PRIVACY POLICY – BEST BRAINS MENA REGION
1. Introduction
Best Brains Corporate MENA, together with its applicable affiliates, regional offices, and corporate entities ("Best Brains," "we," "us," or "our"), respects your privacy and is committed to protecting personal data in accordance with applicable privacy and data-protection laws.
This Privacy Policy explains how we collect, use, disclose, store, transfer, retain, and protect personal data when you:
- Visit https://bestbrains.com/mena-en/ or another website that links to this Privacy Policy
- Submit an inquiry about Best Brains programs or learning centers
- Request a placement test, consultation, orientation, or appointment
- Submit a franchise, business, vendor, employment, or partnership inquiry
- Subscribe to marketing communications
- Communicate with our corporate office
- Participate in a survey, event, promotion, or campaign
- Otherwise interact with Best Brains through an online or corporate service covered by this Privacy Policy.
This Privacy Policy includes regional and country-specific provisions in Schedule A. If a country-specific provision conflicts with the general provisions of this Privacy Policy, the country-specific provision will apply to the extent required by applicable law.
2. Who Is Responsible for Your Personal Data?
For personal data collected through the corporate MENA website, the data controller or responsible entity is generally:
Best Brains Inc.
Email: info@bestbrains.com
Telephone: +1 800-817-1025
The Best Brains franchise network includes independently owned and operated learning centers. A local franchisee may act as a separate data controller or responsible entity for personal data that it collects and uses for its own enrollment, billing, staffing, classroom, parent communication, or center-management purposes.
When you ask to be contacted by a learning center, we may send your information to the center that serves your selected or approximate location. That center's own privacy notice may also apply to its subsequent use of your information.
3. Scope of This Privacy Policy
This Privacy Policy applies to the corporate MENA website and the corporate activities described above.
Separate privacy notices or agreements may apply to:
- Enrollment at an independently owned Best Brains learning center
- Student educational records
- Classroom assessments and placement tests
- Parent, teacher, student, or franchisee portals
- bbConnect, bbParent, bbSupport, Slate, or other Best Brains applications
- Payment-processing services
- Employee and contractor records
- CCTV or security systems at physical locations
- Services offered directly by a local franchisee or third party.
Where another notice applies, that notice should be read together with this Privacy Policy.
4. Meaning of Personal Data
"Personal data" means information relating to an identified or identifiable natural person. Depending on applicable law, this may also be referred to as personal information, personally identifiable information, or data of a personal character.
Personal data may include information that identifies you directly, such as your name or email address, as well as information that may identify you indirectly when combined with other information, such as an IP address, device identifier, location, or online activity.
"Sensitive personal data" may include information concerning health, biometric identifiers, children, religion, ethnicity, political opinions, criminal history, financial information, precise location, or other categories given additional protection under applicable law.
5. Personal Data We Collect
Depending on how you interact with us, we may collect the following categories of personal data.
5.1 Identity and Contact Information
This may include:
- Name
- Postal address
- Email address
- Telephone number
- Country, city, region, or preferred learning-center location
- Preferred language
- Parent, guardian, student, business, or professional relationship.
5.2 Parent, Guardian, and Prospective Student Information
When a parent or guardian requests information about a Best Brains program, we may collect:
- The parent's or guardian's name and contact information
- The child's first name or initials
- The child's age, year of birth, grade, or approximate educational level
- Subjects or programs of interest
- Preferred center, class time, or appointment time
- General educational goals or areas where support is requested
- Information included voluntarily in an inquiry.
Parents and guardians should not submit medical diagnoses, disability information, school records, identification documents, or other sensitive information through a general website inquiry form unless the form specifically requests that information and explains why it is needed.
5.3 Franchise and Business Inquiry Information
This may include:
- Business and professional contact details
- Employment and educational background
- Business ownership or management experience
- Preferred development territory
- Approximate investment capability or financing information
- Information about proposed premises or business partners
- Communications with the franchise-development team
- Supporting documents voluntarily provided by the applicant.
A separate franchise application notice may apply where more detailed financial, identification, background, or due-diligence information is requested.
5.4 Employment and Recruitment Information
If you apply for a position, we may collect:
- Résumé or curriculum vitae
- Work history
- Education, qualifications, and certifications
- Professional references
- Interview notes
- Work-authorization information
- Compensation expectations
- Other information relevant to the application.
Sensitive information will be collected only where permitted or required by law and where appropriate safeguards are used.
5.5 Communications and Customer-Service Information
We may collect:
- Emails, messages, and correspondence
- Inquiry details
- Appointment or booking information
- Feedback, complaints, and survey responses
- Call notes and, where lawfully disclosed, recordings
- Social-media messages
- Records of requests made to our corporate teams.
5.6 Website, Device, and Technical Information
When you use our website, we may automatically collect:
- IP address
- Browser type and version
- Device type
- Operating system
- Language and time-zone settings
- Approximate location derived from an IP address
- Referral source
- Pages viewed
- Links selected
- Date, time, and duration of visits
- Cookie identifiers
- Advertising identifiers
- Website performance, diagnostics, security, and error information.
5.7 Marketing and Preference Information
This may include:
- Newsletter subscriptions
- Communication preferences
- Consent records
- Campaign engagement
- Event registrations
- Promotion participation
- Subjects, programs, or locations of interest
- Records of marketing opt-outs.
5.8 Transaction Information
Where the corporate website accepts payments or fees, we may collect:
- Billing contact information
- Transaction date and amount
- Payment status
- Invoice or reference number
- Limited payment-card information supplied by the payment processor.
We do not intend to store complete payment-card numbers or security codes unless expressly disclosed and lawfully permitted. Payment providers process payment information under their own terms and privacy notices.
5.9 Sensitive Personal Data
We do not seek to collect sensitive personal data through general website forms unless it is reasonably necessary, legally permitted, and clearly disclosed.
Where sensitive personal data is required, we will use an appropriate lawful basis, obtain explicit or written consent where required, and implement additional security and access controls.
6. How We Collect Personal Data
We may collect personal data:
6.1 Directly From You
For example, when you complete a form, contact us, schedule an appointment, register for an event, submit an application, or provide consent.
6.2 From a Parent, Guardian, Family Member, or Authorized Representative
A parent or guardian may provide limited information concerning a child. A business representative may provide information about colleagues, partners, or employees.
Anyone providing information about another person must be authorized to do so and must provide that person with any legally required notice.
6.3 From Best Brains Affiliates and Franchisees
A local center or regional office may refer an inquiry, complaint, business opportunity, or support request to the corporate office.
6.4 Automatically
We collect certain information through cookies, pixels, tags, server logs, software development kits, and similar technologies.
6.5 From Service Providers and Business Partners
We may receive information from appointment-booking providers, advertising platforms, social-media services, lead-management systems, payment processors, event providers, recruitment platforms, and technology suppliers.
6.6 From Public or Professional Sources
For franchise, vendor, employment, or business purposes, we may obtain information from professional networking platforms, company websites, public corporate registries, references, or other lawful public sources.
7. Why We Use Personal Data
We process personal data only where we have a lawful basis under applicable law. Depending on the circumstances and jurisdiction, this may include consent, explicit consent, contractual necessity, steps requested before entering a contract, compliance with a legal obligation, protection of vital interests, legitimate interests, establishment or defense of legal claims, or another basis recognized by applicable law.
We may use personal data for the following purposes.
7.1 Responding to Inquiries
We use contact and inquiry information to:
- Answer questions
- Recommend an appropriate program or center
- Arrange a placement test, consultation, or appointment
- Send requested information
- Follow up on an inquiry.
7.2 Routing Inquiries to Local Learning Centers
We may use your location and program preferences to identify and refer you to a nearby Best Brains center.
Where required, we will obtain consent before sending your information to an independently owned franchisee.
7.3 Providing Corporate and Website Services
We use personal data to:
- Operate and maintain the website
- Authenticate or manage accounts
- Provide requested resources
- Administer events, surveys, and promotions
- Process permitted payments
- Provide technical and customer support.
7.4 Franchise Development and Business Relationships
We may use personal data to:
- Evaluate franchise inquiries
- Communicate about available territories
- Conduct preliminary eligibility or suitability reviews
- Arrange meetings
- Manage vendor, landlord, broker, and business-partner relationships
- Perform due diligence where legally permitted
- Prepare or administer business agreements.
7.5 Recruitment
We may use applicant information to:
- Assess applications
- Conduct interviews
- Verify qualifications and references
- Communicate with candidates
- Comply with employment laws
- Maintain records of recruitment decisions.
7.6 Marketing
Subject to applicable consent requirements, we may use personal data to:
- Send newsletters and program information
- Advertise grand openings, open houses, promotions, and events
- Personalize communications
- Measure campaign effectiveness
- Create audiences for online advertising.
You may withdraw marketing consent or unsubscribe at any time.
7.7 Analytics and Improvement
We may use aggregated or appropriately protected information to:
- Understand website usage
- Improve navigation and content
- Evaluate campaign performance
- Diagnose technical issues
- Develop new services
- Improve the Best Brains customer experience.
7.8 Security, Fraud Prevention, and Compliance
We may use personal data to:
- Secure our systems
- Prevent fraud, misuse, and unauthorized activity
- Maintain audit trails
- Investigate complaints or suspected violations
- Enforce agreements and policies
- Protect our rights, users, children, employees, franchisees, and the public
- Respond to lawful government or court requests
- Comply with legal, regulatory, tax, accounting, and recordkeeping requirements.
8. Children's Privacy
Best Brains provides educational programs for children, but the corporate website is primarily directed to parents, guardians, adult franchise applicants, job applicants, and business contacts.
Children should not independently submit personal data through the corporate website unless a parent or lawful guardian has authorized the submission and the collection is otherwise permitted by applicable law.
8.1 Parent and Guardian Submissions
Parents and guardians may provide limited information about a child when requesting program information or scheduling an assessment.
We will seek to collect only the minimum information reasonably necessary for the request.
8.2 Consent
Where applicable law requires parental, guardian, child, judicial, or regulatory consent or authorization, we will not knowingly process the child's personal data without the required consent or authorization.
For a regional default, we treat anyone under the age of 18 as a child unless applicable law establishes another relevant age. We may apply a higher level of protection where laws differ.
8.3 Marketing to Children
We do not knowingly use children's personal data for behavioural advertising or send direct marketing communications to a child without legally valid authorization.
8.4 Images and Testimonials
We will obtain appropriate consent before using an identifiable child's photograph, video, voice, artwork, testimonial, or educational achievement for corporate marketing, except where another lawful basis clearly applies.
8.5 Removal Requests
A parent or lawful guardian who believes that a child submitted personal data without proper authorization may contact us at info@bestbrains.com. We will investigate and delete or restrict the information where legally required.
9. Cookies and Similar Technologies
Our website may use cookies and similar technologies.
9.1 Strictly Necessary Cookies
These cookies are required for security, network management, accessibility, form submission, consent management, and basic website functions. They generally cannot be disabled through our cookie preference tool.
9.2 Functional Cookies
These cookies remember preferences such as language, location, or form selections.
9.3 Analytics Cookies
These cookies help us understand website traffic, performance, navigation, and user interaction.
9.4 Advertising Cookies and Pixels
With required consent, these technologies may be used to measure advertisements, limit repeated advertisements, understand campaign conversions, or deliver advertisements based on interests.
9.5 Cookie Consent
Except where applicable law allows otherwise, non-essential cookies will not be activated until you have made a consent choice.
You can manage your choices through the "Cookie Settings" link on our website. Withdrawing consent does not affect the lawfulness of processing completed before withdrawal.
Blocking certain cookies may affect website features.
Additional information should be provided in our Cookie Notice, including the names, providers, purposes, and durations of the cookies used.
10. Direct Marketing
We may send marketing communications where:
- You have given valid consent
- You requested information about a related program or service and applicable law permits follow-up
- The communication is otherwise lawfully permitted
- The communication is sent to a business contact in accordance with applicable law.
Every electronic marketing message will contain an unsubscribe method where required.
You may also opt out by contacting info@bestbrains.com.
We may retain limited suppression information, such as an email address and opt-out status, to ensure that we honor your request.
11. When We Disclose Personal Data
We do not disclose personal data except as described in this Privacy Policy, as authorized by you, or as otherwise permitted or required by law.
11.1 Best Brains Corporate Affiliates
We may disclose personal data to Best Brains corporate entities and regional affiliates for centralized operations, support, administration, compliance, technology, franchise development, and marketing.
11.2 Independently Owned Franchisees
We may disclose an inquiry to an independently owned Best Brains learning center when:
- You select that center
- The center serves your location
- You ask to be contacted
- Disclosure is necessary to respond to your request
- You otherwise authorize the referral.
The local franchisee may be independently responsible for its subsequent use of the information.
11.3 Service Providers
We may engage service providers for:
- Website hosting
- Cloud storage
- Cybersecurity
- Customer-relationship management
- Appointment booking
- Email and communications
- Analytics
- Cookie-consent management
- Advertising
- Payment processing
- Recruitment
- Document management
- Professional support
- Other corporate services.
Service providers may process personal data only for authorized purposes and are required to protect it through appropriate contractual, organizational, and technical measures.
11.4 Professional Advisers
We may disclose information to attorneys, accountants, auditors, insurers, consultants, and other professional advisers where reasonably necessary.
11.5 Authorities and Legal Proceedings
We may disclose personal data:
- To comply with law
- In response to a valid court order, warrant, subpoena, regulatory request, or government demand
- To report suspected unlawful conduct
- To protect legal rights, safety, or security
- To establish, exercise, or defend legal claims.
We will assess requests for legality, necessity, and proportionality where required.
11.6 Corporate Transactions
Personal data may be disclosed in connection with a merger, acquisition, financing, restructuring, sale, transfer, insolvency, or proposed transaction involving all or part of our organization.
Any recipient will be required to process personal data consistently with applicable law.
11.7 With Your Consent
We may disclose information for another purpose that has been clearly explained to you and to which you have validly consented.
12. Sale of Personal Data
Best Brains does not sell or rent personal data in exchange for money.
Where consented to, we may provide limited online identifiers or activity information to analytics or advertising providers. Depending on the law applicable to a particular user, such activity may be treated as advertising disclosure or data sharing and will be managed through our cookie-consent process.
13. International and Cross-Border Transfers
Best Brains may operate across multiple countries and may use service providers whose servers or personnel are located outside the country in which personal data was collected.
As a result, personal data may be transferred to or accessed from the United States, Canada, the United Kingdom, the European Economic Area, India, other MENA countries, or another country in which Best Brains or its approved service providers operate.
Before making a restricted international transfer, we will use a legally recognized transfer mechanism where required. Depending on the applicable law, this may include:
- A regulator-approved destination
- An adequacy determination
- Standard or model contractual clauses
- Binding corporate arrangements
- Explicit consent where legally valid
- Performance of a contract
- A statutory exception
- Regulatory authorization, notification, declaration, or permit
- Data localization
- Supplementary technical and organizational safeguards.
Where required, we will conduct a transfer-risk or transfer-impact assessment.
14. Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, regulatory, contractual, accounting, security, dispute-resolution, and recordkeeping purposes.
Our general retention criteria include:
- General website inquiries: Normally up to 24 months after the last meaningful interaction.
- Placement-test or center-referral inquiries: Normally up to 24 months unless enrollment occurs or local law requires another period.
- Marketing records: Until consent is withdrawn, the person opts out, or the information is no longer useful, plus a limited suppression record.
- Cookie-consent records: For the period necessary to demonstrate consent and comply with applicable limitation periods.
- Franchise inquiries: Normally up to 5 years after the last meaningful interaction or longer where a franchise relationship develops.
- Recruitment records: Normally up to 2 years after the recruitment decision unless another period is required or consented to.
- Business contracts and transaction records: Normally for the contract term and up to 7 years afterward, subject to local requirements.
- Complaints and legal matters: For the duration of the matter and applicable limitation period.
- Security and system logs: For a limited period proportionate to security and operational requirements.
These periods may be shortened or extended where required by local law, regulatory instruction, litigation hold, contract, or operational necessity.
When personal data is no longer required, we will securely delete, destroy, anonymize, or restrict it.
15. Data Accuracy
We take reasonable steps to keep personal data accurate and up to date.
Please notify us at info@bestbrains.com when your contact or other relevant information changes.
16. Security
We use reasonable and appropriate technical and organizational safeguards designed to protect personal data against:
- Unauthorized access
- Unlawful processing
- Accidental loss
- Alteration
- Disclosure
- Destruction
- Misuse
- Other security threats.
Depending on the nature of the information and risk, safeguards may include:
- Access controls
- Role-based permissions
- Multifactor authentication
- Encryption
- Secure transmission
- Network monitoring
- Backups
- Logging
- Vulnerability management
- Employee confidentiality requirements
- Vendor due diligence
- Incident-response procedures
- Staff training.
No internet transmission or electronic storage system can be guaranteed to be completely secure. Users should avoid sending highly sensitive information through an unsecured email or general website form.
17. Personal Data Breaches
We maintain procedures for identifying, investigating, containing, documenting, and responding to personal-data breaches.
Where required by applicable law, we will notify the relevant regulator, authority, affected individuals, controller, or business partner within the legally prescribed period.
Notifications will include the information required by applicable law and will be updated where additional facts become available.
18. Automated Decision-Making and Artificial Intelligence
We may use automated tools to assist with website security, spam prevention, inquiry categorization, analytics, customer support, marketing measurement, or administrative workflows.
We do not intend to make a decision that produces a legally significant or similarly substantial effect on an individual solely through automated processing unless:
- The process is legally permitted
- Appropriate notice has been provided
- Required consent has been obtained
- Suitable safeguards are in place
- A right to human review is provided where required.
Personal data submitted through general inquiry forms will not be used to train a publicly available artificial-intelligence model unless that use is separately disclosed and lawfully authorized.
19. Your Privacy Rights
Depending on your country and the applicable law, you may have the right to:
- Be informed about how your personal data is processed
- Obtain confirmation that we process your personal data
- Access your personal data
- Obtain a copy in an available or machine-readable format
- Correct or complete inaccurate information
- Request deletion, erasure, destruction, or anonymization
- Withdraw consent
- Object to certain processing
- Restrict or stop processing
- Request portability or transfer to another controller
- Object to direct marketing
- Object to or request review of certain automated decisions
- Know the source of personal data
- Know the parties to whom data has been disclosed
- File a complaint with a privacy or data-protection authority
- Exercise other rights provided by applicable law.
These rights are subject to legal conditions, exceptions, exemptions, and verification requirements.
19.1 How to Submit a Request
Submit a request to:
Email: info@bestbrains.com
Please describe the right you wish to exercise and the personal data involved.
19.2 Verification
We may request information reasonably necessary to verify your identity and protect personal data from unauthorized disclosure.
We will not request more verification information than reasonably necessary.
19.3 Authorized Representatives
Where permitted, an authorized representative may submit a request on your behalf. We may require written authorization and verification of the representative's identity and authority.
For a child, we may require evidence of parental or legal guardianship.
19.4 Response Period
We will respond within the period required by applicable law. Where an extension is permitted because a request is complex or numerous, we will inform you of the extension.
19.5 Fees and Refusals
Requests will normally be handled without charge. We may charge a legally permitted fee or decline a request that is manifestly unfounded, excessive, repetitive, fraudulent, or subject to a legal exception.
Where legally required, we will explain the reason for a refusal and any available complaint or appeal process.
20. Complaints
Please contact us first at info@bestbrains.com so that we can investigate and attempt to resolve your concern.
You may also have the right to submit a complaint to the privacy, data-protection, communications, digital-economy, or other competent authority in your country.
Applicable regulators are identified in Schedule A where appropriate.
21. Third-Party Websites and Services
Our website may contain links to:
- Independently operated Best Brains center websites
- Social-media platforms
- Mapping services
- Payment processors
- Appointment-booking providers
- Franchise or recruitment platforms
- Other third-party websites.
We do not control the privacy practices of an independent third party. Review its privacy notice before providing personal data.
22. Social Media
When you interact with us through a social-media platform, the platform may independently collect and use personal data under its own privacy terms.
We may receive information such as your public profile name, comments, messages, reactions, advertising engagement, and information permitted by your platform settings.
23. Changes to This Privacy Policy
We may update this Privacy Policy to reflect:
- Changes in law
- Regulatory guidance
- New services
- New technologies
- Changes in our vendors or processing practices
- Organizational changes.
The revised version will be posted with a new "Last Updated" date.
Where required, we will provide additional notice or obtain renewed consent before a material change takes effect.
24. Language
This Privacy Policy may be made available in English, Arabic, or another local language.
Where local law requires an Arabic or other official-language version, that version will be provided. If versions conflict, the version designated by applicable law or the locally published version will control to the extent required.
25. Contact Us
Questions, concerns, complaints, or requests concerning this Privacy Policy may be directed to:
Best Brains Corporate MENA
Email: info@bestbrains.com
Schedule A
MENA Country and Special-Jurisdiction Addenda
A.1 United Arab Emirates — Federal Jurisdiction
Where the UAE Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data applies, the following provisions supplement the general Privacy Policy:
- Personal data will be processed fairly, transparently, securely, and for a specified purpose.
- UAE residents may exercise rights available under UAE law, including applicable rights of access, correction, updating, restriction, cessation, deletion, portability, objection, and review of automated processing.
- International transfers will be made only where a legally recognized transfer condition or exception applies.
- We will appoint or involve a data protection officer where legally required because of the nature, volume, sensitivity, or risk of the processing.
- A personal-data breach will be reported to the UAE Data Office and affected individuals where and within the time required by applicable regulations.
- The federal regime may not apply to processing governed by excluded governmental, health, banking, credit, or free-zone frameworks. The applicable sectoral or special-zone rules will control in those circumstances.
A.2 Dubai International Financial Centre
Where processing is subject to the DIFC Data Protection Law No. 5 of 2020, as amended, and its regulations:
- Processing will rely on a lawful basis recognized by DIFC law.
- Special-category personal data will receive enhanced protection.
- Individuals may exercise the rights available under DIFC law.
- Transfers outside the DIFC will use an adequacy decision, DIFC-approved clauses, another appropriate safeguard, or a permitted derogation.
- Processing notifications, data-protection officer appointments, impact assessments, autonomous-system assessments, and breach reports will be completed where required.
- Complaints may be submitted to the DIFC Commissioner of Data Protection.
A.3 Abu Dhabi Global Market
Where processing is subject to the ADGM Data Protection Regulations 2021 and applicable rules:
- We will comply with ADGM lawfulness, fairness, transparency, purpose limitation, minimization, accuracy, retention, security, and accountability requirements.
- Individuals may exercise ADGM rights, including applicable access, rectification, erasure, restriction, objection, portability, and automated-decision rights.
- Restricted international transfers will use an ADGM-recognized mechanism.
- An ADGM establishment acting as a controller will complete required registration and renewal obligations.
- Required data-protection impact assessments, processor contracts, security controls, and breach notifications will be maintained.
- Complaints may be made to the ADGM Office of Data Protection.
A.4 Kingdom of Saudi Arabia
Where the Saudi Personal Data Protection Law, its Implementing Regulations, and applicable transfer regulations apply:
- We will provide a clear privacy notice before or at the time personal data is collected.
- Processing will rely on consent or another basis permitted by Saudi law.
- Consent will be documented and capable of withdrawal. Separate consent will be obtained for direct marketing where required.
- Individuals may exercise applicable Saudi rights, including the rights to be informed, access data, obtain a copy, correct or complete data, and request destruction when legal conditions are met.
- Children's and sensitive personal data will be processed using heightened safeguards and required consent.
- Personal data will not be retained longer than necessary unless continued retention is legally required.
- Transfers outside Saudi Arabia will follow the statutory transfer conditions, risk-assessment requirements, safeguards, exemptions, and approvals applicable to the transfer.
- Complaints may be submitted to the Saudi Data and Artificial Intelligence Authority or the competent national data authority.
A.5 State of Qatar
Where Qatar Law No. 13 of 2016 Concerning Personal Data Privacy Protection applies:
- Personal data will be collected and processed transparently and for lawful, specified purposes.
- We will provide the information required by Qatari law and obtain consent where required.
- Individuals may request access, review, correction, updating, deletion, or withdrawal of consent as provided by law.
- Personal data of children and personal data of a special nature will be subject to the additional restrictions, permissions, and safeguards required by law.
- Direct electronic marketing will be conducted only where legally permitted.
- Security and privacy-by-design measures will be implemented.
- Complaints may be submitted to the competent department of Qatar's National Cyber Security Agency.
A.6 Qatar Financial Centre
Where an entity or processing activity is subject to the QFC Data Protection Regulations 2021 and Data Protection Rules:
- The QFC requirements apply in addition to or instead of the Qatar national framework to the extent specified by law.
- Individuals may exercise the rights available under the QFC framework.
- Transfers outside the QFC will use a recognized lawful transfer mechanism.
- Required controller notifications, processor terms, impact assessments, data-protection officer measures, and breach notifications will be completed.
- Complaints may be submitted to the QFC Data Protection Office.
A.7 Kingdom of Bahrain
Where Bahrain Law No. 30 of 2018 Promulgating the Personal Data Protection Law applies:
- Processing will have a valid legal basis and comply with Bahrain's fairness, purpose, proportionality, accuracy, retention, security, and transparency requirements.
- Sensitive personal data will not be processed without the consent, authorization, or exception required by law.
- Individuals may exercise applicable rights of access, objection, correction, blocking, deletion, and complaint.
- International transfers will be made only to permitted jurisdictions or under an applicable authorization, safeguard, consent, or exception.
- Direct marketing will be carried out only in accordance with Bahrain's consent and objection requirements.
- Required notifications, authorizations, or data-protection manager appointments will be completed where applicable.
- Complaints may be directed to Bahrain's Personal Data Protection Authority.
A.8 Sultanate of Oman
Where Oman's Personal Data Protection Law issued by Royal Decree No. 6/2022 and its Executive Regulations apply:
- We will obtain consent before processing where required and document consent appropriately.
- Individuals may exercise the rights available under Omani law, including applicable rights concerning access, correction, updating, transfer, withdrawal, and deletion.
- Processing of children's data, genetic data, health data, biometric data, criminal data, or other protected categories will be subject to applicable permits, approvals, and heightened safeguards.
- International transfers will follow the approval, protection-level, contractual, risk-assessment, or exception requirements established by Omani law.
- Direct marketing will be conducted only under legally valid authorization.
- Required records, impact assessments, data-protection officer measures, permits, and breach reports will be maintained.
- Complaints may be submitted to Oman's Ministry of Transport, Communications and Information Technology.
A.9 State of Kuwait
Kuwait does not currently apply a single comprehensive private-sector data-protection statute in the same manner as several other MENA jurisdictions. The CITRA Data Privacy Protection Regulation issued under Decision No. 26 of 2024 applies principally within the communications and information-technology regulatory scope.
Where that regulation or another Kuwaiti privacy, communications, cybersecurity, consumer-protection, electronic-transactions, employment, or sectoral rule applies:
- We will provide clear information concerning collection and processing.
- We will obtain consent where required.
- We will implement appropriate security and confidentiality controls.
- Individuals may exercise the access, correction, deletion, objection, or other rights provided by the applicable rule.
- Cross-border transfers and disclosures will comply with applicable CITRA and sector-specific conditions.
- A regulated service provider will comply with applicable breach-notification obligations.
- Complaints within CITRA's jurisdiction may be submitted to the Communication and Information Technology Regulatory Authority.
A.10 Arab Republic of Egypt
Where Egypt's Personal Data Protection Law No. 151 of 2020, its Executive Regulations, and Personal Data Protection Center requirements apply:
- Processing will rely on a lawful basis recognized by Egyptian law.
- Consent requests will be clear, specific, informed, freely given, documented, and in Arabic where required.
- Sensitive personal data will be processed only under the required written consent, license, permit, or statutory condition.
- Processing children's personal data will require the guardian or other authorization required by Egyptian law and regulator guidance.
- Individuals may exercise applicable rights of access, correction, erasure, restriction, objection, withdrawal, and notification.
- Required licenses, permits, accreditations, controller or processor registrations, and data-protection officer registrations will be obtained.
- Transfers outside Egypt will follow applicable licenses, permits, approved safeguards, or statutory exceptions.
- Required breach reports will be provided to the Personal Data Protection Center and affected persons.
- Complaints may be submitted to Egypt's Personal Data Protection Center.
A.11 Hashemite Kingdom of Jordan
Where Jordan's Personal Data Protection Law No. 24 of 2023 and its implementing requirements apply:
- We will process personal data only with consent or another condition recognized by Jordanian law.
- Consent will be documented and capable of withdrawal.
- Individuals may exercise applicable rights to information, access, obtain a copy, withdraw consent, correct, update, restrict, erase, object, and complain.
- Sensitive personal data and children's data will receive additional protection.
- A data protection officer will be appointed where the processing falls within a category requiring one.
- A data-protection impact assessment will be conducted where required, including certain sensitive-data and international-transfer activities.
- Cross-border transfers will comply with Jordan's applicable conditions, adequacy requirements, approvals, and safeguards.
- Complaints may be submitted to Jordan's Personal Data Protection Directorate or Council.
A.12 Kingdom of Morocco
Where Morocco's Law No. 09-08 and Decree No. 2-09-165 apply:
- Personal data will be collected fairly, lawfully, transparently, and for a specific purpose.
- Individuals may exercise applicable rights of information, access, rectification, and objection.
- Marketing communications will respect applicable consent and objection requirements.
- Processing operations will be declared to or authorized by the Commission Nationale de contrôle de la protection des Données à caractère Personnel where required.
- Sensitive processing will not begin until required authorization has been obtained.
- Transfers outside Morocco will be made only in accordance with CNDP requirements, including required transfer applications or authorizations.
- Complaints may be submitted to the CNDP.
A.13 People's Democratic Republic of Algeria
Where Algeria's Law No. 18-07, as amended, applies:
- Personal data will be processed with express consent or another legally recognized basis.
- Individuals may exercise applicable information, access, rectification, objection, and deletion rights.
- Sensitive, biometric, genetic, health, criminal, and children's data will be processed only under applicable enhanced requirements.
- Required declarations and prior authorizations will be submitted to the National Authority for the Protection of Personal Data.
- A foreign controller will appoint an Algerian representative where required.
- International transfers will be made only under the authorization, adequate-protection, safeguard, or exception conditions established by Algerian law.
- Complaints may be submitted to Algeria's Autorité Nationale de Protection des Données à Caractère Personnel.
A.14 Republic of Tunisia
Where Tunisia's Organic Law No. 2004-63 and its implementing decrees apply:
- Processing will be transparent, fair, proportionate, accurate, secure, and limited to lawful and explicit purposes.
- Express written consent will be obtained where required.
- Required prior declarations and authorization applications will be submitted to the Instance Nationale de Protection des Données Personnelles.
- Processing a child's personal data will not take place without the guardian's consent and any family-judge authorization required by Tunisian law.
- Sensitive personal data will be processed only under an applicable authorization or statutory exception.
- Advertising use will require specific consent where required.
- Individuals may exercise applicable rights of access, rectification, modification, correction, erasure, withdrawal, and objection.
- International transfers will occur only under the conditions and authorizations required by Tunisian law.
- Complaints may be submitted to the INPDP.
A.15 Lebanese Republic
Where Lebanon's Law No. 81 of 2018 on Electronic Transactions and Personal Data applies:
- Personal data will be collected and processed for lawful and specified purposes.
- Required notices will be provided and consent obtained where applicable.
- Individuals may exercise applicable rights concerning access, correction, objection, and processing.
- Sensitive categories will be processed only under the authorization, consent, or exception required by law.
- Any declaration, permit, or authorization required by the Ministry of Economy and Trade or another competent authority will be obtained.
- Personal data will be protected against unauthorized access, disclosure, alteration, and destruction.
- Marketing and disclosure activities will comply with applicable Lebanese requirements.
A.16 Other MENA Countries and Territories
This regional website may be accessible from countries or territories not expressly identified above, including Iraq, Libya, Palestine, Syria, Yemen, or another MENA jurisdiction.
Before Best Brains intentionally targets residents of, establishes operations in, or regularly collects personal data from another jurisdiction, Best Brains will assess:
- Applicable constitutional and civil privacy rights
- Telecommunications and cybersecurity requirements
- Consumer and electronic-transactions laws
- Education and children's-data rules
- Employment and recruitment laws
- Marketing-consent requirements
- Government filing and localization requirements
- Cross-border data-transfer restrictions.
Where local law provides greater protection than this Privacy Policy, the local requirement will apply.
Schedule B
State, Province, Emirate, and Special-Zone Application
Most privacy laws addressed in this Privacy Policy apply at the national level and do not require separate state, province, governorate, or emirate consumer privacy addenda.
Separate amendments are required when processing is governed by:
- The Dubai International Financial Centre
- The Abu Dhabi Global Market
- The Qatar Financial Centre
- Another economic or financial free zone with its own privacy rules
- A sector-specific regulator, including education, health, financial, telecommunications, employment, or government authorities
- A future state, province, emirate, governorate, free-zone, or municipal law that provides additional privacy rights.
Best Brains will apply the more protective requirement where multiple laws govern the same processing activity.