Privacy Policy

We employ advanced security measures and encryption technologies to safeguard your data against unauthorized access and breaches.



Last updated August 2026

PART A: ABOUT THIS NOTICE

1. Who we are

1.1 Escrow Made Easy Limited (“EME”, “we”, “us”, “our”) is a company incorporated and registered in the Dubai International Financial Centre (“DIFC”) under Registered Number 8510 and regulated by the Dubai Financial Services Authority (“DFSA”) under Firm Reference Number F009738.

1.2 Our registered address is DIFC Gate Building 4, Floor 6, Office 16, P.O. Box 38115, Dubai, United Arab Emirates.

1.3 You can contact us by telephone on +971 4 554 5303, by mobile on +971 52 621 2511, by email at [email protected], or online at www.escrowmadeeasy.com. Our business hours are 9:00 a.m. to 5:30 p.m. on Working Days, being Monday to Friday, excluding public holidays observed in the United Arab Emirates.

1.4 EME is the Controller of the Personal Data described in this notice, except where this notice states that EME acts as Processor.

1.5 EME has not appointed a Data Protection Officer and is not required to appoint one, because it does not perform High Risk Processing Activities and has not been directed by the Commissioner to appoint one. Responsibility for oversight of, and compliance with, the Data Protection Legislation is allocated within EME to the Compliance Officer, who may be contacted at [email protected] or in writing at the address in paragraph 1.2, marked for the attention of the Compliance Officer. We will confirm the identity of the person holding that responsibility to the Commissioner on request.

2. What this notice covers, and who it applies to

2.1 This notice explains what Personal Data EME collects, where it comes from, why and on what lawful basis we Process it, who we share it with, whether we transfer it out of the DIFC, how long we keep it, how we keep it secure, the automated and autonomous systems we use, and what rights you have and how to exercise them.

2.2 This is a single notice covering all categories of individual whose Personal Data we Process in connection with our business, namely:

(a) individual clients and prospective clients;

(b) Users and other persons authorised to give instructions or operate an account on a client’s behalf;

(c) directors, partners, officers, employees, shareholders, ultimate beneficial owners and controllers of clients and prospective clients that are not individuals;

(d) counterparties, beneficiaries, payers and their representatives, in each case connected with a Transaction;

(e) introducers and agents, and contact persons at banks, payment service providers, our approved foreign exchange partner, suppliers, auditors and professional advisers;

(f) visitors to our website and users of our onboarding portal; and

(g) complainants and other persons who correspond with us.

2.3 Where a provision of this notice applies only to a particular category of individual, that is stated. Where no category is stated, the provision applies to all of them.

2.4 This notice does not cover the Personal Data of EME’s employees, officers, contractors or job applicants, who are given a separate notice.

2.5 This notice forms part of the Terms. It is to be read together with sections relating to Data Protection, Automated and Autonomous Verification Technology, Your Data Protection Rights and Automated Processing and Verification Technology Notice of the Terms. Part F of this notice supplements the Terms and constitutes the notice required by applicable regulation.

2.6 Where there is any inconsistency between this notice and the Terms as to the information required to be provided under Articles 29 to 31 of the Law or under Regulation 10, this notice prevails. In all other respects the Terms prevail.

3. Definitions

3.1 Words and expressions defined in the Terms have the same meaning in this notice. In particular, “Applicable Law”, “AML Legislation”, “Commissioner”, “Court”, “Data Protection Legislation”, “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing” and “Profiling” have the meanings given in the Terms.

3.2 In addition, in this notice:

(a) “Law” means the Data Protection Law, DIFC Law No. 5 of 2020, as amended;

(b) “Regulations” means the DIFC Data Protection Regulations, as amended;

(c) “Special Categories of Personal Data” has the meaning given in the Law;

(d) “System” means a machine-based system operating in an autonomous or semi-autonomous manner which can Process Personal Data for human-defined purposes or purposes it defines itself, or both, and generate output on the basis of that Processing, as defined in Regulation 10.1.1(a); and “Deployer”, “Operator” and “Provider” have the meanings given in Regulation 10.1.1(b) to (d);

(e) “Onboarding platform” means the Third-party KYC and AML platform used for client onboarding, identity verification, sanctions screening, risk assessment, and transaction monitoring;

(f) “Assistive AI Tool” means the third-party AI assistant used internally for drafting, summarising, translating, analysing, and reviewing documents, subject to human oversight;

(g) “Systems” means the Onboarding platform and the Assistive AI Tool;

(h) “Terms” means EME’s Terms and Conditions in force from time to time; and

(i) “Transaction” means a transaction in respect of which EME provides or is asked to provide its services.

4. How this notice is given, and our commitment as to its accuracy

4.1 This notice is provided in writing, by electronic means. It is published on our website, is made available to you at or before your first access to our onboarding portal, and is provided with the Terms upon completion of onboarding.

4.2 Where we collect Personal Data from you by telephone, or where you otherwise ask us to provide this information orally, we will do so once we have verified your identity.

4.3 We may satisfy our obligations under Articles 29 and 30 of the Law by directing you to this notice. We are not required to provide you with information you already have.

4.4 This notice is written to be concise, transparent, intelligible and easily accessible, in clear and plain language. The statements in it about our Processing activities, and about the codes, certifications and standards to which we or our Systems adhere, are intended to be accurate and not misleading. If you consider any statement in this notice to be inaccurate or misleading, please tell us using the details in section 1 and we will review it.

PART B: OUR PRINCIPLES AND OUR ACCOUNTABILITY

5. How we handle Personal Data

5.1 We Process Personal Data in accordance with the data protection principles in Article 9 of the Law. That means Personal Data is:

(a) Processed on one or more of the lawful bases in Article 10 and, in the case of Special Categories of Personal Data, on one or more of the conditions in Article 11;

(b) Processed lawfully, fairly and in a transparent manner;

(c) Processed for specified, explicit and legitimate purposes determined at the time of collection, and not in a way incompatible with those purposes;

(d) Processed in a manner that permits ready access to it for the purpose of complying with the Law, in particular Articles 9, 14 and 33;

(e) relevant and limited to what is necessary for those purposes;

(f) Processed in accordance with your rights under the Law;

(g) accurate and, where necessary, kept up to date, including by erasure or rectification without undue delay;

(h) kept in a form that permits your identification for no longer than is necessary for those purposes; and

(i) kept secure, using appropriate technical and organisational measures.

5.2 We are responsible for these principles and must be able to demonstrate our compliance with them to the Commissioner.

6. Accountability, records, registration and supervision

6.1 We maintain a written data protection policy, proportionate to the extent and type of our Processing and consistent with the Law, and a programme of technical and organisational measures to demonstrate that our Processing is performed in accordance with the Law. In designing those measures we take into account the nature, scope, context and purpose of the Processing, the risks it presents to individuals, and prevailing information security good industry practice, and we review and update them to reflect legal, operational and technical developments.

6.2 We apply data protection by design and by default. By default we Process only the Personal Data necessary for each specific purpose, and we do not make Personal Data accessible to an indefinite number of persons without your intervention. Where we offer services through our onboarding portal, the default privacy preferences are set so that no more than the minimum Personal Data necessary to deliver or receive the service is collected.

6.3 We maintain a Record of Processing Activities in electronic form containing, as a minimum, the information set out in Article 15(1)(a) to (h) of the Law: our name and contact details and those of any Joint Controller; the purposes of the Processing; the categories of Data Subject; the categories of Personal Data; the categories of recipient, including recipients in Third Countries and International Organisations; the identity of any Third Country or International Organisation to which Personal Data is transferred and, for transfers under Article 27, the documentation of suitable safeguards; the time limits for erasure of each category of Personal Data; and a general description of our technical and organisational security measures. We keep the Record accurate and up to date and make it available to the Commissioner on request.

6.4 Our Record of Processing Activities includes, or links to, documentation covering the lawful basis for the Processing and the sources of the Personal Data, our records of consent, our Controller and Processor contracts, the location of Personal Data, our data protection impact assessments, our records of Personal Data Breaches, the information required in order to Process Special Categories of Personal Data and criminal conviction and offence related data, and our retention and erasure policy documents.

6.5 Regulation 2.2 provides that the obligations in Article 15 and Regulation 2 do not apply to a Controller or Processor employing fewer than fifty persons unless it engages in High Risk Processing Activities. EME employs fewer than fifty persons and does not engage in High Risk Processing Activities. We nevertheless maintain the Record of Processing Activities described in paragraphs 6.3 and 6.4 in full.

6.6 We are registered with the Commissioner and have filed a notification of our Processing operations covering the Processing of Personal Data, the Processing of Special Categories of Personal Data, and the transfer of Personal Data to recipients outside the DIFC that are not subject to laws and regulations ensuring an adequate level of protection. That notification contains a general description of the Processing carried out, an explanation of its purpose, the classes of Data Subject whose Personal Data is Processed, a description of the classes of Personal Data Processed, and a statement of the jurisdictions to which Personal Data is transferred together with an indication of whether each has been assessed as adequate for the purposes of Articles 26 and 27 of the Law. Our notification is kept on the public register maintained by the Commissioner.

6.7 We filed that notification within thirty days of commencing the Processing, we renew it on each anniversary for so long as the Processing continues, and we file an amended notification as soon as possible and in any event within thirty days of any Processing being carried out in a manner different to that described.

6.8 Where a Controller is required to appoint a Data Protection Officer, an assessment of its Processing activities must be submitted to the Commissioner at least once a year, in the format, with the content and by the deadline the Commissioner has approved and published via the DIFC Client Portal. As explained in paragraph 1.5, EME is not required to appoint a Data Protection Officer, and accordingly no annual assessment is due from us. If that position changes we will appoint a Data Protection Officer, submit annual assessments and update this notice.

6.9 We carry out a data protection impact assessment before undertaking any High Risk Processing Activity, and may do so in other cases. We consult the Commissioner where an assessment indicates that the risks to individuals remain particularly high.

6.10 We co-operate with the Commissioner’s audits, investigations and inspections, and respond to any notice of inspection or requirement to produce information within the time prescribed.

6.11 We maintain a register of the Systems we deploy in the form contemplated by Regulation 10.2.2(g). Section 21 explains what that register contains and how you may ask for it.

PART C: THE PERSONAL DATA WE PROCESS

7. Where your Personal Data comes from

7.1 From you: your KYC form and onboarding portal submissions; your identity and address documents and the images you upload; your facial image captured during verification; your correspondence with us, including email, telephone and messaging; your Payment Instructions; and your use of our website and onboarding portal.

7.2 From a client or its representative: if you are a User, or a director, officer, employee, shareholder, ultimate beneficial owner or controller of a client, or a counterparty, beneficiary or payer connected with a Transaction, your Personal Data is usually provided to us by that client or its adviser. Under the Terms, the client is responsible for ensuring that it has the consents and notices in place that are necessary to enable that transfer, and under the Acknowledgment and Consent of the Terms the client confirms that it is authorised to provide your Personal Data and has given you this notice.

7.3 From third parties and public sources: sanctions lists, politically exposed person databases and adverse media sources; identity verification and document authentication services; banks, payment service providers and our approved foreign exchange partner; introducers; corporate registries, public registers and open sources; and the DFSA, the Commissioner, law enforcement and other competent authorities.

7.4 Where we obtain your Personal Data other than from you, we provide you with the information in this notice no later than one month after obtaining it or, if earlier, no later than our first communication with you or the first disclosure of that Personal Data to a Processor or a third party. We are not obliged to do so where you already have the information, where it would be impossible or involve disproportionate effort, where the disclosure is expressly required by Applicable Law or by a Requesting Authority and appropriate measures protect your interests, or where the Personal Data must remain confidential under an obligation of professional secrecy.

7.5 Where we obtain your Personal Data other than from you, the source is one of those listed in paragraphs 7.2 and 7.3. We will identify the specific source on request.

8. The categories of Personal Data we Process

8.1 Depending on your relationship with us, we Process the following categories of Personal Data:

(a) identification data: full name, former names, date and place of birth, gender, nationality and dual nationality, identity document numbers and expiry dates;

(b) contact data: residential and business address, email addresses, telephone and mobile numbers, messaging identifiers;

(c) identity and address document data: passports, national identity cards, residence visas, driving licences, utility bills, bank statements and tenancy documents, and the images of them;

(d) facial image and the biometric data derived from it, generated in the course of verifying your identity;

(e) residence and tax residence data, including tax identification numbers where required;

(f) role and relationship data: your position, shareholding, ownership percentage, control rights, signing authority and relationship to a client, counterparty or Transaction;

(g) employment, occupation and business activity data;

(h) financial data: source of funds and source of wealth information and the documents evidencing it, bank and payment account details, and the amounts and currencies concerned;

(i) Transaction and instruction data: escrow instructions, Payment Instructions, beneficiary details, Value Dates, foreign exchange instructions, statements, invoices and fee records;

(j) screening data: the results of sanctions, politically exposed person and adverse media searches, including the underlying media and list entries, and the record of the searches carried out;

(k) risk and status data: your customer risk rating, account status, due diligence classification and the record of decisions taken;

(l) correspondence and communications records, including email, telephone notes, messaging and complaint records; and

(m) website and portal data: device and browser information, IP address, access and audit logs, and cookie data as described in section 15.

9. Special Categories of Personal Data

9.1 We Process the following Special Categories of Personal Data:

(a) biometric data derived from your facial image, generated in the course of comparing your face against your identity document and confirming that you are present at the time;

(b) data contained in identity documents which reveals your place of birth or nationality, to the extent that it constitutes a Special Category of Personal Data; and

(c) data relating to criminal convictions, offences, allegations, investigations or proceedings, where it is returned by sanctions, politically exposed person or adverse media screening.

9.2 We rely on the following conditions in Article 11 of the Law:

9.2(a) Your Consent: Where required by law, we will process your Personal Data with your consent. You may withdraw your consent at any time where applicable.

9.2(b) To Provide Our Services: We process your Personal Data where necessary to provide our services, enter into or perform our agreement with you, or respond to your requests.

9.2(c) To Comply with the Law: We process your Personal Data to comply with our legal and regulatory obligations, including anti-money laundering and sanctions requirements.

9.2(d) To Protect Vital Interests: We may process your Personal Data where necessary to protect your life, health, or safety, or that of another person.

9.2(e) Our Legitimate Interests: We may process your Personal Data where necessary for our legitimate business interests, provided these do not override your rights and freedoms. This includes improving our services, preventing fraud, protecting our business, and maintaining the security of our systems.

9.3 Where we Process Special Categories of Personal Data in order to comply with a specific requirement of Applicable Law, we give you clear notice of that Processing as soon as reasonably practicable, unless the obligation in question prohibits us from doing so.

9.4 We do not intentionally Process Special Categories of Personal Data through the Assistive AI Tool, and no condition in Article 11 is relied on in respect of that System.

PART D: WHY WE PROCESS YOUR PERSONAL DATA, AND ON WHAT BASIS

10. Our purposes and the lawful basis for each

10.1 The table below sets out the purposes for which we Process Personal Data and the lawful basis on which we rely for each. Where more than one basis is stated, each applies to a part of the Processing described.

(a) Purpose: Assessing an application, classifying you as a client, and onboarding — Categories of Personal Data used: 8.1(a) to (h) — Lawful basis: Article 10(b): steps taken at your request prior to entering into a contract, and performance of that contract. Article 10(c): compliance with the DFSA Rulebook

(b) Purpose: Customer due diligence, verification of identity, and verification of source of funds and source of wealth — Categories of Personal Data used: 8.1(a) to (h) — Lawful basis: Article 10(c): compliance with the AML Legislation and the DFSA Rulebook. Article 11(h) and 11(j) for Special Categories

(c) Purpose: Screening against sanctions lists, politically exposed person data and adverse media sources, and periodic re-screening — Categories of Personal Data used: 8.1(a), (e), (f), (j) — Lawful basis: Article 10(c). Article 11(h) and 11(j) for Special Categories

(d) Purpose: Customer risk rating and ongoing monitoring of the relationship — Categories of Personal Data used: 8.1(a) to (k) — Lawful basis: Article 10(c). Article 11(h) for Special Categories

(e) Purpose: Establishing and administering the escrow account and any Sub-Account, and receiving and holding Client Money — Categories of Personal Data used: 8.1(a), (b), (h), (i) — Lawful basis: Article 10(b). Article 10(c): the DFSA client money requirements

(f) Purpose: Executing Payment Instructions, arranging foreign exchange through the FX Partner, and settlement — Categories of Personal Data used: 8.1(a), (b), (h), (i) — Lawful basis: Article 10(b)

(g) Purpose: Client Money reconciliation, statements, invoicing and record keeping — Categories of Personal Data used: 8.1(a), (b), (h), (i) — Lawful basis: Article 10(b) and Article 10(c)

(h) Purpose: Transaction monitoring, and the identification, investigation and reporting of suspicious activity — Categories of Personal Data used: 8.1(a) to (k) — Lawful basis: Article 10(c). Article 11(h) for Special Categories

(i) Purpose: Preventing fraud, verifying the authenticity of instructions, and information security — Categories of Personal Data used: 8.1(a) to (m) — Lawful basis: Article 10(f): our legitimate interests, as described in section 11. Article 10(c)

(j) Purpose: Handling complaints in accordance with the DFSA Rulebook — Categories of Personal Data used: 8.1(a), (b), (i), (l) — Lawful basis: Article 10(c) and Article 10(f)

(k) Purpose: Responding to requests, enquiries and directions from the DFSA, the Commissioner, the UAE Financial Intelligence Unit, law enforcement, the Court and other competent authorities — Categories of Personal Data used: Any category, as required — Lawful basis: Article 10(c). Article 11(h) for Special Categories

(l) Purpose: Establishing, exercising or defending legal claims, and conducting regulatory or court proceedings — Categories of Personal Data used: Any category, as required — Lawful basis: Article 10(f). Article 11(f) for Special Categories

(m) Purpose: Drafting, summarisation, translation, cross-referencing and analysis carried out internally with the assistance of the Assistive AI Tool, as described in section 19 — Categories of Personal Data used: 8.1(a) to (l), limited to the specific matter under review — Lawful basis: Article 10(f). Article 10(c) where the task supports translation of KYC documents, sanctions and regulatory enquiry screening, or adverse media checks

(n) Purpose: Administering the relationship, corresponding with you and sending service communications — Categories of Personal Data used: 8.1(a), (b), (f), (i), (l) — Lawful basis: Article 10(b) and Article 10(f)

(o) Purpose: Operating, securing and maintaining the availability of our website and onboarding portal — Categories of Personal Data used: 8.1(a), (b), (m) — Lawful basis: Article 10(f)

(p) Purpose: Internal quality control and audit of our files — Categories of Personal Data used: Any category held on the file — Lawful basis: Article 10(f)

(q) Purpose: Retention and archiving of records — Categories of Personal Data used: Any category retained — Lawful basis: Article 10(c). Article 22(4) of the Law as to continued retention

(r) Purpose: Sending you information about our other products and services — Categories of Personal Data used: 8.1(a), (b) — Lawful basis: Article 10(a): your consent, which is optional and may be withdrawn at any time

11. The legitimate interests and compliance obligations we rely on

11.1 Where we rely on Article 10(f), our legitimate interests are: preventing fraud and ensuring network and information security, each of which Article 13(3) of the Law treats as a legitimate interest where the Processing is necessary and proportionate; protecting our own legal, regulatory and financial position, including in relation to claims; administering our business efficiently, including drafting, summarisation, translation, cross-referencing and analysis carried out with the assistance of the Assistive AI Tool; and maintaining the quality and consistency of our service. We do not rely on legitimate interests where your interests or rights override them.

11.2 Where we rely on Article 10(c), the compliance obligations to which we are subject are: the AML Legislation, including the DFSA Rulebook module governing anti-money laundering, counter-terrorist financing and sanctions, UAE Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025; the DFSA Rulebook more generally, including the modules governing conduct of business and client money; applicable sanctions regimes; and the Data Protection Legislation itself.

12. Where we rely on your consent

12.1 We rely on your consent only where we ask for it for a specific optional purpose. Most of our Processing is carried out in order to perform our contract with you or to comply with Applicable Law, and does not depend on your consent.

12.2 Where we ask for consent, we do so by a clear affirmative act that shows an unambiguous indication that consent is freely given. In practice this means an unticked selection box or another equally straightforward method, accompanied by language that explains the reason we are collecting the Personal Data and the purposes for which it may be used, and a link to this notice explaining how you may exercise your rights, including withdrawal of consent.

12.3 We do not treat a pre-ticked selection box, silence or inactivity as consent.

12.4 Where consent would cover more than one purpose, we obtain it separately for each purpose in a manner that is clearly distinguishable. Where we ask for consent alongside any other matter, the request for consent is clearly distinguishable from that other matter.

12.5 Where explicit consent is required in order to Process Special Categories of Personal Data, we ask for it separately.

12.6 You may withdraw your consent at any time, by either of the methods in section 36. Withdrawing consent is at least as easy as giving it, and does not require undue effort. Withdrawal does not affect the lawfulness of Processing carried out before it, and does not affect Processing carried out on any other lawful basis, including compliance with Applicable Law.

12.7 Where Processing on the basis of consent is continuing rather than a single discrete incident, we assess the ongoing validity of that consent, taking into account whether you would still reasonably expect the Processing to continue. If we conclude that you would not, we will contact you without delay and ask you to re-affirm your consent. If you do not do so within a reasonable period, your consent is treated as withdrawn. We also give you the opportunity to re-affirm or withdraw consent periodically.

12.8 We maintain records of consent and of withdrawal of consent, and evaluate our methods and procedures for doing so periodically.

12.9 When consent is withdrawn we cease the Processing concerned as soon as reasonably practicable, ensure that our Processors do the same, and deal with the Personal Data in accordance with section 32.

13. Whether you have to give us your Personal Data

13.1 Most of the Personal Data we ask for is obtained pursuant to a statutory or contractual requirement, or is necessary in order to enter into a contract with us. In particular, the identification, verification, source of funds, source of wealth and screening information described in sections 8 and 9 is required by the AML Legislation and the DFSA Rulebook.

13.2 You are obliged to provide that Personal Data if you wish us to provide our services. If you do not provide it, or if the information you provide is inaccurate, untrue or incomplete, we may be unable to accept your application, may be unable to open or operate your account, may be unable to execute an instruction, and may have to suspend or terminate the relationship. The Terms records your obligation to provide true, complete and accurate information and to keep us updated.

13.3 Where a reply is voluntary rather than obligatory, we say so at the point of collection. In particular, consent to receive information about our other products and services is optional, and declining it has no effect on our provision of services to you.

PART E: MARKETING, DIGITAL COMMUNICATIONS AND OUR WEBSITE

14. Direct marketing and digital communications

14.1 We use your Personal Data for the purposes of digital communications and services, being electronic communications enabled through behavioural advertising, only as described in this section. Electronic communications include email, SMS and multimedia messages, in-application messaging and digital messaging services. Behavioural advertising includes direct marketing, the use of cookies for personalisation, analytics or advertising profile development, and pixel or in-application tracking.

14.2 We will use your contact details to send you information about our other products and services only where you have consented. We tell you, at the time we collect your Personal Data, whether it will be used for those purposes, in a concise, transparent, intelligible and easily accessible form and in clear and plain language.

14.3 The first time we collect your Personal Data for those purposes, we give you the opportunity to refuse or opt out. The Acknowledgment and Consent in the Terms includes a separate, optional item for this purpose.

14.4 You may unsubscribe, change your preferences, refuse or opt out at any time, and every communication we send for these purposes includes a straightforward means of doing so. We provide a reliable and straightforward means of withdrawing consent at any time, together with the information required by Articles 22, 32 and 40 of the Law.

14.5 Where we have had previous contact with you, or you have previously consented, we may continue to rely on that consent or information only where: we obtained the Personal Data directly from you; we obtained it in the course of a sale or the negotiation of a sale of our services; the communications relate to services similar to those to which the previous contact or consent related; you are given the opportunity to unsubscribe, change your preferences, refuse or opt out at any time and whenever you receive a further communication; we assess the ongoing validity of your consent and contact you without delay to ask you to re-affirm it if we conclude that you would no longer reasonably expect the communications to continue; and we provide a reliable and straightforward means of withdrawing consent at any time.

14.6 Before your Personal Data is disclosed for the first time to a third party for the purposes of direct marketing, or used on a third party’s behalf for that purpose, we will inform you and expressly offer you the right to object.

14.7 We do not sell Personal Data, and we do not make Personal Data available to third parties for their own marketing purposes.

15. Our website, our onboarding portal, cookies and privacy preferences

15.1 The default privacy preferences on our website and onboarding portal are set so that no more than the minimum Personal Data necessary to deliver or receive the relevant service is obtained or collected.

15.2 On first use you are prompted to select your privacy preferences. The means of doing so consist of clear, colour-neutral selection boxes or buttons that neither promote nor discourage any particular selection, plain language text explaining what each preference does and how to change it, and an easily accessible preferences link or dashboard by which you can change your preferences on any subsequent use.

15.3 We use cookies and similar technologies that are strictly necessary for the operation and security of our website and onboarding portal. Any cookie or similar technology used for personalisation, analytics or advertising profile development, or for pixel, in-application or cross-application tracking, is used only with your consent, obtained in accordance with section 12.

PART F: AUTOMATED AND AUTONOMOUS SYSTEMS

16. The Systems we use and our role in respect of them

16.1 We use two Systems that Process Personal Data. Each is a machine-based system operating in an autonomous or semi-autonomous manner within the meaning of Regulation 10.1.1(a):

(a) the Onboarding platform: a know your customer and anti-money laundering onboarding and screening platform, provided and operated for us by a third party provider and accessed through that provider’s web application and through application programming interface and connector integration. Our internal reference for it is SYS-001; and

(b) the Assistive AI Tool: a general-purpose assistant, provided and operated for us by a third party provider and accessed through that provider’s web, desktop and mobile interfaces. Our internal reference for it is SYS-002.

16.2 In respect of each System, EME is the Deployer, because each System is operated under our authority, on our direction and for our benefit, and we receive the benefit of its output. A Deployer is deemed to act as Controller in respect of the Processing of Personal Data by the System. Accordingly, EME acts as Controller in respect of Personal Data Processed by each System.

16.3 The Provider of each System is its Operator, because it operates and supervises the System on our direction and for our benefit. An Operator is deemed to act as Processor. The identity of the Provider and Operator of each System is recorded in our Systems register and is provided on request, as described in section 21. EME remains responsible for the acts and omissions of each Operator as if they were its own. There are no Joint Controllers.

16.4 Where Personal Data is Processed for use in, or in order to enable the learning processes of, a System, both we as Deployer and the Operator must comply with the requirements for legitimate and lawful Processing under the Law in substantially the same manner as a Controller and a Processor. We do not Process your Personal Data for the purpose of training or refining the System.

16.5 Neither System is used for High Risk Processing Activities. Accordingly, no Autonomous Systems Officer has been appointed, and none is required.

16.6 Neither System is used solely to make automated decisions about you. Section 23 explains how human review operates.

17. Notice that some Processing is not initiated, controlled or directed by a person

17.1 This section is given to you in clear and explicit terms upon your initial use of, or access to, each System. It alerts you to the underlying technology and processes comprising each System which may Process your Personal Data without that Processing being initiated, controlled or directed by an individual member of our staff. Section 22 explains the impact of the use of the Systems on the exercise of your rights.

17.2 In the Onboarding platform, the following Processing is not initiated, controlled or directed by an individual member of our staff: optical character recognition and extraction of the data on your identity and address documents; assessment of whether those documents appear authentic; biometric comparison of your facial image against the image on your identity document, and assessment of your presence at the time; screening and periodic re-screening of your details against sanctions lists, politically exposed person data and adverse media sources; generation of an indicative risk rating; analysis or translation of data or information provided in a language other than English; and monitoring of Transactions against defined rules and the generation of alerts.

17.3 In the Assistive AI Tool, the generation of output in response to material submitted to it by a member of our staff is not directed step by step by a person. The output is a draft or an analysis; it has no effect until a member of our staff has verified it against the source material and approved it.

17.4 Neither System is capable of defining further purposes for Processing on its own. Each Processes Personal Data only for the purposes we define and approve, which are set out in paragraphs 18.1 and 19.1, together with the rules, thresholds and limits we set and review.

18. The Onboarding platform

18.1 Purposes. The Onboarding platform Processes your Personal Data for the following purposes, each of which is defined by EME:

(a) collecting and holding onboarding form submissions from individual and legal entity clients, capturing and storing know your customer documentation, and progressing submissions through their onboarding states, being new, onboarding, compliance review and approved or rejected;

(b) reading the data on your identity and address documents and assessing whether those documents appear authentic;

(c) comparing your facial image against the image on your identity document and confirming that you are present at the time;

(d) screening you, and connected persons, ultimate beneficial owners and controllers, against sanctions lists, politically exposed person data and adverse media sources, and re-screening periodically;

(e) producing an indicative customer risk rating and account status on the basis of established weighted criteria;

(f) analysing or translating data or information provided in a language other than English; and

(g) monitoring Transactions against defined rules and producing alerts.

18.2 The Onboarding platform is our system of record for onboarding. The Personal Data it Processes comprises your identifying and contact details, your documents and the images of them, your facial image and the biometric data derived from it, your screening results, your risk rating and account status, and your Transaction data.

18.3 Necessity and proportionality. The Onboarding platform is necessary in order for us to discharge our customer due diligence, screening, ongoing monitoring and record keeping obligations at the volume, consistency and level of auditability those obligations require. Screening against consolidated sanctions lists, and continuous re-screening as those lists are updated, cannot be performed reliably by manual means. The fields collected are those required by the applicable onboarding form template, which is configured to the due diligence standard appropriate to your risk classification, with enhanced fields required only in enhanced due diligence cases. No less intrusive means is available, because the Personal Data collected is the Personal Data we are obliged to obtain and retain.

18.4 Human-defined principles and limits. The Onboarding platform cannot define new purposes for Processing. It operates only for the purposes in paragraph 18.1, which are set and reviewed by EME, together with the rules, matching criteria and thresholds we configure and review. There are accordingly no principles on the basis of which, or limits within which, it is capable of defining further purposes for itself, because it has no such capability.

18.5 Output, and how it is used. The Onboarding platform produces extracted document data, an authenticity indicator, a facial comparison and liveness result, screening results, a risk rating and Transaction alerts. A screening match is a matter to be investigated and not a finding; screening tools commonly report individuals who merely share a name with a listed person. Each output is reviewed by a member of our Compliance function, who can see the data on which the output was based and who records the decision taken. The consequences for you may include a request for further documents, a delay in opening or operating your account, enhanced due diligence, or a decision not to accept or to discontinue the relationship.

18.6 Design principles and built-in safeguards. The Onboarding platform is designed so that a person reviews any output before it affects a decision about you and can see the data on which that output was based; so that only the Personal Data necessary for the purposes in paragraph 18.1 is Processed; and so that Personal Data is kept secure, including by encryption of data in transit and periodic penetration testing of the environment.

18.7 Codes, certifications and principles. The Onboarding platform is designed and developed in accordance with the standards applicable to the technology and with the Guidelines for Financial Institutions adopting Enabling Technologies published by the relevant authorities.

19. The Assistive AI Tool

19.1 Purposes. The Assistive AI Tool is used as an internal productivity aid only, within the use cases authorised by EME, each of which is defined by EME:

(a) in our sales function: drafting client proposals, summarising meeting notes, and preparing correspondence and reports;

(b) in our accounts function: drafting invoices and non-critical reports, and correlating financial data for human review;

(c) in our compliance function: summarising regulatory documents, drafting internal notices, and cross-referencing; and

(d) in our anti-money laundering function: drafting reports, correlating information from multiple sources, translating know your customer documents with quality assurance, assisting with sanctions and regulatory enquiry screening with the final disposition taken by the Money Laundering Reporting Officer, and assisting with adverse media checks.

19.2 The Policy excludes the following: any direct interaction between the Assistive AI Tool and our critical accounting, enterprise resource planning, ledger, banking or payment systems; any use that is not for EME’s business; the provision of final compliance advice; and any client-facing output that has not been reviewed by our Compliance function and signed off by the Senior Executive Officer.

19.3 Necessity and proportionality. The Assistive AI Tool is used to reduce drafting, summarisation, translation and cross-referencing effort in a small compliance and operations team. It is a first-draft and analytical aid. It is not a system of record and it is not a decision-maker. No regulatory obligation is discharged by the Assistive AI Tool itself: every output is verified against the source documents and approved by a qualified member of staff before use. Input is limited to the specific document or subject under review, on a matter-by-matter basis. Our client base is not uploaded in bulk. Manual drafting, translation and searching remain available and are used where the material is too sensitive to submit.

19.4 Human-defined principles and limits. The Assistive AI Tool does not define its own purposes for Processing Personal Data. The purposes for which it may Process Personal Data, the material that may be submitted to it, and the persons who may use it are defined in 19.1 and are reviewed by EME. The limits within which it operates are the authorised use cases in paragraph 19.1, the exclusions in paragraph 19.2, the requirement in paragraph 19.3 that every output be verified against source material and approved by a qualified member of staff, and the restriction of input to the matter under review.

19.5 Output, and how it is used. The Assistive AI Tool produces drafts, summaries, translations, correlations of information and analyses in text form. No output is used, sent, relied upon or placed on a file until a member of our staff has verified it against the source material and approved it. No output is the sole basis for any decision about you, and no output is provided to you or to any third party unless it has been reviewed by our Compliance function and signed off by the Senior Executive Officer.

19.6 Design principles and built-in safeguards. The Assistive AI Tool is designed and operated so that Processing is subject to the Operator’s technical and organisational security measures, contractual confidentiality obligations, and security incident notification commitments, and so that material submitted to it is Processed only on our instructions and for the purposes we specify. Within EME, the safeguards are the input restrictions and the mandatory human verification and approval described in paragraphs 19.2 to 19.5.

19.7 Codes, certifications and principles. The Assistive AI Tool is designed and developed in accordance with the Operator’s published safety and responsible development framework and its published commercial terms and data processing addendum.

19.8 The Assistive AI Tool is not our system of record. The authoritative record of your Personal Data is held in the Onboarding platform and in our own systems. Material submitted to the Assistive AI Tool is retained only for so long as the matter requires and is then deleted from our workspace within it.

20. The general requirements we apply to both Systems

20.1 Each System is designed in accordance with the concepts required by Regulation 10.3.1, namely that it be ethical, in that algorithmic decisions and the associated data lineage should be unbiased or bias mitigated; fair, in that it should treat all individuals equally and fairly regardless of race, gender or other subjective factors and should avoid or mitigate potential and unjust bias; transparent, in that its Processing of Personal Data should be explainable to you and to other stakeholders in non-technical terms and with appropriate supporting evidence; secure, in that it should keep Personal Data protected and confidential and prevent Personal Data Breaches; and accountable, in that mechanisms should be in place to ensure responsibility and accountability for it and its outcomes, including internal governance and control frameworks for monitoring it.

20.2 We do not use, operate or receive the benefit of or output from a System unless it is capable of Processing Personal Data only for purposes that are human-defined or human-approved, or defined by the System itself solely on the basis of human-defined principles and solely within the limits of human-defined constraints, and unless it is designed in compliance with the concepts in paragraph 20.1 and complies with any audit and certification requirements the Commissioner may establish from time to time. Neither System is capable of defining purposes for itself, as stated in paragraphs 17.4, 18.4 and 19.4.

20.3 We do not use a System to engage in High Risk Processing Activities. If that position were to change, we would do so only where the Commissioner had established audit and certification requirements applicable to Systems used in such activities, the System complied with those requirements, the System Processed Personal Data solely for human-defined or human-approved purposes, and an Autonomous Systems Officer had been appointed.

20.4 We keep the structure of our Systems register and this Part F under review against amendments to Regulation 10 and any further guidance or certification requirements issued by the Commissioner.

21. The register and the evidence available to you on request

21.1 We maintain a register of the Systems we deploy. On request by any relevant party, we will provide that register, which lists in respect of each System: the use cases, and the necessity and proportionality of the Processing activities or categories of Processing activity in which the System is used; how information in the System can be accessed by individuals in accordance with Articles 32 to 40 of the Law; whether the System will be used solely to make automated decisions; the third parties and, to the extent permitted by Applicable Law, the Requesting Authorities with which Personal Data used in the System is Processed as part of stable arrangements other than on an occasional basis; the third parties and Requesting Authorities with which Personal Data used in the System is Processed on one or more of the lawful bases in Article 10 or Article 11 of the Law; the contractual obligations of any Joint Controller, Processor or Sub-processor; and where those third parties and authorities are located, together with the appropriate safeguards for exporting Personal Data to them.

21.2 On request by an affected party, we will provide evidence of each System’s compliance with any audit or certification requirements the Commissioner establishes from time to time.

21.3 On request by an affected party, we will provide evidence of any algorithm that causes a System to seek human intervention where Processing may result in an unfair or discriminatory impact on an individual, together with our assessment of the risk and impact of Processing by the System resulting in unjust bias or High Risk Processing.

21.4 On request by a relevant party, we will provide evidence of any algorithm that causes a System to seek human intervention where Personal Data Processed by it must be accessed by or on behalf of competent government authorities, including law enforcement, for the purposes of the prevention or prosecution of alleged or confirmed criminal offences, together with our assessment of the risk and impact in that respect.

21.5 On request by a relevant party, we will provide evidence of any algorithm that instructs a System to seek human intervention where Processing by it may result in non-compliance with Regulation 9, together with our assessment of the risk and impact in that respect.

21.6 We will provide any other information the Commissioner requests in order to demonstrate our compliance with the Law, the Regulations or other Applicable Law.

21.7 Information provided under paragraphs 21.2 to 21.5 may be redacted or summarised, as reasonably determined by us or the Operator, solely to the minimum extent necessary to protect intellectual property rights in the System or in any raw data used to train it, or to comply with restrictions under Applicable Law. Where information is redacted or summarised, the full and unredacted information is provided to the Commissioner on request, together with any revisions the Commissioner requires.

21.8 Requests under this section should be made using the details in section 36.

22. The effect of the Systems on your rights

22.1 Your rights under the Law subsist in respect of Personal Data Processed by each System. Please read this section carefully. It explains, as Article 29(1)(h)(ix) of the Law and Regulation 10.2.2(a) require, how our Processing may restrict or prevent the exercise of certain of those rights, and what the expected impact on them is.

22.2 In respect of Personal Data Processed by the Onboarding platform, four rights are restricted:

22.2(a) Access. We may withhold information where releasing it would obstruct an official or legal inquiry, investigation or procedure, or prejudice the prevention, detection, investigation or prosecution of criminal offences. We are prohibited by law from telling you whether we have made, or have been asked about, a report of suspicious activity, or from disclosing the contents of any such report.

22.2(b) Rectification. We will correct inaccurate Personal Data, but we will not alter the record of what a document originally showed or what a screening search originally returned, because we must keep an accurate record of the checks we carried out and of the information on which we acted. Rectification of that record is not feasible for that reason, and this notice states expressly that it will not be carried out.

22.2(c) Erasure. We will not erase this Personal Data for so long as we are required to retain it by Applicable Law, or for so long as it is required for the establishment or defence of legal claims. We will not erase your verification, screening, risk rating or monitoring records during the statutory retention period, even if you ask us to and even if you close your account. Erasure of those records is not feasible for that reason, and this notice states expressly that it will not be carried out.

22.2(d) Objection. Processing by the Onboarding platform which produces legal consequences for you is authorised by Applicable Law, because the law governing the monitoring and prevention of money laundering, fraud, counter-terrorist financing and tax evasion expressly permits it. An objection therefore cannot be implemented for so long as we are required to carry out that Processing. We will consider and reply to any objection, but we will continue to verify, screen, risk rate and monitor for as long as the law requires. We cannot provide our services to you without doing so.

22.3 In respect of Personal Data Processed by the Assistive AI Tool, your rights are not restricted. That System is not our system of record. A request is satisfied against the Onboarding platform and our own systems, and any material within our workspace in the Assistive AI Tool containing your Personal Data is located and deleted as part of our response.

22.4 The restrictions in paragraph 22.2 are the restrictions and exemptions provided for by the Law. We rely on any such restriction or exemption only to the extent, and for so long as, the Law permits. Nothing in this notice or in the Terms operates to exclude, limit, waive or vary any right conferred on you by the Law, save as the Law expressly provides.

22.5 So that we can satisfy ourselves that you understand and acknowledge the extent of these restrictions, the Acknowledgment and Consent in the Terms asks you to confirm that you have read and that you understand that the rights of access, rectification, erasure and objection are restricted to the extent described.

22.6 Where we rely on a restriction on the provision of information to you, we will inform you in writing without undue delay of the fact of the restriction, of the reasons for it, of your right to lodge a complaint with the Commissioner and of your right to apply to the Court, except to the extent that doing so would undermine the purpose of the restriction.

23. Automated decision-making, Profiling and manual review

23.1 You have the right to object to any decision based solely on automated Processing, including Profiling, which produces legal consequences for you or other seriously impactful consequences, and to require that decision to be reviewed manually.

23.2 No decision we take about you is based solely on automated Processing. Every output of the Onboarding platform that could affect a decision about you is reviewed by a member of our Compliance function, who can see the data on which the output was based and who records the decision. Every output of the Assistive AI Tool is verified against source material and approved by a qualified member of staff before use. You may request an explanation of any outcome, request that it be reconsidered, and submit further information or documents for consideration.

23.3 The logic involved in the automated Processing is as follows: the Onboarding platform extracts data from your documents and assesses their authenticity; it compares your facial image against your document image and assesses your presence; it matches your details against sanctions, politically exposed person and adverse media data sources using matching criteria we configure; it applies established weighted criteria to produce an indicative risk rating; and it applies defined rules and thresholds to Transaction data to produce alerts. The significance and possible outcomes for you are described in paragraph 18.5.

23.4 Where Processing by a System produces legal consequences for you, it is authorised by Applicable Law concerning fraud, counter-terrorism, money laundering and tax evasion monitoring and prevention, and we maintain the safeguards required in respect of such Processing, including the ability for the Processing to be reviewed manually.

23.5 We do not base any decision affecting you solely on the automated Processing, including Profiling, of Special Categories of Personal Data.

24. Challenging the outcome of Processing by a System

24.1 In addition to your rights in Part I, you may submit a complaint challenging the outcome of the Processing of your Personal Data by a System, in accordance with Parts 9 and 10 of the Law. Section 38 explains how.

PART G: SHARING, TRANSFERS, SECURITY AND BREACHES

25. Who we share your Personal Data with

25.1 We disclose Personal Data to the following recipients and categories of recipient:

(a) the provider of the Onboarding platform, as Operator and Processor, together with the cloud infrastructure provider that hosts that platform;

(b) the provider of the Assistive AI Tool, as Operator and Processor, together with that provider’s published sub-processors, being its cloud infrastructure, billing, communications, single sign-on and security, fraud detection, identity verification, search and customer support providers;

(c) the provider of the productivity and document systems in which our own records are held;

(d) the sources against which screening is carried out, being sanctions list, politically exposed person and adverse media data providers;

(e) banks, payment service providers and our approved foreign exchange partner, and any bank or payment service provider with which a Sub-Account is established;

(f) our auditors, including our Client Money Auditor, our external legal advisers and our insurers;

(g) introducers and agents, to the extent relevant to an introduction or to instructions given on your behalf;

(h) the DFSA, the Commissioner, the UAE Financial Intelligence Unit, law enforcement agencies, the Court and other competent authorities, where we are required or permitted to disclose it. The Terms records your agreement that we may share Personal Data, information and documents with any law enforcement or regulatory body and in order to perform identity and other searches to comply with our legal obligations, and that we and our service providers may store the results of those searches and the fact that they have taken place; and

(i) a transferee of our rights and obligations, where we assign or transfer them in accordance with the Terms.

25.2 We do not disclose Personal Data to any other person, except as you instruct or as Applicable Law requires or permits.

25.3 The identity of each recipient described in paragraphs 25.1(a) to (d) is recorded in our Record of Processing Activities and, in the case of a System, in our Systems register. We will identify any of them to you on request, using the details in section 36.

26. Processors, Sub-processors and our own role as Processor

26.1 Each Processor we appoint is engaged under a legally binding written agreement which sets out the subject matter and duration of the Processing, its nature and purpose, the type of Personal Data and the categories of Data Subject concerned, and our obligations and rights, and which commits the Processor to: Process Personal Data only on our documented instructions unless required to do otherwise by Applicable Law; ensure that persons authorised to Process the Personal Data are subject to binding duties of confidentiality; implement appropriate technical and organisational measures; comply with the conditions for engaging a Sub-processor; assist us in responding to requests by individuals exercising their rights; assist us with our obligations as to security, data protection impact assessments, prior consultation and the notification of Personal Data Breaches; delete or return Personal Data at the end of the services; make available the information necessary to demonstrate compliance; and permit and assist with audits and inspections by us, our auditor or the Commissioner.

26.2 We appoint Processors only where they provide sufficient assurances that they will implement appropriate technical and organisational measures that ensure the Processing meets the requirements of the Law and protects your rights. Under the Terms, clients give us prior general authorisation to appoint Processors, and we remain responsible for the acts and omissions of any Processor as if they were our own.

26.3 A Processor may not engage a Sub-processor without our prior written authorisation. Where we give a general authorisation, we do so only where conditions are in place enabling present and future Sub-processors to give the assurances described in paragraph 26.2, and the Processor must inform us of any intended addition or replacement of a Sub-processor and take account of any good faith objection we raise. Each Sub-processor must be engaged under a written agreement fully delegating the obligations the Processor owes to us, and the Processor remains fully liable to us for the Sub-processor’s performance.

26.4 Our Controller and Processor contracts are recorded in, or linked to, our Record of Processing Activities as described in paragraph 6.4. A summary of the contractual obligations imposed on each Operator is available on request, as described in section 21.

26.5 Where EME acts as Processor on a client’s instructions under the Terms, that client is the Controller. A request to exercise your rights in respect of that Personal Data should be directed to the client, and we will render the assistance provided for in the Terms.

27. Requests from public authorities

27.1 Where we or our Processors receive a request from a public authority for the disclosure and transfer of Personal Data, we exercise reasonable caution and diligence to determine the validity and proportionality of the request and to ensure that any disclosure is made solely for the purpose of meeting the objectives identified in it; we assess the impact of the proposed transfer in light of the potential risks to you and, where appropriate, implement measures to minimise those risks, including by redacting or minimising the Personal Data transferred or applying technical or other safeguards; and, where reasonably practicable, we obtain written and binding assurances from the authority that it will respect your rights and comply with the general data protection principles. We may consult the Commissioner on any such matter.

28. Transfers of Personal Data out of the DIFC

28.1 We transfer Personal Data out of the DIFC to the following jurisdictions:

(a) the United Arab Emirates outside the DIFC, being the primary location of the Onboarding platform and of our banking and payment arrangements;

(b) the United Kingdom, being the location of the mirrored backup and disaster recovery environment of the Onboarding platform;

(c) the United States, being the location of the Operator of the Assistive AI Tool; and

(d) any other jurisdiction where a Transaction, a payment, or a request from a regulator, law enforcement agency or court requires it.

28.2 The United Kingdom is included in the list of jurisdictions the Commissioner has assessed as ensuring an adequate level of protection, set out in Appendix 3 to the Regulations. Transfers to an adequate jurisdiction are made under Article 26 of the Law and require no specific authorisation or notification.

28.3 Where a jurisdiction has not been assessed as adequate, we transfer Personal Data only where:

(a) appropriate safeguards are in place under Article 27(1)(a) and Article 27(2), and enforceable rights and effective legal remedies are available to you. The safeguard we use for this purpose is one of the two sets of standard contractual clauses approved and published by the Commissioner under Article 27(2)(c) and Regulation 5, which are available on the Data Protection section of the DIFC website; or

(b) one of the derogations in Article 27(3) applies, and in particular: Article 27(3)(b), where the transfer is necessary for the performance of a contract between you and us or the implementation of pre-contractual measures taken at your request; Article 27(3)(f), where the transfer is necessary for the establishment, exercise or defence of a legal claim; Article 27(3)(i), where the transfer is necessary for compliance with an obligation under Applicable Law to which we are subject or is made at the reasonable request of a regulator, police or other government agency or competent authority; and Article 27(3)(k), where the transfer is necessary to comply with applicable anti-money laundering or counter-terrorist financing obligations or for the prevention or detection of crime.

28.4 In respect of the Assistive AI Tool, the Operator’s data processing addendum incorporates standard contractual clauses for international transfers, together with contractual confidentiality obligations, published sub-processor commitments, technical and organisational security measures and notification of changes to sub-processors.

28.5 In respect of the Onboarding platform, Personal Data is held primarily in the United Arab Emirates, with a mirrored backup and disaster recovery environment in the United Kingdom, which is an adequate jurisdiction. Data in transit is encrypted using HTTPS and the environment is subject to periodic penetration testing. Certification against the applicable international information security standard is in progress and is not yet complete. For any transfer to a jurisdiction that has not been assessed as adequate, we rely on the derogations described in paragraph 28.3(b), and in particular Article 27(3)(b), 27(3)(f), 27(3)(i) and 27(3)(k).

28.6 You may obtain a copy of the safeguards relied on, or details of where they have been made available, by contacting us using the details in section 36.

28.7 We do not transfer Personal Data in reliance on Article 27(4) of the Law as a matter of course. If we ever do so, we will inform the Commissioner of the transfer and will inform you of the transfer and of the compelling legitimate interests relied on.

28.8 The Terms records your prior general authorisation for us to transfer Personal Data outside the DIFC as required for the fulfilment of our services, provided that every such transfer is effected in accordance with the Data Protection Legislation. This notice and that paragraph use the same perimeter, being the DIFC.

29. How we keep Personal Data secure

29.1 We implement and maintain appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful Processing, including unauthorised transfers, and against accidental loss, destruction or damage. Those measures ensure a level of security appropriate to the risks associated with the Processing, taking account of any wilful, negligent, accidental, unauthorised or unlawful destruction, loss, alteration or disclosure of, or access to, Personal Data, and against all other unlawful forms of Processing. They include access controls and least-privilege access, binding confidentiality obligations on our personnel, encryption of data in transit, segregation of environments, logging and audit, periodic penetration testing, and measures to ensure the confidentiality, integrity, availability and resilience of Personal Data.

29.2 Any person acting under our authority who has access to Personal Data may Process it only on our instructions, unless required to do otherwise by Applicable Law.

29.3 We review and update these measures where necessary to reflect legal, operational and technical developments.

29.4 The security of your own email, telephone, messaging and other communication channels remains your responsibility under the Terms.

30. Personal Data Breaches

30.1 Where there is a Personal Data Breach that compromises your confidentiality, security or privacy, we notify the Commissioner as soon as practicable in the circumstances, and without undue delay after becoming aware of it, either by writing to [email protected] or by submitting the form available on the Data Protection section of the DIFC website.

30.2 That notification describes the nature of the Personal Data Breach, including, where possible, the categories and approximate number of individuals concerned and the categories and approximate amount of Personal Data records concerned; communicates the name and contact details of the contact point from which more information can be obtained; describes the likely consequences of the Personal Data Breach; and describes the measures taken or proposed in order to address it, including measures to mitigate its possible adverse effects. Where it is not possible to provide all of that information at once, we provide it in phases as it becomes available.

30.3 Where a Personal Data Breach is likely to result in a high risk to your security or rights, we communicate it to you as soon as practicable in the circumstances, in clear and plain language, describing the nature of the breach and containing at least the information in paragraph 30.2 as to the contact point, the likely consequences and the measures taken, and, where possible, making recommendations for you to mitigate its potential adverse effects. Where there is an immediate risk of damage to you, we communicate with you promptly.

30.4 Where communicating with each affected individual would involve disproportionate effort, we may instead make a public communication or take a similar measure by which affected individuals are informed in an equally effective manner. The Commissioner may direct us to communicate a Personal Data Breach to all affected individuals, or to make a public communication, by any reasonable means including email, written letter or media outlets.

30.5 We document every Personal Data Breach in writing, comprising the facts relating to it, its effects and the remedial action taken, in sufficient detail to enable the Commissioner to verify our compliance, and we make that record available without delay on request.

30.6 Our Processors are required to notify us without undue delay after becoming aware of a Personal Data Breach. Where we act as Processor for a client, we notify that client without undue delay on becoming aware of a Personal Data Breach involving its Personal Data, in accordance with the Terms.

PART H: HOW LONG WE KEEP PERSONAL DATA

31. Retention periods

31.1 We keep Personal Data for the periods set out below. Where a period is expressed by reference to the end of the business relationship, that period runs from the date on which the relationship ends, and is not affected by the earlier expiry or termination of the Terms.

(a) Record: Onboarding and customer due diligence records, including identity and address documents and their images, facial images and biometric data, screening results, risk ratings and account status — Retention period: six (6) years from the end of the business relationship — Reason: AML Legislation; DFSA Rulebook

(b) Record: Transaction records, Payment Instructions, foreign exchange records, Client Money records, statements and invoices — Retention period: six (6) years from the date of the Transaction — Reason: DFSA Rulebook; AML Legislation

(c) Record: Records relating to internal or external suspicious activity reports — Retention period: six (6) years from the date of the report — Reason: AML Legislation

(d) Record: Complaint records — Retention period: six (6) years from the resolution of the complaint — Reason: DFSA Rulebook

(e) Record: Correspondence, telephone notes and messaging records relating to the relationship or a Transaction — Retention period: six (6) years from the end of the business relationship — Reason: AML Legislation; DFSA Rulebook; limitation periods for claims

(f) Record: Records of consent and marketing preferences — Retention period: For the duration of the consent and six (6) years after its withdrawal or expiry — Reason: Demonstrating compliance with Article 12

(g) Record: Material submitted to the Assistive AI Tool, and the output generated from it — Retention period: Deleted from our workspace within the Assistive AI Tool on completion of the matter; the approved output is retained on the relevant file for the period applicable to that file — Reason: The Assistive AI Tool is not a system of record

(h) Record: Website and onboarding portal access and audit logs — Retention period: six (6) years — Reason: Information security; investigation of incidents

31.2 Where we cannot specify a fixed period, we determine it by reference to the nature and sensitivity of the record, the purpose for which it is held, the retention requirements of the AML Legislation and the DFSA Rulebook, the limitation period applicable to any claim to which it may be relevant, and whether any inquiry, investigation, proceeding or regulatory request is on foot or in prospect.

31.3 The Terms records that Personal Data will be retained as required by applicable regulatory requirements. Our retention obligations continue after the relationship ends, and are the reason why the rights of rectification and erasure are restricted as described in paragraph 22.2.

32. What happens when we no longer need your Personal Data

32.1 Where the basis for Processing changes or ceases to exist, or where we are required to cease Processing because you have exercised a right, we ensure that all of the Personal Data concerned, including Personal Data held by our Processors, is securely and permanently deleted, anonymised so that no individual can be identified from it, pseudonymised, or securely encrypted.

32.2 Where we are unable to do any of those things, the Personal Data is archived in a manner that puts it beyond further use. That means that we and our Processors are unable to use it to inform any decision in respect of you or in a manner that affects you in any way, other than where it must be cross-checked by automated means solely in order to prevent further Processing relating to you; that no party other than we and our Processors has access to it; that it is protected by technical and organisational security measures equivalent to those applied to live Personal Data; and that we have and comply with a strategy for its permanent deletion, anonymisation, pseudonymisation or secure encryption.

32.3 We are not required to delete, anonymise, pseudonymise, encrypt or put beyond further use Personal Data that is necessary for the establishment or defence of legal claims or that must be retained in order to comply with Applicable Law. We do not retain Personal Data on the basis that it forms part of a dataset used to train or refine an artificial intelligence system.

32.4 We maintain a policy and process for managing Personal Data retained under paragraph 32.3, and we delete, anonymise, pseudonymise, encrypt or put beyond further use that Personal Data once the grounds for retaining it no longer apply.

PART I: YOUR RIGHTS

33. Your right to object

33.1 This section is set out separately, and at the beginning of this Part, because the Law requires us to bring the following rights to your attention in clear language, prominently and separately from other information, no later than our first communication with you.

33.2 You may object at any time, on reasonable grounds relating to your particular situation, to our Processing of your Personal Data where that Processing is carried out on the basis of our legitimate interests, or on the basis that it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.

33.3 You may object at any time to the Processing of your Personal Data for the purposes of direct marketing, including Profiling to the extent that it relates to direct marketing. If you do, we will stop.

33.4 Before your Personal Data is disclosed for the first time to a third party for the purposes of direct marketing, or used on a third party’s behalf for that purpose, we will inform you and expressly offer you the right to object.

33.5 An objection is treated as justified unless we can demonstrate compelling grounds for the Processing which override your interests and rights, or unless the Processing is Processing to which paragraph 22.2(d) applies. Where an objection is justified, we will cease the Processing concerned and deal with the Personal Data in accordance with section 32.

33.6 To object, use either of the methods in section 36.

34. Your other rights

34.1 Withdrawal of consent. Where we Process your Personal Data on the basis of your consent, you may withdraw that consent at any time, as described in section 12.

34.2 Access. You may require us, without charge, to confirm in writing whether we Process Personal Data relating to you and, if we do, to provide information as to the purposes of the Processing, the categories of Personal Data concerned and the recipients or categories of recipient to whom it is disclosed; and to provide a copy of the Personal Data undergoing Processing in an appropriate format, together with any available information as to its source and the information required by Articles 29 and 30 of the Law. Where we provide a copy, we will not disclose the Personal Data of other individuals in a way that may infringe their rights, and may redact or obscure it.

34.3 Rectification. You may require us to rectify inaccurate Personal Data relating to you, unless it is not technically feasible to do so. Paragraph 22.2(b) explains where rectification is not feasible.

34.4 Erasure. You may require us to erase your Personal Data where the Processing is no longer necessary in relation to the purposes for which it was collected; where you have withdrawn consent and there is no other lawful basis; where the Processing is unlawful or the Personal Data must be deleted in order to comply with Applicable Law; or where you have objected and there are no overriding legitimate grounds for us to continue. We are not required to erase Personal Data that we must retain in order to comply with Applicable Law or that is required for the establishment or defence of legal claims. Paragraph 22.2(c) explains where erasure will not be carried out.

34.5 Restriction of Processing. You may require us to restrict Processing where you contest the accuracy of the Personal Data, for a period allowing us to verify it; where the Processing is unlawful and you oppose erasure and ask for restriction instead; where we no longer need the Personal Data but you require it for the establishment, exercise or defence of legal claims; or where you have objected, pending verification of whether our legitimate grounds override yours. Where Processing is restricted, we may continue only to store the Personal Data, to Process it for the establishment, exercise or defence of legal claims, to Process it for the protection of the rights of another person, or to Process it for reasons of Substantial Public Interest. If we lift a restriction we will inform you in writing.

34.6 Notification to recipients. We will communicate any rectification, erasure or restriction of Processing to each recipient to whom the Personal Data has been disclosed, unless that proves impossible or would involve disproportionate effort, and we will tell you who those recipients are if you ask.

34.7 Data portability. Where we Process Personal Data that you have provided to us, by automated means, and on the basis of your consent or the performance of a contract, you may require us to provide it to you in a structured, commonly used and machine-readable format, or to transmit it directly to another Controller where that is technically feasible. We are not required to provide or transmit Personal Data where doing so would infringe the rights of another person. Most of the Personal Data we hold about you is Processed in order to comply with Applicable Law, and this right is not engaged in respect of Personal Data so Processed.

34.8 Automated decision-making. Your rights in respect of decisions based solely on automated Processing, including Profiling, are described in section 23.

34.9 Challenging the outcome of Processing by a System. See section 24.

35. Where your rights are restricted

35.1 Section 22 sets out the restrictions that apply to Personal Data Processed by the Systems, and the expected impact of those restrictions on your rights. Those restrictions are the principal restrictions that apply.

35.2 In addition, we may restrict, wholly or in part, the provision of information to you in response to an access request, to the extent that and for so long as the restriction is a necessary and proportionate measure, having regard to your fundamental rights and legitimate interests, in order to avoid obstructing an official or legal inquiry, investigation or procedure; to avoid prejudicing the prevention, detection, investigation or prosecution of criminal offences or the execution of criminal penalties; to protect public security; to protect national security; or to protect the rights of others. Where we do so, paragraph 22.6 applies.

35.3 We are subject to obligations requiring the retention of certain Personal Data, and to prohibitions on the disclosure of certain matters, including the prohibition on disclosing that a report of suspicious activity has been made or requested. The Law provides for restrictions on and exemptions from your rights in consequence. We rely on any such restriction or exemption only to the extent, and for so long as, the Law permits.

35.4 The Terms records these restrictions and Part F of this notice constitute the notice required by the Law as to the manner in which Processing may restrict or prevent the exercise of your rights.

36. How to exercise your rights

36.1 You may exercise any right in this Part by either of the following methods, and you need not use both:

(a) by email to [email protected]; or

(b) in writing to EME at the address in paragraph 1.2, marked for the attention of the Compliance Officer.

36.2 Neither method requires payment of any charge, the use of any prescribed form, or the creation of any account. The email method is available free of charge via our website without the need to submit data to create an account of any sort, and corresponds to the contact details given in section 1.

36.3 We will respond within one month of receipt. Where a request is particularly complex, or where requests are numerous, we may extend that period by up to two further months, and will notify you of the extension and the reasons for it within one month of receipt.

36.4 Where we have reasonable doubts as to your identity, we may require such further information as is sufficient to confirm it, and the period in paragraph 36.3 does not begin until we have received it.

36.5 Where a request is manifestly unfounded or excessive, in particular by reason of its repetitive character, we may either charge a reasonable fee reflecting the administrative cost of complying, or refuse to act on the request and provide written confirmation of our reasons. We maintain a register of the instances in which we rely on this paragraph or on paragraph 36.3, setting out our reasons, which the Commissioner may inspect.

36.6 Where your request is received by electronic means, and unless you ask otherwise, we will respond in a commonly used electronic form. The information we supply is supplied by reference to the Personal Data as at the time your request is received, except that it may take account of any amendment or deletion made between that time and the time of our response which would have been made regardless of your request.

37. Non-discrimination

37.1 We will not discriminate against you because you have exercised a right under the Law. In particular, we will not deny you goods or services, charge you a different price or rate, including by withholding a discount or other benefit or imposing a penalty, provide you with a lesser level or quality of service, or suggest that we will do any of those things.

37.2 We do not operate any financial or non-financial incentive scheme in exchange for the Processing of Personal Data.

38. Complaints

38.1 If you are not satisfied with how we Process your Personal Data, please tell us first, using either method in section 36, and we will investigate. A complaint about our services generally is handled under the Terms, in accordance with the rules of the DFSA Rulebook: we acknowledge receipt within seven days, provide an update or substantive response within thirty days, and aim to issue our final response within sixty days.

38.2 You may lodge a complaint with the Commissioner. A complaint is lodged by written notice giving your full name and address, identifying the Controller you believe has contravened the Law, setting out a detailed statement of the facts you believe give rise to the contravention, and stating the relief you seek. The Commissioner may be contacted at [email protected] or at the Commissioner of Data Protection, PO Box 74777, DIFC, Dubai, United Arab Emirates. The Commissioner may investigate or mediate the complaint.

38.3 You may also apply to the Court, including for compensation. Recourse to us under paragraph 38.1 is not a condition precedent to a complaint to the Commissioner or to an application to the Court.

PART J: CHANGES TO THIS NOTICE

39. Changes, version and effective date

39.1 We review this notice periodically and will update it where our Processing changes, where we deploy or cease to use a System, or where the Data Protection Legislation changes. The current version is always available on our website.

39.2 Where a change is material, we will notify you by the means set out in the Terms.

39.3 This is version 2.0, effective August 2026. It supersedes any earlier privacy policy issued by EME.