Privacy Policy

Last Updated: 23 August 2026

1. Who We Are

SERAPH is a growth partner providing services that may include growth strategy, positioning, creative, performance marketing, media buying, development, technology, automation, artificial intelligence, analytics, consulting, and related services.

Our company details are:

SERAPH
Registered Entity: Seraph Global FZCO
Email: info@srph.co
Website: srph.co
Registered Address:
5–7 Al A’amal Street
25 Marasi Drive
Business Bay, Za’abeel
Dubai, Dubai Municipality
United Arab Emirates

For privacy-related enquiries, you may contact us at info@srph.co.

2. Scope of This Privacy Policy

This Privacy Policy applies to personal information collected through:

  • Our website

  • Contact forms

  • Consultation bookings

  • Email communications

  • Client onboarding

  • Proposals and commercial discussions

  • Service delivery

  • Marketing activities

  • Analytics systems

  • Advertising platforms

  • CRM systems

  • Events and business development

  • Third-party integrations used in connection with our services

This Privacy Policy does not necessarily govern personal information processed exclusively on behalf of a client where SERAPH acts solely as a processor or service provider. In those circumstances, the relevant client may be the primary controller of that information.

3. Personal Information We May Collect

Depending on how you interact with us, we may collect the following categories of personal information.

Identity Information

This may include:

  • Full name

  • Job title

  • Company name

  • Business role

  • Professional profile information

Contact Information

This may include:

  • Email address

  • Telephone number

  • Business address

  • Communication preferences

Business Information

Where you enquire about or engage our services, we may collect:

  • Business name

  • Industry

  • Website

  • Revenue or business-size information

  • Marketing budgets

  • Commercial objectives

  • Growth targets

  • Project requirements

  • Technology stack

  • Marketing performance information

  • Internal business challenges

  • Existing agencies or vendors

Financial and Transaction Information

Where applicable, we may collect or process:

  • Billing details

  • Invoice information

  • Payment status

  • Transaction references

  • Contract values

  • Commercial terms

Where payments are processed through third-party payment providers, SERAPH may not directly receive or store full card information.

Communications

We may retain communications you send to us, including:

  • Emails

  • Contact-form submissions

  • Meeting notes

  • Project messages

  • Support requests

  • Consultation enquiries

  • Feedback

Technical Information

When you visit our website, we may automatically collect information including:

  • IP address

  • Browser type

  • Device type

  • Operating system

  • Screen resolution

  • Referring website

  • Approximate geographic location

  • Pages visited

  • Time spent on pages

  • Links clicked

  • Session information

  • Cookie identifiers

  • Device identifiers

Marketing and Analytics Information

We may collect information relating to:

  • Advertisement interactions

  • Campaign attribution

  • Conversion events

  • Website activity

  • Email engagement

  • Traffic sources

  • Audience characteristics

  • Marketing preferences

4. How We Collect Personal Information

We may collect personal information in several ways.

Directly From You

For example, when you:

  • Contact us

  • Submit a form

  • Book a consultation

  • Request a proposal

  • Sign an agreement

  • Become a client

  • Send us files

  • Provide system access

  • Communicate with our team

Automatically

Certain technical information may be collected automatically through:

  • Cookies

  • Analytics tools

  • Pixels

  • Server logs

  • Advertising technologies

  • Website-monitoring tools

Through Third Parties

We may receive information from:

  • Advertising platforms

  • Analytics providers

  • CRM systems

  • Referral partners

  • Public business directories

  • Professional networking platforms

  • Clients

  • Service providers

  • Business partners

5. How We Use Personal Information

We may use personal information for the following purposes.

To Respond to Enquiries

We use your information to:

  • Respond to questions

  • Assess whether we may be a suitable partner

  • Schedule calls

  • Prepare proposals

  • Provide requested information

To Deliver Our Services

We may use personal information to:

  • Manage projects

  • Provide strategy and consulting

  • Develop campaigns

  • Build websites or software

  • Manage advertising

  • Configure CRM systems

  • Create automations

  • Implement analytics

  • Provide ongoing optimization

  • Communicate with client teams

To Manage Commercial Relationships

We may use information to:

  • Prepare contracts

  • Manage invoices

  • Process payments

  • Maintain records

  • Administer client accounts

  • Monitor contractual performance

To Improve SERAPH

We may use information to:

  • Improve our website

  • Improve our service offering

  • Analyze demand

  • Understand how visitors interact with our website

  • Improve our internal systems

  • Develop new services and capabilities

For Marketing

Where lawful, we may use information to:

  • Send relevant business communications

  • Share company updates

  • Provide insights

  • Promote services

  • Conduct business development

  • Measure marketing effectiveness

For Security and Fraud Prevention

We may process information to:

  • Protect our systems

  • Prevent unauthorized access

  • Detect fraud

  • Investigate suspicious activity

  • Maintain cybersecurity

  • Enforce our agreements

To Meet Legal Obligations

We may process or disclose information where necessary to:

  • Comply with applicable law

  • Respond to lawful government requests

  • Fulfil accounting or tax obligations

  • Establish or defend legal claims

  • Protect our rights or the rights of others

6. Legal Bases for Processing

Where applicable law requires us to identify a legal basis for processing personal information, we may rely on one or more of the following.

Contractual Necessity

Where processing is necessary to:

  • Enter into an agreement with you

  • Deliver agreed services

  • Administer an existing engagement

Legitimate Interests

We may process information where necessary for legitimate business interests, including:

  • Operating SERAPH

  • Improving our services

  • Managing client relationships

  • Preventing fraud

  • Protecting systems

  • Measuring performance

  • Conducting appropriate business development

We seek to balance those interests against your privacy rights.

Consent

Where required, we may rely on your consent, particularly for:

  • Certain cookies

  • Marketing communications

  • Certain forms of tracking

  • Certain uses of personal data

You may withdraw consent where applicable.

Legal Obligation

We may process personal information where required to comply with legal, regulatory, accounting, tax, or judicial obligations.

7. UAE Data Protection

As a company operating from the United Arab Emirates, SERAPH seeks to process personal information in accordance with applicable UAE privacy and data protection requirements.

Where applicable, this may include obligations under the UAE's federal personal data protection framework and other relevant legislation.

Depending on the nature of an engagement, additional privacy rules may apply based on:

  • The client’s jurisdiction

  • The location of the individual

  • The location where data is processed

  • Industry-specific requirements

  • Applicable free-zone rules

  • Contractual obligations

8. European Union and United Kingdom Users

If you are located in the European Economic Area or United Kingdom, you may have rights under applicable data protection law.

These may include the right to:

  • Access personal information

  • Correct inaccurate information

  • Request deletion

  • Restrict certain processing

  • Object to certain processing

  • Withdraw consent

  • Request data portability

  • Lodge a complaint with a supervisory authority

These rights may be subject to statutory exceptions.

Where SERAPH processes personal information on behalf of one of our clients, requests relating to that information may need to be directed to the relevant client.

9. Marketing Communications

Where permitted by law, SERAPH may send you communications concerning:

  • Our services

  • Business updates

  • Relevant insights

  • New capabilities

  • Events

  • Commercial opportunities

You may unsubscribe from marketing communications at any time by using the unsubscribe option included in the message, where available, or by contacting info@srph.co.

Unsubscribing from marketing does not prevent us from sending communications necessary for an existing contractual or business relationship.

10. Cookies and Similar Technologies

Our website may use cookies and similar technologies.

Cookies are small files or identifiers stored on or associated with your device.

We may use cookies for purposes including:

  • Website functionality

  • Security

  • Analytics

  • Performance measurement

  • Remembering preferences

  • Conversion tracking

  • Advertising measurement

  • Audience analysis

Where required by law, we will request consent before using non-essential cookies.

You may also be able to restrict cookies through your browser settings.

11. Analytics

We may use third-party analytics tools to understand how users interact with srph.co.

Information processed through analytics may include:

  • Page views

  • Traffic sources

  • Session duration

  • Click activity

  • Device information

  • Browser information

  • Approximate location

  • Conversion activity

We use this information to improve our website, understand demand, and evaluate our marketing.

12. Advertising Technologies

SERAPH may use advertising and measurement technologies offered by platforms such as:

  • Google

  • Meta

  • LinkedIn

  • TikTok

  • X

  • Other advertising providers

These technologies may be used to:

  • Measure advertising performance

  • Attribute conversions

  • Build advertising audiences

  • Conduct remarketing

  • Improve targeting

  • Understand user journeys

The relevant platforms may independently process information under their own privacy policies.

13. Client Data

During client engagements, SERAPH may have access to data held within client systems.

This may include:

  • CRM records

  • Customer information

  • Campaign data

  • Advertising audiences

  • Transaction data

  • Website analytics

  • Lead data

  • Email lists

  • Platform activity

  • Internal business records

Where SERAPH processes this information solely on behalf of a client, SERAPH may act as a processor or service provider and the client may remain responsible as the controller.

SERAPH processes such information only as necessary to deliver the agreed services and subject to applicable contractual obligations.

14. CRM and Marketing Databases

SERAPH may use customer relationship management and marketing systems to manage:

  • Prospective clients

  • Existing clients

  • Business contacts

  • Communications

  • Opportunities

  • Project history

  • Marketing preferences

Information stored within such systems may be hosted by third-party providers.

15. Artificial Intelligence and Automation

As part of our services and internal operations, we may use:

  • Artificial intelligence tools

  • Machine-learning systems

  • Automation platforms

  • Large-language-model services

  • Data-processing tools

These tools may support activities including:

  • Research

  • Content generation

  • Data analysis

  • Workflow automation

  • Development

  • Reporting

  • Internal productivity

We seek to avoid providing unnecessary sensitive information to third-party AI providers.

Where client information is processed through AI or automation systems, we seek to do so in accordance with contractual and legal requirements.

16. Sharing Personal Information

We do not disclose personal information indiscriminately.

We may share information with trusted third parties where reasonably necessary.

These may include:

  • Hosting providers

  • Cloud providers

  • CRM providers

  • Email providers

  • Analytics providers

  • Advertising platforms

  • Payment providers

  • Accountants

  • Legal advisers

  • Contractors

  • Developers

  • Consultants

  • Cybersecurity providers

  • AI and automation providers

  • Project-management platforms

We may also share information where required by law.

17. Contractors and Service Providers

SERAPH may engage contractors, specialists, developers, consultants, or other external service providers.

Where those parties require access to personal or confidential information, we seek to limit access to what is reasonably necessary for their role.

Where appropriate, confidentiality and data-processing obligations may apply.

18. International Data Transfers

SERAPH operates in an international digital environment.

As a result, information may be stored or processed in countries outside the United Arab Emirates or outside your country of residence.

This may occur where:

  • Clients operate internationally

  • Team members work remotely

  • Cloud providers operate globally

  • Software providers host infrastructure overseas

  • Marketing platforms process data internationally

Where required, appropriate contractual or legal safeguards may be implemented for international transfers.

19. Data Retention

We do not intend to retain personal information indefinitely.

Retention periods depend on the nature and purpose of the information.

We may retain information for as long as reasonably necessary to:

  • Provide services

  • Maintain business relationships

  • Handle enquiries

  • Fulfil contractual obligations

  • Comply with tax and accounting requirements

  • Resolve disputes

  • Protect legal rights

  • Maintain security

  • Meet regulatory obligations

After the relevant retention period, information may be deleted, anonymized, or securely archived.

20. Data Security

SERAPH takes reasonable administrative, technical, and organizational measures intended to protect personal information from:

  • Unauthorized access

  • Misuse

  • Alteration

  • Loss

  • Disclosure

  • Destruction

Measures may include:

  • Access restrictions

  • Authentication

  • Password management

  • Secure cloud services

  • Encryption where appropriate

  • Limited access permissions

  • System monitoring

  • Confidentiality obligations

However, no internet transmission or electronic-storage system can be guaranteed to be completely secure.

21. Account Credentials

Where clients provide SERAPH access to platforms or systems, we encourage the use of:

  • Role-based access

  • User invitations

  • Temporary credentials

  • Least-privilege permissions

  • Two-factor authentication

Clients should avoid sharing primary passwords where secure delegated access is available.

22. Sensitive Personal Information

SERAPH generally does not require highly sensitive personal information for ordinary enquiries or commercial engagements.

Unless specifically required, please do not provide information concerning:

  • Health

  • Medical conditions

  • Biometric information

  • Government identification numbers

  • Financial account passwords

  • Religious beliefs

  • Political opinions

  • Sexual orientation

  • Criminal history

  • Other highly sensitive matters

Where sensitive information must legitimately be processed, additional safeguards may apply.

23. Payment Information

Invoices and payments may be processed through banks, accounting providers, or external payment processors.

Such providers may independently process payment details according to their own privacy policies.

SERAPH does not necessarily retain full payment-card credentials.

24. Children

SERAPH provides business-to-business and professional services.

Our website is not designed primarily for children, and we do not knowingly seek to collect personal information from children.

If you believe a child has improperly provided personal information to us, contact us at info@srph.co.

25. Third-Party Websites

Our website may include links to external websites, platforms, or services.

SERAPH does not control those services and is not responsible for:

  • Their content

  • Their privacy practices

  • Their security

  • Their terms

You should review the privacy policy of any external service you use.

26. Business Transactions

If SERAPH undergoes:

  • A merger

  • Acquisition

  • Reorganization

  • Sale

  • Financing transaction

  • Asset transfer

  • Corporate restructuring

personal information may be disclosed or transferred as part of that transaction where legally permitted.

27. Legal and Regulatory Disclosures

SERAPH may disclose information where we reasonably believe disclosure is necessary to:

  • Comply with applicable law

  • Respond to lawful court orders

  • Respond to governmental authorities

  • Enforce contractual rights

  • Investigate fraud

  • Protect our systems

  • Protect SERAPH, our clients, or other persons

28. Your Rights

Depending on applicable law and your location, you may have rights regarding your personal information.

These may include rights to:

  • Request access

  • Request correction

  • Request deletion

  • Request restriction of processing

  • Object to processing

  • Withdraw consent

  • Request portability

  • Opt out of certain marketing

  • Request information about data sharing

  • Lodge a complaint with the relevant authority

Certain rights may be restricted where we have legitimate legal grounds to retain or process the information.

29. Exercising Your Rights

To submit a privacy request, contact:

info@srph.co

Please include enough information for us to understand and reasonably verify your request.

We may request additional information where necessary to verify identity or authority.

Where we process information exclusively for a client, we may direct your request to that client.

30. Do Not Sell or Share

SERAPH does not sell personal information in the ordinary commercial sense of exchanging personal information directly for monetary payment.

However, certain advertising or analytics technologies may potentially constitute “sharing,” “sale,” or targeted advertising under specific privacy laws.

Where applicable law requires us to offer an opt-out mechanism, we will make reasonable efforts to provide one.

31. Automated Decision-Making

SERAPH does not ordinarily make legally significant decisions about individuals solely through automated processing.

If this changes in circumstances where applicable law grants specific rights concerning automated decision-making, we will seek to comply with those requirements.

32. Confidential Business Information

Information received during commercial discussions or client engagements may include confidential business information that does not necessarily constitute personal information.

Such information may also be protected under:

  • Client agreements

  • Non-disclosure agreements

  • Confidentiality provisions

  • Intellectual-property rights

This Privacy Policy does not replace those contractual protections.

33. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect:

  • Changes to our services

  • New technologies

  • New regulatory requirements

  • Changes to our processing activities

  • Changes to our business structure

When we make changes, the updated policy will be published on srph.co with a revised “Last Updated” date.

34. Contact SERAPH

If you have questions, concerns, or requests regarding this Privacy Policy or how SERAPH handles personal information, please contact:

SERAPH
Seraph Global FZCO

Email: info@srph.co
Website: srph.co

Registered Address:
5–7 Al A’amal Street
25 Marasi Drive
Business Bay, Za’abeel
Dubai, Dubai Municipality
United Arab Emirates

Effective Date: 23 August 2026