P

Legal · PDPL Compliant

Privacy Policy

How Capital Tech collects, uses, and protects your personal data under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021).

Last Updated · 26 May 2026Effective · 26 May 2026
01

Who We Are

This Privacy Policy explains how [Entity Legal Name] (trading as “Capital Tech”, “we”, “us”, or “our”), a company registered in the United Arab Emirates with registered office at [Registered Address], processes your personal data when you visit [website URL] or contact us about our managed IT, cloud, or consulting services.

We act as the Data Controller for the personal data described below, in accordance with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “UAE PDPL”) and its Executive Regulations.

02

What Data We Collect

CategoryExamplesSource
Contact dataName, email, phone, company, job titleYou — via contact form, email, phone
Enquiry contentMessages, project briefs, attachments you sendYou
Technical dataIP address, browser type, device type, OS, referring URLAutomatic (server logs)
Usage dataPages visited, time on page, clicks, session durationCookies / analytics
CommunicationsRecords of calls, emails, and meetings with our teamYou and us

We do not intentionally collect special-category data (health, religion, biometric, etc.) and ask that you do not submit such data through the website.

03

Why We Process Your Data and Our Lawful Basis

Under Article 5 of the PDPL, we rely on the following lawful bases:

PurposeLawful Basis
Responding to your enquiry / quote requestYour consent and pre-contractual steps at your request
Delivering proposals, service information, and follow-upsLegitimate interest in operating our business
Website security, fraud prevention, server logsLegitimate interest in protecting our systems
Analytics to improve the websiteYour consent (via cookie banner)
Complying with UAE law (tax, AML, regulatory requests)Legal obligation
04

Who We Share Your Data With

We do not sell your personal data. We share it only with the following categories of recipients, under written agreements that require them to protect your data:

  • Hosting and infrastructure providers (e.g., our website host, email provider)
  • Analytics providers (only if you consent to analytics cookies)
  • Professional advisers (lawyers, auditors) where strictly necessary
  • UAE regulatory authorities when required by law

A current list of categories and named sub-processors is available on request at [privacy email].

05

International Transfers

Some of our service providers may process data outside the UAE. Where this happens, we ensure that the destination country is on the UAE Data Office’s list of jurisdictions with adequate protection, or we put in place appropriate safeguards (contractual clauses, binding corporate rules, or your explicit consent) in line with Articles 22–23 of the PDPL.

06

How Long We Keep Your Data

DataRetention
Enquiry / lead data (no contract follows)24 months from last contact
Client data (contract entered)7 years after contract end (UAE commercial records)
Server / security logs12 months
Marketing data after you unsubscribeSuppression list only — 5 years

After these periods, data is securely deleted or anonymised.

07

Your Rights Under the PDPL

Subject to Article 13 of the PDPL, you have the right to:

Access

View the data we hold about you

Correct

Fix inaccurate or incomplete data

Delete

Remove your data (subject to legal retention)

Restrict

Limit how we process your data

Object

Refuse certain processing activities

Withdraw Consent

Revoke consent at any time

Portability

Receive your data in a portable format

Complain

Escalate to the UAE Data Office

To exercise any right, email [privacy email]. We will respond within 30 days as required by the PDPL.

08

Cookies

We use cookies and similar technologies as described in our Cookie Notice [link]. You can accept, reject, or customise cookies via the banner shown on your first visit, and change your preferences at any time.

09

Security

We maintain administrative, technical, and physical safeguards appropriate to the risk — including encryption in transit, access controls, MFA on admin accounts, and regular reviews. No system is perfectly secure; in the event of a personal data breach affecting your rights, we will notify you and the UAE Data Office in line with Articles 9 and 21 of the PDPL.

10

Children

The website is not directed at children under 18, and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.

11

Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will:

  • Update the Last Updated date above
  • Maintain a change log at the bottom of this Policy
  • Notify you by email or website banner at least 30 days before the change takes effect, where the change affects you materially

Continued use of the website after the effective date of a change indicates you have read the updated Policy; it does not waive any rights you have under the PDPL.

12

Contact and Data Protection Officer

Data Controller

[Entity Legal Name]

Address

[Registered Address]

Email (general)

[email protected]

Email (privacy)

[privacy email]

Data Protection Officer

[DPO name / Privacy Lead]

Change Log

  • 26 May 2026 — Initial version.