Data Protection Officer

Privacy Policy

Comprehensive protection of personal data under GDPR, Dubai PDPL and VARA/DFSA regulations

GDPR Compliant
Dubai PDPL
Updated: 15/01/2025

Introduction

Elysium Media FZCO ("we", "our" or "the Platform") is committed to protecting your privacy and complying with all applicable data protection laws, including:

  • GDPR (General Data Protection Regulation EU 2016/679)
  • Dubai PDPL (Personal Data Protection Law, DIFC Law No. 5 of 2020)
  • VARA Regulations (Virtual Assets Regulatory Authority)
  • DFSA Rules (Dubai Financial Services Authority)

This policy explains how we collect, use, store and protect your personal data when you use our tokenized real estate investment services.

1. Data Controller

Controller Identity:

  • Name: Elysium Media FZCO
  • Registration: Dubai Digital Park
  • VARA License: Pending
  • DFSA License: Pending
  • Address: IFZA Business Park, DDP, PO Box 342001, Dubai, United Arab Emirates
  • Email: [email protected]
  • DPO Email: [email protected]

We act as the data controller of all personal data collected through the Platform.

3. Personal Data Collected

We collect the following categories of personal data:

A. Identification Data (KYC)

  • Full name, date of birth, nationality
  • Identity document (passport, ID card, Emirates ID)
  • Proof of address (maximum 3 months old)
  • Facial photograph (selfie) for biometric verification
  • Tax identification number (TIN)

B. Contact Data

  • Email address
  • Mobile phone number
  • Full postal address
  • Language and communication preferences

C. Financial Data

  • Banking information (IBAN, SWIFT for withdrawals)
  • Blockchain wallet addresses (Ethereum, Polygon)
  • Transaction history and operations
  • Wealth level and source of funds (AML)
  • Accredited investor status (if applicable)

D. Technical Data

  • IP address, geolocation
  • Device type, browser, operating system
  • Cookies and tracking technologies
  • Activity logs and access records
  • Platform usage data (analytics)

E. Compliance Data

  • KYC/AML verification results (via Sumsub)
  • Risk score and compliance flags
  • FATCA/CRS declarations (if applicable)
  • Support communications records
  • Disputes or incidents history

Sensitive Data: We do not collect sensitive data (GDPR Art. 9) such as religion, political opinions or health data, except where legally required for compliance.

4. Purpose of Data Processing

We use your personal data to:

  • Service Provision: Create and manage your account, process transactions, issue tokens, distribute rents
  • KYC/AML Verification: Comply with legal obligations for identification, fraud prevention and money laundering
  • Regulatory Compliance: Reports to VARA, DFSA, tax authorities (FATCA/CRS), terrorism prevention
  • Communications: Notifications about investments, changes in terms, regulatory updates
  • Customer Support: Resolve queries, manage disputes, provide technical assistance
  • Security: Fraud protection, detection of suspicious activities, prevention of unauthorized access
  • Marketing: Sending offers, market news, available properties (only with consent)
  • Analysis and Improvement: Usage statistics, UX optimization, development of new features

5. Data Retention Period

Data Type Retention Period
Active account data While account is active
KYC/AML data 10 years from last transaction (UAE AML Law)
Transaction history 7 years (VARA/DFSA requirement)
Tax records (FATCA/CRS) 6 years minimum
Marketing communications Until consent withdrawal
Technical logs 2 years (security and audit)
Voluntarily closed account 90 days (grace period for reactivation)

Note: Retention periods are calculated from the last interaction or transaction. Once expired, data is securely and irreversibly deleted.

6. User Rights (GDPR Art. 15-22)

Under GDPR and Dubai PDPL, you have the following rights:

Right of Access

Request a copy of all your personal data that we process.

Right of Rectification

Correct inaccurate or incomplete data.

Right to Erasure

Delete your data (except when we have a legal obligation to retain it).

Right to Portability

Receive your data in a structured, readable and transferable format (JSON/CSV).

Right to Object

Object to processing based on legitimate interest (e.g., direct marketing).

Right to Restriction

Limit processing while a dispute about accuracy or legality is resolved.

Withdraw Consent

Revoke consent for marketing or non-essential cookies at any time.

Right to Lodge a Complaint

File a complaint with a data protection authority (AEPD, ICO, CNIL, etc.).

How to exercise your rights: Send request to [email protected] with subject "Data Subject Request". We will respond within a maximum of 30 days.

7. Cookies and Tracking Technologies

We use cookies and similar technologies to improve your experience. For detailed information, please see our Cookie Policy.

Types of cookies used:

  • Essential: Session, authentication, security (no consent required)
  • Functional: Language preferences, currency, UI settings
  • Analytics: Google Analytics, Hotjar (anonymized)
  • Marketing: Meta Pixel, Google Ads (require explicit consent)

You can manage your cookie preferences in your browser settings or through our consent banner.

8. Sharing Data with Third Parties

We share your personal data only when necessary with the following trusted third parties:

Provider Purpose Location
Sumsub (iDenfy) Biometric KYC/AML verification UK (GDPR)
Fireblocks Token and wallet custody USA (SCCs)
KPMG Lower Gulf Asset audit and certification UAE
Stripe / PayPal Payment processing USA/EU (PCI-DSS)
AWS (Amazon) Hosting, storage, database EU (Ireland)
SendGrid Transactional email sending USA (SCCs)
Intercom Customer support chat USA (SCCs)

Guarantee: All providers sign data processing agreements (DPA) and comply with GDPR. We conduct annual compliance audits.

We may also share data with:

  • Regulatory Authorities: VARA, DFSA, tax authorities, law enforcement (when legally required)
  • Professional Advisors: Lawyers, auditors, consultants under confidentiality obligations
  • Business Buyers: In case of merger, acquisition or asset sale (we will notify you)

We never sell your personal data to third parties for commercial purposes.

9. International Data Transfers

Your data may be transferred and processed outside the European Economic Area (EEA) and UAE, specifically to:

  • United States: Cloud providers (AWS), payment processing (Stripe), custody (Fireblocks)
  • United Kingdom: KYC/AML services (Sumsub)
  • Singapore: Alternative payment processors

Safeguards for international transfers:

Standard Contractual Clauses (SCCs)

Standard contractual clauses approved by the European Commission (Decision 2021/914).

Adequacy Decisions

UK has EU adequacy decision. UAE is currently negotiating its recognition.

Additional Security Measures

End-to-end encryption, pseudonymization, strict access controls, regular audits.

Certifications

Providers certified ISO 27001, SOC 2 Type II, PCI-DSS as applicable.

10. Data Security Measures

We implement state-of-the-art technical and organizational measures to protect your personal data:

Encryption

  • TLS 1.3 in transit
  • AES-256 at rest
  • Backup encryption

Access Control

  • Mandatory 2FA
  • Least privilege principle
  • Audit logs

Monitoring

  • 24/7 IDS/IPS
  • WAF (Web Application Firewall)
  • Anomaly detection

Infrastructure

  • Isolated AWS VPC
  • Network segregation
  • Encrypted daily backups

Personnel

  • Continuous security training
  • Signed NDAs
  • Background checks

Audits

  • Quarterly pentesting
  • Annual KPMG audits
  • Bug bounty program

Breach Notification: In case of a security breach affecting your data, we will notify you within 72 hours according to GDPR Art. 33-34 and report to competent authorities.

11. Contact - Data Protection Officer (DPO)

For any queries related to personal data protection, you can contact our Data Protection Officer:

Contact Information:

  • DPO: Sarah Al-Maktoum
  • Email: [email protected]
  • Phone: +971 505924965
  • Address: IFZA Business Park, DDP, PO Box 342001, Dubai, United Arab Emirates

Supervisory Authorities:

Response time: We commit to respond to all privacy-related requests within a maximum of 30 calendar days from receipt.

Updates to this Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technologies or legal requirements. We will notify you of material changes by email and by prominent notice on the Platform with 30 days notice.

Last update: 15/01/2025
Version: 2.0
Next scheduled review: July 2026

1