Privacy policy
What we collect, why, and what you can make us do about it
Written against the UAE Personal Data Protection Law rather than copied from a template written for somewhere else. Short, because we collect very little.
Last reviewed
1. Who controls your data
WebSec FZCO, trading as RedTeam Security, licence number 67814, registered in the IFZA, Dubai Silicon Oasis Authority free zone, is the controller of the personal data described here. Contact [email protected] for anything in this document.
This policy is written against Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its implementing decisions, which is the regime that applies to us as a UAE-established company. Where an engagement brings another regime into play, that is handled in the engagement agreement rather than here.
2. What we collect
- Enquiry data. Your name, work email, company and whatever you type into the enquiry form or send us by email.
- Engagement data. For clients: contact details, scope documents, authorisation records, and the technical findings produced by the work.
- Technical data. Server logs containing IP address, user agent, requested URL and timestamp, kept for security and abuse investigation.
- Aggregate analytics. Cloudflare Web Analytics, which is cookieless and does not build a profile of you or follow you across sites.
We do not sell personal data, we do not run advertising or remarketing pixels, and we do not operate a tracking cookie. There is no cookie banner on this site because there is nothing to consent to.
3. Why we process it, and on what basis
Article 4 of Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data requires a lawful basis for each purpose. Ours are:
- To answer your enquiry and prepare a proposal. Steps taken at your request before entering a contract.
- To deliver an engagement and support it afterwards. Performance of a contract.
- To keep our own systems secure and investigate abuse. Our legitimate interest in defending infrastructure, balanced against your interests, which is why logs are minimal and short-lived.
- To meet accounting, tax and licensing obligations. Compliance with a legal obligation in the UAE.
- To send you something you asked to receive. Your consent, which you can withdraw at any time.
4. Who else sees it
Our hosting and network provider, our email provider, and, where an engagement requires it, professional advisers and auditors bound by confidentiality. Every processor is engaged under a written contract that limits them to our instructions.
We disclose personal data to a UAE authority only where a valid legal instrument compels it. Where we are lawfully permitted to tell you that has happened, we will.
We do not publish or share client findings. Reports, evidence and the fact of an engagement are confidential, which is also why this site names no client except the five who have given explicit permission.
5. Transfers outside the UAE
Some of our processors operate infrastructure outside the United Arab Emirates. Articles 22 and 23 of Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data permit a transfer where the destination has an adequate level of protection, or where appropriate contractual safeguards are in place. We rely on one or the other for every transfer, and we can tell you which applies to a given processor if you ask.
6. How long we keep it
- Enquiries that do not become engagements: twelve months, then deleted.
- Engagement records and reports: for the period agreed in the engagement, tied to the retest window, then destroyed. Retention is stated in writing before work starts rather than left open.
- Server logs: thirty days, unless a specific investigation requires holding a subset for longer.
- Records we must keep for tax and licensing: for the period UAE law requires, and no longer.
7. How we protect it
The controls you would expect from a security company: encryption in transit, access limited to the people working on your matter, screened personnel, dedicated engagement infrastructure destroyed at closure, and an ISO 27001 certified management system. No control set is absolute, and we do not claim otherwise.
8. If something goes wrong
Article 9 of Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data requires a controller to notify the UAE Data Office of a personal data breach that would prejudice the privacy, confidentiality or security of the data subject, and to notify affected individuals where the breach poses a risk to them. We will do both, without undue delay, and we will tell you what we know rather than what is comfortable.
9. Your rights
Under Articles 13 to 17 of Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data you may ask us to give you a copy of your data, correct it, delete it, restrict or stop a particular processing activity, transfer it to another controller in a structured format, or object to processing based on our legitimate interest. You may also withdraw consent where consent is what we rely on.
Write to [email protected]. We respond within thirty days. If we refuse, we tell you why. If you are not satisfied you may complain to the UAE Data Office.
One honest limit: where personal data forms part of the evidence in a client engagement, the client is the controller of that data and we act on their instructions. We will pass your request to them and tell you we have done so.
10. Children
This is a business-to-business site. Our services are not directed at children and we do not knowingly collect their data. If you believe we hold data about a child, write to us and we will delete it.
11. Changes
When this policy changes we update the reviewed date at the top. Material changes affecting an active engagement are notified to the client directly rather than left to be discovered on a web page.
See also our terms and conditions and our responsible disclosure policy.
The entity behind this document
WebSec FZCO, trading as RedTeam Security, licence number 67814, registered in the IFZA, Dubai Silicon Oasis Authority free zone. IFZA Business Park, Building A2, Nadd Hessa, Dubai Silicon Oasis, Dubai, United Arab Emirates.
Questions about this document: [email protected]. Privacy requests: [email protected]. Security reports: [email protected].
Questions about your data
Write to [email protected] and a person will answer, usually the same week.
Email [email protected]Nadd Hessa, Dubai Silicon Oasis
Dubai, United Arab Emirates