Current version: updated 31 August 2026. This version replaces all earlier versions.
This policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and what you can do about it. It is written to be read, not to be skipped.
1. Who We Are
This site and the services described in it are operated by Sophia Global Consulting F.Z.E., a free zone establishment registered in Ajman Free Zone, United Arab Emirates ("Sophiall", "we", "us", "our"). We are the controller of the personal information described in this policy.
For anything to do with your personal information, contact us at privacy@sophiall.com.
We are not required to appoint a Data Protection Officer and have not appointed one. The address above reaches the person responsible.
2. What This Policy Covers
This policy covers sophiall.com and its subdomains, our email newsletter, the Critical Systems Scorecard, our forms and booking pages, purchases of our courses and programmes, the Business Owners Club, and advisory engagements.
Our Terms of Use govern the services themselves. This policy governs the information.
3. The Law We Work To
We are a UAE entity and we handle personal information in line with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.
Where we deal with people in the European Economic Area or the United Kingdom, we also apply the General Data Protection Regulation and the UK GDPR, and the rights in section 8 are available to you wherever you live, not only in those places.
4. What We Collect
4.1 Information you give us
- Email list: your name and email address.
- Critical Systems Scorecard: your name, email address, and your answers to the 25 questions, which describe how your business operates.
- Enquiries and bookings: your name, email address, telephone number, company name, and whatever you choose to tell us in a message or on a call.
- Purchases: your name, email address, billing address, and the record of what you bought and when.
- Advisory clients: the financial, operational and commercial information you provide for the engagement, which may include information about your employees, customers and suppliers, plus the identification documents we are required to hold.
- Community: anything you post in the Business Owners Club or another group we run.
4.2 Payment information
When you buy from us, our order form displays payment fields supplied by Stripe. Your card number, expiry date and security code go directly from your browser to Stripe. We do not receive them and we do not store them. What we receive is confirmation of the payment, the card type and the last four digits.
On rare occasions, and only where you ask us to, we may take card details from you on a call and enter them into Stripe on your behalf. Where that happens we do not write the details down, store them, or keep them after the payment is taken.
4.3 Information collected automatically
When you visit the site we collect your IP address, browser type and version, device type, operating system, approximate location derived from your IP address, the pages you viewed, how you arrived, and how long you stayed. When we send you an email we can see whether it was opened and which links were clicked.
5. Why We Collect It
We collect personal information for the purposes below, and for no others. Where the GDPR or UK GDPR applies to you, the legal basis is given in the third column.
| Purpose | What we use | Legal basis |
|---|---|---|
| Sending you our newsletter and marketing emails | Name, email, engagement data | Consent, which you can withdraw at any time |
| Generating and sending your Scorecard report | Name, email, your answers | Performance of a contract, being your request for the report |
| Responding to enquiries and holding calls | Contact details, message content | Legitimate interests in responding to people who contact us |
| Selling and delivering courses and programmes | Contact and purchase details | Performance of a contract |
| Delivering advisory engagements | Everything provided for the engagement | Performance of a contract |
| Identity and source-of-funds checks | Identification documents | Legal obligation under anti-money-laundering rules |
| Understanding how the site is used and improving it | Analytics and usage data | Consent for non-essential cookies; otherwise legitimate interests |
| Advertising and measuring our advertising | Tracking data | Consent |
| Keeping accounting and tax records | Transaction records | Legal obligation |
| Establishing or defending a legal claim | Whatever is relevant | Legitimate interests in defending our position |
5.1 Scorecard answers
Your Scorecard answers are used to generate your report and to inform how we follow up with you. We may also use them in aggregated and anonymised form for benchmarking, research and improving the tool, in a way from which neither you nor your business can be identified. We do not sell your answers and we do not share them with any third party in identifiable form.
5.2 What we do not do
We do not sell your personal information. We do not rent or trade our email list. We do not use your business information to approach your competitors, your customers or your suppliers.
6. Cookies and Tracking
Cookies are small files placed on your device. We use them, along with pixels and similar technologies, for three things: making the site work, understanding how it is used, and measuring our advertising.
| Type | What it does | Set by |
|---|---|---|
| Essential | Keeps the site working, remembers form entries, security | Our site and our CRM |
| Analytics | Tells us which pages are read and how people move through the site | Google Analytics, via Google Tag Manager |
| Advertising | Measures whether our advertising works and shows our ads to relevant audiences | Meta (Facebook and Instagram) |
You can control cookies through your browser settings, and most browsers let you block them or delete existing ones. Blocking essential cookies may stop parts of the site working. You can opt out of Google Analytics specifically using Google's browser add-on, and you can control advertising preferences in your Facebook and Instagram account settings.
Analytics and advertising cookies are not necessary for the site to function. If you are in the EEA or UK and would prefer we did not use them, tell us at privacy@sophiall.com and we will exclude you.
7. Who We Share It With
We do not sell your data. We share it with the service providers we need in order to run the business. Each of them is bound to use it only on our instructions.
| Who | What for |
|---|---|
| GoHighLevel | Our CRM, forms, Scorecard, booking pages, email delivery and payment links. Most of the information described in section 4 is held here. |
| Stripe | Taking payment. Stripe receives your card details directly, not through us. |
| Google (Analytics and Tag Manager) | Understanding site usage |
| Meta | Advertising and measurement |
| Our web host and WordPress plugins | Running and securing the site |
| Our accountants, auditors, insurers and legal advisers | Running the business and defending claims |
| Subcontractors and collaborating firms on an engagement | Delivering that engagement, and only with your knowledge |
We will also disclose information where we are legally required to, and where necessary to establish, exercise or defend a legal claim.
If the business is ever sold or restructured, personal information may transfer with it. The buyer would be bound by this policy or one no less protective.
8. Where Your Information Goes
We are based in the UAE. Our service providers operate in the United States, the European Union and elsewhere, so your information will be transferred outside your own country.
Where information moves out of the EEA or the UK, our providers rely on the transfer mechanisms available to them, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and adequacy decisions where one applies. We rely on those mechanisms rather than on your consent, so that the protection travels with the data.
9. How Long We Keep It
| What | How long |
|---|---|
| Newsletter subscription and engagement data | Until you unsubscribe, then up to 12 months so we can honour your unsubscribe |
| Scorecard answers and reports | 36 months from completion, unless you ask us to delete them sooner |
| Enquiries that do not become clients | 24 months from last contact |
| Client and engagement records | 10 years from the end of the engagement, as required by UAE commercial and tax law |
| Purchase and accounting records | 10 years, as required by law |
| Identification and anti-money-laundering records | As required by the applicable rules, generally 5 years from the end of the relationship |
| Analytics data | As configured in Google Analytics, currently 14 months |
Where we no longer need information but cannot delete it cleanly, we anonymise it so it can no longer be connected to you.
10. Your Rights
You can ask us to do any of the following, and we will not charge you for it or treat you differently for asking.
- Access. Get a copy of the personal information we hold about you.
- Correction. Have anything inaccurate or incomplete put right.
- Deletion. Have your information deleted, where we have no overriding legal reason to keep it.
- Restriction. Have us pause our use of your information while a dispute about it is resolved.
- Portability. Receive the information you gave us in a machine-readable format, or have it sent to someone else.
- Objection. Object to processing we carry out on the basis of legitimate interests, including profiling.
- Withdraw consent. Withdraw consent at any time, including by clicking unsubscribe in any marketing email. Withdrawing consent does not affect anything done before you withdrew it.
- Stop marketing. Tell us to stop sending you marketing, at any time, for any reason or none.
Email privacy@sophiall.com. We will respond within 30 days. If a request is complex we may extend that and will tell you why. We may ask you to confirm your identity before we act, to stop somebody else obtaining your information.
Deleting your information means we can no longer provide services that depend on it, including access to any programme you have purchased.
11. Complaints
If you think we have handled your information badly, tell us first at privacy@sophiall.com and we will try to put it right.
You also have the right to complain to a regulator. In the UAE that is the UAE Data Office. In the UK it is the Information Commissioner's Office. In the EEA it is the supervisory authority for the country you live in.
12. Security
We use reputable providers, access our systems through individual accounts protected by strong passwords and two-factor authentication where available, and limit access to the people who need it.
No system is completely secure, and we cannot guarantee the security of information sent to us over the internet. Please do not send us card details, passwords or identification documents by email or messaging app. If we need them, we will tell you how to send them securely.
13. Children
Our services are for business owners and are not directed at anyone under 18. We do not knowingly collect information from children. If you believe a child has given us their information, tell us at privacy@sophiall.com and we will delete it.
14. Changes to This Policy
We may update this policy. The version in force is the one published here, and each version carries the date it was issued. Where a change materially affects how we use information we already hold, we will tell subscribers and clients by email before it takes effect.
15. Contact
Sophia Global Consulting F.Z.E.
Ajman Free Zone, United Arab Emirates
privacy@sophiall.com