Legal

Privacy Policy

Your privacy matters to us. This policy sets out clearly what data we collect through this website, why we need it, who we share it with, how long we keep it, and the rights you hold over it under the UK GDPR. If anything is unclear, write to us at privacy@exporya.com.

Last updated:

Who we are, and the scope of this policy

This policy covers the website exporya.com (Arabic, with an English version at /en/), owned and operated by Exporya Ltd. Exporya Ltd is the Data Controller for personal data collected through this website, under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR) regarding storage on your device.

  • Companies House registration number: 13585919
  • Registered office: 1 Bedford Row, Chincilla Suite 105, London, England, WC1R 4BU (visits by appointment only)
  • ICO registration number: ZB614381
  • Privacy email: privacy@exporya.com
  • General email: support@exporya.com

This policy's scope is narrow: it covers only data collected through this website — your browsing, your use of the company-name check tool, and any message you send us via WhatsApp, email or the contact form.

It does not cover the client dashboard (dash.exporya.com): placing an actual order, uploading identity-verification documents and making payment all happen exclusively in the client dashboard, which has its own privacy notice and terms of use that you read when you create an account there. We never ask you to send a passport photo or any ID document through a form on this website or via WhatsApp.

What data we collect, and its source

We collect only what we need to answer you and run the website:

  • Identification and contact data: Name, phone or WhatsApp number, email and country — provided by you directly via the contact form, a WhatsApp message or email.
  • Content of your correspondence: Your enquiry text, the proposed company name you type into the name-check tool, and any file you voluntarily attach — provided by you directly.
  • Technical data about your device and visit: General browser and device type, pages visited, chosen language and your consent-banner choice — collected automatically as you browse, with some of it kept on your device only (see "Cookies and local storage").
  • What passes through WhatsApp: If you contact us via WhatsApp, your phone number, account name and message content pass through the WhatsApp Business service owned by Meta; we do not control its own privacy policy.

We do not collect any payment data or identity data (passport, ID card, verification selfie) through this website; such data is collected only via the client dashboard, outside the scope of this policy.

Purposes and lawful bases for processing

Every processing activity has a defined purpose and a lawful basis under Article 6 of the UK GDPR:

  • Responding to your enquiry and providing information about our services: Steps taken prior to entering a contract (Art. 6(1)(b)), or our legitimate interests in responding to information requests (Art. 6(1)(f)).
  • Operating the company-name check tool: Our legitimate interests in providing a useful free tool (Art. 6(1)(f)); no binding automated decision results from it.
  • Complying with our legal obligations: As an Authorised Corporate Service Provider (ACSP) to Companies House and an entity supervised for anti-money laundering by HMRC, we retain identity-verification records tied to an actual order (handled via the client dashboard): legal obligation (Art. 6(1)(c)).
  • Responding to requests to exercise your rights or complaints: Legal obligation (Art. 6(1)(c)).
  • Measuring visits and the results of our ads (only after you consent): Your consent (Article 6(1)(a)); you can withdraw it at any time in "Privacy settings".

When we obtain your data indirectly

If we obtain your data from a source other than you directly (for example, a referral from a partner or firm you have engaged), we tell you the categories of data concerned and their source (including whether it is publicly available), within one month of obtaining it, or at first contact with you if sooner, or before disclosure to another party if that comes first.

Cookies and local storage

This website sets no cookies before you consent (see "Measurement and advertising tools" below). We use localStorage for the following functional items. Optional measurement storage is described under Measurement and advertising tools:

  • ex-cookie-choice: Stores your choice on the consent banner, so we do not ask again on every visit.
  • ex-gate-v2: Stores only that you have seen the entrance screen, so it does not show again; it holds no data about you.

This storage is itself subject to PECR as information stored on your device, which is why the consent banner appears before any tool loads. You can clear it at any time in your browser settings, and the permanent "Privacy settings" link in the footer of every page reopens the consent banner so you can change your choice whenever you like.

Measurement and advertising tools (only after you consent)

None of the following tools loads, and none receives any data, until you click "Accept all" in the consent banner. Then they set the cookies listed and receive technical data about your visit (such as the pages you opened, your device and browser type and IP address). The events our site sends them — a WhatsApp click, an "Order now" click or a sent contact form — never carry your name, number or e-mail. The legal basis is your consent (UK GDPR Article 6(1)(a) and PECR). If we add or change a tool, we ask for your consent again.

  • Exporya first-party measurement — Exporya: Consent-gated page, approximate geography, referring host, campaign, device, foreground time and contact/order click measurements. No raw IP or form data is stored; daily derived grouping can combine people sharing a network, without an identity cookie. After consent, sessionStorage stores ex-analytics-session-v2 with a random session identifier and its acquisition source. The session expires after 30 minutes of inactivity; the key is removed on consent withdrawal. Events are retained for 30 days. Foreground time is not proof of reading, and an order click is not a purchase.

You can withdraw consent at any time from the "Privacy settings" link in the footer of every page: we stop these tools at once by reloading the page and delete the cookies they set on our domain; cookies they set on their own domains (such as CLID and MUID) are cleared in your browser settings. These providers may process or transfer data outside the UK (for example to the United States) under the mechanisms set out in "International data transfers".

Who we share your data with

We do not sell your personal data to anyone. We share limited data only with the following parties, each within the bounds of its role:

  • Vercel Inc.: Hosting and infrastructure provider for the website: basic technical visit data, no payment or ID data.
  • WhatsApp (Meta Platforms): The contact channel when you message us via the "Contact us" button or the floating bubble: your phone number, account name and message content, under WhatsApp's own privacy policy.
  • Transactional email provider: A specialised service (Resend or Postmark) for sending automated emails, such as notifying our team that a contact form has arrived: the form data and the automated message content only, separate from the company's human mailboxes on its current hosting.
  • Companies House: On completion of an actual order via the client dashboard, we transmit identity-verification data to it as a legal obligation in our capacity as an authorised agent (ACSP).
  • Client dashboard: A separate ordering, payment and identity-verification system run by a separate team; data from this website is not automatically shared with it, and creating an account there is governed by its own privacy notice.
  • Regulators and legal authorities: Where a legal obligation or a court or regulator order requires it (such as the ICO or HMRC), and only as far as the specific legal request requires.
  • Providers of measurement and advertising tools (only after you consent): The providers named in "Measurement and advertising tools", each only for the purpose stated there.

We are finalising formal data processing agreements (DPAs under UK GDPR Article 28) with each provider that processes data on our behalf; this section will be updated once they are in place.

International data transfers

Some of our providers (such as Vercel and Meta) may process or store your data on servers outside the United Kingdom, including in the United States or the European Union. When this happens, we ensure a level of protection equivalent to that required by UK law through one of the following mechanisms:

  • UK Adequacy Regulations issued by the UK government regarding the receiving country, where applicable.
  • The UK Addendum to the EU Standard Contractual Clauses (EU SCCs), or the UK International Data Transfer Agreement (UK IDTA).
  • An equivalent mechanism recognised by the ICO, such as the Data Privacy Framework, where it applies to the relevant US provider.

We will make a summary of each data flow (country, receiving entity and legal mechanism used) available here once the review of our processor contracts is complete.

How long we keep your data

We keep data only for as long as is necessary to achieve the purpose of the processing, subject to any longer statutory retention obligation:

  • Identity-verification records held as an Authorised Corporate Service Provider (ACSP) to Companies House: Seven (7) years from the date the verification check is completed — a legal obligation on the authorised agent, whatever the channel through which the identity data reached us.
  • General correspondence and name-check data: Only as long as needed to fulfil the purpose for which it was collected, under the data-minimisation and storage-limitation principles (UK GDPR Art. 5(1)(c) and (e)) — this covers an enquiry that did not become an order, and the name you type to check its availability.
  • Your consent-banner choice and the entrance-screen flag: They remain on your device in local storage until you clear them or change your choice, and are not stored on our servers.
  • Actual order, identity-verification and payment data: Governed by the client dashboard's own privacy notice, outside the scope of this policy.
  • Cookies of the measurement and advertising tools: The lifetimes given for each tool in "Measurement and advertising tools", or until you withdraw consent; each provider keeps what it receives under its own retention settings.

Your rights over your data

Under the UK GDPR, you have the following rights regarding your personal data:

  • Right of access: Obtain a copy of the data we process about you and understand how it is processed.
  • Right to rectification: Correct any inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten"): Request deletion of your data, subject to legal exceptions, such as our obligation to retain ACSP verification records for 7 years if you completed an actual order.
  • Right to restrict processing: Request a temporary halt on the use of your data in certain circumstances, such as disputing its accuracy while it is being checked.
  • Right to object: Object to processing based on legitimate interests, or to any direct marketing at any time.
  • Right to data portability: Receive your data in a structured, transferable format, where processing is based on consent or contract and carried out by automated means.
  • Right to withdraw consent: At any time, for any processing based on your consent, without affecting the lawfulness of processing before withdrawal.
  • Right to lodge a complaint: See "Your right to complain" below.

To exercise any right, email privacy@exporya.com stating which right you wish to exercise. We will ask only for what is necessary to verify your identity before responding, proportionate to the sensitivity of the request, and we respond without undue delay and within one month of receiving the request, with a possible extension of two further months for complex or numerous requests, notifying you of the extension and its reason in the first month.

Giving us your name and contact details is entirely optional for browsing the site, but it is necessary for us to respond to your enquiry or begin any service request.

Automated decision-making and profiling

Our processing through this website involves no wholly automated decision that produces a legal effect concerning you or similarly significantly affects you. The company-name check is a purely informational, indicative tool that tells you the likely availability of a name, and it issues no final approval or rejection — the official decision is issued exclusively by Companies House when an actual application is filed.

Your right to complain

You have the right to lodge a complaint with the relevant supervisory authority if you believe our processing of your data breaches the law:

  • In the United Kingdom: The Information Commissioner's Office (ICO), via its website ico.org.uk.
  • If you are resident in the European Union: Also the competent data protection authority in your country of residence.

We commit to acknowledging receipt of any data-protection complaint you send us directly within 30 days of receipt, then taking appropriate steps to respond without undue delay, under the right introduced by the Data (Use and Access) Act 2025, in force since 19 June 2026.

We encourage you to contact us first via privacy@exporya.com so we can try to resolve the matter directly, but this is not a precondition to lodging a formal complaint with the ICO or any other authority at any time.

EU Representative (Article 27, EU GDPR)

Because we provide our services (including EU trademark registration) to clients located within the European Union, the EU General Data Protection Regulation applies to this processing under its Article 3(2), requiring the appointment of an EU Representative under Article 27:

  • The representative (a natural person or a company specialising in this role) is appointed under a formal written mandate, and this policy will be updated with their full name and contact details once the appointment is complete.
  • The EU Representative is not a substitute for a Data Protection Officer; their principal role is to represent Exporya before data subjects and EU authorities regarding processing subject to the EU GDPR.
  • Until the representative's details are published, you can send any request about this processing to us directly at privacy@exporya.com.

Data Protection Officer (DPO)

We have internally assessed whether a formal Data Protection Officer must be appointed under Article 37 of the UK GDPR, and concluded that our activity does not require a mandatory appointment, as it involves no regular and systematic monitoring of individuals on a large scale, nor large-scale processing of special category data as a core activity. This assessment is documented internally and reviewed periodically.

We nonetheless have an internal data-protection team reachable at privacy@exporya.com.

Identity documents and anti-money-laundering data

  • One channel for identity documents: Identity documents are uploaded exclusively via the client dashboard (dash.exporya.com) and are not accepted through any form on this website, via WhatsApp or via email. If you mistakenly send us an ID document through another channel, we ask you to delete it and re-upload it via the client dashboard, and we handle whatever we received with the highest level of protection and delete it as soon as you have been redirected to the correct channel.
  • Our legal obligations: As an authorised agent (ACSP) to Companies House and an entity supervised for anti-money laundering by HMRC (registration number XWML00000209713), our processing of identity-verification data is subject to specific legal obligations: conducting due-diligence checks, retaining records for 7 years, and reporting any suspicious activity to the competent authorities where legally required.

Data security, and breach notification

We apply reasonable technical and organisational measures to protect your data, including need-to-know access controls, mandatory multi-factor authentication (MFA) for all our team's administrative accounts, encryption in transit (HTTPS/TLS) across the entire website, and an audit log of every sensitive login or change to our internal systems. No data transmission over the internet can be guaranteed to be absolutely secure, so please do not share sensitive data (such as card numbers or identity documents) through any channel other than the client dashboard.

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we commit to the following:

  • Assessing the nature and scope of the breach as soon as we discover it.
  • Notifying the Information Commissioner's Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of the breach, under Article 33 of the UK GDPR.
  • Notifying you directly without undue delay where the breach is likely to result in a high risk to your rights and freedoms, under Article 34 of the UK GDPR, explaining its nature, the steps we have taken and our recommendations for protecting yourself.
  • Keeping an internal record of every actual or suspected breach, regardless of whether external notification is required.

Minors

Our services (company formation, trademark registration, apostille and legalisation) are directed at adult entrepreneurs and businesses with legal capacity to contract. We do not knowingly target minors or collect personal data from persons below the legal age to contract without parental consent. If we learn that we have inadvertently collected a minor's data without the necessary consent, we delete it as soon as we become aware.

Updates to this policy

We may update this policy from time to time to reflect changes in our services, the applicable law or our providers. The date of the last update always appears at the top of this page, we publish any material change clearly (such as adding a new measurement tool, appointing the EU Representative or changing a retention period), and we seek your renewed consent where the law requires it.

Contact usprivacy@exporya.com