Privacy Policy — Rootsec
Last updated: June 2026 · Trade Licence No.: [to be added]
At Rootsec, we take your privacy seriously. We process personal data in a safe, careful and transparent manner, in accordance with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, “PDPL”). This privacy statement explains what data we collect, why, and what your rights are.
In short — your privacy at Rootsec
- We only collect personal data necessary for our services.
- We do not use tracking cookies without your consent.
- You always have the right to access, correct or delete your data.
- We never share your data with third parties without a valid reason.
Contact: [email protected]
1. Who are we?
This privacy policy applies to the website https://www.rootsec.ae, managed by Rootsec (UAE trade licence no. [to be added]), located at Office 159, Ground Floor, Exchange Tower, Business Bay, Dubai, UAE.
2. What personal data do we process?
We only collect personal data that you provide directly via our contact form or email. This may include:
- Name and contact details
- Company information
- Any other information you voluntarily share with us
We use this data to: contact you · provide services or process your requests · maintain our relationship with you as a client.
3. Cookies
Our website only uses functional cookies (to make the website work) and anonymous analytical cookies (e.g. via Google Analytics). We do not use tracking cookies without your explicit consent.
4. Your rights
Under the UAE PDPL, you have the right to access, correct or delete your personal data, restrict or object to certain processing, request data portability, and withdraw consent at any time.
To exercise any of these rights, email [email protected] with your request and, where needed to verify your identity, a secure copy of your Emirates ID / passport (please obscure sensitive fields). We will respond within the period required by the PDPL.
5. Security & retention
Rootsec takes appropriate technical and organisational measures to protect your data against loss or unauthorised use. We do not retain your data longer than legally required or necessary for the purpose for which it was collected.
6. Sharing data with third parties
We only share your personal data when legally required (e.g. on request from a competent UAE authority), or with parties that assist us in our services under strict agreements to protect your privacy.
7. Your responsibility
While visiting our website, you may not collect or use the personal data of others. If you encounter such data, please notify us immediately and refrain from using it.
8. Intellectual property
All text, images and other content on this website are protected by copyright. You may not copy or reuse them without written permission from Rootsec.
9. Questions or complaints?
For questions about this privacy policy, contact Emil Pilecki — [email protected]. If you have complaints about how we handle your personal data, you may also contact the UAE Data Office (the federal data protection authority under the PDPL).
10. Processing personal data during our services
Beyond data collected via our website, Rootsec also processes personal data as part of its services to clients — for example when conducting penetration tests and security assessments, monitoring networks, systems and endpoints (e.g. via Cynet), or supporting incident response and forensic investigations. In these cases, Rootsec acts as a data processor on behalf of the client (the data controller). We process such data only on the client’s written instructions and strictly for the agreed purposes.
Data Processing Agreement
For each service involving personal data, we enter into a Data Processing Agreement (DPA) consistent with the UAE PDPL’s controller–processor requirements.
Sub-processors and data storage
If Rootsec engages sub-processors (e.g. for cloud hosting or monitoring), we ensure they also meet PDPL requirements. Where personal data is transferred outside the UAE, we ensure an appropriate legal basis and safeguards for cross-border transfer as required by the PDPL and its executive regulations.
Security and confidentiality
Rootsec applies appropriate technical and organisational measures to protect personal data against loss, unauthorised access or unlawful processing — including access logging and monitoring, need-to-know access control, encryption where appropriate, and strict confidentiality agreements for all employees and partners.