Privacy Policy

Privacy Policy

LAST UPDATED ON: 10-Aug-26

SPLIDU PRIVACY NOTICE

August 2026 · Version 1.1

This notice explains how Fused Portal Services (“splidu”, “we”) handles your personal data, as required by Articles 5, 6 and 13 of Federal Decree-Law 45/2021 on the Protection of Personal Data (“PDPL”). It is a notice, not a contract — you are not asked to sign it.

1. Who we are

Fused Portal Services, trading as splidu — a UAE Civil Company, trade licence 1027773, TRN 104587673500003, Citadel Tower, Office 2103-C-35, Business Bay, Dubai, UAE. Data questions: info@splidu.com.

2. What we collect

  • Account data — name, email, mobile number, password (stored hashed — never readable).
  • Booking and membership data — what you book or subscribe to, dates, guests, visits, payments made and refunds received. Card payments are processed by our licensed payment providers; your card number never touches splidu’s systems.
  • Membership pass photograph — if you buy a splidu Membership, the photograph you provide at checkout, before your first payment is taken. It is required: a membership cannot be issued without one, and if you do not provide one, no membership is issued — and if you were charged, that month is refunded in full. It appears on your membership pass so restaurant staff can check by eye that the pass belongs to the person presenting it — memberships are personal to you and cannot be transferred or shared. You cannot change the photograph yourself, which protects the pass against being altered after it is issued, but you can ask us to replace it at any time by emailing info@splidu.com and we do. We do not run facial recognition, face-matching, template extraction or any other automated analysis on it, and the restaurant is contractually forbidden to do so either.
  • Record of your acceptance — when you accept the Membership Terms we record your name, your email address, your IP address, the date and time with timezone, each confirmation you gave, the version you accepted, and a certificate reference, so both of us have proof of what was agreed (Federal Decree-Law 46/2021).
  • Dietary and allergy information — only if you choose to give it (see section 4).
  • Technical data — device, IP address, and usage of the platform; cookies as described in the Cookies Notice.
  • Support correspondence — what you send us.

3. Why we use it, and on what legal basis (PDPL Art. 4–6)

Purpose PDPL ground
Running your account, bookings, memberships, payments, refunds necessary to perform our contract with you (PDPL Art. 4)
Passing your booking details to the chef or restaurant hosting you necessary to perform our contract with you (PDPL Art. 4)
Tax invoices, records, and legal retention necessary to comply with UAE law (PDPL Art. 4)
Fraud prevention and platform security necessary for splidu’s legitimate interests, where these do not override your rights, freedoms and interests (PDPL Art. 4)
Putting your photograph on your membership pass, and showing it to the restaurant you joined, so its staff can check by eye that the pass belongs to the person presenting it — this stops memberships being shared, lent or resold, and stops fraudulent use of a pass necessary for splidu’s legitimate interests in preventing membership sharing and fraud, where these do not override your rights, freedoms and interests (PDPL Art. 4) — you have the right to object; see below
Keeping the record of your acceptance — your name, email, IP address, date and time with timezone, each confirmation given, the version accepted and a certificate reference necessary to establish, exercise or defend legal claims and to prove what was agreed under Federal Decree-Law 46/2021 (PDPL Art. 4)
Marketing emails about splidu services your consent (PDPL Art. 6) — withdraw any time via the unsubscribe link or by emailing info@splidu.com
Passing allergy/dietary data to the kitchen your explicit consent (section 4; PDPL Art. 6)

About the photograph. We rely on legitimate interests here rather than on your consent, and we want to be straight with you about why. A membership pass cannot exist without a photograph, so you cannot refuse it and still buy the membership — and a consent you cannot refuse is not a free consent, so it would be the wrong basis to claim. Legitimate interests is the honest one, and it comes with a real right to object. We think the balance is a fair one: it is a single still image, shown only to the one restaurant your membership is with, never put through any machine analysis, and deleted when your membership ends. It is the same thing a gym or a club does with a membership card photo, for the same reason — the membership is personal to you and is not transferable. If you want to object, email info@splidu.com and we will look at your situation properly. The honest consequence is that a pass cannot exist without a photograph, so an objection will normally mean the membership ends; no month you have already paid for is affected.

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects. If that ever changes, this notice will say so first and your Article 18–19 rights will apply.

Separately and absolutely: we never subject your membership pass photograph to facial recognition, face-matching, template extraction or any other automated or biometric analysis. It is looked at by human eye only. The restaurant is under the same contractual prohibition and may not analyse it either. If we ever wanted to change that, we would tell you before it happened and we would need your explicit consent — it would not simply start.

4. Allergy and dietary data — sensitive data — and your membership pass photograph

At every booking you confirm that you are aware of your own allergies and dietary restrictions and that you have reviewed the ingredients and dietary information the chef or restaurant publishes for that experience — this confirmation is your own declaration and a condition of booking.

Separately, if you choose to share allergy or dietary details with us, that is sensitive personal data under the PDPL: we pass it only with your explicit consent to the chef or restaurant preparing your meal, and only for that purpose. Under our contract with them, they may not use it for anything else and may not keep it beyond your visit and their food-safety records. You can withdraw this consent at any time by emailing info@splidu.com.

Your membership pass photograph is not biometric data under the PDPL. Biometric data means a photograph put through technical processing that produces a template or a machine match of your face. Yours never is. It is stored and displayed as an ordinary picture, and it is compared only by a human eye — a member of the restaurant’s staff looking at the pass and looking at you. The restaurant is contractually barred from subjecting it to facial recognition, face-matching, template extraction or any other automated or biometric analysis, and so are we. If that ever changed, we would tell you before it happened and obtain your explicit consent.

5. Who receives your data

  • The chef or restaurant you book — your name, contact details, booking reference, party size, visit entitlement, and, with consent, dietary needs; the same applies to named guests you add to a booking. For this data they are an independent controller under the PDPL, responsible for their own compliance.
  • The restaurant your Membership is with — your name, your membership reference, your visit entitlement, your membership pass photograph, and, with your consent, your allergy and dietary information. Nothing else: not your contact details, not your party size. Its staff may only view the photograph, on the platform, to check that a pass belongs to the person presenting it. Under our contract with the restaurant it may not copy, download, publish or share the photograph, may not keep it beyond the life of your membership, and may not run facial recognition or any other automated or biometric analysis on it. For this data the restaurant is an independent controller under the PDPL, responsible for its own compliance.
  • Service providers — payment providers (card processing), email delivery, and hosting, under contracts that restrict their use of your data. A current list of these providers is available from info@splidu.com on request.
  • Authorities — where the law requires it.

We do not sell your personal data.

6. Where your data is kept

Your data is processed in the UAE or with service providers under the safeguards UAE law permits for processing outside the UAE (PDPL Articles 22–23).

7. How long we keep it

Account data for as long as your account exists; booking, membership, payment and invoice records for the periods UAE tax and commercial law require (up to seven years); support correspondence as long as needed to resolve the matter.

Your membership pass photograph is deleted within 30 days after your membership ends, however it ends — you cancel, the programme ends, the restaurant closes, or the membership is withdrawn. Note that cancelling does not end your membership at once: it runs to the end of the month you have paid for and your pass works until then, so the 30 days start from that date. A membership On hold has not ended, so the photograph is kept while the membership can still be reactivated — but if a membership stays On hold for six consecutive months we treat it as ended for this purpose and delete the photograph within 30 days of that point.

The record of your acceptance — your name, email, IP address, date and time with timezone, each confirmation given, the version accepted and the certificate reference — is kept for seven years from the end of the year in which your membership or account ends. We use it only to prove what was agreed and to defend claims.

At the end of each of these periods we delete or anonymise the data.

8. Your rights (PDPL Arts. 13–19)

You may ask for access to your data, a copy of it, correction, deletion, restriction of or objection to processing (Articles 13–19, including rights relating to automated processing), and transfer of your data; where processing rests on consent you may withdraw it at any time without affecting past processing. Some of these rights are qualified, in the following ways. Records UAE law requires us to keep (tax and accounting records) are kept for the legal period, and the record of your acceptance is kept to establish, exercise or defend legal claims, as the PDPL permits. If you ask us to delete your membership pass photograph while your membership is live, we treat that as an objection under section 3 — we cannot issue or keep a pass without it, so your membership would end; no month you have already paid for is affected. If you ask us to erase your data, we delete or anonymise everything we are not required or entitled to keep. What is kept is put beyond ordinary use — it is not used for marketing, for profiling, for delivering our service, or for anything other than the purpose that justifies keeping it — and it is deleted at the end of the periods in section 7. We tell you what we kept and why. Write to info@splidu.com — we respond within 30 days. You may also complain to the UAE Data Office (established by Federal Decree-Law 44/2021) via its published complaint channel.

9. Security

We protect your data with encryption in transit on every page, hashed passwords, access controls, and least-access rules for staff and partners. No system is perfectly secure; if a breach affects you, we notify you and the authorities as the PDPL requires.

10. Changes

We may update this notice; the current version, with its date, is always at splidu.com. If a change materially affects you, we tell you before it takes effect.

Version: 1.1 · Effective: 11 August 2026 · Replaces the Privacy Policy dated 17 November 2022. What changed — v1.1: adds the membership pass photograph; adds the record of your acceptance of the Membership Terms; gives a clearer explanation of how long we keep things and when we delete them (section 7); and gives a clearer explanation of how your rights are qualified (section 8).