PDPL-compliant Privacy Policy (UAE)
Sahara Advisory (“we,” “our,” or “us”) is committed to protecting the privacy and personal data of our clients, visitors, and users (“you,” “your”). This Privacy Policy outlines how we collect, process, store, and protect your personal data in compliance with the UAE Personal Data Protection Law (PDPL) – Federal Decree-Law No. 45 of 2021.
By using our website, services, or digital products, you agree to the practices described in this Policy.
Personal Data We Collect
We may collect the following categories of personal data:
-
Identity & Contact Information: Name, email address, phone number, company name, job title
-
Payment Information: Payment details for membership or digital product purchases (processed securely via Stripe)
-
Professional Data: Business type, company registration details, visa requirements
-
Website Usage Data: IP address, browser type, operating system, pages visited, interaction with forms or digital products
-
Membership Data: Membership status, start and expiration dates, access rights
Purpose of Processing
We process your personal data for the following purposes:
-
To provide our services, memberships, and digital products
-
To manage payments, subscriptions, and invoicing
-
To communicate with you regarding services, membership updates, promotions, or inquiries
-
To analyze website usage, improve services, and optimize user experience
-
To comply with legal obligations under UAE law, including PDPL
Legal Basis for Processing
Under the PDPL, we process personal data based on one or more of the following legal grounds:
-
Consent: When you explicitly agree to the processing of your data (e.g., subscribing to newsletters or membership services)
-
Contractual necessity: To perform obligations arising from your engagement with us
-
Legal obligation: To comply with applicable laws and regulations in the UAE
-
Legitimate interest: To improve our services and website functionality, while respecting your rights
Data Retention
We retain personal data only as long as necessary to fulfill the purposes outlined in this Policy, or as required by law. Specific retention periods:
-
Membership records: Until membership expires and related financial obligations are settled
-
Payment data: For the duration required for financial and tax compliance
-
Contact and inquiry data: Up to 3 years, unless you request deletion
Your Rights
Under the PDPL, you have the right to:
-
Access your personal data
-
Correct inaccurate or incomplete data
-
Request deletion of your personal data
-
Withdraw consent for data processing where applicable
-
Object to processing based on legitimate interest