1. Who we are
This website is operated by InfraSol Next Solutions, trading as ISONEX ("ISONEX", "we", "us", or "our"), a compliance and cybersecurity consultancy headquartered in Manama, Bahrain, with registered offices in Manama, Dubai, and Riyadh.
For the purposes of applicable data protection law, ISONEX is the data controller for personal data collected through this website and in the course of our own sales, marketing, and client-relationship activities.
2. Scope of this policy
This Privacy Policy applies to:
- Visitors to our website at isonex.co and any subdomains;
- Prospective clients who contact us or whom we contact;
- Clients and their representatives during an engagement;
- Individuals who interact with us through email, events, or professional networks.
It does not apply to personal data we process on behalf of our clients when acting as a data processor — for example, data held within a client's GRC platform (such as Drata or Vanta) during an engagement. In those cases, the client is the data controller and the client's own privacy policy governs that data.
3. Data we collect
Depending on how you interact with us, we may collect:
Information you provide
- Full name and job title;
- Business email address and phone number;
- Company name and location;
- The content of any message you send us by email or through our contact channels.
Information collected automatically
- IP address and approximate location;
- Browser type, device type, and operating system;
- Pages viewed, time on site, referring website, and similar usage data, collected through analytics cookies (see Section 6).
We do not intentionally collect special categories of personal data (such as health, religious, or biometric data) through this website.
4. How we use your data
We use personal data to:
- Respond to enquiries and provide the information or services you request;
- Deliver and manage compliance and cybersecurity engagements;
- Communicate with you about your engagement or our services;
- Understand how our website is used and improve it;
- Meet our own legal, regulatory, and contractual obligations.
We do not sell your personal data to third parties.
5. Legal basis for processing
Where the GDPR or Bahrain's PDPL applies, we rely on one or more of the following legal bases:
- Consent — for example, when you accept analytics cookies or opt in to marketing communications;
- Contract — where processing is necessary to provide services you have engaged us for;
- Legitimate interests — for example, responding to a business enquiry, securing our website, and understanding how it is used, balanced against your rights;
- Legal obligation — where we must process data to comply with applicable law.
6. Cookies & analytics
Our website uses cookies and similar technologies. These fall into two groups:
- Essential cookies — required for the site to function. These do not require consent.
- Analytics cookies — used to understand how visitors use the site so we can improve it. We use a web analytics service for this purpose. Where required by law, we set these only with your consent.
You can control or disable cookies through your browser settings. Disabling analytics cookies will not affect your ability to use the site.
7. Sharing & service providers
We share personal data only where necessary, with:
- Service providers who support our operations — for example, website hosting, email, and analytics providers — acting as our processors under written agreements;
- Professional advisers such as lawyers, auditors, and accountants where necessary;
- Authorities or regulators where we are required to do so by law.
When we act as a processor for client data within a GRC platform, we process that data only on the client's documented instructions.
8. International transfers
ISONEX operates across the GCC and serves clients in the European Union and elsewhere. Where personal data is transferred outside its country of origin — for example between our offices, or to a service provider in another country — we take steps to ensure an appropriate level of protection, such as relying on adequacy decisions or standard contractual clauses where required by the GDPR or PDPL.
9. Data retention
We keep personal data only as long as necessary for the purposes set out in this policy, including to meet legal, accounting, or reporting requirements. Enquiry data that does not lead to an engagement is kept for a limited period and then deleted or anonymised. Engagement records are retained for the period required by our contractual and legal obligations.
10. Your rights
Subject to applicable law, you may have the right to:
- Access the personal data we hold about you;
- Request correction of inaccurate data;
- Request erasure of your data;
- Object to or restrict certain processing;
- Withdraw consent at any time, where processing is based on consent;
- Request a copy of your data in a portable format;
- Lodge a complaint with a supervisory authority — in Bahrain, the Personal Data Protection Authority; in the EU, your local data protection authority.
To exercise any of these rights, contact us using the details in Section 12.
11. How we protect your data
As a cybersecurity and compliance consultancy, information security is central to how we operate. We apply appropriate technical and organisational measures — including access controls, encryption in transit, and the principle of least privilege — to protect personal data against unauthorised access, loss, or misuse. No method of transmission over the internet is completely secure, but we work to protect your data and review our measures regularly.
12. Contact us
For any question about this policy, or to exercise your rights, contact us at:
InfraSol Next Solutions (trading as ISONEX)
Email: info@isonex.co
Manama · Dubai · Riyadh