Privacy Policy

DC Technologies LLC (“DC Technologies,” “DCTech,” “we,” “us,” or “our”) provides managed infrastructure and managed security servicesincluding MDR, SOC as a Service, VA & Penetration Testing, Sangfor HCI/VDI, Backup & Disaster Recovery, ImmuneFiles, and Xyra XDR — to businesses across the United Arab Emirates. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website dctechnologies.ae (the “Site”), request a consultation, or engage us for our services. It is intended to comply with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, “PDPL”) and applicable regulations.

1. Information We Collect

Information you provide to us directly, such as when you:

  • Submit a “Talk to Our Team” or contact form request
  • Request a consultation, demo, or quote for our services
  • Communicate with us by email or phone
  • Engage us as a client for managed security or infrastructure services

This may include your name, business email address, phone number, company name, job title, industry, and details about your infrastructure or security requirements.

Information collected automatically when you browse the Site:

  • IP address, browser type, device type, and operating system
  • Pages visited, referring/exit pages, and general usage patterns
  • Cookies and similar tracking technologies (see Section 5)

Client and service-delivery data, where we act as a service provider. If you engage us for MDR, SOC as a Service, VAPT, Xyra XDR, or related services, we may process security telemetry, log data, network data, or other technical data from your environment on your behalf, strictly for the purpose of delivering the contracted service. In these cases, we act as a “data processor” (or equivalent role under PDPL) and process such data according to your instructions and our service agreement this data is not used for our own independent purposes.

Information from third parties, such as technology or channel partners (e.g., Sangfor, CrowdStrike, Sophos, SentinelOne) where relevant to delivering integrated services, and analytics providers.

2. How We Use Your Information

We use the information we collect to:

  • Respond to enquiries and schedule consultations
  • Assess your infrastructure or security needs and prepare proposals
  • Deliver, monitor, and support the services you have engaged us for
  • Maintain and improve our Site and service offerings
  • Communicate with you about your account, engagement, or support requests
  • Send updates, insights, or marketing communications (you may opt out at any time)
  • Comply with legal, regulatory, and contractual obligations
  • Detect, investigate, and prevent fraud, misuse, or security incidents

We do not sell your personal information.

3. How We Share Your Information

We may share your information with:

  • Subcontractors and technology partners who support service delivery (e.g., infrastructure hosting, security tooling vendors, communication platforms), bound by confidentiality and data protection obligations
  • Professional advisors (legal, audit, insurance) where necessary
  • Regulatory or governmental authorities, where required by UAE law or a valid legal process
  • Business transferees, in the event of a merger, acquisition, restructuring, or sale of assets

Where we process client environment data (telemetry, logs, security events) as part of MDR, SOC, or Xyra XDR services, this data is handled under the terms of the applicable service agreement and is not shared beyond what is necessary to deliver the service, escalate incidents, or as instructed by the client.

4. Data Residency and Cross-Border Transfers

Client security telemetry, event data, and logs processed through Xyra XDR and related managed security services are stored and processed on UAE-resident infrastructure. For other data, where information is transferred outside the UAE (for example, to a service provider located abroad), we take reasonable steps to ensure an adequate level of protection consistent with PDPL requirements, including through contractual safeguards.

5. Cookies and Tracking Technologies

Our Site may use cookies and similar technologies to remember preferences, understand how visitors use the Site (via analytics tools), and improve Site performance. You can manage or disable cookies through your browser settings; doing so may affect certain Site features.

Our Site may use cookies and similar technologies to remember preferences, understand how visitors use the Site (via analytics tools), and improve Site performance. You can manage or disable cookies through your browser settings; doing so may affect certain Site features.

6. Data Security

We maintain administrative, technical, and organizational safeguards designed to protect personal information and client environment data against unauthorized access, disclosure, alteration, or destruction. Given the nature of our business, we apply security controls consistent with the standards we help our clients meet (e.g., access controls, monitoring, encryption where appropriate). No system is completely secure, and we cannot guarantee absolute protection.

In the event of a personal data breach affecting your information, we will notify affected parties and, where required, the UAE Data Office, within the timeframes mandated by PDPL (currently within 72 hours of becoming aware, where feasible).

7. Data Retention

We retain personal information for as long as necessary to fulfill the purposes described in this policy, including maintaining business records, honoring service agreements, meeting regulatory retention requirements (including those specific to regulated sectors such as healthcare and BFSI), and resolving disputes. Client environment data processed under a service agreement is retained and disposed of according to the terms of that agreement.

8. Your Rights

Subject to PDPL and applicable law, you may have the right to:

  • Request access to the personal information we hold about you
  • Request correction of inaccurate or incomplete information
  • Request deletion of your personal information, subject to legal or contractual retention obligations
  • Withdraw consent to marketing communications at any time
  • Object to or request restriction of certain processing activities
  • Request that we transfer certain data to another provider, where applicable

To exercise these rights, contact us using the details in Section 11. We may need to verify your identity before fulfilling a request.

9. Sector-Specific Considerations

We work with clients in regulated industries such as healthcare, BFSI/fintech, real estate, and hospitality. Where our services touch data governed by sector-specific frameworks (e.g., ADHICS V2, NABIDH, or other regulatory requirements), we process such data strictly in accordance with the applicable client agreement, PDPL, and any relevant sector-specific rules. This Privacy Policy governs our handling of your personal information as a website visitor or prospective/existing client contact; it does not override obligations set out in a specific client services agreement.

10. Third-Party Links

Our Site may link to third-party websites, including partner products such as Xyra XDR (xyraxdr.com) or vendor sites. We are not responsible for the privacy practices of these third parties and encourage you to review their respective privacy policies.

11. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us at:

DC Technologies LLC Dubai, United Arab Emirates

Email: info@dctechnologies.ae

12. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, services, or legal requirements. The “Last updated” date above reflects the most recent revision. We encourage you to review this policy periodically.