Last updated: April 2026 · Version 1.0
Rendevy is a UAE-based Software-as-a-Service (SaaS) platform that provides AI-powered appointment booking and management services for businesses including clinics, salons, wellness centres, and other appointment-driven businesses operating in the UAE.
Rendevy acts as a data controller for personal data we collect directly (e.g. admin account information), and as a data processor on behalf of our business customers (clinics and salons) for the personal data of their clients and patients.
Data Controller: Rendevy Platform
Contact: privacy@curiousstack.co
Jurisdiction: United Arab Emirates
We collect only the minimum data necessary to provide our services.
Client / patient data (collected when a person interacts with a business's booking chatbot):
Business admin user data (collected when a clinic or salon signs up):
Automatically collected data:
Under the UAE Personal Data Protection Law (PDPL, Federal Decree-Law No. 45 of 2021) and the EU General Data Protection Regulation (GDPR) where applicable, we rely on the following lawful bases:
| Processing activity | Lawful basis |
|---|---|
| Booking and managing appointments | Contract performance — necessary to deliver the service you requested |
| WhatsApp messaging and reminders | Consent — you confirm consent by replying YES to our onboarding message; withdraw anytime by replying STOP |
| Outbound voice call reminders | Consent — covered by the same YES consent given during WhatsApp onboarding; withdraw anytime by replying STOP or emailing privacy@curiousstack.co |
| Security and audit logging | Legitimate interests — protecting the platform and our users |
| Email notifications | Consent / contract performance |
| Health record retention (medical clinics) | Legal obligation — UAE Federal Law No. 2 of 2019 on health data |
You may withdraw consent for WhatsApp communications at any time by replying STOP to any message from our chatbot. To opt out of voice call reminders specifically, reply STOP via WhatsApp or email privacy@curiousstack.co. Withdrawing consent will not affect appointments already booked.
We share your data only with the third-party service providers listed below, who process it solely on our instructions and under Data Processing Agreements:
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Database storage (CosmosDB), AI processing (Azure OpenAI) | UAE North (primary); data residency policy enforced |
| Twilio | WhatsApp message delivery and voice calls | United States |
| Staff calendar scheduling (appointment slots only; no client PII) | United States / Global | |
| SendGrid (Twilio) | Email appointment reminders | United States |
| Microsoft Azure Monitor | Application performance and error logging | UAE North (primary) |
We do not sell your personal data. We do not share it with third parties for their own marketing purposes.
We may disclose data to law enforcement or regulatory authorities where required by UAE law or a valid court order.
We store your data primarily in the UAE North Azure data centre. Some processing operations involve sub-processors located outside the UAE (see Section 5).
Where personal data is transferred outside the UAE, we ensure appropriate safeguards are in place, including:
For clients whose data may constitute health data under UAE Federal Law No. 2 of 2019, we take additional steps to minimise cross-border processing and apply the highest available safeguards.
| Data category | Retention period | Basis |
|---|---|---|
| Appointment records (medical clinics) | Up to 10 years from last appointment | UAE Health Data Law minimum |
| Appointment records (wellness / non-medical) | Up to 5 years from last appointment | Commercial records standard |
| Client registration data | Duration of active relationship + 3 years after last activity | PDPL data minimisation |
| WhatsApp conversation logs | 24 months | Operational need; deleted thereafter |
| Voice call logs (metadata only — no recordings stored) | 12 months | Operational need and dispute resolution; deleted thereafter |
| System and application logs | 6–12 months | Security monitoring |
| Security incident and audit logs | 5 years | Legal defence and regulatory compliance |
| Consent records | Duration of relationship + 5 years | Proof of lawful basis for processing |
When retention periods expire, data is securely deleted or irreversibly anonymised. You may request earlier deletion — see Section 8.
Under the UAE PDPL (and GDPR where applicable), you have the following rights regarding your personal data:
| Right | What it means | How to exercise |
|---|---|---|
| Access | Obtain a copy of the personal data we hold about you | Email privacy@curiousstack.co |
| Rectification | Correct inaccurate or incomplete data | Via the chatbot or email |
| Erasure | Request deletion of your personal data | Email privacy@curiousstack.co |
| Portability | Receive your data in a structured, machine-readable format | Email privacy@curiousstack.co |
| Withdraw consent | Stop receiving WhatsApp communications and/or voice call reminders | Reply STOP to any WhatsApp message; or email privacy@curiousstack.co to opt out of voice calls specifically |
| Objection | Object to processing based on legitimate interests | Email privacy@curiousstack.co |
| Restriction | Restrict processing of your data pending a dispute | Email privacy@curiousstack.co |
We will respond to all valid requests within 30 days. Erasure requests may be subject to legal retention obligations (e.g. health records required to be retained under UAE law).
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure:
The Rendevy WhatsApp chatbot does not use cookies.
The Rendevy admin web panel uses the following cookies:
We do not use third-party tracking, advertising, or analytics cookies on the admin panel.
We have designated a Data Protection Officer (DPO) responsible for overseeing our data protection strategy and compliance with the UAE PDPL and applicable regulations.
DPO Contact: privacy@curiousstack.co
You may contact the DPO with any questions about how your personal data is processed, or to exercise your data subject rights.
If you are not satisfied with how we handle your personal data or respond to your rights request, you have the right to lodge a complaint with the UAE Data Office:
UAE Data Office
Website: www.uaedataoffice.gov.ae
If you are located in the European Union, you may also contact your local EU data protection supervisory authority.
We may update this Privacy Policy from time to time. When we make material changes, we will:
Continued use of the service after the effective date of any changes constitutes acceptance of the updated policy.
Version history: v1.0 — April 2026 (initial publication)
For any privacy-related questions, requests, or concerns:
Email: privacy@curiousstack.co
Subject line: Privacy Request — [your name or phone last 4 digits]
We aim to acknowledge all requests within 2 business days and resolve them within 30 days.