Privacy Policy

Learn how UAE Compliance Direct handles and protects your personal information.

1. Introduction

This Privacy Policy explains how personal information may be collected, used, stored, disclosed, transferred and protected when you:

  • visit www.uaecompliancedirect.com;
  • create or use an account;
  • contact the website by form, email, telephone, WhatsApp or another communication channel;
  • request eligibility guidance, document review or application support;
  • upload documents;
  • purchase or enquire about a service;
  • request SIRA, DHA, DataFlow, professional licensing, security licensing, certification, training or related compliance assistance; or
  • otherwise interact with the website or its services.

The website is an independent private consultancy and support service. It is not SIRA, DHA, DataFlow, Dubai Police or any other UAE government authority, and it is not affiliated with or endorsed by those authorities unless expressly stated otherwise.

The official authority, training centre, verification provider or other organisation involved in an application may have its own privacy policy and may independently determine how it processes information submitted to it.

2. Data Controller and Privacy Contact

For the purposes of applicable data protection law, the organisation responsible for the personal information described in this Privacy Policy may be identified through the contact details below:

Email: support@uaecompliancedirect.com
Telephone / WhatsApp: +44 20 4577 3361
Website: www.uaecompliancedirect.com

Where applicable law uses the terms Data Controller, Controller, Data Processor or similar terminology, the legal role depends on the particular processing activity.

In most cases where you directly request services through the website, the service provider determines why and how your information is processed and therefore acts as a controller.

When information is processed strictly on the documented instructions of another organisation, the service provider may instead act as a processor.

3. Applicable Data Protection Laws

Depending on your location, the location of the service provider, the services requested and where your information is processed, the handling of personal information may be subject to applicable privacy and data protection legislation, including:

Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data of the United Arab Emirates, together with applicable regulations, decisions and guidance;

and, where applicable,

UK data protection legislation, including the UK General Data Protection Regulation and the Data Protection Act 2018, as amended from time to time.

Other local privacy, consumer or sector-specific laws may apply depending on the nature of a particular service.

Nothing in this Privacy Policy is intended to reduce any rights granted to you under mandatory applicable law.

4. Personal Information That May Be Collected

The information collected depends on the service requested.

4.1 Identity and personal information

The following information may be collected:

  • full name;
  • date of birth;
  • nationality;
  • gender where required for an application;
  • photograph;
  • signature;
  • passport details;
  • passport copy;
  • Emirates ID information;
  • Emirates ID copy;
  • UAE visa information;
  • residence permit information;
  • immigration status; and
  • other official identification information necessary for the requested service.

4.2 Contact information

The following information may be collected:

  • email address;
  • telephone number;
  • WhatsApp number;
  • postal address;
  • country of residence;
  • preferred contact method; and
  • correspondence with the support team.

4.3 Professional and licensing information

Depending on the service, the following information may be collected:

  • occupation;
  • employer;
  • company name;
  • job title;
  • professional licence details;
  • trade licence information;
  • employment history;
  • professional experience;
  • educational qualifications;
  • degree certificates;
  • training certificates;
  • examination results;
  • professional registration information;
  • CV or résumé;
  • letters of experience;
  • eligibility information;
  • security-industry qualifications;
  • healthcare-professional qualifications;
  • DataFlow or Primary Source Verification information; and
  • information relating to previous or current applications.

4.4 Government and regulatory documentation

Where necessary for the requested service, documents or information may relate to:

  • SIRA;
  • Dubai Health Authority;
  • DataFlow Group;
  • Dubai Police;
  • UAE immigration or identity authorities;
  • Department of Economy and Tourism;
  • free-zone authorities;
  • professional regulatory bodies;
  • accredited training centres;
  • examination providers; and
  • other competent authorities or organisations.

4.5 Good-conduct and background information

Certain licensing services may require a Good Conduct Certificate, Police Clearance Certificate or similar record.

Where such information is provided, it is processed only where necessary to provide the requested service and subject to applicable legal requirements governing criminal-offence or similarly protected information.

4.6 Health and medical information

Some DHA, fitness, occupational, licensing or certification processes may require health-related information or documentation.

This may include, where relevant:

  • medical-fitness certificates;
  • health or occupational-fitness information;
  • professional medical licensing documents;
  • medical examination results; or
  • related records necessary for the requested service.

Health information may constitute sensitive or specially protected personal information under applicable law.

Such information will only be requested and processed where reasonably necessary and where an appropriate lawful basis and, where required, additional legal condition or consent exists.

4.7 Application and service information

The following information may be collected:

  • service selected;
  • application type;
  • eligibility answers;
  • uploaded files;
  • application status;
  • document-review comments;
  • missing-document information;
  • communications relating to a case;
  • appointment or training information;
  • examination information;
  • authority-reference numbers;
  • payment status; and
  • service history.

4.8 Payment and transaction information

When payment is enabled for a service, information may include:

  • amount paid;
  • currency;
  • transaction identifier;
  • payment status;
  • date and time of payment;
  • refund status;
  • invoice information; and
  • limited payment-provider information.

Payment-card or financial-account credentials are normally processed directly by the relevant payment provider rather than stored on the website's systems.

Full payment-card numbers, card security codes and online-banking credentials are not intended to be stored on the website's systems.

4.9 Technical and website information

When the website is used, certain information may be collected automatically, including:

  • IP address;
  • browser type;
  • device type;
  • operating system;
  • language;
  • approximate geographic region derived from an IP address;
  • referring website;
  • pages visited;
  • date and time of access;
  • session information;
  • authentication information;
  • error logs;
  • security logs; and
  • cookie or similar-technology identifiers.

4.10 Communications

If you make contact by email, telephone, WhatsApp, web form or another communication service, the content of that communication and related metadata may be retained where necessary to provide support, maintain records, prevent fraud or resolve disputes.

Calls are not recorded unless you are separately informed where recording is used and applicable consent and notice requirements are followed.

5. Information You Should Not Provide

Please do not send information that is not required for the selected service.

In particular, unless specifically requested for a legitimate application requirement, do not upload:

  • passwords;
  • PIN numbers;
  • card security codes;
  • online banking credentials;
  • unrelated medical records;
  • unrelated criminal records;
  • private documents belonging to another person without authority;
  • unnecessary biometric data; or
  • documents containing information irrelevant to the application.

Where practical, unnecessary information may be deleted, redacted or disregarded.

6. How Personal Information Is Collected

Personal information may be obtained:

Directly from you, including when you create an account, complete a form, upload a document, request assistance, contact support or make a payment.

From a person authorised by you, such as an employer, representative, company administrator or authorised agent.

From companies requesting services for their personnel, where they are legally authorised to provide the relevant information.

From service providers, such as payment processors, authentication providers or verification services.

From authorities or official sources, where legally permitted and necessary for the service.

Automatically, through website infrastructure, cookies, logs and security technologies.

If someone provides information about another individual, that person is responsible for ensuring that they have appropriate authority and a lawful basis to provide that information.

7. Why Personal Information Is Used

Personal information may be processed to:

7.1 Provide requested services

This includes:

  • identifying the service required;
  • assessing preliminary eligibility;
  • reviewing documentation;
  • identifying missing information;
  • providing application guidance;
  • preparing document checklists;
  • assisting with forms;
  • coordinating permitted application-support activities;
  • coordinating training or examination requirements;
  • responding to questions;
  • communicating updates;
  • managing an account; and
  • providing post-service assistance.

7.2 Prepare or support regulatory applications

Where included in the requested service and authorised by you, information may be used to assist with applications or interactions involving organisations such as SIRA, DHA, DataFlow, accredited training providers or other competent authorities.

The service provider does not control whether an authority accepts, rejects, delays or requests additional information regarding an application.

7.3 Verify information

Documents may be reviewed for apparent completeness, consistency and suitability for the requested service.

This review does not constitute government verification or guarantee that any document will be accepted by an authority.

7.4 Communicate with you

Contact information may be used to:

  • answer enquiries;
  • provide application updates;
  • request missing documents;
  • provide service notices;
  • communicate payment information;
  • provide customer support;
  • notify you of material changes affecting an active service; and
  • respond to complaints or requests.

7.5 Process payments and refunds

Transaction data may be processed to:

  • collect service fees;
  • confirm payment;
  • generate invoices or receipts;
  • administer refunds;
  • reconcile accounts;
  • prevent fraud; and
  • comply with accounting and tax obligations.

7.6 Operate and secure the website

Technical information may be processed to:

  • authenticate users;
  • maintain accounts;
  • protect uploaded documents;
  • prevent unauthorised access;
  • identify abuse;
  • investigate suspicious activity;
  • diagnose technical problems;
  • maintain service availability; and
  • improve security.

7.7 Improve services

Aggregated, statistical or appropriately de-identified information may be used to understand:

  • frequently requested services;
  • application difficulties;
  • website performance;
  • support requirements; and
  • areas where guidance can be improved.

Where information has been irreversibly anonymised so that it no longer identifies an individual, it is no longer treated as personal information to the extent permitted by applicable law.

7.8 Meet legal and regulatory obligations

Information may be processed and retained where necessary to:

  • comply with applicable laws;
  • respond to lawful government or regulatory requests;
  • maintain accounting records;
  • prevent fraud or misuse;
  • establish, exercise or defend legal claims;
  • investigate security incidents; or
  • comply with court orders or other lawful requirements.

8. Lawful Bases for Processing

Where applicable data protection law requires a lawful basis to be identified, processing may rely on one or more of the following.

Contract and pre-contractual steps

Information may be processed where necessary to provide a requested service or to take steps requested before entering into a service agreement.

Examples include eligibility review, document review, case administration, support and payment processing.

Consent

Consent may be relied upon where required or appropriate, particularly for certain optional processing activities or sensitive information.

Where processing is based on consent, consent may be withdrawn at any time. Withdrawal does not make earlier lawful processing unlawful.

Legal obligation

Information may be processed where necessary to comply with a legal or regulatory obligation.

Legitimate interests

Where permitted by applicable law, information may be processed for legitimate interests including:

  • operating and improving services;
  • securing systems;
  • preventing fraud;
  • administering customer relationships;
  • maintaining appropriate business records; and
  • establishing or defending legal claims.

Consideration is given to whether those interests are proportionate and whether privacy rights override them.

Vital or emergency interests

In exceptional situations, information may be processed where necessary to protect a person's life, physical safety or other vital interests and the law permits such processing.

Sensitive and specially protected information

Where health information, criminal-offence information or other sensitive personal information is processed, an additional legal condition required by applicable law will also be relied upon.

Where explicit consent is legally required, it will be sought before the relevant processing occurs.

9. When Personal Information Is Shared

Personal information is not sold to advertisers or data brokers.

Information may be shared only where reasonably necessary for the purposes described in this Privacy Policy.

Recipients may include:

Government and regulatory authorities

Where required for the requested service and authorised or otherwise lawfully permitted, information may be submitted to or shared with organisations such as:

  • Security Industry Regulatory Agency (SIRA);
  • Dubai Health Authority (DHA);
  • Dubai Police;
  • UAE identity or immigration authorities;
  • Department of Economy and Tourism;
  • relevant free-zone authorities; and
  • other competent government or regulatory bodies.

Once submitted to a government authority, that authority generally processes the information under its own legal powers and privacy arrangements.

Verification and professional service organisations

Depending on the service, information may be shared with:

  • DataFlow or other Primary Source Verification providers;
  • approved or accredited training centres;
  • examination centres;
  • professional regulatory bodies;
  • educational institutions where verification is authorised;
  • courier or document-delivery providers; and
  • other organisations required to complete the requested process.

Technology providers

Third-party providers may be used for:

  • website hosting;
  • cloud infrastructure;
  • authentication;
  • database services;
  • encrypted or access-controlled file storage;
  • email;
  • customer communications;
  • cybersecurity;
  • error monitoring;
  • document processing; and
  • backups.

Where such providers process personal information on behalf of the service provider, they are expected to process it subject to appropriate contractual, confidentiality and security obligations.

Payment providers

Payment providers process information required to facilitate transactions.

The payment provider's own privacy policy and terms may also apply to its processing.

Professional advisers

Information may be disclosed where reasonably necessary to:

  • lawyers;
  • accountants;
  • auditors;
  • insurers;
  • security advisers; or
  • other professional advisers,

subject to appropriate confidentiality obligations.

Legal requests

Information may be disclosed if required by law, court order or lawful regulatory request, or where reasonably necessary to protect rights, security or safety.

10. Government Authorities Are Separate Controllers

When information is submitted to SIRA, DHA, DataFlow, Dubai Police or another authority or external organisation, that organisation may act as an independent controller of the information it receives.

Its use and retention of information are governed by its own laws, policies and procedures.

The service provider cannot normally delete, amend or control records already lawfully submitted to another independent organisation.

If you wish to exercise rights over information held by such an organisation, you may need to contact that organisation directly.

11. International Transfers of Personal Information

Clients, support personnel, technology providers, cloud infrastructure, payment providers and service partners may be located in different countries.

As a result, personal information may be processed or stored outside the country in which you are located, including potentially outside the United Arab Emirates.

Where applicable data protection law restricts international transfers, appropriate steps will be taken to ensure that the transfer is legally permitted.

Depending on the circumstances, safeguards may include:

  • transferring information to a jurisdiction recognised as providing an adequate level of protection;
  • contractual data-protection safeguards;
  • contractual obligations requiring an overseas recipient to protect personal information to an appropriate standard;
  • obtaining consent where legally valid and appropriate;
  • transfers necessary to perform a contract or requested service where permitted by law; or
  • another transfer mechanism permitted by applicable data protection legislation.

You may contact the privacy address if you would like further information about safeguards applicable to a particular international transfer.

12. Document Uploads

Because many services involve official documentation, document security is particularly important.

When uploading documents:

  • use only the upload mechanism provided through the website or another communication method approved by the support team;
  • upload only documents relevant to the service;
  • do not publicly share upload links;
  • protect account credentials;
  • notify the support team immediately if you believe somebody has gained unauthorised access to your account or documents.

Where reasonably possible, access to uploaded application documents is restricted to personnel or providers who require access to perform authorised functions.

Documents should not be copied to personal devices or shared outside authorised workflows except where necessary to provide the requested service.

13. Data Security

Technical and organisational measures are used to protect personal information against:

  • unauthorised access;
  • accidental loss;
  • inappropriate disclosure;
  • alteration;
  • destruction; and
  • misuse.

Depending on the system and type of information, measures may include:

  • encrypted communications using HTTPS/TLS;
  • authentication and access controls;
  • role-based or need-to-know access;
  • restricted administrative permissions;
  • secure cloud infrastructure;
  • access logging;
  • security monitoring;
  • password controls;
  • multi-factor authentication where supported and appropriate;
  • backups;
  • confidentiality obligations;
  • secure deletion procedures; and
  • periodic review of access permissions.

No website, internet transmission or electronic storage system can be guaranteed to be completely secure. Absolute security cannot therefore be promised.

If a personal-data breach becomes known, it will be investigated and appropriate measures will be taken. Affected individuals and/or the relevant authority will be notified where notification is legally required.

14. Data Retention

Personal information is not intended to be kept indefinitely.

Retention depends on the type of information, the service provided, regulatory requirements, potential disputes and legal obligations.

The intended standard retention schedule is:

Enquiries and general support communications: normally up to 24 months after the last meaningful interaction.

Active application and case information: retained for the duration of the service.

Uploaded identity, licensing and supporting application documents: normally deleted or securely archived within 12 months after completion, cancellation or closure of the service, unless continued retention is reasonably necessary for another service requested by you, a dispute, legal obligation or documented business requirement.

Account information: retained while the account remains active and normally for up to 24 months after account closure or prolonged inactivity, subject to legal requirements.

Payment, invoice and accounting records: may be retained for up to 7 years, or any other period required under applicable accounting, tax or legal obligations.

Complaints and dispute records: normally retained for up to 6 years following resolution where reasonably necessary for legal claims or compliance.

Security and technical logs: normally retained for up to 12 months unless a longer period is required to investigate a security incident.

Marketing preferences: retained while you remain subscribed. A minimal suppression record may be retained after opt-out so that further marketing requests can be respected.

Backups: deleted information may remain temporarily in secure backup systems until those backups are overwritten according to the normal backup lifecycle.

Information may be retained for longer where reasonably necessary to comply with law, respond to an authority, resolve a dispute, investigate fraud or establish, exercise or defend legal claims.

Information may be deleted earlier where it is no longer reasonably necessary.

15. Privacy Rights

Depending on applicable law and the circumstances, you may have rights concerning your personal information.

These may include the right to:

  • obtain information about how personal information is processed;
  • request access to personal information held about you;
  • request correction of inaccurate or incomplete information;
  • request deletion where applicable;
  • request restriction or suspension of certain processing;
  • object to certain processing;
  • withdraw consent where processing relies on consent;
  • request transfer or portability of information where applicable;
  • object to direct marketing;
  • request information about certain automated processing; and
  • lodge a complaint with an applicable data-protection authority.

These rights are not always absolute.

For example, information may be required or permitted to be retained despite a deletion request where it is needed for legal obligations, the establishment or defence of legal claims or another lawful purpose.

To submit a privacy request, contact:

support@uaecompliancedirect.com

Please include “Privacy Request” in the subject line.

Information reasonably necessary to verify your identity may be requested before acting on a request. This is intended to prevent information from being disclosed or deleted at the request of an unauthorised person.

A response will be provided within the time required by applicable law.

16. Right to Object to Direct Marketing

You have the right to ask for your personal information to stop being used for direct marketing at any time.

You may:

Operational communications relating to an active service, security issue, account or transaction are not marketing communications and may continue where necessary.

17. Automated Decision-Making

Automated systems may be used to organise information, validate fields, route requests or assist with administrative processes.

Decisions producing legal or similarly significant effects on an applicant are not intended to be made solely through automated processing without meaningful human involvement unless the practice is separately disclosed and permitted by applicable law.

Eligibility information displayed by the website or automated tools is guidance only.

Final decisions regarding official licences, approvals, examinations, registrations or certifications are made by the relevant external authority or provider.

18. Cookies and Similar Technologies

The website may use cookies, browser storage and similar technologies.

These may include:

Strictly necessary technologies

Used for functions such as:

  • security;
  • authentication;
  • session management;
  • fraud prevention;
  • remembering essential service states; and
  • maintaining website functionality.

These may be required for the website to function correctly.

Preference technologies

These may remember settings such as language or user preferences.

Analytics technologies

If analytics are enabled, they may help understand website traffic, page performance and how visitors use the service.

Advertising or marketing technologies

If advertising or remarketing technologies are used in the future, appropriate notice will be provided and consent will be obtained where required by law.

Where applicable law requires consent for non-essential cookies, non-essential cookies should not be activated until the required consent has been obtained.

Cookies can be controlled through your browser and, where available, cookie-preference controls.

Disabling strictly necessary technology may prevent portions of the website from working.

A separate Cookie Policy may provide further information about individual technologies used on the website.

19. Marketing Communications

Promotional communications may be sent only where permitted by applicable law.

Email addresses or telephone/WhatsApp details may be used for marketing where:

  • the required consent has been provided;
  • applicable law otherwise permits the communication; or
  • another valid basis exists.

Consent to marketing is not a condition of receiving a licensing-support service.

You may opt out at any time.

Customer contact lists are not sold to third-party advertisers.

20. WhatsApp and Third-Party Communications

If you choose to communicate through WhatsApp or another third-party communication platform, the provider of that platform may independently process information according to its own privacy terms.

Please avoid sending unnecessarily sensitive documents through messaging platforms where a secure document-upload system is available.

For particularly sensitive application documents, you may be asked to use a designated secure upload facility instead.

21. Payment Providers

Payments may be processed through a third-party payment provider.

When a payment provider is used, information may be transmitted directly to that provider and processed under its own privacy policy.

The service provider normally receives transaction information such as:

  • customer identifier;
  • payment confirmation;
  • amount;
  • currency;
  • transaction ID;
  • payment status; and
  • refund information.

Full payment-card security credentials are not normally received or retained.

22. External Links

The website may contain links to:

  • SIRA;
  • DHA;
  • DataFlow;
  • Dubai Police;
  • training centres;
  • payment providers;
  • other government agencies; or
  • third-party websites.

The website is not responsible for the privacy practices, content or security of independent third-party websites.

You should review the privacy policy of any external site before submitting personal information.

23. Information About Other People

If you submit personal information about another person, including an employee or applicant, you confirm that you are authorised to provide that information and that its collection and use are lawful.

Where appropriate, you should provide the individual with this Privacy Policy.

Any person or organisation submitting information concerning employees remains responsible for complying with its own privacy and employment-law obligations.

24. Children

Professional licensing and compliance services are generally intended for adults.

The website and services are not directed at children under 18.

Personal information is not knowingly sought from children under 18 through ordinary service applications.

If you believe that a child has submitted personal information without appropriate authority, contact support@uaecompliancedirect.com so that the situation can be assessed and addressed.

25. Fraud, Misuse and Document Authenticity

Information may be investigated where there is a reasonable suspicion of:

  • fraudulent documents;
  • impersonation;
  • unauthorised account access;
  • payment fraud;
  • abuse of systems;
  • security threats; or
  • unlawful activity.

Where permitted or required by law, relevant information may be retained or disclosed to competent authorities, payment providers, cybersecurity providers or professional advisers.

Falsified documents or false regulatory applications are not knowingly supported.

26. Changes to Application Information

You are responsible for providing information that is accurate and reasonably complete.

If information changes while an application is being supported, the support team should be notified promptly.

You may request correction of inaccurate information held through the website or service.

Information already submitted to an independent government authority or external organisation may need to be corrected through that organisation's own process.

27. Sensitive Processing

Because some services may involve identity records, government documentation, health information, background information or large volumes of applicant documents, additional privacy and security safeguards may be assessed.

Where required by applicable law, this may include a data-protection impact assessment, appointment or involvement of a Data Protection Officer, additional access restrictions or other compliance measures.

28. Privacy Contact

The privacy contact is:

Privacy Team / Data Protection Contact
Email: support@uaecompliancedirect.com
Telephone / WhatsApp: +44 20 4577 3361

If a formal Data Protection Officer is appointed, the DPO's contact information will be published here.

29. Complaints

If you have a concern about how personal information is processed, please contact the privacy team first so that the matter can be investigated.

Email:

support@uaecompliancedirect.com

Subject:

Privacy Complaint

You may also have the right to complain to an applicable data-protection supervisory authority.

Depending on the applicable legal regime and circumstances, this may include the UAE Data Office or another competent UAE regulator.

Where UK data protection law applies, you may also have the right to complain to the UK Information Commissioner's Office (ICO).

Nothing in this section limits a right available to you under applicable law.

30. Changes to This Privacy Policy

This Privacy Policy may be updated to reflect:

  • changes to the services;
  • changes to technology;
  • new service providers;
  • new regulatory requirements;
  • changes in applicable privacy law; or
  • improvements to privacy practices.

When material changes are made, the Last Updated date at the beginning of the policy will be updated and additional notice will be provided where required.

Users are encouraged to review this Privacy Policy periodically.

31. Contact

For privacy questions, data requests, account concerns or complaints, contact:

Email: support@uaecompliancedirect.com
Telephone / WhatsApp: +44 20 4577 3361
Website: www.uaecompliancedirect.com


Last Updated: 10 September 2026