All documents

Privacy policy

What data we collect, why, how long we keep it and who we share it with. No legal fog: if something cannot be deleted, it says so.

Edition of 22 August 2026 Draft · under legal review

01What this policy covers

This policy describes what personal data the Platform collects, on what basis it processes it, how long it keeps it and who it shares it with. It applies to the website, your account and support enquiries.

Processing follows UAE personal data protection law. For Clients in the European Union, the provisions of the GDPR apply in addition.

02What we collect

  • Account data: email address, password hash, second-factor settings.
  • Verification documents: proof of identity, a selfie with the document, proof of address — only where the level of activity requires it.
  • Financial data: transaction amounts, withdrawal wallet addresses, accrual history.
  • Technical data: IP address, device and browser type, sign-in times, session identifiers.
  • Support correspondence and any attachments to it.

We collect no biometrics beyond what the verification documents themselves contain, and we do not use Client data to train models.

03Why we process it

  • Performing the contract: running the account, accruals, processing withdrawals.
  • Legal requirement: identity verification, anti-money-laundering, tax and regulatory reporting.
  • Security: detecting suspicious activity and preventing unauthorised access.
  • Improving the service: aggregate statistics not tied to an individual Client.

Marketing emails are sent only with explicit consent and can be switched off in settings in one click.

04Storage and protection

Sensitive data and verification documents are stored encrypted with AES-256-GCM. Encryption keys are kept separately from the application. Passwords are stored as hashes and cannot be recovered.

Staff access to personal data is limited by role and logged. Every time a verification document is opened, it is recorded in the audit log.

Verification documents and transaction records are kept for at least five years after an account is closed — anti-money-laundering law requires it. Technical logs are kept for 12 months.

05Who we share it with

  • The identity verification provider — only what is needed to check the documents.
  • Payment partners and the card issuer — when you use those services.
  • Competent state authorities — upon a lawful request.
  • Auditors and legal advisers — under a confidentiality agreement.

We do not sell personal data and do not pass it to advertising networks.

06Your rights

You may request a copy of your data, ask for inaccuracies to be corrected, restrict processing and withdraw consent to marketing. Requests are made from your account; we reply within 30 days.

The right to erasure is limited by law: transaction records and verification documents cannot be deleted before the mandatory retention period ends. That limit applies after the account is closed too.

07Cookies

Essential cookies keep you signed in and protect your session — the service does not work without them. Analytics cookies are used only with consent and are not linked to your identity.

The partner referral marker is stored for 90 days and used solely to calculate the partner’s reward.

08Contact

Questions about data processing go to the data protection officer through the support form in your account. The contact address and company details will appear here once registration in the UAE is complete.

This document is informational and is not investment advice or a public offer. Where language versions differ, the English edition prevails.