Back to Home
Aera by Amalfi Labs
Contact Legal
LEGAL COMPLIANCE & DATA PRIVACY

Privacy Policy

Comprehensive disclosure on data protection, processing standards, and user rights under GDPR (EU), UK GDPR, UAE PDPL, and CCPA/CPRA.

Effective Date: September 10, 2026 Data Controller: Amalfi Labs FZ-LLC / Amalfi Labs S.r.l. Inquiries: privacy@amalfilabs.art

Contents

  • 1. Data Controller Identity
  • 2. Scope & Legal Framework
  • 3. Categories of Data Collected
  • 4. Legal Bases for Processing
  • 5. Sub-Processors & Third Parties
  • 6. Cross-Border Data Transfers
  • 7. Retention & Data Deletion
  • 8. Your Data Subject Rights (GDPR/UK)
  • 9. UAE PDPL Disclosures
  • 10. California Privacy Rights (CCPA/CPRA)
  • 11. Children's Privacy
  • 12. Technical & Organizational Security
  • 13. Inquiries & Supervisory Authorities

1. Identity & Contact Details of the Data Controller

This Privacy Policy applies to the collection, processing, and storage of personal data by Amalfi Labs ("Amalfi Labs", "we", "us", or "our"), operating the immersive real estate marketing and spatial sales platform known as Aera by Amalfi Labs.

Primary Contact Details:

  • Entity Names: Amalfi Labs FZ-LLC (Dubai, United Arab Emirates) & Amalfi Labs S.r.l. (Milan, Italy)
  • Designated Data Protection Officer (DPO): Legal & Compliance Team
  • Dedicated Privacy Email: privacy@amalfilabs.art
  • General Inquiries: contact@amalfilabs.art
  • Primary Web Domain: https://amalfilabs.art

2. Scope & International Legal Framework

Amalfi Labs is committed to upholding the highest international standards of privacy and data security. We align our data processing procedures with:

  • Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR) and the Directive 2002/58/EC (ePrivacy Directive).
  • The United Kingdom Data Protection Act 2018 and UK GDPR.
  • United Arab Emirates Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and Dubai International Financial Centre (DIFC) Data Protection Law No. 5 of 2020.
  • The California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA).

3. Categories of Personal Data Collected

Depending on your interaction with the Aera platform, we collect and process the following categories of data:

Data Category Specific Data Points Source & Purpose
Contact & Inquiry Data First and last name, corporate email address, telephone/WhatsApp number, developer or brokerage firm name, geographic territory of interest (e.g. Milan, UAE), and project specifications. Provided directly by you via our contact request forms, demo requests, and Cal.com appointment bookings.
Interactive Telemetry & Device Data IP address (anonymized where feasible), browser type and version, operating system, device screen resolution, GPU capabilities (for 3D WebGL streaming optimization), time zone, and language preferences. Collected automatically during your navigation and interaction with our 3D walkthrough engine and website assets.
Scheduling & Communication Logs Meeting date, timestamp, selected time slot, virtual conference room links, and correspondence notes provided during call booking via Cal.com or WhatsApp. Facilitating synchronized live presentation sessions and commercial consultations.
Cookie & Consent Preferences Consent timestamps, chosen cookie preference state (essential, analytics, functional, marketing), and local session tokens. Maintained locally within your browser to respect and demonstrate your privacy choices.

No Sensitive Data: Amalfi Labs does NOT collect, store, or process any Special Categories of Personal Data (such as biometric identifiers for identification, racial origin, political opinions, health data, or religious beliefs).

4. Purposes & Legal Bases for Processing (GDPR Art. 6)

Under European and international data protection laws, every processing operation must rely on a recognized legal justification:

  • Performance of a Contract or Pre-Contractual Steps (Art. 6(1)(b) GDPR): To schedule and execute 3D property demonstrations, respond to your inquiries, deliver commercial proposals, and administer our platform services.
  • Legitimate Interests (Art. 6(1)(f) GDPR): To secure our web infrastructure, monitor server performance, optimize 3D WebGL render delivery, and protect our proprietary software and IP against fraud or misuse.
  • Consent (Art. 6(1)(a) GDPR): To activate optional non-essential performance cookies, analytical measurement tools, and personalized communications. You retain the absolute right to revoke consent at any time.
  • Compliance with Legal Obligations (Art. 6(1)(c) GDPR): To satisfy statutory bookkeeping, tax reporting, and regulatory audit standards in Italy and the UAE.

5. Sub-Processors & Third-Party Services

We work exclusively with certified, enterprise-grade cloud providers who adhere to strict data protection agreements:

  • Hosting & Edge Network: Vercel Inc. (Global CDN and secure serverless hosting).
  • Meeting & Demonstration Scheduling: Cal.com Inc. (Open-source, privacy-first appointment infrastructure; TLS encrypted).
  • Direct Client Communication: WhatsApp Ireland Ltd. / Meta Platforms Inc. (End-to-end encrypted messaging channels for sales & support).
  • Interactive 3D Engine & Asset Streaming: Cloudflare Inc. & AWS (Global edge distribution of encrypted real-time 3D walkthrough assets).

6. Cross-Border Data Transfers

As a luxury real estate solution operating between Europe (Milan) and the United Arab Emirates (Dubai / Abu Dhabi), your data may be processed in countries outside your country of residence.

Where personal data originating in the European Economic Area (EEA) or UK is transferred to jurisdictions that have not received an adequacy decision from the European Commission, Amalfi Labs executes standard contractual clauses (Standard Contractual Clauses - SCCs) and implements supplementary technical encryption measures to ensure an equivalent level of protection.

7. Retention & Data Deletion Policy

Personal data is retained only for the duration strictly necessary to fulfill the purposes for which it was gathered:

  • Commercial Inquiries & Demo Requests: Retained for a maximum of 24 months following the last active communication, unless an ongoing enterprise agreement is executed.
  • Scheduling Logs: Automatically archived after 12 months following completion of the scheduled demo session.
  • Technical Server & Security Logs: Retained for up to 90 days for network threat mitigation, then permanently expunged.

8. Your Data Subject Rights (GDPR & UK GDPR)

Under Chapters III of the GDPR and UK GDPR, you are guaranteed the following statutory rights:

Right of Access (Art. 15)

Obtain confirmation of whether your data is being processed, and request a structured copy of your records.

Right to Rectification (Art. 16)

Request correction of inaccurate, obsolete, or incomplete personal records without undue delay.

Right to Erasure ("Forgotten", Art. 17)

Request the complete deletion of your data when it is no longer required or where consent has been withdrawn.

Right to Restriction (Art. 18)

Restrict the scope of processing where accuracy is contested or processing lawfulness is challenged.

Right to Data Portability (Art. 20)

Receive your personal data in a structured, commonly used, machine-readable format (JSON/CSV).

Right to Object & Withdraw (Art. 21)

Object to processing grounded in legitimate interests, and revoke consent at any moment free of charge.

To exercise any of these rights, submit a Data Subject Access Request (DSAR) to: privacy@amalfilabs.art. We respond to all verified requests within thirty (30) calendar days.

9. United Arab Emirates PDPL Disclosures

In accordance with UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection:

  • You have the right to request access to the information Amalfi Labs maintains regarding your professional profile and developer requirements.
  • You have the right to restrict or stop data processing where marketing communications exceed the scope of your agreed property consultation.
  • Complaints regarding UAE-based processing may be directed to our UAE Data Representative at privacy@amalfilabs.art or to the UAE Data Office.

10. California Privacy Rights (CCPA / CPRA)

For California residents accessing our site:

  • No Sale or Sharing of Personal Information: Amalfi Labs has NOT sold, leased, or monetized personal information to third parties in the preceding 12 months, nor will we do so.
  • Right to Know & Delete: You may submit requests to know the specific pieces of information collected and request deletion without fear of discriminatory treatment.
  • Non-Discrimination: We do not alter platform pricing, demo access, or performance based upon whether you exercise your privacy rights.

11. Protection of Children's Privacy

Aera by Amalfi Labs is a B2B enterprise real estate sales solution engineered for real estate developers, architectural institutions, and brokerage firms. The website is not targeted to, nor intentionally intended for, individuals under sixteen (16) years of age. We do not knowingly gather data from minors.

12. Technical & Organizational Security Safeguards

We maintain comprehensive physical, administrative, and technological controls to preserve the integrity, confidentiality, and availability of our systems:

  • Full Transport Layer Security (TLS 1.3) encryption across all endpoints and web sessions.
  • Automated DDoS protection, rate limiting, and web application firewall (WAF) filtering.
  • Principle of least privilege (PoLP) and multi-factor authentication (MFA) required for internal administrative access.
  • Regular vulnerability testing and secure code reviews.

13. Inquiries, DPO Contact & Regulatory Authorities

If you have questions, feedback, or wish to exercise any statutory rights, contact our Data Protection Team directly:

Amalfi Labs Privacy & Data Governance Office

Email: privacy@amalfilabs.art

Physical Correspondence: Amalfi Labs Legal, Milan (Italy) & Dubai (UAE)

If you believe that your rights under GDPR have been infringed, you retain the right to lodge a formal complaint with a competent European Supervisory Authority, including the Garante per la protezione dei dati personali (Italy, www.garanteprivacy.it) or the supervisory body in your EU Member State.

© 2026 Aera by Amalfi Labs. All rights reserved.

Privacy Policy • Terms & Conditions • Cookie Policy •

Cookie Management Center

Customize your privacy preferences. Strictly necessary cookies cannot be disabled as they are required for core security, multilingual support, and spatial engine performance.

Strictly Necessary Always Active

Essential for core security, session routing, language preferences, and CSRF defense.

Performance & Analytics Optional

Aggregated anonymous telemetry measuring page load speed and WebGL rendering latency.

Functional & 3D Interactive Optional

Stores custom finish selections, camera positioning states, and Cal.com meeting parameters.

Marketing & Attribution Optional

Enables partnership referral attribution for luxury broker inquiries and developer events.