Privacy policy
In effect from 7 September 2026
How Dropxcel handles personal data — both the data we hold about our own visitors, clients and personnel, and the personal data that sits inside the accounting records our clients ask us to work on. Those are two different roles with different rules, and this policy keeps them apart.
1Scope of this policy
This policy applies to dropxcel.com and to personal data Dropxcel handles in the course of its business. Dropxcel provides accounting, taxation, AML compliance and finance operations services to businesses in the UAE and wider GCC. The company is established in India, and our delivery team works from there.
It should be read alongside your engagement letter and any data processing agreement signed with us. Where a signed agreement says something different about client data, that agreement prevails over this policy.
2The two roles we hold
Most of the personal data we touch is not ours. Keeping the distinction clear matters, because it determines who you should approach about it.
As a Data Fiduciary — a controller, in GDPR terms — we decide why and how personal data is processed. This covers visitors to this website, people who contact us, our client and supplier contacts, applicants and our own personnel.
As a Data Processor, we handle personal data inside a client’s accounting records — their employees, customers, suppliers and directors — strictly on that client’s documented instructions. The client decides why and how. If your personal data reached us because you deal with one of our clients, please approach that client. We will support them in responding, and we will tell them if you contact us directly.
3Personal data we collect as a Data Fiduciary
Depending on how you interact with us, this can include:
- Identity and contact data — name, employer, role, email address, telephone number and postal address.
- Correspondence — the content of emails, enquiry messages, meeting notes and call records where you have been told a call is being recorded.
- Engagement data — records needed to scope, price, deliver, invoice and evidence our services, including client due diligence records where we are required to hold them.
- Recruitment data — your application, CV, references, qualifications and interview notes.
- Technical data — IP address, browser type, approximate location derived from IP, and pages requested, held in standard server logs.
We do not seek special category or sensitive personal data through this website. Please do not send it to us in an unsolicited enquiry.
4Why we process it, and on what basis
- To respond to your enquiry and to scope work — because you asked us to, and to take steps before entering a contract.
- To deliver, administer and invoice our services — to perform our contract with you or with your employer.
- To meet legal and regulatory obligations — including record-keeping under the Companies Act 2013, the Income-tax Act 1961 and the goods and services tax legislation, and anti-money-laundering obligations where they apply to an engagement.
- To keep our systems and records secure, and to investigate suspected misuse — because we have a legitimate interest in protecting our business and our clients, having weighed that against your interests.
- To assess applications for employment — to take steps before entering a contract with you, and with your consent where consent is the appropriate basis.
Where we rely on your consent, you can withdraw it at any time. Withdrawal does not affect processing already carried out, and it will not affect processing we are legally required to continue.
5Client data we process on instructions
When we work on a client’s books, payroll or filings, we act only within the instructions recorded in the engagement letter and any data processing agreement. In particular:
- We do not use client data for our own purposes, and we never sell it.
- We do not move client data outside the systems agreed with the client.
- We engage a sub-processor only where the client has agreed to it, and we remain answerable for that sub-processor’s performance.
- Everyone working on a file is bound by individual confidentiality obligations and is given access only to what their role requires.
- On termination we return the client’s records in a usable format and delete our copies on the agreed timetable, retaining only what law requires us to keep.
If we become aware of a personal data breach affecting client data, we notify the client without undue delay so that they can meet their own obligations, and we support their response.
6Who we share personal data with
- Service providers who support our operations — cloud hosting, email, document storage, accounting and payroll platforms — under contracts that restrict them to our instructions.
- Professional advisers, including our auditors, lawyers and insurers, where they need it to advise us.
- Courts, regulators, tax authorities and law enforcement, where we are legally required to disclose or where disclosure is necessary to establish or defend a legal claim.
- A buyer or successor, if the business or part of it is transferred, subject to equivalent protections.
We do not sell personal data, and we do not share it for third-party advertising.
7Transfers across borders
Our operations are in India, so personal data you send us is processed there, and client records are accessed from there by the engagement team. Clients are told this before an engagement begins, and it is recorded in the engagement letter.
Because our clients are established outside India, the data protection law of their own jurisdiction will usually apply alongside ours — commonly the UAE Personal Data Protection Law, and the GDPR where a client has a European establishment or customers. Transfers are governed by the terms of the relevant agreement, including standard contractual clauses where the GDPR requires them. We do not transfer personal data to a country where the transfer is barred by applicable law.
8How long we keep it
We keep personal data only as long as it is needed for the purpose it was collected for, and then for as long as the law requires. In practice:
- Enquiries that do not become engagements are deleted within twenty-four months.
- Our own engagement and accounting records are retained for the statutory periods that apply to us in India, which for certain books of account run to eight financial years. Records we hold on a client’s behalf are retained for the period their own law requires — for businesses in the UAE, generally at least five years for accounting, VAT and corporate tax records, and longer for certain real estate and AML records.
- Unsuccessful recruitment records are deleted within twelve months unless you agree we may keep them longer.
- Server logs are retained for a short operational period and then discarded.
9How we protect it
- Access is granted by role on a least-privilege basis, reviewed periodically, and revoked when someone leaves an engagement or the company.
- Traffic to this website and to the systems we use is encrypted in transit.
- Client engagements are kept in separate workspaces; working files are not commingled and credentials are not shared between engagements.
- Every person on an engagement is individually bound by confidentiality and data-handling obligations.
- We maintain a documented incident response and backup procedure, and we test restoration.
No system is perfectly secure. If a breach occurs that is likely to affect you, we will notify you and the Data Protection Board of India, and any other authority we are required to notify, within the time limits that apply.
10Your rights
Under the Digital Personal Data Protection Act 2023, where we are the Data Fiduciary, you may:
- Ask what personal data of yours we are processing and who it has been shared with.
- Ask us to correct, complete or update inaccurate personal data.
- Ask us to erase personal data where we no longer need it and no law requires us to keep it.
- Withdraw a consent you previously gave.
- Nominate another person to exercise these rights on your behalf in the event of your death or incapacity.
- Raise a grievance with us, and escalate to the Data Protection Board of India if you are not satisfied with our response.
Where the UAE Personal Data Protection Law or the GDPR applies to processing carried out for a client, you have equivalent rights under that law — including access, rectification, erasure, restriction, portability and objection — and the right to complain to the relevant authority. Those rights are exercised against the client who controls the data, and we will support them in answering you.
To exercise any of these, write to contact@finanshels.com. We may need to verify your identity before we act. We aim to respond within thirty days and will tell you if we need longer.
11Cookies and site measurement
This website is a static set of pages. It does not set advertising cookies, and it does not track you across other websites.
Our hosting provider keeps standard server logs, including IP address and requested page, to deliver the site and to detect abuse. If we later add analytics or any cookie that is not strictly necessary, we will update this policy and ask for consent where consent is required.
12Children
This website and our services are directed at businesses, not at children. We do not knowingly collect the personal data of a child through this site. If you believe a child has provided us with personal data, contact us and we will delete it.
13Changes to this policy
We update this policy when our practices or the law change. The date at the top of the page is the date the current version took effect. Where a change materially affects how we handle your personal data, we will tell you directly rather than rely on you noticing this page.
14Contact and grievances
Questions, requests and grievances about personal data go to contact@finanshels.com, addressed to the Grievance Officer.
The name and postal address of the Grievance Officer, and our registered office, are provided on request and are set out in every engagement letter.
If we cannot resolve your grievance, you may complain to the Data Protection Board of India, or to your own supervisory authority where the GDPR applies.