🔥 20% OFF
SEO from $99/mo
Free Site Analysis
Claim Now

Privacy Policy

Last updated: July 15, 2026 | Version: 2.0 | Effective: July 15, 2026

1. Introduction & Scope

CyberSpeed LLC ("we," "us," "our," "the Company") is a limited liability company incorporated under the laws of the Emirate of Ras Al Khaimah, United Arab Emirates, with its registered office at FOAM2399 Compass Building, Al Shohada Road, AL Hamra Industrial Zone-FZ, Ras Al Khaimah, UAE (Trade License No. [CLIENT ACTION: Insert Trade License Number]). We operate the website cyberspeedllc.com and provide digital services including web & mobile app development, SEO, Shopify development, AI automation, AI development, digital advertising, and expert hiring services.

This Privacy Policy explains how we collect, use, disclose, process, and protect your Personal Data in accordance with:

  • UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("PDPL")
  • UAE Federal Law No. 34 of 2021 on Countering Rumors and Cybercrimes
  • DIFC Data Protection Law No. 5 of 2020 (where applicable to DIFC entities)
  • ADGM Data Protection Regulations 2021 (where applicable to ADGM entities)
  • UAE Consumer Protection Law (Federal Law No. 15 of 2020)
  • GDPR (EU 2016/679) — where we process data of EU/EEA residents

This policy applies to all Personal Data processed by CyberSpeed LLC whether through our website, service engagements, contracts, or any other interaction. By using our website or engaging our services, you acknowledge that you have read and understood this policy.

2. Definitions

Personal Data
Any information relating to an identified or identifiable natural person ("Data Subject"), directly or indirectly, by reference to an identifier such as a name, identification number, location data, online identifier, or factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person (PDPL Article 1).
Processing
Any operation or set of operations performed on Personal Data, whether automated or not, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
Controller
The natural or legal person who, alone or jointly with others, determines the purposes and means of Processing. CyberSpeed LLC is the Controller for data collected via our website and service engagements.
Processor
A natural or legal person who Processes Personal Data on behalf of the Controller. We engage subprocessors (e.g., cloud providers, analytics) under written Data Processing Agreements.
Sensitive Personal Data
Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning a person's sex life or sexual orientation (PDPL Article 1).
Data Subject
The identified or identifiable natural person to whom the Personal Data relates.
Data Processing Agreement (DPA)
A legally binding contract between Controller and Processor setting out the subject-matter, duration, nature, purpose, type of Personal Data, categories of Data Subjects, and obligations and rights of the Controller.

3. Data Protection Officer (DPO)

In accordance with PDPL Article 10, CyberSpeed LLC has appointed a Data Protection Officer who can be contacted for all data protection matters:

Data Protection Officer: [CLIENT ACTION: Insert DPO Name]

Email: dpo@cyberspeedllc.com

Phone: +971 4 200 0000

Postal Address: CyberSpeed LLC, FOAM2399 Compass Building, Al Shohada Road, AL Hamra Industrial Zone-FZ, Ras Al Khaimah, UAE — Attn: DPO

4. Categories of Personal Data We Collect

We collect only the Personal Data necessary for the specific purposes described in Section 5. We do not collect Sensitive Personal Data unless explicitly required for a service engagement and with your explicit consent.

4.1 Data You Provide Voluntarily

CategoryData FieldsSourcePurpose
Contact & Inquiry DataFull name, email address, phone number (including WhatsApp), company name, job title, project description, budget range, timelineContact forms, email, WhatsApp, phone calls, in-person meetingsRespond to inquiries, prepare proposals, contract negotiation
Account & Authentication DataEmail, password (hashed), MFA tokens, login timestamps, IP addressClient portal registration, project management toolsProvide secure access to project deliverables, reporting dashboards
Contract & Billing DataLegal entity name, trade license number, VAT registration number (TRN), authorized signatory details, billing address, payment information, purchase order numbersService agreements, invoices, payment gatewaysContract execution, invoicing, VAT compliance, payment processing
Project & Service DataRequirements, specifications, credentials (API keys, database access — encrypted), feedback, approvals, user acceptance testing resultsProject kickoff, collaboration tools (Jira, Trello, Slack, email), code repositoriesService delivery, quality assurance, project management
Marketing & Communications DataEmail preferences, newsletter subscriptions, event registrations, webinar attendance, survey responses, testimonial contentWebsite forms, event platforms, email marketing toolsSend relevant updates, event invitations, case study participation (with consent)

4.2 Automatically Collected Data

CategoryData FieldsCollection MethodLegal Basis
Website AnalyticsIP address (anonymised), device type, browser, OS, screen resolution, language, timezone, pages visited, referrer, session duration, scroll depth, click eventsGoogle Analytics 4 (GA4), server logsLegitimate Interest (PDPL Art. 6(1)(f)) — website improvement
Security & Fraud PreventionIP address, geolocation (country/city), user agent, request headers, failed login attempts, rate-limit triggersWAF (Cloudflare), application logs, auth logsLegitimate Interest (PDPL Art. 6(1)(f)) — security, legal obligation
Performance MonitoringPage load times, API response times, error rates, Core Web VitalsReal User Monitoring (RUM), synthetic monitoringLegitimate Interest — service quality

4.3 Data from Third Parties

  • Payment Processors: Stripe, PayPal, Tabby, Tamara — transaction status, masked card details, billing confirmation (Processor acts as independent Controller for payment data)
  • Identity Verification: UAE Pass, Emirates ID verification services (where required for regulated sectors)
  • Third-Party Platforms: Shopify, Google Ads, Meta, LinkedIn, TikTok — campaign performance data, audience insights (governed by respective platform terms)
  • Public Sources: Trade license verification (DED, DIFC, ADGM), company registry data — only for KYC/compliance

5. Purposes & Legal Bases for Processing

Under PDPL Article 6, we process Personal Data only where at least one lawful basis applies:

6. Data Subject Rights (PDPL Articles 12–21)

As a Data Subject under UAE PDPL, you have the following rights. We facilitate their exercise within 30 days (extendable by 30 days for complex requests).

Right to Access (Art. 12)

Obtain confirmation whether we process your Personal Data and, if so, access to that Data and information about purposes, categories, recipients, retention periods, and source.

Right to Rectification (Art. 13)

Request correction of inaccurate Personal Data and completion of incomplete Data, including by supplementary statement.

Right to Erasure (Art. 14)

Request deletion where Data is no longer necessary, consent withdrawn, objection upheld, unlawfully processed, or required by law. Subject to legal retention obligations.

Right to Restriction (Art. 15)

Request restriction of Processing where accuracy contested, Processing unlawful, Data no longer needed but required for legal claims, or pending objection verification.

Right to Data Portability (Art. 16)

Receive your Personal Data in a structured, commonly used, machine-readable format and transmit to another Controller where technically feasible.

Right to Object (Art. 17)

Object to Processing based on legitimate interest (Art. 6(1)(f)) including profiling. We cease unless we demonstrate compelling legitimate grounds overriding your rights.

Right to Withdraw Consent (Art. 18)

Where Processing is based on consent, withdraw at any time without affecting lawfulness of Processing before withdrawal. As easy to withdraw as to give.

Right Not to Be Subject to Automated Decisions (Art. 19)

Not to be subject to decisions based solely on automated Processing producing legal or similarly significant effects, unless authorised by law, necessary for contract, or based on explicit consent.

Right to Lodge Complaint (Art. 20)

Lodge a complaint with the UAE Data Office (Federal Authority for Identity, Citizenship, Customs & Port Security) or relevant Free Zone authority (DIFC Commissioner, ADGM Registrar).

How to Exercise Your Rights

Submit a written request to our DPO at dpo@cyberspeedllc.com or via our Contact page. Include:

  • Full name and contact details
  • Specific right(s) you wish to exercise
  • Details of the Personal Data concerned
  • Proof of identity (Emirates ID, passport copy) — required for security

We respond within 30 days (extendable by 30 days for complexity). No fee unless requests are manifestly unfounded or excessive.

7. International Data Transfers (PDPL Articles 22–24)

CyberSpeed LLC's primary infrastructure is hosted in UAE (Azure UAE North, AWS Middle East - Bahrain/UAE) and GCC regions. Where subprocessors or third-party services are located outside UAE/GCC, we ensure adequate protection via:

  • Adequacy Decisions: Transfers to jurisdictions with UAE Data Office adequacy recognition
  • Standard Contractual Clauses: UAE Data Office-approved SCCs for Controller-to-Processor and Controller-to-Controller transfers
  • Binding Corporate Rules (BCRs): Where applicable for intra-group transfers
  • Explicit Consent: For one-off transfers where no other mechanism applies

Current Subprocessors with International Presence:

  • Google Analytics / Google Cloud (USA/EU) — SCCs + supplementary measures
  • Microsoft Azure (UAE regions primary; EU/US fallback) — SCCs
  • AWS (Bahrain/UAE primary; US fallback) — SCCs
  • Stripe (USA) — Payment processing, independent Controller, SCCs for data we receive
  • Cloudflare (USA/EU) — WAF/CDN, SCCs
  • Atlassian (Jira/Confluence — USA/AUS) — SCCs
  • Slack (USA) — SCCs
  • GitHub/GitLab (USA) — SCCs

A current Subprocessor List with transfer mechanisms is available upon request to dpo@cyberspeedllc.com.

8. Data Security & Organisational Measures (PDPL Article 9)

We implement appropriate technical and organisational measures commensurate with risk, including:

Technical Measures

  • TLS 1.2+ encryption in transit (TLS 1.3 preferred)
  • AES-256 encryption at rest for databases, backups, object storage
  • WAF (Cloudflare) with OWASP Top 10 rules, rate limiting, bot management
  • Zero-trust network architecture; least-privilege access; MFA enforced for all staff
  • Secrets management (HashiCorp Vault / AWS Secrets Manager) — no secrets in code
  • Automated vulnerability scanning (SAST/DAST/SCA) in CI/CD pipeline
  • Immutable infrastructure; infrastructure-as-code with drift detection
  • Automated backups with point-in-time recovery; encrypted, geo-redundant
  • SIEM with real-time alerting; 90-day log retention minimum

Organisational Measures

  • ISO 27001-aligned ISMS (certification in progress — target Q4 2026)
  • Annual penetration testing by CREST-certified third party
  • Quarterly internal security assessments; monthly vulnerability scans
  • Data Protection Impact Assessments (DPIAs) for high-risk Processing (Art. 25)
  • Mandatory security awareness training for all staff (onboarding + annual)
  • Phishing simulations quarterly
  • Incident Response Plan (tested annually); 72-hour breach notification procedure
  • Vendor risk management: DPAs with all subprocessors; annual security reviews
  • Clean desk policy; encrypted devices; MDM for mobile device management
  • Background checks for personnel with access to client data

Despite these measures, no internet transmission or storage system is 100% secure. We encourage you to use secure channels (encrypted email, client portal) for highly sensitive information.

9. Data Retention & Deletion

We retain Personal Data only as long as necessary for the purposes collected or as required by UAE law.

Data CategoryRetention PeriodLegal Basis / Notes
Contact & Inquiry Data (no contract)24 months from last interactionLegitimate interest — follow-up, service improvement
Contract & Project DataContract term + 6 yearsUAE Commercial Transactions Law (Federal Law No. 18 of 1993); limitation period
Billing, Invoices, VAT Records6 yearsUAE Federal Decree-Law No. 8 of 2017 (VAT Law) — Art. 64
Payment Transaction Data6 years (Processor may retain longer per their terms)VAT Law; AML/CTF regulations (Cabinet Decision No. 10 of 2019)
Authentication & Access Logs12 monthsSecurity, fraud prevention; Cybercrime Law compliance
Website Analytics (GA4)14 months (configurable: 14/26/38/50)Legitimate interest; user-level deletion on request
Security Event Logs (WAF, SIEM)12 months; 3 years for incidentsCybercrime Law; incident response
Marketing Consent RecordsUntil withdrawal + 2 yearsConsent evidence; PDPL Art. 6(1)(a)
Case Study / Testimonial ContentUntil withdrawal of consentExplicit consent; published works may remain attributed
HR / Recruitment Data (if applicable)2 years post-processUAE Labour Law (Federal Decree-Law No. 33 of 2021)

After retention expiry, data is securely deleted (cryptographic erasure for encrypted storage; NIST 800-88 media sanitization for physical media). Deletion logs are maintained for audit.

10. Children's Data

Our services are not directed at individuals under 18 years of age. We do not knowingly collect Personal Data from children. If we become aware that a child has provided Personal Data, we will delete it promptly. If you believe a child has provided data, contact dpo@cyberspeedllc.com.

11. Cookies & Similar Technologies

This website uses cookies and similar tracking technologies. For detailed information, please see our Cookie Policy. Summary:

  • Essential Cookies: Session management, security, load balancing — no consent required
  • Analytics Cookies (GA4): Pseudonymised usage statistics — consent required (opt-in)
  • No Advertising/Tracking Cookies: We do not use third-party advertising cookies or cross-site tracking

You can manage cookie preferences via the cookie banner (first visit) or Cookie Policy page. Browser settings also allow blocking/deleting cookies.

12. Third-Party Links & Integrations

Our website may contain links to third-party websites (partners, platforms, social media). This Privacy Policy applies only to cyberspeedllc.com. We are not responsible for the privacy practices of external sites. When you integrate third-party platforms (Shopify, Google Ads, Meta, etc.) as part of our services, your data flows are governed by those platforms' privacy policies and our Data Processing Agreements with them.

13. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated via:

  • Prominent notice on this page with updated "Last updated" date
  • Email notification to registered clients (where we have contact details)
  • Website banner for at least 30 days

Continued use of our website or services after the effective date constitutes acceptance of the revised policy. We recommend reviewing this policy periodically.

14. Contact Us

For questions, concerns, or to exercise your rights under this Privacy Policy or UAE PDPL:

Data Protection Officer: [CLIENT ACTION: Insert DPO Name]

Email: dpo@cyberspeedllc.com | privacy@cyberspeedllc.com

Phone: +971 4 200 0000

Postal: CyberSpeed LLC, FOAM2399 Compass Building, Al Shohada Road, AL Hamra Industrial Zone-FZ, Ras Al Khaimah, UAE — Attn: DPO

Online: Contact Form

We aim to respond to all privacy inquiries within 30 days.

15. Regulatory Authorities

You have the right to lodge a complaint with the relevant UAE data protection authority:

  • UAE Data Office (Federal Authority for Identity, Citizenship, Customs & Port Security) — dataoffice.gov.ae
  • DIFC Commissioner of Data Protectiondifc.ae (for DIFC entities)
  • ADGM Registraradgm.com (for ADGM entities)
  • TDRA (Telecommunications and Digital Government Regulatory Authority) — for telecommunications/data matters