Legal
Privacy Policy
- Legal entity
- THE DESIGN TO MANUFACTURING CO FZCO
- Contact
- [email protected]
- Registered address
- OneJLT-05-121, DMCC-EZ1-1AB, Plot No: DMCC-EZ1-1AB, Jumeirah Lake Towers, Dubai, UAE
- Effective date
- 1 May 2026
- Last updated
- 1 May 2026
Contents
1. Who we are
This Privacy Policy explains how The Design to Manufacturing Co. collects, uses, stores, shares, and protects personal data through our website and related business-enquiry workflows.
The website is operated by THE DESIGN TO MANUFACTURING CO FZCO, trading publicly as The Design to Manufacturing Co.
Registered address: OneJLT-05-121, DMCC-EZ1-1AB, Plot No: DMCC-EZ1-1AB, Jumeirah Lake Towers, Dubai, UAE
Licence authority: Dubai Multi Commodities Centre / DMCC Free Zone
Trade licence number: DMCC-953014
Phone: +971 50 342 6059
Privacy contact: [email protected]
General contact: [email protected]
For personal data processed through the website, THE DESIGN TO MANUFACTURING CO FZCO is the data controller, or equivalent responsible organisation, unless a separate written agreement states otherwise.
2. Scope of this Privacy Policy
This Privacy Policy applies to personal data we process through our public website and related business-enquiry channels, including when you:
- visit our website;
- submit a contact form;
- subscribe to a newsletter;
- request or download a resource;
- submit a consultation request;
- submit a quote request;
- upload a technical file for part review;
- click an email or phone link;
- interact with website analytics or consent tools; or
- communicate with us about a website enquiry.
This Privacy Policy does not replace any separate non-disclosure agreement, project agreement, distribution agreement, purchase order, quote terms, manufacturer terms, data-processing agreement, employment notice, or other written contract that may apply to a specific relationship with us.
3. Business-use-only website
Our website is intended for business, professional, institutional, and organisational users. It is not directed at consumers, children, or minors.
Our primary target markets are the UAE, Saudi Arabia, and the GCC. The website may be accessible globally, but we do not actively target every jurisdiction. Enquiries from the EU, UK, US, or other regions outside our active commercial focus may be handled directly, declined, or referred to appropriate partners where suitable.
Our forms are intended for business email addresses. We may reject common personal email domains or otherwise decline submissions that do not appear to relate to a legitimate business enquiry.
If you submit personal data on behalf of your employer, client, institution, or another organisation, you confirm that you are authorised to do so.
4. Personal data we collect
We collect only the personal data that is reasonably needed for the purposes described in this Privacy Policy.
4.1 Identity and contact data
This may include first name, last name, full name, business email address, phone number, company name, institution name, job title, website, country, location, and related business-contact details.
4.2 Professional and organisational data
This may include institution type, industry, technology interest, strategic objective, business requirements, end-user status, end-user name, requested products, quantities, timeline, application area, manufacturing selections, material details, mission requirements, and project or programme context.
4.3 Enquiry and message data
This may include subject, topic, message text, notes, consultation details, quote-request details, resource interest, sales qualification information, source page, source label, event key, and related routing metadata.
Please do not include sensitive personal data in free-text fields unless it is strictly necessary for your enquiry.
4.4 Newsletter data
For newsletter signups, we may collect first name, business email, source path or source label, generated event key, subscription status, and related email-delivery or engagement data.
4.5 Resource-download data
For gated resources, we may collect business email, resource type or name, resource slug, source path or label, industry tags, technology tags, and related content-interest metadata. We use this to provide or reveal the resource and to understand relevant business interests.
4.6 Quote-request data
For quote requests, we may collect name, business email, phone, company, website, job title, location, end-user status, end-user name, requested products or items, quantities, industry, timeline, notes, accepted policy checkbox status, source metadata, and related sales-routing data.
Quotes are not generated automatically by the website. Quote requests are reviewed by our team.
4.7 Consultation-request data
For consultation requests, we may collect name, business email, phone, company, website, job title, location, institution type, topic, industry, strategic objective, notes, accepted policy checkbox status, source metadata, and related routing data.
4.8 Part-review and technical-file upload data
If you submit a part-review or technical-file upload, we may collect contact details, business email, company, manufacturing selections, quantities, material details, deadline, application or use case, mission requirements, file object key, upload ID, ETag, filename, file size, content type, upload status, source metadata, session identifiers, and related technical metadata.
Technical files may include CAD, 3D model, scan, additive-manufacturing assessment, or similar engineering files submitted for initial review.
We treat object keys, upload IDs, signed URL data, filenames, ETags, and similar upload metadata as sensitive technical metadata.
4.9 Website, analytics, and event data
Depending on your consent choices and the technologies enabled on the website, we may collect page views, page path, page location, page title, source or layout metadata, CTA clicks, email-link clicks, phone-link clicks, resource-download events, form-success events, upload-started events, upload-completed events, upload mode, file-size bucket, browser or device metadata, approximate location derived from technical signals, and consent-preference data.
Analytics events are not intended to include raw form contents, filenames, uploaded files, file contents, CAD contents, message text, quote notes, mission requirements, phone numbers, or business email addresses.
4.10 Security and abuse-prevention data
We may process IP-derived data, route buckets, request timestamps, rate-limiting signals, server logs, malware-scan results, upload-validation data, and other technical information needed to protect the website, prevent abuse, and troubleshoot operational issues.
5. How we collect personal data
We collect personal data directly from you when you submit forms, sign up for newsletters, request resources, ask for a quote, request a consultation, upload files, email us, call us, or otherwise communicate with us.
We also collect personal data or technical data automatically through website hosting, analytics tools, consent tools, localStorage, security controls, rate-limiting systems, malware scanning, and server logs.
We may receive personal data from service providers that support our website, CRM, email, automation, analytics, hosting, storage, and enquiry-routing workflows.
6. How we use personal data
Where applicable data-protection law requires a legal basis, we rely on one or more of the following bases, depending on the context: your consent; steps taken at your request before entering into a contract; our legitimate business interests; compliance with legal obligations; or another basis permitted by applicable law.
| Purpose | How we use the data | Basis for processing |
|---|---|---|
| Responding to enquiries | To route, review, and respond to business enquiries | Pre-contract steps; legitimate business interests; user request |
| Consultation requests | To assess your request, arrange a meeting, and provide relevant follow-up | Pre-contract steps; legitimate business interests; user request |
| Quote requests | To assess requested products, quantities, end-user details, timeline, and sales suitability | Pre-contract steps; legitimate business interests; legal or commercial recordkeeping where applicable |
| Newsletter signups | To send briefings, updates, and marketing communications | Consent or business marketing permission, depending on applicable law |
| Resource downloads | To provide or reveal gated resources and send relevant follow-up | Consent; business marketing permission; legitimate interests in understanding business needs |
| Technical upload review | To conduct an initial human review of submitted files and arrange follow-up discussion | User request; pre-contract steps; legitimate business interests |
| Security and rate limiting | To protect the website, prevent abuse, detect malware, and maintain service integrity | Legitimate interests; legal obligation where applicable |
| Analytics and website improvement | To understand website performance, content engagement, conversion events, and user journeys | Consent where required; legitimate interests for limited privacy-preserving analytics where lawful |
| Google Analytics 4 | To measure consent-based website analytics and conversion events | Consent |
| Legal and compliance records | To maintain records, enforce terms, respond to disputes, and comply with legal duties | Legal obligation; legitimate interests |
7. Forms, enquiries, newsletters, resource downloads, and quote requests
7.1 Business-enquiry forms
All public forms are treated as business-enquiry forms. We use form information to understand your request, route it internally, respond to you, and manage follow-up.
Our sales, engineering, operations, or leadership team may review your submission depending on the nature of the enquiry.
7.2 Newsletter signups
If you subscribe to our newsletter, we use your name, business email, source metadata, and subscription information to send briefings, updates, and marketing communications.
Submitting the newsletter form indicates that you agree to receive these communications. You can unsubscribe at any time.
7.3 Resource downloads
Some resources may be gated. When you provide a business email to access a gated resource, we may use your email, resource interest, industry tags, technology tags, and source metadata to provide or reveal the resource and to send relevant marketing or sales follow-up.
Resource access may be provided in exchange for a marketing opt-in. You can opt out later through the unsubscribe link in our emails or by contacting us.
7.4 General enquiries
For general enquiries, we may collect first name, last name, work email, institution type, strategic objective, subject or topic, message, and source metadata. We use this information to route and respond to the enquiry.
7.5 Consultation requests
For consultation requests, we may collect your contact details, company information, professional role, location, institution type, topic, industry, strategic objective, notes, accepted policy checkbox status, and source metadata. We use this to assess the request, prepare for the consultation, and contact you about next steps.
7.6 Quote requests
For quote requests, we may collect your contact details, company information, end-user status, end-user name, requested products or items, quantities, industry, timeline, notes, accepted policy checkbox status, and source metadata.
Quote requests may be entered into our CRM or business systems, including Odoo through a UAE service provider. Quotes are provided only in writing by our sales team and are subject to the expiry date and terms stated in the quote.
8. Technical-file uploads and part reviews
This section applies when you upload CAD, 3D model, scan, additive-manufacturing assessment, or similar technical files for part review.
8.1 Intended scope of the public upload workflow
The public part-review upload workflow is intended for ordinary business technical files and commercially sensitive information that you are authorised to submit.
It is not intended for material that goes beyond commercially sensitive business information, including classified material, export-controlled material, ITAR/EAR-controlled material, defence-sensitive material requiring special handling, medical or patient data, personal data embedded in technical files, highly confidential information, regulated-sector information requiring special controls, illegal material, infringing material, malware, or third-party confidential material submitted without authority.
If your file goes beyond commercially sensitive business information, contact us first and do not upload it until appropriate handling terms have been agreed in writing.
8.2 Purpose of upload review
Uploads are used for initial internal engineering review or assessment on your behalf. The purpose is to understand your enquiry, prepare for a discussion, identify possible manufacturing considerations, and determine whether we may be able to support you.
Uploading a file does not create a manufacturing agreement, engineering sign-off, certification, compliance opinion, regulatory approval, export-control clearance, NDA, or obligation for us to proceed.
8.3 Human review only
Technical files are reviewed by humans only. We do not use uploaded technical files for AI training.
8.4 No marketing or case-study use without approval
We do not use uploaded files, designs, technical details, or project information for marketing, public case studies, social media, presentations, or promotional materials unless you expressly approve that use in writing.
8.5 Upload route and metadata
The upload process may allow your browser to upload file bytes directly to secure, encrypted private object storage using a time-limited presigned URL. In that workflow, our application and workflow automation systems may receive signed URL data and metadata rather than the file bytes themselves.
We may process upload metadata including object keys, upload IDs, ETags, filenames, file size, content type, session IDs, business email, source metadata, upload-started events, upload-completed events, and malware-scan or validation results.
Presigned URLs, object keys, and upload identifiers are confidential technical access mechanisms and should not be shared publicly.
8.6 Retention of uploads
Uploaded files are normally retained for up to 7 days if the enquiry does not progress. If the enquiry becomes an active discussion, agreed review, quote, project, or written arrangement, related files and metadata may be retained for the period reasonably necessary to manage that relationship, comply with legal obligations, or protect our legitimate interests.
9. Cookies and Similar Technologies
This section is our website notice for cookies, localStorage, analytics, pixels, tags, and similar technologies. We do not maintain a separate Cookie Policy for the current website structure.
9.1 Consent preference storage
We use localStorage to remember your analytics-consent choice. The consent key is:
d2m_analytics_consent
This storage is used to remember whether you accepted or rejected analytics. It does not intentionally store raw form content, uploaded files, filenames, or message text.
9.2 Umami
We use self-hosted Umami analytics. It operates as cookieless analytics in our current website configuration.
9.3 Vercel Analytics
We use Vercel Analytics and hosting telemetry to understand website performance, routing, and usage. Vercel may process technical information such as page and performance telemetry, request metadata, device or browser information, and related analytics signals, depending on configuration.
9.4 Google Analytics 4 and Google Tag Manager
We use Google Analytics 4, potentially through Google Tag Manager, only after analytics cookies are accepted. GA4 may use cookies or identifiers to measure page views, user interactions, and website performance.
GA4 analytics events are not intended to include raw form contents, filenames, uploaded files, file contents, message text, quote notes, mission requirements, phone numbers, or business email addresses.
9.5 Rejecting or changing analytics choices
You can accept or reject analytics through the website banner. If you later want to change your choice and no privacy-preference control is available on the website, you can clear your browser cookies and localStorage for our website and choose again on your next visit.
10. Analytics events and measurement data
Subject to your consent choices and the tool configuration, analytics may include:
- page views;
- page path, location, and title;
- CTA clicks;
- form-success events;
- resource-download events;
- email-link clicks;
- phone-link clicks;
- upload-started events;
- upload-completed events;
- upload mode;
- file-size bucket;
- source, location, and layout metadata; and
- general browser, device, or performance metadata.
Analytics events are not intended to include raw form contents, uploaded files, filenames, CAD or technical-file contents, message text, quote notes, mission requirements, phone numbers, or business emails.
We use analytics to understand which business content is useful, improve website performance, detect broken journeys, measure campaign effectiveness, and improve enquiry workflows.
11. Security, rate limiting, and abuse prevention
We use technical and organisational measures designed to protect personal data and technical files, including access controls, private object storage, encryption, malware scanning, upload validation, rate limiting, and operational logging.
In production, rate limiting may use Upstash Redis. Rate limiting may process IP-derived route buckets, request timestamps, and related abuse-prevention signals. We use this data to protect the website, not for marketing.
No website, storage system, transmission method, or security measure can be guaranteed to be perfectly secure. You should not upload material that goes beyond commercially sensitive business information unless we have first agreed appropriate handling in writing.
12. When we share personal data
We share personal data only where reasonably necessary for the purposes described in this Privacy Policy.
This may include sharing with website hosting providers, CMS providers, workflow automation tools, email marketing providers, object-storage providers, analytics providers, CRM or business-system providers, professional advisers, IT/security providers, and appropriate partners where an enquiry is better handled through a partner.
We may also share personal data where required by law, regulation, court order, government authority, dispute process, contract enforcement need, or to protect our rights, users, systems, or business.
We do not allow service providers to use personal data for their own independent marketing unless you have separately consented or the use is otherwise disclosed and lawful.
13. Third-party processors and service providers
We use the following categories of processors and service providers for the website and related workflows.
| Provider or system | Purpose | Data involved |
|---|---|---|
| Sanity CMS / CDN | Website content, images, resources, PDFs/files, CMS pages | Public website content, public assets, resource files, CMS metadata |
| Vercel | Website hosting, deployment, logs, analytics, and telemetry | IP addresses, request logs, routing data, device/browser metadata, performance data |
| n8n | Workflow automation and form routing | Form payloads, source metadata, upload metadata |
| Brevo | Email marketing, newsletters, resource delivery, subscription management | Names, business emails, subscription status, resource interests, email engagement data |
| Cloudflare R2 / object storage | Technical-file upload storage | File bytes, filenames, content type, file size, object keys, ETags, upload IDs, upload metadata |
| Upstash Redis | Rate limiting and abuse prevention | IP-derived route buckets, request timestamps, rate-limit signals |
| Umami | Self-hosted cookieless analytics | Page and event analytics, technical metadata depending on deployment |
| Vercel Analytics | Website analytics and performance telemetry | Page, device, browser, performance, and usage telemetry depending on configuration |
| Google Analytics / Google Tag Manager | Consent-based analytics | Page path, page title, page location, GA identifiers or cookies, event data |
| Odoo through a UAE service provider | CRM, quote handling, business records | Quote-request contact, company, end-user, product, and enquiry details |
| Professional advisers and business partners | Legal, accounting, compliance, referral, partner fulfilment | Relevant business-contact, enquiry, and project information as needed |
14. International processing and transfers
We are based in Dubai, UAE. Personal data may be processed in the UAE and in other countries where we or our service providers operate. This may include Germany and other locations depending on provider configuration, hosting, support access, backups, or routing.
Countries outside your location may have data-protection laws that differ from the laws where you are based. Where required, we use appropriate contractual, technical, and organisational safeguards for international processing and transfers.
Where Saudi Arabia’s Personal Data Protection Law applies to personal data relating to individuals residing in Saudi Arabia, we will take steps designed to ensure cross-border processing is handled in accordance with applicable Saudi requirements.
15. Retention
We keep personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law, contract, accounting requirements, tax requirements, audit needs, dispute handling, security, or legitimate business interests.
| Data category | Retention approach |
|---|---|
| Newsletter subscriber data | Until you unsubscribe or the list is cleaned for inactivity. Suppression records may be retained as long as needed to honour opt-outs. |
| Resource-download lead data | Up to 24 months after the last meaningful interaction, unless converted into an active customer, project, quote, or business record. |
| General enquiry data | Up to 24 months after the last interaction, unless needed for ongoing business, legal, compliance, or dispute reasons. |
| Consultation-request data | Up to 36 months after the last interaction, unless converted into a project, customer, quote, or business record. |
| Quote-request and commercial records | Up to 6 years after the last meaningful interaction, quote expiry, project closure, or relationship end, unless a longer period is required or permitted for legal, tax, accounting, audit, compliance, sanctions, export-control, or dispute reasons. |
| Accounting, tax, audit, and compliance records | For the minimum period required by applicable law, and where appropriate up to 6 years or longer if a legal obligation, audit, investigation, dispute, or regulatory requirement applies. |
| Part-review form metadata | Up to 7 days if no follow-up occurs; longer if the enquiry becomes an active discussion, review, quote, project, or written arrangement. |
| Uploaded technical files | Normally deleted after up to 7 days if no follow-up or continuing project occurs; longer only where agreed, required, or reasonably necessary for an active review, quote, project, or written arrangement. |
| Upload logs, object keys, ETags, and troubleshooting metadata | Typically 7 to 90 days for troubleshooting, security, and audit, unless connected to an active enquiry or project. |
| Rate-limiting and IP-derived data | For the short period necessary for security and abuse prevention, typically 30 to 90 days. |
| Web analytics data | According to provider settings, typically up to 14 to 26 months unless aggregated or anonymised. |
| Server and hosting logs | For the shortest practical operational and security period, typically 30 to 90 days unless needed for security, legal, or incident-response reasons. |
| Backups | Typically 30 to 90 days before being overwritten or deleted in the ordinary backup cycle, unless a legal hold, incident, dispute, or business-continuity need requires longer retention. |
| Unsubscribe and suppression records | As long as needed to honour opt-outs and prevent unwanted marketing. |
| Legal and dispute records | As required or permitted by applicable law, contracts, tax/accounting duties, audits, investigations, or dispute needs. |
Deletion from active systems and deletion from backups may occur on different schedules. Backup copies are normally overwritten or deleted through routine backup cycles.
16. Marketing choices and unsubscribe rights
You can unsubscribe from marketing emails at any time by using the unsubscribe link included in our emails or by contacting [email protected] or [email protected].
Unsubscribing from marketing does not stop transactional, service, legal, security, quote-related, or project-related communications where those communications are necessary for an existing relationship or enquiry.
17. Your privacy rights
Depending on where you are located and which laws apply, you may have rights over your personal data. These may include the right to:
- access personal data we hold about you;
- receive information about how we process personal data;
- correct inaccurate or incomplete data;
- request deletion or destruction of data where applicable;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent;
- opt out of marketing;
- request portability where applicable; and
- lodge a complaint with a competent data-protection authority where available.
For UAE, Saudi Arabia, GDPR/UK GDPR, California, and other US or international privacy regimes, rights may differ in scope, conditions, timing, exceptions, and terminology. We will respond to valid requests in accordance with applicable law.
To exercise your rights, contact [email protected]. We may need to verify your identity and authority before acting on a request, especially where the request relates to a business organisation, quote, uploaded technical file, or confidential enquiry.
18. No sale of personal information and no cross-context advertising sharing
We do not sell personal information.
We do not share personal information for cross-context behavioural advertising. If we introduce advertising pixels, remarketing tags, or similar advertising technologies in the future, we will update this Privacy Policy and provide any required consent or choice mechanism before using them.
19. Automated decision-making
We do not use personal data submitted through the website for automated decision-making that produces legal or similarly significant effects.
Technical controls such as rate limiting, spam prevention, upload validation, and malware scanning may operate automatically to protect the website and systems, but they are not used to make legal or similarly significant decisions about you.
20. Children and minors
The website is not intended for children or minors. We do not knowingly target, collect from, or market to children or minors through the website.
If you believe a child or minor has submitted personal data to us, contact [email protected].
21. Third-party websites
Our website may link to third-party websites, manufacturer pages, partner resources, social media platforms, or external content. We are not responsible for the privacy practices, content, security, or policies of third-party websites or platforms.
You should review the privacy information provided by those third parties before interacting with them.
22. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our website, technologies, service providers, legal requirements, or business processes.
The updated version will be posted on this page with a revised “Last updated” date. Where required by law, we will provide additional notice or request renewed consent.
23. Contact us
For privacy or data-protection requests, contact:
For general legal or business enquiries, contact:
[email protected]
+971 50 342 6059
Postal address:
THE DESIGN TO MANUFACTURING CO FZCO
OneJLT-05-121, DMCC-EZ1-1AB
Plot No: DMCC-EZ1-1AB
Jumeirah Lake Towers
Dubai, UAE