Data & Compliance
Last updated: August 20, 2026
Read alongside our Privacy Policy and Terms of Use.
Clients trust us with financial information, and prospective clients reasonably want to know how that information is handled before they share any of it. This page sets out how we approach confidentiality, data governance, security and the regulatory framework we work within.
This page describes our own practices. It is not advice. Nothing here should be relied on as guidance on your obligations — those depend on your circumstances and should be considered under a proper engagement.
1. Confidentiality
Client information is treated as confidential. We use it only for the purpose for which it was provided, share it internally only with those who need it for that purpose, and do not disclose it to third parties except where you authorise us to, where a provider processes it on our behalf to deliver our services, or where disclosure is required by law or by a competent authority.
Our confidentiality obligations continue after an engagement ends. Where a legal or regulatory duty requires disclosure, we comply with that duty; in some cases the law prohibits us from telling you that a disclosure has been made, and we cannot act contrary to that.
2. Regulatory Framework
PrimeLedger Consultancy FZCO is a free zone entity registered in Dubai, United Arab Emirates. Our work, and the obligations of the clients we act for, sit within a framework that includes:
| Area | Principal legislation |
|---|---|
| Personal data | Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data |
| Corporate tax | Federal Decree-Law No. 47 of 2022 on the Taxation of Corporations and Businesses |
| Value added tax | Federal Decree-Law No. 8 of 2017, as amended |
| Tax procedures | Federal Decree-Law No. 28 of 2022 on Tax Procedures |
| Anti-money laundering | Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019, under which accountants and auditors fall within the designated non-financial businesses and professions regime |
| Companies | Federal Decree-Law No. 32 of 2021 on Commercial Companies |
| Financial reporting | International Financial Reporting Standards (IFRS), including IFRS for SMEs where applicable |
Free zone entities are treated differently from mainland entities under some of this legislation, and free zones are outside the territorial scope of the federal data protection law, several operating their own regimes instead. We therefore align our data handling with the principles of that law and with comparable international standards, rather than treating any single regime as the whole answer. Where your own position depends on which regime applies, that is a question to settle under an engagement.
3. Client Due Diligence
Where we act in a capacity that brings an engagement within the scope of the UAE's anti-money laundering and counter-terrorist financing framework, we are required to carry out client due diligence before and during that engagement. In practice this means we may need to:
- verify the identity of the client and, for an entity, of its beneficial owners;
- understand the purpose and intended nature of the business relationship;
- establish the source of funds or wealth where the circumstances call for it;
- apply enhanced measures to higher-risk relationships;
- keep the information current through the life of the engagement; and
- maintain records of the checks performed.
We may be unable to accept or continue an engagement where the required information is not provided. The framework also imposes reporting obligations that operate independently of our duty of confidentiality, and which in defined circumstances prohibit us from disclosing that a report has been made.
PrimeLedger is registered with the UAE's goAML system as a Designated Non-Financial Business or Profession (DNFBP), consistent with its obligations under Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019.
4. Where Your Data Lives
We keep our supply chain small and name it openly. The providers we rely on, the role each performs and the data each handles are listed in section 9 of our Privacy Policy. In summary, authentication, database hosting, AI inference, transactional email and application hosting are each provided by a single named third party.
Those providers operate infrastructure outside the United Arab Emirates, so international transfer is inherent in delivering the service. We transfer personal data only on a basis permitted by applicable law and under the contractual protections offered by the provider concerned. If we change a provider, the list is updated.
5. Security Controls
The following describes measures that are actually implemented, rather than aspirations:
| Control | What it does |
|---|---|
| Encryption in transit | All traffic is served over HTTPS; plain HTTP requests are redirected |
| Strict transport security | Browsers that have visited once will not attempt an unencrypted connection again |
| Response security headers | Content security policy, framing restrictions, content-type protection and a restrictive permissions policy on every response |
| Authenticated access | The portal requires sign-in through a dedicated authentication provider |
| Per-account scoping | Every database query is bound to the requesting account |
| Parameterised queries | Values are never concatenated into SQL, removing the injection class of attack |
| Server-side validation | Submitted data is validated on the server; the browser is not trusted |
| Request-origin checks | Cross-site request forgery is rejected at the edge |
| Rate limiting | Automated abuse and resource exhaustion are constrained |
| Credential isolation | Provider credentials are held server-side and never delivered to the browser |
| Transient document handling | Uploaded files are parsed in memory and discarded, never written to durable storage |
No system can be made completely secure, and we do not suggest ours is an exception. These measures reduce risk; they do not eliminate it.
6. Record Retention
Records are kept for as long as there is a business or legal reason to keep them, and no longer. Several statutory periods commonly bear on the records we handle — for example, anti-money laundering records are generally required to be kept for at least five years from completion of a transaction or the end of a business relationship, and tax legislation sets its own minimum periods, with longer periods applying to certain categories such as real estate records.
These periods are stated here as general context only. The period that applies to a particular record depends on its nature and the circumstances, and should be confirmed for your own situation. Where a retention obligation applies, it takes precedence over a request to delete the specific records concerned — we will say so if that is the case.
7. Incident Response
If we become aware of a security or personal-data incident, our approach is to:
- contain it and establish what data and which people are affected;
- remediate the cause and verify the fix;
- notify affected individuals and any competent authority where the incident meets the threshold for notification under applicable law, within the period that law requires;
- tell those affected what happened, what it means for them, and what we are doing about it; and
- record the incident and what we changed as a result.
We will not conceal an incident, and we will not describe one in terms designed to minimise it.
8. Use of Artificial Intelligence
We use AI assistants on this website and in the portal, and we think the terms on which we do so should be explicit:
- Your data is not training data. Content you submit is used to generate your response, not to train models.
- You see what is sent. Where a feature attaches a summary of your recorded figures to a conversation, that summary is shown to you first and can be edited or removed.
- AI does not make decisions about you. We do not use automated decision-making that produces legal or similarly significant effects.
- AI output is not advice. It is general information, it can be wrong, and it is not a substitute for professional judgement on your circumstances.
- Professional work is performed by people. AI assists with drafting and research; it does not sign off deliverables, and conclusions in client work are reviewed by a person.
9. Professional Conduct
We aim to act with integrity, objectivity and professional competence, to decline work we are not competent to perform, and to raise conflicts of interest with the parties concerned before proceeding rather than after. Where a conflict cannot be managed appropriately, we decline the engagement.
We do not accept engagements whose purpose is to misstate a financial position or to evade a legal obligation.
10. Reporting a Security Concern
If you believe you have found a vulnerability in this website or the portal, please tell us at info@primeledgerconsultancy.com with enough detail to reproduce it. Please give us a reasonable opportunity to fix the issue before disclosing it publicly, and please do not access, modify or delete data belonging to anyone else, or degrade the service for other users, while investigating. We will acknowledge reports made in good faith on that basis and will not pursue action against a reporter who follows it.
11. What We Do Not Claim
Compliance pages often imply more than they say. To be unambiguous, this page does not claim any security certification, accreditation, external audit or assurance opinion over our systems, nor any specific insurance cover, and nothing on it should be read as such a claim. Where a certification, registration or cover is relevant to an engagement you are considering, ask us directly and we will answer specifically rather than in general terms.
12. Questions
Questions about anything on this page, including a request for detail on how we would handle a particular category of information, can be sent to info@primeledgerconsultancy.com, or by post to PrimeLedger Consultancy FZCO, IFZA Business Park, DDP, Dubai Silicon Oasis, Dubai, United Arab Emirates.
