← Back to onahagroup.com

Data Privacy Notice

Last updated: 16/07/26 · Version 1.0.

1. Purpose of this Notice

Onaha Group (“Onaha”, “we”, “us”, “our”) provides corporate advisory, corporate services, management, and family office and wealth advisory services to entrepreneurial families and founders across the Africa–Gulf corridor. Delivering those services means we necessarily hold personal information about our clients, their families, their representatives, and other individuals connected to our work.

This Data Privacy Notice (the "Notice") explains, in plain terms, what personal data we collect, why we collect it, who else touches it (including the technology providers we rely on), where it is held, and what control you retain over it. It is written to apply across the whole Onaha Group, regardless of which entity you are dealing with, and is intended to satisfy the disclosure obligations under the data protection laws applicable to our operating jurisdictions, including the Mauritius Data Protection Act 2017 and UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.

2. The Onaha Group entities

Onaha operates through various entities in Dubai, UAE and in Mauritius. This Notice covers all of them; where the practices of a specific entity differ, that entity will tell you so directly as part of your engagement.

Whichever entity you sign an engagement letter with is the controller responsible for your personal data in connection with that engagement. Because our service model is deliberately integrated, your data may be shared between Onaha entities where doing so is necessary to deliver the service you've engaged us for. It is not shared more widely than that without telling you.

3. Personal data we hold, and why

The personal data we collect falls broadly into these categories, and we use it for the purposes set out below:

  • Identity and contact details (name, date of birth, nationality, passport or ID number, address, phone, email) — to open and maintain your relationship with us and to correspond with you.
  • Client due diligence and source-of-wealth information — because we operate as regulated corporate and fiduciary service providers, we are legally obliged to verify who our clients are and where their funds originate, before and throughout an engagement.
  • Structuring, governance and succession information — details of shareholdings, entities, family relationships and succession plans, to the extent relevant to the mandate you've given us.
  • Financial and tax reporting information — where your structure requires reporting under FATCA, the OECD Common Reporting Standard, or equivalent regimes, we collect and process the data needed to meet those obligations.
  • Correspondence and meeting records — to keep an accurate account of the advice and instructions exchanged between us.
  • Recruitment data — where you apply for a role at Onaha, the information in your application and any related assessment.
  • Marketing contact details — for prospective clients and business contacts we engage with, including through LinkedIn, for the purpose of sharing relevant updates about our work.

Most of this processing is necessary for us to perform our contract with you, or to comply with the legal and regulatory obligations that come with being a licensed corporate and fiduciary services group. Where we instead rely on your consent — principally for marketing communications to prospective clients — you can withdraw it at any time, and we will stop.

4. Where your data comes from

Usually, directly from you or your authorised representatives, in the course of onboarding and throughout our engagement. We supplement this with information from public professional sources such as LinkedIn and company or regulatory registries, and, as part of our due diligence obligations, from independent screening databases used to verify identity and reputational standing. We do not pass this information to outside parties for that screening — the checks are carried out by our own compliance function — except where a regulator or law enforcement authority formally requires it of us.

5. The technology we use to do our work

Onaha does not run its own servers. We rely on a small number of well-established technology providers, engaged under contract, to help us work securely across our Dubai and Mauritius offices. Each of them processes personal data only on our instructions, only for the purposes we set, and is contractually barred from using it for anything else. In practice, that means:

  • Microsoft 365 handles our email, calendars and day-to-day document work.
  • Claude, an AI assistant built by Anthropic, helps our team with drafting, research and internal analysis. We treat information shared with it under the same confidentiality standard that governs everything else we do: we give it only what a task genuinely requires, we don't let it make decisions on a client's behalf, and a member of our team reviews anything AI-assisted before it goes any further.
  • A CRM platform (currently Microsoft Dynamics 365) keeps our client and prospect records organised so nothing falls through the cracks between team members or entities.

The Annex to this Notice lists our current providers by name. We periodically review and, where appropriate, change these providers; swapping one properly vetted provider for another of equivalent standard does not, on its own, change anything material about how your data is protected, so we don't treat it as requiring a rewrite of this Notice.

6. Where your data is held, and how it moves

Your personal data may be processed outside the country in which you are based — most of our technology providers operate international infrastructure, and our CRM data, for example, is currently held within the European Union. It may also move between Onaha's own entities in Dubai and Mauritius, strictly where necessary to deliver your engagement, under internal arrangements intended to keep the same standard of protection wherever the data sits. If a client mandate carries a specific data residency requirement — which can arise depending on your own jurisdiction — we address that directly with you rather than relying on this general statement alone.

7. How long we keep it

We keep personal data for as long as our engagement with you continues, and afterwards for whatever period our legal, regulatory and fiduciary obligations require — this commonly runs 7 to 10 years post-engagement given AML/CFT, corporate services and FATCA/CRS record-keeping rules in the UAE and Mauritius, though the precise period depends on the nature of the mandate. Where no specific legal minimum applies, we keep data only as long as we have a genuine business reason to.

8. Keeping it confidential and secure

Confidentiality is not a policy add-on for us — it sits at the core of the fiduciary duty we owe our clients. Access to your data is limited to Onaha staff who need it to do their job, our systems are run on infrastructure with recognised security certifications, and every member of our team is bound by confidentiality obligations that survive their time working with us. Our IT environment includes back-up and recovery arrangements, and we review our security posture, and that of our technology providers, on an ongoing basis. If something ever goes wrong and your data is affected by a breach, we will tell you and the relevant regulator without unreasonable delay, as required by law.

Our website, onahagroup.com, does not currently use cookies or any similar tracking technology. If that changes — for example, if we add analytics or an interactive tool to the site in future — we will update this section accordingly and, where the law requires it, ask for your consent before setting anything beyond what's strictly necessary for the site to function.

9. Your rights, and how to use them

Wherever you are based, you can generally expect to be able to:

  • Ask us what personal data we hold about you, and get a copy of it.
  • Ask us to correct anything that's wrong or out of date.
  • Ask us to delete your data, or stop or limit how we use it, though this is subject to the legal and fiduciary retention obligations described in Section 7.
  • Withdraw consent, where consent is the basis for our processing (see Section 3).
  • Ask for your data in a format you can take elsewhere, where that's technically practical.
  • Complain to the relevant data protection authority — see Section 11.

To use any of these, contact us using the details in Section 10. We handle each request individually and will respond within the timeframe the applicable law sets; in rare cases where a request is unusually broad or resource-intensive, we may charge a reasonable fee to cover the cost of fulfilling it, and we'll tell you in advance if that applies.

10. How to reach us

11. If you're not satisfied

If you've raised a concern with us and aren't happy with how it was handled, you're entitled to take it to the relevant regulator directly:

  • Mauritius — the Data Protection Office, 5th Floor, SICOM Tower, Wall Street, Ebene Cybercity, Mauritius (dpo@govmu.org).
  • United Arab Emirates — the UAE Data Office, established under Federal Decree-Law No. 44 of 2021.

12. Keeping this Notice up to date

We'll revise this Notice as our practices, our service providers, or the law around us change. The date at the top tells you when it was last updated, and we'll reach out directly to active clients if a change is significant enough to matter to you.

Annex — Technology providers currently in use

Listed here for transparency. This list may be updated from time to time as our technology stack evolves; doing so does not, on its own, amount to a material change to this Notice, provided the standard of protection described in Section 5 is maintained.

  • Email, calendar and document hosting and collaboration: Microsoft 365 and SharePoint (Microsoft Corporation / Microsoft Ireland Operations Limited).
  • AI-assisted drafting, research and analysis: Claude (Anthropic, PBC).
  • Client relationship management: Microsoft Dynamics 365 (Microsoft Corporation / Microsoft Ireland Operations Limited).