Privacy Policy
Last updated: July 15, 2026 | Version: 2.0 | Effective: July 15, 2026
1. Introduction & Scope
CyberSpeed LLC ("we," "us," "our," "the Company") is a limited liability company incorporated under the laws of the Emirate of Ras Al Khaimah, United Arab Emirates, with its registered office at FOAM2399 Compass Building, Al Shohada Road, AL Hamra Industrial Zone-FZ, Ras Al Khaimah, UAE (Trade License No. [CLIENT ACTION: Insert Trade License Number]). We operate the website cyberspeedllc.com and provide digital services including web & mobile app development, SEO, Shopify development, AI automation, AI development, digital advertising, and expert hiring services.
This Privacy Policy explains how we collect, use, disclose, process, and protect your Personal Data in accordance with:
- UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("PDPL")
- UAE Federal Law No. 34 of 2021 on Countering Rumors and Cybercrimes
- DIFC Data Protection Law No. 5 of 2020 (where applicable to DIFC entities)
- ADGM Data Protection Regulations 2021 (where applicable to ADGM entities)
- UAE Consumer Protection Law (Federal Law No. 15 of 2020)
- GDPR (EU 2016/679) — where we process data of EU/EEA residents
This policy applies to all Personal Data processed by CyberSpeed LLC whether through our website, service engagements, contracts, or any other interaction. By using our website or engaging our services, you acknowledge that you have read and understood this policy.
2. Definitions
- Personal Data
- Any information relating to an identified or identifiable natural person ("Data Subject"), directly or indirectly, by reference to an identifier such as a name, identification number, location data, online identifier, or factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person (PDPL Article 1).
- Processing
- Any operation or set of operations performed on Personal Data, whether automated or not, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
- Controller
- The natural or legal person who, alone or jointly with others, determines the purposes and means of Processing. CyberSpeed LLC is the Controller for data collected via our website and service engagements.
- Processor
- A natural or legal person who Processes Personal Data on behalf of the Controller. We engage subprocessors (e.g., cloud providers, analytics) under written Data Processing Agreements.
- Sensitive Personal Data
- Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning a person's sex life or sexual orientation (PDPL Article 1).
- Data Subject
- The identified or identifiable natural person to whom the Personal Data relates.
- Data Processing Agreement (DPA)
- A legally binding contract between Controller and Processor setting out the subject-matter, duration, nature, purpose, type of Personal Data, categories of Data Subjects, and obligations and rights of the Controller.
3. Data Protection Officer (DPO)
In accordance with PDPL Article 10, CyberSpeed LLC has appointed a Data Protection Officer who can be contacted for all data protection matters:
Data Protection Officer: [CLIENT ACTION: Insert DPO Name]
Email: dpo@cyberspeedllc.com
Phone: +971 4 200 0000
Postal Address: CyberSpeed LLC, FOAM2399 Compass Building, Al Shohada Road, AL Hamra Industrial Zone-FZ, Ras Al Khaimah, UAE — Attn: DPO
4. Categories of Personal Data We Collect
We collect only the Personal Data necessary for the specific purposes described in Section 5. We do not collect Sensitive Personal Data unless explicitly required for a service engagement and with your explicit consent.
4.1 Data You Provide Voluntarily
| Category | Data Fields | Source | Purpose |
|---|---|---|---|
| Contact & Inquiry Data | Full name, email address, phone number (including WhatsApp), company name, job title, project description, budget range, timeline | Contact forms, email, WhatsApp, phone calls, in-person meetings | Respond to inquiries, prepare proposals, contract negotiation |
| Account & Authentication Data | Email, password (hashed), MFA tokens, login timestamps, IP address | Client portal registration, project management tools | Provide secure access to project deliverables, reporting dashboards |
| Contract & Billing Data | Legal entity name, trade license number, VAT registration number (TRN), authorized signatory details, billing address, payment information, purchase order numbers | Service agreements, invoices, payment gateways | Contract execution, invoicing, VAT compliance, payment processing |
| Project & Service Data | Requirements, specifications, credentials (API keys, database access — encrypted), feedback, approvals, user acceptance testing results | Project kickoff, collaboration tools (Jira, Trello, Slack, email), code repositories | Service delivery, quality assurance, project management |
| Marketing & Communications Data | Email preferences, newsletter subscriptions, event registrations, webinar attendance, survey responses, testimonial content | Website forms, event platforms, email marketing tools | Send relevant updates, event invitations, case study participation (with consent) |
4.2 Automatically Collected Data
| Category | Data Fields | Collection Method | Legal Basis |
|---|---|---|---|
| Website Analytics | IP address (anonymised), device type, browser, OS, screen resolution, language, timezone, pages visited, referrer, session duration, scroll depth, click events | Google Analytics 4 (GA4), server logs | Legitimate Interest (PDPL Art. 6(1)(f)) — website improvement |
| Security & Fraud Prevention | IP address, geolocation (country/city), user agent, request headers, failed login attempts, rate-limit triggers | WAF (Cloudflare), application logs, auth logs | Legitimate Interest (PDPL Art. 6(1)(f)) — security, legal obligation |
| Performance Monitoring | Page load times, API response times, error rates, Core Web Vitals | Real User Monitoring (RUM), synthetic monitoring | Legitimate Interest — service quality |
4.3 Data from Third Parties
- Payment Processors: Stripe, PayPal, Tabby, Tamara — transaction status, masked card details, billing confirmation (Processor acts as independent Controller for payment data)
- Identity Verification: UAE Pass, Emirates ID verification services (where required for regulated sectors)
- Third-Party Platforms: Shopify, Google Ads, Meta, LinkedIn, TikTok — campaign performance data, audience insights (governed by respective platform terms)
- Public Sources: Trade license verification (DED, DIFC, ADGM), company registry data — only for KYC/compliance
5. Purposes & Legal Bases for Processing
Under PDPL Article 6, we process Personal Data only where at least one lawful basis applies:
| Purpose | Categories of Data | Legal Basis (PDPL Art. 6) | Retention |
|---|---|---|---|
| Respond to inquiries & prepare proposals | Contact & Inquiry Data | Art. 6(1)(b) — pre-contractual measures; Art. 6(1)(f) — legitimate interest | 24 months from last contact |
| Execute & deliver contracted services | Contract, Billing, Project, Authentication Data | Art. 6(1)(b) — contractual necessity | Duration of contract + 6 years (UAE commercial law) |
| Invoicing, payment processing, VAT compliance | Contract & Billing Data | Art. 6(1)(b) — contract; Art. 6(1)(c) — legal obligation (UAE VAT Law) | 6 years per UAE Federal Tax Authority requirements |
| Project management & collaboration | Project & Service Data, Authentication Data | Art. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interest | Project duration + 2 years |
| Website operation, analytics, improvement | Analytics, Performance, Security Data | Art. 6(1)(f) — legitimate interest (improving UX, security) | GA4: 14–26 months (configurable); Logs: 12 months |
| Security, fraud prevention, abuse detection | Security Data, Authentication Data | Art. 6(1)(f) — legitimate interest; Art. 6(1)(c) — legal obligation (Cybercrime Law) | 12 months; longer for incident investigation |
| Marketing communications (newsletter, updates, events) | Marketing Data | Art. 6(1)(a) — explicit consent (opt-in) | Until withdrawal of consent |
| Case studies & testimonials (with consent) | Project Data, Testimonial Content | Art. 6(1)(a) — explicit consent | Until withdrawal; published case studies retained indefinitely with attribution consent |
| Compliance with legal/regulatory requests | All categories as required | Art. 6(1)(c) — legal obligation | As required by applicable law/regulation |
6. Data Subject Rights (PDPL Articles 12–21)
As a Data Subject under UAE PDPL, you have the following rights. We facilitate their exercise within 30 days (extendable by 30 days for complex requests).
Right to Access (Art. 12)
Obtain confirmation whether we process your Personal Data and, if so, access to that Data and information about purposes, categories, recipients, retention periods, and source.
Right to Rectification (Art. 13)
Request correction of inaccurate Personal Data and completion of incomplete Data, including by supplementary statement.
Right to Erasure (Art. 14)
Request deletion where Data is no longer necessary, consent withdrawn, objection upheld, unlawfully processed, or required by law. Subject to legal retention obligations.
Right to Restriction (Art. 15)
Request restriction of Processing where accuracy contested, Processing unlawful, Data no longer needed but required for legal claims, or pending objection verification.
Right to Data Portability (Art. 16)
Receive your Personal Data in a structured, commonly used, machine-readable format and transmit to another Controller where technically feasible.
Right to Object (Art. 17)
Object to Processing based on legitimate interest (Art. 6(1)(f)) including profiling. We cease unless we demonstrate compelling legitimate grounds overriding your rights.
Right to Withdraw Consent (Art. 18)
Where Processing is based on consent, withdraw at any time without affecting lawfulness of Processing before withdrawal. As easy to withdraw as to give.
Right Not to Be Subject to Automated Decisions (Art. 19)
Not to be subject to decisions based solely on automated Processing producing legal or similarly significant effects, unless authorised by law, necessary for contract, or based on explicit consent.
Right to Lodge Complaint (Art. 20)
Lodge a complaint with the UAE Data Office (Federal Authority for Identity, Citizenship, Customs & Port Security) or relevant Free Zone authority (DIFC Commissioner, ADGM Registrar).
How to Exercise Your Rights
Submit a written request to our DPO at dpo@cyberspeedllc.com or via our Contact page. Include:
- Full name and contact details
- Specific right(s) you wish to exercise
- Details of the Personal Data concerned
- Proof of identity (Emirates ID, passport copy) — required for security
We respond within 30 days (extendable by 30 days for complexity). No fee unless requests are manifestly unfounded or excessive.
7. International Data Transfers (PDPL Articles 22–24)
CyberSpeed LLC's primary infrastructure is hosted in UAE (Azure UAE North, AWS Middle East - Bahrain/UAE) and GCC regions. Where subprocessors or third-party services are located outside UAE/GCC, we ensure adequate protection via:
- Adequacy Decisions: Transfers to jurisdictions with UAE Data Office adequacy recognition
- Standard Contractual Clauses: UAE Data Office-approved SCCs for Controller-to-Processor and Controller-to-Controller transfers
- Binding Corporate Rules (BCRs): Where applicable for intra-group transfers
- Explicit Consent: For one-off transfers where no other mechanism applies
Current Subprocessors with International Presence:
- Google Analytics / Google Cloud (USA/EU) — SCCs + supplementary measures
- Microsoft Azure (UAE regions primary; EU/US fallback) — SCCs
- AWS (Bahrain/UAE primary; US fallback) — SCCs
- Stripe (USA) — Payment processing, independent Controller, SCCs for data we receive
- Cloudflare (USA/EU) — WAF/CDN, SCCs
- Atlassian (Jira/Confluence — USA/AUS) — SCCs
- Slack (USA) — SCCs
- GitHub/GitLab (USA) — SCCs
A current Subprocessor List with transfer mechanisms is available upon request to dpo@cyberspeedllc.com.
8. Data Security & Organisational Measures (PDPL Article 9)
We implement appropriate technical and organisational measures commensurate with risk, including:
Technical Measures
- TLS 1.2+ encryption in transit (TLS 1.3 preferred)
- AES-256 encryption at rest for databases, backups, object storage
- WAF (Cloudflare) with OWASP Top 10 rules, rate limiting, bot management
- Zero-trust network architecture; least-privilege access; MFA enforced for all staff
- Secrets management (HashiCorp Vault / AWS Secrets Manager) — no secrets in code
- Automated vulnerability scanning (SAST/DAST/SCA) in CI/CD pipeline
- Immutable infrastructure; infrastructure-as-code with drift detection
- Automated backups with point-in-time recovery; encrypted, geo-redundant
- SIEM with real-time alerting; 90-day log retention minimum
Organisational Measures
- ISO 27001-aligned ISMS (certification in progress — target Q4 2026)
- Annual penetration testing by CREST-certified third party
- Quarterly internal security assessments; monthly vulnerability scans
- Data Protection Impact Assessments (DPIAs) for high-risk Processing (Art. 25)
- Mandatory security awareness training for all staff (onboarding + annual)
- Phishing simulations quarterly
- Incident Response Plan (tested annually); 72-hour breach notification procedure
- Vendor risk management: DPAs with all subprocessors; annual security reviews
- Clean desk policy; encrypted devices; MDM for mobile device management
- Background checks for personnel with access to client data
Despite these measures, no internet transmission or storage system is 100% secure. We encourage you to use secure channels (encrypted email, client portal) for highly sensitive information.
9. Data Retention & Deletion
We retain Personal Data only as long as necessary for the purposes collected or as required by UAE law.
| Data Category | Retention Period | Legal Basis / Notes |
|---|---|---|
| Contact & Inquiry Data (no contract) | 24 months from last interaction | Legitimate interest — follow-up, service improvement |
| Contract & Project Data | Contract term + 6 years | UAE Commercial Transactions Law (Federal Law No. 18 of 1993); limitation period |
| Billing, Invoices, VAT Records | 6 years | UAE Federal Decree-Law No. 8 of 2017 (VAT Law) — Art. 64 |
| Payment Transaction Data | 6 years (Processor may retain longer per their terms) | VAT Law; AML/CTF regulations (Cabinet Decision No. 10 of 2019) |
| Authentication & Access Logs | 12 months | Security, fraud prevention; Cybercrime Law compliance |
| Website Analytics (GA4) | 14 months (configurable: 14/26/38/50) | Legitimate interest; user-level deletion on request |
| Security Event Logs (WAF, SIEM) | 12 months; 3 years for incidents | Cybercrime Law; incident response |
| Marketing Consent Records | Until withdrawal + 2 years | Consent evidence; PDPL Art. 6(1)(a) |
| Case Study / Testimonial Content | Until withdrawal of consent | Explicit consent; published works may remain attributed |
| HR / Recruitment Data (if applicable) | 2 years post-process | UAE Labour Law (Federal Decree-Law No. 33 of 2021) |
After retention expiry, data is securely deleted (cryptographic erasure for encrypted storage; NIST 800-88 media sanitization for physical media). Deletion logs are maintained for audit.
10. Children's Data
Our services are not directed at individuals under 18 years of age. We do not knowingly collect Personal Data from children. If we become aware that a child has provided Personal Data, we will delete it promptly. If you believe a child has provided data, contact dpo@cyberspeedllc.com.
11. Cookies & Similar Technologies
This website uses cookies and similar tracking technologies. For detailed information, please see our Cookie Policy. Summary:
- Essential Cookies: Session management, security, load balancing — no consent required
- Analytics Cookies (GA4): Pseudonymised usage statistics — consent required (opt-in)
- No Advertising/Tracking Cookies: We do not use third-party advertising cookies or cross-site tracking
You can manage cookie preferences via the cookie banner (first visit) or Cookie Policy page. Browser settings also allow blocking/deleting cookies.
12. Third-Party Links & Integrations
Our website may contain links to third-party websites (partners, platforms, social media). This Privacy Policy applies only to cyberspeedllc.com. We are not responsible for the privacy practices of external sites. When you integrate third-party platforms (Shopify, Google Ads, Meta, etc.) as part of our services, your data flows are governed by those platforms' privacy policies and our Data Processing Agreements with them.
13. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated via:
- Prominent notice on this page with updated "Last updated" date
- Email notification to registered clients (where we have contact details)
- Website banner for at least 30 days
Continued use of our website or services after the effective date constitutes acceptance of the revised policy. We recommend reviewing this policy periodically.
14. Contact Us
For questions, concerns, or to exercise your rights under this Privacy Policy or UAE PDPL:
Data Protection Officer: [CLIENT ACTION: Insert DPO Name]
Email: dpo@cyberspeedllc.com | privacy@cyberspeedllc.com
Phone: +971 4 200 0000
Postal: CyberSpeed LLC, FOAM2399 Compass Building, Al Shohada Road, AL Hamra Industrial Zone-FZ, Ras Al Khaimah, UAE — Attn: DPO
Online: Contact Form
We aim to respond to all privacy inquiries within 30 days.
15. Regulatory Authorities
You have the right to lodge a complaint with the relevant UAE data protection authority:
- UAE Data Office (Federal Authority for Identity, Citizenship, Customs & Port Security) — dataoffice.gov.ae
- DIFC Commissioner of Data Protection — difc.ae (for DIFC entities)
- ADGM Registrar — adgm.com (for ADGM entities)
- TDRA (Telecommunications and Digital Government Regulatory Authority) — for telecommunications/data matters
Acceptance of Privacy Policy
By clicking "I Accept," you confirm that you have read, understood, and agree to CyberSpeed LLC's Privacy Policy (Version 2.0, July 15, 2026). This acceptance is logged for compliance with UAE PDPL Art. 6 and international data protection regulations.
I Have QuestionsThis acceptance is timestamped and stored as a cookie for audit purposes. No personal data is collected through this acceptance mechanism. For formal service engagements, full documented consent is obtained per the Service Agreement.