CGC Privacy Policy
Effective Date: [01/05/2026]
This Privacy Policy describes how Centric Group Inc. (referred to as "Centric," "we," "us," or "our") collects, uses, processes, and protects the personal information of visitors to our website (centricdxb.com), users of our services, and users of our enterprise products, including Centric Governance Central (CGC).
1. Scope of this Policy
This policy applies to two main categories of data collection:
A. Website Data: Information collected from visitors browsing the centricdxb.com marketing and information website (e.g., through contact forms and analytics).
B. Product/Enterprise Data: Information processed on behalf of our clients through our enterprise software solutions, specifically the Centric Governance Central (CGC) platform.
2. Information We Collect
A. Website Data
We collect information you voluntarily provide to us and data automatically collected through tracking technologies.
|
Category |
Types of Data Collected |
Purpose of Collection |
|
Contact Data |
Name, Email Address, Phone Number, Company Name, Job Title, and any message content submitted via the "Contact Us" or "Request Demo" forms. |
To respond to inquiries, schedule product demos (CGC), and provide requested information about our services. |
|
Usage Data |
IP address, browser type, device information, operating system, referral URLs, time spent on pages, and clickstream data. |
For website analytics, to improve user experience, and for security monitoring. |
|
Marketing Data |
Preferences regarding receiving marketing communications and tracking of engagement with our emails (e.g., open rates). |
To inform our marketing and content strategy and communicate relevant services. |
B. Product/Enterprise Data
CGC is an enterprise application. Centric acts strictly as a Data Processor on behalf of our client organizations. The specific personal data entered into CGC is determined by the client.
|
Category |
Description |
Centric's Role |
|
User Data |
Employee names, work email addresses, job titles, department, assigned projects, and performance data (KPIs, goal progress, task completion) of the client's personnel. |
Processor. We only process this data according to the client's instructions as defined in the Master Service Agreement (MSA) or Data Processing Agreement (DPA). |
|
System/Audit Data |
User activity logs, system logins, change history, and access permissions within the CGC platform. |
Processor. This data is used solely to maintain system security, auditing, and platform stability for the client. |
Centric does not use or disclose the content or performance data entered into CGC by our clients for any purpose other than providing the CGC service, maintenance, and technical support.
3. How We Use Your Information (Legal Basis)
We use the information we collect for the following purposes based on the corresponding legal grounds:
-
To Perform a Contract: To fulfill our obligations under a service agreement, such as scheduling and conducting a demo you requested.
-
Legitimate Interests: To improve our website, services, and product (CGC), conduct business analysis, monitor security, and send direct marketing communications (where consent is not required).
-
Your Consent: To place non-essential cookies on your device or to send you marketing materials where explicit consent is required.
4. Data Sharing and Disclosure
We may share your personal information with the following parties:
-
Service Providers: Third-party vendors who perform services on our behalf, such as cloud hosting providers (e.g., Microsoft Azure), analytics providers (e.g., Google Analytics), and email marketing services. These parties are contractually obligated to protect your data.
-
Business Transfers: In connection with any merger, sale of company assets, financing, or acquisition of all or a portion of our business.
-
Legal Requirements: When required by law or in response to valid requests by public authorities (e.g., a court order).
-
Affiliates: With our parent company, subsidiaries, and affiliates within the Centric Group for business continuity and internal administrative purposes.
5. Data Security
Centric is committed to protecting your information. We implement technical and organizational security measures, including physical, electronic, and managerial procedures, to help safeguard and secure the information we collect and process, including those mandated by our ISO/IEC 27001:2022 certification (as referenced on our website).
Note on CGC Security: The security of data within the CGC platform is governed by the terms of the client's contract and is supported by Microsoft SharePoint’s robust enterprise-level security architecture.
6. Your Data Protection Rights
Depending on your location (e.g., EU, California, or specific UAE jurisdictions), you may have the right to:
-
Access the personal information we hold about you.
-
Correct inaccurate or incomplete personal information.
-
Request the Deletion of your personal information (the 'right to be forgotten').
-
Object to the processing of your personal information.
-
Request Data Portability to another service provider.
-
Withdraw Consent at any time where we rely on consent to process your data.
To exercise any of these rights, please contact us using the details below.
7. International Data Transfers
As a global agency with addresses in the UAE (Dubai) and the USA (Houston), your information may be stored and processed in countries outside of your own. By using our website or services, you understand that your information may be transferred to our facilities and those third parties with whom we share it as described in this policy. We ensure that any international data transfers comply with applicable legal requirements.
8. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Effective Date" at the top.
