SESecureEdge AdvisoryBeta
ProductsServicesAssessmentsSectorsPricingInsightsAboutContact
Customer loginRequest portal access

Privacy Policy

How SecureEdge Advisory collects, uses and protects personal data, and how you exercise your rights under the UAE Personal Data Protection Law.

Version 1.2Effective 28 July 2026

Who we are

SecureEdge Advisory ("we", "us") is the controller of the personal data described in this policy. Our registered office is PO Box 410193, Dubai, United Arab Emirates.

Questions about this policy, and any request to exercise your rights, should be addressed to privacy@secureedgeadvisory.com. A person reads that mailbox.

The law that applies

We process personal data in accordance with UAE Federal Decree-Law No. 45 of 2021 (PDPL) and the regulations issued under it. Where a customer is subject to another data protection regime, the applicable terms are set out in the Data Processing Agreement rather than in this policy.

What this website collects

This website does not set cookies. It does not run analytics. It does not embed content from any third party, and typefaces are drawn from the fonts already installed on your device rather than requested from an external provider. No tracking identifier is created when you browse these pages.

Our hosting provider processes the technical information necessary to deliver a web page to you, including your IP address, the address of the page you requested, and your browser's user-agent string. That information is used to serve and secure the site, and for no other purpose.

What we collect when you contact us

If you write to us, we receive the contents of your message together with your email address and anything else you choose to include. We use that information solely to respond to you and, where a professional relationship follows, to perform the engagement.

If you submit a company profile requesting portal access, we collect the information you provide about your organisation and the contact details of the person submitting it. We use that information to review the request and to contact you. Submitting a profile does not create an account.

Lawful basis

  • Performance of a contract, where you are a customer or are taking steps to enter into an agreement with us.
  • Our legitimate interests in operating, securing and improving the website, where those interests are not overridden by your rights.
  • Compliance with a legal obligation to which we are subject.
  • Your consent, where consent is the appropriate basis. You may withdraw consent at any time without affecting processing carried out before the withdrawal.

Sub-processors and international transfer

We engage a small number of third parties to process personal data on our behalf. They are named, together with their purpose and hosting region, on our Sub-processors page. We do not sell personal data, and we do not disclose it for advertising.

None of our providers operates a region within the United Arab Emirates. Personal data processed through the website, the customer portal, or correspondence with our published mailboxes therefore rests outside the State. Such transfers are made in accordance with Articles 22 and 23 of the PDPL, and the region and basis relied upon for each provider are stated on the Sub-processors page.

Retention

We retain personal data for as long as it is necessary for the purpose for which it was collected, and thereafter for the period required to meet a legal, accounting or regulatory obligation. The periods below are applied automatically rather than on request.

  • A message sent through our contact form is deleted twelve months after it has been dealt with.
  • A message that we did not answer is deleted twenty-four months after it was received.
  • Records evidencing that a policy was accepted, and the audit trail of actions taken on customer records, are retained for the limitation period. They are held in a form that cannot be altered or deleted, which is what makes them evidence.
  • Data held under an engagement is retained in accordance with the Data Processing Agreement and the engagement letter.

Your rights

Subject to the conditions in the PDPL, you may exercise the rights set out below by writing to privacy@secureedgeadvisory.com. We will respond within the period the law allows. We may ask you to verify your identity before we act, so that we do not disclose your data to somebody else.

  • To be informed about how your personal data is processed.
  • To request access to the personal data we hold about you.
  • To request correction of personal data that is inaccurate or incomplete.
  • To request erasure of your personal data, where the conditions for erasure are met.
  • To restrict or object to processing in the circumstances the law provides.
  • To request that your personal data be transferred to you or to another controller in a structured, machine-readable format.
  • To lodge a complaint with the UAE Data Office.

Security

We apply administrative, technical and physical safeguards appropriate to the risk. Access to personal data is limited to those who require it to perform their role. If you believe you have found a vulnerability affecting our systems, please report it through our responsible disclosure policy rather than testing further.

Children

Our services are directed to organisations rather than to individuals, and are not intended for children. We do not knowingly collect personal data relating to a child.

Changes to this policy

Where we change the substance of this policy we will publish a new version with a new effective date. The version and effective date of the policy you are reading appear at the top of this page. Where you have accepted a version of this policy, the version you accepted is recorded against your account.

On this page
  1. Who we are
  2. The law that applies
  3. What this website collects
  4. What we collect when you contact us
  5. Lawful basis
  6. Sub-processors and international transfer
  7. Retention
  8. Your rights
  9. Security
  10. Children
  11. Changes to this policy
This version
v1.2
Effective 28 July 2026

A new version re-gates everyone who accepted the old one. Your acceptance records the exact version you saw.

The rest of the pack
  • Terms of Service
  • Data Processing and Assessment Terms
  • Acceptable Use Policy
  • Cookie Policy
  • Sub-processors
  • Security and trust
When you are ready

Read it, then let us look at your organisation and tell you what we find.

Create your company profile →
SESecureEdge Advisory

Your CIO & CISO, everywhere. Cyber advisory and a connected GRC product family for the UAE & GCC.

Not open yet. Before we collect a single address we will name the provider that sends it on our sub-processors page, and say in the privacy policy what we use it for.

Products
EvidenceEdgeControlRegistryCertEdgeTrustEdgeImpactEdgeRiskEdgeAssessEdgeChangeEdgeAppEdgeOneAudit
Solutions
vCIO, IT leadershipvCISO, securityAssessmentsToolsBy sectorFrameworks (15)
Company
About usServicesPricingContact
Resources
InsightsFrequently asked questionsCompliance deadlinesFrameworks we coverAEGIS, the enginePlatform securityResponsible disclosure
Legal & Trust
Privacy PolicyTerms of ServiceData Processing (DPA)Acceptable UseCookie PolicySub-processorsSecurity & trustPlatform security
© 2026 SecureEdge Advisory. All rights reserved.
Registered in Dubai, United Arab Emirates · cio@secureedgeadvisory.com
PrivacyCookiesTermsDPA