• Home
  • Privacy Policy

PRIVACY POLICY

Effective Date: 01-07-2025
Last Updated: 20-07-2025

  1. INTRODUCTION AND SCOPE OF APPLICATION

Last Cluster Cloud Services LLC, a company registered in Dubai, United Arab Emirates (hereinafter “Last Cluster”, “we”, “us”, or “our”), is committed to protecting the privacy and security of the personal data of individuals with whom it interacts.

This Privacy Policy describes how Last Cluster, as a Data Controller, collects, uses, stores, shares, and protects Personal Data in accordance with the Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data of the United Arab Emirates (“PDPL”) and other applicable laws and regulations in the UAE.

This policy applies to the Personal Data we process as Controllers, collected through:

  • Our website  http://www.lastcluster.ae (“Website”).
  • The registration and management of our Clients’ accounts.
  • Interactions with our sales, technical support, or administrative teams.
  • Our marketing and promotional activities (subject to consent, where required).
  • The use of certain aggregated or anonymized technical data derived from the general use of our services for improvement and security purposes.

Important: This Privacy Policy does not govern the processing of Client Content (as defined in our General Terms and Conditions of Service – “T&C”) uploaded or processed by the Client within our cloud services (e.g., Cloud Compute, Cloud Storage, etc.). For such processing, Last Cluster acts as a Data Processor on behalf of the Client (who acts as the Controller). This processing is governed exclusively by the Data Processing Addendum (DPA), available at the link [Insert Link to Standard DPA], which forms an integral part of our T&C.

  1. DEFINITIONS

For the purposes of this Privacy Policy, the following terms shall have the meaning specified by the UAE PDPL (or as otherwise specified):

  • Personal Data:Any information relating to an identified or identifiable natural person.
  • Processing:Any operation performed on Personal Data (collection, use, storage, disclosure, etc.).
  • Data Controller:The natural or legal person who determines the purposes and means of the Processing of Personal Data (in this context, Last Cluster for the data covered by this policy).
  • Data Processor:The natural or legal person who processes Personal Data on behalf of the Data Controller (in this context, Last Cluster for the Client Content processed in the Cloud Services, according to the Client’s instructions and as detailed in the DPA).
  • Data Subject:The natural person to whom the Personal Data relates.
  • Consent:A free, specific, informed, and unambiguous manifestation of the Data Subject’s will.
  • Sensitive Personal Data:As defined by the PDPL (racial/ethnic origin, political opinions, religious/philosophical beliefs, trade union membership, genetic/biometric data, data concerning health, sex life/sexual orientation).
  • PDPL:Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data of the UAE.
  • UAE Data Office:The federal authority responsible for the supervision and enforcement of the PDPL.
  • T&C:The General Terms and Conditions of Service of Last Cluster.
  • DPA:The Data Processing Addendum of Last Cluster, which governs the processing of data as a Processor.
  1. INFORMATION ON THE DATA CONTROLLER AND POTENTIAL DPO

The Controller of the Personal Data covered by this Policy is:

Last Cluster Cloud Services LLC
Latifa Tower – Office No. B3107-46, Dubai, UAE
License Number: 1442759

Email for privacy matters: [email protected]
Phone: +971 042201123

Pursuant to the current PDPL regulation, we are not obliged to appoint a Data Protection Officer (DPO). For any questions regarding privacy, please use the Controller’s contact details provided above.

  1. WHAT PERSONAL DATA WE COLLECT AS CONTROLLERS

We collect the following categories of Personal Data when we act as Controllers:

  • Identification and Contact Data:Name, surname, email address, phone number, postal address, company name, professional role, username. (Collected during account registration, information requests, support/sales contacts).
  • Client Account Data:Client ID, account preferences (e.g., language), history of subscribed orders and services (limited to order metadata), account configuration information. (Does not include Client Content processed in the services).
  • Financial and Billing Data:Billing address, transaction history (limited to amounts and dates), partial and tokenized information on the payment method (we do not store full credit card numbers, which are managed by our PCI-DSS compliant payment processors).
  • Technical Data of Website and Account Usage:IP addresses, browser and device type, operating system, pages visited on our website, referring URL, dates and times of access, account access logs (not to internal cloud services), information collected via cookies (see Section 14).
  • Communication Data:Records of communications with our teams (email, chat, phone calls – with prior consent where required), feedback provided, responses to surveys (if anonymized, they are not personal data).
  • Data for Marketing Purposes:Marketing preferences (subscription/unsubscription), information on participation in events or webinars, data provided through lead generation forms (with prior consent).
  1. HOW WE COLLECT PERSONAL DATA AS CONTROLLERS

We collect Personal Data processed as Controllers through:

  • Directly from You:When you register for an account, fill out forms on the Website, contact us for support or information, participate in events, or provide consent for marketing.
  • Automatically:When you browse our Website or interact with your account management console, we collect technical data through logs and cookies (see Section 14).
  • Via Third Parties:We may receive information from payment service providers (transaction confirmation), business partners (if they refer a client to us or vice versa, with prior consent), publicly available sources (for business verification, within legal limits), or marketing platforms (with your prior consent).
  1. PURPOSES OF PROCESSING (AS CONTROLLERS)

We process your Personal Data (as Controllers) for the following purposes:

Purpose Examples of Data Used (Categories Sec. 4) Primary Legal Basis (See Sec. 7)
a) Provision and Management of Client Account Identifiers, Contact, Account, Financial (partial) Contractual Necessity
b) Billing and Payment Management Identifiers, Contact, Account, Financial Contractual Necessity, Legal Obligation
c) Customer Assistance and Technical Support Identifiers, Contact, Account, Communication Contractual Necessity, Legitimate Interest
d) Improvement of Website and User Experience (Account) Technical Website/Account Legitimate Interest, Consent (Cookie)
e) Service-Related Communications Identifiers, Contact, Account Contractual Necessity, Legitimate Interest
f) Marketing and Promotions (with Consent) Identifiers, Contact, Marketing Explicit Consent
g) Security and Fraud Prevention (Systems and Account) Identifiers, Account, Technical Network/Website Legitimate Interest, Legal Obligation
h) Compliance with Legal and Regulatory Obligations All relevant data Legal Obligation
i) Aggregated Statistical Analysis (for Service Improvement) Anonymized/Aggregated Technical Data Legitimate Interest
  1. LEGAL BASIS FOR PROCESSING (ACCORDING TO UAE PDPL)

The processing of your Personal Data is based on one or more of the following legal bases provided by the PDPL:

  • Consent:For specific purposes (e.g., direct marketing, certain cookies), we will ask for your explicit consent. You have the right to withdraw your consent at any time.
  • Contractual Necessity:The processing is necessary for the performance of a contract to which you are a party (e.g., to provide and manage your account and related services as a Controller) or to take pre-contractual steps at your request.
  • Legal Obligation:The processing is necessary to comply with a legal obligation to which Last Cluster is subject under the laws of the United Arab Emirates (e.g., tax obligations, authority requests).
  • Protection of Vital Interests:The processing is necessary to protect the vital interests of the Data Subject or another natural person (rarely applicable in our context).
  • Legitimate Interest:We may process data for our legitimate interests (e.g., ensuring the security of our systems, improving our website, managing customer support efficiently), provided that such interests are not overridden by your fundamental rights and freedoms. We will perform a case-by-case balancing assessment.
  1. DATA SHARING AND COMMUNICATION (AS CONTROLLERS)

We do not sell your Personal Data. We may share Personal Data processed as Controllers only in the following circumstances:

  • Third-Party Service Providers (Our Processors):We share data with companies that provide services on our behalf (e.g., payment processors, CRM/support platform providers, web analytics tools, hosting providers for our website). These providers act as our Data Processors and are contractually obligated to protect the data and use it only for the purposes we define.
  • Business Partners:Only with your explicit consent or where necessary to provide a requested joint service, we may share limited data with selected partners.
  • Legal and Governmental Authorities:We may disclose Personal Data if required by the law of the United Arab Emirates, by a court order, or by a competent governmental authority, or if necessary to protect our legal rights or security.
  • Corporate Transfers:In the event of a merger, acquisition, reorganization, or sale of assets, Personal Data may be transferred as part of the transaction, in compliance with PDPL regulations and by informing you accordingly.
  • Affiliated Companies:We may share data with other companies in our group for internal administrative purposes or for the coordinated provision of services (e.g., global support), always in compliance with this policy and with adequate safeguards.

We require all third parties to respect the security of your Personal Data and to treat it in accordance with the law and our agreements.

  1. INTERNATIONAL DATA TRANSFER (AS CONTROLLERS)

The Personal Data we collect as Controllers may be processed, stored, or accessed from locations outside the United Arab Emirates (UAE), where we, our affiliated companies, or our third-party service providers operate.
We will carry out such international transfers only in accordance with the UAE PDPL. We will transfer data only to:

  • Countries for which the UAE Data Office has issued an adequacy decision.
  • Countries without an adequacy decision, only if appropriate safeguardsapproved under the PDPL are in place, such as:
    • Standard Contractual Clauses (SCC)approved by the UAE Data Office entered into with the data recipient. [Note: Verify if the UAE Data Office has published specific SCCs]
    • Binding Corporate Rules (BCR)approved, for intra-group transfers.
  • In the absence of the above conditions (exceptional circumstances), we may rely on specific derogationsprovided by the PDPL, such as your explicit consent to the proposed transfer (after being informed of the risks), or if the transfer is necessary for the performance of a contract with you, for important reasons of public interest, or to establish/exercise/defend a legal claim.

We will provide you with specific information on the safeguards adopted for the international transfers that concern you, upon request. [Optional: List here the main countries/regions to which transfers occur and the prevailing mechanism, e.g., ‘Our main providers are located in [Europe/USA] and we use approved SCCs…’]

  1. SECURITY MEASURES

We adopt appropriate and commercially reasonable technical, administrative, and physical security measures to protect Personal Data (processed as Controllers) from loss, misuse, unauthorized access, disclosure, alteration, and destruction. These measures include, but are not limited to:

  • Data encryption (at rest and in transit, where technically feasible and appropriate).
  • Strict access controls based on roles and the “need-to-know” principle.
  • Firewalls, intrusion detection/prevention systems, and Anti-DDoS protection for our infrastructures.
  • Vulnerability management and patch management procedures.
  • Staff training on data security and privacy.
  • Backup and disaster recovery procedures.
  • Security monitoring and logging to detect and respond to incidents.

Despite our efforts, no security measure is perfect. In the event of a personal data breach (Data Breach) that may pose a risk to the rights and freedoms of individuals, we will notify the UAE Data Office and, if necessary, the data subjects, in accordance with the requirements of the PDPL.

  1. DATA RETENTION (AS CONTROLLERS)

We retain Personal Data processed as Controllers only for the time strictly necessary to fulfill the purposes for which it was collected, as described in Section 6, and to comply with our legal, regulatory, tax, accounting, or reporting obligations in the UAE.

To determine the appropriate retention period, we consider: the quantity, nature, and sensitivity of the data; the potential risk of harm; the purposes of the processing; the possibility of achieving those purposes by other means; the applicable legal requirements.

Example of criteria/periods (to be adapted):

  • Client Account Data:Retained for the duration of the contractual relationship plus a subsequent period of [Number, e.g., 3] years for legal/tax/rights defense obligations.
  • Marketing Data (based on consent):Retained until consent is revoked.
  • Website Logs:Retained for [Number, e.g., 6] months for security/performance analysis.
    At the end of the retention period, Personal Data will be securely deleted or irreversibly anonymized.
  1. DATA SUBJECT’S RIGHTS (ACCORDING TO UAE PDPL)

Under the UAE PDPL, you have specific rights regarding the Personal Data we process as Controllers:

  • Right of Access:Request information about the processing and a copy of your data.
  • Right to Rectification:Request the correction of inaccurate or incomplete data.
  • Right to Erasure (“Right to be Forgotten”):Request the deletion of your data in certain circumstances.
  • Right to Restriction of Processing:Request to limit the processing of your data in certain situations.
  • Right to Data Portability:Receive your data (provided by you, processed with consent/contract by automated means) in a structured, machine-readable format, and transmit it to another controller.
  • Right to Object:Object to processing based on legitimate interest or for direct marketing. Object to decisions based solely on automated processing (including profiling) with legal/significant effects.
  • Right to Withdraw Consent:Withdraw consent at any time for processing based on it.
  • Right to Lodge a Complaint:Lodge a complaint with the competent authority, the UAE Data Office.
  1. HOW TO EXERCISE YOUR RIGHTS

To exercise any of the rights mentioned above, or to ask questions about this Policy, you can contact us via:

We may need to request specific information from you to confirm your identity before processing the request (security measures). We will try to respond to all legitimate requests within one month of receipt, as provided by the PDPL (extendable by a further two months in complex cases, informing you of the extension).

  1. COOKIES AND SIMILAR TECHNOLOGIES

We use cookies and similar technologies on our Website to improve its functionality, analyze traffic, personalize the user experience, and, with your consent, for advertising purposes. For detailed information on the types of cookies used, the purposes, the legal basis, and how to manage your preferences (including how to provide and revoke consent), please consult our separate Cookie Policy, available at the following link: http://www.lastcluster.ae. (Note: A separate policy is strongly recommended)

  1. CHILDREN’S PRIVACY

Our services and our website are not directed at persons under the age of 18 (or the minimum age provided by applicable law). We do not knowingly collect Personal Data from minors as Controllers. If we become aware that we have collected Personal Data from a minor without the necessary parental/legal guardian consent, we will take steps to delete that information.

  1. CHANGES TO THE PRIVACY POLICY

We reserve the right to modify this Privacy Policy at any time. Any changes will be published on this page with an updated “Effective Date”. In case of substantial changes, we will inform you by appropriate means (e.g., via email or a notice on the Website) before the change becomes effective, and if necessary, we will request your consent again for certain processing. We encourage you to periodically consult this page.

  1. CONTACTS

For any questions, doubts, or requests regarding this Privacy Policy or our data processing practices as Controllers, please contact us:

Last Cluster Cloud Services LLC
Latifa Tower – Office No. B3107-46, Dubai, UAE
Email: [email protected]
Phone: +971 042201123