Legal
Privacy notice
How Expandus collects, uses, shares and protects personal data across the markets we serve.
Indicative intelligence, not regulated advice
Expandus produces indicative market intelligence, readiness scoring, corridor analysis and cost bands. These outputs are informational and are not legal, tax, immigration, audit, accounting or financial advice. Regulated services are delivered by qualified third-party providers where required, and all outputs remain subject to provider confirmation and jurisdiction-specific rules.
1. Who this notice covers
This notice applies to the Expandus website, assessments, Blueprints and customer workspace. Where Expandus decides why and how personal data is processed — for example, account data and assessment inputs — it acts as a controller. Where it processes data on documented instructions from a customer organisation, or passes information to a provider you have asked us to engage, it acts as a processor or as a separate controller alongside that provider. The role that applies depends on the activity described in each section below.
2. Categories of data and why we use them
- Account and identity data (name, work email, company, sign-in metadata) — to create and secure your account and workspace.
- Assessment and Blueprint inputs (origin market, target markets, activity, structure, timeline, budget signals) — to generate indicative readiness scores, corridor analysis and roadmaps.
- Launch and coordination data (launch requests, projects, tasks, provider assignments) — to coordinate execution you have requested.
- Documents you upload — to fulfil document requests raised for your expansion workflow.
- Contact and support messages — to answer enquiries and provide support.
- Technical and security data (device, browser and log information generated when you use the service) — to keep the service available, debug faults and prevent abuse.
3. Lawful bases (where applicable)
Where EU/UK data protection law applies, we rely on: performance of a contract (running your account, assessments and coordination work); legitimate interests (service security, fault diagnosis, product improvement, and responding to business enquiries); consent (optional analytics or marketing storage, which is off unless you turn it on); and legal obligation (where we must keep or disclose records). Other jurisdictions apply their own equivalents; where a jurisdiction requires a different basis, we apply that local requirement.
4. Service providers and subprocessors
We use third-party infrastructure and service vendors to host the platform, store documents, authenticate users, and deliver assistive features. Where you ask us to coordinate execution, information necessary to that engagement is shared with the qualified providers involved. We share only what is needed for the purpose, and we do not sell personal data.
The integrated services, what each is used for, and which of them run only when a feature is enabled, are listed on the Subprocessors and service providers page. Listing a service there does not by itself mean a data processing agreement or transfer safeguard has been completed for it. If you need the position and the provider list relevant to your account, request it through the contact route below.
5. Retention principles
We keep personal data for as long as your account or engagement is active, and afterwards only for as long as needed for the purpose it was collected, to resolve disputes, or to meet a legal or record-keeping requirement that applies to us. This notice does not publish fixed deletion timetables; where you need the retention period that applies to a specific record, ask us and we will confirm what applies.
6. Security
Access to customer data is restricted by authenticated accounts, role-based internal permissions and database-level access rules, and documents are exchanged through authorised, expiring links. No method of transmission or storage is completely secure, and this notice does not claim any certification, audit outcome or security guarantee.
7. International transfers
Expandus is used across multiple countries, so personal data may be processed outside the country where you are located — including where a provider, vendor or member of our team operates. Where a transfer is subject to local transfer rules, we take the steps that those rules require before the transfer takes place. We do not claim any specific adequacy decision or transfer mechanism in this notice. You can see which services are integrated on the Subprocessors and service providers page; contact us if you need the transfer details that apply to your engagement.
8. Automated recommendations and AI-assisted explanations
Assessment scores, corridor rankings, cost bands and recommended next steps are produced by deterministic scoring rules applied to the answers you provide, and some explanatory text may be AI-assisted. These outputs are indicative and are reviewed or confirmed by people before any regulated action is taken. They do not by themselves produce legal or similarly significant effects, and you can ask for a human explanation or review of any recommendation shown to you.
9. Your rights
European Union / United Kingdom (GDPR and UK GDPR): Access, rectification, erasure, restriction, portability, objection (including to processing based on legitimate interests), withdrawal of consent at any time, and the right to complain to your supervisory authority.
United Arab Emirates (PDPL): Access to and a copy of your data, correction, erasure, restriction and objection to processing, data portability, objection to automated processing, and the right to raise a complaint with the competent authority.
India (Digital Personal Data Protection Act (DPDP)): Access a summary of the personal data processed and the processing activities, correction, completion, updating and erasure, nomination of another individual to exercise rights, and access to a grievance-redressal route before escalating to the Data Protection Board. Provisions of the Act and its rules take effect in stages; we handle requests under the provisions in force at the time of your request.
United States (state privacy laws) (CCPA/CPRA and comparable state laws): Where a state privacy law applies to our processing, you may know, access, correct, delete and obtain a portable copy of personal information, and opt out of any sale, sharing or targeted advertising. Coverage and thresholds differ by state. We do not sell or share personal information for cross-context behavioural advertising, and we will not discriminate against you for exercising a right.
Brazil (LGPD): Confirmation of processing, access, correction of incomplete or outdated data, anonymisation, blocking or deletion of unnecessary or excessive data, portability, information about sharing, and withdrawal of consent.
Canada (PIPEDA and provincial equivalents (including Québec Law 25)): Access to your personal information and an account of its use and disclosure, correction of inaccuracies, withdrawal of consent subject to legal or contractual limits, and, in some provinces, portability and the right to challenge automated decisions.
Australia (Privacy Act and the Australian Privacy Principles): Access to the personal information we hold about you, correction of inaccurate or out-of-date information, the option to deal with us anonymously or by pseudonym where that is lawful and practicable, and the right to complain to the OAIC.
Singapore (PDPA): Access to personal data and information about how it has been used or disclosed in the past year, correction of inaccurate data, withdrawal of consent on reasonable notice, and the right to raise a complaint with the PDPC.
Other markets (Local equivalents): Where another privacy or data-protection law applies to you — for example in Switzerland, Japan, South Korea, South Africa, Saudi Arabia, Nigeria, Kenya, Türkiye or elsewhere — we handle your request under that law. Tell us where you are located and we will apply the local equivalent, including any local complaint route.
Which rights you have depends on where you are, which law applies to the processing, and the lawful basis involved. Some rights are conditional or subject to exemptions, and we may need to verify your identity before acting. We will always tell you what we can and cannot do, and why.
Make a request through the privacy request route.
10. Children
Expandus is a business service and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us so we can review and remove it.
11. Cookies and optional storage
Strictly necessary storage is always active. Analytics and marketing storage stay off until you give affirmative consent, and you can change your choice at any time using the Privacy preferences control in the footer. See the Cookies notice.
12. Complaints and contact
Controller: ExpandUs L.L.C-FZ, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.
Privacy contact: hello@expandusglobal.com
If you are not satisfied with our response, you may complain to the data protection or privacy authority in your country.
Exercise your privacy rights
Use the privacy request route to ask for access, correction, deletion, portability, objection or restriction, withdrawal of consent, or a marketing opt-out. Tell us the country or region you are in and the email address we should reply to, so we can apply the right law and verify the request.
Make a privacy request