Legal
Privacy
What we collect, why we collect it, how long we keep it, and what you can ask us to do about it.
Last updated: 30.08.2026
Controller
TME Services FZCO
HDS Business Center Tower, Office 2305
Jumeirah Lake Towers (JLT)
Dubai, United Arab Emirates
TME Services FZCO decides why and how personal data is processed on this website and in our client work. Uwe Hohmann, Chief Executive Officer, answers data protection questions. Write to us at:
Which law applies
We are established in Dubai and bound by UAE data protection law, in particular Federal Decree Law No. 45 of 2021 on the Protection of Personal Data. Because we address and serve clients in Germany, Austria and Switzerland, the GDPR also applies to this website under its Art. 3 (2). This policy is written to the GDPR standard, which is the stricter of the two.
When you visit this website
This website is a set of static pages. There is no account, no login and no registration. As on every website, our hosting provider records a log entry for each request, containing:
- the IP address of the requesting device
- the page requested, with the date and time of the request
- browser type and version, and the operating system used
- the page you came from, if your browser sent one
- the amount of data transferred and whether the request succeeded
We use these entries to deliver the site, to keep it stable and to recognise attacks on it. The legal basis is our legitimate interest in a secure and functioning website, Art. 6 (1) (f) GDPR. The entries are not merged with other data, are not used to identify you, and are deleted or shortened by our hosting provider after a short period. The hosting provider acts on our instructions under a data processing agreement.
No cookies, no tracking
This website sets no cookies, stores nothing in your browser and runs no analytics, no advertising and no tracking pixels. There is no consent banner because there is nothing to consent to.
Fonts, images and scripts are delivered from our own domain. The site makes no request to a third party server, so no data about your visit reaches Google, Meta or any other provider while you read these pages.
The office address links to Google Maps and the team profiles link to LinkedIn. Those are ordinary links: nothing loads from Google or LinkedIn until you click, and once you do, the privacy notice of that provider applies instead of this one.
When you contact us
The contact form asks for your name, your email address, the topic of your enquiry and your message. The company field is optional. We use what you send to answer you and to prepare a possible engagement, and for nothing else. The same applies when you reach us by email, by phone or by post.
The legal basis is Art. 6 (1) (b) GDPR for steps taken at your request before a contract, and our legitimate interest in answering business enquiries, Art. 6 (1) (f) GDPR.
Messages sent through the form reach our mailboxes through Brevo, an email service provider in the European Union, which acts as our processor under a data processing agreement. The form carries simple spam protection that checks the submission itself and builds no profile of you.
An enquiry that leads to no engagement is kept for up to twelve months, so that we can pick up the thread if you come back to us, and is then deleted. A legal retention obligation, where one applies, takes precedence over that.
When you become a client
An engagement brings more data with it: company documents, passport copies and identification data for the persons involved, addresses, accounting records, tax registration numbers and the correspondence in your matter.
We process it to carry out the engagement, Art. 6 (1) (b) GDPR, and to meet the duties UAE law places on us, Art. 6 (1) (c) GDPR. Those duties include identifying clients and beneficial owners and keeping records under UAE anti money laundering, tax and company law.
Where an engagement requires a filing with a UAE authority, a free zone, a bank or an auditor, only the data that the filing requires is passed on.
Who receives your data
- our hosting provider, which operates the servers this website runs on
- Brevo, which delivers the messages sent through the contact form
- inside TME Services, the colleagues who work on your matter
- UAE authorities, free zone authorities, banks and auditors, where an engagement requires a submission to them
- our IT service providers, where access is needed to maintain the systems
We do not sell personal data, we do not pass it on for advertising, and we build no profiles from it.
Transfer to the United Arab Emirates
We sit in Dubai, so data you send us is processed in the United Arab Emirates. The European Commission has issued no adequacy decision for the UAE. That means UAE law is not treated as offering protection equivalent to the GDPR: authorities there may hold access rights that go beyond what EU law permits, and the legal remedies open to you are not the same as those inside the EU.
We transfer the data on the basis of Art. 49 (1) (b) GDPR, because it is necessary to answer your enquiry and to perform the engagement you asked for, and, where that basis does not carry, on your consent under Art. 49 (1) (a) GDPR, which you may withdraw at any time with effect for the future.
How long we keep it
- server log entries: a few days at the hosting provider, then deletion or shortening
- enquiries that lead to no engagement: up to twelve months
- engagement records: for the term of the engagement, then for the retention periods UAE law sets, which run to at least five years for accounting and anti money laundering records
- correspondence: for as long as the matter and any retention obligation require
Your rights
Under the GDPR you have the right to:
- access to the data we hold about you, Art. 15
- rectification of data that is wrong or incomplete, Art. 16
- erasure, Art. 17
- restriction of processing, Art. 18
- portability of the data you gave us, Art. 20
- objection to processing we base on a legitimate interest, Art. 21
Where we process data on your consent, you may withdraw it at any time with effect for the future, Art. 7 (3) GDPR. The withdrawal leaves what was lawful before it untouched.
To exercise a right, write to us at the address at the top of this page. You may also complain to a data protection supervisory authority, Art. 77 GDPR, in the member state where you live, where you work or where you believe the infringement took place.
Data security
This website is delivered over an encrypted TLS connection, which you can see from the https in your address bar. Inside the company, access to client data is limited to the colleagues who need it for the matter, and our systems are run by our own IT team.
No automated decisions
We take no decisions about you by automated means and carry out no profiling within the meaning of Art. 22 GDPR.
Changes to this policy
We update this policy when the website changes or when the law requires it. The version published here is the one that applies, and it carries the date of its last change at the top of the page.