Effective Date: July 2026
How we collect, use, and protect your personal data.
Questions, requests, or complaints regarding personal data should be directed to:
STERLING AXIS - FZCO — Privacy Matters
Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, UAE
info@sterlingaxis.onlineAs a company established outside the European Union, we will designate an EU representative under Article 27 GDPR where that obligation is triggered by the nature and scale of our processing, and this Policy will be updated with their details. Until then, all matters may be raised with us directly at the address above.
1.1. This Privacy Policy describes how STERLING AXIS - FZCO, a free zone company licensed by the Dubai Integrated Economic Zones Authority under Commercial License No. 86372, with registered address at Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, UAE ("Sterling Axis", the "Studio", "we", or "us"), handles personal data belonging to visitors of our website, prospective and existing clients, their representatives, and other individuals who interact with us.
1.2. We process personal data in line with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the UK GDPR where they apply to our activities, as well as UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("PDPL").
1.3. Depending on the context, our role differs:
(a) for data gathered through our website, enquiries, marketing, and the administration of client relationships, Sterling Axis determines the purposes and means of processing and acts as controller;
(b) for data we handle inside a client's ecosystem while delivering social media management, marketing strategy, or consulting services — for example follower data, lead records, CRM exports, or campaign audiences — we act as processor on the client's behalf, and Section 11 of this Policy applies.
3.1. Information you give us. When you fill in our contact form, email us, book a call, or become a client, we may receive your name, business email address, phone number, company name and role, the content of your message, project goals, budget indications, and — for clients — billing and contractual details such as invoicing address and tax identifiers.
3.2. Information collected automatically. When you browse our website, our systems and cookie technologies may record your IP address, approximate location derived from it, device and browser characteristics, the pages you view, how you arrived at the site, and how you move through it. See Section 10 for cookie details.
3.3. Information from other sources. We may enrich our records with publicly available professional data (for example company websites or LinkedIn profiles), information shared by referral partners, and interaction data supplied by social and advertising platforms when you engage with our profiles or campaigns.
3.4. We do not seek to collect sensitive data (such as health information, religious or political views) or data about minors under 16, and we ask that you do not submit any. If we discover such data has been provided inadvertently, we will delete it.
4.1. Under Article 6 GDPR, every processing activity we carry out rests on one of the following grounds:
(a) Steps prior to a contract and contract performance — handling your enquiry, preparing proposals, delivering the Services, managing the client relationship, and providing support (Art. 6(1)(b));
(b) Legal obligations — issuing invoices, maintaining accounting and tax records, and responding to lawful requests from authorities (Art. 6(1)(c));
(c) Consent — sending newsletters or promotional messages to non-clients, and placing analytics and advertising cookies (Art. 6(1)(a)); consent can be withdrawn at any time with future effect;
(d) Legitimate interests — securing our website and systems, preventing fraud and abuse, improving our services, sending relevant business communications to existing clients about similar services (with an opt-out in every message), managing our portfolio and business development, and establishing or defending legal claims (Art. 6(1)(f)). For each such activity we have assessed that our interest is not overridden by your rights and freedoms, and you may object as described in Section 8.
4.2. We do not use personal data for automated decision-making that produces legal or similarly significant effects on individuals.
5.1. Access to personal data within Sterling Axis is limited to team members who need it for their role. Beyond that, data may be shared with:
(a) technology suppliers acting under our instructions — website hosting, email and productivity suites, CRM and project tools, scheduling and analytics software, and payment providers — each bound by contracts meeting Article 28 GDPR requirements;
(b) social media and advertising platforms (for example Meta, Google, TikTok, LinkedIn) when you consent to marketing cookies or interact with our content; these operators process data under their own privacy notices as separate controllers;
(c) accountants, auditors, legal counsel, and insurers, to the extent needed for professional advice and compliance;
(d) courts, regulators, and public bodies, where disclosure is legally required; and
(e) a successor entity, in the event of a corporate reorganisation, merger, or sale, under confidentiality protections.
5.2. We never sell personal data, and we never share it with third parties for their own independent marketing.
6.1. Sterling Axis operates from the United Arab Emirates, so personal data of individuals in the EEA or UK is by definition transferred to a third country when they deal with us. Some of our suppliers are also located outside the EEA.
6.2. For transfers subject to Chapter V GDPR, we rely on adequacy decisions where available, and otherwise on the European Commission's Standard Contractual Clauses (and the UK Addendum or IDTA where UK data is involved), reinforced by supplementary safeguards such as encryption and access restrictions where a transfer risk assessment indicates the need.
6.3. Details of the safeguards applied to a specific transfer can be obtained by writing to info@sterlingaxis.online.
7.1. We keep personal data no longer than the purpose requires, applying the following standard periods unless a longer statutory retention or an active legal matter demands otherwise:
(a) prospect enquiries that do not lead to a contract — deleted within 24 months of the last meaningful contact;
(b) client files, contracts, and correspondence — kept for the life of the relationship and for up to 10 years after its end, reflecting UAE commercial record-keeping duties and limitation periods;
(c) marketing consents and subscriber lists — until consent is withdrawn or after 24 months without engagement;
(d) website and analytics logs — up to 26 months;
(e) financial and tax records — as mandated by UAE law.
7.2. At the end of the applicable period, data is erased or anonymised so it can no longer be linked to you.
8.1. Where the GDPR applies to you, you can at any time:
(a) ask for access to the personal data we hold about you and receive a copy (Art. 15);
(b) have inaccurate data corrected and incomplete data completed (Art. 16);
(c) request erasure where the legal conditions are met (Art. 17);
(d) obtain restriction of processing in the situations set out in Art. 18;
(e) receive data you provided to us in a portable, machine-readable format and have it transmitted to another controller where technically feasible (Art. 20);
(f) object to processing based on legitimate interests on grounds relating to your particular situation — and object to direct marketing unconditionally, at any time (Art. 21); and
(g) withdraw any consent previously given, without affecting the lawfulness of prior processing (Art. 7(3)).
8.2. Requests should be sent to info@sterlingaxis.online. We answer within one month; for complex or multiple requests this may be extended by up to two further months, in which case we will tell you why. We may ask for information to verify your identity. No fee applies unless a request is manifestly unfounded or excessive.
8.3. You also have the right to complain to a data protection supervisory authority, in particular in the EU/EEA country where you live or work or where an alleged infringement occurred, or to the UK Information Commissioner's Office if the UK GDPR applies. We would welcome the chance to resolve your concern directly first.
9.1. We apply technical and organisational safeguards proportionate to the risk, including encrypted connections (TLS), access on a need-to-know basis, strong authentication on business systems, vetted suppliers, and confidentiality commitments from everyone working with us.
9.2. If a personal data breach occurs that is likely to put your rights and freedoms at risk, we will notify the competent supervisory authority within 72 hours of becoming aware, as required by Article 33 GDPR, and will inform affected individuals directly where the risk is high (Article 34 GDPR).
10.1. Our website uses three groups of cookies and comparable technologies:
(a) essential cookies, needed for the site to work and exempt from consent;
(b) measurement cookies, which help us understand how visitors use the site — set only if you agree;
(c) advertising cookies and pixels from platforms such as Meta, Google, TikTok, and LinkedIn, used to build audiences and measure campaigns — set only if you agree.
10.2. A consent banner is shown on your first visit, where you can accept everything, reject everything non-essential, or configure each category. Your choices can be revisited at any time through the cookie settings link on the site or via your browser. Blocking cookies does not stop you from using the website, though some features may behave differently.
11.1. In delivering the Services, we frequently work inside data environments that belong to our clients — community and follower data, lead and enquiry records, customer lists used for campaign audiences, and analytics tied to the client's own channels. For all such data, the client is the controller and Sterling Axis is a processor.
11.2. This processing is governed by a data processing agreement concluded with the client in accordance with Article 28 GDPR: we act only on documented instructions, keep the data confidential and secure, involve sub-processors only under equivalent obligations, support the client in handling data subject requests and breach duties, and delete or hand back the data when the engagement closes.
11.3. If you believe Sterling Axis holds your data on behalf of one of our clients, the fastest route is to contact that client, whose own privacy notice applies. Should you contact us instead, we will pass your request to the relevant controller without undue delay.
Our website and content may link to external sites, platforms, and services that we do not operate. Their data practices are their own, and this Policy does not cover them. Please review the privacy notices of any external destination you visit.
We review this Policy periodically and may revise it to reflect changes in our activities, technology, or the law. The current version, with its effective date, is always published on our website, and significant changes will be flagged where legally required.
STERLING AXIS - FZCO
Commercial License No. 86372
Building A1, Dubai Digital Park, Dubai Silicon Oasis
Dubai, United Arab Emirates
info@sterlingaxis.onlineWe use cookies to improve your experience. Essential cookies are always active. You can choose which optional cookies to allow. Learn more in our Privacy Policy.