Skip to content

Privacy Policy

Introduction

At Underwings, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website, engage our cybersecurity services, or communicate with us.

By using our services or website, you agree to the terms outlined in this policy.

We process personal data in accordance with the UAE Personal Data Protection Law (PDPL, Federal Decree-Law No. 45 of 2021). Our lawful bases for processing are: consent (e.g. our marketing briefing), performance of a contract (delivering services you engage us for), legal obligation (e.g. tax records), and legitimate interest (responding to enquiries and business-to-business contact).

Last updated: 27 May 2026.

Information We Collect

Personal Information

When you engage our services or contact us, we may collect:

  • Name and contact details (email, phone number, company name)
  • Job title and department
  • Business information relevant to security assessments
  • Payment and billing information

Technical Information

When you visit our website, we may automatically collect:

  • IP address and browser type
  • Device information and operating system
  • Pages visited and time spent on site
  • Referral source and navigation patterns

Service-Related Information

During penetration testing, compliance assessments, or training delivery, we may access:

  • System configurations and network architecture (with explicit authorization)
  • Vulnerability scan results and security findings
  • Employee training completion data
  • Compliance documentation and audit evidence

How We Use Your Information

We use collected information to:

  • Deliver penetration testing, GRC, and security training services
  • Communicate project updates and findings
  • Process payments and maintain business records
  • Improve our services and website experience
  • Comply with legal and regulatory requirements
  • Send relevant cybersecurity updates (with your consent)

We never sell your personal information to third parties.

Enquiry submissions & marketing opt-in

When you contact us via the enquiry form, by email, or by phone, we collect the information you provide (your name, work email, company, optional phone number, and the details of your enquiry). This information is used to:

  • Respond to your enquiry and follow up with a written quote where applicable
  • Maintain a record of the conversation in our internal CRM for opportunity management

You may optionally opt in to receive our monthly UAE cybersecurity threat briefing. This is a separate marketing communication from any transactional follow-up. We will only add you to the briefing list if you explicitly opt in. You can unsubscribe at any time via the unsubscribe link in any briefing email, or by emailing [email protected].

Our use of this data complies with the UAE Personal Data Protection Law (PDPL, Federal Decree-Law No. 45 of 2021). We retain enquiry data for up to 24 months for opportunity tracking, after which it is anonymised or deleted unless you have become a paying client.

Data Protection & Security

As a cybersecurity company, we practice what we preach:

  • All client data is encrypted in transit and at rest
  • Access to sensitive information is restricted to authorized personnel only
  • We maintain ISO 27001-aligned security controls
  • Penetration testing findings are stored securely and shared only with authorized stakeholders
  • We conduct regular security audits of our own systems

Your rights

You have the right to:

  • Access your personal information we hold
  • Correct inaccurate or incomplete data
  • Delete your information (subject to legal retention requirements)
  • Opt-out of marketing communications at any time
  • Request a copy of your data in portable format
  • Object to certain processing activities

To exercise any of these rights, contact our Data Protection Officer at [email protected]. We will verify your identity and respond within 14 days. There is no charge for a reasonable request. If you are not satisfied with our response, you may lodge a complaint with the UAE Data Office.

Cookies & Tracking Technologies

Our website uses cookies to:

  • Remember your preferences and settings
  • Analyze site traffic and usage patterns
  • Improve user experience

You can disable cookies through your browser settings, though this may limit certain website functionality.

Sub-processors

We run most of our systems — our CRM, scheduling, e-signature, mail server, analytics, and project management — on our own self-hosted infrastructure, so your data is not handed to third parties for those functions. Where we do rely on an external processor, it is limited to:

  • Brevo (Sendinblue SAS, EU/France) — reliable delivery of transactional and opt-in marketing email.
  • Cloudflare, Inc. (USA/global) — DNS, content delivery, and secure access protection for our site.
  • Anthropic PBC (USA) — AI-assisted drafting of proposals; only the scope details of an engagement are sent, processed transiently, and not used to train models.

Each sub-processor is bound by a data-processing agreement to protect your data and use it only for the specified purpose. We maintain an internal Record of Processing Activities documenting every data flow.

Data Retention

We retain personal information only as long as necessary:

  • Active client data: Duration of engagement plus 7 years (for audit/legal purposes)
  • Marketing contacts: Until you opt out or request deletion
  • Security findings: Per contractual agreement and compliance requirements

International Data Transfers

Some of our sub-processors are located outside the UAE — specifically Brevo (EU/France), and Cloudflare and Anthropic (USA). Where personal data is transferred abroad, the PDPL permits this to jurisdictions with adequate protection or under specified safeguards. We rely on:

  • Standard contractual clauses and data-processing agreements with each sub-processor
  • Transfers limited to the minimum data necessary for the service
  • Your explicit consent where the law requires it

Data Breach Notification

In the event of a personal-data breach likely to affect your rights, we will notify the UAE Data Office and, where required, affected individuals within the timelines set by the PDPL and its Executive Regulations. We maintain a documented breach-response process for this purpose.

Changes to This Policy

We may update this Privacy Policy periodically. Changes will be posted on this page with an updated "Last Updated" date. For material changes, we will notify active clients directly.

Contact Us

If you have questions about this Privacy Policy or how we handle your data, or to reach our Data Protection Officer:

Data-subject requests: [email protected]

Data Protection Officer: [email protected]