Talk to us

Privacy policy

Last updated: 14 August 2026 · CollectiveSpend Consultancy LLC, Dubai, United Arab Emirates

This policy explains what personal data CollectiveSpend Consultancy collects through our consultancy services, the assessment tools and this website, why we collect it, and what you can do about it.

Who we are

CollectiveSpend Consultancy LLC is the data controller for the personal data described here. We are registered in Dubai, United Arab Emirates. You can reach us at hello@csconsultancy.ai.

Tail spend and the METIS platform are handled by our sister company, CollectiveSpend Technology FZE. The two companies are separate legal entities and each controls its own website and customer data.

What we collect

DataWhyBasis
Name, work email, company, phoneWhen you submit an enquiry or request a consultation, so we can reply and prepare for the conversation.Your consent, and our legitimate interest in responding to enquiries.
Content of your enquiryTo understand what you need and route it to the right person.Your consent.
Server logs (IP address, browser, pages requested, timestamps)Kept by our hosting provider to run the site securely and diagnose faults.Our legitimate interest in operating a secure service.
Analytics, if you consentAggregate measurement of how the site is used, so we can improve it.Your consent, which you can withdraw at any time.
Platform data, for customersBusiness contact details of your users, approvers and supplier contacts, processed to run the service. We act as processor on your instructions.Our contract with you, under the Data Processing Addendum.

We do not sell personal data, and we do not use it to build advertising profiles.

Cookies

Cookies are small files a site stores in your browser. We keep this deliberately minimal.

You can change your choice at any time using the Cookie settings link in the footer, or by clearing site data in your browser. Blocking cookies in your browser settings will not stop the site from working.

Who we share it with

We share personal data only with service providers who help us run the business, and only as far as they need it:

Some of these providers operate outside the UAE. Where personal data is transferred abroad, we rely on the provider's standard contractual protections and on their own security commitments.

How long we keep it

Enquiry correspondence is kept for up to 24 months after our last contact with you, unless you become a client, in which case it is retained for the life of the relationship plus the period required by UAE commercial and tax law. Server logs are kept for a short operational window, typically no more than 90 days.

Sub-processors

We use sub-processors, including cloud hosting, AI model and payment partners, to deliver the service. Each is bound by data protection obligations no less protective than our own, we stay responsible for their performance, and we keep a current list available on request. Customers get reasonable prior notice of an intended change and may object on reasonable data protection grounds.

Security incidents

If a personal data breach affects customer personal data, we notify the affected customer without undue delay and in any event within 72 hours of becoming aware of it, with the information reasonably available so they can meet their own notification obligations.

Your rights

You can ask us to give you a copy of the personal data we hold about you, correct it if it is wrong, delete it, restrict how we use it, or object to our use of it. You can also withdraw consent at any time, which does not affect anything we did before you withdrew it.

To exercise any of these, email hello@csconsultancy.ai. We will respond within 30 days. If you are in the UAE and are not satisfied with our response, you may complain to the UAE Data Office.

We comply with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and, where it applies, the EU and UK General Data Protection Regulation. Where we act as processor for a customer, we act on their documented instructions and requests are routed to them as controller.

Security

We use encryption in transit and at rest, single sign-on with role-based access, and per-tenant database separation for platform data. SOC 2 certification is in progress; we will say so here when it is awarded, and not before.

Children

This is a business-to-business service. It is not directed at children and we do not knowingly collect personal data from anyone under 18.

Changes

If we change this policy we will update the date at the top. Material changes will be flagged on the site itself.

Contact

CollectiveSpend Consultancy LLC
Dubai, United Arab Emirates
hello@csconsultancy.ai