
PRIVACY NOTICE
PRAECEPTA CYBERSECURITY LLC — PRIVACY NOTICE
Version 1.0 · August 2026 · Reviewed annually
1. Who we are
PRAECEPTA CYBERSECURITY LLC ("PRAECEPTA", "we", "us") is a company registered in Dubai, United Arab Emirates.
Registered address: Sail Star Business Center, Bay Square, Business Bay, Dubai, United Arab Emirates
Privacy contact: [privacy@praecepta.ae]
We are the controller of the personal data described in this Notice.
2. What this Notice covers
This Notice explains how we handle personal data when you visit praecepta.co, download our published resources, subscribe to our communications, contact us, or engage us for professional services.
It does not cover personal data we process on behalf of a client while delivering services. In those engagements we generally act as a processor, the client is the controller, and their privacy notice governs. Our obligations are set out in the Data Processing Addendum to the relevant engagement agreement.
3. Personal data we collect
3.1 Website visitors
3.2 Resource downloads and subscribers
Where you request our Working Pack, subscribe to our newsletter, or request another gated resource:
Our ungated resources require no personal data. The framework crosswalk PDF and other ungated publications download without a form, without registration, and without consent to marketing. Consent to receive communications is never a condition of accessing them.
3.3 Enquiries and prospective clients
Name, job title, organisation, email, telephone, and the content of your enquiry — including any information you choose to share about your organisation's security or compliance position.
Please do not send us sensitive technical detail about your security posture, vulnerabilities, or incidents through the website contact form or by unencrypted email. We will arrange a secure channel. If you have already done so, tell us and we will handle it appropriately.
3.4 Clients and engagement contacts
Name, job title, organisation, contact details, engagement correspondence, meeting records, contractual documentation, and billing and payment information.
3.5 Suppliers, associates and subcontractors
Contact details, contractual documentation, professional credentials, insurance certificates, and payment details.
3.6 Special categories of personal data
We do not seek and do not require special categories of personal data. If any is disclosed to us incidentally — for example within evidence provided during an engagement — we minimise, restrict access to, and delete it at the earliest opportunity, and we will tell the client.
4. Why we process personal data
-
Providing professional services under an engagement agreement
-
Responding to enquiries and preparing proposals
-
Delivering resources you have requested
-
Sending communications you have consented to receive
-
Operating and securing our website
-
Managing supplier and associate relationships
-
Invoicing, payment and financial record-keeping
-
Complying with legal, regulatory, tax and accounting obligations
-
Maintaining professional indemnity cover and, if required, defending claims
-
Maintaining our client register and conflict-of-interest records — see §5
5. Our client register and conflict checks
We maintain a register of clients and active business pursuits. It exists so that we can honour non-solicitation undertakings given to channel partners, identify conflicts of interest before accepting engagements, and comply with our published Declaration of Interests.
It contains organisation names, engagement dates and scope, and the names of key contacts.
6. Who we share personal data with
We do not sell personal data. We do not share it for third-party marketing.
7. International transfers
Some of our service providers process personal data outside the UAE.
Under the PDPL, transfer of personal data outside the UAE is permitted where the destination provides an adequate level of protection, or where another permitted basis or safeguard applies.
We minimise cross-border transfer where practical, and prefer providers offering UAE or regional hosting where a viable option exists.
8. How long we keep personal data
9. Your rights
Subject to applicable law and any permitted exceptions, you have the right to:
-
Be informed about how your personal data is processed
-
Access your personal data
-
Correct or rectify inaccurate or incomplete data
-
Request erasure of your personal data
-
Request restriction of processing
-
Data portability — receive your data in a structured, machine-readable format
-
Object to, or stop, processing — including processing for direct marketing purposes
-
Rights in relation to automated decision-making and profiling
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
Withdrawing consent. Where we rely on consent, you may withdraw it at any time — use the unsubscribe link in any email, or contact us. Withdrawal is straightforward and carries no penalty. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
How to exercise your rights. Email [privacy@praecepta.ae]. We will respond within one month of receipt. Where a request is complex or onerous, we may extend by a further two months and will tell you if we do.
10. Security
We apply technical and organisational measures appropriate to the risk, including: encryption in transit and at rest; multi-factor authentication on all administrative accounts; least-privilege access control; network protection; logging and monitoring; secure document handling for client material; and defined retention and deletion.
We are a security practice and we hold ourselves to the standards we advise. If you believe you have identified a vulnerability in praecepta.co, please tell us at [security@praecepta.co]. We will acknowledge and investigate, and we will not pursue good-faith security research.
11. Personal data breaches
Where a personal data breach occurs, we will assess it, take steps to contain and remedy it, and notify the UAE Data Office promptly after becoming aware of it, in accordance with applicable requirements. Where the breach is likely to prejudice the privacy, confidentiality, security, integrity or rights of affected individuals, we will notify those individuals.
12. Complaints
If you are dissatisfied with how we have handled your personal data, contact us first at [privacy@praecepta.ae] and we will investigate.
You also have the right to complain to the UAE Data Office.
13. Changes
We review this Notice at least annually. The version number and date appear at the top. Where changes materially affect how we process your personal data, we will notify subscribers directly.
14. Contact
PRAECEPTA CYBERSECURITY LLC
Sail Star Business Center, Bay Square, Business Bay, Dubai, United Arab Emirates
Privacy: [privacy@praecepta.ae] · Security: [security@praecepta.ae]
Data: IP address, browser type, device type, operating system, referring page, pages viewed, time and date
Purpose: Site security, fraud prevention, operation, aggregate traffic measurement
Legal basis: Legitimate Interest Assessment**
Data: Essential Cookies
Purpose: Site function, security, load balancing
Legal basis: Legitimate Interest Assessment**
Data: Analytics cookies and identifiers
Purpose: Understanding site use and improving content
Legal basis: Consent
Data: Email address (required)
Purpose: Delivering the resource; sending communications you consented to
Legal basis: Consent
Data: Organisation name (required)
Purpose: Understanding our audience; relevance of communications
Legal basis: Consent
Data: Role (optional)
Purpose: Tailoring content
Legal basis: Consent
Data: Consent record — timestamp, IP, consent wording version, form version
Purpose: Demonstrating that consent was validly obtained, as we are required to do
Legal basis: Consent
Data: Email engagement data — opens, link clicks
Purpose: Measuring usefulness of communications
Legal basis: Consent
Hosting and website infrastructure providers:
Operating praecepta.co
Email marketing platform:
Delivering resources and communications
Analytics provider:
Aggregate site measurement, subject to your cookie consent
Cloud storage and productivity providers:
Business operations and secure document handling
Professional advisers — legal, accounting, tax, insurance:
Obtaining advice; maintaining cover
Associates and subcontractors:
Where engaged on a specific project, under equivalent confidentiality and data protection obligations
Channel partners:
Only where you are a contact on a jointly-delivered engagement, and only to the extent necessary
Banks and payment providers:
Processing payments
Website analytics:
Operating praecepta.co
Newsletter subscribers:
Until consent is withdrawn, then a suppression record only
Consent records:
For as long as needed to demonstrate valid consent, plus [PERIOD]
Enquiries not proceeding to engagement:
24 months
Client engagement records:
Term of engagement plus client association and communications
Financial and tax records:
As required by UAE law
Client register and conflict records:
Until legal and regulatory requirements deem necessary
Professional indemnity records:
For the applicable limitation period
