Privacy Notice — United Arab Emirates

How we collect, use and protect personal data

19 September 2026

1. About this notice

This notice explains how Sterling Hunter Accountancy and Professional Services - FZCO, trading as Sterling & Hunter, collects, uses, shares and protects personal data. It applies to our clients, to the people connected with our clients, and to anyone else whose personal data we hold in connection with our services.

It sits alongside your Letter of Engagement and our Terms of Business at Appendix C. Clause 13 of those terms points you to this notice. Where we act on your behalf in a way that makes you the controller of the personal data and us your processor, our Data Processing Terms apply as well.

This notice is issued under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and the requirements that apply to us in the United Arab Emirates.

2. Who we are

Sterling Hunter Accountancy and Professional Services - FZCO, trading as Sterling & Hunter, is a free zone company licensed by the Dubai Integrated Economic Zones Authority (IFZA) under trade licence number 92269, with its registered address at IFZA Business Park, DDP, PO Box 342001, Dubai, United Arab Emirates. Our licence address is DSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai.

We are the controller of the personal data described in this notice, except where we are processing it on your instructions as your processor.

If you have a question about this notice or about how we handle personal data, contact us at info@sterlingandhunter.com.

3. The personal data we collect

The personal data we hold depends on the services you have engaged us for. It will usually include some or all of the following.

  • Identity and contact details, including name, date of birth, nationality, passport and Emirates ID details, photographs, residential and business addresses, telephone numbers and email addresses.
  • Client due diligence information, including proof of identity and address, source of funds and source of wealth information, ownership and control information, and the results of sanctions, politically exposed person and adverse media screening.
  • Financial and business information, including bank details, accounting records, transaction data, invoices, contracts, payroll information, shareholdings, loans and drawings.
  • Tax information, including tax registration numbers, filings, computations, correspondence with tax authorities, residence and days of presence information, and details of income and assets.
  • Corporate and licensing information, including company documents, licence details, visa and immigration status, establishment card details and authority correspondence.
  • Correspondence and records of our dealings with you, including emails, messages, meeting notes, call records and file notes.

Some of this is sensitive by nature, particularly identity documents and financial information. Where we collect medical information as part of a visa application, we handle it only for that purpose and only for as long as the application requires.

4. Where we get personal data from

  • From you directly, when you instruct us, complete our onboarding, or send us records and information.
  • From people connected with you, such as your directors, shareholders, employees, family members or other advisers.
  • From public and official sources, including company registries, free zone authorities, tax authority portals, sanctions lists and public records.
  • From screening and verification providers we use to meet our anti-money laundering obligations.

Where you give us personal data about other people, you confirm that you are entitled to do so and that those people have been given the information they are entitled to receive about how their data will be used. It helps if you pass this notice on to them.

5. Why we use personal data and on what basis

We use personal data for the following purposes.

  • To provide the services set out in your engagement, including accounting, tax, corporate, licensing and visa work. We do this because it is necessary to perform our contract with you or to take steps at your request before entering into it.
  • To meet our own legal and regulatory obligations, including anti-money laundering, counter-terrorist financing, sanctions, tax and record-keeping requirements. We do this because the law requires it of us.
  • To manage our relationship with you, including billing, collecting fees, keeping our records accurate and dealing with queries and complaints.
  • To protect our position, including establishing, exercising or defending legal claims, responding to authorities, and meeting our professional indemnity insurance obligations.
  • To run and improve our business, including quality reviews, training, security, and the technology described in section 7.
  • To send you information about our services, where you have asked for it or where you are an existing client and we think it is relevant to you. You can ask us to stop at any time.

Where we rely on your consent for a particular use, you can withdraw it at any time. Withdrawing consent does not affect anything we did before you withdrew it, and it does not affect processing we carry out on another basis, such as a legal obligation.

6. Who we share personal data with

We do not sell personal data. We share it only where it is necessary, and only with the following.

  • Government and regulatory bodies, including the Federal Tax Authority, free zone authorities, immigration and labour authorities, and any authority we are legally required to report to.
  • Banks, payment providers and typing centres, where this is part of the work you have asked us to do.
  • Auditors, lawyers and other professional advisers, where you have asked us to work with them or where we need advice ourselves.
  • Subcontractors and other accounting or tax professionals to whom we subcontract work. Each is bound by our confidentiality and security terms, as clause 12 of our Terms of Business explains.
  • Technology and service providers, including cloud accounting, document management, communications, automation, screening and artificial intelligence providers.
  • Our insurers and professional indemnity insurers, and their advisers.
  • A buyer or successor, if we sell or reorganise our business, subject to appropriate confidentiality protections.

Our current technology and service providers are set out below. We keep this list under review and will update this notice when it changes.

  • Cloud accounting and bookkeeping:Xero, Wafeq.
  • Document management and file storage:Microsoft 365 (SharePoint and OneDrive).
  • Email, calendar and communications:Microsoft 365 (Outlook and Teams).
  • Meeting recording and transcription:Fathom.
  • Artificial intelligence and automation:Anthropic (Claude).
  • Design and marketing:Canva.
  • Client due diligence and screening:XAMA.
  • Subcontracted accounting and tax professionals:MPS Accountancy, United Kingdom.

We may also disclose personal data where the law, a regulator, a court or a professional obligation requires it. In some cases we are not permitted to tell you that we have done so, and clause 14 of our Terms of Business explains that we may also have to stop work without explanation while a report is considered.

7. Technology, automation and artificial intelligence

We use artificial intelligence, machine learning, automation, document processing, data analytics and cloud software to deliver our services. This is described in clause 11 of our Terms of Business, and it includes document and data extraction, bookkeeping and reconciliation, research assistance, preparation of working papers and drafts, screening, and workflow automation.

The output of these tools is reviewed by us. We do not make decisions about you by automated means alone where that decision would have a legal effect on you or a similarly significant effect.

We select providers that offer appropriate security and confidentiality terms, and we do not permit client data to be used to train publicly available models.

8. Transfers outside the United Arab Emirates

Some of our processing takes place outside the United Arab Emirates, because we work across the United Kingdom and the United Arab Emirates and because some of our providers host data in other countries. The countries currently involved are the United Kingdom, Ireland, the Netherlands, the United States and Australia.

Where personal data leaves the United Arab Emirates, we transfer it only where the receiving country is recognised as offering an adequate level of protection, or where we have appropriate contractual protections in place, or where the transfer is necessary to perform our contract with you or for another basis permitted by the Personal Data Protection Law.

9. How long we keep personal data

We keep personal data for as long as we need it for the purpose we collected it for, and then for as long as we are required or permitted to keep it.

  • Corporate Tax records are kept for seven years after the end of the relevant tax period.
  • VAT records are kept for at least five years, and longer where the law requires it for particular assets.
  • Client due diligence records are kept for at least five years after the end of our business relationship with you, as our anti-money laundering obligations require.
  • Engagement files, advice and correspondence are kept for seven years after the engagement ends, so that we can answer queries, meet our professional and insurance obligations and defend claims.

After those periods we delete personal data or put it beyond use. Original documents are returned to you on request. Clause 29 of our Terms of Business sets out the same retention periods and explains that, following termination, we may destroy documents we have been unable to return to you after six months.

10. How we protect personal data

We take reasonable technical and organisational steps to protect personal data against loss, misuse, unauthorised access, disclosure, alteration and destruction. These include access controls, encryption in transit and at rest where available, multi-factor authentication, virus and malware scanning, supplier due diligence, staff confidentiality obligations and training.

No system is completely secure, and email in particular carries a risk of interception and misdirection, as clause 20 of our Terms of Business explains. Tell us if you would prefer us to use a different method for sensitive material.

If a personal data breach occurs, we will act on it promptly, and we will notify the UAE Data Office and any affected individuals where the law requires us to.

11. Your rights

Under the Personal Data Protection Law you have the following rights, subject to the conditions and exceptions in that law.

  • To be told how your personal data is processed, and to ask for a copy of it.
  • To ask us to correct personal data that is inaccurate or incomplete.
  • To ask us to delete your personal data, where we no longer have a reason to keep it.
  • To ask us to restrict or stop processing your personal data in certain circumstances.
  • To receive personal data you gave us in a structured, machine-readable format, and to ask us to transfer it to someone else, where the processing is based on your consent or on our contract with you.
  • To object to decisions made about you by automated processing alone.
  • To withdraw consent, where we rely on your consent.

These rights are not absolute. We may not be able to delete or stop processing personal data where the law requires us to keep it, for example our tax and anti-money laundering record-keeping obligations, or where we need it to establish or defend a legal claim. If we cannot do what you have asked, we will tell you why.

12. How to contact us, and how to complain

To exercise any of your rights, or to ask a question about this notice, contact us at info@sterlingandhunter.com. We will respond within the period the law allows, and we may need to verify your identity before we act.

If you are not satisfied with our response, please tell us, so that we have the chance to put it right. We handle it under clause 27 of our Terms of Business, which means we acknowledge your complaint within five working days and give you a full written response within 30 days, or explain why we need longer. You also have the right to complain to the UAE Data Office.

13. Changes to this notice

We review this notice from time to time. Where we make a material change, we will tell you in writing, and the updated notice will apply from the date stated in that notice. The current version is shown on the front page.

A general note. This notice describes how Sterling & Hunter handles personal data in the United Arab Emirates. Our United Kingdom company, Sterling & Hunter Limited, issues a separate privacy notice under United Kingdom law. Where you take services from both entities, both notices apply to the work each of them does for you.