, authorised User, verification provider, payment provider, or security service, or from a lawful public or official source. Where Qotbox lawfully uses such channels, this may include a verification or KYC report issued by an official platform or authorised provider, with the data subject’s consent when required. This is done only to the extent necessary for verification, service operation, Platform protection, or compliance.

6. Protection of verification documents

Qotbox treats identity documents, licences, permits, and verification documents as data of elevated operational sensitivity.

Full copies of verification documents are not shown to other Buyers or Suppliers merely because a verification badge is displayed.

Access to verification documents is limited to authorised persons, systems, and providers who need them for verification, security, compliance, or handling a lawful legal request.

Qotbox applies appropriate access and permission controls and retains access logs or audit procedures where appropriate.

Verification documents are retained only for the period necessary according to the purpose, legal requirements, and retention standards set out in this Policy.

If Qotbox uses an external verification provider or an official or authorised KYC service, verification data or documents may be shared, or verification results received, to the extent necessary to perform the service, and subject to the authorities, consents, and safeguards required by law.

7. Sensitive data and data not required

Qotbox does not ask the User to submit sensitive personal data that are not necessary for its services. The User should avoid including excess or sensitive personal data in RFQs, offers, chats, or attachments unless necessary and lawfully permitted to be shared.

If Qotbox receives sensitive data necessarily or incidentally, it handles them with a level of protection and a legal basis appropriate to their nature.

8. Data of other persons

If a User enters another person’s data—such as an employee, representative, or contact—they represent that they have authority or a legitimate basis to share the data and have provided that person with the required information about the processing where required. Qotbox must not be used to upload other persons’ data without entitlement.

9. How and why we use data

Purpose

Examples of data

Reason for use

Legal basis depending on the case

Account creation and management

Name, phone, email, company data

Creating the account, signing in, managing permissions

For an individual account holder: performance of a contract to which the data subject is party, or steps taken at their request before entering a contract. For establishment representatives and employees: the legal basis appropriate to the nature of the role and purpose, including consent where required or any case in which the law permits processing without consent.

Account and establishment verification

Licence, identity data, representative data, document status

Verifying the account, preventing impersonation, protecting the Platform

Consent where required, or compliance with a legal or regulatory obligation, or any other case in which the law permits verification or processing without consent; an establishment representative is not assumed to be a personal party to the company’s contract merely because they are an authorised User.

Operating RFQs and offers

Requests, specifications, prices, attachments, offer statuses

Enabling Buyer and Supplier to use Platform functions

For a data subject who is a party to the contractual relationship: performance of the contract or pre-contractual steps. For an authorised User or establishment representative: the appropriate legal basis permitted according to role and purpose, with consent obtained if required.

Chats

Messages, attachments, chat data

Operating business communication and handling reports

Service performance, protection of rights, and prevention of misuse in accordance with cases permitted by law.

Service Credits and billing

Balance, movements, payment references, invoices

Performing paid services, reconciliation, billing, and support

Performance of the contract and related legal and financial obligations.

Security and fraud prevention

IP, login logs, device, unusual activities

Protecting accounts and the Platform and investigating fraud

Legal obligation, protection of rights, and cases permitted without consent under the law.

Support and complaints

Correspondence, files, account and transaction data

Resolving issues, reports, and disputes

Service performance, protection of rights, or legal obligations depending on the case.

Analytics and service development

Usage, performance, and fault events

Improving performance, reliability, and the product

The legal basis appropriate to the type of data and tool; consent is requested where required.

Marketing

Contact channels and preferences

Sending Qotbox offers or news

Consent where required, or any other basis expressly permitted by law, with a right to object or unsubscribe in accordance with applicable rules.

Compliance and claims

Account, transaction, and report records

Responding to authorities and defending rights

Legal obligation, legal proceedings or claims, and cases provided for by law.

10. Legal bases for processing

Qotbox relies on the legal basis appropriate to each processing operation under applicable law. This may include:

the data subject’s consent where consent is required, provided it is specific, clear, demonstrable, and withdrawable in accordance with law;

necessity of processing to perform a contract to which the data subject is party, or to take steps at their request before entering a contract;

necessity of processing to comply with a legal or regulatory obligation;

necessity of processing to establish, exercise, or defend a legal claim or right, or in the context of judicial or security proceedings in accordance with law;

any other case in which the law permits processing of data without consent.

Reviewing the Privacy Policy or accepting the Terms and Conditions is not a substitute for determining the correct legal basis for each processing purpose, nor for obtaining independent consent where the law requires it.

Qotbox maintains an up-to-date internal record of processing activities, service providers, SDKs, hosting or data-access locations, and categories of data exchanged, and reviews this record when a new provider or technology is added so that actual implementation remains consistent with this Policy and with relevant app-store disclosures and consent tools.

11. What other Users can see

Stage

What the other party may see

What is not usually shown

Public profile on the Platform

Name or trade name, account type, category, verification status, and professional information designed for display.

Full identity or licence documents, sensitive payment data, internal security logs.

Before an RFQ is unlocked for a Supplier

The summary and information Qotbox has decided to show for assessing opportunity suitability.

Any data or details Qotbox has classified as shown only after unlocking the request or meeting access conditions.

After an RFQ is unlocked

Request details, attachments, and data the service is designed to make available to the eligible Supplier.

The Buyer’s internal verification documents or sensitive data not needed for the deal.

After an offer is submitted

Offer details and the Supplier’s professional information needed for the Buyer to review the offer.

Full verification documents and internal data not needed.

Chats

Messages and attachments the parties send to each other.

Account security data, internal logs, or verification documents not expressly shared.

Data visible to other Users vary by account type, RFQ status, permissions, and the feature used. Qotbox does not publish full identity or verification documents publicly merely because a verification badge exists, and displays only data necessary to operate the feature or that the User chooses to share in accordance with service settings.

12. Direct marketing

Qotbox may send marketing messages where permitted by law. Creating an account, accepting the Terms and Conditions, or reviewing this Policy does not constitute independent consent to marketing. Where marketing requires consent, consent is requested in a clear, separate, demonstrable, and withdrawable manner, and the User may object or unsubscribe through the means available in the message or account settings.

Unsubscribing from marketing does not affect notices necessary for account operation, security, transactions, or legal obligations.

Qotbox does not make consent to marketing a condition of using core Platform functions where marketing is not necessary to provide those functions.

13. Automated processing and matching

Qotbox may use rules or automated systems to help match Suppliers to requests, rank or classify content, detect unusual activity, prevent fraud, or protect the Platform.

Automated matching is not an endorsement, recommendation, or warranty of Supplier quality or transaction success.

If Qotbox uses automated processing that produces a decision with legal effect or a similarly significant effect on the data subject as regulated by law, it will provide the information and rights required by law, including the ability to object or request human review where mandatory.

14. Data sharing

Qotbox does not sell personal data or rent them as a commodity or standalone data list. Data may be shared to the extent necessary, for a legitimate purpose, and in accordance with law with:

other Users when sharing is part of the service requested by the User;

hosting, cloud infrastructure, and database providers;

email, communications, messaging, OTP, and notification providers;

payment and billing providers when payment services are used;

identity or document verification providers when actually used;

cybersecurity, fraud-prevention, and crash-monitoring providers;

analytics or technical support providers under appropriate controls;

advisers, lawyers, and auditors where there is a legitimate need and subject to confidentiality;

authorities and judicial, regulatory, or law-enforcement bodies where disclosure is required or permitted by law;

a legal successor or a party to a lawful restructuring, merger, or acquisition, subject to legal requirements.

Where a service provider acts as a processor on behalf of Qotbox, Qotbox puts in place appropriate contractual and security obligations to govern the processing.

15. Service providers, SDKs, and third-party technologies

Qotbox applications and website may use software libraries, SDKs, and third-party services to provide functions such as analytics, crash reporting, notifications, authentication, communications, payments, fraud prevention, or support.

Qotbox assesses tools before use, identifies the data they access, the purpose, the recipient, and the place of processing, and updates disclosures or the privacy preference centre when adding a tool that materially changes data-processing practices.

Qotbox uses third-party tools to the extent necessary for the stated purposes and on the appropriate legal basis, and requests consent where required. If an external provider processes data for its own independent purposes, its privacy policy may also apply alongside this Policy depending on the nature of the integration.

A User may request, through the privacy contact channel below, the categories of service providers used, the purpose of each category, and the safeguards applied to it.

16. Mobile application permissions

The application may request iOS or Android system permissions only when needed for a specific feature. Depending on actual features, these may include:

Notifications: to send account, RFQ, offer, message, and security alerts.

Camera: to capture an image or document the User chooses to upload.

Photos or files: to select and send images, documents, and attachments.

Location: only if a feature that needs location is used and permission is required.

The User can manage app permissions from their device settings. Refusing a particular permission may prevent the feature that depends on it from working, without blocking other unrelated functions.

Qotbox requests device permissions when needed for the relevant feature, and does not use data available through a permission for a materially different purpose without appropriate disclosure and the required legal basis.

17. Transfer of data outside the UAE

Some hosting, technical, or support services may require processing of, or access to, data from outside the United Arab Emirates. When Qotbox transfers personal data across borders, it adopts the mechanisms and safeguards required by law, including reliance on an adequate level of protection, or permitted safeguards, agreements, or legal exceptions, as applicable.

A data subject may request information about the categories of recipients to whom transfers are made and the safeguards applied, in accordance with rights granted by law.

18. Data retention

Qotbox retains personal data only for the period necessary to achieve the purpose, or for the period required by law, tax, accounting, or security rules, or needed to establish, exercise, or defend rights and claims.

The period is determined by the nature of the data, sensitivity, duration of the relationship with the User, ongoing transactions and disputes, fraud risks, requirements of competent authorities, and backup cycles.

Data category

Retention criterion

Action after the need ends

Account data

For the life of the account and a subsequent period justified by legal obligations, disputes, or security.

Deletion, anonymisation, or restriction depending on the case.

Verification documents

For the period needed for verification, compliance, security, and defence of rights, in accordance with legal requirements.

Secure deletion or isolation when legal and operational need ends.

RFQs and offers

According to the request lifecycle, legal obligations, disputes, and support for the transaction record.

Deletion, anonymisation, or limited legal archiving.

Chats and attachments

According to the chat lifecycle, reports, disputes, security, and Qotbox’s adopted retention standards.

Deletion or anonymisation, while retaining what is needed for a dispute or legal obligation.

Payment and invoice data

In accordance with tax, accounting, claims, and fraud-prevention requirements.

Deletion or restricted archiving in accordance with law.

Security logs

For a period proportionate to security risks, investigations, and fraud prevention.

Deletion or anonymisation when the need ends.

Support and reports

Until the request is handled, then for the period needed for disputes, security, and protection of rights.

Deletion or restriction as needed.

After the legitimate need ends, data are deleted, anonymised, or isolated until removed from backup cycles in accordance with adopted technical procedures. Account closure is not an automatic request to erase all records if retention of some of them is required or permitted by law.

Some periods are fixed and are applied automatically by the Platform: a conversation on a rejected offer stays readable for 4 days and is then permanently deleted together with its messages and attachments; a conversation on an accepted offer is deleted 7 days after it closes; and a request to close an account has a grace period of 15 days during which the User may cancel it, after which closure is enforced. Where no fixed period is stated, the criteria set out above determine how long data is kept.

19. Information security

Qotbox applies technical and organisational measures appropriate to the nature of the data and the risks, which may include, depending on the actual system:

access controls, permissions, and least-privilege principles;

authentication, session management, and account-protection measures;

encryption in transit and appropriate protection for stored data according to their nature;

logging, monitoring, and detection of unusual activities;

backups and recovery and business-continuity plans;

vulnerability management and security updates;

incident and breach management procedures;

and controls over employees and suppliers who may access data.

No electronic means can be guaranteed absolutely secure; accordingly, Qotbox manages risk and takes appropriate measures rather than providing an absolute warranty that no incident will occur.

20. Data breaches

If Qotbox becomes aware of a breach or violation relating to personal data, it assesses the incident and takes containment, remediation, and documentation steps. If the breach or violation is likely to compromise the privacy, confidentiality, or security of the data in a manner that requires notification, Qotbox notifies the competent authority and the data subject within the period and in accordance with the procedures and information specified by law.

21. Data protection impact assessment and Data Protection Officer

Qotbox assesses new processing operations that may involve high risks to data subjects’ privacy. Where the circumstances in which law requires a data protection impact assessment arise—including certain forms of systematic and comprehensive evaluation using automated processing with legal or similarly significant effect, or large-scale processing of sensitive personal data—Qotbox carries out the appropriate assessment and takes measures to address the risks.

Qotbox periodically assesses whether the nature, technologies, or scale of processing require appointment of a Data Protection Officer, including high-risk cases or systematic comprehensive evaluation of sensitive personal data or large-scale processing of such data under the law. If appointment becomes mandatory or is adopted voluntarily, Qotbox provides the officer’s contact details in accordance with applicable requirements.

22. Data subject rights

Subject to legal conditions and exceptions, a data subject may exercise available rights, which may include:

obtaining information about the types of data processed and the purposes of processing;

knowing the categories or intended recipients with whom data are shared inside or outside the State;

knowing data retention controls or criteria and cross-border transfer safeguards;

requesting access to information relating to processing of their data;

requesting correction of inaccurate data or completion of incomplete data;

requesting erasure of data in the cases provided by law;

requesting restriction or cessation of processing in the cases provided by law;

objecting to processing in legal cases, including direct marketing;

requesting to receive or transmit data in a structured, machine-readable format where portability conditions apply;

exercising rights relating to automated processing and decisions where applicable;

withdrawing consent where processing is based on consent, without affecting the lawfulness of prior processing;

lodging a complaint with the competent data protection authority in accordance with legal procedures.

23. How to exercise privacy rights

Privacy requests may be sent to: privacy@qotbox.com.

Qotbox may request reasonable information to verify the identity of the requester and the authority of their representative before fulfilling the request, in order to protect data from unauthorised disclosure or alteration.

Qotbox handles requests within legal timeframes and requirements. It may refuse or restrict a request in cases permitted by law, such as conflict with an investigation or judicial proceeding, or with the rights and privacy of other persons, or where there is a legal obligation to retain the data.

24. Account closure and data deletion

A User may request closure of their account through the means provided by Qotbox. Closure ends ordinary access to the account in accordance with the Terms of Service.

A data-deletion request is handled separately in accordance with erasure rights and legal exceptions. Qotbox may retain data necessary for compliance, fraud prevention, tax and accounting, settling transactions, protecting rights, disputes, investigations, or any other legitimate purpose permitted by law.

25. User responsibility for information they share

The User should review information placed in their profile, RFQ, offers, chats, or attachments, and avoid entering personal data not needed for the commercial purpose.

Another User may be able to save or use information the User chooses to share with them. The receiving party is responsible for any independent processing they carry out outside Qotbox’s tools in accordance with law.

26. External links and services

Qotbox may include links or integrations with external services. Qotbox does not control the privacy practices of an external party when it acts as an independent controller, and the User is advised to review that party’s privacy policy before submitting their data.

27. Changes to the Privacy Policy

This Policy may be updated when Qotbox’s services, processing practices, or legal or technical requirements change.

The last-updated date appears at the top of the Policy. Where a material change significantly affects how data are processed, Qotbox provides appropriate notice via the application, website, or a registered contact method, and requests fresh consent where consent is legally required.

28. Relationship with the Terms and Conditions

This Policy governs processing of personal data, while the Terms and Conditions govern use of the Platform and the contractual relationship relating to the services.

This Policy does not change the nature of Qotbox described in the Terms and Conditions as a technology platform for matching and communication between Buyers and Suppliers, while Qotbox remains responsible for processing personal data for which it determines the purposes and means in accordance with law.

29. Applicable law

Personal data are processed in accordance with data-protection legislation applicable in the United Arab Emirates. This includes the federal Personal Data Protection Law to the extent it applies to the operating entity and its activity.

If the operating entity or a particular processing operation is subject to a special data-protection regime in a free zone or regulatory jurisdiction with mandatory special provisions, those provisions apply to the extent they are applicable, and this Policy is interpreted consistently with them without diminishing data-subject rights.

30. Contact and complaints

For any enquiry, request, or complaint relating to privacy or data processing:

Qotbox - Qot Box FZC

Privacy email: privacy@qotbox.com

Legal email: legal@qotbox.com

Registered address: Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates

The data subject retains the right to lodge a complaint with the competent data protection authority in accordance with law and applicable procedures.

This document is in effect for the Qotbox platform and governs use of the platform as of the effective date above.