Privacy Policy

B&B Consulting LLC, trading as Trading ERP Consulting
Version 1.0  ·  Effective from 27 July 2026
Last updated: 27 July 2026

1. Introduction

B&B Consulting LLC, a company incorporated in the Sharjah Media City (Shams) Free Zone in the United Arab Emirates and carrying on business under the trading name Trading ERP Consulting, operates the website published at https://tradingerpconsulting.com. Respect for the confidentiality of the information entrusted to us sits at the centre of a consulting practice that regularly encounters the financial, commercial, and personnel records of its clients, and the present Policy explains in detail how personal data are collected through the website and through the channels connected to it, the purposes for which those data are used, the persons to whom they may be disclosed, and the rights available to the individuals concerned.

Reading the Policy alongside the Cookie Policy is recommended, since the latter describes in granular form the technologies deployed on the website, the consent architecture that governs them, and the mechanisms through which a visitor may exercise choice. Where the two documents address the same subject, the Cookie Policy governs matters of terminal equipment storage and the present Policy governs the subsequent treatment of the data obtained.

Terms used here carry the meanings given to them by Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and, where the European framework applies, by Regulation (EU) 2016/679.

2. Identity and Contact Details of the Controller

ItemDetails
Legal entityB&B Consulting LLC
Trading nameTrading ERP Consulting
Place of incorporationSharjah Media City (Shams) Free Zone, Emirate of Sharjah, United Arab Emirates
Trade licence number2646844.01
Registered officeSharjah Media City, Sharjah, United Arab Emirates
Websitehttps://tradingerpconsulting.com
General enquiriesinfo@tradingerpconsulting.com

We act as controller in respect of the processing described below, which is to say that we determine the purposes for which personal data are processed and the means by which the processing is carried out. In the course of delivering implementation and support services to a client, our position frequently changes: where we configure, migrate, or maintain an environment containing records relating to the employees, customers, or suppliers of that client, we act as processor on the documented instructions of the client, and the terms of the relevant engagement documentation, rather than the present Policy, govern that relationship. In that capacity, our obligations of confidentiality, of security, of the engagement of any subprocessor, of assistance in the event of a personal data breach, and of the return or the deletion of the data at the conclusion of the work are recorded in the engagement documentation or in a separate data processing agreement concluded with the client, consistently with Article 28 of Regulation (EU) 2016/679 where the European framework applies and with the corresponding requirements of Federal Decree-Law No. 45 of 2021.

3. Scope of Application

Application of the Policy extends to personal data collected through the website, through the enquiry form published on the contact page, through the appointment scheduling tools linked from the website, through electronic mail and messaging channels addressed to us, and through business development activity conducted by our personnel. Personal data received by us in the capacity of processor, personal data held within the environments of our clients, and personal data collected by third parties operating their own websites fall outside its application.

Nothing in the Policy displaces the confidentiality provisions of any engagement letter, non-disclosure agreement, or master services agreement concluded between us and a client. Where such provisions offer greater protection, they prevail.

Our processing is governed principally by Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, the federal statute applicable across the United Arab Emirates to controllers and processors established in the country outside the two financial free zones, and applicable also, by virtue of its extraterritorial reach, to entities abroad that process the personal data of individuals located in the Emirates. Sharjah Media City being a free zone of general commercial character, the federal regime applies to us in full, and the separate regimes established for the Dubai International Financial Centre and for the Abu Dhabi Global Market are not engaged.

Position as at the date of the present Policy: the Implementing Regulations contemplated by Federal Decree-Law No. 45 of 2021 have not yet been issued. Certain operational parameters, among them the prescribed deadlines for responding to requests, the approved mechanisms for transfers abroad, and the thresholds triggering appointment of a data protection officer, will be settled only upon their publication. Our practice in the interim is described below and follows the text of the statute together with recognised international standards. Revision of the Policy will follow publication of the implementing framework.

Where we offer services to, or monitor the behaviour of, individuals located in the European Union, Regulation (EU) 2016/679 applies to the processing concerned by operation of its Article 3(2). Equivalent provisions of the United Kingdom General Data Protection Regulation, read together with the Data Protection Act 2018, apply in respect of individuals located in the United Kingdom. Storage of information on, and access to information already stored on, the terminal equipment of visitors located in those territories is additionally governed by Article 5(3) of Directive 2002/58/EC and, in the United Kingdom, by regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003.

5. Categories of Personal Data We Collect

5.1 Data supplied through the enquiry form

The enquiry form published on our contact page collects the first name, the last name, the business electronic mail address, the telephone number, the name of the organisation, an indication of the system currently in use, a selection identifying the principal requirement, and a free-text message.

Particular attention attaches to the free-text field. Enquirers describing a migration involving accounting records, human resources data, or payroll frequently include information about identified individuals, and occasionally information falling within the category of sensitive personal data. We do not solicit information of that character at the enquiry stage, and we ask that it be withheld until a confidentiality agreement is in place. Where such information reaches us notwithstanding, access is restricted to personnel handling the enquiry and the material is deleted or reduced to a summary at the earliest opportunity consistent with the purpose for which it was sent.

5.2 Data supplied through appointment scheduling

Two scheduling tools are presently linked from the website, one operated by Calendly LLC and one forming part of the Google Workspace appointment scheduling facility. Booking a consultation through either tool involves the collection of the name, the electronic mail address, the selected time slot, the applicable time zone, and any information volunteered in the notes field, together with the technical data generated by the tool itself. Confirmation and reminder messages are dispatched by the tool on our behalf.

5.3 Data arising from correspondence

Electronic mail addressed to us and telephone conversations generate personal data comprising the identity of the correspondent, the contact details used, the content of the exchange, and the associated metadata such as the date, the time, and the duration.

5.4 Technical and usage data

Visiting the website causes technical data to be generated automatically, including the internet protocol address, the type and version of the browser, the operating system, the screen characteristics, the language preference, the referring address, the pages requested, the sequence in which they were requested, and the duration of the visit. Collection through analytics technologies is conditional upon consent, as described in the Cookie Policy. A limited quantity of technical data is recorded in server logs for security and diagnostic purposes irrespective of consent, on the basis of our legitimate interest in maintaining the integrity of the service.

5.5 Client and engagement data

Where an enquiry matures into an engagement, we collect and hold the identity and contact details of the individuals nominated by the client as project sponsors, key users, and administrative contacts, together with the correspondence, meeting records, requirement documents, and support tickets generated during the project, and the billing and payment information necessary to administer the relationship.

5.6 Supplier, partner, and applicant data

Personal data relating to the representatives of our suppliers, subcontractors, and referral partners are held for the administration of those relationships. Applications for employment or subcontracting generate curricula vitae, correspondence, and interview records, retained in accordance with the periods stated at section 11.

6. Sources of Personal Data

Most of the personal data we hold are supplied to us directly by the individual concerned. Data reach us from other sources in three further ways: from the organisation that employs or engages the individual, where a client nominates a person to act as a project contact; from publicly accessible professional sources, business networking platforms such as LinkedIn, business directories, and corporate websites, in the course of business development activity; and from referral partners and other intermediaries who introduce prospective clients to us. Where personal data are obtained otherwise than from the individual, we provide the information required by Article 14 of Regulation (EU) 2016/679 within a reasonable period and in any event before the data are first used to communicate with that individual.

Every processing operation we undertake is anchored to a stated purpose and to a lawful basis. Bases available under Federal Decree-Law No. 45 of 2021 differ in their architecture from those available under Regulation (EU) 2016/679, notably in that the federal statute treats consent as the ordinary basis and admits the alternatives as defined exceptions, while the European instrument places six bases on an equal footing. The table below identifies, for each purpose, the basis relied upon under each regime.

PurposePersonal data involvedBasis under UAE lawBasis under GDPR and UK GDPR
Responding to an enquiry and preparing a proposalIdentity, contact, organisation, and requirement dataNecessary for the performance of a contract or for steps taken at the request of the data subject prior to entering into oneArticle 6(1)(b), steps at the request of the data subject prior to contract
Administering a scheduled consultationIdentity, contact, and scheduling dataAs aboveArticle 6(1)(b)
Delivering consulting, implementation, migration, training, and support servicesEngagement and correspondence dataNecessary for the performance of a contractArticle 6(1)(b)
Invoicing, collection, and financial record keepingIdentity, contact, and billing dataNecessary for compliance with a legal obligationArticle 6(1)(c), read with the retention obligations of UAE tax and commercial legislation
Maintaining the security, integrity, and availability of the websiteTechnical and log dataNecessary to protect the legitimate interests of the controllerArticle 6(1)(f), legitimate interest in network and information security
Measuring website audience and performanceAnalytics identifiers and usage dataConsentArticle 6(1)(a), consent, obtained through the cookie interface
Business development and marketing communications about our servicesIdentity and contact dataConsent, or our legitimate interest in developing business relationshipsArticle 6(1)(f), legitimate interest in business-to-business development through enquiries, professional networking, corporate directories, and referrals; Article 6(1)(a) where the electronic marketing rules require consent, subject to an opt-out in every message and to the exception at regulation 22(3) of the Privacy and Electronic Communications (EC Directive) Regulations 2003 for existing clients contacted about similar services
Establishing, exercising, or defending legal claimsAny relevant categoryNecessary for the establishment or defence of a right before the competent authoritiesArticle 6(1)(f), legitimate interest in the protection of legal position
Assessing an application for employment or subcontractingApplication and interview dataSteps prior to entering into a contract, with consent for retention beyond the processArticle 6(1)(b), and Article 6(1)(a) for retention in a talent pool

Where we rely upon legitimate interest, an assessment balancing that interest against the interests, rights, and freedoms of the individual has been conducted and is documented. A summary of any such assessment is available on request addressed to info@tradingerpconsulting.com.

Consent, where relied upon, is sought by means of an affirmative act performed by the individual, and never through pre-ticked boxes, silence, or continued browsing. Requests for consent are presented separately from other matters, in intelligible language, and identify the purpose to which they relate.

Withdrawal is available at any time and is as straightforward as the original act. Consent to analytics and other non-essential technologies may be withdrawn through the cookie preference control accessible from every page of the website. Commercial communications, whether sent in reliance upon consent or upon our legitimate interest in business development, may be stopped at any time through the unsubscribe facility contained in each message or by writing to info@tradingerpconsulting.com. Withdrawal operates prospectively and does not affect the lawfulness of processing carried out before it took effect.

Refusal of consent, or its subsequent withdrawal, carries no adverse consequence for the individual and does not affect the availability or the quality of the services we provide. Submission of an enquiry has never been conditional upon acceptance of marketing communications, and the two matters are presented separately on the form.

9. Recipients and Categories of Recipient

Personal data are disclosed only where a defined purpose requires it, and only to the categories identified below. We do not sell personal data, and we do not disclose personal data to third parties for their own independent marketing purposes.

Our business evolves, and the suppliers supporting it change from time to time. In order that the present Policy should remain accurate without requiring amendment upon every such change, a register of the third-party services in use, identifying each provider, the purpose it serves, the categories of data involved, and the location of processing, is maintained separately and made available on request addressed to info@tradingerpconsulting.com. Each version of the register carries a date, and superseded versions are retained. Where a new category of recipient is introduced, or where a change materially alters the character of the processing, the Policy itself is amended and the individuals concerned are notified in accordance with section 19.

10. International Transfers

Our operations are conducted from the United Arab Emirates, while several of the services we rely upon are supplied by providers established in the United States and in the European Union, with processing infrastructure distributed across multiple territories. Transfers of personal data outside the United Arab Emirates therefore occur in the ordinary course.

Federal Decree-Law No. 45 of 2021 permits transfer to a jurisdiction affording an adequate level of protection, and, in the absence of adequacy, permits transfer where appropriate contractual safeguards are in place, where the transfer is necessary for the performance of a contract with the data subject or in the interest of the data subject, or where the data subject has given consent to the transfer having been informed of its implications. The mechanism for the formal determination of adequacy awaits the Implementing Regulations, and our present practice is accordingly to secure contractual safeguards in every case in which the destination has not been recognised as adequate, and to keep the position under review.

Where personal data are transferred out of the European Economic Area or out of the United Kingdom, we rely upon the standard contractual clauses adopted by the European Commission and, for United Kingdom transfers, upon the International Data Transfer Addendum issued by the Information Commissioner, supplemented where the circumstances warrant by additional technical and organisational measures identified through a transfer risk assessment. Copies of the safeguards applied to a particular transfer may be requested at info@tradingerpconsulting.com, subject to the redaction of commercially confidential terms.

11. Retention

Personal data are kept for no longer than is necessary for the purposes for which they were collected, after which they are deleted or irreversibly anonymised. Periods applied in the ordinary course appear below and are subject to extension where a legal obligation, an actual or anticipated dispute, or a regulatory investigation requires it.

CategoryRetention periodRationale
Enquiries that do not result in an engagement24 months from the last substantive contactContinuity of commercial dialogue and defence against claims arising from the enquiry
Records of scheduled consultations24 months from the date of the appointmentConsistency with the treatment of enquiries
Client engagement records6 years from the conclusion of the engagementPeriod exceeding by a deliberate margin the five-year limitation applicable to obligations arising between merchants under Federal Decree-Law No. 50 of 2022, so that a claim asserted late within that period remains capable of being answered, together with continuity of support
Accounting and tax recordsSeven years from the end of the relevant tax periodRecord-keeping obligations under the UAE Corporate Tax and tax procedures legislation, together with any value added tax obligation should the company become registered for that tax
Marketing contact recordsUntil consent is withdrawn, and thereafter a suppression record indefinitelySuppression records exist for the purpose of honouring the withdrawal itself
Website server logs12 monthsSecurity monitoring and incident investigation
Analytics dataGoverned by the retention setting configured within Google Analytics 4, presently 14 monthsAudience measurement over a comparable annual cycle
Unsuccessful applications12 months from the conclusion of the process, or longer with consentConsideration for subsequent opportunities
Records of consent and of rights requests6 years from the eventDemonstration of compliance

12. Security

Technical and organisational measures proportionate to the size of our operations and to the risk presented by the data we hold are applied, and we keep them under review as the business develops. Being a small consultancy, we rely to a considerable degree on the security of established, reputable platforms for the hosting of the website and the storage of our records, and we configure the controls that those platforms make available. Measures in use include encryption of data in transit through transport layer security across the website and our correspondence channels, encryption at rest within the platforms on which our records reside, access confined to the members of our team who require it, multi-factor authentication on the principal accounts, the use of strong and distinct credentials, and confidentiality undertakings binding those who act for us. Files of importance are backed up, and we take reasonable care to keep the material relating to individual client engagements apart from our general administrative records. Before a new supplier is adopted, we have regard to the security and the reputation of the service concerned.

No system connected to a public network can be rendered wholly immune from compromise, and no assurance to that effect is offered. Should a breach of personal data occur that is likely to result in risk to the individuals concerned, we will notify the competent federal authority without undue delay and, where the risk is high, will communicate the breach to those individuals directly, together with a description of the likely consequences and of the measures taken to address it. We keep an internal record of any such breach and of the steps taken in response to it.

13. Rights of Individuals

Rights available depend upon the regime applicable to the processing in question. Rather than presenting a single composite list, the table below distinguishes the two frameworks, since the scope and the conditions attaching to each right differ.

RightUnder Federal Decree-Law No. 45 of 2021Under GDPR and UK GDPR
Information and accessAvailable, including the right to obtain information about the processing and to request a copy of the personal data heldArticle 15
RectificationAvailable in respect of inaccurate or incomplete dataArticle 16
ErasureAvailable, subject to exceptions including retention required by law and the defence of legal claimsArticle 17
Restriction of processingAvailable in defined circumstancesArticle 18
PortabilityAvailable in respect of data processed by automated means on the basis of consent or contractArticle 20
ObjectionAvailable in respect of processing for direct marketing and, on grounds relating to the particular situation, in respect of certain other processingArticle 21
Automated decision-makingAvailable in respect of decisions producing legal effects or comparably significant effectsArticle 22
Withdrawal of consentAvailable at any timeArticle 7(3)
Complaint to a supervisory authorityAvailable to the competent federal authorityArticle 77

Requests should be addressed to info@tradingerpconsulting.com and should identify the right invoked and the personal data concerned with sufficient particularity to permit a search. Verification of identity may be required before a request is actioned, and we will seek only such information as is necessary for that purpose.

Our practice is to respond within one month of receipt, in line with Article 12(3) of Regulation (EU) 2016/679, extendable by two further months where the request is complex or where several requests have been received, in which case the individual is informed of the extension and of its reasons within the first month. The federal deadline applicable to requests under Federal Decree-Law No. 45 of 2021 awaits the Implementing Regulations, and the one-month standard is applied in the interim to every request irrespective of its origin. No fee is charged, save where a request is manifestly unfounded or excessive, in which case a reasonable administrative fee may be levied or the request declined, with reasons given in writing.

14. Complaints and Supervisory Authorities

Should a response fail to satisfy the individual concerned, a complaint may be pursued as follows.

We would ask, without prejudice to any of those routes, that concerns be raised with us in the first instance, since most are capable of resolution directly and promptly.

15. Automated Decision-Making and Profiling

Decisions producing legal effects concerning an individual, or affecting an individual in a comparably significant manner, are not taken by automated means. Ordering of enquiries within our internal workflow may be assisted by automated sorting, but every commercial decision, including the decision whether to submit a proposal and on what terms, is taken by a human being who is able to consider the circumstances of the particular case.

16. Children

Our services are directed exclusively to businesses and to the professionals who represent them, and the website is not designed for, nor addressed to, persons below the age of eighteen years. Personal data relating to children are not knowingly collected. Should we become aware that such data have reached us, they will be deleted promptly, and a parent or guardian who believes that a child has provided personal data to us is invited to write to info@tradingerpconsulting.com.

17. Third-Party Services and Odoo S.A.

Links published on the website lead to resources operated by others, among them the scheduling tools and material published by Odoo S.A. Following such a link takes the visitor outside our control, and the privacy practices of the destination are governed by its own documentation, which we would encourage visitors to read.

A distinction of some importance should be recorded in relation to Odoo. Our business consists of consulting, implementation, migration, integration, training, and support services. Software licences, cloud hosting, subscription services, and the associated platform facilities are supplied by Odoo S.A. under its own contractual and privacy documentation. Where a client contracts directly with Odoo S.A., that company acts as controller or processor in respect of the data held within the subscribed environment according to the arrangements it has concluded with the client, and the present Policy does not extend to that processing.

18. Representatives in the European Union and the United Kingdom

Article 27 of Regulation (EU) 2016/679, and the corresponding provision of the United Kingdom General Data Protection Regulation, require a controller established outside the respective territory and falling within the extraterritorial scope of the instrument to designate a representative, subject to a derogation for processing that is occasional, does not involve large-scale processing of special category data, and is unlikely to result in risk to the rights and freedoms of individuals.

Our engagement with individuals in the European Union and the United Kingdom is presently occasional in character and confined to business contact details and enquiry correspondence, and no representative has been designated. Should the volume or the character of that engagement change, a representative will be appointed and the present section amended, with the contact details published here.

19. Amendments to the Policy

Revision may become necessary as our services develop, as the technologies deployed on the website change, or as the applicable law evolves. Publication of the Implementing Regulations to Federal Decree-Law No. 45 of 2021 is expected to require a review of the retention periods, the transfer mechanisms, and the response deadlines described above.

Every version carries a version number and a date, and the current version is that shown at the head of the document. Where an amendment materially affects the rights of individuals or introduces a purpose incompatible with those previously disclosed, notice will be given by a prominent statement on the website and, where we hold an address for the individual, by direct communication, in advance of the amendment taking effect. Superseded versions are archived and may be obtained on request.

20. Contact

Questions concerning the present Policy, requests for the register of third-party services, requests relating to the exercise of rights, and complaints should be addressed to info@tradingerpconsulting.com, or to B&B Consulting LLC at the registered office identified at section 2.