Legal
Privacy Policy
Version 1.0 · Effective 1 September 2026
Permanent URL of this version: https://www.oasisguestlab.ai/legal/privacy/v1.0/ Current version always at: https://www.oasisguestlab.ai/legal/privacy/
Who we are
Oasis Guest Lab is a service of Lux Oasis Advisory & Services LLC, a company registered in the Sharjah Free Zone (SHAMS), United Arab Emirates, licence number 2645909, TRN 104722180700003 ("we", "us", "our").
Contact for anything in this policy: info@luxoasisadvisory.com · WhatsApp +971 58 508 9283
Lux Oasis Advisory & Services LLC and Lux Oasis Holiday Homes are two separate companies registered in the United Arab Emirates. Neither owns the other. Lux Oasis Holiday Homes holds a DTCM licence and operates a short-term rental portfolio in JBR, Dubai Marina and Downtown Dubai. It is our operating partner: the live operation in which our systems and methods are tested before they are offered to clients. Lux Oasis Advisory & Services LLC does not hold a DTCM licence and does not operate short-term rental accommodation.
Why this policy has two parts
We handle personal data in two completely different roles, and the rules are different for each. Reading them as one thing is how privacy policies end up incoherent, so we have split them.
Part A is data we control. Website visitors, people who send us an enquiry, and the people at our client businesses who hold accounts with us. We decide why and how that data is used, so we are the controller, we choose the legal basis, and you come to us with your rights requests.
Part B is data we process for a client. The personal data of guests who message a property operator on WhatsApp. The operator decides why and how that data is used, so the operator is the controller and we are the processor. We act only on the operator's documented instructions. We do not choose the legal basis for that data and we cannot answer a guest's rights request in our own name.
Part C applies to both.
If you are a guest and you are not sure which applies to you, the short answer is Part B: contact the operator of the property you are staying in. If you cannot reach them, contact us and we will pass your request to them.
PART A: DATA WE CONTROL
We are the controller of the data in this Part.
A1. Website visitors
What we collect. Our web server records the standard technical information generated by any web request: IP address, the page requested, the date and time, the referring page, and browser and device information sent by your browser.
We set no cookies on our website. We run no analytics product. We use no advertising or tracking technology, and we do not store anything in your browser's local storage or session storage. See the Cookie Policy for the detail, including the one third-party request our pages make.
Why, and on what basis. To serve the website, keep it secure, and diagnose faults. Our legal basis is our legitimate interest in operating and protecting our own website. That interest is limited: we do not build profiles, we do not track you across other sites, and we do not use this data for marketing.
How long. Server logs are kept for [PLACEHOLDER: LOG RETENTION PERIOD, TO BE CONFIRMED BY THE OWNER] and then deleted.
A2. Enquiries
What we collect. Whatever you put in your message to us: your name, your email address, your WhatsApp number, your company, the size of your portfolio, and anything else you choose to tell us. Our website forms have no backend; submitting one opens a pre-filled email in your own email client, so the message reaches us as an ordinary email. If you contact us on WhatsApp, we receive your WhatsApp number and profile name.
Why, and on what basis. To answer you, to prepare a proposal, and to keep a record of what was discussed. Our legal basis is our legitimate interest in responding to people who contact us about our services, and, once we are working towards an agreement, the steps taken at your request before entering into a contract.
Marketing. We do not add enquirers to a marketing list. If we ever introduce one, it will be opt-in, and the opt-in will be separate and unticked.
How long. Enquiries that do not lead to an agreement are kept for 24 months and then deleted. Enquiries that lead to an agreement become part of the client record under A3.
A3. Client account holders
What we collect. The name, business email address, telephone or WhatsApp number and role of the people at our client businesses who hold accounts or act as our contacts, together with account activity records such as sign-in times, actions taken in the dashboard and support correspondence. We also hold the client's business details, licence and TRN, billing details and payment records, which are mostly company information rather than personal data.
Why, and on what basis.
| Purpose | Legal basis |
|---|---|
| Providing the platform to the client, administering accounts, providing support | Performance of our contract with the client, and our legitimate interest in administering that contract where the individual is not personally the counterparty |
| Billing, invoicing, credit control | Performance of the contract, and legal obligation under UAE tax law |
| Security, access control, keeping audit records of who did what in the dashboard | Our legitimate interest in keeping the platform secure, and our obligations to our clients under the Data Processing Addendum |
| Service messages: outages, changes to documents, changes to price, security notices | Performance of the contract |
| Keeping accounting and tax records | Legal obligation |
| Establishing, exercising or defending legal claims | Our legitimate interest in protecting our position |
How long. Account records are deleted within 30 days of the end of the client agreement, in line with clause 13 of the Terms of Service. Invoices and accounting records are kept for the period required by applicable UAE tax and accounting law and for nothing else.
A4. Our own AI improvement work
We improve our models, our prompts and our product using Aggregated and De-identified Data as defined in clause 11.3 of the Terms of Service: data from which names, phone numbers, email addresses, booking references, unit and building identifiers and client identity have been removed or irreversibly obscured, so that neither a guest, nor a member of a client's team, nor a unit, nor a client can reasonably be identified.
We do not use identifiable guest personal data, or guest conversation content in a form from which an individual can reasonably be re-identified, to train, fine-tune, evaluate or improve any model, for benchmarking, or for product analytics. Doing so would be processing for our own purposes and would make us a controller of guest data. We do not do it, and our contract with each client does not permit it.
We do not attempt to re-identify Aggregated and De-identified Data.
A5. Your rights over data we control
Where the law gives you these rights, you have them, and you exercise them by emailing info@luxoasisadvisory.com. We will respond within one month.
- Access to the personal data we hold about you, and a copy of it.
- Correction of data that is wrong or incomplete.
- Deletion, where we no longer have a good reason to keep it.
- Restriction of processing while a dispute about accuracy or legitimacy is resolved.
- Objection to processing based on legitimate interests, including an absolute right to object to direct marketing.
- Portability of data you gave us, where processing is by consent or contract and carried out by automated means.
- Withdrawal of consent, where we relied on consent, without affecting what we did before you withdrew it.
- To complain to a supervisory authority. Which authority that is depends on where you are and which law applies to you.
We may need to verify your identity before acting. We will not charge you unless a request is manifestly unfounded or excessive, and we will tell you before we charge anything.
PART B: DATA WE PROCESS ON A CLIENT'S INSTRUCTIONS
We are the processor of the data in this Part. The property operator is the controller. The operator decides what data is collected, why it is used, how long it is kept and on what legal basis it is processed. We act only on the operator's documented instructions, which are set out in the Data Processing Addendum at https://www.oasisguestlab.ai/legal/dpa/.
We are stating this in one sentence so it cannot be misread: for guest personal data, we do not choose the purpose, we do not choose the legal basis, and we do not decide a guest's rights request.
B1. Whose data, and what data
Data subjects: guests and prospective guests who message a WhatsApp number connected to the Service; other individuals a guest mentions in a message; and the operator's own staff who use the Chatwoot dashboard.
Categories of data:
- WhatsApp phone number and WhatsApp profile display name.
- The content of messages sent to and from the connected number, including anything a guest chooses to put in a message.
- Conversation metadata: timestamps, delivery status, message direction, language, whether a message was AI generated or sent by a human operator, escalation labels.
- Booking data received from the operator's property management system where the operator connects one: guest name, phone number, unit, check-in and check-out dates, booking source and booking reference.
- Operator staff data: dashboard user names, email addresses and action logs.
Special category data. The Service is not designed to collect health data, data about religious or philosophical beliefs, or any other special category of data, and operators must not configure it to. A guest may nonetheless volunteer such data in a free-text message, for example by mentioning an allergy, a disability, a medical need or a dietary requirement tied to belief. Where that happens the data is processed only because it is in the message, and it is subject to the same handling as the rest of the conversation. Operators should account for that possibility in their own privacy notice and in their own legal basis analysis.
Children. The Service is not directed at children. Where a booking includes children, their data may appear in a message.
B2. What we do with it
Only what is needed to run the Service for the operator:
- match an incoming message to the right unit and the right booking;
- generate a reply from that unit's knowledge layer;
- apply the operator's escalation rules and flag conversations to the operator's team;
- present the conversation in the Chatwoot dashboard so the operator can read it, take it over and continue it;
- keep the conversation history so context is not lost when a human takes over;
- keep the Service secure and diagnose faults;
- comply with law.
We do not use guest data for our own marketing or for the operator's marketing. We do not sell it. We do not use it for advertising, and we do not permit WhatsApp data to be used for advertising. We do not use it to train models except in the aggregated and de-identified form described in A4, which is not guest personal data.
B3. The legal basis for guest data
The operator determines it. Typically an operator will rely on performance of its accommodation contract with the guest, on its legitimate interests in servicing a stay, or on consent, but that is the operator's call and the operator's responsibility to state in its own privacy notice.
We do not adopt, assert or publish a legal basis for guest personal data, because a processor that selects a legal basis is not a processor.
B4. Retention of guest data
Our default, which applies unless the operator instructs otherwise in writing:
- conversation data is kept for twelve months from the date of the last message in that conversation, then deleted;
- on termination of the operator's agreement, all of it is deleted within 30 days, or within 30 days of delivering an export the operator has requested, whichever is later;
- an operator may instruct a shorter period at any time, and we will apply it.
This is the single retention position for the Service. It replaces every other retention statement previously published for Oasis Guest Lab.
B5. Guest rights requests
If you are a guest and you want access to, correction of, or deletion of your data, or you want to object to processing, the request goes to the operator of the property you stayed in. They are the controller and the decision is theirs.
If you send the request to us, we will not decide it. We will forward it to the operator without undue delay and tell you that we have done so, and we will help the operator answer it. We can identify the operator connected to the number you messaged.
We can act on a guest request directly only where the operator instructs us to.
B6. Sub-processors for guest data
The current list, what each one does, and where each one processes, is at https://www.oasisguestlab.ai/legal/sub-processors/. We give operators at least 30 days' notice before adding or replacing one, and operators may object. See the Data Processing Addendum, clause 7.
PART C: MATTERS THAT APPLY TO BOTH PARTS
C1. Where data is stored and processed
Guest and unit data is hosted in the European Union, on servers operated by Hetzner. It is not hosted in the United Arab Emirates.
This is a change of position, stated plainly. Earlier versions of our privacy policy claimed compliance with UAE data residency requirements while also saying data sits in the EU. Those two statements cannot both be true, and the accurate one is that the data is in the EU. If your own regulatory position, or a requirement imposed on you by a landlord, an owners' association, a licensing authority or your own client, requires that guest data stays inside the UAE, tell us before onboarding. We cannot meet a UAE residency requirement on the current infrastructure.
Some processing necessarily happens outside the EU:
| Flow | Where |
|---|---|
| Message transport to and from guests | Meta's global infrastructure, including the United States |
| WhatsApp Business API connectivity | Our WhatsApp Business Solution Provider, 360dialog, in the European Union |
| Generating AI replies | OpenAI, in the United States |
| Hosting, storage, the operator dashboard | Hetzner, in the European Union |
| Booking data, where an operator connects a property management system | The operator's own PMS provider, under the operator's own contract with them |
| Our own staff access for support and administration | The United Arab Emirates |
C2. Cross-border transfers, and where the position is unsettled
We would rather be exact than reassuring, so this section says what we rely on and where the ground is not yet firm.
Transfers out of the UAE. The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) restricts transfers of personal data outside the UAE, permitting them where the receiving jurisdiction provides an adequate level of protection, or where an appropriate safeguard such as a contract, binding corporate rules or an approved instrument is in place, or on other limited grounds. The detail of the adequacy list, of the approved contractual instruments and of the notification procedure is left to executive regulations.
As at the effective date of this document, we do not treat those executive regulations as settled, and we have not built any position that depends on them. Where a document, a certification body or a competitor tells you that UAE cross-border transfer requirements are fully resolved, treat that as a claim to be checked rather than a fact. Our position is:
- we rely on written contractual commitments with each provider that carry data protection obligations equivalent in substance to those we owe our clients;
- where the provider offers them, we rely in addition on the standard contractual clauses adopted by the European Commission;
- we will re-paper on the PDPL's own transfer instruments as soon as they exist in a usable form, and we will publish an updated version of this policy when we do;
- this section is flagged for review by a qualified UAE lawyer at publication and at each material change in the regulations.
Transfers out of the EU, where the GDPR applies. We do not assert that the GDPR applies to every operator or every guest, and we do not assert that it does not. Whether it applies depends on where the operator is established and whether the operator is offering services to individuals in the EU or the UK. That is the operator's determination to make, and the Data Processing Addendum contains the GDPR terms that apply where the operator determines it does.
Where the GDPR applies and personal data hosted in the EU is transferred onward to a provider outside the EU, we rely on the standard contractual clauses adopted by the European Commission, in the module appropriate to the relationship, together with the transfer risk assessment and supplementary measures those clauses require. Where a recipient is certified under the EU-US Data Privacy Framework and the transfer falls within that certification, we may rely on the framework instead. We do not claim that any particular provider holds such a certification; the current position for each is stated in the Sub-processor List.
What we do not claim. We do not claim UAE data residency. We do not claim adequacy for any jurisdiction. We do not claim certification under any privacy framework in our own name. We do not claim compliance with any regulation not addressed in this document.
C3. Security
We protect data in transit with TLS encryption. Access to systems is restricted to the people who need it to do their job, under individual credentials. Guest and unit data is held on infrastructure we control, in EU data centres operated by Hetzner. The operator dashboard, Chatwoot, is open-source software that we self-host on that same infrastructure, so guest conversations are not sent to a third-party dashboard vendor. Everyone with access is under a written confidentiality obligation.
The full and current list of technical and organisational measures is in Annex 2 of the Data Processing Addendum, which is the document a client or a client's lawyer should read. We describe there only measures we actually have in place. We hold no security certification and we do not claim one. Where a measure is planned but not yet implemented, Annex 2 says so.
No system is perfectly secure, and we do not say ours is.
C4. Personal data breaches
If a breach affects data we control under Part A, we will notify the individuals affected and any competent authority where the law requires it, without undue delay.
If a breach affects data we process under Part B, we notify the operator, not the guest. The operator is the controller and decides what to tell guests and regulators. Our notification obligations and timings are in clause 9 of the Data Processing Addendum.
C5. Complaints
Tell us first: info@luxoasisadvisory.com. We would rather fix it than have it escalated, and we will answer within one month.
You may also complain to a supervisory authority. Which one that is depends on where you are and which law applies. For data we process for an operator, a complaint about how the data is used goes to the operator in the first instance.
C6. Third-party marks
Third-party names, logos and trademarks are the property of their respective owners. Their appearance on this site indicates the tools and platforms we work with. It does not imply any endorsement, sponsorship or affiliation beyond any partner status we expressly state and hold.
C7. Changes to this policy
Every version carries a version number and an effective date, and every version is archived at a permanent URL and is never overwritten in place.
For a material change we give clients at least 30 days' notice by email and ask them to accept the new version. Continued use of the Service after the effective date is not acceptance of a material change. Non-material changes take effect on publication.
C8. Language
These documents are written in English. English is the governing language. If they are translated, the English version prevails.
This document has been prepared for review and requires sign-off by a qualified UAE lawyer before publication. It is not legal advice.