1. Executive Summary & Institutional Scope UAEP GOLD (“the Company”, “We”, “Us”) operates as a premier institutional-grade physical precious metals procurement, logistics, and depository infrastructure provider. Due to the high-value nature of sovereign wealth, family office, and corporate capital allocations, data security is treated with the same uncompromising rigor as the physical custody of bullion.

This Global Privacy Policy outlines our exhaustive protocols for the collection, encryption, processing, and restricted dissemination of corporate, financial, and personal data. This framework is strictly aligned with the UAE Personal Data Protection Law (PDPL), the Dubai International Financial Centre (DIFC) Data Protection Law No. 5 of 2020, and the European General Data Protection Regulation (GDPR). By interacting with our digital portals, executing block trades, or utilizing our vaulting networks, your institution consents to the practices codified herein.

2. Exhaustive Data Taxonomy: Information We Collect To execute secure, multi-tonne cross-border commodity transactions and satisfy international Anti-Money Laundering (AML) mandates, we are legally required to capture highly granular data. This is categorized as follows:

  • Corporate Entity Identity: Certificates of incorporation, memorandums of association, operating agreements, corporate registers, global tax identifiers (e.g., LEI codes), and trade licenses.

  • Ultimate Beneficial Owner (UBO) & Biometric Data: Passports, government-issued identification, proof of residency, biometric facility access logs, and visual identification records for all UBOs holding 25% or more equity, alongside authorized trading desk directors.

  • Financial Telemetry & Source of Wealth: SWIFT/BIC routing architectures, corporate banking references, audited financial statements, source of wealth (SOW) declarations, and comprehensive historical transaction ledgers.

  • Logistics & Geospatial Tracking Data: Authorized delivery coordinates, bonded warehouse receiving protocols, specific serial number assignments, and secure armored transport routing manifests.

  • Digital & Cryptographic Metadata: Encrypted login session keys, IP addresses, endpoint device profiles, network access timestamps, and encrypted communication logs designed to monitor and defend our internal portals.

3. Zero Trust Architecture (ZTA) & Cyber Defense Protocols Your operational privacy is defended by enterprise-grade cybersecurity. Our digital infrastructure is built entirely on a strict Zero Trust Architecture (ZTA). We operate under the principle of "never trust, always verify."

  • Granular Access Control: All internal data requests to client KYC repositories or transactional telemetry require multi-factor cryptographic authentication, continuous endpoint posture assessment, and dynamic network micro-segmentation.

  • Data Encryption: All data, both in transit and at rest, is secured utilizing military-grade AES-256 cryptographic encryption.

  • Air-Gapped Cold Storage: Highly sensitive corporate KYC profiles and UBO maps are aggressively isolated. They are stored in offline, air-gapped servers distributed across highly secure data centers in Switzerland and the UAE, rendering them immune to conventional network-based cyber-intrusions.

4. Permissioned Distributed Ledgers & Cryptographic Auditability To ensure absolute end-to-end verifiability of physical allocations without compromising operational privacy, UAEP GOLD integrates enterprise-grade permissioned blockchains. Vault telemetry, serial number registries, and chain-of-custody transfer logs are anchored using distributed ledger technology (such as Hyperledger Fabric). This provides sovereign-level cryptographic auditability for your institutional balance sheet, guaranteeing that while the asset's provenance and physical existence are immutably verified, the underlying corporate identity linked to the asset remains strictly private and off-chain.

5. Legal Basis and Purpose of Data Processing Under GDPR Article 6 and corresponding DIFC laws, we process your institutional data strictly under the following legal bases:

  • Contractual Necessity: To execute wholesale spot purchases, lock in global market pricing, and coordinate the physical armored transit of bullion to designated depositories.

  • Legal Obligation: To perform continuous, mandatory screening against global sanctions lists (OFAC, UN, EU), thereby preventing money laundering (AML), terrorist financing (CFT), and ensuring OECD conflict-free supply chain compliance.

  • Legitimate Operational Interest: To authenticate authorized corporate officers for highly secure physical vault access, issue notarized proof-of-reserve audits, and defend our infrastructure against digital fraud or forensic anomalies.

6. Zero-Trust Data Disclosure & Third-Party Sharing UAEP GOLD operates a strict non-commercialization policy. We absolutely do not sell, monetize, or distribute your corporate data. Information is shared strictly on a "need-to-know" operational basis with deeply vetted third parties bound by severe non-disclosure agreements (NDAs), including:

  • Tier-1 Logistics & Vault Operators: Entities such as Brinks, G4S, or Malca-Amit require exact delivery coordinates, asset serial manifests, and authorized personnel lists to execute secure, insured transfers.

  • Sovereign Customs & Regulatory Authorities: Cross-border asset movement requires mandatory tax, tariff, and compliance declarations to sovereign border authorities, central banks, and Financial Intelligence Units (FIUs).

  • Independent Institutional Auditors: Accredited third-party accounting firms executing verifiable proof-of-reserve audits on your behalf require temporary, restricted access to specific asset serial numbers and allocation registries to verify your corporate holdings.

7. Cross-Border Data Transfers Due to the global nature of our supply chain and vaulting network (spanning Dubai, London, Zurich, and Singapore), your corporate data may be transferred across international borders. UAEP GOLD guarantees that any cross-border data transfer is executed exclusively using Standard Contractual Clauses (SCCs) and robust cryptographic tunnels, ensuring that your data receives the exact same level of legal protection regardless of the server's physical geographic node.

8. Incident Response & Digital Forensics In the highly unlikely event of a data breach, UAEP GOLD maintains a rigorous incident response protocol. Our digital forensics team will immediately isolate and quarantine affected network segments. We are legally committed to notifying the relevant regional data protection authorities and your designated corporate compliance officers within seventy-two (72) hours of confirming a breach, providing a full forensic breakdown of the vector, the exposed data, and the immediate remediation actions deployed.

9. Statutory Data Retention Protocols As a regulated commodities infrastructure provider, UAEP GOLD is bound by severe international financial laws. We are legally mandated to retain all corporate KYC profiles, compliance audit trails, communication logs, and transactional ledgers for a minimum statutory period of seven (7) to ten (10) years following the formal closure of your account or the execution of your final transaction. Following the expiration of this mandatory retention window, all digital records are cryptographically shredded, and physical documents are securely destroyed via certified compliance protocols.

10. Institutional Privacy Rights and Subject Access Requests Subject to applicable global jurisdictions, your authorized corporate officers and compliance teams retain extensive, actionable rights over your data ecosystem:

  • Right of Access & Portability: You may request full, structured cryptographic data exports of your entire entity profile and transaction history at any time.

  • Right to Rectification: You may mandate the immediate correction of any inaccurate or outdated corporate registry records.

  • Right to Restrict Processing: You may temporarily halt the processing of specific data points during active legal disputes or internal audits.

  • Notice regarding the Right to Erasure (The "Right to be Forgotten"): Due to immutable global AML/CFT regulations, requests for the complete deletion of transactional or KYC data cannot be honored until the mandatory 7-to-10 year regulatory retention period has completely expired.

All compliance inquiries, data export requests, or restriction mandates must be formally submitted and securely routed via encrypted channels to your designated UAEP GOLD Chief Compliance Officer.