Data Protection

Data Protection

Personal Data Protection Policy (Processor)

Last updated: September 26, 2026 · Version 1.0

Introduction, scope and purpose

This Policy explains how Meena Business Consultancy Services (“Meena”, “we”, “us”) protects personal data that we process on behalf of our clients while delivering our services — for example company formation, visa and PRO services, accounting and payroll, employee leasing, business matchmaking and market research. In these cases the client is the data “controller” and Meena acts as a data “processor”.

This Policy does not cover personal data that Meena collects and uses for its own purposes (for example, visitors to this website or people who contact us directly). That is governed by our Privacy Policy. Where a signed services agreement or data processing agreement exists between you and Meena, that agreement prevails over this Policy to the extent of any conflict.

Meena Business Consultancy Services is registered in the Ajman Free Zone, United Arab Emirates (Free Zone License No. 31732), with its registered office at Building C1, Ajman Free Zone, UAE.

1. Personal data we process

We process personal data only as needed to deliver the services set out in the client’s services agreement. Depending on the service, this may include names and contact details; passport, Emirates ID or national ID information; visa and immigration data; employment and payroll details; shareholder and beneficial-owner information; and business-partner or candidate contact data. The specific categories, purposes and retention period for each engagement are defined in the relevant services agreement.

2. How we use personal data

We process client personal data only on the client’s documented instructions and for the purpose of providing the agreed services, unless we are required to process it by applicable law. We do not sell personal data. We may use aggregated or anonymised data — which no longer identifies any individual — for internal analysis and service improvement.

3. Sub-processing

To deliver some services we rely on trusted third parties — for example cloud hosting, IT and communication providers, and local partners or government-liaison agents in the markets we serve. We engage sub-processors only under written terms that impose data-protection obligations equivalent to those in this Policy, and we remain responsible for their performance. A current list of the categories of sub-processors we use is available to clients on request at dataprotection@meenasonline.com. Clients may request information about the categories of sub-processors used to provide our services, including relevant hosting, IT, communication, and other service providers.

4. Confidentiality and security

We keep personal data confidential and require our staff and sub-processors to do the same. We apply appropriate technical and organisational measures to protect personal data against accidental or unlawful loss, alteration, and unauthorised disclosure or access, taking into account the nature of the data and the risks involved. We implement access controls and user permissions to limit access to personal data to authorised personnel. We use appropriate authentication and security measures to protect personal data against unauthorised access, loss, alteration, or disclosure. Staff and relevant service providers are required to maintain confidentiality.

5. Co-operating with client requests

Where required by applicable data-protection law, we assist clients with: (a) responding to requests from individuals exercising their rights, such as access, correction, deletion or objection; (b) data-protection impact assessments; and (c) reasonable audits to demonstrate our compliance, on reasonable prior notice and during normal business hours.

6. Deletion or return of data

At the end of the relevant services, we will — at the client’s choice — delete or return the personal data we processed on their behalf, unless we are required by law to retain it. Retention periods for specific engagements are set out in the applicable services agreement.

7. Incident management

If we become aware of a personal-data breach affecting data we process for a client, we will notify the client without undue delay and provide the information reasonably needed for the client to meet its own notification obligations. We will co-operate with the client on investigating, mitigating and remediating the breach.

8. International transfers of personal data

Meena operates across the UAE, Saudi Arabia, Qatar, Iraq, Pakistan and Europe, so delivering our services may involve transferring personal data between these countries. Where personal data is transferred across borders, we apply the safeguards required by the relevant law — for example the UAE PDPL, the EU/EEA GDPR, the Saudi Arabia PDPL and Qatar Law No. 13 of 2016 — such as standard contractual clauses or equivalent measures where applicable.

9. Liability

Each party’s liability in connection with the processing of personal data is governed by the services agreement between the client and Meena.

10. Contact us

For any questions about this Policy, or to make a data-protection request relating to data we process on behalf of a client, please contact:

Meena Business Consultancy Services — Data Protection
Building C1, Ajman Free Zone, United Arab Emirates
Email: dataprotection@meenasonline.com
Phone: +971 50 623 9155

Definitions

Related documents

Privacy Policy · Terms & Conditions · Cookie Settings

Changes to this Policy

We may update this Policy from time to time. The version in effect when your services agreement takes effect will continue to apply to that agreement unless we agree otherwise in writing. Last updated: September 26, 2026.

Chat with Meena