Privacy Notice
1. This notice at a glance
We are a business-to-business (B2B) data protection and compliance advisory practice. We keep personal data to a minimum. In short:
- Business contact data. We mainly process professional contact details of people at client, prospective client and supplier organisations.
- Two roles. When we deliver outsourced Data Protection Officer (DPO) and advisory services, we may handle personal data on behalf of our clients, acting on their documented instructions as a processor. For that data, our client remains responsible as the controller.
- What we don’t do. We do not sell personal data, we do not use it for automated decision-making, and our services and website are not directed at children.
- Your rights. You have rights over your personal data, and this notice explains how to exercise them and how to complain.
The rest of this notice gives the detail. It is written to meet the transparency requirements of the UK GDPR and EU GDPR (Articles 12–14), the guidance of the UK Information Commissioner’s Office (ICO), and the United Arab Emirates Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “UAE PDPL”), together with any regulations issued under those laws.
2. Who we are and how to contact us
Ayla Advisory (“Ayla”, “we”, “us”, “our”) is a professional advisory practice providing data protection, privacy and regulatory compliance services to business clients, including outsourced Data Protection Officer services, audits, assessments, training and related consultancy.
Legal entity name: Ayla Advisory Ltd
For anything in this notice, or to exercise your rights, contact us at:
- Email: shad@aylaadvisory.ae
We have appointed a senior privacy lead responsible for data protection compliance within our own business. If applicable law requires us to appoint a formally designated Data Protection Officer for our own processing, the contact details above reach that person.
3. Who and what this notice covers
This notice applies to:
- Business contacts — individuals at organisations that are our clients, prospective clients, suppliers or professional contacts (directors, employees, representatives);
- Website visitors and enquirers — anyone who visits our website, completes a contact form, subscribes to updates or corresponds with us;
- Event and training attendees — people attending our events, webinars or training sessions;
- Job applicants — individuals who apply to work with us.
It does not cover personal data we process on behalf of our clients when delivering our services — see section 5, which explains that distinction and what it means for you.
4. Our role: controller
For the categories of people listed in section 3, we decide why and how personal data is used. In data protection language, we are the “controller”, and this notice describes that processing in full.
5. Our role: processor (data we handle for our clients)
Delivering data protection advisory and outsourced DPO services sometimes requires us to access or handle personal data held by our clients — for example, when reviewing a subject access request response, auditing HR records, investigating a data breach or advising on a disclosure exercise. When we do this:
- The client is the controller. Our client determines the purposes and means of the processing.
- We are the processor. We act only on the client’s documented instructions, under a written contract that meets the requirements of Article 28 UK/EU GDPR and the equivalent provisions of the UAE PDPL, including confidentiality, security, sub-processing controls and deletion or return of data at the end of the engagement.
- Minimisation applies. We access only the personal data necessary for the specific engagement, for no longer than necessary.
If your personal data is included in material a client has asked us to work on, the client’s own privacy notice governs that processing, and rights requests should be directed to the client. If you contact us about data we process for a client, we will not ignore you — we will pass your request to the relevant client without undue delay and support them in responding, as their instructions and the law require.
6. The personal data we collect
| Category | Examples |
|---|---|
| Identity and business contact data | Name, job title, employer, work email address, work telephone number, business address, LinkedIn or other professional profile. |
| Engagement and relationship data | Correspondence with us, meeting notes, enquiry details, engagement history, billing and payment details for client organisations (which may identify individuals at smaller businesses). |
| Marketing preferences | Your subscription status, preferences and opt-outs. |
| Technical and usage data | IP address, browser type and version, device identifiers, pages visited, referral source and interaction data collected through cookies and similar technologies when you use our website. |
| Event and training data | Registration details, attendance records, dietary or access requirements you choose to share for in-person events. |
| Recruitment data | CV, work history, qualifications, references and right-to-work information for applicants. |
We do not seek to collect special category data (such as health, religion or biometric data) or criminal offence data through our website or business development activity. Where a client engagement requires us to handle such data on the client’s behalf, section 5 applies and additional safeguards are agreed with the client in writing.
7. How we collect personal data
- Directly from you — when you contact us, complete a form on our website, subscribe to updates, register for an event or engage our services;
- From your organisation or a referrer — when a colleague at your organisation gives us your details as a point of contact, or a professional contact introduces us;
- From publicly available sources — business contact details from your organisation’s website, professional directories or LinkedIn, used proportionately for legitimate business development;
- Automatically — cookies and analytics tools collect technical data when you browse our website (see section 10).
8. Why we use your data and our lawful bases
The table below sets out each purpose and the lawful basis we rely on under Article 6 UK/EU GDPR and, in parallel, under Article 4 of the UAE PDPL, which permits processing without consent where necessary for a contract, a legal obligation or other grounds specified in that law.
| Purpose | UK / EU GDPR basis | UAE PDPL position |
|---|---|---|
| Responding to enquiries and providing proposals | Legitimate interests (running and growing our business); contract, where steps are taken at your request before entering one | Processing necessary for contract to which the data subject (or their organisation) is party, or legitimate purpose consistent with Art. 4 |
| Delivering our services, managing client relationships, billing and accounts | Contract; legitimate interests (administering client relationships where the contract is with your employer); legal obligation (accounting and tax records) | Contractual necessity; compliance with applicable law |
| B2B marketing: updates, insights, invitations to relevant contacts | Legitimate interests (promoting our services to relevant business audiences), with an opt-out in every message; consent where required by e-privacy rules | Legitimate purpose, with the right to object and opt out honoured at any time |
| Operating, securing and improving our website | Legitimate interests (security, fraud prevention, service improvement); consent for non-essential cookies | Legitimate purpose; consent for non-essential cookies |
| Complying with legal and regulatory obligations (tax, AML/KYC checks where applicable, responding to lawful requests) | Legal obligation; legitimate interests | Compliance with applicable UAE and other laws |
| Establishing, exercising or defending legal claims; managing insurance | Legitimate interests; legal claims provisions | Protection of legal rights and claims |
| Recruitment | Legitimate interests; contract (pre-employment steps); legal obligation (right to work) | Contractual and legal necessity |
Where we rely on legitimate interests we have carried out a balancing assessment: the data involved is limited, professional in nature and used in ways a business contact would reasonably expect. You can ask us for a summary of any of these assessments, and you can object at any time (see section 14).
9. Business-to-business marketing
Our marketing is aimed at organisations, not consumers. We send occasional, relevant updates — regulatory developments, insights and event invitations — to professional contacts. Every message includes a clear, one-click way to opt out, and we honour opt-outs promptly and permanently. Where the e-privacy rules of a particular jurisdiction require consent for electronic marketing to you, we will obtain it. We never sell or rent contact lists.
10. Cookies and similar technologies
Our website uses:
- Strictly necessary cookies — required for the site to function and for security. These do not need your consent.
- Analytics and performance cookies — which help us understand how the site is used so we can improve it. We ask for your consent through the cookie banner before setting these, and you can change your choice at any time via the cookie settings link on our website.
Full details of each cookie, its purpose and its lifespan are set out in our separate Cookie Policy on the website. We do not use cookies for third-party behavioural advertising.
11. Who we share personal data with
We share personal data only where necessary, with:
- Service providers — IT, hosting, email, document management, CRM and similar suppliers who process data for us under written contracts containing data protection obligations at least as protective as those we owe you;
- Professional advisers — accountants, auditors, lawyers and insurers, under professional duties of confidentiality;
- Regulators and authorities — where the law requires or permits disclosure, such as tax authorities, courts or data protection regulators;
- A prospective buyer or successor — in the event of a merger, acquisition or reorganisation, under confidentiality protections, with notice where required.
We require every supplier who processes personal data for us to commit contractually to confidentiality, security, breach notification and deletion obligations, and we do not permit them to use the data for their own purposes.
12. International transfers
We operate internationally, and personal data may be transferred between the United Kingdom, the European Economic Area, the United Arab Emirates and other countries where our clients, suppliers or systems are located. Where personal data protected by UK or EU law is transferred to a country without an adequacy decision, we use approved safeguards, the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses, supported by a transfer risk assessment where appropriate.
Where personal data is transferred out of the UAE, we comply with the transfer conditions of the UAE PDPL and any implementing regulations, using adequacy, appropriate contractual safeguards or another lawful transfer ground. You can ask us for details of the safeguards applied to any specific transfer.
13. How long we keep personal data
We keep personal data only as long as needed for the purpose it was collected, then delete or anonymise it. Our standard periods are:
| Record type | Standard retention period |
|---|---|
| Enquiries that do not become client engagements | 12 months from last contact |
| Client engagement files and correspondence | 6 years from the end of the engagement (limitation periods for legal claims), unless law or regulation requires longer |
| Accounting, tax and billing records | As required by applicable tax law (typically 5–7 years) |
| Marketing contact data | Until you opt out or 24 months of inactivity, whichever is sooner; opt-out records kept indefinitely on a suppression list |
| Website analytics data | 13 months, then aggregated or deleted |
| Unsuccessful recruitment applications | 6 months from the conclusion of the process, unless you agree to a longer talent-pool period |
| Client personal data processed under section 5 | Returned or deleted at the end of the engagement, as the client instructs |
14. How we protect personal data
We apply technical and organisational measures appropriate to the risk, consistent with Article 32 UK/EU GDPR and the security obligations of the UAE PDPL, including encryption of data in transit and at rest, access controls on a need-to-know basis, multi-factor authentication, vetted suppliers, staff confidentiality obligations and training, and documented incident response procedures. If a personal data breach occurs that is likely to result in a risk to you, we will notify the relevant supervisory authority and, where the risk is high, notify you, in each case within the timescales the applicable law requires.
15. Your rights
Subject to the conditions and exemptions in the applicable law, you have the right to:
- Access — obtain a copy of your personal data and information about how we use it (subject access);
- Rectification — have inaccurate data corrected and incomplete data completed;
- Erasure — have your data deleted where there is no longer a good reason for us to hold it;
- Restriction — limit how we use your data in certain circumstances;
- Portability — receive certain data in a portable, machine-readable format;
- Objection — object to processing based on legitimate interests, and to direct marketing at any time — marketing objections are always honoured without exception;
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.
These rights arise under Articles 15–22 UK/EU GDPR and, for processing subject to UAE law, under the UAE PDPL, which provides equivalent rights of access, correction, erasure, restriction, objection and portability.
How to exercise them
Email us at shad@aylaadvisory.ae. We do not charge a fee. We may need to verify your identity, and we ask only for what is proportionate to do so. We will respond within one month; if a request is complex we may extend by up to two further months, and we will tell you within the first month if so. If an exemption applies to any part of your request, we will explain which one and why, so far as the law allows.
If your request concerns personal data we process on behalf of a client (section 5), we will forward it to that client promptly — the legal duty to respond sits with them as controller, and we will support their response.
How to complain
If you are unhappy with anything we have done with your personal data, please raise it with us first — we take complaints seriously, will acknowledge your complaint within 30 days and will respond without undue delay. You also have the right to complain to a supervisory authority at any time:
- United Kingdom: the Information Commissioner’s Office (ICO) ico.org.uk;
- European Union: the data protection authority of the EU member state where you live or work;
- United Arab Emirates: the UAE Data Office, the federal data protection authority established under the UAE PDPL.
16. Automated decision-making and profiling
We do not make decisions about you based solely on automated processing, and we do not profile individuals. If that ever changes, we will update this notice and put in place the safeguards the law requires before doing so.
17. Children
Our website and services are directed at businesses and professionals. We do not knowingly collect personal data relating to anyone under 18, and if we become aware that we have done so we will delete it.
18. Changes to this notice
We review this notice at least annually and whenever our processing or the law changes materially. The version and date at the top tell you when it was last updated; significant changes will be flagged on our website. If you have any questions, contact us at shad@aylaadvisory.ae.
© Ayla Advisory 2026. This notice is provided for transparency and does not create contractual rights beyond those conferred by applicable data protection law.

