Home/Privacy Policy

Privacy Policy

How we collect, use, store and protect personal data — across this website, the products we operate, and the work we do for clients. Written to be read, not survived.

Last updated 12 February 2026Omelatte FZ-LLCRas Al Khaimah, UAE
/01

Who we are

Omelatte FZ-LLC is a product design and engineering studio registered in Ras Al Khaimah, United Arab Emirates, operating from Al Mamourah Street, RAK. We build software for clients, we operate our own products including Ledgerly and PeerMed, and we publish themes on the Shopify Theme Store.

For anything in this policy, write to info@omelatte.com. We are the data controller for information collected through omelatte.com and for our own products; when we build or run systems for a client, that client is normally the controller and we act as their processor under a written agreement.

/02

What we collect

Information you give us

Your name, email address, phone number, company, and whatever you write in a message when you use the contact form, email us, or book a call. If you become a client, we also hold the commercial and billing details needed to work together.

Information collected automatically

Standard server logs — IP address, browser and device type, pages requested, referring page, and timestamps. We use this to keep the site available, diagnose faults, and understand which pages are useful.

Information inside our products

Ledgerly and PeerMed hold data that customers enter. Ledgerly holds business and accounting records. PeerMed holds clinical case material, de-identified of patient identifiers at the point of submission. Each product is governed by its own agreement with the customer, which takes precedence over this website policy.

What we do not collect

We do not buy contact lists, we do not run third-party advertising pixels on this site, and we do not build behavioural profiles for marketing.

/03

Why we use it

  • To reply to you. Answering enquiries, scheduling calls, and sending the proposals or estimates you asked for.
  • To deliver work. Running projects, providing support, and meeting the obligations in a signed contract.
  • To operate our products. Providing, securing and improving Ledgerly, PeerMed and our Shopify themes.
  • To keep things safe. Detecting abuse, preventing fraud, and maintaining the security of our systems.
  • To meet legal duties. Accounting, tax and regulatory record-keeping, including UAE VAT obligations.

Where the UAE Personal Data Protection Law or the GDPR applies, our legal bases are: performance of a contract, our legitimate interest in running and securing the business, compliance with a legal obligation, and consent where we ask for it — which you can withdraw at any time.

/04

Cookies

This website uses only what it needs. A small preference is stored in your browser to remember whether you chose the dark or light theme; it never leaves your device and identifies nothing about you. We do not set advertising cookies and we do not share browsing data with ad networks.

If we later add analytics, this page will say so before it goes live, and you will be asked first where consent is required.

/05

Who we share it with

We do not sell personal data. Ever. We share it only with:

  • Service providers who host our infrastructure, deliver our email, or process payments — bound by contract to act only on our instructions.
  • Clients, where you contacted us about their project and the enquiry belongs with them.
  • Authorities, where a valid legal obligation requires it.
  • An acquirer, in the event of a merger or sale, with notice to you and no reduction in your rights.

Some providers operate outside the UAE. Where data moves across borders, we rely on providers offering adequate protection and on contractual safeguards including standard contractual clauses.

/06

How we protect it

Encryption in transit and at rest, role-based access limited to people who need it, audit logging on systems that hold sensitive material, and de-identification of personal health information at the point of entry in PeerMed. Our product infrastructure can be deployed in a private cloud or on-premise where an institution requires it.

No system is beyond compromise. If a breach affects your personal data and creates a risk to you, we will notify you and the relevant authority within the timeframes the applicable law requires.

/07

How long we keep it

Enquiries that do not become projects: up to twenty-four months, then deleted. Client records: for the life of the engagement plus the retention period required by UAE commercial and tax law — currently five years. Product data: as set out in each product agreement, and returned or deleted on request when the account closes. Server logs: rotated within twelve months.

/08

Your rights

You can ask us to show you what we hold, correct it, delete it, restrict how we use it, or hand it to you in a portable format. You can object to processing based on legitimate interest, and withdraw consent where you gave it.

Email info@omelatte.com and we will respond within thirty days. We will not charge you for a reasonable request and we will not make the process difficult. If you are unhappy with our answer, you may complain to the UAE Data Office or, where the GDPR applies, your local supervisory authority.

/09

Children

Our website and products are for businesses and professionals. We do not knowingly collect personal data from anyone under eighteen. If you believe a child has provided us data, write to us and we will delete it.

/10

Changes to this policy

If we change how we handle personal data, we will update this page and change the date at the top. Material changes affecting existing clients or product customers are notified directly rather than left here to be discovered.

Question about your data?

Ask a person, not a form. We answer privacy questions directly and we will tell you plainly what we hold.