Licensed Meydan Free Zone Entity | Dubai, UAE
Legal & Compliance

Privacy & Data Protection Policy

Effective 31 August 2026

1

Introduction and Controller Identity

1.1Epiidosis Global Finance LLC-FZ ("Epiidosis", "Company", "we", "us", "our"), registered in a United Arab Emirates free zone under licence number 2422472.01, with its registered office at Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, UAE, respects the privacy of individuals whose personal data it processes and is committed to handling that data lawfully, fairly and transparently.

1.2This Privacy & Data Protection Policy ("Policy") explains what personal data ("Personal Data") the Company collects through the Website and in the course of its business, why it is collected, how it is used, with whom it may be shared, and the rights available to individuals.

1.3The Company acts as data controller in respect of Personal Data it collects for its own business purposes, including onboarding, engagement delivery, compliance and marketing. Where the Company processes data on the documented instructions of a Client, a Third-Party Provider or another controller — for example, data provided by a Client for the purpose of an introduction to a bank — the Company acts as a processor, and the governing engagement, data-processing agreement or instructions of that controller determine the applicable responsibilities in respect of that specific data.

2

Applicable Law and Scope

2.1The Company applies the UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, and its implementing regulations ("UAE PDPL"), as the principal data-protection framework governing its processing activities.

2.2The Company will additionally comply with the EU General Data Protection Regulation ("GDPR") or the UK GDPR where, and only to the extent that, those regimes actually apply to specific processing under their own territorial and material scope rules — for example, where the Company offers services to, or monitors the behaviour of, individuals located in the European Union or United Kingdom in a manner that engages those regimes' extraterritorial provisions.

2.3This Policy does not represent that any other data-protection regime — including, without limitation, the California Consumer Privacy Act, Singapore's Personal Data Protection Act, India's Digital Personal Data Protection Act, or Kenya's Data Protection Act — applies universally to the Company's processing. Where such a regime applies to a specific individual or transaction by virtue of its own applicability criteria, the Company will honour the rights and obligations that regime actually confers, on request and verification.

2.4This Policy applies to Personal Data processed through the Website, in the course of client onboarding and engagement delivery, in recruitment, and in general business correspondence with the Company. It does not apply to information processed entirely by a Third-Party Provider under its own privacy notice.

3

Information We Collect

3.1Depending on the nature of the interaction, the Company may collect and process the following categories of Personal Data:

  • (a) Identity and contact data — full name, nationality, date of birth, passport or national ID details, job title, employer, email address, telephone number and postal address;
  • (b) Corporate and structural data — company registration details, constitutional documents, directors, shareholders, authorised signatories and organisational charts;
  • (c) Beneficial-ownership data — as described in Section 5;
  • (d) Financial data — as described in Section 4;
  • (e) Compliance data — KYC/AML documentation, sanctions and politically exposed person ("PEP") screening results, and adverse-media findings;
  • (f) Recruitment data — CVs, employment history, references and interview notes, where an individual applies for a role with the Company;
  • (g) Technical data — IP address, browser type and version, device identifiers, operating system, referral source, pages visited and interaction logs, collected through the Website and its security systems; and
  • (h) Communications and documents — correspondence with the Company and documents uploaded through the Website or exchanged during an engagement.

3.2A User is not required to provide Personal Data to browse general Website content, but certain data is necessary to respond to an enquiry, progress an engagement, or satisfy the Company's legal and compliance obligations; where such data is not provided, the Company may be unable to proceed with the relevant request.

4

Financial Information

4.1In the course of an engagement, the Company may collect financial information about a Client or a Client's principals, including bank account details, financial statements, credit information, transaction history, asset and liability information, source-of-funds and source-of-wealth documentation, and tax-residency information.

4.2Financial information is processed for the purposes described in Section 7, including engagement delivery, compliance with AML/CFT obligations, and, where relevant, facilitating introductions to Third-Party Providers who will conduct their own independent assessment.

4.3The Company does not sell, rent or otherwise monetise financial information as a data-broking activity.

5

KYC, KYB and Beneficial-Owner Information

5.1Consistent with the Company's Public AML/CFT, Sanctions & Financial Crime Compliance Policy, the Company collects and verifies identity and business information ("KYC" for individuals, "KYB" for entities) proportionate to the risk of the engagement, including identification documents, proof of address, licences, constitutional documents and evidence of good standing.

5.2The Company identifies, where required, the natural persons who ultimately own or control a corporate Client or transaction structure ("beneficial owners"), including their identity, nationality, percentage ownership or control, and PEP status. This information may be obtained directly from the Client, from public beneficial-ownership registers, or from licensed due-diligence and corporate-intelligence providers.

5.3Beneficial-owner Personal Data is processed on the basis of the Company's legal obligation to conduct customer due diligence and, where applicable, the Company's legitimate interest in preventing financial crime, and is retained in accordance with Section 15.

6

Sources of Information

6.1Personal Data may be obtained: directly from the individual or the entity they represent; from public corporate and beneficial-ownership registers; from professional advisers instructed by or on behalf of a Client; from banks and Third-Party Providers involved in a transaction; from licensed due-diligence, sanctions-screening and adverse-media providers; from publicly available sources, including public websites and regulatory filings; and automatically through the Website's technical and security systems.

7

Purposes of Processing

7.1The Company processes Personal Data to: provide and administer the Services; assess and onboard prospective Clients; perform obligations under an Engagement Agreement; conduct KYC/KYB, sanctions screening, PEP screening and other AML/CFT measures; detect, investigate and prevent fraud; manage legal, credit and reputational risk; administer transactions and coordinate with Third-Party Providers; maintain accounting, tax and statutory records; protect the security and integrity of the Company's systems; recruit personnel; respond to lawful requests from courts, regulators and law-enforcement authorities; establish, exercise or defend legal claims; improve and analyse Website performance; and otherwise comply with Applicable Law.

8

Lawful Grounds for Processing

8.1Depending on the applicable data-protection regime and the circumstances, the Company relies on one or more of the following lawful grounds: the individual's consent; the necessity of processing for the performance of a contract to which the individual is party or in order to take steps at their request prior to entering a contract; compliance with a legal obligation (including AML/CFT and tax-reporting obligations); the Company's or a third party's legitimate interests (including fraud prevention, information security and direct marketing to existing business contacts), balanced against the individual's rights; and, in limited cases, the protection of vital interests or grounds necessary for the establishment, exercise or defence of legal claims.

8.2Where consent is the relied-upon ground, it may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal. Consent is not required, and cannot be used to override, processing that is separately required by law, such as AML/CFT record-keeping.

9

Sensitive and Special-Category Data

9.1The Company does not intentionally seek to collect sensitive or special-category data (such as health data, biometric data used for identification, or data revealing racial or ethnic origin, religious belief or political opinion) through ordinary Website forms.

9.2Where such data is unavoidably processed — for example, nationality or place of birth appearing on an identity document collected for KYC purposes, or PEP status derived from a political role — the Company processes it only to the extent necessary for the stated compliance purpose, applies enhanced access controls, and does not use it for any other purpose.

10

Cookies and Tracking Technologies

10.1The Website may use the following categories of cookies and similar tracking technologies:

  • Strictly necessary / security cookies — required for the Website to function and to protect against fraud and abuse;
  • Functional cookies — used to remember User preferences and improve usability;
  • Analytics cookies — used to understand aggregate Website usage and improve content and performance; and
  • Third-party / embedded-service cookies — set by embedded tools such as scheduling widgets, chat tools or video players, subject to that provider's own policy.

10.2Non-essential cookies will be deployed subject to User consent where required by Applicable Law, using a cookie-consent mechanism that allows Users to accept, reject or manage preferences by category. Strictly necessary cookies do not require consent as they are essential to Website operation and security.

10.3The specific cookie inventory in production — including the name, purpose, provider and duration of each cookie actually deployed — must be documented and kept current in a cookie table accessible from the Website's cookie-consent banner, and is incorporated into this Policy by that reference.

10.4Users can manage or withdraw cookie consent at any time through the Website's cookie-preference centre or through their browser settings, noting that disabling certain cookies may affect Website functionality.

11

Sharing of Information

11.1The Company does not sell Personal Data as a business model. The Company may disclose Personal Data, where lawful and proportionate, to:

  • affiliated Epiidosis-branded entities, only where a legitimate business purpose and lawful basis exists for the specific disclosure (see Section 24);
  • banks, lenders, investors, funds and other institutional counterparties involved in a Client's transaction, on a need-to-know basis;
  • lawyers, accountants, auditors and other professional advisers engaged in connection with an engagement;
  • compliance, KYC, sanctions-screening and due-diligence service providers;
  • hosting, cloud infrastructure, cybersecurity and other technology providers who support the Company's systems;
  • government authorities, courts, regulators, tax authorities and law-enforcement bodies, where required or permitted by Applicable Law; and
  • a successor entity in connection with a merger, acquisition, financing or sale of business, subject to confidentiality safeguards.
12

Data Processors and Sub-Processors

12.1Where the Company engages a third party to process Personal Data on its behalf and instructions (a "processor") — for example, a cloud-hosting provider, an email or CRM platform, or a KYC-screening vendor — the Company will enter into a data-processing agreement imposing confidentiality, security, sub-processing, assistance and deletion/return obligations consistent with Applicable Law.

12.2A current register of material processors and their processing purposes should be maintained internally and made available to a data subject or regulator on lawful request.

12.3A processor may only engage a further sub-processor with the Company's authorisation (general or specific) and subject to flow-down of equivalent contractual protections.

13

International Transfers

13.1Because the Company operates in an international business context and may engage processors, Third-Party Providers or group contacts located outside the United Arab Emirates, Personal Data may be transferred to, and processed in, other jurisdictions.

13.2Where such a transfer is subject to the UAE PDPL, GDPR, UK GDPR or another applicable transfer-restriction regime, the Company will use a recognised transfer mechanism available under that regime, which may include: a jurisdictional adequacy determination; standard contractual clauses or equivalent model clauses; binding corporate rules; or another safeguard recognised by the applicable law, together with a documented transfer risk assessment where required.

13.3A data subject may request further information about the safeguards applied to a specific international transfer by contacting the Company using the details in Section 26.

14

Security

14.1The Company implements technical and organisational security measures proportionate to the risk associated with the Personal Data it processes, which may include access controls and role-based permissions, encryption of data in transit and, where appropriate, at rest, network and endpoint security monitoring, secure system-development practices, confidentiality undertakings for personnel and contractors, and incident-response procedures.

14.2No method of transmission or storage is completely secure, and the Company cannot guarantee absolute security. Users should also take reasonable precautions, including safeguarding credentials and independently verifying sensitive instructions in accordance with Section 17 of the Terms of Use.

15

Retention

15.1The Company retains Personal Data only for as long as necessary for the purposes for which it was collected, having regard to: the duration of the Client relationship or engagement; statutory limitation periods; AML/CFT record-keeping obligations (which typically require retention for a defined period following the end of a business relationship or completion of a transaction, in accordance with Applicable Law); tax and accounting retention requirements; the existence of an actual or anticipated dispute or regulatory inquiry; and the Company's legitimate business and archival requirements.

15.2The Company maintains an internal data-retention schedule setting out standard retention periods by data category, which is reviewed periodically and applied consistently, subject to documented exceptions where longer or shorter retention is legally required or justified.

15.3On expiry of the applicable retention period, Personal Data is securely deleted, anonymised or archived in a manner that prevents further processing, except where continued retention is separately required by law.

16

Data-Subject Rights

16.1Subject to the conditions and exceptions of the applicable data-protection law, an individual may have the right to: access the Personal Data the Company holds about them; correct inaccurate or incomplete data; request deletion of data no longer needed for its original purpose; restrict processing in defined circumstances; object to processing based on legitimate interests or for direct marketing; withdraw consent where consent is the processing basis; receive a portable copy of data provided by the individual in a structured, commonly used format, where applicable; and lodge a complaint with a competent supervisory or regulatory authority.

16.2These rights are not absolute. They may be limited or subject to exemption where, for example, continued processing is required by law (including AML/CFT retention obligations), necessary for the establishment or defence of legal claims, or where a request is manifestly unfounded or excessive.

16.3Requests to exercise a right under this Section should be submitted through the contact channel in Section 26. The Company will respond within the period required by the applicable law, or otherwise within a reasonable time.

17

Identity Verification for Rights Requests

17.1To protect against unauthorised disclosure, the Company may require reasonable proof of identity, and, where the request is made by a representative, proof of authority to act on the data subject's behalf, before acting on a rights request.

17.2The Company may decline to act on a request where identity or authority cannot be reasonably verified, and will explain the reason for any such refusal where legally required to do so.

18

Automated Decision-Making and Profiling

18.1The Company does not intend to make decisions based solely on automated processing (without meaningful human involvement) that produce legal effects concerning an individual or similarly significantly affect them, such as an automated decision to decline an engagement, unless such a process is established with the safeguards, transparency and human-review rights required by Applicable Law.

18.2Compliance screening tools (such as sanctions or PEP screening) may generate alerts used to inform, but not to conclusively determine without human review, onboarding and engagement decisions.

19

Children's Data

19.1The Website and Services are directed at corporate, institutional and professional audiences and are not intended for use by children. The Company does not knowingly collect Personal Data from individuals under the age of 18. Where the Company becomes aware that it has inadvertently collected such data, it will take steps to delete it, save where retention is required for a legitimate, lawful purpose.

20

Breach Handling and Notification

20.1The Company maintains an incident-response process to detect, assess, contain and remediate suspected Personal Data breaches.

20.2Where a Personal Data breach is likely to result in a risk to the rights and freedoms of affected individuals, the Company will assess the breach and, where required by Applicable Law, notify the competent supervisory authority within the timeframe required by that law, and notify affected individuals where the breach is likely to result in a high risk to them, unless an exemption applies (for example, where the affected data was rendered unintelligible through encryption).

20.3The Company will document all Personal Data breaches, including their facts, effects and remedial action taken, regardless of whether notification is required.

21

Marketing and Direct Communications

21.1The Company may send direct marketing communications — such as updates on services, market insights or events — to individuals who have consented, or, where permitted by Applicable Law, on the basis of an existing business relationship and a legitimate interest, subject always to an easy opt-out mechanism.

21.2A recipient may unsubscribe from marketing communications at any time using the link or instructions provided in each communication, or by contacting the Company directly. Opting out of marketing does not affect the Company's ability to send transactional, contractual, security or compliance-related communications necessary to the engagement.

22

Third-Party Websites and Embedded Services

22.1The Website may link to, or embed content from, third-party websites and services (for example, scheduling tools, video platforms or social media widgets). Those third parties operate under their own privacy policies and terms, over which the Company has no control, and the Company is not responsible for their data-handling practices.

23

Complaints and Supervisory Authorities

23.1An individual with a privacy concern is encouraged to raise it first with the Company's designated privacy contact using the details in Section 26, so that it can be investigated and addressed directly.

23.2Where applicable, an individual retains the right to lodge a complaint with the competent data-protection supervisory or regulatory authority in their jurisdiction, including, where relevant to UAE-based processing, the UAE Data Office established under the UAE PDPL, without prejudice to any other administrative or judicial remedy.

24

Corporate-Entity Separation

24.1Epiidosis Global Finance LLC-FZ is a separate legal entity from Epiidosis Investments L.L.C. and from any other Epiidosis-branded entity. Personal Data collected by one entity is not transferred to another Epiidosis-branded entity merely because of shared branding, common ownership or informal affiliation.

24.2Any transfer of Personal Data between Epiidosis-branded entities will occur only where there is a specific, documented, lawful purpose and legal basis for that transfer (for example, a Client's engagement spanning both entities under a single, disclosed mandate), and will be conducted subject to appropriate safeguards and, where required, prior notice to the affected individual.

25

Changes to This Policy

25.1The Company may update this Policy to reflect changes in Applicable Law, its business, processing activities or technology. The version published on the Website with the most recent Effective Date applies. Material changes will be highlighted on the Website, and, where required by Applicable Law, affected individuals will be separately notified.

26

Contact

26.1Questions, requests or complaints regarding this Policy or the Company's processing of Personal Data should be directed to:

  • Privacy contact: enquiry@epiidosisglobalfin.com Postal address: Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, UAE