Legal

Privacy Policy

Legal entity
THE DESIGN TO MANUFACTURING CO FZCO
Registered address
OneJLT-05-121, DMCC-EZ1-1AB, Plot No: DMCC-EZ1-1AB, Jumeirah Lake Towers, Dubai, UAE
Effective date
1 May 2026
Last updated
1 May 2026

1. Who we are

This Privacy Policy explains how The Design to Manufacturing Co. collects, uses, stores, shares, and protects personal data through our website and related business-enquiry workflows.

The website is operated by THE DESIGN TO MANUFACTURING CO FZCO, trading publicly as The Design to Manufacturing Co.

Registered address: OneJLT-05-121, DMCC-EZ1-1AB, Plot No: DMCC-EZ1-1AB, Jumeirah Lake Towers, Dubai, UAE
Licence authority: Dubai Multi Commodities Centre / DMCC Free Zone
Trade licence number: DMCC-953014
Phone: +971 50 342 6059
Privacy contact: [email protected]
General contact: [email protected]

For personal data processed through the website, THE DESIGN TO MANUFACTURING CO FZCO is the data controller, or equivalent responsible organisation, unless a separate written agreement states otherwise.

2. Scope of this Privacy Policy

This Privacy Policy applies to personal data we process through our public website and related business-enquiry channels, including when you:

  • visit our website;
  • submit a contact form;
  • subscribe to a newsletter;
  • request or download a resource;
  • submit a consultation request;
  • submit a quote request;
  • upload a technical file for part review;
  • click an email or phone link;
  • interact with website analytics or consent tools; or
  • communicate with us about a website enquiry.

This Privacy Policy does not replace any separate non-disclosure agreement, project agreement, distribution agreement, purchase order, quote terms, manufacturer terms, data-processing agreement, employment notice, or other written contract that may apply to a specific relationship with us.

3. Business-use-only website

Our website is intended for business, professional, institutional, and organisational users. It is not directed at consumers, children, or minors.

Our primary target markets are the UAE, Saudi Arabia, and the GCC. The website may be accessible globally, but we do not actively target every jurisdiction. Enquiries from the EU, UK, US, or other regions outside our active commercial focus may be handled directly, declined, or referred to appropriate partners where suitable.

Our forms are intended for business email addresses. We may reject common personal email domains or otherwise decline submissions that do not appear to relate to a legitimate business enquiry.

If you submit personal data on behalf of your employer, client, institution, or another organisation, you confirm that you are authorised to do so.

4. Personal data we collect

We collect only the personal data that is reasonably needed for the purposes described in this Privacy Policy.

4.1 Identity and contact data

This may include first name, last name, full name, business email address, phone number, company name, institution name, job title, website, country, location, and related business-contact details.

4.2 Professional and organisational data

This may include institution type, industry, technology interest, strategic objective, business requirements, end-user status, end-user name, requested products, quantities, timeline, application area, manufacturing selections, material details, mission requirements, and project or programme context.

4.3 Enquiry and message data

This may include subject, topic, message text, notes, consultation details, quote-request details, resource interest, sales qualification information, source page, source label, event key, and related routing metadata.

Please do not include sensitive personal data in free-text fields unless it is strictly necessary for your enquiry.

4.4 Newsletter data

For newsletter signups, we may collect first name, business email, source path or source label, generated event key, subscription status, and related email-delivery or engagement data.

4.5 Resource-download data

For gated resources, we may collect business email, resource type or name, resource slug, source path or label, industry tags, technology tags, and related content-interest metadata. We use this to provide or reveal the resource and to understand relevant business interests.

4.6 Quote-request data

For quote requests, we may collect name, business email, phone, company, website, job title, location, end-user status, end-user name, requested products or items, quantities, industry, timeline, notes, accepted policy checkbox status, source metadata, and related sales-routing data.

Quotes are not generated automatically by the website. Quote requests are reviewed by our team.

4.7 Consultation-request data

For consultation requests, we may collect name, business email, phone, company, website, job title, location, institution type, topic, industry, strategic objective, notes, accepted policy checkbox status, source metadata, and related routing data.

4.8 Part-review and technical-file upload data

If you submit a part-review or technical-file upload, we may collect contact details, business email, company, manufacturing selections, quantities, material details, deadline, application or use case, mission requirements, file object key, upload ID, ETag, filename, file size, content type, upload status, source metadata, session identifiers, and related technical metadata.

Technical files may include CAD, 3D model, scan, additive-manufacturing assessment, or similar engineering files submitted for initial review.

We treat object keys, upload IDs, signed URL data, filenames, ETags, and similar upload metadata as sensitive technical metadata.

4.9 Website, analytics, and event data

Depending on your consent choices and the technologies enabled on the website, we may collect page views, page path, page location, page title, source or layout metadata, CTA clicks, email-link clicks, phone-link clicks, resource-download events, form-success events, upload-started events, upload-completed events, upload mode, file-size bucket, browser or device metadata, approximate location derived from technical signals, and consent-preference data.

Analytics events are not intended to include raw form contents, filenames, uploaded files, file contents, CAD contents, message text, quote notes, mission requirements, phone numbers, or business email addresses.

4.10 Security and abuse-prevention data

We may process IP-derived data, route buckets, request timestamps, rate-limiting signals, server logs, malware-scan results, upload-validation data, and other technical information needed to protect the website, prevent abuse, and troubleshoot operational issues.

5. How we collect personal data

We collect personal data directly from you when you submit forms, sign up for newsletters, request resources, ask for a quote, request a consultation, upload files, email us, call us, or otherwise communicate with us.

We also collect personal data or technical data automatically through website hosting, analytics tools, consent tools, localStorage, security controls, rate-limiting systems, malware scanning, and server logs.

We may receive personal data from service providers that support our website, CRM, email, automation, analytics, hosting, storage, and enquiry-routing workflows.

6. How we use personal data

Where applicable data-protection law requires a legal basis, we rely on one or more of the following bases, depending on the context: your consent; steps taken at your request before entering into a contract; our legitimate business interests; compliance with legal obligations; or another basis permitted by applicable law.

PurposeHow we use the dataBasis for processing
Responding to enquiriesTo route, review, and respond to business enquiriesPre-contract steps; legitimate business interests; user request
Consultation requestsTo assess your request, arrange a meeting, and provide relevant follow-upPre-contract steps; legitimate business interests; user request
Quote requestsTo assess requested products, quantities, end-user details, timeline, and sales suitabilityPre-contract steps; legitimate business interests; legal or commercial recordkeeping where applicable
Newsletter signupsTo send briefings, updates, and marketing communicationsConsent or business marketing permission, depending on applicable law
Resource downloadsTo provide or reveal gated resources and send relevant follow-upConsent; business marketing permission; legitimate interests in understanding business needs
Technical upload reviewTo conduct an initial human review of submitted files and arrange follow-up discussionUser request; pre-contract steps; legitimate business interests
Security and rate limitingTo protect the website, prevent abuse, detect malware, and maintain service integrityLegitimate interests; legal obligation where applicable
Analytics and website improvementTo understand website performance, content engagement, conversion events, and user journeysConsent where required; legitimate interests for limited privacy-preserving analytics where lawful
Google Analytics 4To measure consent-based website analytics and conversion eventsConsent
Legal and compliance recordsTo maintain records, enforce terms, respond to disputes, and comply with legal dutiesLegal obligation; legitimate interests

7. Forms, enquiries, newsletters, resource downloads, and quote requests

7.1 Business-enquiry forms

All public forms are treated as business-enquiry forms. We use form information to understand your request, route it internally, respond to you, and manage follow-up.

Our sales, engineering, operations, or leadership team may review your submission depending on the nature of the enquiry.

7.2 Newsletter signups

If you subscribe to our newsletter, we use your name, business email, source metadata, and subscription information to send briefings, updates, and marketing communications.

Submitting the newsletter form indicates that you agree to receive these communications. You can unsubscribe at any time.

7.3 Resource downloads

Some resources may be gated. When you provide a business email to access a gated resource, we may use your email, resource interest, industry tags, technology tags, and source metadata to provide or reveal the resource and to send relevant marketing or sales follow-up.

Resource access may be provided in exchange for a marketing opt-in. You can opt out later through the unsubscribe link in our emails or by contacting us.

7.4 General enquiries

For general enquiries, we may collect first name, last name, work email, institution type, strategic objective, subject or topic, message, and source metadata. We use this information to route and respond to the enquiry.

7.5 Consultation requests

For consultation requests, we may collect your contact details, company information, professional role, location, institution type, topic, industry, strategic objective, notes, accepted policy checkbox status, and source metadata. We use this to assess the request, prepare for the consultation, and contact you about next steps.

7.6 Quote requests

For quote requests, we may collect your contact details, company information, end-user status, end-user name, requested products or items, quantities, industry, timeline, notes, accepted policy checkbox status, and source metadata.

Quote requests may be entered into our CRM or business systems, including Odoo through a UAE service provider. Quotes are provided only in writing by our sales team and are subject to the expiry date and terms stated in the quote.

8. Technical-file uploads and part reviews

This section applies when you upload CAD, 3D model, scan, additive-manufacturing assessment, or similar technical files for part review.

8.1 Intended scope of the public upload workflow

The public part-review upload workflow is intended for ordinary business technical files and commercially sensitive information that you are authorised to submit.

It is not intended for material that goes beyond commercially sensitive business information, including classified material, export-controlled material, ITAR/EAR-controlled material, defence-sensitive material requiring special handling, medical or patient data, personal data embedded in technical files, highly confidential information, regulated-sector information requiring special controls, illegal material, infringing material, malware, or third-party confidential material submitted without authority.

If your file goes beyond commercially sensitive business information, contact us first and do not upload it until appropriate handling terms have been agreed in writing.

8.2 Purpose of upload review

Uploads are used for initial internal engineering review or assessment on your behalf. The purpose is to understand your enquiry, prepare for a discussion, identify possible manufacturing considerations, and determine whether we may be able to support you.

Uploading a file does not create a manufacturing agreement, engineering sign-off, certification, compliance opinion, regulatory approval, export-control clearance, NDA, or obligation for us to proceed.

8.3 Human review only

Technical files are reviewed by humans only. We do not use uploaded technical files for AI training.

8.4 No marketing or case-study use without approval

We do not use uploaded files, designs, technical details, or project information for marketing, public case studies, social media, presentations, or promotional materials unless you expressly approve that use in writing.

8.5 Upload route and metadata

The upload process may allow your browser to upload file bytes directly to secure, encrypted private object storage using a time-limited presigned URL. In that workflow, our application and workflow automation systems may receive signed URL data and metadata rather than the file bytes themselves.

We may process upload metadata including object keys, upload IDs, ETags, filenames, file size, content type, session IDs, business email, source metadata, upload-started events, upload-completed events, and malware-scan or validation results.

Presigned URLs, object keys, and upload identifiers are confidential technical access mechanisms and should not be shared publicly.

8.6 Retention of uploads

Uploaded files are normally retained for up to 7 days if the enquiry does not progress. If the enquiry becomes an active discussion, agreed review, quote, project, or written arrangement, related files and metadata may be retained for the period reasonably necessary to manage that relationship, comply with legal obligations, or protect our legitimate interests.

9. Cookies and Similar Technologies

This section is our website notice for cookies, localStorage, analytics, pixels, tags, and similar technologies. We do not maintain a separate Cookie Policy for the current website structure.

We use localStorage to remember your analytics-consent choice. The consent key is:

d2m_analytics_consent

This storage is used to remember whether you accepted or rejected analytics. It does not intentionally store raw form content, uploaded files, filenames, or message text.

9.2 Umami

We use self-hosted Umami analytics. It operates as cookieless analytics in our current website configuration.

9.3 Vercel Analytics

We use Vercel Analytics and hosting telemetry to understand website performance, routing, and usage. Vercel may process technical information such as page and performance telemetry, request metadata, device or browser information, and related analytics signals, depending on configuration.

9.4 Google Analytics 4 and Google Tag Manager

We use Google Analytics 4, potentially through Google Tag Manager, only after analytics cookies are accepted. GA4 may use cookies or identifiers to measure page views, user interactions, and website performance.

GA4 analytics events are not intended to include raw form contents, filenames, uploaded files, file contents, message text, quote notes, mission requirements, phone numbers, or business email addresses.

9.5 Rejecting or changing analytics choices

You can accept or reject analytics through the website banner. If you later want to change your choice and no privacy-preference control is available on the website, you can clear your browser cookies and localStorage for our website and choose again on your next visit.

10. Analytics events and measurement data

Subject to your consent choices and the tool configuration, analytics may include:

  • page views;
  • page path, location, and title;
  • CTA clicks;
  • form-success events;
  • resource-download events;
  • email-link clicks;
  • phone-link clicks;
  • upload-started events;
  • upload-completed events;
  • upload mode;
  • file-size bucket;
  • source, location, and layout metadata; and
  • general browser, device, or performance metadata.

Analytics events are not intended to include raw form contents, uploaded files, filenames, CAD or technical-file contents, message text, quote notes, mission requirements, phone numbers, or business emails.

We use analytics to understand which business content is useful, improve website performance, detect broken journeys, measure campaign effectiveness, and improve enquiry workflows.

11. Security, rate limiting, and abuse prevention

We use technical and organisational measures designed to protect personal data and technical files, including access controls, private object storage, encryption, malware scanning, upload validation, rate limiting, and operational logging.

In production, rate limiting may use Upstash Redis. Rate limiting may process IP-derived route buckets, request timestamps, and related abuse-prevention signals. We use this data to protect the website, not for marketing.

No website, storage system, transmission method, or security measure can be guaranteed to be perfectly secure. You should not upload material that goes beyond commercially sensitive business information unless we have first agreed appropriate handling in writing.

12. When we share personal data

We share personal data only where reasonably necessary for the purposes described in this Privacy Policy.

This may include sharing with website hosting providers, CMS providers, workflow automation tools, email marketing providers, object-storage providers, analytics providers, CRM or business-system providers, professional advisers, IT/security providers, and appropriate partners where an enquiry is better handled through a partner.

We may also share personal data where required by law, regulation, court order, government authority, dispute process, contract enforcement need, or to protect our rights, users, systems, or business.

We do not allow service providers to use personal data for their own independent marketing unless you have separately consented or the use is otherwise disclosed and lawful.

13. Third-party processors and service providers

We use the following categories of processors and service providers for the website and related workflows.

Provider or systemPurposeData involved
Sanity CMS / CDNWebsite content, images, resources, PDFs/files, CMS pagesPublic website content, public assets, resource files, CMS metadata
VercelWebsite hosting, deployment, logs, analytics, and telemetryIP addresses, request logs, routing data, device/browser metadata, performance data
n8nWorkflow automation and form routingForm payloads, source metadata, upload metadata
BrevoEmail marketing, newsletters, resource delivery, subscription managementNames, business emails, subscription status, resource interests, email engagement data
Cloudflare R2 / object storageTechnical-file upload storageFile bytes, filenames, content type, file size, object keys, ETags, upload IDs, upload metadata
Upstash RedisRate limiting and abuse preventionIP-derived route buckets, request timestamps, rate-limit signals
UmamiSelf-hosted cookieless analyticsPage and event analytics, technical metadata depending on deployment
Vercel AnalyticsWebsite analytics and performance telemetryPage, device, browser, performance, and usage telemetry depending on configuration
Google Analytics / Google Tag ManagerConsent-based analyticsPage path, page title, page location, GA identifiers or cookies, event data
Odoo through a UAE service providerCRM, quote handling, business recordsQuote-request contact, company, end-user, product, and enquiry details
Professional advisers and business partnersLegal, accounting, compliance, referral, partner fulfilmentRelevant business-contact, enquiry, and project information as needed

14. International processing and transfers

We are based in Dubai, UAE. Personal data may be processed in the UAE and in other countries where we or our service providers operate. This may include Germany and other locations depending on provider configuration, hosting, support access, backups, or routing.

Countries outside your location may have data-protection laws that differ from the laws where you are based. Where required, we use appropriate contractual, technical, and organisational safeguards for international processing and transfers.

Where Saudi Arabia’s Personal Data Protection Law applies to personal data relating to individuals residing in Saudi Arabia, we will take steps designed to ensure cross-border processing is handled in accordance with applicable Saudi requirements.

15. Retention

We keep personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law, contract, accounting requirements, tax requirements, audit needs, dispute handling, security, or legitimate business interests.

Data categoryRetention approach
Newsletter subscriber dataUntil you unsubscribe or the list is cleaned for inactivity. Suppression records may be retained as long as needed to honour opt-outs.
Resource-download lead dataUp to 24 months after the last meaningful interaction, unless converted into an active customer, project, quote, or business record.
General enquiry dataUp to 24 months after the last interaction, unless needed for ongoing business, legal, compliance, or dispute reasons.
Consultation-request dataUp to 36 months after the last interaction, unless converted into a project, customer, quote, or business record.
Quote-request and commercial recordsUp to 6 years after the last meaningful interaction, quote expiry, project closure, or relationship end, unless a longer period is required or permitted for legal, tax, accounting, audit, compliance, sanctions, export-control, or dispute reasons.
Accounting, tax, audit, and compliance recordsFor the minimum period required by applicable law, and where appropriate up to 6 years or longer if a legal obligation, audit, investigation, dispute, or regulatory requirement applies.
Part-review form metadataUp to 7 days if no follow-up occurs; longer if the enquiry becomes an active discussion, review, quote, project, or written arrangement.
Uploaded technical filesNormally deleted after up to 7 days if no follow-up or continuing project occurs; longer only where agreed, required, or reasonably necessary for an active review, quote, project, or written arrangement.
Upload logs, object keys, ETags, and troubleshooting metadataTypically 7 to 90 days for troubleshooting, security, and audit, unless connected to an active enquiry or project.
Rate-limiting and IP-derived dataFor the short period necessary for security and abuse prevention, typically 30 to 90 days.
Web analytics dataAccording to provider settings, typically up to 14 to 26 months unless aggregated or anonymised.
Server and hosting logsFor the shortest practical operational and security period, typically 30 to 90 days unless needed for security, legal, or incident-response reasons.
BackupsTypically 30 to 90 days before being overwritten or deleted in the ordinary backup cycle, unless a legal hold, incident, dispute, or business-continuity need requires longer retention.
Unsubscribe and suppression recordsAs long as needed to honour opt-outs and prevent unwanted marketing.
Legal and dispute recordsAs required or permitted by applicable law, contracts, tax/accounting duties, audits, investigations, or dispute needs.

Deletion from active systems and deletion from backups may occur on different schedules. Backup copies are normally overwritten or deleted through routine backup cycles.

16. Marketing choices and unsubscribe rights

You can unsubscribe from marketing emails at any time by using the unsubscribe link included in our emails or by contacting [email protected] or [email protected].

Unsubscribing from marketing does not stop transactional, service, legal, security, quote-related, or project-related communications where those communications are necessary for an existing relationship or enquiry.

17. Your privacy rights

Depending on where you are located and which laws apply, you may have rights over your personal data. These may include the right to:

  • access personal data we hold about you;
  • receive information about how we process personal data;
  • correct inaccurate or incomplete data;
  • request deletion or destruction of data where applicable;
  • object to or restrict certain processing;
  • withdraw consent where processing is based on consent;
  • opt out of marketing;
  • request portability where applicable; and
  • lodge a complaint with a competent data-protection authority where available.

For UAE, Saudi Arabia, GDPR/UK GDPR, California, and other US or international privacy regimes, rights may differ in scope, conditions, timing, exceptions, and terminology. We will respond to valid requests in accordance with applicable law.

To exercise your rights, contact [email protected]. We may need to verify your identity and authority before acting on a request, especially where the request relates to a business organisation, quote, uploaded technical file, or confidential enquiry.

18. No sale of personal information and no cross-context advertising sharing

We do not sell personal information.

We do not share personal information for cross-context behavioural advertising. If we introduce advertising pixels, remarketing tags, or similar advertising technologies in the future, we will update this Privacy Policy and provide any required consent or choice mechanism before using them.

19. Automated decision-making

We do not use personal data submitted through the website for automated decision-making that produces legal or similarly significant effects.

Technical controls such as rate limiting, spam prevention, upload validation, and malware scanning may operate automatically to protect the website and systems, but they are not used to make legal or similarly significant decisions about you.

20. Children and minors

The website is not intended for children or minors. We do not knowingly target, collect from, or market to children or minors through the website.

If you believe a child or minor has submitted personal data to us, contact [email protected].

21. Third-party websites

Our website may link to third-party websites, manufacturer pages, partner resources, social media platforms, or external content. We are not responsible for the privacy practices, content, security, or policies of third-party websites or platforms.

You should review the privacy information provided by those third parties before interacting with them.

22. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our website, technologies, service providers, legal requirements, or business processes.

The updated version will be posted on this page with a revised “Last updated” date. Where required by law, we will provide additional notice or request renewed consent.

23. Contact us

For privacy or data-protection requests, contact:

[email protected]

For general legal or business enquiries, contact:

[email protected]
+971 50 342 6059

Postal address:

THE DESIGN TO MANUFACTURING CO FZCO
OneJLT-05-121, DMCC-EZ1-1AB
Plot No: DMCC-EZ1-1AB
Jumeirah Lake Towers
Dubai, UAE