Data Privacy

Collection and processing of personal data

1. Data Protection at ista

ista Middle East W.L.L, a company registered in the Kingdom of Bahrain with company number 181907-1 whose registered office is at Sovereign Business Hub WLL 12th Floor YBA Kanoo Tower, Diplomatic Area, P.O. Box 60202, Manama, Kingdom of Bahrain, and email address infome@ista.com (“ista”, “us”, “we”, or “our), is the owner and operator of the www.ista.bh website (the "Website").

This page informs you and the other users of the Website (hereinafter referred to as the “User”, “Users”, “you”, “your”, or “yours”) of our policies regarding the collection, use, and disclosure of personal data when you use our Website, or when you use ista’s services, and the choices you have associated with that data.

By using the Website or using our services (Billing or Metering, etc.), submitting your data and accepting our terms and conditions, you agree to the collection and processing of your data in accordance with this policy. Unless otherwise defined in this Privacy Policy (the “Privacy Policy”), the terms used in this Privacy Policy have the same meanings as in our Terms and Conditions.

The protection of your personal data is very important to ista.

ista complies with the legal data protection regulations and does everything to keep your data (whether you be a landlord, or a customer/tenant, or a user of the ista Website in any other capacity) and your customer’s/tenant‘s data (if applicable) confidential. All personal data is collected, processed and used in accordance with the provisions of the Bahrain Law no. 30 of 2018 on Personal Data Protection Law (the “PDPL”) and its Implementing Regulations, and the Ministerial Resolutions issued by the Ministry of Justice Islamic Affairs and Waqf of Bahrain, as amended from time to time, and the European Union’s General Data Protection Regulation (the “GDPR”) and only for the purposes of contract processing, fulfilment of our legal obligations, and/or for improving our advice and support of the customers as well as the demand-oriented product design. By submitting your Information and accepting our terms and conditions, you specifically agree to our processing of your personal data for the herein mentioned purposes.

All service providers of ista dealing with the processing of personal data also comply with the provisions of the GDPR in accordance with Art. 28 GDPR, and Section 2 of the PDPL on general rules for legitimate processing, and Order No. 45 of 2022 regarding the rules and procedures for processing sensitive personal data. Compliance is monitored by our data protection officer.

2. Collection and processing of personal data

Each time a user accesses the ista Website and each time a file is accessed, data about that activity is stored in a log file. This data is not related to a person; so ista cannot trace back which user has retrieved what data.

In detail, the following data record is saved for each call:

• Name of the file

• Date and time of access

• Amount of data transferred

• Message whether the call was successful

• Anonymous IP-Address

• If necessary, operating system and browser software on your computer

• As well as the website from which you visited the ista Website

Personal user profiles cannot be created.

The above-mentioned data is evaluated for statistical purposes only.

Personal data will only be collected if you give it to ista on your own - for example, when registering for a survey or conducting a contract with ista. A transmission of your data to third parties does not take place, unless ista is legally obliged to do so under the PDPL and in compliance with Order No. 42 of 2022. Insofar as external service providers come into contact with your personal data, ista has ensured that they comply with the provisions of the GDPR and PDPL through legal, technical and organizational measures as well as regular checks.

The transfer of your personal data, within ista group, will be carried out in accordance with the Law and Order No. 42 of 2022. Pursuant to these regulations, such transfers are permitted where the receiving country ensures an adequate level of data protection. For the purposes of this Privacy Policy, it is acknowledged that the Federal Republic of Germany, the United Kingdom and the United Arab Emirates are jurisdictions recognized by Bahrain as providing appropriate safeguards for the protection of personal data. Therefore, your data may be transferred to these countries where necessary.

Should you have entered into a billing or metering services agreement with ista, you hereby covenant and undertake:

- to provide ista in good time the personal data and all the information and documentation relevant to the billing or metering services; and

- to promptly bring to ista’s attention any change in your personal data or any matter which may affect ista’s ability to perform the billing/metering services object of this agreement.

Should you have entered into a billing or metering services agreement with ista, you hereby warrant to ista that:

- the data shared with ista is true, complete, accurate, up to date and free of any errors and is in sufficient order to enable ista to provide the billing/metering services; and

- the use by ista of any of your data in accordance with the billing or metering services agreement shall not infringe the Intellectual Property Rights or any other right of a third party

3. Cookies:

ista uses so-called cookies on the ista Website to recognize multiple use of the offer by the same user/internet connection owner. Cookies are small text files that your internet browser stores on your computer. They serve to optimize ista's internet presence and offers. The cookies are usually so-called "session cookies", which are deleted after the end of your visit.

In some cases, however, these cookies provide information in order to automatically recognize you. This recognition is based on the IP address stored in the cookies. The information obtained in this way serves to optimize ista's offers and to make it easier for you to access the ista Website.

You may refuse the use of cookies by selecting the appropriate settings in your browser; however, ista points out that in this case you may not be able to use the full functionality of the ista Website.

The cookies used on the ista website are classified into different categories:

a. Strictly necessary cookies (mandatory)

These cookies are essential for the ista Website to function properly. They may include, for example, cookies which collect session ID and authentication data, cookies that make it possible to personalize the interface of the ista Website (for example, for the choice of the language or presentation of a service) or some audience measurement and/or certain analytics cookies. This category also includes cookies that allow us to comply with our legal obligations, including ensuring a safe online environment (for example by detecting repeated login failures in order to prevent unauthorized persons from accessing your account).

 

b. Web Analytics (subject to your consent, except in some circumstances)

This Website uses Matomo, an open source software for the statistical evaluation of user access. Matomo uses "cookies", which are text files that are stored on your computer and serve to analyse the use of the Website or Website optimization. For this purpose, the usage information generated by the cookie is transmitted to the server of ista. The IP address is anonymized immediately after processing and prior to its storage. The information generated by the cookie about your use of this Website will not be disclosed to third parties.

These cookies may be exempt from consent when they are strictly necessary for the functioning of the Website in accordance with the precedent paragraph (a).

Otherwise, they are subject to consent in accordance with the present paragraph.

c. Google Tag Manager (mandatory)

Google Tag Manager is a solution that we can use to manage “website tags” using an interface (allowing us, for example, to incorporate Google Analytics and other Google marketing services into our online offering). The tag manager itself (which implements the tags) does not process any personal data relating to users. With regard to the processing of users' personal data, we refer users to the following information on the Google services. Use policy: www.google.com/intl/de/tagmanager/use-policy.html

d. Remarketing activities and cookies (subject to your consent)

This Website uses the remarketing or "similar target group" function of Google Inc. (1Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; „Google“).

This feature allows you to view interest-based ads on Google Display Network web pages. For this purpose, a cookie is stored in your browser when you visit a website. This serves to recognize you as a visitor to the Website and to determine visits and usage data.

According to Google's own information, server logs are stored in which parts of the IP address and cookie information are partially deleted after 9 to 18 months. For more information, please visit www.google.com/policies/technologies/ads/.

An example of a server log is provided by Google at the following link: policies.google.com/privacy/key-terms

 

4. How can you manage cookies?

To see the different categories of cookies that we use on the Platform and configure your choices, you can consult the cookie management module accessible at the top & the bottom of the page. You can modify at any time your preferences, withdraw or give again your consent at any time.

Please note that the use of strictly necessary cookies for the proper functioning of the ista Website does not require your consent. This is why the option "strictly necessary cookies" is pre-checked in our cookie management tool and is not optional.

By refusing certain types of cookies (preference cookies for example), we will not be able to optimize your user experience on our Website and some parts may not function properly.

By default, we save your cookie choices on a device for a maximum of 13 months. If you change your mind about the preferences you have expressed regarding cookies, you can update your choices at any time, by following this link. We will ask you to make a choice again every 6 months.

https://www.google.com/settings/ads/plugin

Furthermore, there are several ways in which cookies can be deactivated in the browser to exclude your own browser from remarketing.

Google provides the option of downloading a browser plug-in that permanently deactivates these cookies under the following link: www.google.com/settings/ads/plugin

You can also make settings in your browser to deactivate the installation of cookies.

If you wish to object to tracking, you can do so by adjusting your browser settings regarding cookie installations. You can find information on this under the following links: Firefox: support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences Internet Explorer: support.microsoft.com/en-gb/help/17442/windows-internet-explorer-delete-manage-cookies Chrome: support.google.com/chrome/answer/95647 Safari: support.apple.com/en-gb/HT201265

Third-party providers may also disable browser cookies. The Network Advertising Initiative (NAI) offers the possibility to implement an opt-out for your own browser. Information can be found on the following page: optout.networkadvertising.org.

 

This Website uses the conversion tracking of "Google-Adwords", a Google service.

When you visit Google pages, Google stores cookies. You can deactivate or leave this storage activated. If the cookie is still activated and you visit certain websites on the Website, Google and ista can recognize that you have clicked on an ad placed by ista and have thus been forwarded to an ista page.

The information collected is used by Google to generate statistics for Adwords customers. These statistics include information about the number of users who clicked on ads and were redirected to pages that were tagged with a conversion tracking tag. You can find Google's privacy policy here: policies.google.com/privacy

This function can be deactivated here.

 

5. Googlemaps and Google Address Autocomplete

Several contact and order forms are available for contacting ista. In this context, ista asks for your address for processing the request. To support address entry, ista uses the Google Address Autocomplete function from Google.

6. Usercentrics

Use of the Usercentrics Consent Management Platform

We use the Usercentrics Consent Management Platform to comply with the statutory provision pursuant to Article 7, para. 1 GDPR, and articles 4 and 5 of the PDPL and Order No. 45 of 2022. The operator is Usercentrics GmbH, Rosental 4, 80331 Munich.

 

The Usercentrics Consent Management Platform collects Logfile data, user agent (device, browser type, browser language, browser version, resolution) and consent data (consent yes/no, timestamp, data extent, data attributes, ControllerID, ProcessorID, consentID) by means of a Javascript. This JavaScript permits Usercentrics GmbH to inform the user about specific tags and web technologies on our Website and to obtain, manage and document the user’s consent.

 

The legal basis for data processing is Article 6, para. 1, letter c) GDPR, and Article 5, para. 1 PDPL and Order No. 45 of 2022, since we are legally obliged to prove consent (pursuant to Article 7, para 1 GDPR and articles 4 and 5 of the PDPL and Order No. 45 of 2022). Our aim is to know and implement our users' preferences as well as to document these legally in a secure manner. The data are deleted as soon as they are no longer required for our documentation and there are no legal obligations to retain records.

 

You can permanently disable the execution of JavaScript at any time by selecting the relevant settings in your browser, which would also prevent Usercentrics from executing JavaScript.

For further details on Usercentrics data protection policy go to: usercentrics.com/privacy-policy/

 

Change now

7. Piwik Pro Analytics Suite

We use the analysis software Piwik PRO Analytics Suite (piwikpro.de) to analyse and optimise this Website. The data collected with this software can be used to create user profiles under a pseudonym. You specifically consent to the processing of your below indicated personal data for the below indicated purposes.

Data processing purposes

This list contains the purposes for which data are collected and processed. Consent is valid only for the purposes specified. The data collected cannot be used or stored for purposes other than those listed below.

· Analysis

· Optimisation

Technologies used

· Cookies

Data collected

This list contains all (personal) data that are collected during or through the use of the service.

· Anonymised shortened IP address

· Usage data

· User ID

· Date and time of the visit

· Referrer URL

· Websites visited

· Screen resolution

· Geographic location

· User agent

· Visitor ID

Legal basis

The required legal basis for the processing of data is listed in the following:

· Art. 6, para. 1 s. 1 lit. a GDPR

· Article 4 of the PDPL

Location of processing

· European Union

· Kingdom of Bahrain

Retention period

The retention period is the period of time during which the data collected are stored for processing. The data must be deleted as soon as they are no longer needed for the stated

processing purposes. The data are stored for up to 25 months.

Data recipient

· Piwik PRO Sp. z o.o.

· Piwik PRO GmbH

Data protection officer of the processing company

Below you will find the email address of the data protection officer of the processing company. gdpr@piwik.pro

Consent to the collection and storage of data can be withdrawn at any time with immediate future effect. Click here to read the privacy policy of the data processor piwik.pro/privacy-policy/

Click here to withdraw consent on all domains of the data processing company piwik.pro/opt-out/

 

8. Rights of data subjects

In accordance with the GDPR and the PDPL, ista takes appropriate measures to provide the data subject with all information and communications relating to processing in a precise, transparent, comprehensible and easily accessible form in clear and simple language. The information shall be transmitted in writing or in any other form, including, where appropriate, electronically.

Since ista processes personal data automatically, ista informs you of the following information in accordance with Art. 13 GDPR:

ista Middle East W.L.L,

Sovereign Business Hub WLL 12th Floor YBA Kanoo Tower, Diplomatic Area, P.O. Box 60202, Manama, Kingdom of Bahrain

 

Responsible for content: Oliver Sporrer

The contact details of ista's data protection officer are:

Dhanraj Attarade Tel: +971 4 454 1212

 

ista Middle East W.L.L,

Sovereign Business Hub WLL 12th Floor YBA Kanoo Tower, Diplomatic Area, P.O. Box 60202, Manama, Kingdom of Bahrain

 

The purpose for which the personal data is to be processed and the legal basis for the processing are as follows: contract processing, fulfilment of our legal obligations, and/or

for improving our advice and support of the customers as well as the demand-oriented product design, and the Website.

9. Data deletion and duration of storage

The personal data of the data subjects will be deleted or blocked as soon as the purpose of storage ceases to apply. Furthermore, data may be stored if this has been provided for the Kingdom of Bahrain, or European Union, or national legislator in EU regulations, laws or other provisions to which the person responsible is subject. The data will also be blocked or deleted if a storage period prescribed by the aforementioned standards expires, unless there is a need for further storage of the data for the conclusion or fulfilment of a contract.

10. Newsletter

ista offers you the option to subscribe to a newsletter on the ista webpage. From this newsletter you will receive information on ista topics and offers at regular intervals. To receive this newsletter, you need a valid e-mail address. Your entered e-mail address will be checked by ista for accuracy and completeness. Your login data as well as your official IP address, date and time will be stored. This serves as security to prevent your e-mail address from being misused by unauthorized third parties. No other data will be stored by ista. The data collected will only be used for the newsletter dispatch. ista undertakes not to transmit the data collected to other third parties. You have the option of cancelling the newsletter at any time without giving reasons and requesting information from the ista site. The details are marked in each newsletter.

11. Rights of data subjects

In accordance with the PDPL and GDPR, ista takes appropriate measures to provide the data subject with all information and communications relating to data processing in a precise, transparent, understandable and easily accessible form in clear and simple language. The information shall be transmitted in writing or in any other form, including, where appropriate, electronically.

 

Your Rights under the PDPL regarding the protection of personal data. The User’s principal rights under the PDPL are as follows:

 

· the right to information and protection and lawful processing;

· the right to object to processing in certain circumstances;

· the right to be notified of processing;

· the right to request erasure, rectification and blocking access to your personal data;

· the right to not be subject to automated decision making;

· the right to data portability;

· the right to be notified of inaccurate disclosure.

 

ista endeavors to apply your rights following any justified request on your part.

12. Social Media / Social Bookmarks

Social bookmarks from LinkedIn and YouTube are integrated on the ista Website. Social Bookmarks are internet bookmarks that allow users of such services to collect links and news messages. These are only included on the Website as a link to the corresponding services. After clicking on the integrated graphic you will be forwarded to the page of the respective provider, i.e. only then will user information be transferred to the respective provider. For information on the handling of your personal data when using these websites, please refer to the respective data protection regulations of the providers.

Important Notice: This data protection information applies exclusively to ista's internet service offering. The ista Website contains links to other websites. Please note that ista is not responsible for the data protection or the content of these other internet services. We recommend all internet users to inform themselves about the respective data protection notices of other internet services when leaving ista's Website.

13. Changes to this data protection information

ista reserves the right to amend these disclosures at any time in compliance with the applicable data protection regulations of the European Union and of the Kingdom of Bahrain, as amended from time to time.

If you have any questions regarding the processing or security of your personal data, you can contact ista’s data protection officer directly.

 

14. Storage and Transfer of Information

You agree that we have the right to transfer your Information described in this Privacy Policy, including Personal Data and Personally Identifiable Information, to and from, and process and store it in the Kingdom of Bahrain, the European Union, the United Kingdom, and other countries, some of which may have less protective data protection laws than the region in which you reside. Where this is the case, we will take appropriate measures to protect your Information in accordance with this Privacy Policy. By submitting your Information, you agree to this transfer, storing or processing. We will take all steps reasonably necessary to ensure your data is treated securely and in accordance with this Privacy Policy and the applicable laws.

 

15. Complaints

Users may contact us for any complaints or information via ista’s data protection officer details indicated under section 8 of this Privacy Policy.

 

Users may also file complaints to the Personal Data Protection Authority of Bahrain (the “Authority”) in case we violated any provisions of the PDPL or any related Ministerial Decision.

 

According to Order No. 49 of 2022 with respect to rules and procedures governing submission of complaints regarding violations of the PDPL, complaints may be lodged to the Authority, by using the prescribed form on the Authority’s website, a complaint shall specifically include the following:

 

1. Complainant’s name, capacity, address, and contact information.

2. Defendant’s name, address, and contact information.

3. Relevant facts concerning the violation or breach.

4. Any evidence or documents supporting the complaint.

You may contact the Authority at www.pdp.gov.bh/en/contact.html