Privacy Policy
Effective date: 1 July 2025
1. Introduction
Zentraxis Technologies L.L.C-FZ ("Zentraxis", "we", "us" or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose and safeguard personal data obtained through our website at zentraxis.com, our advisory services, and any other interactions you may have with us.
We operate in accordance with applicable data protection legislation, including the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), the General Data Protection Regulation (GDPR) where applicable, and other relevant international frameworks. Please read this policy carefully. By using our website or engaging our services, you acknowledge the practices described herein.
2. Information We Collect
We may collect the following categories of personal data:
- Contact and identity information: name, job title, organisation name, business email address, telephone number, and country of residence — provided when you complete our contact form, request a consultation, or correspond with us directly.
- Communications data: the content of emails, messages and enquiries you send to us, including your stated service interests and the details of your business challenge.
- Technical and usage data: IP address, browser type and version, operating system, referral source, pages visited, time spent on pages, and other diagnostic data collected automatically when you visit our website.
- Cookie data: session identifiers and preference data collected via cookies and similar tracking technologies. See our Cookie Policy for full details.
- Professional data: information about your organisation's regulatory environment, technology landscape, or security posture that you voluntarily share during an advisory engagement.
We do not collect sensitive personal data (such as health data, biometric data, or data relating to criminal convictions) unless specifically required for a contracted engagement and subject to your explicit consent.
3. How We Use Your Information
We use personal data for the following purposes and on the following legal bases:
- To respond to enquiries and provide advisory services — our legitimate interest in conducting business and our contractual obligation to deliver agreed services.
- To send service-related communications — including consultation confirmations, proposals, reports, and follow-up correspondence, based on contract performance or legitimate interest.
- To improve our website and services — analysing usage patterns and identifying areas for improvement, based on our legitimate business interests.
- To comply with legal and regulatory obligations — including anti-money laundering checks, sanctions screening, and record-keeping requirements applicable to professional advisory firms in the UAE and internationally.
- To send thought leadership and industry updates — only where you have provided explicit consent or where we have a legitimate interest and you have not objected. You may opt out at any time.
We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.
4. Cookies
Our website uses cookies and similar technologies to enhance your browsing experience, analyse site traffic, and support our security operations. Cookies are small text files placed on your device by your browser when you visit our website.
We use strictly necessary cookies (required for the website to function), analytical cookies (to understand how visitors use our site), and functional cookies (to remember your preferences). We do not use advertising or cross-site tracking cookies.
For full details on the cookies we use, how long they are retained, and how to manage your preferences, please refer to our Cookie Policy.
5. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, to maintain business records in accordance with applicable law, or to defend against legal claims. Our standard retention periods are as follows:
- Contact enquiries: 24 months from last interaction, unless converted to a client engagement.
- Client engagement records: 7 years from the conclusion of the engagement, in line with UAE commercial record-keeping requirements.
- Website analytics data: 26 months from collection, subject to anonymisation.
- Email correspondence: 3 years from the date of the last communication, unless related to an active matter.
At the end of the applicable retention period, personal data is securely deleted or anonymised in accordance with our internal data disposal procedures.
6. Third-Party Services
We engage trusted third-party service providers to support our operations. These providers act as data processors under our instruction and are contractually bound to protect your data. The categories of third-party processors we use include:
- Cloud infrastructure and hosting: our website is hosted on secure cloud infrastructure with industry-standard security controls.
- Email and communications platforms: we use enterprise-grade email services to send and receive business correspondence.
- Analytics services: we may use privacy-respecting analytics tools to understand website traffic and user behaviour in aggregate.
- Customer relationship management: we use CRM tools to manage client relationships and track engagement history.
We do not transfer personal data to third parties outside of our operational requirements. Where personal data is transferred internationally, we ensure appropriate safeguards are in place, including standard contractual clauses or adequacy decisions.
7. Security
Zentraxis operates as an enterprise cybersecurity advisory firm, and we apply the same security rigour to our own information handling that we recommend to our clients. We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, and destruction.
These measures include, but are not limited to: encryption of data in transit (TLS 1.2+) and at rest, access controls based on the principle of least privilege, multi-factor authentication for internal systems, and regular internal security reviews.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected individuals in accordance with applicable law.
8. Your Rights
Depending on your jurisdiction, you may have the following rights with respect to your personal data:
- Right of access: to request a copy of the personal data we hold about you.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data where we no longer have a lawful basis to hold it.
- Right to restriction: to request that we restrict the processing of your data in certain circumstances.
- Right to data portability: to receive your data in a structured, machine-readable format.
- Right to object: to object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time.
To exercise any of these rights, or to raise a concern about how we handle your data, please contact us at the address below. We will respond within 30 days. You also have the right to lodge a complaint with the relevant data protection authority in your jurisdiction.
9. Contact Information
If you have any questions, concerns, or requests relating to this Privacy Policy or our handling of your personal data, please contact us:
Meydan Grandstand, 6th Floor
Meydan Road, Nad Al Sheba
Dubai, United Arab Emirates
Email: contact@zentraxis.com
This Privacy Policy was last updated on 1 July 2025. We reserve the right to amend this policy at any time. Material changes will be communicated via our website. Continued use of our website or services following any update constitutes acceptance of the revised policy.