Privacy Policy

1. Controller and contact

GRock, trade licence No. 106907, registered at Premises 310, EIB 01 Building, Dubai Internet City, Dubai, United Arab Emirates. GRock operates grock.ae and is the controller of the personal data described in this Policy. References in this Policy to "GRock", "we", "us" and "our" are references to GRock.

Privacy enquiries and requests under clause 10 should be sent to info@grock.ae.

If we appoint a Data Protection Officer, that person’s contact details will be published here. The absence of a separately named officer does not affect your ability to contact us or to exercise your rights.

2. Scope

This Policy applies to personal data we process through the Website, our contact forms, and correspondence by email, telephone and messaging services, including during our internal checks before we accept an engagement.

Where we perform services under a signed services agreement, that agreement and any notice given under it govern the processing carried out for those services. This Policy continues to apply to everything not covered by such an agreement, and nothing in an agreement reduces a right you have under applicable law.

This Policy does not apply to third-party websites we link to.

3. Personal data we collect

3.1 Information you provide. Your name, telephone number and email address; your company and role, where you give them; the subject of your enquiry and the content of the correspondence that follows; your preferences, feedback, and your recorded consent and marketing choices.

3.2 Information collected automatically. Your IP address, the approximate location derived from it, device and browser information, operating system, referring page, pages viewed, timestamps, interaction records, cookie identifiers and security logs. Non-essential analytics technologies are used only in accordance with the choices you make under Part C.

3.3 Information from other sources. Where relevant and permitted by law, we may receive personal data from companies within our group, from your own representatives, and from publicly available sources such as company registers and websites. If you provide us with personal data about another person, you confirm that you are authorised to do so and that you have informed that person of this Policy where it is appropriate to do so.

3.4 Data we do not collect through the Website. We do not request, and the Website is not configured to receive, identity document numbers, payment card or bank account details, or documents relating to a specific engagement. Please do not submit such information through a Website form.

3.5 Sensitive personal data. We do not seek sensitive personal data as defined in Federal Decree-Law No. 45 of 2021, and we ask that you do not include it in an enquiry. If sensitive personal data reaches us despite this, we restrict access to it, use it only so far as necessary for the purpose for which it was sent, and delete it once that purpose has ended.

4. Purposes and legal grounds

Our processing is subject to Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. We process personal data only for a specified purpose and on a ground permitted by that Decree-Law, which includes your consent; steps taken at your request before entering into a contract; performance of a contract; compliance with a legal obligation; the establishment, exercise or defence of a legal claim; and the protection of our legitimate interests where this does not prejudice your rights.

The purposes are:
• responding to your enquiry, answering your questions and arranging a meeting or call;
• carrying out our internal checks before deciding whether to accept an engagement, including checking for competing interests;
• providing, administering and improving our services, and managing records, invoicing, payments and complaints;
• sending you material you have specifically asked for;
• operating, securing, troubleshooting and measuring the Website and our business systems;
• sending you information about our services, where you have separately consented;
• establishing, exercising or defending legal rights, and protecting people, systems and property; and
• complying with the applicable law of the United Arab Emirates, with the regulations of the Dubai Development Authority, and with lawful orders and requests of competent authorities.

Visiting the Website or sending an enquiry is not by itself treated as consent to anything beyond handling that enquiry. Where we rely on consent, we ask for it clearly and specifically, we keep a record of it, and you may withdraw it at any time without affecting processing already lawfully carried out. Consent to marketing is asked for separately from a request for services.

5. If you choose not to provide information

You are not obliged to give us personal data. If you withhold information we need in order to identify you, to carry out our internal checks, or to perform a service you have asked for, we may be unable to respond fully, to accept an engagement, or to continue with one.

6. Who has access, and to whom we disclose

6.1 Internal access is limited to personnel and contractors who need the data for a purpose in clause 4 and who are subject to confidentiality obligations.

6.2 We may disclose personal data to:

• companies within our group, where they are involved in responding to your enquiry or in providing a service you have asked about;
• providers acting on our instructions, including website hosting, form processing, CRM, email, cloud storage, document management, communications, analytics and cybersecurity providers;
• our banks and payment service providers, auditors, insurers and professional advisers;
• the Dubai Development Authority, tax authorities, and any other competent regulatory or governmental authority of the United Arab Emirates, where we are required to disclose;
• a court, prosecutor, notary, registry or law enforcement authority, in response to a lawful order or request; and
• a purchaser, investor or successor in connection with a genuine corporate transaction, subject to confidentiality.

6.3 We do not sell personal data and we do not disclose it for the marketing purposes of third parties.

6.4 We require providers who process personal data on our behalf to act only on our documented instructions, to apply appropriate security measures, to restrict their use of sub-processors, and to assist us with deletion, with requests under clause 10, and with incidents. Personal data we hold must not be used by a technology provider to train general-purpose models unless we have expressly approved that use and have a lawful basis for it.

7. Transfers outside the United Arab Emirates

Some of the providers we use may store or process personal data outside the United Arab Emirates. Before a transfer we assess the destination, the recipient, the purpose and the safeguards available.

We transfer personal data only where Articles 22 and 23 of Federal Decree-Law No. 45 of 2021 permit it, which includes transfer to a jurisdiction recognised as providing an adequate level of protection, transfer under contractual undertakings securing a comparable level of protection, and transfer with your express consent. Practical safeguards may include contractual restrictions, access controls, encryption, data minimisation and vendor due diligence.

Current principal hosting and processing locations: United Arab Emirates. You may ask us for further information about the safeguards relevant to your data, subject to confidentiality and security limitations.

8. Retention and deletion

We keep personal data only for as long as it is needed for the purpose for which it was collected, and then for any further period required by law. The following periods apply unless a different period is required by law or is justified for a documented reason:

• enquiries that do not lead to an engagement: 24 months after our last substantive contact with you;
• records of enquiries we declined and the reason for declining: 36 months after the decision, in a limited-access form;
• records relating to an engagement: for the duration of the engagement and for 5 years after it ends, or longer where a legal, tax, evidential or dispute-related requirement applies;
• accounting, tax and transaction records: for the periods required under Federal Decree-Law No. 47 of 2022 on the Taxation of Corporations and Businesses, Federal Decree-Law No. 28 of 2022 on Tax Procedures and the regulations issued under them, and under the regulations of the Dubai Development Authority;
• marketing preferences and opt-out records: while marketing continues and for a reasonable period afterwards, so that we can respect your choice;
• security and access logs: ordinarily 12 months, unless a longer period is needed to investigate an incident; and
• cookies and analytics identifiers: as stated in Part C.

At the end of the applicable period, personal data is securely deleted, anonymised, or isolated from routine use. Deletion from encrypted backups takes effect through the normal backup rotation cycle. Where a legal hold applies, routine deletion is suspended only for as long as the hold is necessary.

Where the law requires us to keep a record, we keep it even if you ask us to erase it, and we restrict its use to that legal purpose.

9. Security and incidents

9.1 We apply technical and organisational measures appropriate to the nature of the data and to the risk. These include access control on a need-to-know basis, encryption of data in transit, role-based permissions, logging, secure backups, confidentiality obligations on personnel, assessment of providers, and incident response procedures.

9.2 No method of transmission over the internet and no method of electronic storage is completely secure. We do not warrant that personal data sent to us or held by us will remain free from unauthorised access in all circumstances.

9.3 If a personal data breach occurs that may prejudice the privacy, confidentiality or security of personal data, we will investigate, contain and document it, and we will make any notification to the UAE Data Office, to another competent authority, and to the individuals affected that is required by Federal Decree-Law No. 45 of 2021 and the regulations issued under it, within the period and in the manner prescribed.

9.4 If you believe that data you sent us has been compromised, please tell us at info@grock.ae as soon as you can.

10. Your rights

Subject to the conditions and exceptions in Federal Decree-Law No. 45 of 2021, you may ask us to:

• confirm what personal data we process about you and give you information about the purposes, the recipients, the retention periods and the safeguards applied to any international transfer;
• provide a copy of the personal data you gave us in a structured, commonly used and machine-readable format, or transfer it to another controller where this is technically feasible;
• correct or complete personal data that is inaccurate or incomplete;
• erase personal data, subject to clause 8;
• restrict processing in the circumstances provided by law, including while a request under this clause is being considered;
• stop processing carried out for direct marketing, or processing that is not necessary for the purpose for which the data was collected;
• withdraw a consent you have given; and
• review or object to a decision taken solely by automated processing that produces legal or similarly significant effects for you.

10.1 To exercise a right, write to info@grock.ae and describe your request. We may ask for proportionate proof of identity and, where you act for someone else, of authority.

10.2 We aim to respond within 30 days of receiving a complete request. Where a request is complex, or where you have made several requests, we may extend that period and will tell you if we do.

10.3 We do not ordinarily charge a fee. Applicable law may permit us to refuse a request, or to charge a reasonable fee, where a request is manifestly unfounded or excessive.

10.4 We may decline a request, in whole or in part, where the Decree-Law permits, including where compliance would conflict with a legal obligation, prejudice an investigation, or affect the rights of another person. If we decline, we will explain why.

11. Automated processing

We do not take decisions producing legal or similarly significant effects for you solely by automated processing.

We may use technology to assist with tasks such as document text extraction, translation, search and workflow prioritisation. Substantive decisions remain subject to human review. If this changes, we will update this Policy or give you a specific notice.

12. Marketing

Where we send direct marketing, we keep it separate from communications about an enquiry or an engagement, and we send it only where you have consented or where the applicable law otherwise permits. You may opt out at any time using the unsubscribe method in the message, or by writing to us. Opting out does not stop necessary communications about an enquiry, an engagement, a payment, a security matter or a legal obligation.

13. Children

The Website is directed at businesses and at persons aged 18 and over. We do not knowingly collect personal data from a person under 18 through the Website. If you believe that a child has provided us with personal data, write to us at info@grock.ae and we will delete it.

14. Complaints

If you are not satisfied with how we have handled your personal data, please write to us first at info@grock.ae so that we can investigate.

You may also complain to the UAE Data Office, which supervises compliance with Federal Decree-Law No. 45 of 2021, in accordance with the procedure available at the time. Exercising this right does not affect any other remedy available to you.

15. Changes to this Policy

We may update this Policy to reflect changes in law, in our services, in the technology we use, or in how we process personal data. The current version and its effective date are published on the Website. Where a change materially affects processing of personal data you have already given us, we will take reasonable steps to bring it to your attention and, where the law requires it, to obtain your consent.

16. Language

This Policy is published in English.

17. Contact

GRock, Premises 310, EIB 01 Building, Dubai Internet City, Dubai, United Arab Emirates.

info@grock.ae