This Privacy Policy describes how CRIF Gulf DWC LLC (“CRIF Gulf”) manages this website (www.synesgy.ae ) and processes the personal data of users who access it. This Policy is provided pursuant to Federal Decree‑Law No. 45 of 2021 on the Protection of Personal Data (the “UAE PDPL”) and other applicable UAE laws and regulations. If you register for the Synesgy/ESG services operated on the global platform, certain processing may be carried out by CRIF S.p.A. as an independent controller; please see its information notice at https://service.synesgy.com/global/information-notice. CRIF Gulf remains the controller for processing described in this Policy in relation to users in the UAE.
2. Data Controller and Contact Details
The Data Controller is CRIF Gulf DWC LLC, 15th floor, 48 Burj Gate, Downtown Burj Khalifa, PO Box 72478, Dubai, UAE. You can contact the Controller at info.me@crif.com
For privacy queries and to exercise data subject rights, you can reach us at info.me@crif.com
3. Location of Processing and Processors
Personal data is processed at CRIF Gulf’s offices in the UAE and by authorised personnel and service providers. Where service providers (processors) are engaged, they are bound by contracts imposing confidentiality, security, and assistance obligations consistent with the UAE PDPL.
Remote support or access from outside the UAE may occur for maintenance or support purposes; see Section 9 (Cross‑Border Transfers).
We process personal data lawfully, fairly and transparently, implementing appropriate technical and organisational measures to ensure confidentiality, integrity, availability and resilience. Processing takes place primarily by electronic means, with access controls, encryption in transit (where applicable), role‑based access, logging and retention controls proportionate to the risk.
Provide the website and related online services (including
navigation and responding to your enquiries). Legal basis: Contract
necessity / pre‑contractual steps; legitimate interests to operate
and secure the site.
Provide technology services (remote or on‑site assistance and
maintenance). Legal basis: Legitimate interests to maintain
services; contract necessity where applicable.
Produce aggregated statistics on the use and performance of the
website. Legal basis: Legitimate interests to improve services;
minimal impact, with opt‑out available where required
Business information services requested by clients (including assessments regarding activities, stability, reliability, solvency, and capacity in economic and business terms; checks in relation to existing or prospective business relationships). Legal basis: Legitimate interests of clients and CRIF Gulf to perform due diligence and risk assessment; contract necessity where data relates to our direct counterparties; compliance with legal obligations where applicable.
Deriving indices/scores and opinions (including automated analysis) relating to reliability/solvency or probability of insolvency; and ESG questionnaire support and customer‑satisfaction follow‑up calls. Legal basis: Legitimate interests; contract necessity where we provide such scoring to a contracting party; you have the right to object to profiling used for direct marketing or which produces legal or similarly significant effects.
Direct marketing by electronic means (email/SMS/automated
calling/instant messaging). Legal basis: Your prior opt‑in consent;
you may withdraw consent at any time without affecting the core
services.
Where we rely on legitimate interests, we perform a balancing test and implement safeguards (e.g., minimisation, opt‑outs where appropriate).
Retention purposes to enable the competent authorities to verify and reconstruct the rating determination process in accordance with Regulation (EU) 2024/3005.
We will process your personal data for marketing purposes only with your prior consent. This may include contacting you by SMS/MMS, e‑mail, telephone, or other electronic channels using automated systems. You may withdraw your consent or object to marketing at any time - for example, by clicking “unsubscribe” in e‑mails or replying “STOP” to SMS - after which we will stop sending you marketing messages. Refusing or withdrawing marketing consent will not affect our provision of the core services, but you will not receive marketing offers.
We disclose personal data, where relevant, to: (i) CRIF Group companies supporting the Synesgy/ESG platform; (ii) IT hosting, support and cybersecurity providers; (iii) analytics and communication service providers; (iv) professional advisers and auditors; (v) clients to whom business information services are delivered; and (vi) public authorities where required by law. All processors act under contract and instructions.
Personal data we process may include: identification and contact data (e.g., name, role, business email/phone), login and usage data (IP address, device, logs), business and financial indicators used in due‑diligence reports, records of communications, preferences/consents, and ESG questionnaire inputs. We may obtain data directly from you, from your employer/customer relationship, from publicly available sources (e.g., commercial registries), or from third‑party data providers subject to law.
Where personal data is transferred outside the UAE (including remote access), we will do so in accordance with Articles 22–23 of the UAE PDPL and applicable guidance. We will use one of the following: (a) transfer to a country/territory recognised as providing an adequate level of protection (once designated by the competent UAE authority); (b) appropriate safeguards such as contractual clauses ensuring enforceable data‑subject rights and effective legal remedies; or © a permitted derogation, for example where the transfer is necessary for the performance of a contract, for the establishment/exercise/defence of legal claims, or based on your explicit consent. We will document the applicable mechanism and can provide a description on request (with redactions for confidentiality).
We keep personal data no longer than is necessary for the purposes described in this Policy. Retention is determined using objective criteria, including: the nature of the data and processing purpose, statutory/contractual retention requirements, limitation periods for legal claims, and our security/backup practices. We will securely delete or anonymise data when it is no longer required.
Your personal data relating to ESG ratings, will be retained for 5 years from the conclusion of the rating process, as provided for in Article 18 of Regulation (EU) 2024/3005. Thereafter, the data will be deleted or anonymised, unless further retention is required to comply with legal obligations.
You have the right to: obtain information and access; rectification; erasure; restriction; data portability; and to object to processing (including to direct marketing and profiling for direct marketing). Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing. We aim to respond within 30 days, subject to identity verification and permitted extensions for complex requests. You may contact us at info.me@crif.com to exercise your rights. You also have the right to lodge a complaint with the UAE Data Office.
For details about the cookies used on this website, please refer to our Cookie Policy.
Our services are directed to business users. We do not knowingly collect personal data from minors. If we become aware that we have collected such data contrary to law, we will delete it and, where required, obtain guardian consent.
We may update this Policy from time to time. Material changes will be notified on this page and, where appropriate, by direct notice. The “Last update” date will be revised accordingly.
Last update: 29 June 2026