Privacy policy

Website: https://emdra.co
Effective date: 29 August 2026
Last updated: 29 August 2026

This Privacy Policy explains how EMDRA MARKETING - FZCO (“EMDRA”, “we”, “us”, “our”) collects, uses, stores, and shares personal data when you visit emdra.co, submit an application, or otherwise contact us.

1. Who is responsible

The controller of your personal data is:

EMDRA MARKETING - FZCO
IFZA Business Park, DDP
PO Box 342001
Dubai Silicon Oasis
Dubai, United Arab Emirates

Trade licence no. 30024 (Dubai Integrated Economic Zones Authority)

Contact for privacy requests
Email: [email protected]

We are a Dubai free-zone company. We offer marketing services (including video sales letters and related consulting) to coaches, consultants, and service businesses, including people in the EU/EEA and Switzerland (DACH). For those visitors, we treat the EU General Data Protection Regulation (GDPR) as applying alongside the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL).

We have not appointed a data protection officer. We have not appointed an EU/EEA representative under GDPR Article 27.

2. What this policy covers

This policy covers:

  • https://emdra.co and its pages (including /work-with-me)
  • Application and survey forms on those pages
  • Email, phone, and messaging that follow from an application or enquiry
  • Cookies and similar technologies on the site

It does not cover third-party websites we link to (including Meta/Facebook). Those sites have their own policies.

3. Personal data we collect

We only collect what we need to run the site, review applications, and deliver services.

3.1 Data you give us

On the application form at https://emdra.co/work-with-me we currently collect:

  • First name and last name
  • Email address
  • Phone number
  • Whether you run a coaching, consulting, or service business
  • How long you have run that business
  • Number of clients
  • Price of your main offer
  • Approximate close rate
  • Current monthly revenue range
  • How you get clients (organic content, referrals, paid ads, outbound, mix)
  • Your revenue or growth goal
  • Your main bottleneck
  • Paid-ads experience
  • Other yes/no or multiple-choice answers on that form

If you email, call, or message us, we also store the content of that conversation and any files you send.

If you become a client, we additionally process contract details, invoices, payment references, and the project materials needed to do the work.

3.2 Data collected automatically

When you visit the site, our hosting and security tools (HighLevel / LeadConnector and Cloudflare) typically log:

  • IP address
  • Date and time of the request
  • Pages and URLs visited
  • Referrer
  • Browser type and version
  • Device and operating system
  • Approximate location derived from IP
  • Cookie and pixel identifiers (see section 6)

3.3 Data from ads and analytics

The homepage uses the Meta (Facebook) Pixel, ID 800340246271413. Meta may collect or receive:

  • Pixel / cookie identifiers
  • Pages viewed and events (for example PageView)
  • Browser and device data
  • A hashed version of data you later submit (if we enable advanced matching)

We use this to measure ads, see which campaigns sent you here, and (where allowed) retarget visitors.

We did not find Google Analytics, Google Ads conversion tags, Google AdSense, TikTok, LinkedIn, Hotjar, or similar extra trackers on the live pages we checked on 29 August 2026. If we add any, we will update this policy.

3.4 Data we do not intentionally collect

We do not ask for special-category data (health, religion, politics, sexual orientation, biometrics). Please do not send it. We do not knowingly collect data from children under 18.

4. Why we use your data (purposes and legal bases)

Purpose Examples GDPR legal basis UAE PDPL basis
Run and secure the website Hosting, firewall, abuse prevention, error logs Legitimate interests (Art. 6(1)(f)): keep the site up and safe Processing needed to perform the service / legitimate interests
Review applications Read your form, decide if we take a call, reply Pre-contract steps (Art. 6(1)(b)); legitimate interests if you only enquire Processing to conclude or perform a contract
Deliver services VSL / marketing work, project communication Contract (Art. 6(1)(b)) Contract
Invoicing and tax Invoices, bookkeeping, TRN records Legal obligation (Art. 6(1)(c)) Legal obligation
Measure and improve ads Meta Pixel, campaign reporting, retargeting Consent where required (Art. 6(1)(a)); otherwise legitimate interests in measuring our own ads Consent / legitimate interests, as applicable
Send follow-up about your application Email or phone after you apply Pre-contract (Art. 6(1)(b)); consent for marketing that is not about that application Contract / consent
Defend legal claims Keep records if there is a dispute Legitimate interests (Art. 6(1)(f)) Legal claims

You can refuse cookies that are not strictly necessary. You can withdraw consent at any time without affecting processing that already happened.

If we ever send newsletters that are not a direct follow-up to an application, we will only do that with your consent or another lawful basis, and every message will have an unsubscribe path.

5. Who we share data with

We do not sell your personal data.

We share it with service providers who process it for us, under contract, only as needed:

Recipient Role Location
HighLevel Inc. / LeadConnector (leadconnectorhq.com, services.leadconnectorhq.com, backend.leadconnectorhq.com, stcdn.leadconnectorhq.com, images.leadconnectorhq.com, filesafe.space, msgsndr) Website / funnel hosting, forms, CRM, automations, file storage United States and other HighLevel regions
Cloudflare, Inc. Security and bot challenge on some pages (including the application form) Global / United States
Meta Platforms Ireland Ltd. / Meta Platforms, Inc. Facebook / Instagram ads and Pixel Ireland / United States
Google Ireland Ltd. / Google LLC Google Fonts loaded on the site Ireland / United States
Email and phone providers we use to answer you Delivery of messages and calls Depends on the tool in use
Professional advisers (lawyer, accountant) Only if needed for a matter that involves you As required
Authorities Only if the law requires it As required

If you become a client, payment and invoicing may go through our bank and, if we use one, a payment processor. The live application pages we checked do not take card payments.

Team members and contractors who help run EMDRA may see application and client data, only as needed for their work, under confidentiality.

6. Cookies and similar technologies

emdra.co is built on HighLevel. The site and the Meta Pixel set cookies and similar identifiers.

Strictly necessary
Needed to load the page, keep the form working, and protect it (including Cloudflare challenges). These run because the site cannot function without them.

Analytics and marketing
The Meta Pixel on the homepage sets cookies such as _fbp and may use the Facebook cookie _fbc if you arrive from a Meta ad. These help us measure and improve ads.

We do not currently show a full cookie banner that blocks the Pixel until you opt in. If you are in the EU/EEA/UK, you can:

7. International transfers

We are based in the UAE. Several processors (HighLevel, Meta, Google, Cloudflare) store or access data in the United States and other countries that may not have an EU adequacy decision.

Where GDPR applies, we rely on:

  • The processor’s Standard Contractual Clauses (or equivalent transfer tool), and
  • The fact that you started the transfer yourself when you submit a form to a UAE company

UAE PDPL transfer rules also apply to data we send out of the UAE.

8. How long we keep data

We keep data only as long as we need it for the purpose above, then delete or anonymise it.

Data Typical retention
Server / security logs A short technical period (usually days to a few months), unless needed for security
Meta Pixel events As long as Meta retains them under its own policy and our ad account settings
Unsuccessful or unused applications Up to 24 months after the last contact, then delete unless you ask us to delete sooner or we must keep them for a claim
Successful applications that become clients For the contract, then as long as tax and commercial law require (in the UAE this is commonly 7 years for accounting records)
Correspondence With the related application or client file

You can ask us to delete sooner. We will do that unless we must keep the record.

9. Your rights

Depending on where you live, you may have some or all of these rights:

  • Access – a copy of the data we hold about you
  • Rectification – fix inaccurate data
  • Erasure – delete data (“right to be forgotten”)
  • Restriction – pause certain processing
  • Portability – receive data you gave us in a common format
  • Object – object to processing based on legitimate interests, including profiling for ads
  • Withdraw consent – where we rely on consent
  • Complaint – complain to a supervisory authority

How to use them: email [email protected] with the subject “Privacy request”. Tell us what you want and enough detail to find you (name, email used on the form). We may need to verify it is you. We will answer without undue delay, and within one month where GDPR applies.

EU/EEA: you can complain to your local data protection authority (for example Österreichische Datenschutzbehörde in Austria, BfDI / a German Landesdatenschutzbehörde in Germany, or EDÖB in Switzerland).
UAE: you can complain to the UAE Data Office if you are not satisfied with our response.

We will not discriminate against you for exercising these rights.

10. Security

We use HTTPS, HighLevel’s access controls, and Cloudflare protection on the application flow. Access to the CRM is limited to people who need it. No method of transmission or storage is 100% secure. If we become aware of a breach that affects you and the law requires notice, we will tell you and the relevant authority.

11. Children

The site and our services are for adults. We do not knowingly collect personal data from anyone under 18. If you believe a child submitted data, email [email protected] and we will delete it.

12. Automated decisions

The application form is a survey. We use your answers to decide whether to offer a call. A human reviews applications. We do not make solely automated decisions that produce legal or similarly significant effects (GDPR Art. 22).

13. Third-party links and Meta

The homepage states that emdra.co is not part of Facebook and is not endorsed by Meta. If you click through to Instagram, Facebook, YouTube, or any other site, their privacy policy applies.

14. Changes

We will update this page when we change how we process data (for example a new tracker, a new form field, or a new processor). The “Last updated” date at the top will change. For material changes we will, where reasonable, also note them on the site or email applicants we are still in contact with.

15. How to contact us

Privacy and data requests: [email protected]

EMDRA MARKETING - FZCO
IFZA Business Park, DDP, PO Box 342001
Dubai Silicon Oasis, Dubai, United Arab Emirates

© emdra.co | All rights reserved.

Privacy policy

This site is not a part of the Facebook website or Facebook Inc. Additionally, This site is NOT endorsed by Facebook in any way. FACEBOOK is a trademark of FACEBOOK, Inc.