Privacy Policy

Information Security is the practice of protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction. Combination of Confidentiality, Integrity and Availability(CIA) provide a secure environment. 

  • Confidentiality - Information should not be made available or be disclosed to unauthorized entities (i.e. persons, organizations, and systems).
  • Integrity - Reliability of information will be maintained through protection from unauthorized, unintended modifications during transmission, storage, and retrieval.
  • Availability - Authorized users are granted timely and uninterrupted access to information. 

 

Information Security Management System 

ENOVA Facilities Management Services LLC IT wish to inform you that information security management system has been initiated within the IT environment. Information security management provides end to end protection for customer and organization information with systematic management process with policies, procedures and controls. 

 

Information Security Objectives 

  • Protect ENOVA Facilities Management Services LLC business information and customer information
  • Preservation of the confidentiality, integrity and availability within ENOVA Facilities Management Services LLC information and information processing facilities.
  • Establish responsibility and accountability for information security in ENOVA Facilities Management Services LLC.
  • Maintain an appropriate level of awareness, knowledge and skill within the ENOVA Facilities Management Services LLC management and staff to help them to minimize the occurrence and severity of information security incidents. (Security Awareness)
  • Maintain risk based ENOVA Facilities Management Services LLC information assets protection in cost-effectively way. (Risk Management)
  • Ensure that ENOVA Facilities Management Services LLC manages information security incidents in order to minimize impact on the organization and individuals. (Incident Management)
  • Ensure that ENOVA Facilities Management Services LLC is able to continue its business critical IT services in the event of significant information security incidents. (Disaster Recovery) 

 

Policy Statement 

  • ENOVA Facilities Management Services LLC IT provides entire IT application and infrastructure support to ENOVA Facilities Management Services LLC and ENOVA Facilities Management Services LLC IT security team is responsible to implement, maintain and monitor the information security management processes within ENOVA Facilities Management Services LLC.
  • All ENOVA Facilities Management Services LLC employees, customers, contractual third parties, service providers, consultants and any other parties are responsible to protect ENOVA Facilities Management Services LLC information and information processing facilities from all threats, whether internal or external, deliberate or accidental.
  • All ENOVA Facilities Management Services LLC employees, contractual third parties, service providers, consultants and any other party are responsible to sustain high-level information security posture within the organization with preserving the confidentiality, integrity and availability at any given time.
  • ENOVA Facilities Management Services LLC shall be responsible to minimize internal and external information security risks to the acceptable level. This will include, ensuring that adequate information security risk management practices within the ENOVA Facilities Management Services LLC.
  • ENOVA Facilities Management Services LLC IT is committed to continually improve the sustainability, adequacy and effectiveness of information security management system.
  • ENOVA Facilities Management Services LLC shall maintain the compliance effect to the information security management with any applicable legal, regulatory and contractual obligations while preserving ENOVA Facilities Management Services LLC reputation and image. 

 

Data Privacy Policy

Introduction 

Enova (“Enova”, “we”, “us”, or “our”) is committed to protecting the privacy and confidentiality of all personal data entrusted to us. This Privacy Notice explains how we collect, use, disclose, store, retain, secure, and protect personal data in accordance with:

  • UAE Personal Data Protection Law (UAE PDPL – Federal Decree Law No. 45/2021) and other applicable data protection regulations in the jurisdiction where Enova operates (Including ADGM and GDPR where applicable).
  • This Notice applies to employees, visitors, customers, service providers, website users, and any other individual whose personal data we process.

 

Categories of Personal Data We Collect 

We may collect the following categories of personal data:

Employees and Job Applicants
  • Identification data (name, Emirates ID, passport, nationality)
  • Contact details (phone, email, address)
  • Employment data (CVs, contracts, attendance, training, performance)
  • Financial data (bank details, payroll, benefits)
  • IT system and access logs
  • CCTV and building access records
Visitors to Enova premises
  • Name, ID and visitor records
  • Visit details
  • CCTV and access control logs
Customers
  • Name, contact details
  • Service and contract information
  • Billing and Payment data
Vendors, Contractors, and Subcontractors
  • Contact and company details
  • Bank and payment details
  • Contractual and compliance information
Website and digital platform users
  • IP address and device information
  • Cookies and website usage data

Any other personal data provided during service delivery or contractual engagement.

 

How We Collect Personal Data

We collect personal data through:

  • From employees during recruitment, onboarding, payroll, and training
  • From visitors through reception and security systems
  • From customers through service requests and contracts
  • From vendors through procurement and payment processes
  • From website users through cookies and online forms
  • From third parties such as recruitment agencies, clients, and subcontractors

 

Purposes of Processing 

We process personal data for the following lawful and legitimate purposes, depending on the category of data subject:

Employees and Job Applicants
  • Recruitment, onboarding, payroll, and benefits administration
  • Performance management, training, and disciplinary processes
  • IT account management and access control
  • Health, safety, and workplace security
  • Compliance with labour, tax and regulatory obligations
Visitors to Enova Premises
  • Building access management and security
  • Health, safety, and incident investigations
  • Regulatory and audit requirements
Customers
  • Contract execution and service delivery
  • Customer support and communications
  • Billing and payment processing
  • Service improvement and quality management
Vendors, Contractors, and Subcontractors
  • Contract management and service delivery
  • Payment processing
  • Compliance and due-diligence checks
  • Operational communications
Website and Digital Platform Users
  • Website functionality and security
  • User experience improvement and analytics
  • Communication via online forms

 

Legal Basis for Processing 

Depending on the processing activity, we rely on the following legal bases:

  • Performance of a contract
  • Compliance with applicable laws
  • Legitimate interests pursued by Enova
  • Consent (where required under PDPL, GDPR, DIFC, ADGM)
  • Protection of vital interests
  • Public interest or official authority (where applicable)

 

Data Sharing and Transfers

Enova may share personal data with the following categories of recipients, depending on the purpose of processing:

  • Authorized Enova departments
  • Clients and customers
  • Vendors, subcontractors, and service providers
  • Government authorities and regulators
  • Third parties required for service delivery
  • Cloud or IT service providers
  • Group companies or Affiliates (where applicable)

Cross-Border Transfers Personal data may be transferred outside the country where it was originally collected, including between Enova entities, group companies, and external service providers. Where such cross-border transfers occur, Enova ensures that appropriate safeguards are implemented, including:

  • Adequacy decisions or approved jurisdictions (where applicable)
  • Data Processing Agreements (DPAs) and contractual safeguards
  • Standard Contractual Clauses (SCCs), where required
  • Transfer Impact Assessments (TIAs), where required by applicable law

No cross-border transfer is permitted unless it has been assessed and approved in accordance with Enova’s Transfer Impact Assessment and cross-border data transfer procedures.

 

Data Retention

Personal data is retained only for the period necessary to fulfil the processing purpose, comply with legal obligations, or protect Enova’s legitimate interests. Each department must follow Enova’s approved Data retention and disposal schedule, which defines how long different categories of personal data are retained and when they are securely deleted.

 

Data Security 

Enova has implemented generally accepted standards of technology and operational security designed to protect personal data against:

  • Unauthorized access
  • Loss or destruction
  • Disclosure or alteration
  • Cybersecurity incidents
  • Misuse or accidental damage.

These include technical, organizational, and administrative controls.

 

Your Rights as a Data Subject

Depending on the applicable regulation, you may have the right to:

  • Access your personal data.
  • Request correction or updating.
  • Request deletion (“right to erasure”)
  • Request restriction of processing.
  • Request portability of your data.
  • Object to processing
  • Withdraw consent at any time (if processing is based on consent)

Opt-Out of:

  • marketing communications
  • non-essential cookies
  • certain processing activities based on legitimate interests.

To exercise any of the rights listed above, you may submit a request using one of the following methods

  • By emailing Enova’s Data Protection Officer
  • By submitting a request through Enova’s official website or customer service channels
  • By contacting Enova through your usual business or contractual contact

Once Enova receives your request:

  • Your request will be recorded and reviewed by the Data Protection Officer
  • Your identity may be verified to protect your personal data
  • The relevant departments will be instructed to locate, correct, delete, restrict, or provide your data
  • You will receive a response within the timeframes required by applicable data protection laws

Enova will not discriminate against any individual for exercising their data protection rights.

 

Contact Details – Data Protection Officer

  • Email: dpo@enova-me.com
  • By post to:
    Enova Facilities Management Services LLC
    Data Protection Officer
    PO Box: 22707 | 2nd Floor City Centre Offices, City Centre Deira Complex, Dubai | United Arab Emirates
    www.enova-me.com

 

Amendments and Updates 

Enova may update this Privacy Notice to reflect legal or operational changes. The latest version will always be made available.

 

AIEVA