Privacy Policy

  • Home
  • Privacy Policy

1. Introduction

DT Global Capital LLC-FZ (“DT Global Capital”, the “Company”, “we”, “us” or “our”) is a limited liability free zone company registered with the Meydan Free Zone Authority in Dubai, United Arab Emirates (the “UAE”), with its registered office at The Meydan Hotel, Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, UAE. We are an international advisory firm delivering artificial intelligence (AI) development, business strategy and economic advisory services to clients in the UAE and around the world. We do not provide regulated financial services, and we do not solicit business, investment or funds from anyone (see Section 9).

We take the privacy and security of personal data seriously. This Privacy Policy (the “Policy”) describes how we collect, use, disclose, transfer, store and otherwise process personal data through our website at www.dtglobalcapital.com (the “Website”) and in the course of our business activities, and it explains the rights available to individuals under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “PDPL”), its implementing regulations as issued from time to time, and other applicable laws and regulations of the UAE.

Please read this Policy carefully. Where the processing of your personal data requires your consent under the PDPL, we will ask for that consent in a clear, specific and unambiguous manner, and you may withdraw it at any time as described in Section 15. Certain processing described in this Policy does not depend on consent because it is necessary for the performance of a contract, required by law, or otherwise permitted under the PDPL.

This Policy at a glance

  • We collect the personal data you give us — for example when you contact us, subscribe to our insights, apply for a role or engage our services — together with limited technical data collected automatically when you browse the Website.
  • We use personal data to operate the Website, deliver our advisory and AI development services, communicate with you, meet our legal and regulatory obligations and, only with your consent, send you marketing communications.
  • We do not sell personal data. We share it only with trusted service providers, professional advisers, group entities and authorities where required, and otherwise only as described in Section 11.
  • We do not solicit anyone. We make no unsolicited approaches by telephone, message, email, post, social media or in person, and nothing on the Website or in our communications is an offer or solicitation of investment or of any regulated financial product or service (Section 9).
  • Because our work is international, personal data may be transferred outside the UAE. When it is, we apply the safeguards required by Articles 22 and 23 of the PDPL.
  • You have rights over your personal data, including access, correction, erasure and objection. Contact us at compliance@dtglobalcapital.com to exercise them.

2. Who this Policy covers

This Policy applies to personal data that we process as a controller in connection with:

  • visitors to and users of the Website;
  • individuals who contact us by email, telephone, through the Website or otherwise;
  • clients and prospective clients who are natural persons, and the directors, officers, employees and other representatives of corporate clients and prospective clients;
  • subscribers to our newsletters, insights, research and event communications;
  • suppliers, consultants and business partners, and their personnel;
  • candidates who apply for roles with us; and
  • other individuals whose personal data we receive in the course of providing our services.

Where we process personal data on behalf of and under the documented instructions of a client — for example, personal data contained in datasets that a client entrusts to us for an AI development or advisory engagement — we generally act as a processor. In those cases the client’s own privacy notice governs the processing, and this Policy applies only to the extent that we determine the purposes and means of the processing ourselves. Section 10 explains our approach to client data in AI engagements in more detail.

3. Key terms

In this Policy, the following terms carry the meanings given to them in the PDPL, summarised here for convenience:

  • “Personal data” means any data relating to an identified natural person, or a natural person who can be identified directly or indirectly by way of linking data, including through name, voice, picture, identification number, online identifier, geographic location, or one or more features of their physical, psychological, economic, cultural or social identity.
  • “Sensitive personal data” means personal data that directly or indirectly reveals a person’s family or racial origin, political or philosophical opinions, religious beliefs, criminal record, biometric data, or health data.
  • “Processing” means any operation performed on personal data, whether or not by automated means, including collection, storage, recording, organisation, adaptation, retrieval, use, disclosure, transfer, restriction, erasure or destruction.
  • “Controller” and “processor” refer, respectively, to the party that determines the purposes and means of processing personal data, and the party that processes personal data on that party’s behalf and under its instructions.

4. Personal data we collect

4.1 Information you provide to us

  • Identity and contact details — your name, job title, organisation, email address, telephone number and country, for example when you complete the contact form on the Website, write to us at compliance@dtglobalcapital.com, or exchange contact details with us at a meeting or event.
  • Inquiry and correspondence data — the content of your messages, requests, proposals and other communications with us, together with any information you choose to include in them.
  • Client and engagement data — where you or your organisation engage us: onboarding and verification information (including, where applicable, identity documents and information required for conflict-of-interest, sanctions and anti-money-laundering checks), billing and payment details, and personal data contained in materials relevant to the engagement.
  • Marketing preferences — your subscription choices when you sign up to receive our newsletters, insights, research or event invitations.
  • Recruitment data — your CV or résumé, cover letter, education and employment history, qualifications, right-to-work and visa status, references, and any other information you submit when applying for a role with us.
  • Event and meeting data — registration details for events, webinars and meetings that we host or attend and, where lawfully recorded and notified to you in advance, recordings or transcripts of calls and virtual meetings.

4.2 Information we collect automatically

When you visit the Website, we and our analytics providers automatically collect certain technical information about your device and your interaction with the Website. This includes your IP address, browser type and version, operating system, device identifiers, the website that referred you to us, the pages you view, the links you click, the date, time and duration of your visit, and your approximate (city-level) location derived from your IP address. This information is collected through cookies and similar technologies, which are explained in Section 7.

4.3 Information we receive from other sources

We may also receive personal data about you from:

  • your organisation or colleagues — for example, when a colleague identifies you as a contact for an engagement;
  • referrals and introductions from clients, partners and other professional contacts, where you have asked to be introduced to us;
  • publicly available sources, such as commercial registries, licensing records, professional networking sites (such as LinkedIn), company websites and reputable media, in order to verify the identity and standing of clients, suppliers and counterparties;
  • our service providers, such as website analytics providers;
  • recruitment agencies and referees, in connection with applications for roles with us; and
  • screening and compliance databases, where checks are required by law or by our risk policies.

4.4 Sensitive personal data

We do not seek to collect sensitive personal data through the Website, and we ask that you do not submit it to us unless it is necessary. We process sensitive personal data only where it is strictly necessary and lawful — for example, where it appears in documents you choose to send us, in recruitment records, or in datasets a client entrusts to us under contract with enhanced safeguards — and we obtain consent where the PDPL requires it.

5. How we use personal data

We process personal data for the following purposes:

  • Operating the Website — to provide, secure, maintain and improve the Website and tailor its content to our audience.
  • Responding to you — to handle your inquiries, requests, proposals and other correspondence.
  • Providing our services — to deliver AI development, business strategy and economic advisory engagements, manage client relationships, administer projects, and invoice and collect payment.
  • Client onboarding and compliance — to carry out due-diligence, conflict-of-interest, sanctions and, where applicable, anti-money-laundering checks required by law, regulation or our internal risk policies.
  • Marketing communications and relationship management — with your consent, to send you newsletters, insights, research and event invitations, to measure engagement with them, and to maintain our client relationship records.
  • Recruitment — to assess applications, verify credentials and references, and communicate with candidates.
  • Analytics and improvement — to understand how the Website and our communications are used and to develop and improve our services, using aggregated or de-identified information wherever feasible.
  • Safety, security and fraud prevention — to protect our systems, premises, personnel, clients and data, and to detect, prevent and investigate fraud, misuse and security incidents.
  • Legal and regulatory compliance — to comply with the laws and regulations of the UAE, the licence conditions of the Meydan Free Zone Authority, and lawful requests of courts, regulators and law enforcement, and to maintain statutory and tax records.
  • Legal claims — to establish, exercise or defend legal claims and rights.
  • Corporate transactions — in connection with the evaluation or completion of a merger, acquisition, reorganisation, financing or sale of assets, subject to appropriate safeguards.

We will not use personal data for a purpose incompatible with those described above without informing you and, where the PDPL requires it, obtaining your consent.

7. Cookies and similar technologies

Cookies are small text files placed on your device when you visit a website. We use cookies and similar technologies (such as pixels and local storage) in the following categories:

Category What it does Basis
Strictly necessary Enables core functionality such as security, network management and page navigation. The Website cannot function properly without these. Necessity
Analytics & performance Helps us understand how visitors use the Website — pages visited, time on site, errors — so that we can improve it. Data is aggregated wherever possible. Consent
Functionality Remembers choices you make, such as language or region, to personalise your experience. Consent
Marketing Measures the effectiveness of our communications. We do not currently use third-party advertising cookies on the Website. Consent

Where required, non-essential cookies are set only after you indicate your preferences through our cookie notice. You can also manage or delete cookies through your browser settings at any time; if you disable cookies, parts of the Website may not function as intended. Where we use third-party analytics tools (such as Google Analytics), the providers process technical data on our behalf under contractual safeguards, and we configure them to minimise the personal data collected wherever the tools allow.

8. Direct marketing and your choices

We send newsletters, insights, research and event invitations by email only where you have subscribed to them or otherwise given your consent. Every marketing email we send includes an unsubscribe link, and you may opt out at any time by using that link or by writing to compliance@dtglobalcapital.com. We act on opt-out requests promptly. Opting out of marketing does not affect service, engagement-related or administrative communications, which we will continue to send where necessary. We do not make marketing telephone calls and we do not send marketing text or social-media messages. Our marketing practices are designed to comply with the PDPL, Cabinet Resolution No. 56 of 2024 Concerning the Telemarketing Regulations and the applicable regulatory policies of the Telecommunications and Digital Government Regulatory Authority (TDRA). See also Section 9.

9. No solicitation

DT Global Capital does not solicit business, investment or funds from anyone, by any means, and we do not make unsolicited requests for personal data. This Section explains what that means in practice and the UAE legal framework that it reflects.

9.1 No unsolicited approaches

We do not make unsolicited telephone calls; we do not send unsolicited SMS, instant-messaging, social-media or email messages; we do not make unsolicited approaches in person or by post; and we do not engage agents, introducers, call centres or other third parties to do any of these things on our behalf. We do not buy, rent or scrape contact lists for marketing purposes. We contact you only where you have approached us or asked to be introduced to us, where an existing engagement or professional relationship makes the contact necessary, or where you have subscribed to communications that you can stop at any time, as described in Section 8.

9.2 No offer or promotion of financial products or services

DT Global Capital holds a commercial licence issued by the Meydan Free Zone Authority. We are not licensed or regulated by the Securities and Commodities Authority (SCA), the Central Bank of the UAE, the Dubai Financial Services Authority (DFSA) or the Financial Services Regulatory Authority of Abu Dhabi Global Market (FSRA), and we do not carry on any activity that requires such a licence. We do not offer, promote, market, introduce, recommend or solicit subscriptions for securities, investment funds, virtual assets, deposits or any other financial product or service; we do not provide investment, financial or credit advice; and we do not hold or manage money or assets on behalf of clients or third parties. Nothing on the Website or in our publications, insights, research, presentations or other communications constitutes an offer, invitation, inducement, solicitation or recommendation to buy, sell or subscribe for any financial product, or investment, legal or tax advice, in the UAE or in any other jurisdiction. Our advisory services are provided only under a written engagement agreed with the client.

9.3 Legal framework

This Section reflects, among others, the SCA Rulebook (Decision No. 13/R.M of 2021 of the Chairman of the SCA Board of Directors), under which the promotion of financial products in the UAE is a licensed activity; Cabinet Resolution No. 56 of 2024 Concerning the Telemarketing Regulations; the TDRA’s Regulatory Policy on Unsolicited Electronic Communications; Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes; and Article 17 of the PDPL, which gives you an unconditional right to object to direct marketing.

9.4 Impersonation

If you receive a call, message or email that claims to come from DT Global Capital and invites you to invest, transfer money or share personal or financial information, do not respond and please report it to compliance@dtglobalcapital.com. We will never ask you to make a payment or to share banking details through an unsolicited call or message.

10. AI development and client data

Building and deploying AI solutions responsibly is central to what we do. Where an engagement involves personal data, we apply the following principles:

  • Processor role and contracts — where a client entrusts us with personal data, we process it only on the client’s documented instructions and under written terms that reflect the requirements of the PDPL, including confidentiality, security and onward-transfer obligations.
  • No cross-client training — we do not use personal data entrusted to us by one client to train, fine-tune or improve models, products or services for any other client, unless this is expressly agreed in writing or the data has first been irreversibly anonymised.
  • Privacy by design — we encourage anonymisation, pseudonymisation or the use of synthetic data before personal data enters a model development pipeline, and we assess privacy risks at the design stage of each engagement, including through data protection impact assessments where the PDPL requires them.
  • Third-party AI tools — we vet third-party AI tools before use and do not enter personal data into them unless appropriate contractual and technical safeguards are in place.
  • Human oversight — AI-generated analyses and outputs that we rely on for client deliverables are subject to review by our professionals, as described in Section 16.

11. How we share personal data

We do not sell personal data, and we do not share it with third parties for their own marketing purposes. We share personal data only as follows:

  • Group entities and affiliates — for the purposes described in this Policy and consistent with it.
  • Service providers — carefully selected providers that support our business, including hosting and cloud infrastructure, IT support, email and communications, client relationship management, marketing distribution, analytics, banking and payment processing, and document management. They are bound by written contracts imposing confidentiality, use-limitation and security obligations.
  • Professional advisers — lawyers, auditors, accountants, tax advisers and insurers, under professional or contractual duties of confidentiality.
  • Authorities — the Meydan Free Zone Authority, courts, law enforcement, tax and other UAE or foreign authorities, where disclosure is required by law or by a lawful and proportionate request.
  • Corporate transactions — prospective or actual counterparties and their advisers in connection with a merger, acquisition, financing, reorganisation or sale of assets, subject to confidentiality safeguards.
  • With your direction or consent — in other cases, where you ask us to share information or agree to the sharing.

12. International data transfers

We operate internationally, and personal data may be transferred to, stored in or accessed from countries outside the UAE — for example, where our service providers, clients or partners are located abroad.

When we transfer personal data outside the UAE, we do so in accordance with Articles 22 and 23 of the PDPL: we transfer to jurisdictions recognised as providing an adequate level of protection; where no adequacy applies, we put in place appropriate safeguards, such as contractual clauses imposing obligations equivalent to those of the PDPL; or we rely on a specific derogation permitted by the PDPL, such as your express consent, necessity for the performance of a contract, or the establishment, exercise or defence of legal claims. You can request further information about our transfer safeguards at compliance@dtglobalcapital.com.

13. How we protect personal data

We maintain technical and organisational measures proportionate to the nature and risks of our processing, including encryption of data in transit, access controls and least-privilege permissions, multi-factor authentication on key systems, logging and monitoring, staff confidentiality undertakings and training, due diligence over vendors, secure disposal, and documented incident-response procedures.

If a personal data breach occurs that is likely to prejudice the privacy, confidentiality or security of personal data, we will notify the UAE Data Office and, where required, affected individuals in accordance with Article 9 of the PDPL and its implementing regulations. No method of transmission or storage is completely secure; if you have reason to believe that your interaction with us is no longer secure, please contact us immediately at compliance@dtglobalcapital.com.

14. How long we keep personal data

We keep personal data only for as long as necessary for the purposes for which it was collected, including satisfying legal, accounting, tax and reporting requirements. In determining retention periods we consider the nature and sensitivity of the data, the purposes of processing, statutory retention obligations under UAE law, applicable limitation periods, and actual or anticipated disputes. Typical periods are:

Category of data Typical retention period
Website inquiries and correspondence (no engagement follows) Up to 24 months from our last interaction with you
Client engagement, onboarding and billing records Duration of the engagement plus at least 5 years; records relevant to tax typically 7 years, in line with UAE commercial and tax laws
Newsletter and marketing lists Until you unsubscribe or we learn that your address is no longer active
Recruitment records (unsuccessful applications) Up to 12 months after the conclusion of the recruitment process, or longer with your consent
Website technical logs and analytics data Up to 26 months, after which data is deleted or aggregated

When personal data is no longer required, we delete or irreversibly anonymise it securely. We may retain anonymised information, which no longer identifies you, for analytical and service-improvement purposes.

15. Your rights under the PDPL

Subject to the conditions and exemptions set out in the PDPL (in particular Articles 13 to 18), you have the following rights in relation to your personal data:

  • Access and information — to confirm whether we process your personal data and to receive a copy of it, together with information about the purposes of processing, the categories of recipients (including recipients outside the UAE), the retention criteria, and how to seek redress.
  • Portability — to receive your personal data in a structured, machine-readable format and to have it transmitted to another controller where technically feasible.
  • Rectification — to have inaccurate or incomplete personal data corrected.
  • Erasure — to have your personal data deleted in the circumstances contemplated by the PDPL.
  • Restriction — to restrict processing in certain circumstances.
  • Objection and cessation — to object to, or request that we stop, particular processing, including an unconditional right to object to processing for direct marketing.
  • Automated decisions — to object to decisions based solely on automated processing that produce legal or similarly significant effects, and to request human review.
  • Withdrawal of consent — to withdraw any consent you have given, at any time, without affecting processing already carried out.

To exercise any of these rights, email compliance@dtglobalcapital.com with the subject line “Data Privacy Request”. We may need to verify your identity before acting on a request, and we will respond without undue delay and within any period prescribed by the PDPL and its implementing regulations. We do not charge a fee unless permitted by law. If we decline a request in reliance on an exemption, we will explain why, and you may complain as described in Section 21.

16. Automated decision-making

Although AI is at the heart of our services, we do not make decisions that produce legal effects for you, or that similarly significantly affect you, based solely on automated processing without human involvement. AI-assisted analyses that inform our advice or deliverables are reviewed by our professionals. If this ever changes, we will update this Policy, tell you, and ensure you can obtain human review of any such decision as required by the PDPL.

17. Children’s privacy

The Website and our services are directed at businesses and professionals, not at individuals under the age of 18, and we do not knowingly collect personal data from children. If you believe that a child has provided personal data to us, please contact us at compliance@dtglobalcapital.com and we will delete it promptly.

18. Third-party websites

The Website may contain links to third-party websites and platforms, including professional networking and social media sites. We are not responsible for the privacy practices or content of those third parties, and this Policy does not apply to them. We encourage you to review the privacy notices of any third-party site you visit.

19. Visitors and clients outside the UAE

If you interact with us from outside the UAE, the data protection laws of your country — for example, the EU or UK General Data Protection Regulation for individuals in the European Economic Area or the United Kingdom — may grant you additional rights in respect of particular processing to which those laws apply. Where such laws apply to our processing, we will honour the rights they provide. Please contact us at compliance@dtglobalcapital.com with any questions.

20. Changes to this Policy

We may update this Policy from time to time to reflect changes in law — including the issuance of executive regulations and decisions under the PDPL — or changes in our practices and services. The updated version will be posted on the Website with a revised “Last updated” date. If we make material changes, we will provide a prominent notice on the Website or notify you directly where the law requires it. We encourage you to review this Policy periodically.

21. Contacting us and complaints

Questions, requests and complaints concerning this Policy or our handling of personal data should be addressed to:

Compliance & Data Privacy

DT Global Capital LLC-FZ

The Meydan Hotel, Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

Email: compliance@dtglobalcapital.com

We aim to acknowledge privacy inquiries promptly and to resolve them within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the UAE Data Office, the federal data protection authority established under Federal Decree-Law No. 44 of 2021, in accordance with the procedures prescribed under the PDPL.

This Policy is governed by the laws of the United Arab Emirates as applied in the Emirate of Dubai.

© 2026 DT Global Capital LLC-FZ. All rights reserved. Last updated: 21 August 2026.