General Data Protection Regulation (GDPR) Policy
Introduction and Purpose
To help comply with the protection of personal data and relevant laws and regulations and recommendations of the Financial Action Task Force (FATF) where the users of PayBiroPro reside and operate, ’s best practice of Data Protection Regulation which is subject to relevant amendments as and when such amendment takes place is shown in this policy. Data Protection Regulation is a regulation in UAE law on data protection and privacy for all individuals within the United Arab Emirates.
In this Policy “we”, “us”, “our” means and the terms “user”, “individuals”, “non-individuals” means the residents of UAE and the business enterprises registered in the UAE under Federal Decree Law No. 32 of 2021 on Commercial Companies where the users of PayBiroPro reside and operate.
The Data Protection Policy is uniformly applicable to all Users intending to utilize the Services or gain advantages from the Online Platforms of , constituting an integral element of the User Terms and Conditions. Before engaging with the Online Platforms or divulging any personal information, it's imperative to thoroughly examine this Data Protection Policy. Your use of the Online Platforms implies your explicit acknowledgment and adherence to the User Terms and Conditions and, consequently, this Data Protection Policy.
The purpose of ’s Data Protection Compliance policy is to ensure that the customers of get their privacy protected invariably by protection of their personal data and information. Data Protection Policy of optimises
and enhances transparency and accountability in processing of the valuable data and specifics provided by the customers, giving greater control of their personal data and sensitive information.
Scope
’s Data Protection Policy applies both to the processing of personal data taking place within the periphery of the UAE and even outside the territories of UAE if the customer or Controller is residing in the State and carrying out business or working for gain relating to processing personal data inside and outside the State1 for the purpose of the Controller’s statutory functions or in other purposes provided for2 in pursuance of proper discharge of the functions of the Controller3 or for detection and prevention of serious crime or criminal proceedings, following the data protection principles and makes sure that the information is used fairly, legally and transparently for specified and explicit purposes in a way that is adequate and accurate, notwithstanding that the information is relevant and limited to only what is necessary. Record retention techniques at retains relevant information of the customers involved in a transaction for a maximum period of five years from the date of completion of the transaction and/or after off-boarding. also ascertains that there is a strong legal protection by its legal team for more sensitive information like race, ethnic background, political and religious opinions and beliefs, genetics, trade union membership and sex life or orientation, and most pertinently, setting separate safeguards and measures for personal data relating to criminal convictions and offences.
1 Article 2 of Federal Decree by Law No. (45) of 2021
2 Article 1 of Federal Decree by Law No. (45) of 2021
3 ‘Controller’ implies an establishment or natural person that has Personal Data, and by virtue of its activity, determines whether individually or jointly with other persons or establishments, the method and criteria for processing such Personal Data and the purpose of processing it.
Principle of GDPR Policy
With the unerring adherence to Data Protection Regulations of PayitoPro which is applicable in UAE, the Compliance Team at is responsible for compliance regarding the Personal data and Personally Identifiable Information of the customers of 4 in a manner if that is:
- processed legally, without prejudice and in a transparent manner,
- the said information and data is adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed,
- the information is collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes;
- accurate and, where necessary, kept updated;
4 FATF Recommendation on information sharing (2016-2017)
- every reasonable step is taken to ensure that personal data that are inaccurate in terms of the purpose for which that was collected are erased or rectified in an expeditious manner;
- the data is kept in a form which permits identification of customers for no longer than is necessary for the purposes for which the relevant personal data are processed;
- the data is processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
Types of Data collected5
While using the services provided by , certain Personally Identifiable Information (PII) are collected which can be used to identify or contact the customers. The Personally Identifiable Information (PII) may include, but is not limited to:
5 FATF (2016-2017), Consolidated FATF Standards on Information Sharing
- Name
- Address
- Place and Date of birth
- UAE Pass, Emirates ID, Emirates Facial Recognition or Passport number6
- Phone number
- Account password
The Employment Information of the Customers is also collected in the subsequent steps like
- Industry
- Occupation
- Source of Funds
- Employment Category
- Employment Type
- Annual Income
- Net Worth
6 National-level identification systems and processes currently in place or under development in the UAE
- Transaction Volume
- If the Applicant is a Politically Exposed Person (PEP) or not
- Purpose of the account
- Current Banking Partner
- How long the Applicant had that banking relationship
The applicant and/or customer shall have to also provide and upload the following documents and information via mobile applications or web browsers.
- One of the government-issued identity documents bearing the individual’s photograph, an identification number and date of birth
- Passport or UAE Pass, Emirates ID, Emirates Facial Recognition
- National Identity Card
- Driver’s License
- Proof of residence issued within the last three
- Real-time live selfie of themselves
- Industry and
When the customer uses the services provided by by or through a mobile device or web in regards to crypto exchange, collects, retains, uses, or stores data or information automatically certain information automatically, including, but not limited to, device verification, gathering the IP address of the device used by the customers, accessing the photo gallery/media/files/camera and user’s other apps and services including messaging through SMS and usage data, tracking the location from where the customer has logged in, the type of browser used by the customer and the device ID, browser type, browser version, unique device identifiers, and the time and date of visit during login using local storage. User’s device information is also collected including but not limited to IMEI or equipment identification number, IMSI or subscriber identification, MAC address, Android version, device details, network operator, contact list information, Wifi / Data Network connectivity.
also collects information that the browser sends whenever the customer visits the site to login or when the customer accesses the services provided by through a mobile device.
In terms of website handling, uses cookies and tracking technologies like Google Analytics. In terms of cookies, uses cookies like:
- Necessary/Essential cookies which provide the customers with services available through the Website and to enable the customers to use some of the features of . These cookies help to authenticate users and prevent fraudulent use of user accounts.
- Notice acceptance cookies identify if users have accepted the use of cookies on the Website.
- Functionality cookies which allow to remember choices the customer makes when the customers use the website, such as remembering the login details or language preference.
- Tracking and performance cookies which are used to track information about traffic to the website and how users use the website.
Processing of data relating to Criminal Conviction and Offences
carries out security measures relating to processing of personal data pertaining to criminal convictions and offences under the control of official authority or when the processing is authorised by the UAE Data Bureau7 providing for appropriate safeguards for the rights and freedoms of data subjects. Any comprehensive register of criminal convictions are kept under the control of official authority only.
Use of Personal Data
uses Personal Data of its customers for the following purposes:
- To provide and maintain the Service fairly and transparently in addition to monitoring the usage of the service.
- To manage the Account of the customers in terms of the registration and login as a user of the service provided by so that the personal data provided can give the customers access to different functionalities of the service that are available to them as a registered user.
7 Established under Federal Decree by Law No. (44) of 2021
- For the performance of a contract encompassing the development, compliance and undertaking of the contract for the services the customer has obtained or of any other contract with .
- To contact the customers by email, telephone calls, SMS, or other equivalent forms of electronic communication, such as a mobile application's push notifications regarding updates or informative communications related to the functionalities or contracted services, including the security updates, when necessary or reasonable for their implementation.
- To provide the customer with news, special offers and general information about other services and events which are offered by unless the customer has opted not to receive such information.
- To manage the requests of the customers to .
- may use the customer information for other purposes like data analysis, identifying usage trends, determining the effectiveness of the promotional campaigns and to evaluate and improve the Service, products, services and marketing.
- It is to be noted that the personal information of the customers for any relevant purpose whatsoever are always disclosed with the consent of the customers.
Retention of Personal Data
shall retain the Personal and Professional Data of the customers for as long as the account of the customers is active or as needed to provide services in accordance with FATF Recommendations. The personal and professional data obtained by for verification purposes before using and/or availing the services of are kept throughout the continuance of business relationship with the customer and are retained for a tenure of at least five years after the conclusion of business relationship. shall retain and use the Personal Data of the customers to the extent necessary to comply with the legal obligations, and for the purpose of enforcing the legal agreements and policies.
keeps a copy of the data and information as well as sufficient supporting records of the transactions provided by the customers of for fulfilment of its Customer Due Diligence (CDD) obligations for a period of five years following the completion of the transaction or the end of the business relationship. After the completion of the five-year tenure, the information and personal data of the customers is retained only either under an enactment or for the purposes of court proceedings, or the data of customers can also be retained by if the concerned customer consents to such retention of data.8
keeps staff training records at least for three years after the date of completion of such training.
The retention period may extend beyond the termination of business relationship with a customer only as long as it is necessary for to have sufficient information to respond to any issues that may arise later, including but not limited to the purpose of investigations or ongoing prosecutions or in case of Suspicious transactions or if requires the information for its records or to support legal proceedings, or if believes in good faith that a law, regulation, rule or guideline requires it, but such archiving period of retaining information is always maintained within the five-year tenure of retention of data. However, the Retention period of personal data of customers can last for a maximum period of ten years in circumstances when the relevant laws permit where the users of reside and operate, allows it in cases when the business relationship with such a customer has come to an end for any data relating to any transaction which occurs as a part of such business relationship before deletion or anonymity of such data. Nevertheless, there is no obligation to do so in all instances. shall not be liable or responsible for the non-availability of information beyond the termination of business relationship with their clients.
Disclosure of Personal Data
Law enforcement
Under certain exceptional circumstances, shall disclose the Personal Data of the customers if required to do so by relevant laws of the UAE or in response to valid requests by supervisory authority namely Financial Action Task Force (FATF).
Other legal requirements
shall disclose the personal data and information of the customers in good faith that such action is necessary to either abide by a legal obligation, or for protection against legal liability and defence of however deemed applicable by the Compliance team at .
For the purposes of disclosure of information, the disclosure shall be made by only if the disclosure was made with the consent of the customer himself or by the legal representative of the customer carrying on the business of the customer for the time being, or the information which was obtained by or provided
to the Controller or representative as appointed by the Controller in the course or purposes of discharge of the Controller’s functions, or for the purpose of making the data or information available to the public in relevant and respective manner or where the disclosure of information was made for the purposes of criminal or civil proceedings, or such disclosure was necessary in the public interest.9
Transfer of Personal Data
The information of the customers, including Personal Data, is processed at the operating offices of and in any other places where the customer and involved in the processing are located. Data Protection Regulation operating in the UAE is applicable to the states of UAE. Therefore, it implies that the relevant information may be transferred to and maintained on computers located outside of the state if approved by the Data Protection Bureau and the same shall be done after complying with , including for onward transfers of personal data from the third country located outside the aforementioned jurisdictional borders or an international organisation to another country or international organisation. The consent of the customers followed by submission of such information represents the agreement and consent to such transfer10. Transfer of data can even take place to a third country if the particular state or province has proper and coherent legislations addressing personal data protection of the customers including but not limited to significant provisions, measures, controls, stipulations and rules and the ability to
9 Article 20 of Federal Decree by Law No. (45) of 2021 Concerning the Protection of Personal Data
10 Article 14 of Federal Decree by Law No. (45) of 2021 Concerning the Protection of Personal Data
exercise the personal rights of the customers from where the users of reside and operate11. takes all reasonable steps necessary to guarantee that the data of the customers is treated securely and in accordance with this Policy and no transfer of Personal Data shall take place to an organisation or in the vicinity of any jurisdiction unless there are adequate controls in place including the security of the data and other personal information of the customers.
The transfer of personal data of customers shall be so applied that the level of protection of customers which is guaranteed by is not undermined.
Security of Personal Data
Taking into account the purposes of processing personal data as well as the risk of deviating likelihood and severity for the rights and freedoms of customers of , implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including pseudonymisation12 and encryption of personal data, the ability to ensure the ongoing confidentiality, integrity, and resilience of processing systems and services, the ability to restore the availability and access to personal data in an expeditious manner in the event of a physical or technical incident and incorporates a process for regularly testing, assessing and evaluating the effectiveness of technical and
11 Article 22 of the Federal Decree by Law No. (45) of 2021 Concerning the Protection of Personal Data
12 Pseudonymisation and other encryptions shall be performed at the discretion of , subject to the applicable and existing laws and regulations of the land.
organisational measures for ensuring the security of processing of personal data and information of the customers.13
The security of personal data of customers of is held in highest regard and all kinds of chamber-tight security protocols are implemented and always in place, but it has to be borne in mind that no method of transmission or transfer of information over the internet, or method of electronic storage is 100% secure and are susceptible to malicious cyber attacks. Although strives to use the prime means to protect the Personal Data of the customers, its absolute security is not guaranteed.
Legal Basis for Processing Personal Data under GDPR
processes personal data of customers under the following conditions:
- Consent: Where the customer has given his consent for processing personal data for one or more specific purposes.
- Performance of a contract: Processing of Personal Data is necessary for the performance of an agreement with the customer or for any pre-contractual obligations thereof.
- Legal obligations: Processing Personal Data is necessary for compliance with legal obligations to which is subject.
13 Article 20 of Federal Decree by Law No. (45) of 2021 Concerning the Protection of Personal Data
- Legitimate interests: When processing of personal data becomes necessary for the purposes of the legitimate interests pursued by .
In any of the aforementioned scenarios, undertakes to clarify the specific legal basis which applies to the processing of personal data and information, and in particular whether the provision of Personal Data is a statutory or contractual requirement.
Rights of the Customer14
Under the Data Protection Policy framed and implemented strictly by being a Centralised Crypto Trading Platform, the Customers have the right to find out what information stores about them, including the right to:
- be informed about how the relevant data of the customers is being used
- have incorrect data replaced and updated with the correct information
- have data erased
- stop or restrict the processing of data
- object to how your data is processed in certain circumstances.
14 Articles 13 to 18 of Federal Decree by Law No. (45) of 2021 Concerning the Protection of Personal Data
The data collection regulator of UAE where the users of PayBiroPro reside and operate has the authority to delegate with the responsibility for monitoring and enforcing their provisions relating to data protection. The various rights enforceable by the customer as per the Data Protection policy of are as follows:
Rights of access by the customer pertaining to the personal data concerning him or her whether being processed, and, where that is the case, access to the personal data and the relevant information.
Right to Information of personal data where is liable to provide information to the customer like the identity and the relevant contact details and information of , the legal foundation and purposes for which the personal data of the customer is processed by , the categories of personal data of the customer which is being processed, the categories of recipients of the personal data (if any) and any other information needed to secure that the personal data of customer is processed fairly and Right of Rectification by the customer who has the right to rectify the inaccurate personal data concerning him or her from the database of . The customer also has the right to complete the incomplete personal data, including providing a supplementary statement conditional to the purpose of processing the data of the customers.
Right to erasure by the customer to obtain the erasure of personal data concerning him or her where either the personal data of the customer is no longer necessary in relation to the purposes for which they were collected or otherwise processed, or the customer withdraws consent on to the processing of his or her personal data for one or more specific purposes. Data deletion involves the secure and irreversible removal of data from all relevant storage locations involving the procedure of identification of data to be deleted, Verifying the deletion request and obtaining necessary approvals and using appropriate methods to securely delete data. ensures documenting the deletion process of data for audit and compliance purposes. Customers may request complete deletion of their data by using the “Delete my data” button in the Settings of the interface. Upon using this feature, the customer’s data goes immediately to the deletion queue from where it is automatically and permanently deleted at the end of the retention period, wherever applicable.
Right of Restriction of data of the customer from being processed where the accuracy of personal data is contested by the customer which in turn will enable to verify the accuracy of the personal data, or where no longer needs the personal data for the purposes of the processing, but they are required by the customer for the establishment, exercise or defence of legal claims.
Right to request transfer of personal data where the customer is entitled to receive the personal data provided to the Controller for processing when it is necessary for the implementation of a contractual obligation with the consent of the Furthermore, the customers of also have the right to request transfer of personal data to another Controller with the consent of the customer whenever technically feasible.
Right to object on grounds relating to the particular situation of a customer, at any time to processing of personal data of the customer which is based either for public interest or for the purpose of any legitimate interest, including profiling. shall process such personal data after providing legitimate grounds for the processing which supersedes the interests, rights and freedoms of the customer pertaining to the situation or for the establishment, exercise or defence of legal claims.
Right to automated individual decision-making where the customer has the right to not be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or But, this right is not absolute for the customers of and is dependant on the decision if the decision is necessary for entering into a contract or its performance between the customer and or the decision is authorised by Union or Member State law to which is subject. These laws lay down suitable measures to safeguard rights and freedoms and legitimate interests of the customer or the decision based on the explicit consent of the customer.
Exercising GDPR Data Protection Rights
The customers of may exercise the rights of access, rectification, cancellation and opposition by contacting . It must be noted that may ask its customers to verify their identity before responding to such requests, but shall strive to respond and reciprocate to any of such requests of its customers instantaneously. The customer shall have the right to complain to the Data Protection Authority which in the case of collection and use of personal data is the Data Protection Officer.15
Children's Privacy
There are no specific provisions in the Law of the UAE regulating the processing of minors' data. But in relation to the processing of the personal data of a child at , the processing of data shall be lawful where the child is at least 16 years old in compliance to GDPR Guidelines16 extending to non-EU countries like the UAE. Where the child is below the age of 16 years, such processing shall be lawful only if that consent is given or authorised by the parent, or the legal guardian of the child.17
does not address anyone under the age of 16. Personally Identifiable Information from anyone under the age of 16 is collected if and to the extent that consent is given or authorised by the parent or the legal guardian of the child.
If a parent or legal guardian of a child is aware that his/her child has provided with Personal Data without consent and/or approval, such parent or guardian is requested to contact the customer service executive of at the first instance. If Personal Data from anyone under the age of 16 without verification of parental consent is collected, required steps are taken to remove that information from the servers of PayBitioPro.
15 Article 11 of Federal Decree by Law No. (45) of 2021 Concerning the Protection of Personal Data
16 General Data Protection Regulations (EU)
17 Article 8 of GDPR Regulations, EU
Changes to Policy
updates its privacy policy from time to time. Any changes whatsoever shall be notified to the customers of by posting the new Privacy Policy on this page.
The customers are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page on the Website.
Contact
For any query about this Policy, the contact information is given below:
- By visiting this page on the website: [.com]
- By sending an email: [compliance@.com]