Privacy Policy
1. Overview
1.1 Scope of Commitment
Shadow Lynx, (the “Company”) operates at the apex of defense innovation, training, critical infrastructure safeguarding, and strategic intelligence advisory. This Privacy Policy governs the data processing architectures of our primary digital infrastructure, including shadow-lynx.com, and applies to Shadow Lynx and its corporate Affiliates.
For the purposes of this protocol, “Affiliates” refers to any corporate entity, subsidiary, or joint venture controlled by or under common control with Shadow Lynx, where control represents the direct or indirect power to direct the management, operations, or board decisions of said entity.
In executing our mandates, we and our Affiliates are unwaveringly committed to protecting the data overeignty, confidentiality, and privacy of our institutional clients, sovereign partners, and individual liaisons.
1.2 Statutory Compliance Framework
Our data preservation, isolation, and processing protocols are engineered in strict alignment with:
- Federal Decree-Law No. 45 of 2021 on Personal Data Protection (UAE PDPL).
- Regulation (EU) 2016/679 (General Data Protection Regulation / GDPR).
- Applicable international statutory frameworks governing defense-sector communications, military export controls, and information asset protection.
- National Security Supremacy: Notwithstanding anything to the contrary in this policy, all data processing operations are strictly subordinate to the national security interests, federal sovereignty, and defense regulations of the United Arab Emirates
2. Information We Cultivate – Data Collection
To maintain absolute operational integrity and secure intake pipelines, Shadow Lynx processes data across two strict classifications:
2.1 Information Voluntarily Disclosed via Secure Channels
When coordinating initial operational assessments or initiating contact with our secure command structure, you choose to consent to the collection of:
- Identity Parameters: Full legal name, institutional affiliation, official title, and government-vetted credentials (where required for procurement verification).
- Liaison Matrix: Secure corporate or diplomatic email addresses, phone numbers, encrypted telecommunication vectors, and physical institutional addresses.
- Operational Directives: High-level threat vectors, asset profiles, or geographical context provided during secure inquiries to determine mission viability.
- Classified Data Exclusion Notice: Users are strictly prohibited from submitting, uploading, or transmitting any classified military information, state secrets, or restricted technical data under international traffic in arms regulations through our public web interface.
2.2 Automated System Telemetry & Cookies
To defend our digital perimeter against adversarial narrative manipulation and cyber incursions, our infrastructure automatically monitors baseline technical parameters known as Log Data. This includes your device’s Internet Protocol (IP) address, browser version, localized time and date stamps, and interaction logs with our digital service hub.
2.3 Cookie Protocol
Our website utilizes “Cookies”, small data files deployed to your device’s storage infrastructure, acting as anonymous unique identifiers, to optimize user experience and analyze traffic flow. You maintain the absolute right to accept or refuse these cookies via your browser architecture. Note that refusing cookies may limit operational functionality across certain segments of our digital infrastructure.
3. Operational Utilization of Data – Data Use
3.1 Lawful Bases for Processing
In strict accordance with Article 5 of the UAE PDPL and Article 6 of the GDPR, the Company processes your personal data under the following lawful thresholds:
- Explicit Consent provided by you through our digital forms;
- Contractual Necessity to execute or negotiate agreements;
- Legal Obligation to comply with global export controls and federal corporate transparency mandates; and
- Legitimate Interests in safeguarding our digital perimeter against cyber threats.
3.2 Operational Objectives
Shadow Lynx and its Affiliates process personal and institutional data strictly under authorized legal bases to fulfill commanding operational objectives:
- Contractual Execution: Validating organizational credentials, drafting customized risk frameworks, and executing approved security, rescue, or defensive logistics protocols.
- Perimeter Fortification: Monitoring digital traffic to identify, track, and neutralize hostile reconnaissance, corporate espionage vectors, or unauthorized tracking attempts.
- Service Enhancement: Improving our digital interfaces, personalizing delivery frameworks, and optimizing responsiveness to institutional requests.
- Regulatory Alignment: Ensuring all communications, personnel intakes, and advisory engagements meet rigid global export compliance, sanctions screening, and UAE corporate transparency mandates.
4. Trusted Data Transfers & Operational Boundaries
Shadow Lynx does not sell, lease, trade, or commercially distribute client or visitor data to outside parties under any circumstances. Information is only transferred or disclosed under the following explicit operational thresholds:
4.1 Authorized Service Providers
We may engage trusted third-party companies and individuals to host our digital infrastructure, facilitate our communication channels, or assist in analyzing platform security. These partners are granted access to specific technical parameters solely to perform these structural tasks on our behalf and are bound by strict legal obligations to maintain absolute confidentiality and zero data reuse.
4.2 Sovereign Mandates & Critical Safeguards
We will release information when explicitly appropriate to:
- Comply with an unshakeable statutory decree from authorized judicial or federal bodies within the United Arab Emirates. Any requests from foreign or international courts shall be processed exclusively through the formal mutual legal assistance treaties (MLAT) executed by the UAE government.
- Enforce our platform security parameters, or protect the rights, property, safety, and human life of our personnel or clients during active extraction, rescue, or high-threat operations.
4.3 Third-Party External Links
Our digital framework may contain links to external, third-party sites not operated by us or our Affiliates. We hold no control over, and assume zero liability for, the content, privacy protocols, or security postures of any external third-party services.
5. System Transmission Disclaimers & Security
Shadow Lynx and its Affiliates value institutional trust and employ advanced, commercially acceptable cryptographic layers and physical security parameters to safeguard your data. However, it is fundamentally critical to acknowledge that no method of data transmission over the internet, or method of electronic storage, is 100% secure or impenetrable. While we strive for complete perimeter fortification, we cannot guarantee its absolute security against unprecedented cyber warfare, state-sponsored cyber incursions, or asymmetric digital breaches. Consequently, the Company disclaims any liability for damages resulting from illegal interception or state-level cyber attacks beyond our reasonable commercial control.
6. Data Retention Architecture
Shadow Lynx and its Affiliates will retain your personal data matrix only for the minimum period necessary to fulfill the operational purposes outlined in Section 3 of this protocol, or to satisfy mandatory statutory retention periods under applicable UAE federal laws and defense-sector procurement regulations. Once the lawful basis or retention period expires, data assets will be securely and permanently destroyed, sanitized, or anonymized under strict cryptographic deletion protocols.
7. Data Sovereignty Rights (User Rights)
Depending on your geographical jurisdiction and sovereign status, you hold explicit rights regarding your personal data matrix, subject to local national security exemptions and statutory defense mandates:
- The Right to Audit (Access): Request a complete mapping of the personal data assets we hold regarding your profile.
- The Right to Rectify (Correction): Command immediate updates to any incomplete or inaccurate parameter within our active records.
- The Right to Sanitize (Erasure): Request the complete purging of your personal records from our active operational databases, provided it does not conflict with active contractual, defense procurement, or statutory retention mandates.
- The Right to Restrict Processing: Limit the operational scope under which your data is utilized during ongoing vetting reviews.
- The Right to Withdraw Consent: The explicit right to revoke your authorized consent for data processing at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
- The Right to Lodge a Complaint: The right to file an official grievance regarding our data practices directly before the UAE Data Office (the regulatory authority under Federal Decree-Law No. 45 of 2021) or your local Supervisory Authority.
8. Modifications to This Security Protocol
Shadow Lynx reserves the absolute right to modify, adapt, or overhaul this Privacy Policy to match updates to international defense regulations, UAE federal decrees, or our internal security postures. Any structural alterations will be indexed here immediately with an updated effective date, taking immediate effect upon posting.
9. Data Protection Officer (DPO) & Regulatory Inquiries
For the exercise of your statutory data sovereignty rights, or to submit any regulatory inquiry or suggestions regarding this security protocol, please contact our designated compliance channel:
Attn: Data Protection & Compliance Desk / Shadow Lynx
Head Office: Dubai, United Arab Emirates
Email: contact@shadow-lynx.com
