Privacy Policy

See Aureus Academy's commitment to data security and privacy in our comprehensive Privacy Policy. Your trust is our top priority.

Thank you for reviewing our Privacy Policy. This Privacy Policy governs our online educational mobile application and website, including all modifications, enhancements, or updates thereto (the “Platform”) as operated by of Interactive Aureus Fine Arts Training LLC, its affiliates and parent entities (“Aureus”, “we”, “our” or “us”). Terms used but not defined here have the meanings given in our Terms of Use.  Your privacy matters to us. We are committed to safeguarding personal data in accordance with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and applicable UAE regulations.  By accessing or using our Platform, you acknowledge and consent to this Privacy Policy. If you do not agree, please do not use our Platform. If you are under 18, please obtain consent from your parent or legal guardian before providing any personal data. Parents/guardians who believe a child has provided data without consent should contact us so we can delete it.

1. What We Collect, Why We Collect It, and Lawful Bases

We may collect the following personal data from you:

Your account information. We collect your identification number (NRIC, FIN, or passport), address, date of birth, email address and telephone number, as well as service-related information such as bank and credit card details when you register with us. You may provide us with the telephone numbers in your mobile address book, including those of both users and your other contacts. You confirm that you are authorised to provide us with such numbers;

Device and connection information. We collect device-specific information when you access or use our Platform. This includes information such as the hardware model, operating system information, browser information, IP address, mobile network information including phone number and device identifiers;

Usage and log information.
We collect service-related, diagnostic, and performance information when you use our Platform. This includes information about your activity (such as how you use our Platform, how you interact with other users using our, etc), log files, and diagnostic, crash and performance logs and reports;

Your attendance records and usage of our Platform.
We collect your attendance records, progress, and completion of our online lessons, seminars, webinars, events, or service offerings. Your usage of our Platform. To improve our performance and for quality and training purposes, we may retain records of your voice, likeness, and image (e.g., in the form of photographs or video and audio recordings) while you use our Platform;

Voluntarily provided information.
We collect voluntarily provided information to us, such as when you register with us or post or share any content on the Platform;

Your messages.
When you message us or other users on the Platform, we retain your messages (including your note or recording of a call to us, email, or letter you sent us or other records of contact with us, chats, photos, videos, voice messages and files) on our servers in the ordinary course of providing our services to you. To improve performance and deliver messages more efficiently, such as real-time market data, we may retain such content on our servers for a longer period;

Customer support and feedback.
We collect copies of your messages and how to contact you to provide customer support when you contact us with queries or provide feedback to us on your use of our Platform;

Transactional information.
If you pay for our services, we may receive information and confirmations, such as payment receipts, including from app stores or other third parties processing your payment;Information others provide about you. We may receive information that other people provide to us, which may include information about you. For example, when other users you know use our Platform, they may provide your telephone number from their mobile address book (just as you may provide theirs);

Third-Party providers.
We work with third-party providers to help us operate, provide, improve, understand, customise, support and market our Platform. These providers may provide us information about you in certain circumstances; andThird-Party services. We may allow you to use our Platform in connection with third-party services. Please note that when you use third-party services, their own terms and privacy policies will govern your use of those services.

We may collect, use and/or disclose your personal data for the following purposes:
setting up your registered user account and profile on the Platform;
to provide and improve our Platform, including informing you of any change or updates to our Platform;
to organise the data to allow you to view, manage your information, or to help you visualise your data;
for targeted online marketing;
for accounting, billing, and verification purposes;
to contact you regarding any complaints, feedback, queries, requests, claims or disputes;
to facilitate investigations into or to take action regarding any suspicious or illegal activity on the Platform;
for internal review, business improvement, and quality and training purposes;
for internal administrative and management purposes;
where required by any act, statute, law, or regulation, rules, directives, or by the order of a government authority or a court or tribunal of competent jurisdiction;
such other purposes as consented to by you; and
any other purpose reasonably related to the aforesaid.

We may disclose your personal data to our partners, service providers, contractors, select vendors and affiliates whom we have engaged to provide our services, to maintain the Platform or to protect the security or integrity of the Platform and our databases. All such third parties are prohibited from using your personal information except to provide these services to us, and they are required to maintain the confidentiality of your information.We may also share your personal data with our affiliates, subsidiaries and parent companies, industry regulators and other government organisations as required by local law and regulations, financial institutions, research institutions for market analysis purposes, or other third parties in our partner network who we work with to deliver our services. In some cases, the information will be encrypted, anonymised or aggregated, whereby all identifying information has been removed, such that the remaining data does not identify any person.

Please refer to Clause 10 below for details on how you can contact us should you decide to withdraw your consent.

2. How We Use Personal Data (Summary Purposes)

- Set up and administer your account and learner profile
- Provide, maintain, secure, and improve the Platform and our services
- Communicate with you (service updates, transactional notices, support)
- Personalise learning journeys and progress dashboards
- Billing, payment processing, refunds, dispute handling
- Detect, investigate, and prevent fraud, misuse, and security incidents
- Compliance with UAE law/lawful requests (e.g., tax, regulatory, court orders)
- Research, analytics, and quality/training (using de-identified/aggregated data where possible)
- Marketing with your consent (you can opt out any time)  

We will not sell your personal data.

3. Disclosure of Personal Data

We may share personal data with:
- Service providers / processors (hosting, cloud, analytics, communications, payment gateways, security, customer support) under contracts that require confidentiality and PDPL-compliant processing.
- Aureus group companies (intra-group transfers under appropriate safeguards).
- Regulators and authorities when required by UAE law or lawful requests.
- Professional advisers (legal, auditors, insurers) under confidentiality obligations.
- Partners only where necessary to deliver a chosen feature or programme and on a lawful basis.
Where feasible, we use de-identified or aggregated data.

4. Confidentiality

We keep your personal data confidential and use it only as described in this Policy, except where disclosure is required by law, authorised by you, or necessary to protect rights, safety, and security.

5. Your Rights under the UAE PDPL

Subject to applicable exemptions, you have the right to:
- Be informed about how your data is processed;
- Access your personal data; Rectify inaccurate or incomplete data;
- Erase personal data in certain cases; Restrict or stop processing in certain cases;
- Data portability (receive data in a structured, commonly used, machine-readable format and transmit it to another controller where technically feasible);
- Object to processing, including direct marketing;
- Not be subject to decisions based solely on automated processing that significantly affect you, where applicable; - - Withdraw consent at any time (this does not affect earlier lawful processing).  

You can exercise rights via your account settings (where available) or by contacting us (see Section 10). We will respond within PDPL timelines.  

You may also lodge a complaint with the UAE Data Office. We encourage you to contact us first so we can try to resolve your concerns directly.

6) Access, Correction, and Deletion Requests

- To access or obtain a copy of your data, or to request correction or deletion, contact us (Section 10).
- We may request information to verify your identity and the scope of your request.
- We will act on requests within a reasonable time in accordance with PDPL.
- We may retain certain data where required by law, for the establishment, exercise or defence of legal claims, for accounting/tax obligations, or to ensure platform integrity and safety.

7. Retention

We retain personal data only for as long as necessary to: provide services; meet legal, regulatory, tax, accounting, or security requirements; resolve disputes; and enforce agreements. When data is no longer needed, we will delete or irreversibly anonymise it.

8. Security Measures

We implement technical and organisational measures appropriate to the risk, including access controls, encryption in transit and at rest where appropriate, network monitoring, and staff training.  
No system is 100% secure; you are responsible for safeguarding your account credentials and using up-to-date device and antivirus protections.

9. Cookies and Similar Technologies

We use:
- Essential cookies (strictly necessary for the Platform to function).
- Performance/analytics cookies (to improve the Platform).
- Functional cookies (to remember preferences).
- Advertising/marketing cookies (only with your consent).  

You can manage cookie preferences via our cookie banner and your browser settings. Disabling certain cookies may affect functionality. When you access third-party services through our Platform, their cookie and privacy policies apply.

10. Marketing Communications

We may send you service and transactional communications. We will only send marketing communications where permitted by PDPL and, where required, with your opt-in consent. You can unsubscribe at any time via the message footer or by contacting us.

11. Cross-Border Transfers

Your personal data may be transferred to and processed in other countries where Aureus or our providers operate. Where we transfer data outside the UAE, we will use one or more of the following safeguards as required by PDPL:
- Transfer to jurisdictions deemed to provide an adequate level of protection;
- Appropriate safeguards, such as PDPL-compliant contractual clauses;
- Your explicit consent;
- Performance of a contract at your request or in your interest;
- Compliance with legal obligations, protection of public interest, or establishment/exercise/defence of legal claims.
We take steps to ensure transferred data remains protected.

12. Children’s Data

We do not knowingly collect personal data from children without verifiable parental or guardian consent. If you believe a child has provided data without consent, contact us and we will promptly delete it.

13. Third-Party Websites and Services

Our Platform may link to third-party websites or enable third-party services. Their privacy and security practices are governed by their own policies. Please review those policies before using such services.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the latest version on the Platform and update the “Last updated” date. Significant changes may be notified through the Platform or by email. Your continued use after changes become effective signifies acceptance.

15. Contact Us (and DPO)

If you wish to exercise your rights, withdraw consent, or have questions about this Policy or our data practices, please contact:  

Interactive Aureus Fine Arts Training LLC
Email: contact@aureusacademy.com (general privacy requests)
Address: Office No. 14 Sayeh Shuaib, 2, King of Dubai Industrial City LLC J-0610, Dubai

16. General

By using the Platform, you are deemed to have accepted our Terms of Use in addition to this Privacy Policy.