Legal
Privacy Notice
How MAST Consulting Group collects, uses, retains and protects personal data across our advisory and digital services.
Last updated 2026-06-01
1. Who we are
MAST Consulting Group ("MAST", "we") is a specialist GRC and cybersecurity advisory firm with offices in Dubai, Riyadh, Mumbai, London and New York. Our UAE entity is the data controller for this website unless stated otherwise in an engagement letter.
2. Personal data we collect
Contact details you submit through forms (name, email, phone, company, role, country), engagement-related correspondence, and limited technical data (IP, browser, pages viewed) collected via first-party analytics.
3. Why we process it
To respond to enquiries, deliver contracted services, send opt-in insights, comply with legal obligations (KYC, AML, audit evidence retention) and improve our website.
4. Legal bases
Performance of a contract, legitimate interests (running a B2B advisory practice), consent (marketing communications) and legal obligation (regulatory record-keeping). For EU/UK data subjects we apply GDPR equivalents; for UAE data subjects we apply Federal Decree-Law No. 45 of 2021.
5. Sharing & subprocessors
We share personal data only with vetted subprocessors who support delivery (cloud hosting, email, CRM, e-signature). A current subprocessor list is available on request.
6. International transfers
Where data is transferred outside the originating jurisdiction we rely on Standard Contractual Clauses, adequacy decisions, or equivalent legal mechanisms recognised by the source-country regulator.
7. Retention
Enquiry data: up to 24 months from last contact. Engagement records: 7 years post-engagement to satisfy professional and tax obligations. Audit evidence: as agreed in the engagement letter.
8. Your rights
Access, correction, deletion, restriction, portability and objection. To exercise any right contact privacy@mastcgroup.com. We respond within 30 days.
9. Security
MAST operates an ISO/IEC 27001 and ISO/IEC 27701 certified management system. Controls include encryption in transit and at rest, role-based access, MFA, logging and an annual penetration test.
10. Contact
Privacy Officer — privacy@mastcgroup.com. UAE supervisory authority: UAE Data Office. EU/UK: your local supervisory authority.