Privacy Policy

Ebuild / MANA.Core

Effective date: 28 June 2026


1. Who we are (controller identity and contact)

This Privacy Policy explains how personal data is collected, used, shared, and protected when you use the Ebuild platform, the MANA.Core admin and web applications, and our website at manacore.co (together, the "Platform" and the "Services").

The party responsible for the Platform is:

Maksim Plashchynski, a sole professional licensed by the Free Zones Authority of Ajman (Licence No. 35981), registered at FL.H-01622, Ajman Free Zone C1 Building, Ajman, United Arab Emirates, trading as "Ebuild" and "MANA.Core" ("Ebuild", "we", "us").

Please note that the provider is currently an individual sole professional, not a company.

For all privacy matters — including to exercise your rights or raise a concern — contact us at maksimplashchynski@manacore.co or by post at the address above.

This Policy refers to the United Arab Emirates Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL") and its Executive Regulations as in force, and, where it applies to you, the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act as amended ("CCPA/CPRA").

We are established in Ajman Free Zone, which is a non-financial free zone with no separate data-protection regime of its own; we are therefore subject to the federal PDPL and its Executive Regulations as in force, and not to the DIFC or ADGM data-protection laws.


2. Scope of this Policy — and the two different roles we play

This Policy applies to personal data we handle as a controller — that is, where we decide why and how the data is processed. That covers:

  • the accounts, billing, and use of the Platform by real-estate developers who subscribe to our Services (each a "Developer", a/k/a "Customer") and their staff; and
  • visitors to our own website at manacore.co.

Important distinction for Buyer and lead data. A Developer uses the Platform to publish a buyer-facing site that we host for it (a "Public Site"), typically on an *.ebuild.estate Subdomain or a custom domain. When a person browsing a Public Site (a "Buyer") submits an enquiry, a lead, a reservation, or a Reservation Deposit contact, the Developer — not Ebuild — is the controller of that Buyer/lead data. The Developer decides why it collects that data and what it does with it. In relation to that data, Ebuild acts only as the Developer's processor, handling it on the Developer's documented instructions to operate the Services.

This means:

  • If you are a Developer, this Policy describes how we process your own account, billing, and usage data as a controller. Our processing of the Buyer/lead data you collect through your Public Site is governed instead by our Data Processing Addendum and by your instructions.
  • If you are a Buyer who submitted information through a Developer's Public Site, the Developer is responsible for that data as controller. Please consult that Developer's own privacy notice and direct your data-subject requests to the Developer. We will forward to the relevant Developer any request you send us about such data.

We do not re-use Buyer/lead data collected on behalf of Developers for our own independent purposes.


3. Categories of personal data we process

(a) Developer account and contact data — name, email address, password credentials (stored hashed), workspace and project names, role and permissions, profile details, and authentication data (including Google OAuth sign-in identifiers and any two-factor-authentication settings).

(b) Billing and subscription data — Subscription plan and status, billing contact, billing history and invoices, and payment-method tokens and references held at our payment processor. We do not receive or store full payment-card numbers; card data is handled directly by Stripe (see Section 6).

(c) Usage, product, and operational data — actions taken in the Platform, feature usage, presence/"online now" signals about Developer staff used for the operator console, audit-log entries, and support correspondence.

(d) Device and technical data — IP address, browser and device type, operating system, language, approximate location derived from IP, log data, and cookie or similar-technology identifiers (see Section 9).

(e) Analytics data — product-analytics events about how the Platform and our website are used.

(f) Buyer/lead data processed on behalf of Developers — names, contact details, enquiry and lead records, reservation and Reservation Deposit contact details, and analytics identifiers captured through Public Sites. As stated in Section 2, the Developer is the controller of this data and we process it as the Developer's processor. We describe it here only for transparency; the rest of this Policy (purposes, legal bases, rights) addresses the data for which we are the controller.

We do not intentionally collect special-category/sensitive personal data and ask that you do not submit it through the Platform.


4. Purposes for which we process personal data (as controller)

We process the personal data described in Section 3(a)–(e) to:

  1. create, operate, secure, and maintain your account and the Platform;
  2. provide the Services and the hosting of Public Sites you configure;
  3. process Subscriptions, billing, renewals, and related communications;
  4. authenticate users, prevent fraud and abuse, and maintain the security and integrity of the Platform (including multi-tenant isolation and audit logging);
  5. provide customer support and respond to your requests;
  6. operate our internal operator console and monitor service health, presence, and usage;
  7. understand and improve how the Platform and our website are used through product analytics;
  8. send service, security, billing, renewal, and price-change communications, and — where permitted — relevant product updates you can opt out of;
  9. comply with our legal, regulatory, accounting, and tax obligations; and
  10. establish, exercise, or defend legal claims.

5. Legal bases for processing

Where the PDPL and its Executive Regulations as in force apply, we process personal data on the bases they permit, including the performance of a contract with you, our legitimate business interests, compliance with a legal obligation, and — where required — your consent.

Where the GDPR applies, our legal bases are:

  • Performance of a contract (Art. 6(1)(b)) — to create and operate your account, deliver the Services, host your Public Sites, and process your Subscription and billing.
  • Legitimate interests (Art. 6(1)(f)) — to secure the Platform, prevent fraud and abuse, operate our operator console, understand and improve our Services, and send service-related and limited product communications. You may object to processing based on legitimate interests (see Section 11).
  • Legal obligation (Art. 6(1)(c)) — to meet accounting, tax, and other regulatory duties.
  • Consent (Art. 6(1)(a)) — for non-essential cookies/analytics and any optional marketing, where consent is required. You may withdraw consent at any time, without affecting processing already carried out.

Where the CCPA/CPRA applies, you have the rights described in Section 11. We do not sell personal data and do not share it for cross-context behavioural advertising.


6. Recipients and sub-processors

We share personal data with service providers who help us run the Platform. Each acts under contract and is permitted to use the data only to provide services to us. Our current sub-processors are:

Sub-processorPurposeIndicative location
StripePayment processing and Subscription billing; Developer Stripe Connect onboarding for Reservation DepositsUSA / EU
NeonManaged database hostingUSA / EU
VercelApplication and Public Site hosting and deliveryUSA / global edge
Cloudflare R2Media storage and content delivery (CDN)Global edge
ResendTransactional and notification email deliveryUSA
GoogleOAuth sign-in (authentication)USA / global

We maintain a current sub-processor list and provide advance notice of changes to Developers as described in our Data Processing Addendum. We may also disclose personal data to professional advisers, and to courts, regulators, or competent authorities where required by law or to establish, exercise, or defend legal claims, in each case as permitted by applicable law.

Reservation Deposits / payments. Where a Developer enables Reservation Deposits, Buyers pay the Developer's own connected Stripe account directly. The Developer is the merchant of record and the controller of that payment data, and Stripe acts as the Developer's processor. Ebuild holds no funds and does not receive Buyer payment-card data.


7. International transfers

We and our sub-processors process personal data outside the United Arab Emirates, including in the United States and the European Union. The UAE is not currently on the EU list of countries recognised as providing an adequate level of data protection.

Where personal data is transferred internationally, we rely on the transfer mechanisms and appropriate safeguards permitted under applicable law:

  • under the GDPR, on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), supported by appropriate technical and organisational measures and a transfer assessment; and
  • under the PDPL and its Executive Regulations as in force, on the lawful transfer bases they permit (including contractual necessity, appropriate contractual safeguards, or your consent).

We keep a record of our transfer assessments. You may contact us at maksimplashchynski@manacore.co for more information about the safeguards that apply.


8. Retention

We keep personal data only for as long as necessary for the purposes set out in this Policy, and then delete or anonymise it, taking into account:

  • the life of your account and Subscription, plus a reasonable wind-down period;
  • legal, accounting, and tax retention requirements (for example, billing and invoice records);
  • the need to resolve disputes and enforce our agreements; and
  • security, audit, and fraud-prevention needs.

When your account or a Developer Subscription ends, we apply a post-termination export window for the Developer's own raw data as described in our Terms and Data Processing Addendum, after which the relevant personal data is deleted or anonymised on our normal deletion cycle. Backups are overwritten on a rolling basis and held beyond use until overwritten.


9. Cookies and analytics

We and our providers use cookies and similar technologies for purposes that are strictly necessary (such as authentication, security, and load balancing) and, subject to consent where required, for product analytics.

We use our own first-party analytics — usage data stored in our own database and not shared with a third-party analytics provider — to understand how the Platform and the sites we host are used. Where consent is required for any non-essential cookies, we ask for it through a consent mechanism and you can change or withdraw your choice at any time.

You can opt out of non-essential analytics by adjusting your choices in our cookie/consent controls where shown, and you can control cookies through your browser settings. Blocking strictly necessary cookies may prevent parts of the Platform from working.

Public Sites hosted for Developers may use their own cookie and consent configuration; the Developer is responsible for the cookie notice and lawful basis on its Public Site.


10. Automated decision-making

We do not carry out automated decision-making that produces legal or similarly significant effects concerning you within the meaning of GDPR Article 22. Any analytics or scoring we apply (for example, internal usage metrics) does not by itself make decisions that significantly affect you. Lead-scoring or similar logic surfaced inside a Developer's workspace is configured and used by the Developer as controller of that data.


11. Your rights

Subject to applicable law, you have the right to:

  • access the personal data we hold about you;
  • request rectification of inaccurate or incomplete data;
  • request erasure of your data;
  • request restriction of, or object to, certain processing (including processing based on our legitimate interests, and any direct marketing);
  • request portability of data you provided to us, in a structured, commonly used, machine-readable format; and
  • withdraw consent at any time where we rely on consent, without affecting prior processing.

Where the CCPA/CPRA applies, you also have the right to know, to delete, and to correct personal information, and not to be discriminated against for exercising your rights. We do not sell or share personal information as those terms are defined under that law.

To exercise any right, contact us at maksimplashchynski@manacore.co. We will respond within the timeframes required by applicable law and may need to verify your identity first. Exercising these rights is free unless a request is manifestly unfounded or excessive.

If you are a Buyer: for data you submitted through a Developer's Public Site, the Developer is the controller — please address your request to that Developer. If you contact us, we will forward your request to the relevant Developer.

We never condition the export or deletion of personal data on the payment of any outstanding fees.


12. Data security

We maintain technical and organisational measures that are reasonable and appropriate to the risk, including encryption of data in transit and at rest, access controls and least-privilege access, logical multi-tenant isolation between Developer workspaces, authentication safeguards, audit logging, and monitoring. While we work hard to protect personal data, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.


13. Personal data breaches

If a personal data breach occurs, we will assess it and act in accordance with the PDPL and its Executive Regulations as in force and, where applicable, the GDPR. Where we act as a processor for a Developer's Buyer/lead data, we will notify the affected Developer-controller without undue delay with the information it needs; the Developer is responsible for any notification to regulators or affected individuals. Where we are the controller, we will make any notifications required of us under applicable law. A notification is not an admission of fault or liability.


14. Children

The Services are intended for businesses and their professional users and are not directed to individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.


15. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a revised effective date and, where the change is material, take reasonable steps to notify you. Your continued use of the Platform after an update takes effect constitutes acceptance of the revised Policy, to the extent permitted by applicable law.


16. How to complain

We would like the chance to resolve your concern first, so please contact us at maksimplashchynski@manacore.co.

You also have the right to lodge a complaint with a supervisory authority:

  • in the United Arab Emirates, with the competent data-protection authority designated under the PDPL and its Executive Regulations as in force; and
  • in the EU/EEA or UK, with your local data-protection supervisory authority.

17. Contact

Maksim Plashchynski, sole professional (Licence No. 35981, Free Zones Authority of Ajman) FL.H-01622, Ajman Free Zone C1 Building, Ajman, United Arab Emirates Trading as Ebuild / MANA.Core Email: maksimplashchynski@manacore.co


Governing law: this Policy and any non-contractual obligations arising from it are governed by the federal law of the United Arab Emirates, and disputes are subject to the courts of Ajman, UAE.