PROJECTGET OUT
PRIVACY POLICY 2026
Back to Project Get Out ↗

PROJECT GET OUT · PRIVACY · 2026

Privacy Policy.

How we collect, use, share and protect personal data across our website, publications and services.

Complete policy

Please read this policy before sharing personal data with us.

01

Who we are and what this policy covers

Project Get Out Consultancy FZ-LLC, trade name “Project Get Out” (“we”, “us”, “our”), is a management consultancy incorporated in the Ras Al Khaimah Economic Zone, United Arab Emirates. We help people plan and coordinate international relocation and the cessation of tax residency, we publish educational guides, and we produce public content. We are the controller of the personal data described in this policy, and we process it under the UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021 (the “PDPL”). Because most of the people we work with are in Australia, and some of our readers and buyers are elsewhere, we also apply the standards of the Australian Privacy Principles to Australian individuals, and of the EU and UK General Data Protection Regulations where they apply to you. Where those laws give you greater rights than the PDPL, we honour them.

This policy applies to everyone whose personal data we handle: visitors to our website and subscribers to our content, purchasers of our guides and other publications, people who enquire about or engage our services, the family members, dependants, business associates and entities whose information our clients give us, and the personnel of the advisers, suppliers and institutions we work with. It should be read with our Terms of Business, our Terms of Sale and our cookie settings, and with any specific notice we give you when we collect particular information. Our privacy contact is haider@projectgetout.com, and the details for exercising your rights or complaining are in section 12.

02

The personal data we collect

What we collect depends on your relationship with us. We collect only what we need for the purposes in section 4, and we do not collect more sensitive information than your matter requires.

If you visit our website or follow our content

Your device and connection information, such as IP address, browser and operating system, the pages you visit and how you interact with them, the source you arrived from, and, if you subscribe, your name, email address and content preferences. Some of this is collected through cookies and similar tools, explained in section 13. If you engage with us on a social platform, that platform also processes your data under its own policy.

If you buy a guide or other publication

Your name, email address, billing country, the product and edition purchased, payment confirmation from our payment processor, and, where you pay in a digital asset, the sending wallet address and transaction identifier. We do not receive or store your full card number. We may also collect your country to determine which taxes and consumer laws apply to your purchase.

If you enquire about or engage our services

Because our work concerns your tax residency, your relocation and the structure of your affairs, the information we hold about clients is unusually detailed. It may include: identity information, including your passport and identity documents, date and place of birth, nationalities, photographs and signature; contact and address history; your family and household, including spouse or partner, children and other dependants and their identity documents where they are part of your plan; your residency, immigration and travel history, and your records of days spent in each country; your assets, income, entities, trusts, investments, property, banking arrangements and digital asset holdings, including exchange records and wallet histories where wealth is held in digital assets; your tax history, filings, rulings and correspondence with revenue authorities; your employment, business and professional background; information about your goals, timing and the reasons for your relocation; where your plan involves insurance or a financial product arranged by a licensed adviser, information that adviser needs, which may include health information; and the correspondence, meeting notes, recordings and transcripts generated during our work with you.

Compliance and screening information

We are required by UAE law to identify our clients and understand the source of their funds and wealth. For that purpose we collect certified identity documents, proof of address and source of wealth evidence, and we screen clients, family members and connected parties against sanctions, politically exposed person and adverse media databases. Screening results are personal data and are handled under section 4.

Information from other sources

We receive personal data about you from the specialist advisers, corporate service providers, banks, insurers and authorities involved in your matter; from screening and verification providers and public registers; from the person who introduced you to us, where you were referred; and from the platforms through which you found or contacted us.

03

Information you give us about other people

Relocation planning is a family and business exercise, so clients routinely give us personal data about other people: a spouse or partner, children, other dependants, business partners, employees of your entities, and beneficiaries of your trusts. When you do, you confirm that you are entitled to share that information with us for the purposes of your matter, that you will make this policy available to the adults concerned, and that where a child’s information is involved you are that child’s parent or legal guardian. We use information about other people only for the purposes of the client’s matter, we do not market to them, and they may exercise the rights in section 12 in respect of their own data. Our services are not directed to anyone under 18, and we do not knowingly collect a child’s data except from a parent or guardian in the course of an engagement.

04

Why we use your data, and our lawful basis

Under the PDPL we process personal data with your consent, or without consent where the law permits, such as where processing is necessary to perform a contract with you, to comply with a legal obligation, to establish, exercise or defend legal claims, or where the law otherwise allows. Where the Australian Privacy Principles or the GDPR apply, we rely on the equivalent bases under those laws. We use your data for the following purposes:

  1. To provide our services: assessing your position, designing your exit plan and calendar, identifying and briefing specialist advisers, coordinating implementation, keeping the implementation record, reporting to you, and managing our relationship with you. Basis: performance of your engagement with us.
  2. To supply publications and manage your account: taking your order, delivering the product, providing support and honouring your consumer rights. Basis: performance of your purchase contract.
  3. To meet our legal obligations: client identification, source of wealth and sanctions screening under UAE anti-money laundering and sanctions law, tax and accounting record keeping, and responding to lawful requests from courts, regulators and authorities. Basis: legal obligation. Where the law requires us to report a matter, we may be prohibited from telling you.
  4. To communicate with you about your matter or purchase, including by email, messaging services and video calls, and to record and transcribe calls so that we hold an accurate record of instructions and discussions. Basis: performance of the contract, and your consent to recording, which we ask for when you engage us and which you may withdraw.
  5. To send you marketing, newsletters, event invitations and information about our products and services, only where you have opted in or where you are an existing client or customer and the law allows. Basis: consent, or a permitted existing-customer communication. You may unsubscribe at any time.
  6. To protect our business and our clients: securing our systems, preventing fraud and payment redirection, verifying identity when you contact us, enforcing our terms, and establishing, exercising or defending legal claims. Basis: legal obligation, legal claims, and our legitimate interests where the law recognises them.
  7. To improve our services and content: learning from our engagements and using aggregated or anonymised information that no longer identifies you to develop our playbooks, publications and public content. Basis: our legitimate interests where recognised; identifying information is not used for this purpose without your consent.
  8. To process sensitive personal data, including health information where an insurer or licensed adviser requires it, and screening results that may reveal criminal or political exposure. Basis: your explicit consent, or a legal obligation, and never for any other purpose.

We do not sell personal data, we do not trade in it, and we do not use it to make decisions about you by automated means alone. Screening results are always reviewed by a person before any decision is taken.

05

Marketing, public content and your privacy

We produce public content across podcasts, video, social media, newsletters and events. Subscribing to any of these is optional, every marketing message we send identifies us and carries a working unsubscribe mechanism, and we do not send marketing to people who have not opted in or who have asked us to stop. We comply with the Australian Spam Act 2003 and equivalent laws for the people we contact.

Separately, we will never identify you as a client, or disclose the existence or content of any engagement, in any marketing, media, social media, podcast or other public material without your prior written consent, and where you consent you may withdraw it for future use at any time. Testimonials, case studies and client stories appear only with written consent and only to the extent consented.

06

Who we share your data with

Coordination is the heart of our services, and it means sharing your data with the people who deliver your relocation. We share only what each recipient needs for their part of your matter, and only under the authority you give us in your engagement, which you may narrow or withdraw.

Specialist advisers

The lawyers, tax advisers, accountants, structuring advisers, licensed financial and insurance advisers, migration agents and other professionals you engage directly on their own terms. We brief them and coordinate their work, and they may return information about you to us. Each of them is an independent controller of the data they hold and processes it under their own privacy policy, which you should read when you engage them.

Implementation counterparties

Freezone and licensing authorities, immigration authorities and government-approved application centres, corporate service providers, banks and payment institutions, insurers, and relocation, housing and education providers, where your plan requires an application, account or arrangement with them. Most are independent controllers, and many are government bodies with their own statutory powers over your data.

Our service providers

Companies that process data on our behalf and on our instructions, under contracts that require confidentiality, security and use for our purposes only. They currently include providers of: cloud email, storage and document production; customer relationship management; video conferencing, call recording and transcription; electronic signature; payment processing, including digital asset payment processing; website hosting, analytics and email delivery; identity verification and sanctions screening; and artificial intelligence tools described in section 7. A current list of the categories and locations of our providers is available on request from our privacy contact.

Others

Our professional advisers, insurers and auditors; regulators, courts, law enforcement and revenue authorities where the law requires or permits disclosure, including under anti-money laundering and sanctions law; a purchaser or successor of our business, who will be bound by this policy; and any other person you ask or authorise us to share your data with.

07

Artificial intelligence and automated tools

We use reputable third-party artificial intelligence tools to assist with research, drafting, transcription and document production in delivering our services. We use them under commercial terms that prohibit the provider from using your data to train its models and that require confidentiality and security, we limit what is submitted to what the task requires, and every output that forms part of a deliverable is reviewed by a member of our team before it is issued. We do not use these tools to make decisions about you. If you do not wish AI-assisted tools to be used on your matter, tell us in writing and we will discuss the implications with you.

08

International transfers

Our business is international by nature, and your data will leave the country you are in. We are established in the United Arab Emirates, our clients are mostly in Australia, the specialist advisers and counterparties in your matter are in the countries you are leaving and moving to, including Australia, the United Arab Emirates, Singapore, the United Kingdom, the Cayman Islands and elsewhere, and our service providers store data in data centres in the United Arab Emirates, Australia, the European Union, the United Kingdom, the United States and Singapore.

Where we transfer personal data outside the United Arab Emirates, we do so to countries the UAE recognises as providing adequate protection, or under contractual safeguards that bind the recipient to protect your data to the standard the PDPL requires, or with your consent, or where the transfer is necessary to perform your contract with us or to establish, exercise or defend legal claims, in each case as the PDPL permits. For Australian individuals, we take reasonable steps to ensure that overseas recipients handle your information consistently with the Australian Privacy Principles, and you should be aware that overseas recipients may be subject to foreign laws that require disclosure. For individuals protected by the GDPR or UK GDPR, transfers outside those areas are made under standard contractual clauses or another lawful mechanism. Government authorities that receive your data in the course of an application process it under their own laws.

09

How we protect your data

We treat client files as highly confidential, because they are. We protect personal data with technical and organisational measures appropriate to its sensitivity, including encryption in transit and at rest, multi-factor authentication and role-based access to our systems, restriction of access to the personnel who need it for your matter, confidentiality obligations on everyone who works with us, due diligence on our service providers, and secure channels for the exchange of identity and financial documents. We ask you to use those channels rather than sending sensitive documents by unsecured email or instant message. No system is perfectly secure, and we cannot guarantee that unauthorised access will never occur, but if a breach affects your data we will act as described in section 11.

One protection depends on you. We will never change our bank account or wallet details by email alone. If you receive a message that appears to come from us and asks you to pay to new details, do not pay until you have verified the request by telephone or video call with your named contact.

10

How long we keep your data

We keep personal data for as long as we need it for the purposes it was collected, and then for as long as the law requires or a legal claim could reasonably arise. In practice:

  1. Engagement files, including the implementation record, correspondence, recordings and transcripts: at least ten years from the end of the engagement, because residency and tax positions are commonly examined by authorities years after an exit and the file is the evidence for both you and us, and because UAE anti-money laundering law requires client identification records to be kept for a minimum period after the relationship ends.
  2. Identification, source of wealth and screening records: for the period UAE anti-money laundering law requires, currently at least five years after the end of the relationship or the transaction, and longer where an authority requires it.
  3. Purchase records for publications: for the period tax and accounting law requires, generally seven years.
  4. Enquiries that do not become engagements: up to two years from our last contact, unless you ask us to delete them sooner.
  5. Marketing data: until you unsubscribe, after which we keep only what we need to make sure we do not contact you again.
  6. Website and analytics data: for the periods set out in our cookie settings.

When a retention period ends we delete or anonymise the data. We may keep data longer where it is subject to a legal hold, an investigation or an unresolved dispute. We are not the custodian of your original documents, and you should keep your own copies of everything you give us and everything we deliver to you.

11

Data breaches

If we become aware of a breach of security affecting personal data, we will contain and assess it, notify the UAE Data Office where the PDPL requires, notify the Office of the Australian Information Commissioner or another supervisory authority where their laws require, and tell you without undue delay where the breach is likely to prejudice your privacy or security, together with what we are doing about it and what you can do to protect yourself.

12

Your rights, and how to use them

Under the PDPL, and under the Australian Privacy Principles and the GDPR where they apply to you, you have the right to ask us what personal data we hold about you and to receive a copy of it; to have inaccurate or incomplete data corrected; to have data erased, or its processing restricted, in the circumstances the law provides; to receive the data you gave us in a structured, machine-readable format; to object to direct marketing at any time; to object to processing carried out by automated means; and to withdraw any consent you have given, without affecting processing that took place before withdrawal.

To exercise a right, contact our privacy contact at haider@projectgetout.com. We will confirm your identity before acting, because the data we hold is sensitive and we must not release it to the wrong person. We aim to respond within 30 days, and we will tell you if we need longer. Some rights are limited by law: we cannot delete records that anti-money laundering, tax or other law requires us to keep, we cannot release information that would reveal another person’s data or that is subject to legal privilege or an investigation, and where you withdraw consent or ask for erasure during an engagement we may be unable to continue the services.

If you are unhappy with how we have handled your data or your request, tell us first and we will try to resolve it. You also have the right to complain to a supervisory authority: the UAE Data Office for the PDPL; the Office of the Australian Information Commissioner if you are in Australia; the Information Commissioner’s Office if you are in the United Kingdom; or the data protection authority of your country in the European Union.

13

Cookies and analytics

Our website uses cookies and similar technologies. Essential cookies make the site and checkout work and are always on. Analytics cookies help us understand how the site is used. Marketing cookies and pixels from advertising and social platforms allow us to measure our campaigns and show relevant content, and are set only with your consent. You can accept or refuse non-essential cookies through the settings banner when you first visit, change your choice at any time through the cookie settings link on our site, and control cookies through your browser. Refusing non-essential cookies does not affect your ability to buy from or engage us.

14

Changes to this policy and how to contact us

We will update this policy as our services, providers or the law change. The effective date at the top tells you when it was last revised, and where a change materially affects how we use your data we will tell current clients and subscribers directly. Questions, requests and complaints about privacy should be sent to our privacy contact at haider@projectgetout.com.