This policy explains, in plain language, what personal data Tend handles, why, where it is stored, and the choices you have. Nothing here is overstated.
Legal
Privacy Policy
Last updated 9 August 2026
1.Who we are
Tend provides AI-assisted WhatsApp lead handling, qualification and booking for real-estate agencies in the UAE. In this policy, “Tend”, “we” and “us” mean CodexaAI, the entity that operates tend.ae and contracts with our customers. For most data we handle, our agency clients are the data controller and Tend is the processor acting on their instructions. Privacy enquiries: privacy@tend.ae.
2.What data we process
We process only what is needed to run the service for an agency:
- Contact details a buyer shares on WhatsApp (name, phone number, message content).
- Enquiry details we extract to qualify a lead (budget, area, timeline, requirements).
- Agency data you connect: listings, inventory, calendar availability and team members.
- Account data for agency users (name, work email, role) and basic usage logs.
- Website analytics from visitors to our public marketing pages (pages viewed, referring site, approximate location, device and browser) — see “Cookies and similar technologies” below.
We do not sell personal data, and we do not use your leads to train third-party models.
3.How we use it
We use the data to answer and qualify enquiries, book viewings, route leads to the right agent, send reminders, and give agency owners reporting. WhatsApp messaging follows Meta’s WhatsApp Business policies: we treat a customer’s own first message to your number as opt-in, honour opt-out keywords in English and Arabic, and respect the 24-hour customer-care window.
4.AI processing
Replies are generated by an enterprise AI model, grounded in the agency’s own data, so answers reflect real listings and never invent a price. Prompts and content are processed to produce a response and are not used to train the underlying provider’s models.
5.Where data is stored
Tend runs on Amazon Web Services in the EU (Ireland) region, a GDPR-grade jurisdiction recognised for cross-border data transfer. Data is encrypted in transit (HTTPS) and at rest, and credentials such as WhatsApp tokens are held in a managed secrets store. Moving to the AWS UAE region is on our roadmap.
6.Sharing and sub-processors
We share data only with the providers required to deliver the service, each bound by contract to protect it. Our current sub-processors are:
- Amazon Web Services — cloud hosting and database (EU, eu-west-1).
- Meta Platforms — WhatsApp Business Platform (message delivery).
- Anthropic — AI model provider for assistant replies.
- OpenAI — embeddings used for knowledge-base search.
- Deepgram — voice-note transcription, where enabled.
- Stripe — subscription billing and payment processing.
- MailerSend — transactional and notification email.
- Google — Google Analytics 4, on the public marketing site only.
We disclose data if required by law. We will give notice before adding or replacing a sub-processor that materially affects how your data is handled.
7.Cookies and similar technologies
When you sign in to the Tend application we set one strictly necessary cookie (tend_session) that keeps you signed in. It holds your session token and nothing else — no tracking, no advertising, and it is never shared with a third party. It is marked HttpOnly, so scripts running in the page cannot read it, and it is sent only over HTTPS.
By default this cookie lasts only as long as your browser session and is deleted when you close the browser. If you tick “Keep me signed in” when signing in, it instead persists for one week, after which you will need to sign in again. Signing out deletes it immediately. This cookie is required for the application to function, so it cannot be switched off while you are using it — but it is only ever set once you sign in, never on our public marketing pages.
The Tend marketing site (tend.ae and its public pages) uses Google Analytics 4 to measure traffic — which pages are visited, how visitors arrive, and roughly where in the world they are. This sets first-party cookies in your browser and sends a pseudonymous identifier, your truncated IP address and page URL to Google. We use it to understand which content is useful, not to build advertising profiles: Google Signals, ads personalisation and audience-based remarketing are switched off.
Analytics runs on public marketing pages only. It is deliberately absent from the signed-in application, so pages containing leads, conversations and client records are never reported to Google.
If you reach us from an advertisement, we record the campaign parameters in that link (utm_*, and Google/Meta click identifiers) in your browser’s session storage, and attach them to a demo request so we know which campaign it came from. This is cleared when you close the tab. Submitting the demo form also records a conversion event in Google Analytics; it marks that a submission happened and does not include your name, email or message.
You can opt out with Google’s browser add-on, or by using any browser setting or extension that blocks analytics scripts. Blocking it does not affect how the site works.
The application itself uses browser storage strictly to keep you signed in and to remember interface preferences such as theme and sidebar state. These are essential to the service and are not used for advertising or cross-site profiling.
8.Legal bases and UAE PDPL
Where the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL) applies, we process personal data to perform our contract with the agency that engaged us and on the basis of our legitimate interest in operating and securing the service; consent is relied on for marketing messages. Where the GDPR applies, the same bases apply under Articles 6(1)(b), 6(1)(f) and 6(1)(a) respectively. For customer conversation data we act as processor, and the agency is the controller. For website analytics on our public marketing pages we are the controller and rely on legitimate interest in understanding how our site is used; where consent is required for analytics cookies in your jurisdiction, we will ask for it before setting them. The sign-in cookie described above is strictly necessary to deliver the service you have asked for, so it does not require consent.
9.Data processing agreement
A data processing agreement (DPA) covering our role as processor, the sub-processors listed above, security measures and international transfers is available on request. Email privacy@tend.ae and we will send the current version for signature.
10.Retention
We keep personal data only as long as it is needed to run the service for the agency, or as required by law. When an agency stops using Tend, its data can be exported and then deleted on request.
11.Your rights
You can request access to, correction of, or deletion of personal data, and an agency can export its leads and conversations at any time. To exercise a right, contact us or ask your agency, who acts as the controller for their contacts’ data.
12.Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected here with a new “last updated” date.
Questions about this page or how we handle data? Email hello@tend.ae.