top of page

PRIVACY NOTICE

PRAECEPTA CYBERSECURITY LLC — PRIVACY NOTICE
Version 1.0 · August 2026 · Reviewed annually

1. Who we are

 

PRAECEPTA CYBERSECURITY LLC ("PRAECEPTA", "we", "us") is a company registered in Dubai, United Arab Emirates.

 

Registered address: Sail Star Business Center, Bay Square, Business Bay, Dubai, United Arab Emirates
Privacy contact: [privacy@praecepta.ae]

 

We are the controller of the personal data described in this Notice.

 

2. What this Notice covers

 

This Notice explains how we handle personal data when you visit praecepta.co, download our published resources, subscribe to our communications, contact us, or engage us for professional services.

 

It does not cover personal data we process on behalf of a client while delivering services. In those engagements we generally act as a processor, the client is the controller, and their privacy notice governs. Our obligations are set out in the Data Processing Addendum to the relevant engagement agreement.

 
3. Personal data we collect
 
3.1 Website visitors

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

3.2 Resource downloads and subscribers

 

Where you request our Working Pack, subscribe to our newsletter, or request another gated resource:

​​​​​​​

​​​​​Our ungated resources require no personal data. The framework crosswalk PDF and other ungated publications download without a form, without registration, and without consent to marketing. Consent to receive communications is never a condition of accessing them.

 
3.3 Enquiries and prospective clients

 

Name, job title, organisation, email, telephone, and the content of your enquiry — including any information you choose to share about your organisation's security or compliance position.

 

Please do not send us sensitive technical detail about your security posture, vulnerabilities, or incidents through the website contact form or by unencrypted email. We will arrange a secure channel. If you have already done so, tell us and we will handle it appropriately.

 
3.4 Clients and engagement contacts

 

Name, job title, organisation, contact details, engagement correspondence, meeting records, contractual documentation, and billing and payment information.

 
3.5 Suppliers, associates and subcontractors

 

Contact details, contractual documentation, professional credentials, insurance certificates, and payment details.

 
3.6 Special categories of personal data

 

We do not seek and do not require special categories of personal data. If any is disclosed to us incidentally — for example within evidence provided during an engagement — we minimise, restrict access to, and delete it at the earliest opportunity, and we will tell the client.

 
4. Why we process personal data
  • Providing professional services under an engagement agreement

  • Responding to enquiries and preparing proposals

  • Delivering resources you have requested

  • Sending communications you have consented to receive

  • Operating and securing our website

  • Managing supplier and associate relationships

  • Invoicing, payment and financial record-keeping

  • Complying with legal, regulatory, tax and accounting obligations

  • Maintaining professional indemnity cover and, if required, defending claims

  • Maintaining our client register and conflict-of-interest records — see §5

 
5. Our client register and conflict checks

 

We maintain a register of clients and active business pursuits. It exists so that we can honour non-solicitation undertakings given to channel partners, identify conflicts of interest before accepting engagements, and comply with our published Declaration of Interests.

 

It contains organisation names, engagement dates and scope, and the names of key contacts. 

 
6. Who we share personal data with

 

We do not sell personal data. We do not share it for third-party marketing.

 

​​

7. International transfers

 

Some of our service providers process personal data outside the UAE.

 

Under the PDPL, transfer of personal data outside the UAE is permitted where the destination provides an adequate level of protection, or where another permitted basis or safeguard applies.

We minimise cross-border transfer where practical, and prefer providers offering UAE or regional hosting where a viable option exists.

 
8. How long we keep personal data

 

​​​​​

9. Your rights

 

Subject to applicable law and any permitted exceptions, you have the right to:

  • Be informed about how your personal data is processed

  • Access your personal data

  • Correct or rectify inaccurate or incomplete data

  • Request erasure of your personal data

  • Request restriction of processing

  • Data portability — receive your data in a structured, machine-readable format

  • Object to, or stop, processing — including processing for direct marketing purposes

  • Rights in relation to automated decision-making and profiling

 

We do not use automated decision-making or profiling that produces legal or similarly significant effects.

 

Withdrawing consent. Where we rely on consent, you may withdraw it at any time — use the unsubscribe link in any email, or contact us. Withdrawal is straightforward and carries no penalty. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

 

How to exercise your rights. Email [privacy@praecepta.ae]. We will respond within one month of receipt. Where a request is complex or onerous, we may extend by a further two months and will tell you if we do.

 

10. Security

 

We apply technical and organisational measures appropriate to the risk, including: encryption in transit and at rest; multi-factor authentication on all administrative accounts; least-privilege access control; network protection; logging and monitoring; secure document handling for client material; and defined retention and deletion.

 

We are a security practice and we hold ourselves to the standards we advise. If you believe you have identified a vulnerability in praecepta.co, please tell us at [security@praecepta.co]. We will acknowledge and investigate, and we will not pursue good-faith security research.

 
11. Personal data breaches

 

Where a personal data breach occurs, we will assess it, take steps to contain and remedy it, and notify the UAE Data Office promptly after becoming aware of it, in accordance with applicable requirements. Where the breach is likely to prejudice the privacy, confidentiality, security, integrity or rights of affected individuals, we will notify those individuals.

12. Complaints

 

If you are dissatisfied with how we have handled your personal data, contact us first at [privacy@praecepta.ae] and we will investigate.

 

You also have the right to complain to the UAE Data Office.

 
13. Changes

 

We review this Notice at least annually. The version number and date appear at the top. Where changes materially affect how we process your personal data, we will notify subscribers directly.

 
14. Contact

 

PRAECEPTA CYBERSECURITY LLC
Sail Star Business Center, Bay Square, Business Bay, Dubai, United Arab Emirates
Privacy: [
privacy@praecepta.ae] · Security: [security@praecepta.ae]

Data: IP address, browser type, device type, operating system, referring page, pages viewed, time and date 

Purpose: Site security, fraud prevention, operation, aggregate traffic measurement

Legal basis: Legitimate Interest Assessment**

Data: Essential Cookies

Purpose: Site function, security, load balancing

Legal basisLegitimate Interest Assessment**

Data: Analytics cookies and identifiers

Purpose: Understanding site use and improving content

Legal basis: Consent

Data: Email address (required) 

Purpose: Delivering the resource; sending communications you consented to

Legal basis: Consent

Data: Organisation name (required)

Purpose: Understanding our audience; relevance of communications

Legal basis: Consent

Data: Role (optional)

Purpose: Tailoring content

Legal basis: Consent

Data: Consent record — timestamp, IP, consent wording version, form version

Purpose: Demonstrating that consent was validly obtained, as we are required to do

Legal basis: Consent

Data: Email engagement data — opens, link clicks

Purpose: Measuring usefulness of communications

Legal basis: Consent

Hosting and website infrastructure providers:

Operating praecepta.co

Email marketing platform:

Delivering resources and communications

Analytics provider: 

Aggregate site measurement, subject to your cookie consent

Cloud storage and productivity providers: 

Business operations and secure document handling

Professional advisers — legal, accounting, tax, insurance: 

Obtaining advice; maintaining cover

Associates and subcontractors: 

Where engaged on a specific project, under equivalent confidentiality and data protection obligations

Channel partners: 

Only where you are a contact on a jointly-delivered engagement, and only to the extent necessary

Banks and payment providers: 

Processing payments

Website analytics:

Operating praecepta.co

Newsletter subscribers:

Until consent is withdrawn, then a suppression record only

Consent records: 

For as long as needed to demonstrate valid consent, plus [PERIOD]

Enquiries not proceeding to engagement: 

24 months

Client engagement records: 

Term of engagement plus client association and communications

Financial and tax records: 

As required by UAE law

Client register and conflict records: 

Until legal and regulatory requirements deem necessary

Professional indemnity records: 

For the applicable limitation period

bottom of page