HelloGrowthCRM is a sales CRM built by Soor LLC. If you sell to customers in the United Arab Emirates, Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data applies to the contact records and notes you keep. This page explains what the law covers, where the implementing detail still stands open, and which controls the platform provides. It is aimed at procurement and security reviewers. It is not legal advice, and UAE counsel should confirm your position before you rely on any of it.
The PDPL is the UAE's federal data protection law. It applies to data subjects inside the UAE, to controllers and processors established in the UAE that process personal data whether inside or outside the country, and to controllers and processors based outside the UAE that process the personal data of people inside it. For a sales CRM, that means contact records for UAE-based prospects and customers can be in scope even when your company sits elsewhere. The financial and healthcare free zones keep their own regimes: the DIFC has its own data protection law and commissioner, the ADGM has its own regulations, and Dubai Healthcare City operates separately again.
The law defines personal data broadly and treats a subset as sensitive, including health, biometric and genetic data, racial origin, religious belief, political opinion and criminal records. Processing generally requires the data subject's consent, subject to a list of exceptions covering contract performance, legal obligations, protection of the public interest, legal claims, employment duties and similar grounds. Controllers must apply purpose limitation, data minimisation, accuracy and security. Consent must be clear, specific and capable of being withdrawn. In CRM terms, that pushes you towards recording a basis for each record rather than treating a whole imported database as consented by default.
One practical point for sales teams: the PDPL is a data protection law, not a marketing law. Electronic marketing to UAE numbers and inboxes also touches telecommunications rules and, in some sectors, additional regulator expectations. Treat consent to hold a contact record and consent to market to that contact as two separate fields in the CRM. Teams routinely conflate the two and then cannot answer a simple question when somebody objects. Two tick boxes and a source field captured at import time save a great deal of reconstruction later on.
The PDPL was issued in 2021 and was expected to be followed by Executive Regulations setting out operational detail: transfer mechanisms, breach procedures, Data Protection Officer thresholds, registration and enforcement. Those regulations have taken considerably longer than the original timetable envisaged, and the detailed implementing framework has continued to be described as forthcoming rather than final. That is not a reason to ignore the law. The substantive obligations in the decree-law stand, and the UAE Data Office is established as the federal supervisory body. It does mean specific procedural answers remain open, and this position is still developing.
Because of that, verify the current status against the Official Gazette or your UAE counsel before relying on a particular date, cabinet decision number or transition period. Organisations are generally expected to receive a compliance window once regulations are published. Our advice to buyers is to build the practices now, because a lawful basis record, a rights-handling process, a subprocessor register and a documented transfer assessment will not become less necessary when the detail lands. HelloGrowthCRM makes no claim to be PDPL certified. There is no certification scheme under the PDPL, and the phrase would carry no meaning if there were one.
Free zone entities should check which law actually binds them before applying federal analysis by default. A company registered in the DIFC follows the DIFC data protection law, with its own registration, transfer and breach rules and its own commissioner. An ADGM entity follows ADGM regulations. A mainland company follows the federal PDPL. Groups spanning both often standardise CRM handling on the strictest applicable standard, simply to avoid running two sets of practices over one contact list. That decision is much easier to make at procurement than after the data is already loaded.
The PDPL gives data subjects a recognisable set of rights: to receive information about processing, to access their data and obtain a copy, to request portability in a structured machine-readable format, to have inaccurate data corrected and unlawfully processed data erased, to restrict or stop processing in defined circumstances, and to object to automated processing including profiling where it produces legal effects. A CRM is frequently where these requests actually land, because it holds the contact record, the email history and the notes. The system therefore needs to make retrieval and deletion straightforward rather than a bespoke engineering exercise.
Handling requests well is mostly operational. You need to find every record about a person, decide what is genuinely theirs, produce it in a usable format and act on the result. HelloGrowthCRM supports that directly: administrators can search and export account data at any time without raising a ticket, and deletion requests are honoured. The documented process is published at /legal/data-rights. Our practices also align with India's DPDPA, and customers in the EU, UK and California have equivalent rights, so a single set of tooling and process serves several regimes rather than one jurisdiction at a time.
Two decisions are worth making before a request arrives. First, who owns a rights request that reaches a sales representative's inbox rather than a privacy address. Set a route and train the team, because the clock does not wait for the message to find the right desk. Second, what you do with free-text notes. Call notes and meeting summaries often contain opinions about a person that remain personal data. Decide whether they fall inside your access responses, write the policy down, and then apply it the same way every single time.
The PDPL restricts transfers of personal data outside the UAE. Broadly, transfers are permitted to jurisdictions recognised as providing an adequate level of protection, or where appropriate safeguards such as binding contractual commitments are in place, with further exceptions including the data subject's explicit consent, necessity for performance of a contract, international judicial cooperation and protection of the public interest. The list of adequate jurisdictions and the approved form of contractual clauses are among the details expected from the implementing framework, which is why UAE transfer assessments currently rest heavily on contract terms and documented reasoning.
Sector rules can bite harder than the general law. Health data is subject to separate federal requirements that restrict storage and transfer outside the UAE, and parts of the financial sector carry their own regulator expectations about where records sit. If your CRM will hold health-related or regulated-sector records, resolve that question before signing rather than during implementation. For everything else, what a reviewer needs from a vendor is the same anywhere: who processes the data, under what contract, with which subprocessors, and in which region the systems actually run.
HelloGrowthCRM runs on Supabase-managed Postgres hosted on AWS. The region that applies to your account is confirmed during onboarding or a security review, so ask for it in writing and record the answer in your transfer file. The subprocessor list at /subprocessors shows the third parties involved in running the service, and a Data Processing Agreement is available covering processing instructions, confidentiality, security and assistance with data subject requests. Region confirmation, subprocessor list and DPA are usually the three documents a UAE transfer assessment needs in order to be complete.
The PDPL requires controllers and processors to apply appropriate technical and organisational measures and to assess risk where processing is likely to be high risk. HelloGrowthCRM protects data in transit with TLS and encrypts data at rest. Tenant isolation is enforced by row-level security inside Supabase-managed Postgres rather than by application filtering alone, so records belonging to one account are not reachable from another. Role-based access control governs what your own users can see and do. Production access on our side is least-privilege, multi-factor gated, logged and reviewed periodically, so administrative reach is bounded and evidenced.
For independent assurance, Soor LLC completed a SOC 2 Type II examination covering a February to June 2025 observation window. The report is available under NDA from sales@hellogrowthcrm.com, and it is the right artefact to request during due diligence because it describes tested controls rather than asserting a status. Soor LLC holds ISO 27001 certification; the certificate scope and registrar details are {{ISO27001_SCOPE_TBC}}, available on request from sales@hellogrowthcrm.com. We make no claim to PCI DSS. If your questionnaire asks about either, the honest answer is that we do not hold them, and the SOC 2 Type II report is what we offer in their place. Precision here beats an unbroken run of yes answers.
On resilience and incidents, automated backups run with point-in-time recovery and a documented incident-response workflow covers detection, containment and customer notification. The PDPL requires controllers to notify the UAE Data Office of breaches that would prejudice the privacy, confidentiality or security of personal data, and to inform affected data subjects where relevant, with much of the procedural detail expected from the implementing regulations. Define your internal escalation path now, so that a notification from us reaches the person who has to act on it, rather than landing in a shared inbox that nobody has owned since the person who set it up left.
Write to sales@hellogrowthcrm.com for the SOC 2 Type II report under NDA, the Data Processing Agreement and written confirmation of the hosting region for your account. The subprocessor list is at /subprocessors and the data rights process is at /legal/data-rights. Bring your UAE counsel's questions to the security review and we will answer them in writing.