Skip to content
ICAN MENA
Services
Strategy & Growth AdvisoryOrganisation & Talent AdvisoryPeople & Leadership DevelopmentFinance & Compliance AdvisoryDigital & Data SolutionsBrand & Media Advisory
View all services
Solutions
ICAN PlatformOur platformThe operating system for your people.PortalPeoplePipelineProjectsPerformancePrograms
Also available through ICAN
SkeddaSpace & resource schedulingTalentLMSLearning, deliveredMeritioCompensation & total rewardsMystroTransformation with AI
View all solutions See pricing
InsightsAboutCareers
ICAN Portal

Legal

Privacy Policy

Effective 23 July 2026Last updated 23 July 2026

This policy explains what personal data ICAN MENA collects, why, who we share it with, where it is stored, and the rights you have over it. It covers this website, our advisory services, and every product in the ICAN platform.

Platform data is hosted in the European Union (Frankfurt, Germany). We do not sell personal data, and we do not use customer data to train AI models.

Terms of ServiceCookie Notice

On this page

  1. 1. Who we are and what this covers
  2. 2. Controller or processor — which one we are
  3. 3. What we collect
  4. 4. Special category and sensitive data
  5. 5. Why we process it, and our legal basis
  6. 6. Artificial intelligence and automated decisions
  7. 7. Who we share it with
  8. 8. Where your data is stored, and international transfers
  9. 9. How long we keep it
  10. 10. How we protect it
  11. 11. Your rights
  12. 12. Cookies and tracking
  13. 13. Children
  14. 14. Changes to this policy
  15. 15. How to contact us

1Who we are and what this covers

In short: ICAN MENA is a consulting firm in Dubai. This policy covers our website, our advisory work, and every product in the ICAN platform.

ICAN MENA(“ICAN”, “we”, “us”) is a management consulting firm registered in the United Arab Emirates, with its office at 504 Al Nasr Plaza, Oud Metha, Dubai, United Arab Emirates.

This policy applies to all of the following, together the “Services”:

  • This website, www.icanmena.com, and any form or enquiry submitted through it.
  • Our advisory, recruitment, coaching and delivery engagements.
  • The ICAN platform at portal.icanmena.com and its companion applications, covering every product listed below.
  • People — recruitment, onboarding and employee records
  • Portal — the expert and consultant marketplace, including engagements and sessions
  • Performance — goals, reviews and scorecards
  • Programs — coaching, mentoring and learning programmes
  • Potential — competency frameworks and skills mapping
  • Pulse — engagement surveys and feedback
  • Pay — compensation review and rewards planning
  • Plan — scheduling and shared availability
  • Pipeline — client relationship management
  • Projects — project and delivery management
  • Play — business simulations

Where a specific product or engagement has its own agreement with additional or differing privacy terms, that agreement takes precedence over this policy for that product or engagement.

2Controller or processor — which one we are

In short: For our own business contacts we decide how data is used (controller). For the data our customers put into the platform, they decide and we act on their instructions (processor).

The distinction matters because it determines who you should contact about your data, and it changes our legal obligations. There are two situations:

We are the controllerfor data we determine the purposes and means of processing for: people who contact us through this website, our own prospective and current clients’ business contacts, job applicants applying to ICAN itself, our own personnel, and the account records of the individuals who sign in to the platform.

We are a processor for the personal data our customers load into the platform about their own people — candidates, employees, programme participants, experts and consultants. The customer organisation is the controller. They decide what to collect, why, and for how long; we process it on their documented instructions under a data-processing agreement.

If your data is in the platform because an employer, a recruiter or a client organisation put it there, that organisation is the controller and your rights are exercised against them. We will help them respond, and we will tell you who to contact if you ask us — see your rights.

3What we collect

Information you give us directly. Your name, work email address, telephone number where you provide one, employer, role, and the content of any message you send us through a contact form or by email.

Account data. For people who sign in to the platform: name, work email address, the organisation they belong to, their role and permissions, authentication data (a hashed password, or the fact that you signed in with Google or Microsoft), and two-factor authentication enrolment.

Data our customers upload. Candidate profiles and CVs, expert and consultant profiles, employee records, goals and reviews, coaching and session notes, survey responses, compensation data, engagement and project records, invoices, and documents attached to any of these.

Data generated by using the Services. Server logs, request metadata, IP address, browser and device type, timestamps, actions taken in the platform, and error reports. We keep an audit trail of administrative actions because we are required to be able to show who changed what.

Recruitment data, where you apply for a role. Whatever you submit — CV, cover note, availability, expected rate, work authorisation status, and the correspondence about your application.

Mailbox content, only where a customer enables it. Some customers connect a shared recruitment mailbox so that inbound applications are captured automatically. Where enabled, we process the messages in that specific mailbox for that purpose alone.

4Special category and sensitive data

In short: We deliberately configure our CV processing to leave out age, gender, religion, marital status and photographs.

Special category data under Article 9 of the GDPR — racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health, sex life or sexual orientation — is not something we seek, and we ask customers not to load it into the platform.

Our automated CV parsing is configured to excludeage, date of birth, gender, marital status, religion and photographs from extraction, even when a CV contains them. This is a deliberate design decision: the region’s CV conventions often include those fields, and excluding them at the point of extraction reduces the chance they influence a hiring decision.

Nationality and work-permit or visa status are processed where they are operationally necessary for recruitment in the Gulf and have been lawfully provided. Where a customer chooses to upload anything falling within Article 9, they are responsible for establishing a lawful basis under Article 9(2) and for instructing us accordingly.

5Why we process it, and our legal basis

In short: Every use below is tied to a specific legal ground under Article 6 of the GDPR. We do not rely on consent for anything the Services need in order to work.

What we doLegal basis (GDPR Art. 6)
Provide the Services to the organisation you belong to; create and maintain your accountPerformance of a contract — Art. 6(1)(b); or our legitimate interest in serving our customer — Art. 6(1)(f)
Process customer data inside the platform on the customer’s instructionsThe customer’s own lawful basis; we act as processor under Art. 28
Respond to an enquiry you send usSteps prior to entering a contract — Art. 6(1)(b); legitimate interest — Art. 6(1)(f)
Secure the Services: authentication, rate limiting, abuse prevention, audit loggingLegitimate interest in keeping the Services and their data secure — Art. 6(1)(f)
Send transactional notifications about activity in the platformPerformance of a contract — Art. 6(1)(b)
Send marketing or insight emails where you asked for themConsent — Art. 6(1)(a); withdrawable at any time
Deliver the advisory engagement a client has retained us forPerformance of a contract — Art. 6(1)(b)
Keep accounting, tax and corporate recordsLegal obligation — Art. 6(1)(c)
Establish, exercise or defend a legal claimLegitimate interest — Art. 6(1)(f)

Where we rely on legitimate interest, we have considered whether that interest is overridden by your rights and concluded it is not, given the business context and the safeguards described in this policy. You can object to any such processing — see your rights.

6Artificial intelligence and automated decisions

In short: AI in the platform assists people; it does not decide about them. Your data is never used to train anyone’s models.

Several products use AI to structure a CV, draft text, summarise a document, or suggest how well an expert or candidate matches a requirement. Where a feature does this, the relevant text is sent to our AI sub-processor to generate the output and is returned to the platform.

Your data is not used to train models. We contract with our AI provider on terms that prohibit using content submitted through the Services to train or improve their models.

No solely automated decisions with legal or similarly significant effects. AI output in the platform is decision support. A match score, a ranking or a generated summary is presented to a person who reviews it and decides. We do not make hiring, rejection, promotion, compensation or engagement decisions by automated means alone within the meaning of Article 22 of the GDPR. Where a customer configures their own process around our outputs, they are responsible for keeping a human in the loop.

If you believe a decision affecting you was made about you using our AI outputs and you want it explained or reviewed, contact the organisation that made the decision — and tell us at info@icanmena.com so we can support them.

7Who we share it with

In short: Your organisation, the ICAN people working on your account, and the vetted suppliers listed below. We do not sell data.

We never sell personal data, and we do not share it for anyone else’s marketing.

We disclose personal data only to:

  • The customer organisation that owns the data, and the users it authorises.
  • ICAN personnel and contracted operators working on that customer’s engagement, on a need-to-know basis.
  • The sub-processors below, under written contract containing GDPR Article 28 terms.
  • Professional advisers — lawyers, accountants, auditors — where necessary and under a duty of confidence.
  • An acquirer or successor, if the business is sold or reorganised, subject to this policy continuing to apply.
  • Authorities, where we are legally compelled. We will tell the affected customer unless we are prohibited from doing so.

Current sub-processors

ProviderPurposeProcessing locationData involved
SupabasePrimary database, authentication and file storage for the platformEuropean Union (Frankfurt, Germany)All customer platform data, account credentials and uploaded files
VercelApplication hosting and content deliveryEuropean Union and United StatesRequest metadata, IP address, and data in transit while a page is served
AnthropicAI features — CV structuring, drafting assistance and matching as decision supportUnited StatesOnly the text submitted to a given AI feature (for example a CV or a job description)
Twilio SendGridTransactional email — invitations, notifications and alertsUnited States and European UnionRecipient name and email address, and the content of the message
SentryError monitoring and diagnosticsEuropean UnionTechnical error reports, which may incidentally include an account identifier
MicrosoftOptional single sign-on with a work Microsoft accountEuropean Union and United StatesName, email address and the fact that a sign-in occurred
GoogleOptional single sign-on, and mailbox integration where a customer enables itEuropean Union and United StatesName, email address, and — where mailbox integration is enabled — the messages in the connected mailbox

Customers under a data-processing agreement are notified before we add or replace a sub-processor, and may object on reasonable data-protection grounds.

8Where your data is stored, and international transfers

In short: Platform data is hosted in the European Union (Frankfurt, Germany). Some suppliers process data outside the EU under Standard Contractual Clauses.

The platform’s primary database, authentication system and file storage are hosted in European Union — Frankfurt, Germany (eu-central-1). We do not relocate customer data outside the agreed region without the customer’s instruction or agreement.

ICAN is established in the United Arab Emirates, and some of the sub-processors above operate in the United States. Neither the UAE nor the United States benefits from a general adequacy decision covering these transfers, so where personal data of individuals in the European Economic Area or the United Kingdom is transferred outside those areas, we rely on:

  • The European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where UK data is involved), incorporated into our contracts with each recipient; together with
  • Supplementary technical and organisational measures — encryption in transit, encryption at rest, role-based access control, tenant isolation enforced in the database, and audit logging.

You can request a copy of the safeguards applying to a specific transfer by writing to info@icanmena.com.

EU representative. Where Article 27 of the GDPR requires us to appoint a representative in the European Union, we will appoint one and name them here. Until then, and at any time, you may contact us directly at info@icanmena.com about anything in this policy.

9How long we keep it

We keep personal data only as long as we need it for the purpose it was collected for, or as long as the law requires.

  • Customer platform datais kept for the life of the customer’s engagement and for the period the customer specifies. Customers can archive or permanently delete records themselves; a permanent deletion removes the record, its related records and its attached files.
  • Account records are kept while the account is active, and deleted or anonymised within 90 days of the account being closed.
  • Enquiries and correspondence are kept for up to 24 months from the last contact, unless a relationship follows.
  • Applications to ICAN itself are kept for up to 12 months after a decision, so we can consider you for other roles. Tell us if you would rather we deleted yours sooner.
  • Security and audit logs are kept for up to 12 months.
  • Accounting and contractual records are kept for the period required by UAE law, generally five years.

When a customer’s agreement ends, we delete or return their data on their instruction within the period set out in their agreement, save where we are legally required to retain a copy.

10How we protect it

We apply technical and organisational measures appropriate to the risk, including:

  • Encryption in transit (TLS) and encryption at rest.
  • Tenant isolation enforced in the database itself through row-level security, so one customer’s records cannot be read by another regardless of application behaviour.
  • Role-based access control, with ICAN staff access limited to what an engagement requires.
  • Optional two-factor authentication, and the ability for an organisation to require it of its administrators.
  • Rate limiting on public endpoints and audit logging of administrative actions.
  • Regular review of database access rules, credentials and third-party dependencies.

No system is perfectly secure. If we become aware of a personal data breach we will assess it without undue delay, notify affected customers so they can meet their own obligations, and notify the relevant supervisory authority and affected individuals where the GDPR requires it.

If you believe you have found a security vulnerability in our Services, please report it to info@icanmena.com rather than disclosing it publicly. We will acknowledge your report.

11Your rights

In short: You can ask for a copy of your data, correct it, delete it, restrict or object to its use, and complain to a regulator.

Where the GDPR applies to our processing of your data, you have the following rights. They are free to exercise, and we will respond within one month.

  • Access — a copy of the personal data we hold about you, and information about how it is used.
  • Rectification — correction of data that is inaccurate or incomplete.
  • Erasure — deletion, where there is no overriding reason for us to keep it.
  • Restriction — to have us pause processing while a dispute about accuracy or lawfulness is resolved.
  • Portability — a machine-readable copy of data you gave us, where processing is based on consent or contract.
  • Objection — to processing based on legitimate interest, and at any time to direct marketing.
  • Withdraw consent — at any time, where consent is the basis. This does not affect processing before withdrawal.
  • Complain to a supervisory authority— in the EEA, the data protection authority of the country you live or work in, or where the issue arose; in the UK, the Information Commissioner’s Office. We would ask you to raise it with us first, but you are not required to.

How to exercise them. Write to info@icanmena.com. We may ask you to verify your identity before we act, so that we do not disclose someone’s data to the wrong person.

If your data is in the platform because an organisation put it there — for example, you are a candidate, an employee or a programme participant — that organisation is the controller and your request should go to them. If you send it to us, we will tell you who to contact and let them know you have been in touch.

12Cookies and tracking

In short: This website uses only what it needs to function. It does not carry advertising trackers.

This website does not use advertising cookies, cross-site tracking, or third-party marketing pixels. The platform uses strictly necessary cookies and local browser storage to keep you signed in, remember your sign-in preference, and protect against cross-site request forgery.

Full detail is in our Cookie Notice.

13Children

The Services are business tools intended for use by adults in a professional setting. They are not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child’s data has reached us, tell us at info@icanmena.com and we will delete it.

14Changes to this policy

We may update this policy as the Services change or the law does. The effective date at the top always reflects the current version. Where a change materially affects your rights, we will give notice — by email to account holders, or by a prominent notice in the platform — before it takes effect. Continuing to use the Services after that date means the updated policy applies.

15How to contact us

For anything in this policy, including any request about your data:

ICAN MENA
504 Al Nasr Plaza, Oud Metha, Dubai, United Arab Emirates
info@icanmena.com

A partner reads inbound mail directly — you will get a person, not a ticket queue. If you are not satisfied with how we handle your request, you have the right to complain to your data protection authority as described in your rights.

ICAN MENA

Connecting global expertise with the Gulf’s public and private institutions — since 2016.

Practice

Strategy & GrowthOrganisation & TalentPeople & LeadershipFinance & ComplianceDigital & DataBrand & Media

Company

AboutInsightsCase studiesCareersContact

Clients

ICAN PortalContact usLinkedIn

© 2026 ICAN MENA. All rights reserved.

Privacy PolicyTerms of ServiceCookies

Dubai · United Arab Emirates