Onboarding Privacy Notice
Applies to individuals invited to onboard with, or be granted access to, Transcenda systems. Document No. TRX‑ONB‑PRIV‑001 · Version 1.0.
Is this secure? Yes — your data is encrypted in transit (HTTPS/TLS) and at rest, your identity document is held in a private, access-controlled store that is never publicly readable, and only server-side systems (not the browser, not the public) can reach it. Your acceptance is recorded in a tamper-evident, hashed record. No online system can promise absolute security, but this notice sets out exactly what we hold, why, how it is protected, and how long we keep it.
1. Who we are (Data Controller)
TRANSCENDA COMPUTER SYSTEMS & COMMUNICATION EQUIPMENT SOFTWARE DESIGN EST., a Dubai Sole Establishment (DED Professional Licence No. 1062923; D‑U‑N‑S 571233731; registered office: Office 305, Al Qusais 1, Deira, Dubai, UAE; tel. +971 4 368 2705), trading as "Transcenda", represented by its Founder and 100% Owner, Karem Tarek Ahmed Ghoneim, is the controller of your personal data for this onboarding.
Privacy contact: privacy@transcenda.io.
2. What we collect
| Category | Data |
| Identity | Full name, date of birth, nationality, issuing country, document type and number, and the image(s) of your identity document (passport / national or Emirates ID / driving licence). |
| Contact channels | Personal email, mobile / phone number, WhatsApp number, and work email — and confirmation that you received your work email. |
| Verification & technical | One-time codes sent to your email and phone (and the fact/time they were verified), device and browser information, IP address, and event timestamps. |
| Agreement & signature | Your typed name, your drawn signature image, the consents you gave, the exact agreement version you accepted, and cryptographic hashes and timestamps evidencing your acceptance. |
3. Why we use it and our legal basis (UAE PDPL)
- To verify your identity before granting access — necessary for the onboarding you requested and our legitimate interest in securing our systems.
- To conclude and evidence the Access & Confidentiality Agreement — performance of that agreement and, for the specific consent items, your consent.
- To grant, manage and secure your access to devices, networks, accounts and credentials, and to keep audit and security records — our legitimate interest and legal obligations.
- To comply with law (record-keeping, tax, security, lawful requests).
Where we rely on your consent (e.g. processing your ID document, call recording, monitoring and remote administration), you may withdraw it at any time — see Section 8. Withdrawal does not affect processing already carried out, and some access may not be possible without the underlying data.
4. Your identity document — how it is stored and protected
- Uploaded over an encrypted (HTTPS) connection using a short-lived, single-purpose upload link.
- Stored in a private cloud storage bucket that is not publicly accessible and is encrypted at rest; it is never listed, indexed, or served to the public web.
- Reachable only by our server-side systems under a least-privilege service account — never by other applicants, and not by your own browser after upload.
- Read once to auto-fill your details; the extracted fields are shown to you to correct and confirm — the document is not treated as final until you sign, and you can replace it beforehand.
- Not used for any advertising or profiling, and never sold.
5. Security measures
- TLS encryption in transit and encryption at rest for all stored data.
- Private, access-controlled storage and server-only database access (no public read).
- One-time codes are stored only in hashed form and expire quickly.
- Least-privilege service credentials; administrative functions are key-protected.
- A tamper-evident, hash-chained record of your acceptance, independently verifiable by reference number without exposing your personal data.
6. How long we keep it (retention)
- One-time verification codes: deleted on use or within ~10 minutes.
- Your identity document, the signed agreement, your signature, consents and audit record: kept together as a single tamper-evident record and retained for the duration of your engagement and for up to 7 years afterwards. Your identity document is part of this record — it evidences who accepted and signed the Agreement, and is retained as required under UAE law and to establish or defend legal claims within the applicable limitation period. Both you and the Organization keep a copy of the signed Agreement.
- After the retention period — or on a valid erasure request where no overriding legal-retention obligation remains — the data is deleted.
7. Who we share it with
We do not sell your data. It is processed on our behalf by our cloud infrastructure and communications providers (e.g. Google Cloud / Firebase for hosting, storage and identity verification, and our email/SMS delivery providers) under confidentiality and data-processing terms. It may be disclosed to authorities where required by law. Access inside Transcenda is limited to those who need it to onboard you.
8. Your rights
Subject to UAE law, you may request to access, correct, or erase your data, restrict or object to certain processing, receive a copy in a portable form, and withdraw consent where processing is based on consent. We will honour these requests except where we must retain certain data — in particular your signed Agreement and the identity document attached to it — to comply with a legal obligation or to establish, exercise or defend legal claims. To exercise these rights, contact privacy@transcenda.io. You also have the right to complain to the UAE Data Office.
9. International transfer
Your data may be processed on cloud infrastructure located outside the UAE. Where this happens, we rely on providers that apply appropriate technical and contractual safeguards consistent with the UAE PDPL.
10. Changes to this notice
We may update this notice from time to time. The version and document number above identify the current version; material changes affecting you will be brought to your attention.
11. Contact
Questions or requests: privacy@transcenda.io · Transcenda, Office 305, Al Qusais 1, Deira, Dubai, UAE · tel. +971 4 368 2705.