Skip to content
MicellaالعربيةRequest a quoteGet a quote
Legal

Privacy Policy

How Micella Sourcing Consultant Limited collects, uses, and protects personal data, in accordance with the DIFC Data Protection Law 2020.

Last updated: 13 September 2026Jurisdiction: DIFC, Dubaiprivacy@micella.ae
Plain-language summary

Micella is a B2B sourcing company. We only hold business contact details (name, email, phone) of company representatives. We do not sell your data or use it for marketing. Most of what we hold stays in the DIFC and the UAE, and the few services that see data outside it are named below. Email privacy@micella.ae at any time to ask what we hold or request deletion.

Who We Are›

Micella Sourcing Consultant Limited ("Micella", "we", "us") is a DIFC-registered sourcing and trading company headquartered at Innovation One Building, Dubai International Financial Centre, Dubai, UAE (DIFC License #12352).

We act as the Data Controller for all personal data we collect and process. This means we determine how and why personal data is used. Our privacy contact is: privacy@micella.ae.

What Personal Data We Collect›

We process a minimal set of personal data, limited to what is necessary for our business operations. This consists of:

  • Business contact details of company representatives: name, business email address, and phone number
  • Company name and shipping/delivery address (where relevant for order fulfilment)
  • Communications you send us: the content of your enquiries and, if you contact us by phone or WhatsApp, your phone number and WhatsApp profile name
  • Quote requests submitted through the form on our contact page: the company, market, product, volume, email address and message you enter
  • Technical data attached to a quote request: your IP address, an approximate location derived from it, your browser and device identification string, your browser language setting, the page the request was sent from and the page you arrived from

We do not collect sensitive personal data (special categories), and we do not process data relating to children. We use no profiling and no automated decision-making that produces legal or similarly significant effects. The one automated assessment we run is the bot check described under Cookies and Website Technologies, which decides only whether a form submission is accepted; anyone it turns away can reach us by email, phone or WhatsApp instead.

Why We Process Your Data & Legal Basis›

Responding to enquiries. When you contact us about our products or services, we use your contact details to respond. Legal basis: Legitimate Interests (Article 13, DIFC DP Law 2020).

Supplier & customer relationship management. We maintain contact information to manage ongoing business relationships, issue quotes, and fulfil orders. Legal basis: Legitimate Interests and Contractual Necessity.

Website security and abuse prevention. We check that quote requests come from a person rather than an automated script, and we record the technical data listed above so that a submission can be traced if it is fraudulent or abusive. Legal basis: Legitimate Interests (Article 13, DIFC DP Law 2020).

Legal compliance. We may retain records as required by applicable UAE and DIFC commercial law (typically 7 years for commercial documents). Legal basis: Legal Obligation.

Data subject rights management. We process requests submitted to privacy@micella.ae to fulfil your rights under the DIFC DP Law 2020. Legal basis: Legal Obligation.

Who We Share Your Data With›

We do not sell or rent personal data. We share data only where strictly necessary:

  • Logistics and shipping agents receive name and delivery address for the purpose of order fulfilment only
  • The DIFC Commissioner's Office, if required by law (e.g. breach notification)
  • Meta Platforms, Inc. (WhatsApp): if you choose to contact us via WhatsApp, your phone number, WhatsApp profile name and message content are processed by Meta in order to deliver that conversation
  • Microsoft: this website is hosted on Microsoft Azure, and quote requests are delivered to us by Azure Communication Services. The mail service is provisioned with a United Arab Emirates data location
  • Cloudflare, Inc.: our bot check, Cloudflare Turnstile, receives your IP address and browser characteristics in order to judge whether a form submission is automated
  • ipapi.co: when a quote request arrives, we send the submitting IP address to this geolocation service to resolve an approximate city and network operator. No other field from your enquiry is sent
  • Google: the video on our home page is served from youtube-nocookie.com and its preview image from Google servers, so loading a page that carries it discloses your IP address to Google

International transfers. We keep personal data within the DIFC and the UAE wherever possible, and our enquiry mailbox and the mail service that feeds it are provisioned accordingly. Three things fall outside that.

First, WhatsApp. If you choose to message us there, your data is transmitted to and processed by Meta on infrastructure outside the DIFC, including the United States and other countries where Meta operates. This transfer happens only because you have chosen to initiate contact through that channel; we rely on the derogations in Article 27 of the DIFC DP Law 2020, as a transfer necessary for pre-contractual communication taken at your request and made with your informed choice of channel. Meta processes this data under its own terms and privacy policy, which we do not control.

Second, the bot check and the geolocation lookup that run when you submit the quote form. Your IP address and browser characteristics reach Cloudflare, and your IP address alone reaches ipapi.co, both on infrastructure outside the DIFC. We rely on Article 27 for the same reason: you are contacting us to begin a commercial discussion, and these checks are how we accept that contact safely.

Third, the home page video. Its preview image and, if you play it, the player itself are served by Google, which sees your IP address. The player is loaded from youtube-nocookie.com and only after you click it.

If you would prefer that none of your personal data leaves the DIFC, contact us by email, phone or post rather than through WhatsApp or the quote form.

Cookies and Website Technologies›

This website sets no analytics, advertising or tracking cookies, and we run no visitor analytics of any kind. We do not know who reads these pages unless you write to us.

Bot protection. The quote form is protected by Cloudflare Turnstile, which checks that a submission comes from a person rather than a script. It runs without asking you to do anything, and to do so it receives your IP address and characteristics of your browser, and may store a short-lived token in your browser to remember that a check has passed. Cloudflare acts as our processor for this. If the check cannot run, the form will not submit, and the page offers you an email link instead.

Geolocation. When a quote request reaches us, we resolve the submitting IP address to an approximate city and network operator so that we can tell a genuine buyer from an automated or fraudulent submission. That lookup is a request to ipapi.co carrying the IP address and nothing else. It is not used to build a profile, it is not stored separately from the enquiry email, and if it fails the enquiry still reaches us.

Video. The Sargam advertisement on our home page is embedded from youtube-nocookie.com and loads only when you click to play it. Its preview image is fetched from Google when the page loads, which discloses your IP address to Google even if you never press play.

How Long We Keep Your Data›

We retain personal data only as long as necessary:

  • Enquiry and correspondence records (email, phone and WhatsApp): 3 years from last contact
  • Quote requests submitted through the website, including the technical data attached to them: 3 years from last contact, held inside the enquiry email itself
  • Security and delivery logs held by our hosting and bot-protection providers: retained by them on their own schedules, which we do not control
  • Supplier and customer relationship data: duration of relationship plus 5 years
  • Signed contracts and commercial documents: 7 years (UAE commercial law)
  • Data subject rights requests: 3 years from resolution
  • Breach incident records (if any): 5 years from incident date

After the applicable retention period, data is securely deleted.

Your Rights›

Under the DIFC Data Protection Law 2020 (Parts 5 and 6), you have the right to:

  • Access · request a copy of the personal data we hold about you
  • Rectification · ask us to correct inaccurate or incomplete data
  • Erasure · request deletion where there is no lawful reason to retain it
  • Restriction · ask us to limit how we process your data
  • Objection · object to processing based on legitimate interests
  • Portability · receive your data in a structured, machine-readable format

To exercise any of these rights, contact us at privacy@micella.ae or by writing to our registered address. We will respond within 30 days. There is no charge for reasonable requests.

If you are unsatisfied with our response, you have the right to lodge a complaint with the DIFC Commissioner's Office (commissioner.office@difc.ae).

Security›

We take reasonable and appropriate measures to protect personal data against unauthorised access, loss, or disclosure. Our measures include:

  • Microsoft 365 enterprise-grade email security for all communications
  • Access restricted to Micella principals only
  • Password-protected accounts with multi-factor authentication where available
  • The website served over HTTPS behind Azure Front Door with a web application firewall, and quote requests handled by a function inside our own Azure tenancy rather than a third-party form service
  • The mail service that delivers quote requests provisioned with a United Arab Emirates data location, and authorised to send only from micella.ae
  • SPF, DKIM and DMARC published for micella.ae, so that mail claiming to come from us can be checked by the receiving server

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the DIFC Commissioner's Office within 72 hours and, where required, notify affected individuals directly.

Contact & Updates›

For any privacy-related queries, requests, or concerns:

Email: privacy@micella.ae
Phone / WhatsApp: +971 50 628 1708
Post: Micella Sourcing Consultant Limited, Innovation One Building, Dubai International Financial Centre, Dubai, UAE

This policy was last updated on 13 September 2026. We review it annually and will update this page if our processing activities change materially. We encourage you to check back periodically.

Micella Sourcing Consultant Limited is registered in the Dubai International Financial Centre (DIFC License #12352) and operates under the DIFC Data Protection Law 2020. Complaints may be directed to the DIFC Commissioner's Office at commissioner.office@difc.ae.