B&B Consulting LLC, a company incorporated in the Sharjah Media City (Shams) Free Zone in the United Arab Emirates and carrying on business under the trading name Trading ERP Consulting, operates the website published at https://tradingerpconsulting.com. Respect for the confidentiality of the information entrusted to us sits at the centre of a consulting practice that regularly encounters the financial, commercial, and personnel records of its clients, and the present Policy explains in detail how personal data are collected through the website and through the channels connected to it, the purposes for which those data are used, the persons to whom they may be disclosed, and the rights available to the individuals concerned.
Reading the Policy alongside the Cookie Policy is recommended, since the latter describes in granular form the technologies deployed on the website, the consent architecture that governs them, and the mechanisms through which a visitor may exercise choice. Where the two documents address the same subject, the Cookie Policy governs matters of terminal equipment storage and the present Policy governs the subsequent treatment of the data obtained.
Terms used here carry the meanings given to them by Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and, where the European framework applies, by Regulation (EU) 2016/679.
| Item | Details |
|---|---|
| Legal entity | B&B Consulting LLC |
| Trading name | Trading ERP Consulting |
| Place of incorporation | Sharjah Media City (Shams) Free Zone, Emirate of Sharjah, United Arab Emirates |
| Trade licence number | 2646844.01 |
| Registered office | Sharjah Media City, Sharjah, United Arab Emirates |
| Website | https://tradingerpconsulting.com |
| General enquiries | info@tradingerpconsulting.com |
We act as controller in respect of the processing described below, which is to say that we determine the purposes for which personal data are processed and the means by which the processing is carried out. In the course of delivering implementation and support services to a client, our position frequently changes: where we configure, migrate, or maintain an environment containing records relating to the employees, customers, or suppliers of that client, we act as processor on the documented instructions of the client, and the terms of the relevant engagement documentation, rather than the present Policy, govern that relationship. In that capacity, our obligations of confidentiality, of security, of the engagement of any subprocessor, of assistance in the event of a personal data breach, and of the return or the deletion of the data at the conclusion of the work are recorded in the engagement documentation or in a separate data processing agreement concluded with the client, consistently with Article 28 of Regulation (EU) 2016/679 where the European framework applies and with the corresponding requirements of Federal Decree-Law No. 45 of 2021.
Application of the Policy extends to personal data collected through the website, through the enquiry form published on the contact page, through the appointment scheduling tools linked from the website, through electronic mail and messaging channels addressed to us, and through business development activity conducted by our personnel. Personal data received by us in the capacity of processor, personal data held within the environments of our clients, and personal data collected by third parties operating their own websites fall outside its application.
Nothing in the Policy displaces the confidentiality provisions of any engagement letter, non-disclosure agreement, or master services agreement concluded between us and a client. Where such provisions offer greater protection, they prevail.
Our processing is governed principally by Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, the federal statute applicable across the United Arab Emirates to controllers and processors established in the country outside the two financial free zones, and applicable also, by virtue of its extraterritorial reach, to entities abroad that process the personal data of individuals located in the Emirates. Sharjah Media City being a free zone of general commercial character, the federal regime applies to us in full, and the separate regimes established for the Dubai International Financial Centre and for the Abu Dhabi Global Market are not engaged.
Position as at the date of the present Policy: the Implementing Regulations contemplated by Federal Decree-Law No. 45 of 2021 have not yet been issued. Certain operational parameters, among them the prescribed deadlines for responding to requests, the approved mechanisms for transfers abroad, and the thresholds triggering appointment of a data protection officer, will be settled only upon their publication. Our practice in the interim is described below and follows the text of the statute together with recognised international standards. Revision of the Policy will follow publication of the implementing framework.
Where we offer services to, or monitor the behaviour of, individuals located in the European Union, Regulation (EU) 2016/679 applies to the processing concerned by operation of its Article 3(2). Equivalent provisions of the United Kingdom General Data Protection Regulation, read together with the Data Protection Act 2018, apply in respect of individuals located in the United Kingdom. Storage of information on, and access to information already stored on, the terminal equipment of visitors located in those territories is additionally governed by Article 5(3) of Directive 2002/58/EC and, in the United Kingdom, by regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003.
The enquiry form published on our contact page collects the first name, the last name, the business electronic mail address, the telephone number, the name of the organisation, an indication of the system currently in use, a selection identifying the principal requirement, and a free-text message.
Particular attention attaches to the free-text field. Enquirers describing a migration involving accounting records, human resources data, or payroll frequently include information about identified individuals, and occasionally information falling within the category of sensitive personal data. We do not solicit information of that character at the enquiry stage, and we ask that it be withheld until a confidentiality agreement is in place. Where such information reaches us notwithstanding, access is restricted to personnel handling the enquiry and the material is deleted or reduced to a summary at the earliest opportunity consistent with the purpose for which it was sent.
Two scheduling tools are presently linked from the website, one operated by Calendly LLC and one forming part of the Google Workspace appointment scheduling facility. Booking a consultation through either tool involves the collection of the name, the electronic mail address, the selected time slot, the applicable time zone, and any information volunteered in the notes field, together with the technical data generated by the tool itself. Confirmation and reminder messages are dispatched by the tool on our behalf.
Electronic mail addressed to us and telephone conversations generate personal data comprising the identity of the correspondent, the contact details used, the content of the exchange, and the associated metadata such as the date, the time, and the duration.
Visiting the website causes technical data to be generated automatically, including the internet protocol address, the type and version of the browser, the operating system, the screen characteristics, the language preference, the referring address, the pages requested, the sequence in which they were requested, and the duration of the visit. Collection through analytics technologies is conditional upon consent, as described in the Cookie Policy. A limited quantity of technical data is recorded in server logs for security and diagnostic purposes irrespective of consent, on the basis of our legitimate interest in maintaining the integrity of the service.
Where an enquiry matures into an engagement, we collect and hold the identity and contact details of the individuals nominated by the client as project sponsors, key users, and administrative contacts, together with the correspondence, meeting records, requirement documents, and support tickets generated during the project, and the billing and payment information necessary to administer the relationship.
Personal data relating to the representatives of our suppliers, subcontractors, and referral partners are held for the administration of those relationships. Applications for employment or subcontracting generate curricula vitae, correspondence, and interview records, retained in accordance with the periods stated at section 11.
Most of the personal data we hold are supplied to us directly by the individual concerned. Data reach us from other sources in three further ways: from the organisation that employs or engages the individual, where a client nominates a person to act as a project contact; from publicly accessible professional sources, business networking platforms such as LinkedIn, business directories, and corporate websites, in the course of business development activity; and from referral partners and other intermediaries who introduce prospective clients to us. Where personal data are obtained otherwise than from the individual, we provide the information required by Article 14 of Regulation (EU) 2016/679 within a reasonable period and in any event before the data are first used to communicate with that individual.
Every processing operation we undertake is anchored to a stated purpose and to a lawful basis. Bases available under Federal Decree-Law No. 45 of 2021 differ in their architecture from those available under Regulation (EU) 2016/679, notably in that the federal statute treats consent as the ordinary basis and admits the alternatives as defined exceptions, while the European instrument places six bases on an equal footing. The table below identifies, for each purpose, the basis relied upon under each regime.
| Purpose | Personal data involved | Basis under UAE law | Basis under GDPR and UK GDPR |
|---|---|---|---|
| Responding to an enquiry and preparing a proposal | Identity, contact, organisation, and requirement data | Necessary for the performance of a contract or for steps taken at the request of the data subject prior to entering into one | Article 6(1)(b), steps at the request of the data subject prior to contract |
| Administering a scheduled consultation | Identity, contact, and scheduling data | As above | Article 6(1)(b) |
| Delivering consulting, implementation, migration, training, and support services | Engagement and correspondence data | Necessary for the performance of a contract | Article 6(1)(b) |
| Invoicing, collection, and financial record keeping | Identity, contact, and billing data | Necessary for compliance with a legal obligation | Article 6(1)(c), read with the retention obligations of UAE tax and commercial legislation |
| Maintaining the security, integrity, and availability of the website | Technical and log data | Necessary to protect the legitimate interests of the controller | Article 6(1)(f), legitimate interest in network and information security |
| Measuring website audience and performance | Analytics identifiers and usage data | Consent | Article 6(1)(a), consent, obtained through the cookie interface |
| Business development and marketing communications about our services | Identity and contact data | Consent, or our legitimate interest in developing business relationships | Article 6(1)(f), legitimate interest in business-to-business development through enquiries, professional networking, corporate directories, and referrals; Article 6(1)(a) where the electronic marketing rules require consent, subject to an opt-out in every message and to the exception at regulation 22(3) of the Privacy and Electronic Communications (EC Directive) Regulations 2003 for existing clients contacted about similar services |
| Establishing, exercising, or defending legal claims | Any relevant category | Necessary for the establishment or defence of a right before the competent authorities | Article 6(1)(f), legitimate interest in the protection of legal position |
| Assessing an application for employment or subcontracting | Application and interview data | Steps prior to entering into a contract, with consent for retention beyond the process | Article 6(1)(b), and Article 6(1)(a) for retention in a talent pool |
Where we rely upon legitimate interest, an assessment balancing that interest against the interests, rights, and freedoms of the individual has been conducted and is documented. A summary of any such assessment is available on request addressed to info@tradingerpconsulting.com.
Consent, where relied upon, is sought by means of an affirmative act performed by the individual, and never through pre-ticked boxes, silence, or continued browsing. Requests for consent are presented separately from other matters, in intelligible language, and identify the purpose to which they relate.
Withdrawal is available at any time and is as straightforward as the original act. Consent to analytics and other non-essential technologies may be withdrawn through the cookie preference control accessible from every page of the website. Commercial communications, whether sent in reliance upon consent or upon our legitimate interest in business development, may be stopped at any time through the unsubscribe facility contained in each message or by writing to info@tradingerpconsulting.com. Withdrawal operates prospectively and does not affect the lawfulness of processing carried out before it took effect.
Refusal of consent, or its subsequent withdrawal, carries no adverse consequence for the individual and does not affect the availability or the quality of the services we provide. Submission of an enquiry has never been conditional upon acceptance of marketing communications, and the two matters are presented separately on the form.
Personal data are disclosed only where a defined purpose requires it, and only to the categories identified below. We do not sell personal data, and we do not disclose personal data to third parties for their own independent marketing purposes.
Our business evolves, and the suppliers supporting it change from time to time. In order that the present Policy should remain accurate without requiring amendment upon every such change, a register of the third-party services in use, identifying each provider, the purpose it serves, the categories of data involved, and the location of processing, is maintained separately and made available on request addressed to info@tradingerpconsulting.com. Each version of the register carries a date, and superseded versions are retained. Where a new category of recipient is introduced, or where a change materially alters the character of the processing, the Policy itself is amended and the individuals concerned are notified in accordance with section 19.
Our operations are conducted from the United Arab Emirates, while several of the services we rely upon are supplied by providers established in the United States and in the European Union, with processing infrastructure distributed across multiple territories. Transfers of personal data outside the United Arab Emirates therefore occur in the ordinary course.
Federal Decree-Law No. 45 of 2021 permits transfer to a jurisdiction affording an adequate level of protection, and, in the absence of adequacy, permits transfer where appropriate contractual safeguards are in place, where the transfer is necessary for the performance of a contract with the data subject or in the interest of the data subject, or where the data subject has given consent to the transfer having been informed of its implications. The mechanism for the formal determination of adequacy awaits the Implementing Regulations, and our present practice is accordingly to secure contractual safeguards in every case in which the destination has not been recognised as adequate, and to keep the position under review.
Where personal data are transferred out of the European Economic Area or out of the United Kingdom, we rely upon the standard contractual clauses adopted by the European Commission and, for United Kingdom transfers, upon the International Data Transfer Addendum issued by the Information Commissioner, supplemented where the circumstances warrant by additional technical and organisational measures identified through a transfer risk assessment. Copies of the safeguards applied to a particular transfer may be requested at info@tradingerpconsulting.com, subject to the redaction of commercially confidential terms.
Personal data are kept for no longer than is necessary for the purposes for which they were collected, after which they are deleted or irreversibly anonymised. Periods applied in the ordinary course appear below and are subject to extension where a legal obligation, an actual or anticipated dispute, or a regulatory investigation requires it.
| Category | Retention period | Rationale |
|---|---|---|
| Enquiries that do not result in an engagement | 24 months from the last substantive contact | Continuity of commercial dialogue and defence against claims arising from the enquiry |
| Records of scheduled consultations | 24 months from the date of the appointment | Consistency with the treatment of enquiries |
| Client engagement records | 6 years from the conclusion of the engagement | Period exceeding by a deliberate margin the five-year limitation applicable to obligations arising between merchants under Federal Decree-Law No. 50 of 2022, so that a claim asserted late within that period remains capable of being answered, together with continuity of support |
| Accounting and tax records | Seven years from the end of the relevant tax period | Record-keeping obligations under the UAE Corporate Tax and tax procedures legislation, together with any value added tax obligation should the company become registered for that tax |
| Marketing contact records | Until consent is withdrawn, and thereafter a suppression record indefinitely | Suppression records exist for the purpose of honouring the withdrawal itself |
| Website server logs | 12 months | Security monitoring and incident investigation |
| Analytics data | Governed by the retention setting configured within Google Analytics 4, presently 14 months | Audience measurement over a comparable annual cycle |
| Unsuccessful applications | 12 months from the conclusion of the process, or longer with consent | Consideration for subsequent opportunities |
| Records of consent and of rights requests | 6 years from the event | Demonstration of compliance |
Technical and organisational measures proportionate to the size of our operations and to the risk presented by the data we hold are applied, and we keep them under review as the business develops. Being a small consultancy, we rely to a considerable degree on the security of established, reputable platforms for the hosting of the website and the storage of our records, and we configure the controls that those platforms make available. Measures in use include encryption of data in transit through transport layer security across the website and our correspondence channels, encryption at rest within the platforms on which our records reside, access confined to the members of our team who require it, multi-factor authentication on the principal accounts, the use of strong and distinct credentials, and confidentiality undertakings binding those who act for us. Files of importance are backed up, and we take reasonable care to keep the material relating to individual client engagements apart from our general administrative records. Before a new supplier is adopted, we have regard to the security and the reputation of the service concerned.
No system connected to a public network can be rendered wholly immune from compromise, and no assurance to that effect is offered. Should a breach of personal data occur that is likely to result in risk to the individuals concerned, we will notify the competent federal authority without undue delay and, where the risk is high, will communicate the breach to those individuals directly, together with a description of the likely consequences and of the measures taken to address it. We keep an internal record of any such breach and of the steps taken in response to it.
Rights available depend upon the regime applicable to the processing in question. Rather than presenting a single composite list, the table below distinguishes the two frameworks, since the scope and the conditions attaching to each right differ.
| Right | Under Federal Decree-Law No. 45 of 2021 | Under GDPR and UK GDPR |
|---|---|---|
| Information and access | Available, including the right to obtain information about the processing and to request a copy of the personal data held | Article 15 |
| Rectification | Available in respect of inaccurate or incomplete data | Article 16 |
| Erasure | Available, subject to exceptions including retention required by law and the defence of legal claims | Article 17 |
| Restriction of processing | Available in defined circumstances | Article 18 |
| Portability | Available in respect of data processed by automated means on the basis of consent or contract | Article 20 |
| Objection | Available in respect of processing for direct marketing and, on grounds relating to the particular situation, in respect of certain other processing | Article 21 |
| Automated decision-making | Available in respect of decisions producing legal effects or comparably significant effects | Article 22 |
| Withdrawal of consent | Available at any time | Article 7(3) |
| Complaint to a supervisory authority | Available to the competent federal authority | Article 77 |
Requests should be addressed to info@tradingerpconsulting.com and should identify the right invoked and the personal data concerned with sufficient particularity to permit a search. Verification of identity may be required before a request is actioned, and we will seek only such information as is necessary for that purpose.
Our practice is to respond within one month of receipt, in line with Article 12(3) of Regulation (EU) 2016/679, extendable by two further months where the request is complex or where several requests have been received, in which case the individual is informed of the extension and of its reasons within the first month. The federal deadline applicable to requests under Federal Decree-Law No. 45 of 2021 awaits the Implementing Regulations, and the one-month standard is applied in the interim to every request irrespective of its origin. No fee is charged, save where a request is manifestly unfounded or excessive, in which case a reasonable administrative fee may be levied or the request declined, with reasons given in writing.
Should a response fail to satisfy the individual concerned, a complaint may be pursued as follows.
We would ask, without prejudice to any of those routes, that concerns be raised with us in the first instance, since most are capable of resolution directly and promptly.
Decisions producing legal effects concerning an individual, or affecting an individual in a comparably significant manner, are not taken by automated means. Ordering of enquiries within our internal workflow may be assisted by automated sorting, but every commercial decision, including the decision whether to submit a proposal and on what terms, is taken by a human being who is able to consider the circumstances of the particular case.
Our services are directed exclusively to businesses and to the professionals who represent them, and the website is not designed for, nor addressed to, persons below the age of eighteen years. Personal data relating to children are not knowingly collected. Should we become aware that such data have reached us, they will be deleted promptly, and a parent or guardian who believes that a child has provided personal data to us is invited to write to info@tradingerpconsulting.com.
Links published on the website lead to resources operated by others, among them the scheduling tools and material published by Odoo S.A. Following such a link takes the visitor outside our control, and the privacy practices of the destination are governed by its own documentation, which we would encourage visitors to read.
A distinction of some importance should be recorded in relation to Odoo. Our business consists of consulting, implementation, migration, integration, training, and support services. Software licences, cloud hosting, subscription services, and the associated platform facilities are supplied by Odoo S.A. under its own contractual and privacy documentation. Where a client contracts directly with Odoo S.A., that company acts as controller or processor in respect of the data held within the subscribed environment according to the arrangements it has concluded with the client, and the present Policy does not extend to that processing.
Article 27 of Regulation (EU) 2016/679, and the corresponding provision of the United Kingdom General Data Protection Regulation, require a controller established outside the respective territory and falling within the extraterritorial scope of the instrument to designate a representative, subject to a derogation for processing that is occasional, does not involve large-scale processing of special category data, and is unlikely to result in risk to the rights and freedoms of individuals.
Our engagement with individuals in the European Union and the United Kingdom is presently occasional in character and confined to business contact details and enquiry correspondence, and no representative has been designated. Should the volume or the character of that engagement change, a representative will be appointed and the present section amended, with the contact details published here.
Revision may become necessary as our services develop, as the technologies deployed on the website change, or as the applicable law evolves. Publication of the Implementing Regulations to Federal Decree-Law No. 45 of 2021 is expected to require a review of the retention periods, the transfer mechanisms, and the response deadlines described above.
Every version carries a version number and a date, and the current version is that shown at the head of the document. Where an amendment materially affects the rights of individuals or introduces a purpose incompatible with those previously disclosed, notice will be given by a prominent statement on the website and, where we hold an address for the individual, by direct communication, in advance of the amendment taking effect. Superseded versions are archived and may be obtained on request.
Questions concerning the present Policy, requests for the register of third-party services, requests relating to the exercise of rights, and complaints should be addressed to info@tradingerpconsulting.com, or to B&B Consulting LLC at the registered office identified at section 2.