ORVEX

Legal

Privacy Policy

How ORVEX collects, uses, stores and protects personal data. Last updated 30 August 2026.

1. Who we are

ORVEX is a multi-tenant business software platform for companies in the United Arab Emirates, covering the ORVEX website at orvex.ae and the ORVEX application. Its first module, Brokerage, is a CRM for real estate brokerages.

For data a brokerage puts into its own ORVEX account (its staff, its clients, its listings), the brokerage controls that data and decides what is collected — ORVEX processes it only on their instructions. If you are a client of a brokerage that uses ORVEX, contact that brokerage to correct or delete your data.

Questions about this policy: hello@orvex.ae.

2. What we collect, and how long we keep it

If you book a demo: your name, company, email, phone number, and anything you write in the message field — used only to contact you about ORVEX.

If you have an ORVEX account: your name, work email, brokerage, role and permissions, and an audit log of your actions in the product. Failed sign-in attempts and the network address they came from are recorded to limit password guessing.

Data your brokerage enters: leads, owners, listings, transactions and calendar entries — names, phone numbers, emails, and any documents uploaded. ORVEX does not send, receive or store WhatsApp messages: its WhatsApp button simply opens a chat in the agent's own WhatsApp, and the conversation stays there.

Retention: data stays for as long as the account is active, and is the brokerage's to delete. Deleted documents are permanently removed after 90 days (a deleted item may briefly persist in a backup copy afterward). Demo accounts and their contents are deleted when the demo ends.

We do not use tracking pixels, advertising cookies or third-party analytics on this website, and we do not sell personal data to anyone, ever. Cookies are set only to keep you signed in and make the product work — never to track you across other sites.

3. Google user data

What we do with it: we copy your ORVEX tasks, events and viewings into your Google Calendar, and read events from it so they appear in ORVEX. That is the entire purpose — we do not use calendar content for anything else.

What we store: the event details needed to keep the two sides in step, and an access token issued by Google. The token is encrypted at rest and is not readable by you, your brokerage's administrators, or any other ORVEX user.

Limited Use. ORVEX's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties except as necessary to provide or improve this feature, or as required by law; we do not use it for advertising; and we do not allow humans to read it except with your explicit permission, where necessary for security, or where required by law.

Disconnecting: disconnect in ORVEX at any time to delete the stored token, or revoke access directly from your Google Account security settings — that takes effect immediately and independently of us.

4. Apple Calendar

If you connect Apple Calendar, ORVEX uses CalDAV with an app-specific password generated in your Apple ID settings — never your Apple ID password itself. It is encrypted at rest under the same terms as above, and revoking the app-specific password from your Apple ID ends ORVEX's access immediately.

5. Where data is stored, and how we protect it

We use a small number of established providers, named here because you are entitled to know who holds your data: Supabase (the database, Mumbai), Vercel (application hosting, served from Mumbai), Cloudflare R2 (uploaded documents), Backblaze B2 (an encrypted nightly backup in the EU), Resend (transactional email, Ireland), and Google (Maps, and Calendar where connected). These providers store data outside the UAE; where UAE residents' personal data is transferred abroad, we rely on the providers' own contractual data-protection commitments.

Every brokerage's data is isolated from every other brokerage's at the database level (row-level security), not by application code choosing what to show. Credentials for connected services are encrypted at rest and never displayed back to anyone. Actions in the product are written to an append-only audit log nobody can alter or delete, including a brokerage's own administrators, and financial records cannot be deleted by anyone. The database is backed up continuously (a seven-day recovery window) plus a separate encrypted nightly copy with a different provider in a different country. No system is immune from failure, and we do not claim otherwise.

6. Your rights

Under the UAE Personal Data Protection Law you may ask for a copy of the personal data we hold about you, ask for it to be corrected or deleted, object to how it is used, or withdraw consent previously given. If your data is in a brokerage's ORVEX account, contact that brokerage first — they control it. Otherwise write to hello@orvex.ae and we will respond within 30 days.

7. Other

ORVEX is business software, not directed at children, and we do not knowingly collect personal data from anyone under 18. If we change how data is handled, we will update this page and its date above; where a change materially affects an existing customer, we will tell them directly rather than relying on this page being re-read.

Questions about this policy? Get in touch.