Introduction
Elysium Media FZCO ("we", "our" or "the Platform") is committed to protecting your privacy and complying with all applicable data protection laws, including:
- GDPR (General Data Protection Regulation EU 2016/679)
- Dubai PDPL (Personal Data Protection Law, DIFC Law No. 5 of 2020)
- VARA Regulations (Virtual Assets Regulatory Authority)
- DFSA Rules (Dubai Financial Services Authority)
This policy explains how we collect, use, store and protect your personal data when you use our tokenized real estate investment services.
1. Data Controller
Controller Identity:
- Name: Elysium Media FZCO
- Registration: Dubai Digital Park
- VARA License: Pending
- DFSA License: Pending
- Address: IFZA Business Park, DDP, PO Box 342001, Dubai, United Arab Emirates
- Email: [email protected]
- DPO Email: [email protected]
We act as the data controller of all personal data collected through the Platform.
2. Legal Basis for Processing (GDPR Art. 6)
We process your personal data under the following legal bases:
Contract Performance
Necessary to execute the tokenization and investment services contract that you accept upon registration.
Legal Obligation
Compliance with KYC/AML, VARA, DFSA, FATCA, CRS and anti-terrorism regulations.
Consent
For marketing, non-essential communications and non-technical cookies. You can withdraw consent at any time.
Legitimate Interest
Fraud prevention, platform security, service improvement and anonymized data analysis.
3. Personal Data Collected
We collect the following categories of personal data:
A. Identification Data (KYC)
- Full name, date of birth, nationality
- Identity document (passport, ID card, Emirates ID)
- Proof of address (maximum 3 months old)
- Facial photograph (selfie) for biometric verification
- Tax identification number (TIN)
B. Contact Data
- Email address
- Mobile phone number
- Full postal address
- Language and communication preferences
C. Financial Data
- Banking information (IBAN, SWIFT for withdrawals)
- Blockchain wallet addresses (Ethereum, Polygon)
- Transaction history and operations
- Wealth level and source of funds (AML)
- Accredited investor status (if applicable)
D. Technical Data
- IP address, geolocation
- Device type, browser, operating system
- Cookies and tracking technologies
- Activity logs and access records
- Platform usage data (analytics)
E. Compliance Data
- KYC/AML verification results (via Sumsub)
- Risk score and compliance flags
- FATCA/CRS declarations (if applicable)
- Support communications records
- Disputes or incidents history
Sensitive Data: We do not collect sensitive data (GDPR Art. 9) such as religion, political opinions or health data, except where legally required for compliance.
4. Purpose of Data Processing
We use your personal data to:
- Service Provision: Create and manage your account, process transactions, issue tokens, distribute rents
- KYC/AML Verification: Comply with legal obligations for identification, fraud prevention and money laundering
- Regulatory Compliance: Reports to VARA, DFSA, tax authorities (FATCA/CRS), terrorism prevention
- Communications: Notifications about investments, changes in terms, regulatory updates
- Customer Support: Resolve queries, manage disputes, provide technical assistance
- Security: Fraud protection, detection of suspicious activities, prevention of unauthorized access
- Marketing: Sending offers, market news, available properties (only with consent)
- Analysis and Improvement: Usage statistics, UX optimization, development of new features
5. Data Retention Period
| Data Type | Retention Period |
|---|---|
| Active account data | While account is active |
| KYC/AML data | 10 years from last transaction (UAE AML Law) |
| Transaction history | 7 years (VARA/DFSA requirement) |
| Tax records (FATCA/CRS) | 6 years minimum |
| Marketing communications | Until consent withdrawal |
| Technical logs | 2 years (security and audit) |
| Voluntarily closed account | 90 days (grace period for reactivation) |
Note: Retention periods are calculated from the last interaction or transaction. Once expired, data is securely and irreversibly deleted.
6. User Rights (GDPR Art. 15-22)
Under GDPR and Dubai PDPL, you have the following rights:
Right of Access
Request a copy of all your personal data that we process.
Right of Rectification
Correct inaccurate or incomplete data.
Right to Erasure
Delete your data (except when we have a legal obligation to retain it).
Right to Portability
Receive your data in a structured, readable and transferable format (JSON/CSV).
Right to Object
Object to processing based on legitimate interest (e.g., direct marketing).
Right to Restriction
Limit processing while a dispute about accuracy or legality is resolved.
Withdraw Consent
Revoke consent for marketing or non-essential cookies at any time.
Right to Lodge a Complaint
File a complaint with a data protection authority (AEPD, ICO, CNIL, etc.).
How to exercise your rights: Send request to [email protected] with subject "Data Subject Request". We will respond within a maximum of 30 days.
8. Sharing Data with Third Parties
We share your personal data only when necessary with the following trusted third parties:
| Provider | Purpose | Location |
|---|---|---|
| Sumsub (iDenfy) | Biometric KYC/AML verification | UK (GDPR) |
| Fireblocks | Token and wallet custody | USA (SCCs) |
| KPMG Lower Gulf | Asset audit and certification | UAE |
| Stripe / PayPal | Payment processing | USA/EU (PCI-DSS) |
| AWS (Amazon) | Hosting, storage, database | EU (Ireland) |
| SendGrid | Transactional email sending | USA (SCCs) |
| Intercom | Customer support chat | USA (SCCs) |
Guarantee: All providers sign data processing agreements (DPA) and comply with GDPR. We conduct annual compliance audits.
We may also share data with:
- Regulatory Authorities: VARA, DFSA, tax authorities, law enforcement (when legally required)
- Professional Advisors: Lawyers, auditors, consultants under confidentiality obligations
- Business Buyers: In case of merger, acquisition or asset sale (we will notify you)
We never sell your personal data to third parties for commercial purposes.
9. International Data Transfers
Your data may be transferred and processed outside the European Economic Area (EEA) and UAE, specifically to:
- United States: Cloud providers (AWS), payment processing (Stripe), custody (Fireblocks)
- United Kingdom: KYC/AML services (Sumsub)
- Singapore: Alternative payment processors
Safeguards for international transfers:
Standard Contractual Clauses (SCCs)
Standard contractual clauses approved by the European Commission (Decision 2021/914).
Adequacy Decisions
UK has EU adequacy decision. UAE is currently negotiating its recognition.
Additional Security Measures
End-to-end encryption, pseudonymization, strict access controls, regular audits.
Certifications
Providers certified ISO 27001, SOC 2 Type II, PCI-DSS as applicable.
10. Data Security Measures
We implement state-of-the-art technical and organizational measures to protect your personal data:
Encryption
- TLS 1.3 in transit
- AES-256 at rest
- Backup encryption
Access Control
- Mandatory 2FA
- Least privilege principle
- Audit logs
Monitoring
- 24/7 IDS/IPS
- WAF (Web Application Firewall)
- Anomaly detection
Infrastructure
- Isolated AWS VPC
- Network segregation
- Encrypted daily backups
Personnel
- Continuous security training
- Signed NDAs
- Background checks
Audits
- Quarterly pentesting
- Annual KPMG audits
- Bug bounty program
Breach Notification: In case of a security breach affecting your data, we will notify you within 72 hours according to GDPR Art. 33-34 and report to competent authorities.
11. Contact - Data Protection Officer (DPO)
For any queries related to personal data protection, you can contact our Data Protection Officer:
Contact Information:
- DPO: Sarah Al-Maktoum
- Email: [email protected]
- Phone: +971 505924965
- Address: IFZA Business Park, DDP, PO Box 342001, Dubai, United Arab Emirates
Supervisory Authorities:
- EU/EEA: Your national data protection authority (EDPB list)
- UAE: UAE Data Office
u.ae/data-office - DIFC: Commissioner of Data Protection
difc.ae
Response time: We commit to respond to all privacy-related requests within a maximum of 30 calendar days from receipt.
Updates to this Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technologies or legal requirements. We will notify you of material changes by email and by prominent notice on the Platform with 30 days notice.
Last update: 15/01/2025
Version: 2.0
Next scheduled review: July 2026