Skip to content
Corpshore Emirates

This document is drafted to a professional standard for review. It is not legal advice, and it is pending review by Corpshore Emirates UAE counsel before it takes effect. The English version is authoritative; any Arabic version is provided as a translation.

Legal

Privacy policy

Last updated 28 July 2026

This privacy policy explains how Corpshore Emirates, a Corpshore Solutions Corporation company, collects, uses, shares, transfers and protects personal data. It applies to the website at corpshore.ae, to our recruitment and talent services, and to the outsourcing and delivery services we provide to clients from Dubai and Abu Dhabi. Read it with our cookie policy and our candidate privacy notice, which give more detail on specific topics.

We treat personal data in line with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, known as the UAE PDPL, and its executive regulations. Where a client relationship or a specific processing activity sits inside a financial free zone, we also apply the DIFC Data Protection Law No. 5 of 2020 or the ADGM Data Protection Regulations 2021 as relevant. Where we handle the personal data of people in the European Union or the European Economic Area, we apply the EU General Data Protection Regulation. Where two frameworks apply to the same data, we apply the standard that gives the person the stronger protection.

Who is responsible for your data

Corpshore Emirates is the controller for the personal data described in this policy when we decide why and how that data is processed. This is the case for our website, our marketing, and our own hiring. When we process personal data on behalf of a client, under that client's instructions and as part of an outsourcing engagement, the client is the controller and we act as the processor. Section on the controller and processor split below explains this in more detail.

You can reach the team responsible for data protection at legal@corpshore.ae. Our Data Protection Officer is legal@corpshore.ae, and the same address reaches the DPO. The formal registered entity name, the trade licence and the registered address of Corpshore Emirates are Corpshore Emirates. Our parent company, Corpshore Solutions Corporation, is at The Exchange Tower, 130 King Street West, Suite 1900, Toronto, Ontario M5X 2A2, Canada.

Scope of this policy

This policy covers three groups of people whose data we handle for our own purposes. First, people who work for or represent our clients and prospective clients. Second, people who apply to roles or join our talent community as candidates. Third, people who visit the website. We describe the data, the purposes and the legal basis for each group separately, because the answers differ. This policy does not describe the data we process purely on a client's behalf as a processor, which is governed by our agreement with that client and by the client's own privacy notice.

Personal data we collect from clients

When you enquire about our services, enter into an engagement, or work with us as a client contact, we collect the personal data you or your organisation give us and the data we generate in the course of the relationship. This includes:

  • Identity and role data, such as your name, job title, employer and your relationship to the engagement.
  • Contact data, such as your business email address, business phone number and office location.
  • Correspondence, such as the enquiries, briefs, messages and call notes exchanged while we scope and deliver work.
  • Commercial data, such as the services requested, proposals, statements of work, billing contacts and payment records held for the engagement.
  • Usage data from any client portal or shared tool we operate for the engagement, limited to what is needed to run the service and keep it secure.

We collect client data directly from you, from colleagues you introduce us to, and from public professional sources such as a company website or a professional network profile where that is proportionate to a business enquiry.

Personal data we collect from candidates

When you apply to a role, submit your details, or join our talent community, we collect the data needed to assess your suitability and to present you to relevant opportunities. This includes:

  • Identity and contact data, such as your name, email address, phone number and the city or country you are based in.
  • Your CV or resume and the work history, education, skills and certifications it contains.
  • Application data, such as the role you applied to, a cover note, answers to screening questions and your availability.
  • Right-to-work and visa status as a category, meaning whether you are eligible to work in a given location and your visa or sponsorship situation at a general level, without collecting more document detail than a stage requires.
  • Languages you speak and your working proficiency in each.
  • Compensation expectations, only where you choose to provide them.
  • A LinkedIn or professional profile link where you share it, and references where you provide them.
  • Interview notes, assessment results and the record of our contact with you.

We collect most candidate data directly from you. We may also receive your details from a professional network where you have made your profile visible to recruiters, or from a referral where someone recommends you and you then engage with us. We ask you not to send us special categories of data, such as health, religion or political views, and we do not need them to consider you for a role. Our candidate privacy notice sets out the full detail of how candidate data is handled.

Personal data we collect from website visitors

When you visit corpshore.ae, we collect a limited set of data to run the site, keep it secure and understand how it is used. This includes:

  • Enquiry data you submit through a form, such as your name, email address, message and any detail you choose to include.
  • Technical data, such as your IP address, browser type, device type, the pages you view and the approximate region derived from your IP address for security and analytics.
  • Cookie and similar identifiers, where non-essential cookies load only after you consent, as described in our cookie policy.
  • Bot-protection signals from Cloudflare Turnstile, used to tell a genuine visitor from an automated one when you submit a form.

Why we use your data and our legal basis

The PDPL allows us to process personal data only where we have a lawful basis. We rely on the bases below, and we match each purpose to one basis. The GDPR bases we rely on for EU and EEA data subjects are the equivalents named in each row.

  • To answer an enquiry and provide the information you ask for. Legal basis: your consent when you contact us, and our legitimate interest in responding to business enquiries.
  • To scope, agree and deliver a client engagement. Legal basis: performance of a contract with you or with your organisation, and our legitimate interest in managing the relationship.
  • To assess a candidate against a role and present suitable candidates to opportunities. Legal basis: steps taken at your request before any contract, your consent to join a talent community, and our legitimate interest in operating a recruitment service.
  • To send you service updates, insights or marketing you have asked to receive. Legal basis: your consent, which you can withdraw at any time.
  • To keep the website and our systems secure, prevent fraud and abuse, and maintain records. Legal basis: our legitimate interest in security, and compliance with a legal obligation where one applies.
  • To measure and improve how the website performs. Legal basis: your consent to analytics cookies.
  • To meet legal, tax, accounting and regulatory obligations. Legal basis: compliance with a legal obligation.

Where we rely on legitimate interest, we balance that interest against your rights and we do not use it where your interests override ours. You can ask us for the detail of any balancing test we have carried out.

Consent and how to withdraw it

Where we rely on your consent, we ask for it clearly and we keep a record of what you agreed to and when. Consent is always optional, it is never bundled into an unrelated request, and refusing it does not affect a service that does not depend on it. You can withdraw consent at any time, and withdrawal is as easy as giving it. To withdraw marketing consent, use the unsubscribe link in any message or write to us at legal@corpshore.ae. To withdraw analytics or marketing cookie consent, change your choice in the cookie banner or clear the consent stored in your browser. Withdrawing consent does not make past processing unlawful, and it does not affect processing we carry out on another lawful basis.

Who we share data with

We do not sell personal data. We share it only with the categories of recipient below, and only as far as each purpose needs.

  • Our group. Corpshore Emirates and other Corpshore Solutions entities that support delivery, on a need-to-know basis and under internal controls.
  • Zoho, our customer and recruitment platform provider. We use Zoho CRM to manage client and enquiry relationships, Zoho Recruit to manage candidate records and hiring, and Zoho Campaigns to send email you have opted into. Zoho acts as a processor under our instructions.
  • Vercel, our website hosting and content delivery provider, which processes technical and log data needed to serve the site.
  • Cloudflare, which provides the Turnstile bot-protection check on our forms.
  • Calendly, where you book a meeting through the scheduling tool, which processes the booking details you enter.
  • Analytics providers, being Google Analytics and Microsoft Clarity, which run only after you consent to analytics cookies.
  • Clients, where you are a candidate we present for a specific role, in which case we share the parts of your profile relevant to that role and with a view to your application.
  • Professional advisers, auditors, and authorities, where we are required to disclose data by law or to establish, exercise or defend a legal claim.

Every processor we use is bound by a written agreement that requires it to process data only on our instructions, to keep it secure, and to help us meet our obligations to you.

International transfers

We are based in the United Arab Emirates and we work with international clients, an international workforce and service providers located outside the UAE. This means your data may be transferred to and stored in countries other than the one you are in, including where our processors host their infrastructure. Under the PDPL, we transfer personal data outside the UAE only where the destination provides an adequate level of protection, or where an appropriate safeguard is in place, such as standard contractual clauses, binding corporate rules, or your explicit consent for a specific transfer.

For transfers of data protected by the GDPR, we rely on an adequacy decision where one exists, or on standard contractual clauses together with any supplementary measures the transfer requires. For data connected to a DIFC or ADGM engagement, we apply the transfer rules of the DIFC Data Protection Law 2020 or the ADGM Data Protection Regulations 2021. You can ask us which mechanism applies to a given transfer, and we will tell you and, where relevant, provide a copy of the safeguard.

How long we keep your data

We keep personal data only as long as we need it for the purpose we collected it for, or as long as the law requires. The periods below are our drafted retention periods and are pending final confirmation by counsel.

  • Website enquiry data. Kept for 24 months from your last contact, then deleted or anonymised, unless it becomes part of a client engagement.
  • Candidate data. Kept for 24 months from your last activity with us, unless you ask us to remove it sooner, or you consent to remain in our talent pool, in which case we keep it until you withdraw that consent or we periodically ask you to renew it.
  • Client contract data. Kept for the life of the engagement plus a tail of 7 years after it ends, to meet legal, tax and accounting obligations and to defend any claim, after which it is deleted or anonymised.
  • Marketing consent and preference records. Kept until you unsubscribe, plus a short suppression record so we honour your opt-out.
  • Technical and security logs. Kept for a short operational period, generally not longer than 12 months, unless a security investigation requires longer.

When a retention period ends, we delete the data securely or anonymise it so it can no longer identify you. Where a legal hold applies, we keep only what the hold requires and for only as long as it lasts.

Your rights

The PDPL gives you rights over your personal data, and the GDPR gives equivalent rights where it applies to you. Subject to the conditions in the law, you have the right to:

  • Access. Ask whether we hold data about you, and receive a copy of it together with information on how it is used.
  • Correction. Ask us to correct data that is inaccurate, out of date or incomplete.
  • Erasure. Ask us to delete your data where we no longer have a valid reason to keep it.
  • Restriction. Ask us to limit how we use your data while a question about it is resolved.
  • Portability. Receive the data you gave us in a structured, commonly used and machine-readable format, and ask us to transfer it where that is technically feasible.
  • Objection. Object to processing based on our legitimate interest, and object at any time to direct marketing.
  • Withdraw consent. Withdraw any consent you gave, without affecting processing already carried out.
  • Complain. Lodge a complaint with the UAE Data Office, or with the relevant free zone or overseas authority where one applies to you.

To exercise any right, write to us at legal@corpshore.ae and tell us which right you want to use. We may ask for enough information to confirm your identity, so we do not disclose data to the wrong person. We respond without undue delay and in any event within the period the law sets, which we treat as one month from a valid request, and we tell you if a complex request needs a reasonable extension. We do not charge for a request unless the law allows a fee for one that is clearly excessive or repetitive. If you are not satisfied with our response, you can complain to the UAE Data Office. The forum and any governing-law detail for a formal dispute are the laws of the United Arab Emirates.

Automated decisions and profiling

We do not make decisions that produce a legal or similarly significant effect on you based solely on automated processing, without a human involved. Our platforms may sort, tag or score records to help our team work efficiently. For example, a lead in Zoho CRM may carry a score that reflects how well an enquiry matches our services, and a candidate record in Zoho Recruit may be ranked or filtered against a role's requirements. These scores support a person's judgement, they do not replace it, and a human reviews the cases that matter before any decision is taken. If we ever introduce solely automated decision-making with a significant effect, we will tell you, explain the logic in plain terms, and give you a way to ask for human review, to express your view and to contest the decision.

How we protect your data

We apply technical and organisational measures suited to the risk. Data is encrypted in transit and at rest on the platforms we use. Access is limited to the people who need it, controlled by role, and protected by strong authentication. We keep our providers to recognised security standards, we log and monitor access, and we review our controls as the service changes. No system can be guaranteed perfectly secure, so we also plan for the case where something goes wrong.

If there is a data breach

If a personal data breach occurs and it is likely to create a risk to your rights, we will notify the UAE Data Office as the law requires, and we will tell you without undue delay where the breach is likely to result in a high risk to you. Our notice will describe what happened, the likely consequences, and the steps we are taking to address it and to help you protect yourself. We keep an internal record of breaches and of the action we take.

Children's data

Our website and services are meant for organisations and for working adults. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.

Changes to this policy

We may update this policy as our services, our providers or the law change. When we make a material change, we update the date at the top and, where the change affects you significantly, we take reasonable steps to tell you, for example by a notice on the site or a direct message. Please check the current version before you rely on it.

If you have any question about this policy or about how we handle your data, contact us at legal@corpshore.ae.