Privacy Policy

1. Who We Are

This Privacy Policy explains how General Holdings Limited (“General Holdings”, “we”, “us” or “our”) collects, uses, shares and otherwise processes personal data through our website, in connection with our business relationships and transactions, and when you otherwise communicate or deal with us.

General Holdings Limited is a company incorporated in the Dubai International Financial Centre (DIFC) (Licence No. CL9442), with its registered office at Level 2, Innovation One, Dubai International Financial Centre, Dubai, United Arab Emirates. General Holdings is the controller of the personal data described in this policy.

We process personal data in accordance with the DIFC Data Protection Law, DIFC Law No. 5 of 2020, as amended, and applicable DIFC Data Protection Regulations.

If you have any questions about this policy or how we use your personal data, you can contact us at hello@gh.ae, by telephone on +971 4 395 5243, or by writing to our registered office at the address above.

2. Personal Data We Collect

Depending on how you interact with us, we may process the following categories of personal data:
Category
Examples of data
Typical source
Enquiry and correspondence data
Name, email address, organisation, telephone number, subject matter and content of your message or correspondence.
You, including through our website enquiry form, email or telephone.
Business contact data
Name, job title, organisation, business contact details, professional role and business correspondence.
You, your organisation, professional advisers, introducers, publicly available sources and professional or corporate directories.
Due diligence and transaction data
Information reasonably required to assess a proposed or existing business relationship or transaction, which may include identification details, nationality, date of birth, ownership or control information, professional and business information, and results of sanctions, politically exposed person, fraud or adverse-media checks where relevant.
You, your organisation, advisers, counterparties, public registers, public sources and screening or due-diligence service providers.
Technical and website data
IP address, browser and device information, date and time of access, pages requested, security logs and similar technical information.
Automatically through our website, hosting provider and other website infrastructure.
We do not seek to collect Special Categories of Personal Data through our website. Please do not send us sensitive personal information unless it is reasonably required for a matter we are dealing with and we have requested it or there is another appropriate reason for us to receive it.

3. How and Why We Use Personal Data

We may use personal data for the following purposes and on the following lawful bases:
Purpose
Lawful basis
Responding to enquiries and corresponding with you.
Our legitimate interests in responding to enquiries and conducting our business. Where you personally are entering into a contract with us, processing may also be necessary to take steps at your request before entering into that contract or to perform it.
Establishing, managing and developing relationships with operating partners, commercial counterparties, advisers, suppliers and other business contacts.
Our legitimate interests in developing and managing business relationships, evaluating and advancing projects and transactions, communicating with relevant contacts and protecting our commercial interests. Where the individual is personally a party to a contract with us, performance of that contract may also apply.
Conducting due diligence, know-your-counterparty checks and other checks relevant to a proposed or existing relationship or transaction.
Our legitimate interests in assessing counterparties and transactions, preventing fraud, managing risk and protecting our legal and commercial interests; and compliance with applicable legal or regulatory obligations where such obligations apply.
Operating, administering, maintaining and securing our website and information systems.
Our legitimate interests in providing a secure and functional website, maintaining network and information security, preventing misuse and troubleshooting technical issues.
Complying with applicable law, regulatory requests, court orders or lawful requests from public authorities, and establishing, exercising or defending legal claims.
Compliance with applicable legal obligations and our legitimate interests in protecting our rights and pursuing or defending legal claims.
Sending relevant business communications to existing or prospective business contacts about General Holdings, its activities or opportunities, where permitted by applicable law.
Our legitimate interests in developing and maintaining professional and commercial relationships, and consent where consent is required by applicable law.
Where we rely on legitimate interests, we consider whether the processing is necessary and proportionate and whether your interests or rights override our interests.

We do not sell or rent personal data. We do not use personal data for automated decision-making that produces legal effects or similarly significant effects.

We do not operate a consumer advertising mailing list. We may, however, communicate with business contacts about matters that we reasonably believe are relevant to an existing or prospective professional or commercial relationship. Where such a communication constitutes direct marketing, you may object at any time and we will stop using your personal data for that purpose.

4. When We Obtain Personal Data From Other Sources

We may receive business contact or due-diligence information about you from your organisation, an introducer, a professional adviser, a counterparty, a public register, a publicly available source, a professional or corporate directory, or a screening or due-diligence provider.

Where the DIFC Data Protection Law requires us to provide privacy information because we obtained your personal data from another source, we will provide or clearly direct you to this policy within the period required by law. This will normally be no later than our first communication with you, where we use the information to contact you, and otherwise within one month, subject to applicable exceptions.

5. Is Providing Personal Data Mandatory?

Providing personal data to us is generally voluntary. However, certain information may be required so that we can respond to an enquiry, evaluate or enter into a business relationship or transaction, conduct appropriate due diligence, or comply with applicable law. If required information is not provided, we may be unable to respond fully, progress a proposed relationship or transaction, or continue dealing with a matter.

6. Sharing Personal Data and International Transfers

We may share personal data, to the extent reasonably necessary for the purposes described in this policy, with:
  • (a) our directors, officers, employees, consultants and other personnel who need the information for their role;
  • (b) service providers acting on our instructions, including website hosting and security providers (including Webflow), email and IT providers, data-storage providers, due-diligence or screening providers and other technology providers;
  • (c) professional advisers such as lawyers, accountants, auditors and other consultants;
  • (d) counterparties, project participants, investors, financiers and their advisers where relevant to a project, proposed transaction or business relationship in which you or your organisation are involved; and
  • (e) courts, regulators, law-enforcement bodies and other public authorities where disclosure is required or permitted by applicable law.
Some recipients may be located outside the DIFC, including in the United Arab Emirates outside the DIFC, the United States, the United Kingdom and other jurisdictions. Where personal data is transferred to a jurisdiction that has not been recognised by the DIFC Commissioner of Data Protection as providing an adequate level of protection, we will use an appropriate safeguard or another transfer mechanism permitted by the DIFC Data Protection Law. This may include the DIFC Standard Contractual Clauses or other approved or legally permitted safeguards.

You may contact us using the details in section 12 if you would like further information about the safeguards used for international transfers or, where applicable, to obtain a copy of the relevant safeguards.

7. Retention and Security

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected and to meet applicable legal, regulatory, accounting, reporting and record-keeping requirements.
  • (a) Enquiries that do not lead to a business relationship are generally deleted within 24 months after our last substantive contact, unless there is a reason to retain them for longer.
  • (b) Records relating to a business relationship or transaction are generally retained for six years after that relationship or transaction ends, and may be retained for longer where reasonably necessary to comply with applicable law, respond to an investigation or regulatory request, resolve a dispute, or establish, exercise or defend legal claims.
  • (c) Technical and security records are retained for periods reasonably necessary for website administration, security, troubleshooting and the relevant service provider’s legitimate operational requirements, subject to applicable law.
We use appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful access, use, alteration, disclosure, loss or destruction. We also require service providers that process personal data on our behalf to protect it appropriately.

8. Cookies and Third-Party Content

We do not intentionally use analytics or advertising cookies operated by General Holdings on our website. Our website may use technologies that are necessary for the website to function securely and correctly.

Our Contact page includes an embedded Google Map, which loads only if you choose to display it. Our Contact form may use a third-party security service to protect against spam and automated submissions, which processes technical information about your browser and device for that purpose. When third-party content or services of this kind are loaded, your browser may connect directly to the third-party provider. The provider may receive technical information such as your IP address, browser or device information and referring website information, and may set or read cookies or similar technologies in accordance with its own privacy practices. We do not control the third party’s independent processing.

Where applicable law requires a choice or consent before a non-essential third-party technology is loaded, we will not load that technology until the required choice or consent has been obtained. You can also control or delete cookies through your browser settings, although doing so may affect the operation of certain website features.

9. Your Rights

Subject to the conditions and exceptions in the DIFC Data Protection Law, you may have the right to:
  • (a) request access to the personal data we hold about you;
  • (b) ask us to correct inaccurate or incomplete personal data;
  • (c) ask us to erase personal data in certain circumstances;
  • (d) ask us to restrict the processing of personal data in certain circumstances;
  • (e) object to processing based on our legitimate interests and object at any time to processing for direct marketing;
  • (f) receive personal data in a structured, commonly used and machine-readable format and, where applicable, have it transmitted to another controller;
  • (g) withdraw consent at any time where we rely on consent, without affecting processing carried out before withdrawal;
  • (h) not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where the relevant right applies; and
  • (i) exercise your data-protection rights without unlawful discrimination.
You can exercise your rights by emailing hello@gh.ae or by writing to General Holdings Limited, Level 2, Innovation One, Dubai International Financial Centre, Dubai, United Arab Emirates. We may ask you for information reasonably necessary to verify your identity.

We will normally respond to a valid request within one month. If a request is particularly complex or if we receive numerous requests, the DIFC Data Protection Law may permit us to extend the response period by up to a further two months. If we rely on an extension, we will notify you within the initial one-month period and explain the reason.

You may also lodge a complaint with the DIFC Commissioner of Data Protection. Information about the Commissioner and the complaints process is available at www.difc.com.

10. Third-Party Websites

Our website may contain links to websites operated by third parties. We do not control those websites and are not responsible for their privacy practices. We recommend reviewing the privacy information provided by any third-party website you visit.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our processing activities, website, service providers or applicable law. The current version will be published on our website with its effective date.

12. Contact

General Holdings Limited
Level 2, Innovation One
Dubai International Financial Centre
Dubai, United Arab Emirates
Email: hello@gh.ae
Telephone: +971 4 395 5243
‍
Effective date: 8 October 2026
A DIFC-based project sponsor and investment holding company
© 2026 General Holdings Limited
‍
General Holdings Limited is incorporated in the DIFC under DIFC Law No. 5 of 2018 (Licence No. CL9442). It is not authorised or regulated by the DFSA, does not hold any licence, authorisation or registration issued by the DFSA or any other financial regulatory authority, and does not carry on any Financial Service in or from the DIFC.