Privacy Policy
Our global standards for confidentiality and data protection
Introduction
Toralya (“we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you interact with our website (toralya.io) or use our services. It is designed to comply with the EU General Data Protection Regulation (GDPR), the United Arab Emirates Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).
This unified Policy applies to all users worldwide. We adhere to globally recognised privacy principles and legal requirements.
Who We Are: Toralya is a strategic cyber intelligence and forensic analysis brand in the process of establishing its operational base in Dubai, United Arab Emirates, under a DMCC licence. All data processing activities are conducted in accordance with internationally recognised standards, including GDPR, PDPL, and relevant U.S. privacy regulations.
By using our website or providing us with your information, you acknowledge this Policy. If you do not agree with any part of it, please refrain from using our services.
Personal Data We Collect
– Information You Provide: When you contact us via our website form or email, you may provide personal data such as your name, email address, organisation, job title, telephone number, and the content of your inquiry.
– Communication Data: Any correspondence with us (including emails and messages) will contain personal data that we process in order to respond and keep records of our communication.
– Automatic Data Collection: When you visit our site, we may automatically collect technical information such as your IP address, browser type, device identifiers, operating system, referring URL, pages visited, and time/date of access.
– Cookies & Similar Technologies: We use only essential cookies necessary for the operation and security of the site. We do not use marketing cookies, tracking pixels, or third-party behavioural analytics.
– Sensitive Data: We do not intentionally collect sensitive categories of personal data, nor do we knowingly collect personal data from children under 16.
How We Use Personal Data
We use personal data only for legitimate purposes, including:
– Responding to Inquiries: To answer your requests, provide information, and communicate with you.
– Service Delivery: To perform contracts or take pre-contractual steps at your request, including the provision of intelligence reports or forensic services.
– Business Administration & Legal Compliance: To meet legal obligations, manage accounts, billing, and record-keeping.
– Security & Fraud Prevention: To protect our website and systems, detect suspicious activity, and maintain cybersecurity integrity.
– Analytics & Service Improvement: To analyse aggregate data and improve the functionality and quality of our services.
We do not sell personal data or use it for unsolicited marketing.
Legal Basis for Processing
Depending on the context, we process personal data on the following legal grounds:
– Consent – when you expressly consent to processing (e.g., by submitting our contact form).
– Contract – when processing is necessary to perform or prepare for a contract with you.
– Legitimate Interests – when processing is necessary for our business operations (e.g., ensuring cybersecurity), balanced against your rights.
– Legal Obligation – when processing is required by law.
Disclosure of Personal Data
We only disclose personal data in limited circumstances:
– Service Providers: Trusted third parties providing hosting, IT, email, or cloud services, under strict contractual safeguards.
– Professional Advisers: Legal, accounting, or audit advisers bound by confidentiality.
– Legal Requirements: Where required to comply with law or protect rights, safety, and security.
– Corporate Transactions: In the event of a merger, reorganisation, or business transfer, subject to equivalent safeguards.
– With Consent: When you have explicitly authorised disclosure.
We do not sell, rent, or share personal data for advertising or marketing.
International Data Transfers
As Toralya is establishing its base in Dubai under a DMCC licence, personal data may be processed in the UAE and in other jurisdictions where our service providers operate (such as the EU or United States).
We ensure that any international transfers are conducted lawfully, using mechanisms such as adequacy decisions, Standard Contractual Clauses, or other recognised safeguards, so that your personal data remains protected to the highest standards regardless of location.
Data Retention
We retain personal data only for as long as necessary:
– Inquiries: Retained for up to 12 months unless a longer retention is required or you request earlier deletion.
– Client Data: Retained for the duration of the business relationship and as required by law (e.g. accounting or compliance).
– Technical Logs: Retained only for short periods necessary for security and performance monitoring.
Once data is no longer needed, it will be securely deleted or anonymised.
Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. Measures include encryption, access controls, secure servers, monitoring, and staff confidentiality obligations.
In the event of a data breach involving your personal data, we will notify you and relevant authorities in accordance with applicable law.
Your Rights
We respect your rights under GDPR, PDPL, and CCPA/CPRA, including:
– Right of access
– Right to rectification
– Right to erasure
– Right to restrict processing
– Right to data portability
– Right to object
– Right to withdraw consent
– Right to non-discrimination for exercising your rights
California residents additionally have the right to know, delete, correct, and opt out of any sale or sharing of personal information (though Toralya does not engage in such practices).
To exercise your rights, contact us at info@toralya.io
Complaints
If you have concerns about how we process your data, please contact us directly. You also have the right to lodge a complaint with:
Your national Data Protection Authority (for EU/EEA residents),
The UAE Data Office (for UAE residents),
The California Privacy Protection Agency or Attorney General (for California residents).
Updates
We may update this Privacy Policy from time to time. Material changes will be communicated on our website, and your continued use of our services after changes take effect will constitute acceptance. Last Updated: 11 September 2025.