Bizilance Legal Consultants is committed to protecting the personal data entrusted to us. We process personal data in line with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the UAE PDPL), the ADGM Data Protection Regulations 2021 as our jurisdiction of establishment, and the EU GDPR where our activities fall within its scope.
1. Who we are
Bizilance Legal Consultants (“Bizilance”, “we”, “us”, “our”) is a legal consultancy registered in the Abu Dhabi Global Market (ADGM), United Arab Emirates, advising on trade remedies, privacy and data protection, VAT and corporate tax, and competition law.
For the purposes of this policy we act as the data controller for the personal data described below, except where we process client data on documented instructions in the course of an engagement, in which case we act as a data processor under the terms of the relevant engagement letter.
Our details
Bizilance Legal Consultants
D 3 - 4, Office 302, Al Sarab Tower, Level 15th
ADGM, Abu Dhabi, United Arab Emirates
saeed.hasan@bizilancelegal.ae
·
+971 52 914 1118
2. Scope of this policy
This policy applies to personal data we handle when you:
- visit bizilance.ae or any of its pages;
- submit our contact or consultation request form;
- email, call, or message us, including via LinkedIn or Facebook;
- engage us as a client, or act for a client, counterparty, or supplier in a matter we work on;
- attend an event, webinar, or briefing we host or take part in;
- apply for a role or express interest in working with us.
It does not apply to third-party websites we link to, or to personal data we process purely on a client’s instructions, which is governed by the engagement terms agreed with that client.
3. Personal data we collect
3.1 Data you give us
When you complete the enquiry form on our contact page we collect your name, email address, the service you select, and the message you write. Your phone number is optional. We also record the fact, date, and time that you accepted this policy when submitting the form.
3.2 Data we collect during an engagement
Where you become a client or are connected to a matter, we may collect identification and verification documents, corporate and beneficial ownership records, financial and tax information, correspondence, and any other material relevant to the advice requested. Some of this is required of us by anti-money-laundering, sanctions, and know-your-client obligations.
3.3 Data collected automatically
Our website and hosting provider record limited technical information such as IP address, browser and device type, referring page, and pages viewed. This is used to keep the site secure and working properly, and to understand which content is useful.
3.4 Data from other sources
We may receive personal data from your employer or advisers, from public registers and company databases, from sanctions and politically-exposed-person screening tools, and from professional referrals.
3.5 Sensitive data
We do not ask for sensitive personal data through this website. Where a matter unavoidably involves it, we handle it only where the law permits and with the additional safeguards our engagement terms describe. Please do not include sensitive or privileged details in the free-text message field of our enquiry form.
4. How and why we use your data
- To respond to your enquiry — to contact you about the consultation you requested and answer your questions.
- To provide our services — to advise, prepare filings and submissions, and represent you before authorities.
- To run conflict and compliance checks — before accepting instructions, and periodically afterwards.
- To meet legal and regulatory duties — including AML, sanctions, tax, and record-keeping requirements.
- To administer our business — billing, accounting, insurance, IT security, and internal audit.
- To share insights — sending publications, briefings, and event invitations where you have asked to receive them.
- To improve our website — diagnosing faults, preventing abuse, and understanding aggregate usage.
We do not sell personal data, and we do not use it for automated decision-making or profiling that produces legal effects for you.
5. Our lawful bases
Depending on the activity, we rely on one or more of the following:
| Purpose | Lawful basis |
|---|---|
| Responding to a website enquiry | Your consent, and steps taken at your request before entering a contract |
| Delivering advisory services | Performance of our engagement contract |
| KYC, AML, and sanctions screening | Compliance with a legal obligation |
| Records, billing, and dispute defence | Our legitimate interests in running and protecting the practice |
| Marketing and publications | Your consent, withdrawable at any time |
| Site security and fraud prevention | Our legitimate interests in keeping our systems safe |
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing already carried out, or processing we must continue in order to meet a legal obligation.
8. International transfers
We advise clients across seventeen jurisdictions, so personal data may be transferred outside the UAE — for example to local counsel or to cloud infrastructure hosted abroad.
Where data leaves the UAE we transfer it to a jurisdiction recognised as providing an adequate level of protection, or we put appropriate safeguards in place — typically standard contractual clauses, binding commitments from the recipient, or another mechanism permitted under the UAE PDPL and the ADGM Data Protection Regulations. Where no such mechanism is available, we rely on a permitted derogation, such as your explicit consent or the necessity of the transfer for your matter. You may request details of the safeguards applied to a specific transfer.
9. How long we keep data
We keep personal data only as long as we need it for the purpose it was collected for, plus any period we are required or advised to retain it.
| Category | Typical retention |
|---|---|
| Website enquiries that do not become engagements | Up to 24 months from last contact |
| Client matter files and correspondence | Minimum of 5 years after the matter closes, longer where a limitation period or regulator requires |
| KYC and AML records | At least 5 years after the relationship ends, as required by UAE law |
| Accounting and tax records | As required by applicable UAE tax legislation |
| Marketing subscriptions | Until you unsubscribe, then a suppression record only |
| Website technical logs | Short-term, typically no more than 12 months |
When data is no longer needed we securely delete or anonymise it.
10. How we protect your data
We apply technical and organisational measures proportionate to the sensitivity of the data we hold: access controls on a need-to-know basis, encryption in transit, protected and backed-up systems, vetted suppliers, confidentiality undertakings from everyone at the firm, and staff training on data handling.
No system is completely secure. If a personal data breach occurs that is likely to cause you harm, we will notify the competent authority and affected individuals within the timeframes the applicable law sets.
11. Your rights
Subject to the conditions and exemptions in the applicable law, you have the right to:
- Be informed about how your data is used — this policy.
- Access a copy of the personal data we hold about you.
- Correct data that is inaccurate or incomplete.
- Erase data where we no longer have grounds to keep it.
- Restrict or object to certain processing, including direct marketing.
- Portability — receive data you gave us in a structured, machine-readable format.
- Withdraw consent at any time where consent is our basis.
- Complain to the competent supervisory authority.
To exercise any of these, email saeed.hasan@bizilancelegal.ae with the words “Data Subject Request” in the subject line. We may ask you to verify your identity before we act. We respond within one month, and will tell you if a complex request needs longer. There is no charge unless a request is manifestly unfounded or excessive.
Some rights are limited where the data is covered by legal professional privilege, by our confidentiality duty to another client, or by a retention obligation we cannot set aside. Where we cannot meet a request in full, we will explain why.
12. Marketing preferences
We send publications, legal updates, and event invitations only to people who asked for them or who we have an existing professional relationship with. Every message carries an unsubscribe link, and you can opt out at any time by replying or emailing us. Opting out of marketing does not stop the service-related messages we need to send about an active matter.
13. Children’s data
Our services are directed to businesses and professionals. We do not knowingly collect personal data from anyone under 18 through this website. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Third-party sites
Our site links to external publications, social media profiles, and mapping services. We are not responsible for the privacy practices or content of those sites. Read their privacy notices before providing personal data to them.
15. Changes to this policy
We review this policy periodically and update it when our practices, the law, or our technology changes. The effective date at the top of this page always reflects the current version. Where a change materially affects how we use your data, we will take reasonable steps to tell you directly.
16. Contact & complaints
Questions about this policy, or about how we handle your personal data, are welcome and are answered by a senior member of our privacy practice.
Privacy contact
Bizilance Legal Consultants — Privacy Team
D 3 - 4, Office 302, Al Sarab Tower, Level 15th
ADGM, Abu Dhabi, United Arab Emirates
saeed.hasan@bizilancelegal.ae
·
+971 52 914 1118
If you are not satisfied with our response, you may complain to the UAE Data Office, or — where the data was processed within ADGM — to the Office of the Data Protection Commissioner, ADGM. If the GDPR applies to the processing, you may complain to the supervisory authority where you live or work.