Effective date: 04/07/2026
Version: 1.01
ESG Rated is a business-to-business service operated by Talyro Global LLC. This policy explains how we collect, use, share, and protect personal data when you visit our website, use our platform, deal with us as a business contact, or are named in the ESG information we source and publish. It is written for website visitors, account users, business contacts, and individuals named in the ESG data we handle.
1. Who we are and how to contact us
ESG Rated is a brand operated by Talyro Global LLC, a limited liability company licensed in the Sharjah Media City (Shams) free zone, Emirate of Sharjah, United Arab Emirates, We operate the “ESG Rated” service at esgrated.com.
For the personal data described in this policy, Talyro Global LLC is the data controller (the party that decides why and how the data is used).
You can contact us about any privacy matter, including to exercise your rights or raise a concern:
- Data Protection Officer (DPO): We have appointed a Data Protection Officer under Article 10 of the PDPL, given the nature and scale of our processing (including profiling of individuals and monitoring of ESG-related information). You can contact our DPO at dpo@esgrated.com
- Postal address: Talyro Global LLC postal address, Sharjah Media City (Shams), UAE,
2. Scope and our two roles (controller and processor)
We handle personal data in two different roles. It matters which role applies, because this policy only covers one of them.
Controller role (this policy covers this). For some data, we decide why and how it is used. This includes:
- website-visitor data;
- account and user data;
- marketing and business-contact data;
- our own sourcing of public and third-party data to produce Ratings and to run controversy monitoring; and
- our decision to publish Ratings, Scorecards, and Badges.
Processor role (this policy does not restate this). When a business Customer uploads Submitted Evidence that contains personal data (for example, a document naming a director or officer), the Customer is the controller of that personal data and we act only as a processor on the Customer’s instructions. That relationship is governed by our separate Data Processing Agreement (DPA), not by this policy.
Where the DPA conflicts with this policy in relation to personal data, the DPA prevails (consistent with Terms and Conditions clause 23.2). This policy references the DPA but does not repeat its terms.
There is one important boundary. A document may reach us as a processor (inside Submitted Evidence), but the moment we decide what to publish from it as part of a Rating, that publication decision is our own act as a controller. That controller activity is covered by this policy (see Section 5).
3. The personal data we collect, and where it comes from
We collect the following categories of personal data.
- Website and technical data: IP address, device and browser identifiers, cookie and analytics identifiers, pages viewed, referrer, approximate location, and session logs.
- Account and user data: name, business email, job title, employer, role and permissions, login and authentication data, platform-usage and audit logs, and support correspondence. These are the individuals who use our platform for a business Customer (each a “User”).
- Business-contact and marketing data: name, business email, company, job title, and engagement or campaign interaction data.
- Billing and commercial-contact data: contact and administrative details needed to invoice and manage a paid business account.
- Personal data about directors, officers, and named personnel of rated entities: names, roles, and connected details of individuals linked to a rated company, appearing in the public and third-party sources we use, in our published outputs, and in controversy monitoring. Personal data that reaches us only inside a Customer’s Submitted Evidence is processor-role data governed by the DPA (see Section 2), not this Section. These individuals are usually identified in a professional or business capacity.
We get personal data from three types of source:
- Data you give us directly (for example, when you create an account, fill in a form, or contact us). Billing and commercial-contact data is provided to us directly by the Customer when a paid account is set up.
- Data we collect automatically from your use of the site (through cookies and similar technologies).
- Data we obtain from independent third-party and public sources without the individual submitting it to us. These sources include official registries, regulators, news and adverse-media, and sanctions and watchlists.
Most individuals in category (3) are connected to rated companies rather than being our own users, and are typically identified in a professional or business capacity.
We do not intentionally collect Sensitive Personal Data (as defined in Article 1 of the PDPL). Where such data appears in ESG information whose processing is necessary to protect the public interest (for example, adverse media naming an individual in connection with an allegation), its source is the public or third-party record itself (for example, published adverse media or a regulator’s decision), not the individual. We rely on the Article 4 public-interest ground, we apply proportionate safeguards and human review, and we process only what is necessary and proportionate to the ESG assessment. See Sections 5, 6, and 13.
4. How and why we use personal data, and our PDPL lawful bases
The table below sets out each purpose for which we use personal data as a controller, and the PDPL lawful basis for it.
A note on terminology: the PDPL does not contain a standalone “legitimate interests” basis in the way some other laws do. Where we describe balancing our interests, we do so under the specific Article 4 grounds cited below (in particular processing that is necessary to protect the public interest, and processing of personal data the individual has made public by their own act), and we always weigh those grounds against the rights of the individuals concerned.
| Purpose | What it involves | PDPL lawful basis |
|---|---|---|
| Operate and secure the website | Run esgrated.com, keep it available, prevent fraud and abuse, keep security and log integrity | For Users and account holders: performance of a contract (Art. 4). For all visitors: processing necessary to protect our rights and the rights of third parties, and to comply with our security and legal obligations (Art. 4); consent for non-essential cookies and analytics (Art. 6) |
| Operate accounts and provide the Services | Create and administer accounts, authenticate Users, deliver platform access under the Plan, provide support | Performance of a contract with the Customer (Art. 4, contract necessity) |
| Produce ESG Ratings | Assess evidence and independent sources to produce Ratings, Verification Levels, and Scorecards | Article 4 public-interest ground (processing necessary to protect the public interest), balanced against data-subject rights |
| Run controversy and surveillance monitoring | Track regulators, news and adverse-media, registries, and sanctions lists for controversies affecting rated entities | Article 4 public-interest ground (processing necessary to protect the public interest), balanced against data-subject rights |
| Publish Ratings, Scorecards, and Badges | Publish Ratings and Published Rating Data (including personal data in them) on public profiles | Article 4 public-interest ground (processing necessary to protect the public interest); the Article 4 “made public by an act of the data subject” ground only where the individual has themselves made the data public, balanced against data-subject rights |
| Handle billing and administration | Invoice, take payment, keep tax and accounting records | Performance of a contract and compliance with UAE law (Art. 4) |
| Market to business contacts | Send B2B communications, run outreach and events, manage leads | Consent where required for electronic marketing (Art. 6), and/or the Article 4 grounds that permit processing necessary for our legitimate business relationship with the recipient, with opt-out honoured |
| Ensure security | Access control, logging, fraud and abuse prevention | Processing necessary to protect our rights and the rights of third parties, and our information-security obligations (Art. 4) |
| Meet legal obligations | Comply with UAE law, respond to lawful requests, establish or defend legal claims | Compliance with UAE law and the PDPL ground allowing processing to establish, exercise, or defend a legal claim (Art. 4) |
The PDPL has no standalone “legitimate interests” basis; where we describe balancing our interests, we do so under the specific Article 4 grounds cited above and always weigh them against data-subject rights. For any processing that relies on the Article 4 public-interest ground, we carry out and document a balancing assessment that weighs our purpose against the rights and freedoms of the individuals concerned. Individuals can object to this processing. See Section 14 (Your rights).
We will not use personal data for a new purpose that is incompatible with the purposes above without first updating this policy and, where required, establishing a lawful basis.
5. Publication of Published Rating Data (Ratings, Scorecards, and Badges) and the personal data in them
We publish Ratings, Scorecards, and Badges (together, “Published Rating Data”, as defined in the Terms and Conditions) on public company profiles. These publications can include personal data about a rated company’s directors, officers, or named personnel, usually in their professional capacity (for example, the name and role of a signatory to a policy, or an executive named in a regulatory action).
What a Rating is. A Rating is our independent opinion. It is not a certification, an audit, or an assurance engagement (see Terms and Conditions clause 3). Publication is a deliberate editorial and analytical decision that we make as a controller.
Lawful basis. We publish this personal data on the basis of our reliance on Article 4 of the PDPL, which permits processing without the data subject’s consent where the processing is necessary to protect the public interest. Most of the personal data we publish is professional-capacity information about directors, officers, and named personnel of rated entities, sourced from official registries, regulators, and public reporting. We rely on the Article 4 “made public by an act of the data subject” ground only in the limited cases where the individual has themselves made the information public (for example, a policy they have publicly signed or a public statement they have made). We balance our processing against the rights and freedoms of the named individuals, we publish no statement of fact we know to be false, and our publication is made in good faith as an analytical opinion.
Safeguards and recourse. If you are a named individual, you can:
- ask us to correct a factual error;
- query how you have been described; or
- object to your inclusion.
We review each request on its merits, we log our decision, and we tell you the outcome. Where we continue to process or publish your data, we will explain why the public-interest purpose justifies it. See Sections 14 and 19 for how to make a request and how to complain.
6. Continuous surveillance and controversy monitoring
We run continuous surveillance and controversy monitoring of rated entities. We track:
- regulators and enforcement bodies;
- news and adverse-media;
- official and corporate registries; and
- sanctions lists and watchlists.
We do this to detect controversies that affect a rated entity’s ESG profile.
This monitoring can involve personal data about individuals connected to rated entities (for example, a director named in an enforcement action). This data is obtained from independent third-party sources, not from the individual. We do not rely only on what a company submits about itself.
Lawful basis. We rely on the Article 4 public-interest ground (processing necessary to protect the public interest), balanced against data-subject rights. Monitoring is limited to information relevant to ESG assessment.
Data-quality practices. We attribute sources, we apply human analyst review to adverse findings, consistent with our Methodology and Terms and Conditions clause 14.3, before a controversy affects a published Rating, and we provide correction and objection routes. Controversy deductions ease as remediation evidence is provided, not simply with the passage of time. For how AI is used in this process, see Section 7. For your rights, see Section 14.
7. AI and automated processing
We use AI to extract and analyse information from submitted evidence and from sourced material (consistent with Terms and Conditions clause 15.1). The AI is an input tool. It helps us read and organise documents and findings.
A human analyst reviews before a Rating is issued or published. A Rating is not produced by solely automated decision-making. A human analyst reviews the analysis, applies our Methodology, and is accountable for the outcome. The AI does not itself issue a Rating.
Because there is meaningful human review in the process, a Rating is not a decision based solely on automated processing that produces legal or similarly significant effects on an individual (Art. 18). Even so, we provide safeguards:
- human-in-the-loop review of AI outputs and of adverse findings;
- accuracy checks against sources; and
- the ability to contest a Rating outcome or the personal data used in it.
Logic and consequences. In outline, our process uses AI to read and structure source material; a human analyst then applies our published Methodology to assign scores and Verification Levels. The main consequence for a named individual is that they may be identified in a published Rating or controversy record in their professional capacity. We have carried out a data protection impact assessment for this pipeline and review it as the technology changes. You can contest any outcome as set out in Section 14.
We use AI tools and vendors as sub-processors. These are covered at a high level in Section 10 (Who we share data with) and, where relevant, in Section 11 (International data transfers).
8. Cookies and similar technologies
We use cookies and similar technologies on esgrated.com. We group them as follows:
- Strictly necessary: needed for the site and platform to work (for example, security and session handling). These are always active.
- Functional / preferences: remember your choices and settings.
- Analytics / performance: help us understand how the site is used so we can improve it.
We use google analytics to measure and improve site performance. Usage data is collected through the site using these technologies. A full cookie table listing each cookie, its purpose, whether it is first- or third-party, and its retention period is available.
Your control. Strictly necessary cookies are always on. Analytics and other non-essential cookies are set only with your consent, which is the lawful basis for them under the PDPL (Art. 6). You can accept, reject, or manage non-essential cookies through our cookie banner and preferences . You can also control cookies through your browser settings.
9. Marketing and your choices
We market our B2B service to business contacts. We use business-contact data (such as name, company, business email, and role) for outreach, newsletters, event follow-up, and lead management.
Lawful basis. We rely on consent where consent is required for electronic direct marketing (Art. 6). Where we contact existing business contacts about our B2B service, we rely on the Article 4 grounds that permit processing necessary for our legitimate business relationship with the recipient, and we honour every opt-out. The PDPL does not contain a standalone “legitimate interests” basis; we use that phrase only descriptively. Every marketing message includes a way to opt out.
Channels. We market by email and similar channels. We are a paid, business-to-business service with no free consumer tier, so our communications are aimed at business prospects and customers, not consumers.
Your choices. You can opt out of marketing at any time, using the unsubscribe link in any message, your preference settings, or by contacting us at [dpo@esgrated.com]. Opting out of marketing does not affect the Services you receive or our rating and monitoring processing, which rest on separate lawful bases.
10. Who we share data with (recipients and sub-processors)
We share personal data with the following categories of recipient, in our controller role:
- hosting and cloud infrastructure providers;
- IT and security providers;
- analytics and marketing tools;
- payment and billing providers;
- professional advisers (for example, lawyers and auditors); and
- AI and data-processing vendors.
We maintain a current list of our controller-role sub-processors, which names each provider, the service it performs, and its processing location. We update this list when a sub-processor is added or replaced. You can subscribe to change notifications at that page.
Our sub-processors are bound by contractual data-protection obligations and act on our instructions. We may also disclose personal data:
- where required by law, or to a regulator (including the UAE Data Office); and
- in connection with a corporate transaction (such as a merger, acquisition, or reorganisation), subject to appropriate protections.
This section covers our controller-role sharing. It is different from the processor-role sub-processing that applies to personal data inside a Customer’s Submitted Evidence, which is governed by the DPA (see Section 2).
11. International data transfers
We may process personal data outside the UAE, including through our hosting and our sub-processors. Our primary hosting is in [hosting region, previously described as the EU].
The PDPL allows transfers of personal data outside the UAE:
- to a country or territory that the UAE Data Office recognises as providing an adequate level of protection (Art. 22); or
- where there is no adequacy finding, on the basis of appropriate safeguards (such as contractual clauses obliging the recipient to protect the data to PDPL standards) or another lawful transfer condition under Art. 23 (including the data subject’s explicit consent, transfer necessary to perform a contract, transfer necessary for the public interest, or transfer necessary to establish or defend a legal claim).
We rely on [Art. 23 contractual safeguards / an adequacy finding / another mechanism]. As of publication, no UAE Data Office adequacy list has been published, so in practice we expect to rely on Article 23 contractual safeguards unless and until the Data Office issues an adequacy decision. The specific countries and mechanisms for each provider are shown on our sub-processor list . Our sub-processor locations may change over time.
If you would like more detail about the safeguards we use for a specific transfer, contact us at [dpo@esgrated.com].
12. How long we keep data (retention)
We keep personal data only for as long as we need it, then we delete, anonymise, or archive it. Our retention periods by category are:
- Account and user data: for the life of the business relationship.
- Billing and commercial records: for the period required by UAE legal and tax rules.
- Marketing data: until you opt out, plus a short period . We keep a suppression record so we can honour your opt-out.
- Website and analytics data: [server and security logs, e.g. 12 months; analytics per provider settings].
- Support correspondence: [period, e.g. 12 months,] after the ticket is closed.
- Breach records: [period, e.g. 5 years] from the date of the incident, to meet accountability requirements.
- Rating and monitoring data: for as long as the public-interest ESG-transparency purpose applies (see below).
Published Rating Data and the personal data within it may be retained and may remain public for as long as the public-interest ESG-transparency purpose applies. It is subject to correction, updating, and objection handling. A withdrawn Rating is shown as “Withdrawn, no longer monitored as of [date]” rather than being silently removed (see Terms and Conditions clause 14.2). This retention is consistent with our Terms and Conditions and with our right to retain Published Rating Data and Statistical Data.
We set retention periods based on why we hold the data, any legal or tax requirement, and the public-interest purpose of published ESG information. Where a specific period is not fixed above, we retain data no longer than necessary for the purpose and any applicable UAE legal or tax requirement, and we review retention at least annually.
13. How we protect data (security)
We use technical and organisational measures appropriate to the risk, including:
- access controls and role-based access;
- encryption of data in transit and at rest;
- network and application security;
- logging and monitoring;
- regular vulnerability scanning and periodic penetration testing;
- secure, tested backups and recovery procedures;
- pseudonymisation or anonymisation of data where it is not necessary to retain it in identifiable form; and
- due diligence on the vendors we use.
We also apply internal governance: staff are bound by confidentiality, access is limited to those who need it, our analysts are kept separate from commercial data where relevant, and staff receive security training.
No system can be perfectly secure. We maintain incident-response processes to detect, assess, and respond to security events. See Section 15 (Personal data breaches).
14. Your rights under the PDPL and how to exercise them
Under the PDPL, you have the following rights over your personal data:
- Right to information and access: to be told how we process your personal data, and to obtain a copy of it (Art. 13).
- Right to portability: to receive your data in a structured, machine-readable form and, where technically feasible, have it transferred to another controller (Art. 14).
- Right to correction and erasure: to have inaccurate data corrected and, in defined circumstances, deleted (Art. 15).
- Right to restrict processing: to require us to restrict the processing of your data in defined circumstances (Art. 16).
- Right to stop processing: to require us to stop processing your data in defined circumstances, including for direct marketing and statistical-survey purposes (Art. 17).
- Right to object to automated processing, including profiling, where a decision is based solely on automated processing and produces legal effects concerning you or similarly significantly affects you (Art. 18).
- Right to withdraw consent at any time, where we rely on consent (Art. 6). Withdrawal does not affect processing that already took place.
- Right to opt out of direct marketing at any time (see Section 9 for how).
- Right to complain to us and to the UAE Data Office if you are unhappy with how we handle your data (see Section 19).
How these rights apply to published Ratings and to monitoring data. If you are named in a published Rating or in our controversy monitoring, and the data was sourced from third parties, you can still ask us to correct inaccurate data, object to or ask us to stop processing your data, and object to any solely automated assessment about you (Art. 18). Because we publish in the public interest, we will weigh your objection against that purpose. We review each request on its merits, we record our decision, and if we continue processing we will explain why the public-interest purpose justifies it.
How to make a request. Contact us at [dpo@esgrated.com,]. To protect your data, we may ask you to verify your identity before we act. We will respond without undue delay, and in any event within the period required by the PDPL and its Executive Regulations. As a service commitment, we aim to respond within 30 days of a valid request. If a request is complex, we may need more time and will tell you.
Fees and limits. There is normally no fee. We may decline or charge for requests that are clearly unfounded or excessive (for example, repetitive or made in bad faith), and we will explain our reasons. If you are not satisfied with our response, you can complain to us and to the UAE Data Office. See Section 19.
15. Personal data breaches
We maintain procedures to detect, assess, and respond to personal data breaches.
Where the PDPL requires it, we will notify the UAE Data Office immediately after becoming aware of a personal data breach that would prejudice the privacy, confidentiality, or security of your personal data, within the period and in accordance with the procedures set by the PDPL and its Executive Regulations (Art. 9). Where such a breach relates to your personal data, we will also notify you in accordance with those requirements. We keep records of breaches and the action we take.
If you think a breach has happened, or you have a security concern, please tell us at [dpo@esgrated.com].
16. Children
ESG Rated is a business-to-business service that is not directed to children. We do not knowingly collect personal data from children.
Any personal data about individuals that appears in ESG sources is processed in a professional or business context (for example, a company director named in a public record), not as consumer data about a minor.
If we learn that we have inadvertently collected a child’s personal data, we will delete it promptly. If you believe we hold a child’s data, contact us at [dpo@esgrated.com].
17. Third-party links
Our website, company profiles, and monitoring outputs may link to third-party websites and sources, such as registries, news outlets, and regulators.
We are not responsible for the privacy practices of those third parties. Their own privacy policies apply to any data you provide to them. We encourage you to review a third party’s privacy policy before providing your data to it.
18. Changes to this policy
Where a change is material, we will communicate it If you keep using the site or the Services after we update this policy, the updated policy applies to you. We do not treat continued use as your consent to processing. Where the PDPL requires consent for any processing, we will obtain that consent separately in a clear and specific way (Art. 6). For changes that require your consent, we will not rely on continued use: we will ask you again.
19. How to complain
If you have a concern about how we handle your personal data, please contact us first at dpo@esgrated.com, so we can try to resolve it. We will acknowledge your concern, look into it, and respond.
