Privacy & Data Sovereignty Policy

This policy is engineered and overseen by a Principal with an MBA in Data Protection to ensure global compliance across UAE, EU, and Brazilian jurisdictions.

Governance & Scope

This policy governs the processing of personal data by DE SOUZA SILVA CONSULTANCY L.L.C-FZ (“the Firm”). Under the leadership of our Principal, who holds an MBA in Data Protection, we operate with a global standard of information integrity. We comply with the UAE Federal Decree-Law No. 45/2021, the General Data Protection Regulation (GDPR), and the Lei Geral de Proteção de Dados (LGPD).

Legal Basis for Processing

We process data under the following legal constructs:
Consent: Explicitly provided by you when requesting “The Manual” or a Strategic Briefing.
Contractual Necessity: To take steps at your request prior to entering into a mandate.
Legitimate Interest: To ensure the security of our “Private Counsel” and the integrity of our intellectual property.

Acquisition via SureForms

Data is collected through SureForms, a secure intake interface. We collect:
Identity & Professional Data: Names, titles, and corporate entities.
Contact Protocols: Secure emails, phone numbers and encrypted messaging handles.
Mandate Context: High-level briefing notes regarding your strategic needs.

International Data Transfers

As a UAE-based entity serving a global clientele (including EU and Brazilian citizens), data may be transferred across borders. We ensure all transfers employ Standard Contractual Clauses (SCCs) or rely on the adequacy of the UAE’s data protection frameworks, ensuring your data sovereignty is never compromised regardless of geography.

Data Retention (The 7-Year Rule)

In accordance with UAE commercial regulations and international best practices for professional liability, the Firm retains client data for a period of seven (7) years from the date of the last interaction or the conclusion of a mandate. Following this period, data is subject to secure cryptographic erasure unless a legal hold is required.

Rights of the Data Subject

Regardless of your jurisdiction (UAE, EU, or Brazil), you possess the following rights:
Right of Access & Portability: To request a copy of your data.
Right to Rectification: To correct any inaccuracies.
Right to Erasure (Right to be Forgotten): To request deletion, subject to our 7-year regulatory retention obligations.
Right to Restriction of Processing: To limit how we use your data.

Security Architecture

We do not sell, trade, or monetize your data. Information is stored in encrypted environments. Access is restricted exclusively to the Principal and authorized personnel bound by strict non-disclosure agreements.

Non-Regulated Advisory Disclosure

The Firm provides non-regulated strategic management advisory. While we maintain the highest standards of confidentiality, this processing does not constitute a statutory lawyer-client privilege under UAE law, but rather a contractual and professional commitment to absolute discretion.

Contact the Data Principal

For the exercise of your rights under GDPR, LGPD, or UAE Law, contact:
Harrison de Souza Silva Jr.
Data Protection Principal
contato@desouzasilva.com