The short version
This site sets no cookies of its own for analytics or advertising. There is no Google Analytics, no Tag Manager, no Meta pixel, no chat widget, and no advertising tag anywhere on it.
There are three exceptions. The Instagram section on the home page uses Instagram's own embed code. That code loads a script from Instagram automatically, a moment after the page finishes loading, without asking you first. When it loads, Instagram sets third-party cookies on your device, and Meta receives your IP address and the address of the page you were on. Both pages carrying an enquiry form — the home page and the contact page — load Cloudflare Turnstile, a bot-check widget. It is never requested on any other page, and it may set its own short-lived cookie while it checks you are not a bot. The smallest exception is Cloudflare's own network, which may set its own short-lived security cookies — see the section below.
That is the whole picture. The rest of this page explains it properly.
Who is responsible for this site
This notice does not yet identify a controller, which is a gap that needs to close before launch:
Pending · operator input
The operator's legal or trading name.
Pending · operator input
The address at which the operator can be contacted in writing.
Pending · operator input
A working email address for privacy and cookie questions.
Pending · operator input
Whether the operator trades as a licensed entity or as an individual, since this determines which legal person is the controller. No licence, RERA number, employer or credential may be asserted until confirmed.
The site publishes a name — in the footer copyright and in the page metadata — and a WhatsApp number. It does not publish a legal or trading identity, a postal address, or an email address, and a name on its own neither identifies a controller nor gives you a route to exercise a right.
What this site sets by itself
Nothing that tracks you.
The site is a static export. It is served from Cloudflare's network, which acts as the content delivery network and handles security for the domain. As part of delivering the page, Cloudflare processes connection metadata for every visitor: your IP address, your browser's user agent string, and the time of the request. This is how any website on the internet works — a server cannot send you a page without knowing where to send it — but it is processing, and you should know it happens.
Depending on how Cloudflare's security features are configured for this domain, Cloudflare's network may set a short-lived cookie for bot detection or to record that you passed a security challenge. Which of those cookies, if any, are set here has not yet been confirmed — see the note below. Any such cookie is set by Cloudflare for delivery and security, not by this site for marketing, and none is shared with the operator.
Pending · operator input
Confirmation from the Cloudflare dashboard of exactly which Cloudflare security cookies are set on this domain, so they can be named here rather than described in general terms.
Beyond that, the site's own code stores nothing on your device. It does not use local storage or session storage. It sets no preference cookie, no analytics identifier and no advertising identifier. The fonts are hosted on this site's own domain, so loading a page sends no request to Google Fonts or any other font service.
The Instagram embed, in detail
This is the part of the page that has real privacy consequences, so here it is in full.
What it is. The home page has a section showing recent Instagram posts. Rather than copying images across, it uses Instagram's official embed: each post starts as a block of markup on the page, and a script from Instagram replaces it with a live post.
When it loads. The script is requested from https://www.instagram.com/embed.js automatically, shortly after the rest of the page has finished loading. It is deliberately delayed so it does not slow down the page. It is not delayed until you click, and it does not wait for your permission. If you land on the home page and stay there, it loads.
What happens then. Your browser makes a request to Instagram's servers, which are operated by Meta. That request carries your IP address, your user agent, and the address of the page you were on. Each post is then rendered inside an iframe served by Instagram, which makes further requests of its own. Instagram sets third-party cookies through these requests. If you are signed in to Instagram or Facebook in the same browser, Meta can associate that visit with your account.
Who receives what. Meta receives the data described above, as an independent controller. It decides what it does with it under its own policies, and the operator of this site has no access to it, no control over it, and no ability to delete it. What Meta collects through embedded content, and your choices about it, are governed by Meta's own privacy and cookie policies.
What is sent to the site owner. Nothing. The embed does not report back to this site. Nobody here can see which posts you looked at.
If Instagram's script does not load — because you block it, or because it fails — each tile falls back to a plain text link to the post on Instagram. Nothing is set, and nothing is sent to Meta, unless you follow that link.
Cloudflare Turnstile, wherever the form appears
Turnstile runs on the form — both of them, the short one on the home page and the fuller one on the contact page — before either will send. Turnstile checks browser and connection signals to tell a person from a script, rather than making you solve a puzzle or pick out traffic lights.
It loads only on the contact page — no other page on the site requests it — and only once you open that page, not on every visit to the site. Running the check may set a short-lived Cloudflare cookie to record that it has run.
Cloudflare operates Turnstile as part of the same network already described above, under the same data processing addendum. It is not used to profile you or to serve you anything; it exists to stop the form being flooded by automated submissions.
What this site does not do
- No analytics of any kind, first-party or third-party.
- No advertising or remarketing tags, and no Meta pixel.
- No chat widget, no A/B testing tool, no session recording, no heatmaps.
- No visitor accounts and no login.
- No payment processing.
- No device storage for the enquiry form. There is one — a short version on the home page, a fuller one on the contact page — and what you type stays in the page's memory until you send it: no cookie, no local storage, nothing kept for a later visit. The form is screened by Cloudflare Turnstile, which is part of Cloudflare's network, so any short-lived storage that check uses belongs to the Cloudflare section above, including the gap flagged there. What the form collects and where it is sent is in the privacy notice, not here. The two calculators are different again: they compute entirely in your browser and send nothing anywhere.
The law we are applying
There is no cookie-specific statute in the UAE. That is a genuine gap in the law, not an oversight in this notice, and anyone who tells you otherwise is guessing.
What does apply is Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the PDPL), in force since 2 January 2022. It applies to the processing of personal data of people residing or working in the UAE regardless of where the person doing the processing is based. Cookie identifiers and IP addresses are personal data when they can be linked back to a person.
The defensible reading, and the one this site works to, is that the PDPL's consent standard governs non-essential cookies. Under Article 6 that means consent has to be capable of being proven, and it has to be obtained in a clear, simple, unambiguous and accessible way, with a plain explanation of how to withdraw it. Withdrawing consent does not make earlier processing unlawful, but it has to stop the processing from that point.
Three things that are not consent, under that standard: carrying on scrolling, ignoring a banner, and a pre-ticked box.
Judged against that, the Instagram embed as it currently loads does not meet the standard, because it loads before you have been asked. This notice says so rather than pretending otherwise. The fix is to hold the embed until you ask for it, and that change is outstanding.
Pending · operator input
A decision on whether to gate the Instagram embed behind a click-to-load consent step, and if a consent banner is used, who supplies it and how consent records are stored so they can be proven under PDPL Article 6.
Two further points of context. The PDPL's Executive Regulations have not been published, and the UAE Data Office is not yet established, so some of the detail of how these rules will be enforced is still to come. And the free zones — DIFC and ADGM — run their own data protection regimes, which are not what this notice describes.
If you are in the EU or the EEA
The EU and EEA rules apply to you separately and on their own terms, and complying with UAE law does not satisfy them.
Under the ePrivacy rules, storing or reading information on your device requires your prior consent unless it is strictly necessary to provide the service you asked for. If Cloudflare security cookies are set, they are the kind capable of meeting the strictly-necessary test. The Instagram embed is not: it is third-party content that sets cookies and discloses your IP address to Meta, and under those rules it needs your consent before it loads.
That consent is not currently being collected. Until it is, an EU or EEA visitor who does not want Meta to receive their IP address should block third-party cookies or block instagram.com before visiting the home page. The section below explains how.
The GDPR applies alongside this, and the privacy notice sets out the rights it gives you, together with the equivalent rights under the PDPL.
Changes to this notice
If the Instagram embed changes to load only when you ask it to, or if any other third-party technology is introduced, this notice will be updated and the date at the top will change. Material changes will be described here rather than made quietly.
Questions
Once a contact email address and a postal address are published (see "Who is responsible for this site"), send privacy and cookie questions there.
Requests about the data Meta collects through the Instagram embed need to go to Meta, since the operator of this site holds none of it.
End of cookie notice. 6 clauses awaiting an operator.
