THE.EXCHANGE
Legal

Privacy policy

Version 1.0, effective TODO(legal): effective date.

This policy explains what personal data this website collects, why we collect it, how long we keep it, and what rights you have over it.

This policy describes the website as it is built today: an access-controlled site with a waitlist form, a contact form, a password sign-in and a language preference. The platform described in our whitepaper has not launched, so no wallet, identity-verification or transaction data is collected here yet. Passages marked TODO(legal) are placeholders awaiting confirmation before publication.

About this policy

This policy covers the.exchange website: its public pages, the account issued to you, and the signed-in area. It sits alongside our terms of service.

We have written it to Federal Decree-Law No. 45 of 2021 of the United Arab Emirates on the Protection of Personal Data. Because the site is published in several languages and is read from the European Economic Area and the United Kingdom, it also gives the lawful-basis, transfer and rights information that the General Data Protection Regulation requires. Where the two regimes use different words for the same idea, we have used the clearer one.

If a platform service launches later, the identity verification it requires will involve categories of data this policy does not cover, such as identity documents and evidence of source of funds. That will be described in a separate notice given to you before any such data is collected.

Who is responsible for your data

The controller of the personal data described here is TODO(legal): full legal name of the controlling entity, at TODO(legal): registered address. Our contact point for privacy questions is TODO(legal): privacy contact address, and TODO(legal): whether a data protection officer has been appointed.

Our hosting, database and email infrastructure is run by our group's technology function, which processes this data on our behalf and on our instructions.

What we collect

We collect only what the site needs. There is no payment processing and no advertising here, so the list is short.

We do not ask for, and you should not send us, identity documents, payment card details, financial account numbers, or any special category of data such as health, religious or biometric information. If you put such information in a free-text message, we will delete it once we have dealt with your enquiry.

Our servers also keep short-lived technical logs of requests, which can include an IP address and a browser user agent, for security and for diagnosing faults.

Why we use it, and on what basis

We use your data only for the purposes below, each with the lawful basis we rely on.

Where we rely on a legitimate interest, we have weighed it against your interests and rights, and we use the least data that achieves the purpose. You can object to it, as described under your rights below.

Cookies and browser storage

This site sets no advertising, analytics or tracking cookies. Everything it stores is either strictly necessary to make the site work or a preference you chose, so there is no consent banner and nothing to switch off. The complete list is:

The names above are exact, so you can search for them in your browser's storage panel for this site. The local-storage and session-storage entries never leave your browser, and the configurator draft is never sent to us.

You can delete all of this at any time in your browser's settings for this site. Clearing it signs you out, resets the language to your browser's setting, and discards your configurator draft.

What we do not do

To be explicit about the things a privacy policy is usually vague about:

  • We use no third-party analytics, advertising, tag-manager, session-replay or heat-mapping service on this site.
  • We load no fonts, scripts, stylesheets or images from a third-party content delivery network. Every asset, including our fonts, is served from our own systems, so browsing this site does not disclose your IP address to a third-party host.
  • We do not sell your personal data, and we do not share it for anyone else's marketing.
  • We do not build advertising or behavioural profiles, and we take no decision about you by automated means alone.
  • We do not track you across other websites, and we set no cross-site identifiers.

Who we share it with

We share personal data only where we need to, and only with:

  • our group companies and their technology function, which host and operate this site and its database for us;
  • service providers acting on our instructions, such as hosting, email delivery and error monitoring, under contracts requiring them to protect the data and use it only for us;
  • our professional advisers, such as lawyers and auditors, where they need it in order to advise us;
  • a regulator, court or law-enforcement authority, where we are legally required to disclose it, or where we need it to establish or defend a legal claim.

If a platform service launches, the licensed partners carrying regulated activity, such as payment, custody and verification providers, will receive the data they need for their own compliance duties, and where they act as controllers in their own right they will tell you how they use it. None of that applies to the data this website collects today.

Sending data outside your country

We are based in the United Arab Emirates, and our systems and the people who support them are located there and in other countries where our group operates. If you are in the European Economic Area or the United Kingdom, your data will therefore be transferred outside it.

Where we transfer personal data across a border we rely on an appropriate safeguard, such as an adequacy decision where one applies, or contractual terms approved for the purpose, together with an assessment of the destination. The safeguard relied on for a given transfer is available on request, and is recorded as TODO(legal): confirm the transfer mechanism relied upon.

How long we keep it

We keep personal data only for as long as the purpose needs, then delete it:

  • Waitlist contact details: until you ask to be removed, or until we close the waitlist and a reasonable period has passed.
  • Enquiry messages: for as long as we need them to deal with the enquiry and to keep a record of what was said, then deleted.
  • Session records: deleted from our store when the session expires, which is at the latest 7 days after your last activity.
  • Sign-in records and fault records: for as long as we need them to investigate access to an account and to confirm a fix. The exact period is recorded as TODO(legal): confirm the retention period for sign-in and fault records.

How we protect it

We take technical and organisational measures appropriate to the risk, including:

  • encrypted transport for the whole site, and cookies marked secure and restricted to this site;
  • access control on the systems and database holding this data, limited to the people who need it;
  • storing passwords only as a cryptographic hash, never in readable form;
  • password hashing and session controls that limit exposure of account credentials.

No system is completely secure. If a breach happens that is likely to harm you, we will notify you and the competent authority as the applicable law requires.

Your rights

Subject to the conditions and exceptions in the applicable law, you can ask us to:

  • confirm whether we hold personal data about you, and give you a copy of it;
  • correct data that is inaccurate or incomplete;
  • delete data we no longer have a valid reason to keep;
  • restrict how we use your data while a question about it is resolved;
  • transfer the data you gave us, to you or to someone else, in a machine-readable form, where that right applies;
  • stop using your data where we rely on a legitimate interest, by objecting to that use;
  • stop sending you waitlist updates, by withdrawing your consent, which you can do at any time without affecting anything done before you withdrew it.

To exercise any of these, write to us at TODO(legal): privacy contact address. We will respond within the period the applicable law allows, and we may need to verify who you are first. Exercising a right is free, and we will not treat you differently for doing so.

If you are unhappy with how we have handled your data, please tell us first. You can also complain to the UAE Data Office or, if you are in the European Economic Area or the United Kingdom, to your local supervisory authority.

Children

This site is not directed at children, and the early-access programme is open only to people aged 18 or over. We do not knowingly collect data about children. If you believe a child has sent us personal data, tell us and we will delete it.

Changes to this policy

We will update this policy as the project develops, and in particular before launch and whenever a new service starts collecting data. The version in force is the one on this page, with its version number and effective date at the top, and we will take reasonable steps to signal a material change on the site.

Contact and complaints

For anything about this policy or about your personal data, contact us at TODO(legal): privacy contact address, or write to TODO(legal): postal address for privacy correspondence.

You can also reach our team through the contact form on this site, but please do not put sensitive information in it.

Risk disclosure. Tokenized real-world assets carry risk, including loss of principal. Nothing here is investment advice or an offer to buy or sell securities. Markets may be restricted by jurisdiction and to verified investors.