Skip to content
Skip to main content
GOLIATHTECHNOLOGY
Legal

Privacy Policy

Draft — this document is a working draft pending review by legal counsel. Do not rely on it as legal advice.

Last updated · 2 June 2026

Last updated: 2 June 2026 Controller: Goliath Technology Ltd, Unit IH-00-01-01-OF-01, Level 1, Building IH-00-01-CP-05, Dubai International Financial Centre, Dubai, UAE.

1. About this notice

This notice explains how Goliath Technology Ltd ("Goliath", "we") collects and uses personal data when you visit goliath.technology or contact us through the site. It is written with regard to the DIFC Data Protection Law 2020, the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), and the EU/UK GDPR, as applicable to the person whose data we hold.

For any privacy enquiry, contact narish.nathan@goliathtech.io.

2. What data we collect

We collect only what we need to respond to enquiries and to run a secure website.

When you submit the contact form:

  • Name
  • Company / organisation
  • Email address
  • Phone number (optional)
  • The contents of your message
  • Date and time of submission

When you browse the site without contacting us:

  • Anonymous, first-party analytics only: which pages are viewed and a temporary session identifier that is erased when you close your browser tab.

We do not collect your IP address, device fingerprint, browser profile, or any cross-session identifier. We do not use cookies for tracking, and we do not use third-party analytics (see our Cookie Notice). We do not collect sensitive categories of data through this site; if you choose to disclose such information in a free-text message, we minimise its retention.

3. Why we use it — and on what lawful basis

PurposeLawful basis
Responding to your enquiry and exploring a possible engagementLegitimate interest, and steps prior to entering a contract
Keeping the site secure and preventing abuseLegitimate interest
Aggregate, anonymous site analyticsLegitimate interest
Complying with legal obligationsLegal obligation

We do not sell personal data. We do not use your data to train AI models.

4. Who we share data with

We share personal data only with:

  • Our hosting/backend provider, acting on our behalf under contract, which stores your enquiry so we can read and respond to it.
  • Regulators, courts, or law enforcement, where legally required and only to the extent required.
  • Professional advisors (legal, accounting) on a need-to-know basis.

We do not sell, rent, or trade personal data with anyone.

5. Cross-border transfers

Goliath operates from the DIFC, Dubai. Some processors may be located outside the UAE (for example in the EEA, UK, or US). Where we transfer personal data outside the UAE, we rely on adequacy decisions where available, and otherwise on Standard Contractual Clauses or other safeguards permitted under applicable law. You can request details of the mechanism that applies to your data by writing to narish.nathan@goliathtech.io.

6. How long we keep it

CategoryRetention
Enquiry messages from the contact formUp to 24 months from last contact, then deleted or anonymised
Contractual records (where an engagement begins)7 years (DIFC commercial record-keeping)

Anonymous, aggregated analytics may be retained indefinitely, as they no longer constitute personal data.

7. Your rights

Wherever you are, you have the right to: access the data we hold about you; correct inaccurate data; delete data we no longer need; restrict or object to processing based on legitimate interest; withdraw consent; and receive your data in a portable format.

Depending on your jurisdiction, you may also lodge a complaint with the DIFC Commissioner of Data Protection, the UAE Data Office, your EU supervisory authority, or the UK ICO.

To exercise any right, write to narish.nathan@goliathtech.io. We respond within 30 days, extendable by a further period for complex requests, in which case we will tell you the reason.

8. Security

We use appropriate technical controls — TLS encryption in transit, encrypted storage, least-privilege access enforced at the database level, multi-factor authentication on administrative access, and access logging. No system is perfectly secure, but we hold ourselves to the standard appropriate for a B2B consultancy. If we become aware of a personal data breach likely to put your rights at risk, we will notify the relevant authority and affected people in accordance with applicable law.

9. Children

The site is not directed to anyone under 16, and we do not knowingly collect their data. If you believe we have, contact narish.nathan@goliathtech.io and we will delete it.

10. Changes to this notice

We will update this notice when our practices change. The "Last updated" date reflects the latest version; where a change is material, we will inform people who have previously contacted us.

11. Contact

Goliath Technology Ltd Unit IH-00-01-01-OF-01, Level 1, Building IH-00-01-CP-05, Dubai International Financial Centre, Dubai, UAE narish.nathan@goliathtech.io