Effective / Last Updated: 17 July 2026
1. Introduction
This Privacy Policy explains how Stratrich Consulting ("Stratrich," "we," "us," or "our") collects, uses, discloses, stores, transfers and protects your personal data when you:
- visit or interact with our website https://stratrich.com/ae/ (the "Website");
- submit an enquiry, book a free consultation, use the cost calculator, or download a guide;
- engage us for company formation, business setup, taxation, accounting, corporate, advisory or regulatory services in the UAE (the "Services"); or
- communicate with us by phone, email, WhatsApp, or social media.
This Policy is issued in compliance with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and Federal Decree-Law No. 44 of 2021 establishing the UAE Data Office. The Executive Regulations contemplated by the PDPL had not been issued as at the date of this Policy; under Article 51 of the PDPL, controllers have six months from their issuance to align their processing. We nevertheless apply the substantive requirements of the PDPL in full, and will update this Policy once the Executive Regulations are published. We are established in IFZA, which is not a financial free zone; the federal PDPL therefore applies to us, and the DIFC Data Protection Law No. 5 of 2020 and the ADGM Data Protection Regulations 2021 do not, except in respect of personal data we process on behalf of a client established in those centres. Where we offer goods or services to, or monitor the behaviour of, individuals located in the United Kingdom or the European Economic Area (EEA), we additionally process personal data in accordance with (i) the UK General Data Protection Regulation (UK GDPR) as amended by the Data (Use and Access) Act 2025 (DUAA), the Data Protection Act 2018 and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR); and (ii) Regulation (EU) 2016/679 (the EU GDPR) and the ePrivacy Directive 2002/58/EC as implemented in each EEA Member State. In this Policy, a reference to the GDPR is a reference to both the UK GDPR and the EU GDPR; where the UK and EEA positions differ, the difference is stated expressly. Sections 16 and 17 set out the additional information and rights that apply to individuals in the UK and the EEA. Please read this Policy together with our Terms & Conditions. If you do not agree, please do not use the Website or submit your information to us.
2. Who We Are (Data Controller)
Stratrich Consulting is the trading name of Stratrich Consulting FZCO, a free zone company established in IFZA, Dubai. We act as the Data Controller under the PDPL, and under the GDPR in respect of personal data of individuals in the United Kingdom and the EEA that we process for our own purposes. Where we process personal data on behalf of a client under an Engagement Agreement, we act as a Data Processor and that client's privacy notice governs that processing.
- Email: contact@stratrich.com
- Phone: (+971) 55251 3649
- Office: IFZA Business Park, Building A1, DDP, PO Box 342001, Dubai, UAE.
- Data protection contact: contact@stratrich.com
Data Protection Officer. We have assessed the criteria for appointing a Data Protection Officer under the PDPL, and under Article 37 of the UK GDPR and of the EU GDPR, having regard to the volume and sensitivity of the personal data we process and the risk to data subjects, and [have appointed [insert name] as our Data Protection Officer / have concluded that appointment is not presently required, and the data protection contact above handles all data protection matters].
Representatives. We are not established in the United Kingdom or in the EEA. We have assessed our position under Article 27 of the UK GDPR and Article 27 of the EU GDPR and rely in each case on the exemption in Article 27(2)(a), because the relevant processing is occasional, is not carried out on a large scale, does not involve special category or criminal offence data on a large scale, and is unlikely to result in a risk to individuals. Where a representative is appointed, that appointment does not limit our own responsibility or liability.
3. The Personal Data We Collect
a. Information you provide directly
- Identity and contact details: name, email, phone/WhatsApp number, company name, job title, nationality and location.
- Enquiry details: the service you are interested in (Free Zone, Mainland, Offshore, tax/accounting, PRO, visa, etc.), how you heard about us, and the content of your message or consultation request.
- Guide-download and cost-calculator details: the information you submit to download guides or generate an estimate.
- Engagement information (for clients): shareholder/director/partner details, passport and identification documents, corporate documents, financial information, and other onboarding, licensing, visa and KYC data required to deliver the Services.
b. Information collected automatically
- Technical and usage data: IP address, browser and device information, operating system, referring URLs, pages viewed, and dates/times of visits.
- Cookies and similar technologies, including tags managed via Google Tag Manager and analytics tools (see Section 8).
c. Information from third parties
- Publicly available business information, referral partners, partner free zones and authorities, where relevant to the Services.
Sensitive and special category data. Passport copies, Emirates ID, visa and immigration documents supplied for onboarding, licensing and KYC purposes may reveal data treated as sensitive personal data under the PDPL and as special category data under Article 9 of the UK GDPR and of the EU GDPR. We collect such data only where it is required by the relevant free zone, immigration, tax or anti-money-laundering authority or by our own regulatory obligations; we restrict access to personnel who need it; and where the GDPR applies we rely on Article 9(2)(f) (legal claims) or Article 9(2)(g), read in the UK with the relevant condition in Schedule 1 to the Data Protection Act 2018 and in the EEA with the applicable Member State law.
Automated decision-making and profiling. The cost calculator produces an indicative estimate only and is not a decision about you. We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing, and we do not profile you for those purposes. The DUAA relaxed the restrictions in Article 22 of the UK GDPR; the equivalent restriction in the EU GDPR was not relaxed, and we apply the stricter EU standard to all individuals.
4. How We Use Your Personal Data
We use personal data to:
- respond to enquiries, provide requested guides and estimates, and schedule consultations;
- provide, administer and improve the Services and our client relationship;
- carry out onboarding, verification and compliance checks (including KYC and anti-money-laundering requirements where applicable);
- process company formation, trade licence, visa, PRO and related applications with free zones, authorities and government bodies;
- communicate about your enquiries, engagements, and — where permitted — relevant insights, guides and marketing (from which you may opt out);
- operate, secure and improve the Website;
- comply with legal, regulatory and professional obligations (including UAE corporate tax and VAT requirements); and
- establish, exercise or defend legal claims and protect our rights and those of others.
5. Legal Basis / Consent
(a) Individuals in the UAE — PDPL. Under the PDPL, processing generally requires the consent of the data subject, which must be given by a clear affirmative act, must be specific and informed, and must be capable of being withdrawn as easily as it was given. We rely on your consent when you submit a form, use the cost calculator or request a guide. We also rely on the cases in which the PDPL provides that consent is not required — principally where processing is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into a contract; to comply with a legal obligation to which we are subject; to establish, exercise or defend legal claims; or to protect the public interest.
(b) Withdrawal of consent. You may withdraw your consent at any time by contacting us. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and does not affect processing that we may lawfully continue on a basis other than consent — for example records we are required to retain under anti-money-laundering, immigration, corporate tax or VAT legislation.
(c) Individuals in the United Kingdom and the EEA — UK GDPR and EU GDPR. Where the GDPR applies we rely on: consent (Article 6(1)(a)) for optional marketing and non-essential cookies; performance of a contract, or steps taken at your request before entering into a contract (Article 6(1)(b)); compliance with a legal obligation (Article 6(1)(c)); and our legitimate interests (Article 6(1)(f)) in responding to enquiries, administering and securing the Website, preventing fraud, and promoting our services to business contacts — in each case supported by a documented legitimate interests assessment, a copy of which is available on request. The ‘recognised legitimate interests’ basis in Article 6(1)(ea) exists only under the UK GDPR and has no equivalent under the EU GDPR; we do not rely on it for routine Website processing.
6. How We Share Your Personal Data
We do not sell your personal data. We may share it with:
- Stratrich offices and personnel delivering the Services;
- Service providers / Data Processors (IT, hosting, communications, analytics, CRM and marketing) under confidentiality and data-protection obligations;
- Free zones, government and regulatory authorities (e.g. IFZA and other free zone authorities, the Department of Economy & Tourism, immigration and labour authorities, the Federal Tax Authority) as required to complete formation, licensing, visa and tax processes;
- Professional advisers (auditors, lawyers) and, in a business transaction, relevant parties; and
- Others where required by law, court order, or to protect our rights.
Every Data Processor we engage acts only on our documented instructions under a written contract imposing confidentiality, security, sub-processing, audit, breach-notification and deletion obligations that meet the requirements of the PDPL and, where applicable, Article 28 of the UK GDPR and of the EU GDPR. We remain responsible for compliance in respect of processing carried out on our behalf. We do not sell your personal data, and we do not share it for cross-context behavioural advertising or with data brokers.
7. International Data Transfers
(a) Transfers out of the UAE. Stratrich operates across the UAE and India, and your personal data may be transferred to and processed in countries outside the UAE in the course of delivering the Services. Articles 22 and 23 of the PDPL permit such transfers where the destination has an adequate level of protection as determined by the UAE Data Office, and otherwise on the basis of a contract or undertaking containing the protections required by the PDPL, your explicit consent, or one of the specific necessity grounds set out in the PDPL. The UAE Data Office has not yet published an adequacy list; we therefore transfer personal data outside the UAE on the basis of written contractual safeguards, and will review our transfer mechanisms once an adequacy list and the Executive Regulations are issued.
(b) Transfers out of the United Kingdom and the EEA. Neither the UAE nor India is the subject of UK adequacy regulations, or of a European Commission adequacy decision under Article 45 of the EU GDPR. Where personal data is transferred from the United Kingdom we put in place the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses. Where personal data is transferred from the EEA we put in place the European Commission's Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914, in the module appropriate to the transfer.
In each case the safeguard is supported by a risk assessment of the destination country — referred to in UK legislation as a ‘data protection test’, and under the EU GDPR as a transfer impact assessment — and, where necessary, by supplementary technical and organisational measures. This applies equally to onward flows to our India delivery centres. We rely on a derogation under Article 49 of the UK GDPR or of the EU GDPR only where one genuinely applies. You may request a copy of the safeguards we use for a particular transfer by contacting us using the details in Section 18.
8. Cookies and Tracking Technologies
Our Website uses cookies and similar technologies, including tags deployed through Google Tag Manager and web analytics tools. Strictly necessary cookies, which are required to deliver the Website and the functionality you request, are set without consent. All other cookies — including analytics, performance, functionality and advertising cookies — are set only after you have given consent through our cookie banner, and you may withdraw or change your consent at any time through the ‘Cookie settings’ link on the Website. This reflects Regulation 6 of PECR, Article 5(3) of the ePrivacy Directive 2002/58/EC as implemented in EEA Member States, and the consent standard in the GDPR, all of which we apply to every visitor. You may also control or delete cookies through your browser settings, although disabling certain cookies may affect Website functionality. Details of the individual cookies we set, their purpose and their duration are set out in our Cookie Policy.
9. Data Retention
We retain personal data only for as long as is necessary for the purposes set out in this Policy. Indicatively: enquiry, guide-download and cost-calculator records are retained for [24] months from your last interaction with us; marketing contact records are retained until you opt out and thereafter only as a suppression record so that we do not contact you again; and client engagement records, including customer due diligence records, are retained for the periods required by UAE law — [five] years from the end of the business relationship or completion of the transaction under the UAE anti-money-laundering legislation applicable to designated non-financial businesses and professions, and up to [seven] years for records required under the UAE Corporate Tax and VAT legislation. Where a longer period is required by law, or where records are relevant to actual or anticipated legal, regulatory or disciplinary proceedings, we retain them until that requirement or matter is concluded. When personal data is no longer required we securely delete or irreversibly anonymise it, and we require our Data Processors to do the same.
10. Data Security
We implement appropriate technical and organisational security measures as required by the PDPL and by Article 32 of the UK GDPR and of the EU GDPR. These include access control on a need-to-know basis, multi-factor authentication, encryption of personal data in transit and at rest, network and endpoint protection, logging and monitoring, secure backups, staff confidentiality undertakings and training, and due diligence over our Data Processors. These controls are operated within our ISO/IEC 27001:2022-certified information security management system. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Personal data breaches. Where a personal data breach occurs we will notify the UAE Data Office immediately upon becoming aware of it, and will notify affected data subjects where the breach would prejudice their privacy, confidentiality or security, in each case as required by the PDPL. Where the GDPR applies, we will notify the competent supervisory authority — the Information Commissioner's Office in the United Kingdom, and the relevant EEA supervisory authority for EEA-related processing — within 72 hours of becoming aware of the breach unless it is unlikely to result in a risk to individuals, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
11. Your Rights (PDPL – Federal Decree-Law No. 45 of 2021)
Subject to the PDPL, you have the right to:
- request information about and access to your personal data;
- request correction or rectification of inaccurate data;
- request deletion of your personal data;
- restrict or object to certain processing;
- request data portability where applicable;
- withdraw consent at any time; and
- lodge a complaint with the UAE Data Office where you believe your rights have been infringed.
contact@stratrich.com To exercise any right, contact our data protection contact at contact@stratrich.com. We may take reasonable steps to verify your identity before responding, and will respond within the timeframes required by law. Some of these rights are qualified: we may decline or limit a request where the personal data is required for the performance of a contract, for compliance with a legal or regulatory obligation (including anti-money-laundering, immigration, corporate tax and VAT record-keeping), for the establishment, exercise or defence of legal claims, or where the request is manifestly unfounded or excessive. If we decline, we will tell you why. If you remain dissatisfied, you may escalate in accordance with Section 17. Individuals in the United Kingdom and the EEA should also read Section 16.
12. Marketing Communications
contact@stratrich.com Where permitted, we may send you insights, guides, event invitations and service updates. For individuals in the United Kingdom we send electronic marketing only where you have consented, or where the ‘soft opt-in’ in Regulation 22 of PECR applies because you gave us your details in the course of negotiations for our services and we are marketing similar services. For individuals in the EEA we send electronic marketing in accordance with Article 13 of the ePrivacy Directive as implemented in the relevant Member State, which generally requires consent, subject to a comparable existing-customer exemption; Member State rules on marketing to corporate subscribers vary, and we apply the stricter rule where we are uncertain. For individuals in the UAE we send marketing only on the basis of your consent, and in accordance with applicable UAE electronic marketing requirements. Every message contains an unsubscribe link, and you may opt out at any time by contacting contact@stratrich.com. We do not sell, rent or licence our marketing lists.
13. Children's Data
The Website and Services are directed at businesses and professionals and are not directed at children. Under Federal Decree-Law No. 26 of 2025 on Child Digital Safety, which came into force on 1 January 2026, a child is an individual under 18 years of age; that law restricts the collection and processing of the personal data of children under 13 by digital platforms except in defined circumstances, and restricts the profiling of children for marketing. We do not knowingly collect the personal data of children, we do not carry out behavioural profiling of children, and we do not direct advertising at children. Where the UK GDPR applies we do not knowingly offer information society services directly to a child under 13 without parental consent; under Article 8 of the EU GDPR the equivalent age is 16 unless the relevant Member State has set a lower age, which may not be below 13. If you believe a child has provided us with personal data, please contact us and we will delete it.
14. Third-Party Links
The Website may contain links to third-party websites, social media platforms (LinkedIn, Instagram, X, YouTube) and embedded content (such as YouTube videos). This Policy does not apply to those third parties, and we are not responsible for their practices.
15. Changes to This Policy
We may update this Policy from time to time. The updated version will be posted on the Website with a revised "Last Updated" date. Continued use after changes are posted constitutes acceptance.
16. Your Rights under the UK GDPR and the EU GDPR (individuals in the United Kingdom and the EEA)
If you are located in the United Kingdom or the EEA, or your personal data is otherwise subject to the GDPR, you have the right to: request access to your personal data and a copy of it; have inaccurate data rectified and incomplete data completed; have your data erased in certain circumstances; restrict processing; data portability; object to processing based on our legitimate interests; object at any time and absolutely to direct marketing; withdraw consent where processing is based on consent; and not be subject to a decision based solely on automated processing producing legal or similarly significant effects.
We respond to requests within one month. Where a request is complex, or where you have made a number of requests, we may extend that period by up to two further months and will tell you within the first month, in accordance with Article 12(3) of the GDPR. For requests under the UK GDPR only, we may ask you to clarify the scope of a request, in which case the one-month period pauses until you respond, and our searches will be reasonable and proportionate, in accordance with the Data Protection Act 2018 as amended by the DUAA; those provisions have no equivalent under the EU GDPR and we do not apply them to requests from individuals in the EEA.
17. Complaints and Escalation
Complain to us first. If you are unhappy with how we have handled your personal data, you may complain to us at contact@stratrich.com, marked for the attention of our data protection contact. We will acknowledge your complaint within 30 days of receipt, keep you informed of progress, and tell you the outcome. This procedure meets the complaints requirement introduced into the UK GDPR by the DUAA, which took effect on 19 June 2026, and we apply the same procedure to all individuals.
Escalation. If you are not satisfied with our response: individuals in the UAE may complain to the UAE Data Office; individuals in the United Kingdom may complain to the Information Commissioner's Office (ico.org.uk), although the ICO expects you to raise the matter with us first; and individuals in the EEA may complain to the supervisory authority of the Member State of their habitual residence, place of work, or the place of the alleged infringement, under Article 77 of the EU GDPR. Complaining to a regulator does not affect any other legal remedy available to you.
18. Contact Us
Stratrich Consulting contact@stratrich.com | (+971) 55251 3649 | IFZA Business Park, Building A1, DDP, PO Box 342001, Dubai, UAE