CVE-2025-1234 patched in OpenSSL — update recommendedRansomware campaign targeting financial sector — elevated alertNew phishing kit targeting Microsoft 365 detectedCritical Apache Struts vulnerability — patch availableDDoS attacks increasing 40% YoY — ensure protection is activeZero-day exploit in popular VPN software — monitoringCVE-2025-1234 patched in OpenSSL — update recommendedRansomware campaign targeting financial sector — elevated alertNew phishing kit targeting Microsoft 365 detectedCritical Apache Struts vulnerability — patch availableDDoS attacks increasing 40% YoY — ensure protection is activeZero-day exploit in popular VPN software — monitoring
Legal Document
Privacy Policy
We are committed to protecting your personal data. This policy explains what information we collect, how we use it, and your rights under GDPR and applicable data protection laws.
📅 Effective: January 1, 2026🔄 Last updated: April 1, 2026📍 Governed by UAE & EU law
EVERLINE CYBER IT INFRASTRUCTURE L.L.C. ("EVERLINE", "we", "us", "our") collects information to provide cybersecurity services. We collect information you provide directly, information generated through your use of our services, and information from third parties.
Cookies & Tracking: See Section 9 for full details
⚙️ 2. How We Use Your Information
Purpose
Data Used
Basis
Delivering cybersecurity services
Account, Assessment, Technical data
Contract performance
Billing & invoicing
Payment, Contact data
Contract performance
Security incident response
All relevant technical data
Legitimate interest
Service improvement & analytics
Usage, Device data
Legitimate interest
Marketing communications
Email, preferences
Consent
Legal compliance
All data as required
Legal obligation
Fraud prevention
Usage, Device, Account data
Legitimate interest
⚖️ 3. Legal Basis for Processing
We process your personal data only when we have a valid legal basis under applicable data protection law, including the EU General Data Protection Regulation (GDPR) and the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection.
Contract Performance: Processing necessary to deliver services you have contracted with us
Legitimate Interests: Improving our services, fraud prevention, network security monitoring — balanced against your rights
Consent: Marketing emails and non-essential cookies — you may withdraw consent at any time
Legal Obligation: Compliance with applicable laws, court orders, and regulatory requirements
🤝 4. Data Sharing & Disclosure
We do not sell your personal data. We share data only in the following circumstances:
Service Providers: Vetted sub-processors bound by data processing agreements (cloud hosting, payment processing, analytics)
Professional Advisors: Legal, accounting, and insurance professionals under confidentiality obligations
Business Transfers: In the event of merger, acquisition, or sale — with advance notice to you
Legal Requirements: When required by law, court order, or to protect rights, property, or safety
With Your Consent: Any other sharing with your explicit prior consent
🔒 Security Engagement Data: All data shared during penetration tests, vulnerability assessments, or incident response is treated as strictly confidential and is never disclosed to third parties without your explicit written consent.
📅 5. Data Retention
We retain your personal data only as long as necessary for the purposes outlined in this policy or as required by law.
Data Category
Retention Period
Reason
Client account data
Duration of contract + 7 years
Legal & tax obligations
Security assessment reports
5 years after engagement end
Contractual & compliance
Incident response records
7 years
Legal obligation
Marketing data
Until consent withdrawn
Consent-based
Website usage data
26 months
Analytics
Payment records
7 years
Financial regulations
🛡️ 6. Your Rights
Depending on your jurisdiction, you have the following rights regarding your personal data:
Right of Access: Request a copy of the personal data we hold about you
Right to Rectification: Correct inaccurate or incomplete data
Right to Erasure ("Right to be Forgotten"): Request deletion where there is no compelling reason for continued processing
Right to Restrict Processing: Limit how we use your data in certain circumstances
Right to Data Portability: Receive your data in a structured, machine-readable format
Right to Object: Object to processing based on legitimate interests or for direct marketing
Right to Withdraw Consent: Withdraw consent at any time without affecting prior lawful processing
Rights Related to Automated Decision-Making: Not be subject to solely automated decisions that significantly affect you
To exercise any of these rights, contact our Data Protection Officer at privacy@everline.ae. We will respond within 30 days.
🔐 7. Security Measures
As a cybersecurity company, we apply the most rigorous security standards to protect your data:
AES-256 encryption at rest and TLS 1.3 in transit
ISO 27001-certified information security management system
Role-based access control and multi-factor authentication for all systems
Regular penetration testing of our own infrastructure
24/7 SOC monitoring for our client data environments
Annual third-party security audits
Employee background checks and mandatory security awareness training
Despite our best efforts, no security measure is 100% impenetrable. In the event of a data breach, we will notify affected individuals and relevant authorities within 72 hours as required by GDPR Article 33.
🌍 8. International Transfers
Your data may be transferred to and processed in countries outside your jurisdiction. When we transfer data internationally, we ensure appropriate safeguards are in place:
Adequacy Decisions: Transfers to countries recognised as providing adequate protection by the European Commission
Standard Contractual Clauses (SCCs): EU-approved contractual protections for transfers to third countries
Binding Corporate Rules: For intra-group transfers within our corporate structure
Certifications: Transfers to recipients holding valid privacy certifications (e.g., ISO 27701)
Our primary data centres are located in the UAE and EU (Ireland/Germany) with industry-standard data residency controls.
🍪 9. Cookies
We use cookies and similar tracking technologies. For full details on what cookies we use, why, and how to manage them, please see our Cookie Policy.
In summary, we use:
Essential Cookies: Required for site functionality — cannot be disabled
Analytics Cookies: Help us understand how visitors use our site (with your consent)
Marketing Cookies: Used to deliver relevant content and ads (with your consent)
📬 10. Contact & Data Protection Officer
For any questions, requests, or complaints regarding this Privacy Policy or our data practices, contact us:
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. In the EU, this is your national supervisory authority (e.g., the ICO in the UK, CNIL in France).
This policy was last updated on April 1, 2026. We may update it periodically — material changes will be communicated by email or prominent notice on our website.
Questions About Your Data?
Our Data Protection Officer is here to help. Contact us for any privacy-related queries.