Subprocessors

This page lists the third-party companies that Dubai Smart Home (DSH) uses to help run our website, our customer portal, and the smart-home systems we install in your villa. We publish this list so you can see exactly who handles your data, where it sits, and on what legal basis it crosses borders.
last updated: 01.05.26
1. Why we publish this list

DSH is a controller of personal data under UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "UAE PDPL"). When we use a third party to process data on our instructions, that third party becomes our processor.

Article 10 of the UAE PDPL requires the controller to:

  • Pick processors that give enough technical and organisational guarantees.
  • Sign a written contract that binds the processor to the same duties we owe you.
  • Stay liable to you for what our processors do.

Article 16 of the UAE PDPL governs cross-border transfers. Personal data may leave the UAE only when the destination country offers an adequate level of protection, or when the controller puts a recognised safeguard in place such as standard contractual clauses, binding corporate rules, or your explicit consent.

We have the right to engage subprocessors to deliver our services. When we add or replace a subprocessor we will notify you in advance through the customer portal and by email. You have the right to object, as set out in section 5 below.

2. Subprocessors by category
2.1 Cloud hosting, CDN, and edge
NameService we use it forData categoryCountry of processingLawful transfer mechanismPrivacy policy
Vercel Inc.Web hosting for dubaismarthome.aePage logs, IP, request headersUnited StatesStandard contractual clauses + Data Processing Addendumhttps://vercel.com/legal/privacy-policy
Cloudflare Inc.CDN, WAF, Zero Trust tunnel for portalIP, request metadata, TLS metadataUnited States and EUStandard contractual clauses + DPAhttps://www.cloudflare.com/privacypolicy/
Amazon Web Services (AWS)RMM data plane, log lake, customer portal databaseProject records, device telemetry, support ticketsUAE me-central-1 (primary) and EU-west-1 (disaster recovery)Primary processing inside UAE; EU mirror under SCCshttps://aws.amazon.com/privacy/
2.2 Smart-home cloud platforms

These platforms are activated only when you choose the matching brand of lighting, control, audio, or voice. The vendor is the data controller for its own end-user account; DSH is a processor on your behalf during installation and remote support.

NameService we use it forData categoryCountry of processingLawful transfer mechanismPrivacy policy
Lutron ElectronicsRadioRA 3, HomeWorks QSX, Caseta cloud auth and remote keypad updatesDevice IDs, firmware logs, your installer accountUnited StatesSCCs + DPA at integrator levelhttps://www.lutron.com/en-US/Pages/Legal/PrivacyPolicy.aspx
Crestron ElectronicsCrestron Home cloud auth and remote diagnosticProject file metadata, device serialsUnited StatesSCCs + DPAhttps://www.crestron.com/Legal/Privacy-Statement
Snap One (Control4 4Sight)Remote-monitoring portal for Control4 systemsScene names, device status, alarm codesUnited StatesSCCs + DPAhttps://www.snapone.com/privacy-policy
Ubiquiti Inc. (UniFi Cloud)Network controller, remote management of switches and access pointsMAC addresses, device names, traffic countersUnited StatesSCCs + DPAhttps://www.ui.com/legal/privacypolicy/
Apple Inc. (HomeKit, Home Hub, iCloud)HomeKit pairing and iCloud sync of accessory stateAccessory identifiers, end-to-end encrypted home dataUnited States and EUSCCs + DPA; end-to-end encryption for HomeKit datahttps://www.apple.com/legal/privacy/en-ww/
Amazon (Alexa)Voice fall-back and routine triggersVoice utterance metadata, account IDUnited States and EUSCCs + DPAhttps://www.amazon.com/gp/help/customer/display.html?nodeId=GVP69FUJ48X9DT8X
Google LLC (Google Home, Assistant)Voice fall-back and castingVoice utterance metadata, device listUnited States and EUSCCs + DPAhttps://policies.google.com/privacy
Sonos Inc.Multi-room audio cloud and castingAccount ID, room names, content source IDsUnited States and EUSCCs + DPAhttps://www.sonos.com/en/legal/privacy
Josh.ai Inc.Private voice control, voice training, OTA updatesVoice training samples (opt-in), device IDsUnited StatesSCCs + DPA; on-device default, cloud opt-inhttps://www.josh.ai/privacy
2.3 Surveillance and access cloud
NameService we use it forData categoryCountry of processingLawful transfer mechanismPrivacy policy
Hikvision (Hik-Connect)Camera and intercom remote viewStream metadata, device serialsHong Kong SAR with EU mirrorSCCs + DPA; on-prem NVR primary, cloud optionalhttps://www.hikvision.com/en/support/cybersecurity/privacy-policy/
Axis Communications (Axis Companion)Axis camera managementDevice firmware logs, recording metadataSweden (EU)EU adequacy under PDPL Art.16https://www.axis.com/about-axis/privacy
Motorola Solutions (Avigilon Cloud)Avigilon ACC cloud connectionDevice IDs, alarm eventsUnited States and EUSCCs + DPAhttps://www.motorolasolutions.com/en_us/about/privacy-policy.html
Mobotix AGMobotix camera managementDevice IDs, firmware logsGermany (EU)EU adequacy under PDPL Art.16https://www.mobotix.com/en/privacy-statement
2.4 Energy stack monitoring
NameService we use it forData categoryCountry of processingLawful transfer mechanismPrivacy policy
SolarEdge TechnologiesPV inverter monitoringGeneration data, inverter serialIsrael and EUSCCs + DPAhttps://www.solaredge.com/us/legal/privacy-policy
Enphase EnergyMicroinverter and battery monitoringGeneration data, battery stateUnited StatesSCCs + DPAhttps://enphase.com/en-us/privacy-policy
Tesla Inc.Powerwall and Tesla mobile app pairingBattery state, charge cyclesUnited StatesSCCs + DPAhttps://www.tesla.com/legal/privacy
Span.IOSmart electrical panel monitoringPer-circuit consumptionUnited StatesSCCs + DPAhttps://www.span.io/privacy-policy
Wallbox Chargers (myWallbox)EV charger telemetryCharge sessions, kWh, vehicle IDSpain (EU)EU adequacy under PDPL Art.16https://wallbox.com/en_uk/legal/privacy-policy
ABB Ltd (ChargerSync)ABB EV charger managementCharge sessions, firmware logsSwitzerland and EUEU adequacy + SCCshttps://new.abb.com/privacy-notice/customers
2.5 Remote monitoring, management, and observability
NameService we use it forData categoryCountry of processingLawful transfer mechanismPrivacy policy
Auvik NetworksNetwork RMMTopology, device names, SNMP countersCanadaSCCs + DPA; Canada has UK adequacyhttps://www.auvik.com/privacy-notice/
DomotzNetwork and device RMMPing data, device names, MAC addressesUnited KingdomSCCs + DPAhttps://www.domotz.com/privacy-notice.php
Datadog Inc.Application logs and infra metricsService logs, request tracesUnited States and EUSCCs + DPAhttps://www.datadoghq.com/legal/privacy/
Sentry (Functional Software Inc.)Error logging from web and portalStack traces, scrubbed user agentUnited States and EUSCCs + DPAhttps://sentry.io/privacy/
2.6 Productivity and customer operations
NameService we use it forData categoryCountry of processingLawful transfer mechanismPrivacy policy
Google Workspace (Google LLC)Email, calendar, Drive for project documentsEmail, attachments, calendarEU and United StatesSCCs + DPAhttps://workspace.google.com/terms/dpa_terms.html
HubSpot Inc.CRM, lead nurture, ticketingContact details, deal stage, email logsEU (Frankfurt)EU adequacy under PDPL Art.16https://legal.hubspot.com/privacy-policy
Calendly LLCBooking calls with our teamName, email, time zoneUnited StatesSCCs + DPAhttps://calendly.com/privacy
Slack (Salesforce Inc.)Internal team messaging, on-call alertsProject channel dataUnited States and EUSCCs + DPAhttps://slack.com/trust/privacy/privacy-policy
2.7 Backup
NameService we use it forData categoryCountry of processingLawful transfer mechanismPrivacy policy
Backblaze Inc. (B2)Encrypted cloud backup of project filesEncrypted blobs (we hold the keys)United States and EUSCCs + DPA; client-side encryptionhttps://www.backblaze.com/company/privacy.html
Wasabi TechnologiesEncrypted secondary backupEncrypted blobs (we hold the keys)EU (Amsterdam)EU adequacy + DPAhttps://wasabi.com/legal/privacy-policy
2.8 Payment processing

When you pay an invoice or a deposit, the card data is captured by the payment processor and is never stored on DSH systems.

NameService we use it forData categoryCountry of processingLawful transfer mechanismPrivacy policy
Stripe Payments Europe Ltd.Card processing for AED, USD, EURTokenised card data, billing addressIreland (EU)EU adequacy under PDPL Art.16https://stripe.com/en-ae/privacy
Telr Services FZ-LLCLocal AED card processingTokenised card dataUAE (Dubai)Onshore UAE; no cross-border transferhttps://www.telr.com/legal/privacy-policy/
Network International LLCLocal AED card processing for B2BTokenised card dataUAE (Dubai)Onshore UAE; no cross-border transferhttps://www.network.ae/en/privacy-policy
2.9 Web analytics
NameService we use it forData categoryCountry of processingLawful transfer mechanismPrivacy policy
Plausible AnalyticsCookieless website analyticsAggregated visit counts, no personal IDsEU (Germany)EU adequacy under PDPL Art.16https://plausible.io/privacy
Google Analytics 4 (Google LLC)Website analytics with IP anonymisation enabledTruncated IP, page pathEU and United StatesSCCs + DPA; IP anonymisation on by defaulthttps://policies.google.com/privacy
2.10 Voice and AI

We use AI services only as a fall-back path or to assist our support staff. They are not used to process biometric data inside customer villas without your written consent.

NameService we use it forData categoryCountry of processingLawful transfer mechanismPrivacy policy
OpenAI Ireland Ltd.Optional transcription fall-back for support audioTranscribed text only, no trainingIreland (EU)EU adequacy + zero-retention API tierhttps://openai.com/policies/privacy-policy
Anthropic PBCClaude API for support automationCustomer support tickets, no trainingUnited StatesSCCs + DPA; zero-retention enterprise tierhttps://www.anthropic.com/legal/privacy
Microsoft Azure Speech (Microsoft Ireland)Arabic ASR fall-backAudio chunks, transcriptsEU (Netherlands)EU adequacy under PDPL Art.16https://privacy.microsoft.com/en-us/privacystatement
2.11 Government API
NameService we use it forData categoryCountry of processingLawful transfer mechanismPrivacy policy
Islamic Affairs and Charitable Activities Department (IACAD)One-way ingest of UAE prayer-times for Adhan-aware lighting, audio, voicePublic prayer-time table, no personal dataUAE (Dubai)Onshore public dataset; no personal data flows outhttps://www.iacad.gov.ae
2.12 Secure remote support
NameService we use it forData categoryCountry of processingLawful transfer mechanismPrivacy policy
Tailscale Inc.WireGuard tunnels for technician-to-villa supportTunnel metadata, no traffic contentUnited States and EUSCCs + DPA; end-to-end encryptedhttps://tailscale.com/privacy-policy
3. How we vet a new subprocessor

Before any vendor in the table above is given access to customer data, our operations team runs a four-step check:

  • Contract. A signed Data Processing Addendum that binds the vendor to UAE PDPL Article 10 duties, including breach notice, audit rights, and deletion on termination.
  • Security evidence. Current ISO 27001 certificate, SOC 2 Type II report, or equivalent. Where the vendor is a hardware-control cloud, we accept an IEC 62443 attestation.
  • PDPL Article 16 transfer check. We confirm the destination country and pick a lawful transfer mechanism. We prefer UAE-resident processing first, then EU adequacy, then SCCs.
  • Sub-region preference. Where the vendor offers UAE or GCC region hosting we select that region by default. EU is our second preference. United States is the last resort and only with SCCs in place.
4. How we notify you of new subprocessors

Whenever we add or replace a subprocessor we will:

  • Email the account contact listed in your project file.
  • Post a portal notice with the vendor name, the data category, and the lawful transfer mechanism.
  • Update this page and the Last updated date.

The notice goes out at least 30 days before the new subprocessor goes live. This 30-day window is your objection window, in line with UAE PDPL principles on transparency and the data subject right to object under Article 13.

5. Your right to object and your right to terminate

You may object to a new subprocessor by emailing support@dubaismarthome.ae during the 30-day notice window. We will then either:

  • Offer a workaround, for example a regional alternative or an on-prem-only deployment of the same function.
  • Pause the rollout for your account until we can offer a workaround.
  • Allow you to terminate the affected service line for cause, with a pro-rata refund of any prepaid fees, where no workaround is possible.

You may also raise a complaint with the UAE Data Office under Article 25 of the UAE PDPL.

6. Last updated

This list was last updated on 22 June 2026. We review the list at least every six months and on every onboarding of a new platform.

For privacy questions please contact:
support@dubaismarthome.ae
One Central, 8th and 9th Floor, Trade Centre 2, Dubai, United Arab Emirates
+971 50 506 1871

Do you have questions?
Reach out to our team and start a discussion.
Contact us
Contact us