GDPR Statement
GDPR Statement
Last updated: September 26, 2026 · Version 1.0
Meena Business Consultancy Services (“Meena”, “we”, “us”) takes the privacy of its clients, business partners, candidates and staff seriously, and takes care to protect the personal data entrusted to us. Because we advise and support clients in and from the European Economic Area (EEA) — including Germany, where our founders hold BVMW and AHK backgrounds and where we run our “Live in Germany” service — we handle personal data in line with the EU General Data Protection Regulation (GDPR), alongside the other data-protection laws that apply to our work (including the UAE PDPL, the Saudi Arabia PDPL and Qatar Law No. 13 of 2016).
This statement summarises the organisational and technical measures we take to support GDPR compliance. It should be read together with our Privacy Policy (how we handle personal data as a controller) and our Data Protection page (how we process personal data on behalf of clients).
We apply the principles of privacy by design and privacy by default: we consider data protection when we design services, select tools and engage partners, and we limit the personal data we collect and use to what is necessary for the purpose.
Data-protection organisational measures
- Our internal and external privacy policies and statements reflect GDPR requirements.
- Staff are bound by confidentiality and are required to follow our internal data-protection procedures.
- Access to personal data and systems is limited to what each person needs to do their job (least privilege), and duties are separated so that no single person controls a critical process end to end.
- We enter written agreements with the sub-processors and partners who handle personal data on our behalf, requiring equivalent data-protection safeguards.
- Where required, we assess data-protection risks before launching new services or tools that process personal data (data protection impact assessments).
- We keep records of our processing activities where the law requires, and we maintain a dedicated contact for data-protection questions and requests.
- Staff receive data-protection guidance as part of their responsibilities, and internal data-protection practices are reviewed periodically.
Data-protection technical and security measures
- Access to personal data is restricted to authorised staff and reviewed periodically.
- We apply cybersecurity measures proportionate to the size of our organisation and systems.
- Personal data is protected in storage and transmission using appropriate measures.
- Personal data is protected during transmission using appropriate security measures, and access to systems is restricted through user accounts and permissions. Where supported by our service providers, encryption and secure backups are used.
- User accounts and permissions are managed by authorised personnel and reviewed regularly.
Your rights under the GDPR
If you are in the EEA, the GDPR gives you rights over your personal data — including access, rectification, erasure, restriction of processing, data portability, and objection. How to exercise these rights is set out in our Privacy Policy (European Economic Area — GDPR).
International transfers
Delivering our services may involve transferring personal data from the EEA to countries where we operate, such as the UAE. Where we do this, we apply the safeguards required by the GDPR — such as the EU Standard Contractual Clauses or equivalent measures.
More information and contact
We encourage clients, suppliers and partners to review our Privacy Policy and Data Protection page. For any GDPR-related question or request, please contact:
Meena Business Consultancy Services — Data Protection
Building C1, Ajman Free Zone, United Arab Emirates
Email: dataprotection@meenasonline.com · Phone: +971 50 623 9155
Changes to this statement
We may update this statement from time to time to reflect changes in our practices or the law. Last updated: September 26, 2026 · Version 1.0.