Privacy Policy

Privacy Policy

This Privacy Policy explains how BOFS Energy & Sustainability (“BOFS”, “we”, “us” or “our”) collects, uses, and protects personal data when you visit bofs-es.com or contact us. We are committed to handling your personal data in line with the EU General Data Protection Regulation (GDPR / RGPD) and applicable data protection laws. Please read this policy carefully to understand how we treat your information.

Last updated: 19 June 2026.

1. Who we are (data controller)

BOFS Energy & Sustainability is the data controller responsible for the personal data processed through this website. If you have any question about this policy or about how your data is handled, you can reach us using the details below.

BOFS Energy & Sustainability

IFZA, Dubai Silicon Oasis
Dubai, United Arab Emirates

Email: contact@bofs-es.com

Phone: +971 50 977 3760

For any privacy or data protection request, please use the email address above with the subject line “Privacy request”.

If you have any data protection question or wish to exercise your rights, you can contact us at contact@bofs-es.com and we will respond as required by applicable law.

2. What data we collect and why

We only collect the personal data we need to respond to you and to keep the website secure and functional. The categories below reflect what this website actually does today. We do not run advertising pixels, behavioural tracking, or a newsletter at this time.

2.1 Contact form

When you submit the contact form on our Contact page, we collect your name, email address, the subject of your message, and the content of your message. We use this data only to read and reply to your enquiry. The message is delivered to contact@bofs-es.com through our hosting provider’s secure email server.

2.2 Appointment booking

Our Contact page includes an embedded booking tool provided by Cal.com. If you choose to book a meeting through it, you provide details such as your name, email address, and your preferred time. This information is collected and processed by Cal.com so that we can confirm and hold the appointment. The booking tool loads only on the Contact page.

2.3 Map display

Our Contact page embeds a Google Maps view so you can locate us. When this map loads, Google may collect technical data such as your IP address and device information. This is governed by Google’s own privacy practices, described in Section 4.

2.4 Server access logs

Like most websites, our hosting provider automatically records technical information each time a page is requested. This typically includes your IP address, browser type, the pages viewed, and the date and time of access. We use these logs to keep the website secure, diagnose problems, and prevent abuse. We do not use them to build profiles or identify individual visitors for marketing.

2.5 Functional cookie

Our website uses Polylang to manage language settings. It sets a single functional cookie (named pll_language) that remembers your chosen language so the site displays correctly. This cookie is strictly necessary for the site to work as expected and does not track you across other websites. We do not use analytics or advertising cookies. Our SEO tooling (Yoast SEO) does not add tracking or analytics by default.

3. Legal bases for processing

Under the GDPR, we must have a valid legal basis for each use of your personal data. We rely on the following:

  • Consent (Article 6(1)(a)). When you choose to send us a message through the contact form or book a meeting through Cal.com, you do so voluntarily. Loading the Google Maps and Cal.com embeds, which may set their own cookies, also relies on your consent where required.
  • Legitimate interest (Article 6(1)(f)). We process server access logs to keep the website available and secure, to prevent fraud or abuse, and to maintain the technical integrity of the service. We balance this interest against your rights and freedoms.
  • Legal obligation (Article 6(1)(c)). In limited cases we may process or retain data where the law requires us to do so.

The Google Maps and Cal.com embeds are blocked by our cookie consent banner and do not load until you accept, so they are placed only with your consent.

4. Third parties and service providers

We work with a small number of trusted providers who process data on our behalf or as independent controllers for their part of the service. Some of these providers may process data on servers located outside the European Union.

  • OVH (web hosting). Our website and its server logs are hosted by OVH on infrastructure located in France (EU). OVH stores the site files, the database, and the access logs.
  • Cal.com (appointment booking). The booking embed on our Contact page is operated by Cal.com. Any details you enter to schedule a meeting are processed by Cal.com to manage the appointment. Cal.com may process data outside the EU.
  • Google (Google Maps). The map embed on our Contact page is provided by Google. When the map loads, Google may receive technical data such as your IP address. Google may process data outside the EU.

Each of these providers maintains its own privacy policy describing how it handles data. We do not sell your personal data, and we do not share it with third parties for their own marketing purposes.

5. International data transfers

Our website and its server logs are hosted within the European Union, in France, by OVH. BOFS itself is established in Dubai, United Arab Emirates, so personal data you send to us (for example through the contact form) may be accessed by our team from outside the EU. In addition, the Cal.com booking tool and the Google Maps display may transfer data to servers located outside the EU.

Where personal data is transferred outside the European Economic Area, we take reasonable steps to ensure it remains protected, including relying on the safeguards offered by these providers, such as standard contractual clauses or equivalent measures where applicable.

6. How long we keep your data

We keep personal data only for as long as we need it for the purpose it was collected, and then we delete or anonymise it.

  • Contact form messages are kept for as long as needed to handle your enquiry and any follow-up, and then for a reasonable period for our records, after which they are deleted.
  • Booking details are retained for the period necessary to manage and document the meeting, in line with Cal.com’s retention practices.
  • Server access logs are retained for a limited period for security and troubleshooting, then deleted or rotated by our hosting provider.

In practice, contact form messages are kept for up to 24 months after our last contact with you; booking details are retained for the period needed to manage and document the meeting plus a reasonable additional period; and server access logs are kept for up to 12 months. Once data is no longer needed for these purposes, it is deleted or anonymised.

7. How we protect your data

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. Our website is served over an encrypted HTTPS connection, contact messages are delivered through our provider’s secure email server, and access to data is limited to people who need it to respond to you. While no method of transmission over the internet is completely secure, we work to keep your information safe.

8. Your rights under the GDPR

If your personal data is processed by us, you have the following rights under the GDPR:

  • Right of access. You can ask whether we hold personal data about you and request a copy of it.
  • Right to rectification. You can ask us to correct data that is inaccurate or incomplete.
  • Right to erasure. You can ask us to delete your personal data where there is no overriding reason for us to keep it.
  • Right to restriction. You can ask us to limit how we use your data in certain circumstances.
  • Right to data portability. You can ask to receive certain data you provided to us in a structured, commonly used, machine readable format.
  • Right to object. You can object to processing that we carry out on the basis of legitimate interest.
  • Right to withdraw consent. Where we rely on your consent, you can withdraw it at any time, without affecting processing carried out before the withdrawal.
  • Right to lodge a complaint. You can complain to a data protection supervisory authority if you believe your rights have been breached.

How to exercise your rights

To exercise any of these rights, please email us at contact@bofs-es.com with the subject line “Privacy request”. We may need to verify your identity before acting on your request, and we will respond within the timeframe required by law. There is normally no charge, although we may decline or charge for requests that are clearly unfounded or excessive.

If you are located in the EU, you also have the right to lodge a complaint with your local data protection supervisory authority if you believe your rights have been breached.

9. Children’s data

Our website and services are intended for businesses and professional audiences. They are not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

10. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the tools we use, or the law. When we make a material change, we will update the “Last updated” date at the top of this page. We encourage you to review this policy periodically.

11. Contact us

If you have any questions about this Privacy Policy or about how we handle your personal data, please contact us at contact@bofs-es.com or call +971 50 977 3760.

Scroll to Top