NEO& / Legal / Privacy Policy
Privacy Policy
01Who we are
NEO AND FZE LLC (نيو اند م م ح ذ م م) ("NEO&", "we", "us") is responsible for the personal data described in this Privacy Policy when we determine why and how that data is used.
This policy explains what we collect, why we use it, who we may share it with, how long we keep it and the choices and rights available to you.
02What we collect
- Inquiries and contact. Name, business contact details, organization, role, country and the contents of your message.
- Bookings and purchases. Contact and billing details, program or product selected, cohort, language, invoice and payment reference, and transaction status. Card data is handled by the payment provider and is not stored by NEO&.
- Program delivery. Attendance, participation records, communications, submitted work, assessment results and reasonable delivery records.
- Certification. Certificate name, credential, cohort, issue date, verification ID, status and information necessary to administer or verify the credential.
- Corporate engagements. Business contact details and client information supplied for the engagement, which may include information about employees or stakeholders where the client is authorized to provide it.
- Digital products. Order, license, download or access records and support correspondence.
- Webinars. Name, work email, country and, if you give it, mobile number when you register for a webinar, and the webinar you registered for. We use them to send the joining link and calendar invitation and to run the session. A recorded webinar or video plays from YouTube (youtube-nocookie.com) only when you press Play; from then on, YouTube's own privacy policy applies.
- Marketing preferences. Email address, consent or opt-out status and related preference records.
- Website and security data. IP address, device/browser information, security logs and, where consent has been given and analytics are enabled, usage information described in the Cookie Policy.
03Where the data comes from
Most data comes directly from you. We may also receive it from your employer or the organization purchasing a program for you, an authorized booking contact, a payment provider, a certification partner, or a service provider supporting delivery. Where a corporate client gives us personal data about others, the client is responsible for having a lawful basis to provide it.
04How we use personal data
We use personal data to respond to inquiries; process bookings and payments; deliver programs, assessments and consulting services; administer credentials and verification; provide requested communications; maintain our website and business systems; protect our services against misuse; meet legal, accounting and regulatory obligations; and establish or defend legal claims where necessary.
Depending on the activity, we process personal data because it is necessary to perform a contract or take steps you request before a contract, because we have a legitimate business need that does not override your rights, because we must comply with law, or because you have given consent. Where we rely on consent, you may withdraw it at any time for future processing.
05Certification and public verification
Verification is part of the purpose of issuing a professional credential. NEO&'s verification service covers the credentials NEO& issues, including the Strategy Dynamics credentials issued under license, and may display or confirm limited fields such as holder name, credential, issue date, status and verification ID.
OKRmentors credentials are issued and verified by OKRmentors through its own register and verification service; the personal data in that register is handled under the OKRmentors privacy terms.
Where a holder asks us to suppress public display, we will assess the request against the certification rules, legal basis for the register and any legitimate verification requirement. Suppression may mean that third parties can no longer verify the credential online. The rules governing credentials themselves are set out in our Certificate Terms.
06Who we share data with
We share personal data only where reasonably necessary. Recipients may include service providers supporting hosting, communications, live delivery, payment processing, administration and security; professional advisers; relevant certification or licensing partners where required to administer a credential; and public authorities where disclosure is required by law.
We do not sell personal data.
07International data transfers
Some of our service providers and partners may process personal data outside the UAE. Where personal data is transferred internationally, we use a transfer basis and safeguards appropriate to the circumstances and applicable UAE data-protection law.
08Retention
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, tax, accounting, contractual, security and dispute requirements. Our usual retention periods are:
- Unconverted inquiries: normally up to 24 months after the last substantive contact.
- Booking, invoicing and delivery records: for the engagement and then for the period required by applicable tax, accounting and limitation rules.
- Assessment material: normally up to 24 months after the relevant assessment or credential decision unless a longer period is needed for an appeal, integrity matter or partner requirement.
- Certification register data: for as long as the credential remains capable of verification, subject to applicable law and the relevant certification rules.
- Marketing preference records: while the subscription continues and for a reasonable period afterwards to evidence or respect the preference.
- Security logs: for a proportionate period based on security need and system configuration.
09Your rights
Subject to the conditions and exceptions in applicable UAE law, you may have rights to obtain information about processing, access personal data, receive a copy, correct inaccurate data, request erasure, restrict or stop certain processing, object to certain decisions or processing, and request transfer of data where the statutory conditions are met.
Send a request to business@neoand.com. We may ask for reasonable information to verify identity and authority before acting. We will respond within the period required by applicable law. If you are dissatisfied, you may use any complaint route available through the UAE Data Office or another competent authority.
10Automated decision-making
We do not ordinarily make decisions that produce legal or similarly significant effects about you solely by automated means. If that changes for a particular service, we will provide the information required by applicable law.
11Security and breaches
We use organizational and technical safeguards proportionate to the data and risk. Our public Data Protection statement describes the approach. If a personal-data breach occurs, we investigate, contain and document it and make notifications required by applicable UAE law.
12Children
Our website and professional programs are not directed to children. We do not knowingly collect a child's personal data through ordinary website sales. If a client wishes to commission a program involving minors, the privacy and safeguarding arrangements must be agreed separately before any personal data is collected.
13Changes
We update this policy when our processing, technology or legal obligations materially change. The date at the top shows the current version. Where a change materially affects an existing consent or processing arrangement, we will provide any additional notice or consent required by law.
Questions? Email business@neoand.com.