Privacy

Privacy Notice

This Privacy Notice (the “Notice”) is issued by (i) Callidus Consulting (DIFC) Limited (“Callidus DIFC” a company registered in the Dubai International Finance Centre (“DIFC”) providing compliance, regulatory, and financial crime advisory services; and (ii) Callidus Consulting (“Callidus Consulting”), a company incorporated and registered in Dubai, UAE providing operational and business support services, including corporate administration, PRO services, human resources, finance, client (“KYC”) screening, and related administrative functions. Together, Callidus DIFC and Callidus Consulting are the “Callidus UAE Companies”, “we”, “us” or “our”.

We are committed to protecting the privacy and confidentiality of personal data and to processing such data in a lawful, fair, and transparent manner in accordance with applicable data protection laws and regulatory requirements.

This Notice describes our policies and procedures on the collection, use and disclosure of your information when you use the services provided by the Callidus UAE Companies and tells you about your rights and how the law protects you.

We use your personal data to provide and improve the services delivered by the Callidus UAE Companies. By using the services, you agree to the collection and use of information in accordance with this Notice.

1. Applicable Law
This Notice has been prepared in accordance with:

  • DIFC Data Protection Law No. 5 of 2020 (as amended or replaced) (the “DP Law”) and the DIFC Data Protection Regulations 2020;
  • UAE Federal Decree Law No. 45 of 2021 on the Protection of Personal Data (the “PDPL”); and
  • Where required, internationally recognised data protection standards and contractual safeguards.

2. Our Role as Data Processor
In most circumstances, Callidus UAE Companies act as a Data Processor, processing personal data strictly on the documented instructions of its clients, who act as Data Controllers. Our processing activities are governed by the service level agreements and data protection clauses agreed with each client.
We do not use personal data for our own purposes except where required by law, regulation, or expressly permitted under a service level agreement.
This Notice does not apply to personal data relating to Callidus UAE Companies’ employees, consultants, interns or job applicants where Callidus UAE Companies act as the Data Controller. Such processing is governed by Privacy Notice set out in the Employee Handbook.

3. Categories of Personal Data We Process
In connection with the delivery of our services, we may process the following categories of personal data:

3.1. Identification and Contact Data
• Name, address (including proof of address), telephone number, email address, and other contact details.

3.2. Professional and Personal Profile Data
• Job title, employer, profession, employment history, nationality, passport and/or identification numbers, date and place of birth, marital status, geographical location, and other personal characteristics required for identification and regulatory purposes.

3.3. Financial Information
• Bank account details, income, source of wealth, ownership structures, and related financial data.

3.4. KYC, AML, CTF and Sanctions Data
• Information required to conduct “know your client” and customer due diligence procedures in accordance with legal and regulatory requirements.
• Information relating to ultimate beneficial owners, directors, officers, representatives, and other related third parties.
• Screening results obtained from sanctions, politically exposed persons, adverse media, anti-money laundering and counter-terrorist financing databases.

3.5. Special Category / Sensitive Data
• We do not ordinarily process special categories of personal data unless required by applicable law, regulation, or to meet a client’s regulatory obligations.

3.6. Technical and Usage Data
• IP addresses, browser type, operating system, timestamps, and other identifiers collected through use of our website or digital platforms.

4. Purposes and Legal Bases for Processing
We process personal data solely for legitimate business and regulatory purposes, including:

4.1. Performance of Contract
• To perform our contractual obligations to our clients, including compliance advisory, AML, KYC, CDD, sanctions screening, regulatory reporting, company secretarial, finance officer and related services.

4.2. Legal and Regulatory Compliance
• To comply with obligations under financial crime legislation, regulatory requirements, court orders, regulatory inquiries, and government authority requests.

4.3. Provision of Services to Us
• Where you provide services to Callidus UAE Companies, we process personal data as necessary to manage those contractual arrangements.

4.4. Communications, Training and Events
• With your consent where required, to communicate regarding training, events, and professional updates relevant to our services.

4.5. Website and Enquiries
• To respond to enquiries submitted through our website and for legitimate business interests such as system security and service improvement.

4.6. Recruitment
• To assess job applicants and manage recruitment processes.
Where applicable, processing is based on one or more of the following lawful grounds: consent, contractual necessity, compliance with legal obligation, protection of vital interests, and our legitimate business interests (such as delivering or improving our services), or those of a third party. Where we rely on legitimate interests, we ensure that these do not override your rights and interests.

5. Use of Affiliates and Sub-Processors
To deliver certain services, particularly KYC, CDD, and screening activities, Callidus UAE Companies may engage a sub-processor.

Currently this is:
Callidus Compliance Solutions Private Limited, No. 2/573 Singaravelan Pradhana Salai, Chinna Neelankarai, Chennai, Tamil Nadu 600041, India.

This entity acts solely as a sub-processor on our behalf and is contractually bound to:

  • Process personal data only on documented instructions;
  • Maintain strict confidentiality obligations;
  • Implement appropriate technical and organisational security measures;
  • Maintain accurate processing records; and
  • Comply with applicable data protection laws and our contractual requirements.

6. International Data Transfers
The delivery of our services may require the transfer of personal data to other jurisdictions, such India. These jurisdictions may not offer a level of data protection equivalent to the DIFC/UAE.

Where such transfers occur:

  • We rely on DIFC-approved Standard Contractual Clauses (“SCCs”) in accordance with Article 27 of the DP Law;
  • We ensure that appropriate technical, organisational, and contractual safeguards are implemented in line with Articles 24 and 25 of the DP Law; and
  • We require sub-processors to process data only for the specified purposes and to maintain adequate security controls.

Where Personal Data is processed in India by Callidus Compliance Solutions Private Limited, such processing shall also be conducted in compliance with applicable Indian data protection legislation, including the Digital Personal Data Protection Act, 2023, as amended from time to time. We acknowledge that compliance with Indian data protection law is supplementary and does not derogate from the safeguards required under DIFC law or the protections afforded by the SCCs.
International data transfers to India are limited to what is necessary for the provision of services.

7. Confidentiality and Security
We implement appropriate technical, organisational, and physical measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include access controls, secure systems, staff training, and contractual confidentiality obligations.
All persons authorised to process personal data are subject to statutory or contractual confidentiality requirements and receive appropriate data protection training.

8. Personal Data Breaches
We maintain procedures to detect, report, and investigate personal data breaches. Where required by law:
• we will notify the relevant Data Controller without undue delay upon becoming aware of a breach affecting personal data; and
• we will provide reasonable assistance in connection with notifications to regulators and affected individuals, including the DIFC Commissioner of Data Protection, the UAE Data Office or other competent authorities.

9. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected and/or to comply with legal, regulatory, or contractual obligations. When personal data is no longer required, it is securely deleted or anonymised.

10. Your Rights as a Data Subject
Subject to applicable law, you have the following rights:

  • Right of access: You have the right to know if we are using your information and, if so, the right to access it and information about how we are using it. There will not usually be a charge for dealing with these requests. Your personal data will usually be provided to you in writing, unless otherwise requested. Where you have made the request by electronic means the information will be provided to you by electronic means where possible.
  • Right to rectification: We take reasonable steps to ensure that the personal data we hold about you is accurate and complete. However, if you do not believe this is the case you have the right to require us to rectify any errors in the information we hold about you.
  • Right to erasure (“right to be forgotten”): You have the right to require us to delete your information if our continued use is not justified. However, this will need to be balanced against other factors, depending upon the type of personal data we hold about you and why we have collected it, there may be some legal and regulatory obligations which mean we cannot comply with your request.
  • Right to restrict processing: In some circumstances, although you may not be entitled to require us to erase your information, you may be entitled to limit the purposes for which we can use your information.
  • Right to data portability: You have the right to require us to provide you with a copy of the personal data that you have supplied to us in a commonly used machine-readable format or to transfer your information directly to another controller (e.g., a third-party offering services competing with ours). Once transferred, the other party will be responsible for looking after your personal data.
  • Right to withdraw consent (where processing is based on consent): For certain limited uses of your personal data, we may ask for your consent. Where we do this, you have the right to withdraw your consent to further use of your personal data. If you withdraw your consent, we may not be able to provide certain products and services to you. If this is the case, we will tell you at the time you ask to withdraw your consent.

You can make any of the requests set out above using the contact details in this Notice. Please note that in some cases we may not be able to comply with your request for reasons such as our own obligations to comply with other legal or regulatory requirements. We will, however, always respond to any request you make and if we cannot comply with your request, we will inform you why.
To exercise any of these rights, please contact us using the details in Section 14.

11. Complaints
If you believe that your personal data has been processed in contravention of applicable law, you may lodge a complaint with the relevant supervisory authority:

DIFC Commissioner of Data Protection
Dubai International Financial Centre Authority
Level 14, The Gate Building, DIFC, Dubai, UAE
Tel: +971 4 362 2222
Email: commissioner@dp.difc.ae

UAE Data Office

The federal data regulator for the purposes of the PDPL.

12. Cookies and Website Data

12.1. What are cookies?
Cookies are small text files that are placed on your device when you visit a website. They enable the website to recognise your device and store certain information about your preferences or actions.

12.2. Types of cookies we use
Callidus uses only essential (strictly necessary) cookies – we do not use advertising, marketing, or non-essential analytics cookies.
Essential cookies are first-party cookies that are strictly necessary for the operation of a website or service and cannot be switched off in our systems. They are typically set in response to actions made by you, such as logging in, submitting forms, or navigating between pages:

Name Purpose Type
session_id Session management and tracking Essential
csrftoken Protection against CSRF attacks Essential
AWSALB Load balancing and traffic routing Essential
cookieConsent Stores user cookie preferences Essential

These cookies are used solely to ensure our website’s proper functioning, to maintain security, and to support essential operational features.

12.3. Data collected via cookies
Through the use of essential cookies, we may process limited technical data such as:
• IP address;
• Browser type and version;
• Device and operating system;
• Date and time of access; and
• Basic usage and session information.
This information is used only for legitimate business purposes, including ensuring website security, preventing fraud, and maintaining service performance.

13. Updates to This Notice
We may update this Notice from time to time to reflect changes in law, regulation, or our processing practices. The latest version will always be available on our website.

14. Contact Information
If you have any questions regarding this Notice or our handling of personal data, please contact:
Email: solutions@callidusmena.com / Telephone: +971 4 261 5559

 

Last updated: April 17, 2026