Privacy

    Privacy Policy

    How Arcus LLC collects, uses and protects your personal data - in line with Qatar's PDPL and, where applicable, the QFC DPR and the GDPR.

    Last updated: 26 June 2026

    1. Who we are

    Arcus LLC (“Arcus”, “we”, “us”) is a management advisory firm registered with the Qatar Financial Centre (QFC No. 04428). For the purposes of Qatar's Personal Data Privacy Law (Law No. 13 of 2016, the “PDPL”) and, where applicable, the QFC Data Protection Regulations 2021 and the EU GDPR, Arcus is the controller of the personal data described in this policy.

    You can contact us about this policy at info@arcus.consulting.

    2. What data we collect

    Depending on how you interact with us, we may collect:

    • Contact details you provide - name, business name, email address, phone/WhatsApp number.
    • Information you submit in our risk assessment questionnaire - about your organisation, the AI tools you use, and your data-handling practices.
    • Correspondence - the content of messages you send us.
    • Technical data - basic, privacy-respecting analytics about how our website is used (we do not use advertising trackers).

    3. How and why we use it

    We process your personal data only to:

    • Respond to your enquiry and prepare your AI risk assessment.
    • Deliver and support the advisory services you engage us for.
    • Communicate with you about your engagement.
    • Meet our own legal, regulatory and record-keeping obligations.

    4. Lawful basis

    We rely on your consent and/or the necessity of processing to take steps at your request and to perform our agreement with you. Where we process data to meet a legal obligation or our legitimate interest in running our business, we do so consistently with the PDPL and applicable law.

    5. Confidentiality and disclosure

    Confidentiality is fundamental to our service. We sign a mutual confidentiality agreement before every engagement. We do not sell your data, and we do not disclose audit findings to any third party - including regulators. We are an advisory firm with no obligation to report to authorities, and we do not do so.

    We may share data only with trusted service providers who help us operate (for example, secure hosting and scheduling), under agreements that require them to protect it; with professional advisers where necessary; or where required by a valid legal process.

    6. International transfers

    Some of our service providers may process data outside Qatar. Where that happens, we take steps to ensure your data continues to receive an appropriate level of protection, consistent with the PDPL and, where relevant, the GDPR.

    7. Retention

    We keep personal data only for as long as needed for the purposes above - typically for the duration of our engagement plus any period required to meet legal or contractual obligations - after which it is securely deleted or anonymised. You may request deletion at any time after an engagement ends.

    8. Your rights

    Subject to applicable law, you have the right to:

    • Access the personal data we hold about you.
    • Ask us to correct inaccurate or incomplete data.
    • Ask us to delete your data, or to restrict or object to its processing.
    • Withdraw consent at any time, without affecting prior lawful processing.

    9. Security

    We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss or misuse. All findings, communications and documents are stored securely.

    10. Changes to this policy

    We may update this policy from time to time. The “last updated” date above reflects the current version. Material changes will be reflected on this page.

    11. Contact us

    For any question or request about your personal data, email info@arcus.consulting or message us on WhatsApp at +974 3396 6131.