Last updated: February 6, 2026

Privacy Policy

Personal Data Processing Policy of Mountain Accounting and Bookkeeping LLC in accordance with UAE legislation

This personal data processing policy (the "Policy") has been drawn up in accordance with the legislation of the United Arab Emirates on personal data protection, including Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL"), and sets out the procedure for processing personal data and the measures taken by Mountain Accounting and Bookkeeping LLC (the "Controller") to ensure the security of personal data.

The Controller regards compliance with the rights and freedoms of individuals when processing their personal data — including protection of the right to privacy and personal and family confidentiality — as well as compliance with the PDPL and other applicable UAE legal acts, as the most important goal and condition of its activities.

This Policy applies to all information the Controller may obtain about visitors to the mountainfinance.ae website (the "Website"), as well as when providing services and interacting with clients through this Website.

For questions related to the processing and protection of personal data, the User may contact the Controller's Data Protection Contact by email at: info@mountainfinance.ae.

1. General provisions

1.1. The Controller is a legal entity registered in the United Arab Emirates and processes personal data in accordance with the PDPL and other applicable legislation.

1.2. This Policy sets out the procedure and conditions for processing personal data, as well as the rights of data subjects and the obligations of the Controller in such processing.

1.3. By using the Website and providing the Controller with personal data, the User confirms that they have read this Policy and, where required, give their consent to the processing of personal data as prescribed by law.

2. Key definitions

2.1. Automated processing of personal data — the processing of personal data by means of computing technology.

2.2. Blocking of personal data — the temporary suspension of personal data processing (except where processing is necessary to protect the rights and legitimate interests of the data subject or other persons, or to fulfil legal obligations).

2.3. Website — the collection of graphic and information materials, as well as computer programs and databases, that make them accessible on the internet at mountainfinance.ae.

2.4. Personal data information system — the collection of personal data contained in databases, together with the information technologies and technical means that enable their processing.

2.5. De-identification of personal data — actions as a result of which it becomes impossible to determine, without using additional information, which User or other data subject specific personal data belongs to.

2.6. Processing of personal data — any action (operation) or set of actions (operations) performed on personal data, whether or not by automated means, including collection, recording, systematisation, accumulation, storage, clarification, retrieval, use, transfer, de-identification, blocking, deletion and destruction of personal data.

2.7. Controller — Mountain Accounting and Bookkeeping LLC, a legal entity that, alone or jointly with others, determines the purposes and means of processing personal data.

2.8. Personal data — any information relating directly or indirectly to an identified or identifiable User of the Website or other individual (data subject).

2.9. Personal data authorised by the data subject for disclosure — personal data to which access by an unlimited group of persons has been granted by the data subject through explicit consent or publication.

2.10. User — any visitor to the mountainfinance.ae website, as well as any person who fills in web forms or otherwise provides the Controller with their personal data.

2.11. Provision of personal data — any actions aimed at disclosing personal data to a specific person or a specific group of persons.

2.12. Disclosure of personal data — any actions aimed at disclosing personal data to an indefinite group of persons, or granting access to personal data to an unlimited group of persons.

2.13. Cross-border transfer of personal data — the transfer of personal data to the territory of a foreign state or an international organisation, including access to personal data from outside the United Arab Emirates.

2.14. Destruction of personal data — any actions as a result of which personal data is irretrievably destroyed with no possibility of further recovery.

3. Key rights and obligations of the Controller

3.1. The Controller has the right to:

  • receive accurate information from the data subject to the extent necessary to achieve the purposes of processing;
  • continue processing personal data without the separate consent of the data subject if such processing is based on other lawful grounds provided for by the PDPL;
  • independently determine the measures necessary to fulfil the obligations set out in the PDPL;
  • engage third parties (service providers) to process personal data on the basis of concluded agreements.

3.2. The Controller is obliged to:

  • provide the data subject, upon request, with information concerning the processing of their personal data;
  • organise the processing of personal data in accordance with the PDPL and other applicable UAE legislation;
  • respond to requests and enquiries from data subjects within the time frame and in the form prescribed by law;
  • cooperate with the UAE's authorised personal data protection body (the UAE Data Office);
  • take legal, organisational and technical measures to protect personal data;
  • stop processing personal data once the purposes of processing have been achieved, or where there are no longer grounds for further processing.
4. Rights and obligations of data subjects

4.1. Data subjects have the right to:

  • receive information about the purposes, legal grounds, categories of data, storage periods, recipients and cross-border transfer of their data;
  • request the correction or updating of incomplete or inaccurate data;
  • request the deletion of personal data in cases provided for by the PDPL;
  • request the restriction of processing of personal data;
  • object to the processing of data for direct marketing purposes;
  • request that their personal data be provided in a machine-readable format (the right to data portability);
  • withdraw their consent to the processing of personal data at any time;
  • appeal against the Controller's actions to the UAE's authorised body or through the courts.

4.2. Data subjects are obliged to provide the Controller with accurate information about themselves and to promptly report any changes to it.

4.3. Persons who provide the Controller with inaccurate information bear liability in accordance with applicable UAE legislation.

5. Principles of personal data processing

5.1. Personal data is processed lawfully, fairly and transparently with respect to the data subject.

5.2. Processing is limited to achieving specific, predetermined and lawful purposes. Processing of personal data that is incompatible with the purposes of its collection is not permitted.

5.3. The merging of databases containing personal data processed for mutually incompatible purposes is not permitted.

5.4. Only data that is adequate, relevant and not excessive in relation to the stated purposes is subject to processing.

5.5. When processing personal data, its accuracy and relevance are ensured; where necessary, the Controller takes steps to delete or correct incomplete or inaccurate data.

5.6. Personal data is stored for no longer than required by the purposes of processing or by applicable UAE legislation.

6. Purposes of personal data processing

Purpose of processing: providing the User with access to services and materials on the Website, handling enquiries, interacting with prospective and existing clients, concluding and performing contracts, informing about the Controller's services, and analytics and improvement of the Website.

Personal data:

  • last name, first name (and patronymic, if any);
  • email address;
  • phone numbers;
  • company name and position (if provided);
  • data on interaction with the Website (IP address, device and browser type, pages visited, cookies and similar identifiers, including Google Analytics data).

Legal grounds for processing:

  • concluding and performing contracts between the Controller and the data subject;
  • fulfilling the Controller's legal obligations under UAE legislation;
  • the Controller's legitimate interests (business development, ensuring security, improving service quality);
  • the explicit consent of the data subject, where required by the PDPL.
7. Conditions for processing personal data

7.1. Personal data is processed with the consent of the data subject in cases where this is required by the PDPL, including when using certain categories of cookies.

7.2. Personal data may be processed without the separate consent of the data subject if such processing is necessary for: performing a contract; fulfilling the Controller's legal obligations; protecting the vital interests of the data subject; pursuing the Controller's legitimate interests; or on other grounds provided for by the PDPL.

7.3. Personal data may be processed where it has been explicitly made public by the data subject.

7.4. Personal data is processed for direct marketing purposes only where there is a lawful basis for doing so. As of the date this Policy was last updated, the Controller does not carry out regular email newsletters through the Website.

7.5. The Controller's services are not intended for persons under the age of 18. The Controller does not deliberately collect personal data from minors. If such data is obtained, it will be deleted or processed in accordance with legal requirements.

8. Procedure for collecting, storing and transferring personal data

8.1. The security of personal data is ensured through the implementation of the legal, organisational and technical measures necessary to meet PDPL requirements.

8.2. The Controller ensures the safekeeping of personal data, including: restricting access on a need-to-know basis; and using technical protection measures and secure communication channels.

8.3. The User's personal data may be transferred to third parties (hosting providers, CRM, analytics including Google Analytics) only to the extent necessary to provide services, and subject to confidentiality agreements being in place.

8.4. If inaccuracies are found in personal data, the User may update it by sending a notice to info@mountainfinance.ae marked "Personal data update."

8.5. The period for processing personal data is determined by the achievement of the purposes for which it was collected. Once these purposes are achieved, the data is subject to destruction or de-identification.

8.6. The User may withdraw their consent at any time by sending a notice to info@mountainfinance.ae marked "Withdrawal of consent to personal data processing."

8.7. Information collected by third-party services is stored and processed by those parties in accordance with their own privacy policies. The Controller is not responsible for the actions of third parties processing data as independent controllers.

8.8. The restrictions established on the transfer or processing of personal data may not apply where this is required to fulfil the Controller's legal obligations or for other public interest purposes provided for by UAE legislation.

8.9. The Controller maintains the confidentiality of personal data and does not disclose it to third parties, except as provided for by this Policy or applicable legislation.

8.10. The Controller stores personal data for no longer than required by the purposes of processing or by UAE legislation. Once these periods expire, the data is deleted or de-identified.

8.11. Processing of personal data is discontinued once the purposes of processing have been achieved, the data subject withdraws consent, or unlawful processing is identified.

8.12. In the event of a security incident capable of creating a significant risk to the rights of data subjects, the Controller arranges an assessment of the incident and, where necessary, notifies the UAE Data Office in accordance with PDPL requirements.

9. List of actions performed with personal data

9.1. The Controller performs the following actions: collection, recording, systematisation, accumulation, storage, clarification, retrieval, use, transfer, de-identification, blocking, deletion and destruction of personal data.

9.2. The Controller may carry out automated processing of personal data using information and telecommunications networks, as well as combined processing.

10. Cross-border transfer of personal data

10.1. The Controller may carry out cross-border transfers of personal data to other states or international organisations where necessary for operating IT infrastructure, using cloud services, or for other lawful purposes, subject to compliance with the PDPL's requirements for the protection of personal data.

10.2. The transfer of personal data to states that do not provide an adequate level of protection may take place where appropriate safeguards provided for by the PDPL are in place.

10.3. The Controller may keep records of cross-border transfers of personal data and, upon request from the data subject, provide information on the jurisdictions and categories of recipients involved.

11. Confidentiality of personal data

The Controller and other persons who have gained access to personal data under a contract or by law are obliged not to disclose or distribute personal data to third parties without a lawful basis or the data subject's proper consent, except in cases expressly provided for by UAE legislation.

12. Final provisions

12.1. The User can obtain any clarification regarding the processing of their personal data by contacting the Controller by email at info@mountainfinance.ae or through other contact details listed on the Website.

12.2. This Policy may be amended if the Controller's business processes are updated or applicable UAE legislation changes. The new version of the Policy takes effect from the moment it is posted on the Website. The Policy remains in effect indefinitely until replaced by a new version.