This Privacy Policy explains how Cairn Consulting collects, uses, discloses, stores and protects personal data when you visit www.cairnconsulting.ae, contact us, subscribe to updates, interact with Cairn Agency or submit a Cairn Academy registration or inquiry.
Cairn Consulting is the controller of personal data processed for the purposes described in this Policy, unless another notice or agreement states otherwise. In some projects, training programmes or partner activities, Cairn may act jointly with or on behalf of another organization. If that materially affects how your data is handled, additional information will be provided at the appropriate time.
Privacy contact: info@cairnconsulting.ae. Postal address: Cairn Consulting, Al Reem Island, Tamouh Tower, Level 10, Office 1001, Abu Dhabi, United Arab Emirates. Telephone: +971 2 583 7900.
This Policy applies to personal data collected through the Website and related communications that follow directly from a Website submission. It does not replace privacy terms contained in a client contract, employee notice, recruitment process, production release, supplier arrangement, training enrolment agreement or another specific activity. A more specific notice prevails for that activity to the extent of any inconsistency.
Depending on how you use the Website, we may collect:
When you use the Website, Cairn and its technology providers may automatically collect:
1. IP address and approximate location derived from it;
2. browser, operating system, device type and screen resolution;
3. pages viewed, date and time, time spent, navigation events and session identifiers;
4. referring page and campaign parameters such as UTM source, medium, campaign, term and content;
5. cookie identifiers, consent choices and similar technical information;
6. security, diagnostic, error, fraud-prevention and anti-spam information; and
7. interaction with embedded or linked features where the relevant third party receives data.
The Website currently uses own platform statistics and Google Analytics. More detail appears in the Cookie Policy.
We may receive personal data from a person or organization that refers you, a Cairn group company, a client or prospective client, an event or training partner, a certification body, a production partner, a public source, or a provider that supports Website analytics, security or communications. We will process such data only where there is an appropriate purpose and legal basis.
We may use personal data to:
1. operate, secure, maintain, troubleshoot and improve the Website;
2. receive, assess and respond to inquiries and requests for information;
3. understand project or service requirements and take steps requested before a possible contract;
4. administer Cairn Agency inquiries and coordinate with relevant production or creative partners;
5. assess Cairn Academy registrations, contact applicants, determine course fit, manage waiting lists and prepare enrolment or access;
6. coordinate course delivery, assessment, certification and related administration with authorized training or certification partners where applicable;
7. send newsletters and marketing communications where permitted and manage opt-outs;
8. measure Website usage, content performance and campaign effectiveness;
9. protect Cairn, visitors, clients and systems against misuse, security threats, fraud and spam;
10. maintain business, consent, audit and legal records;
11. comply with law, regulation, court orders, professional obligations and lawful authority requests; and
12. establish, exercise or defend legal claims and enforce Website terms.
Depending on the circumstances and applicable law, we rely on one or more of the following grounds:
1. your consent, including for optional cookies or marketing where consent is required;
2. steps taken at your request before entering a contract, or performance of a contract with you;
3. our legitimate interests or those of another party, such as responding to business inquiries, operating a secure Website, understanding service demand and developing our business, provided those interests are not overridden by your rights;
4. compliance with legal or regulatory obligations;
5. protection of rights, safety or important interests where recognized by law; and
6. establishment, exercise or defence of legal claims or another basis permitted under applicable data-protection law.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing lawfully carried out before withdrawal and may not require deletion where another lawful basis or retention obligation applies.
We may send news, insights, event information, course updates or service communications if you have requested them or where otherwise permitted by law. You can unsubscribe using the link in a message, if available, or by emailing info@cairnconsulting.ae. We may retain minimal suppression information so that we can respect an opt-out. Transactional or service messages are not marketing and may continue where necessary.
We use cookies and similar technologies for operation, security, preferences and analytics. Where required, optional cookies will be used in accordance with the choices presented through our cookie controls. You may change browser settings or use the Website’s Cookie Settings feature when available. Blocking some technologies may affect functionality. See the Cookie Policy for details.
We do not sell personal data. We may disclose it, only as reasonably necessary, to:
1. Cairn affiliates, divisions and authorized personnel involved in the relevant request;
2. Hosting provider, content delivery, Website forms, database, email, IT support, security, analytics and anti-spam services;
3. Google in connection with Google Analytics and any anti-spam or related Google service that is activated;
4. training, course-delivery, assessment, certification, venue, technology and payment providers where needed for an Academy request or enrolment;
5. creative, production and media partners where needed to assess or perform a Cairn Agency request;
6. professional advisers, auditors, insurers, banks and consultants bound by appropriate duties;
7. a purchaser, investor, successor or adviser in connection with a genuine corporate transaction, subject to confidentiality and lawful safeguards;
8. courts, regulators, law-enforcement bodies and public authorities where disclosure is required or legally justified; and
9. another person where you direct us or provide valid consent.
Providers must process data under appropriate instructions, contractual duties or their own disclosed responsibilities, as applicable. A third party acting as an independent controller is responsible for its own privacy notice and compliance.
Cairn operates internationally and uses service providers and partners that may process personal data outside the United Arab Emirates. Those destinations may have different data-protection laws. Where applicable law requires it, we use a legally recognized transfer mechanism, contractual and organizational safeguards, an adequacy basis, consent or another permitted exception. You may contact us for further information about safeguards relevant to your data, subject to confidentiality and legal restrictions.
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to respond to an inquiry, administer an application or service, maintain an appropriate business record, comply with law, resolve disputes and establish or defend claims. Retention periods vary according to:
1. the nature and sensitivity of the data;
2.the status and duration of an inquiry, application, subscription, project or relationship;
3. contractual, professional, tax, accounting, certification and regulatory requirements;
4. applicable limitation periods and foreseeable disputes;
5. security, fraud-prevention and audit needs; and
6. the settings and lawful retention periods of relevant technology providers.
When data is no longer required, we delete, anonymize or securely isolate it, subject to backup cycles and legal holds. Anonymized information that no longer identifies a person may be retained for analysis and planning.
We apply reasonable technical, organizational and administrative measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, misuse or destruction. Measures may include access controls, service-provider review, secure configurations, backups, staff confidentiality, incident management and data minimization. No online system is completely secure, and we cannot guarantee absolute security. If you believe information submitted to Cairn has been compromised, contact info@cairnconsulting.ae promptly. Do not send passwords or sensitive identity documents by ordinary email.
Subject to applicable law, conditions and exemptions, you may have the right to:
1. obtain information about our processing and request access to personal data we hold about you;
2. request correction or completion of inaccurate or incomplete data;
3. request deletion of data in circumstances recognised by law;
4. request restriction or suspension of processing in applicable circumstances;
5. object to certain processing, including direct marketing;
6. withdraw consent where processing is based on consent;
7. request transfer or receipt of data in a structured and machine-readable format where applicable;
8. object to decisions based solely on automated processing, including profiling, where the legal conditions apply; and
9. submit a complaint to the competent data-protection authority or seek another remedy available by law.
To exercise a right, email info@cairnconsulting.ae with the subject “Privacy Request”. Describe your request and the Website interaction concerned. We may ask for proportionate information to verify identity and authority. We will respond within the period required by applicable law. A request may be limited or refused where permitted by law, including to protect another person’s rights, confidentiality, legal privilege, security or legal claims; we will explain the basis where required.
Cairn does not currently intend to make Website-related decisions that produce legal or similarly significant effects based solely on automated processing. If this changes, we will provide appropriate information and safeguards as required by law.
The general Website is directed to organizations, professionals and adults. Cairn does not knowingly solicit personal data through the Website from children under 18 without an appropriate lawful process. Academy opportunities are ordinarily intended for university students, graduates and working-age participants. If an applicant is under 18, the applicant should not submit the form unless Cairn has confirmed eligibility and any required parent or guardian involvement. If we learn that a child’s data was collected improperly, we will take reasonable steps to delete or lawfully regularize it.
Website forms are not intended for health data, biometric data, identity-document copies, precise security credentials, financial-account information, classified information, criminal records or other highly sensitive material. Please do not include such information unless Cairn expressly requests it through an appropriate secure and lawful process. Describing your status as transitioning from military service should not include rank, deployment, clearance, operational or security-sensitive details.
Links to LinkedIn, media platforms, clients, partners and other external sites take you to services controlled by third parties. Their privacy policies and cookie practices apply. Cairn is not responsible for their processing, security or content.
We may update this Policy when our activities, providers, Website features or legal obligations change. The latest version will be posted on the Website with its revision date. Material changes may also be highlighted where appropriate. Please review the Policy periodically.
Questions, requests or complaints may be sent to info@cairnconsulting.ae or delivered to Cairn Consulting, Al Reem Island, Tamouh Tower, Level 10, Office 1001, Abu Dhabi, United Arab Emirates. Please mark correspondence “Privacy”. You may also contact the competent UAE data-protection authority where you have the right to do so.