All systems operational
00:00:00:00
ONEKYC // Legal
DOC_TYPE: PRIVACY_POLICY

Personal Data Processing Policy

Version: 1.0Revision: 2026-08-14Effective: 2026-08-14Language: EN

This Policy defines the purposes and principles of personal data processing at ONEKYC and the measures taken to protect the rights of data subjects.

00

General Provisions

Version dated August 14, 2026

01

Purpose, Operator, and Scope

1.1. This Personal Data Processing Policy (hereinafter referred to as the "Policy") defines the purposes, legal grounds, and principles governing the processing of personal data, as well as the procedures for its use, storage, transfer, and protection, and the rights of personal data subjects when using the OneKYC KYC platform (SaaS) and other information resources of Finext Technology Ltd.

1.2. This Policy applies to the processing of personal data carried out by Finext Technology Ltd both for its own purposes and in connection with providing clients with software, infrastructure, and services related to identification, verification, KYC/KYB, fraud prevention, and other related functions.

1.3. The requirements of this Policy apply to employees, contractors, and any other individuals who access personal data in connection with the performance of their duties or the provision of services to the Operator, and are also reflected in agreements with vendors, processors, and sub-processors.

1.4. Operator / Company:

Finext Technology Ltd

Registered Address: IH-00-01-02-OF-01, Level 2, Innovation One, Dubai International Financial Centre (DIFC), Dubai, United Arab Emirates

Registration No.: 14021

1.5. Depending on the specific operation, Finext Technology Ltd may act as a Controller if it independently determines the purposes and means of processing personal data, or as a Processor if it processes personal data in accordance with documented instructions from the client acting as the Controller.

1.6. For the purposes of the Policy, the terms "Personal Data," "Data Subject," "Controller," "Processor," "Sub-processor," "Special Categories of Personal Data," "Personal Data Breach," "Processing," "High-Risk Processing," and other defined terms shall have the meanings ascribed to them under the Data Protection Law, DIFC Law No. 5 of 2020, and the applicable Data Protection Regulations.

02

Compliance with Applicable Law

2.1. As Finext Technology Ltd is incorporated and operates in the Dubai International Financial Centre (DIFC), the primary data protection legislation applicable to the Company's processing of personal data in the DIFC is the Data Protection Law, DIFC Law No. 5 of 2020 (hereinafter referred to as the "DIFC DP Law"), and the Data Protection Regulations issued pursuant to the DIFC DP Law, as amended from time to time.

2.2. Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data (the UAE federal personal data protection law) is taken into account to the extent that it applies to a specific processing operation. In doing so, the federal framework does not supersede the specialized DIFC regime for companies and institutions located in free zones that have their own dedicated personal data protection legislation.

2.3. Depending on the nature of its activities and the specific transaction involved, the Company also complies with other applicable DIFC, Dubai, and UAE legislation, including requirements relating to employment relations, contractual obligations, corporate record-keeping, fraud prevention, AML/CFT, and the execution of lawful requests from competent authorities.

2.4. Where GDPR, UK GDPR, or other mandatory provisions of foreign law apply to a specific processing operation by virtue of extraterritorial effect or contractual obligations, the Company shall observe such requirements in addition to, and without reducing the level of protection established by, the DIFC DP Law.

03

Principles, Purposes, and Scope of Personal Data Processing

3.1. The Company processes personal data lawfully, fairly, and transparently, and solely for specified, explicit, and legitimate purposes. The Company adheres to the principles of purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, as well as the principle of accountability.

3.2. For each processing operation, the Company determines the applicable legal basis in accordance with the DIFC DP Law. Depending on the circumstances, such basis may include:

3.2.1. the Data Subject's consent;

3.2.2. the necessity of processing for the conclusion or performance of a contract with the Data Subject, or for taking steps at their request prior to entering into a contract;

3.2.3. the necessity of fulfilling a legal obligation imposed on the Company;

3.2.4. the necessity of protecting the vital interests of the Data Subject or another natural person;

3.2.5. the need to perform a task in the interests of DIFC or to exercise functions or powers provided for under applicable law, where such ground is applicable;

3.2.6. the legitimate interests of the Company or a third party, provided that such interests are not overridden by the rights and legitimate interests of the Data Subject, taking into account the nature of the data, the reasonable expectations of the Data Subject, and the risks associated with the processing.

3.3. The processing of Special Categories of personal data shall only take place where both an applicable legal basis for processing personal data and a separate condition permitting the processing of Special Categories of personal data exist simultaneously, in accordance with the DIFC DP Law.

3.4. The primary purposes of personal data processing are:

3.4.1. conclusion, performance, amendment, and termination of employment and civil law relationships; personnel recruitment and review of candidates for vacancies;

3.4.2. concluding, executing, managing, and terminating contractual relationships with clients, suppliers, contractors, and other counterparties;

3.4.3. identification and authentication of individuals, contracting parties, representatives, users, and other participants in the interaction;

3.4.4. providing access to OneKYC and other software products of the Company, rendering services, technical support, account administration, and ensuring the operability of the services;

3.4.5. conducting KYC/KYB checks and other identity or authority verification procedures on behalf of the client, including document verification, facial image matching, liveness detection, forgery indicator checks, and fraud prevention;

3.4.6. verification of information against legally accessible registries, sanctions lists, PEP sources, adverse media databases, and other sources, where such verification is required by the product, agreement, or applicable law;

3.4.7. ensuring information and physical security, preventing unauthorized access, fraud, misuse, and other unlawful activities;

3.4.8. processing inquiries, requests, claims, complaints, and communications, conducting business correspondence, and providing customer support;

3.4.9. analytics on software product usage, quality control, development and enhancement of functionality, provided that the principles of data minimization and purpose compatibility are observed;

3.4.10. compliance with statutory requirements, court orders, mandatory directives, and lawful requests from competent authorities;

3.4.11. protecting the rights and legitimate interests of the Company, its clients, and partners, including the establishment, exercise, or defense of legal claims.

3.5. The main categories of Data Subjects include:

3.5.1. visitors to the Company's websites, users of the Company's applications and information resources;

3.5.2. end users and other individuals whose data is submitted by clients to OneKYC for the purposes of KYC/KYB, identification, verification, or anti-fraud checks;

3.5.3. employees, former employees, job applicants, contractors, consultants, and other individuals who are in, or seeking to enter into, a relationship with the Company;

representatives, employees, beneficial owners, founders, directors, and other associated persons of clients and counterparties;

3.5.5. individuals who submit inquiries, requests, applications, complaints, or proposals to the Company;

3.5.6. other natural persons whose information has been lawfully obtained by the Company in connection with the stated purposes of processing.

3.6. Depending on the purposes, the Company may process the following categories of personal data:

3.6.1. identification details: first name, last name, other names, date and place of birth, age, gender, citizenship, nationality, and similar data;

3.6.2. contact details: postal address, residential address, phone number, email address, account identifiers and communication service identifiers;

3.6.3. identity document details and copies thereof, including document number, date of issue, expiry date, issuing authority, machine-readable zones, images, and other particulars;

data on job title, place of employment, authorities, participation in legal entities, education, qualifications, and professional experience;

3.6.5. information on contractual relationships, services, accounts, requests, inquiries, and actions within information systems;

3.6.6. payment and settlement details, where necessary for contractual, accounting, or other lawful purposes;

3.6.7. information from public and lawfully accessible sources, including corporate registries, sanctions lists, PEP sources, and other databases;

3.6.8. images, photographs, video recordings, voice data, and technical inspection results;

3.6.9. technical and network data: IP addresses, device and session identifiers, event logs, browser and operating system parameters, language, time zone, cookie data and data collected through similar technologies;

3.6.10. geolocation data, where such functionality is used and an appropriate legal basis exists;

3.6.11. health information, criminal convictions and offences, or any other Special Categories of Personal Data — only where necessary for a legitimate purpose and permitted under DIFC DP Law;

3.6.12. any other personal data voluntarily provided by the Data Subject or lawfully obtained from a client, counterparty, or other source within the scope of the stated purpose.

3.7. Biometric Data and KYC Checks.

3.7.1. When using OneKYC, the following data may be processed: selfies, photos and videos, facial images, liveness check results, face-to-document matching results, and other technical attributes used for identity verification and fraud prevention.

3.7.2. If a facial image, biometric template, or other biometric identifiers are processed for the purpose of uniquely identifying a natural person, such data shall be considered Special Categories of Personal Data and shall be processed with enhanced legal, organizational, and technical safeguards.

3.7.3. The Company does not use biometric data for purposes incompatible with the stated KYC/identification function, and does not perform open-set facial searches (1:N) against an unrestricted pool of individuals, unless such functionality is explicitly provided for by the product, agreement, applicable notice, and a proper legal basis.

3.8. Processing may be carried out using both automated and non-automated means. Operations include the collection, recording, structuring, storage, alteration, retrieval, use, alignment, disclosure, transfer, restriction, anonymization, erasure, and destruction of data.

3.9. The Company takes reasonable measures to ensure the accuracy and currency of personal data. If inaccuracies are identified, the data is clarified, corrected, or its processing is restricted, as necessary.

3.10. Personal data is retained no longer than necessary to fulfill the relevant purpose, meet contractual and legal obligations, comply with reporting and record-keeping requirements, resolve disputes, and defend legal claims. Retention periods are determined by internal data retention and deletion policies and, where data is processed on behalf of a client, by the applicable agreement and the client's instructions.

3.11. Upon expiration of the applicable retention period, data shall be deleted, destroyed, irreversibly anonymized, pseudonymized, securely encrypted, or otherwise removed from active use, unless further retention is required by law or for the purpose of protecting legal claims.

3.12. Cross-Border Transfer of Personal Data.

The transfer of personal data outside the DIFC is carried out in accordance with Articles 26 and 27 of the DIFC DP Law and the Data Protection Regulations.

3.12.2. If the recipient is located in a jurisdiction recognized by the Commissioner of Data Protection as providing an adequate level of protection, the transfer shall be carried out in accordance with the applicable requirements of such regime.

3.12.3. When transferring data to a jurisdiction that does not have a recognized adequate level of protection, the Company applies legally prescribed safeguards, including approved standard contractual clauses, other contractual mechanisms, risk assessments, and additional technical and organizational measures; or relies on a specific derogation expressly permitted under DIFC DP Law.

3.12.4. In contracts with processors and sub-processors that have access to data outside the DIFC, the Company includes requirements relating to confidentiality, security, purpose limitation, data return/deletion, incident notification, and the further engagement of sub-processors.

3.13. High-Risk Processing and DPIA.

3.13.1. Prior to commencing any operations that, taking into account their nature, scope, context, purposes, use of new technologies, biometrics, profiling, or other factors, may give rise to a high risk to the rights and freedoms of Data Subjects, the Company shall conduct a Data Protection Impact Assessment (DPIA) in the cases and manner prescribed by the DIFC DP Law.

3.13.2. If an identified high risk cannot be reasonably mitigated, the Company acts in accordance with the requirements of the DIFC DP Law regarding prior consultation and other risk management measures.

3.14. Automated processing and autonomous/semi-autonomous systems.

3.14.1. When using automated mechanisms, profiling, artificial intelligence systems, or other autonomous/semi-autonomous systems, the Company ensures transparency, purpose control, the ability for human intervention in cases provided for by law, and compliance with the applicable requirements of Regulation 10 Data Protection Regulations.

3.14.2. The data subject has the right to contest the outcome of processing and exercise other rights provided for under the DIFC DP Law if automated processing materially affects their rights or interests.

04

Processing on Behalf of Clients and Engagement of Processors/Sub-Processors

4.1. When providing OneKYC to clients, the Company generally processes the personal data of end users in accordance with the documented instructions of the relevant client, where that client independently determines the purposes and principal means of processing. In such a situation, the client acts as the Controller, and Finext Technology Ltd acts as the Processor.

4.2. With respect to its own employees, candidates, counterparty representatives, website visitors, contact persons, and other data subjects whose purposes and means of processing are determined by the Company itself, Finext Technology Ltd acts as the Controller.

4.3. The agreement between the Controller and the Processor must govern the subject matter and duration of the processing, the nature and purposes of the processing, the categories of data and Data Subjects, documented instructions, confidentiality, security, assistance in fulfilling Data Subjects' rights, incident response procedures, data deletion/return, audits, and any other requirements of the DIFC DP Law.

4.4. The Company may engage sub-processors only to the extent permitted by the applicable agreement and law. Sub-processors shall be subject to data protection obligations that are substantially equivalent to those owed by the Company to the relevant Controller.

4.5. If a sub-processor carries out processing outside the DIFC, the Company shall additionally ensure that an appropriate international transfer mechanism and contractual safeguards are in place.

4.6. The Client, acting as the Controller, is responsible for the lawfulness of data transfers to OneKYC, the existence of required notices and legal bases, compliance of the processing purposes and data with the minimization principle, and for properly responding to Data Subject requests within the scope of its competence.

06

Electronic User Data, Cookies, and Digital Communications

6.1. The Company's websites and web applications may automatically process technical data, including IP addresses, device and session identifiers, browser and operating system information, event logs, language, time zone, cookies, and similar technologies.

6.2. Cookies may be used to ensure the operation of the website and user accounts, maintain security, save preferences, support analytics, improve the service, and — where a separate appropriate legal basis exists — for marketing and other purposes.

6.3. Information about the cookies and similar technologies in use is provided in a clear, plain, and accessible manner. Default privacy settings are configured so as not to collect more personal data than is necessary for the relevant product or service.

6.4. Where the Company relies on consent for optional cookies, analytics, targeting, or digital communications, the user must have a genuine opportunity to make an affirmative choice; pre-ticked boxes, silence, closing a banner, or inaction do not, in and of themselves, constitute consent.

The user is provided with an accessible means to modify their settings, withdraw consent, or opt out of non-essential digital communications and the associated processing.

6.6. When using third-party analytics, communication, cloud, or other components, processing may also be governed by the terms and conditions of the respective providers. The Company selects such providers with data protection requirements in mind and, where necessary, enters into data processing agreements with them.

6.7. Users may also manage cookies through their browser settings. Restricting strictly necessary cookies may affect the availability of certain website or service features.

07

Confidentiality, Security, and Breach Response

7.1. The Company maintains the confidentiality of personal data and discloses it only to those individuals who require access for the stated purpose, the performance of a contract, compliance with applicable law, or any other legitimate purpose.

7.2. The Company implements appropriate technical and organizational measures proportionate to the risk involved, including, where applicable:

7.2.1. Access control segregation and the principle of least privilege;

7.2.2. multi-factor authentication, account management, and privileged access control;

7.2.3. encryption of data in transit and, where applicable, at rest;

7.2.4. Logging and monitoring of security events;

7.2.5. backup, recovery, and service resilience assurance;

7.2.6. secure development, vulnerability management, and updates;

7.2.7. physical protection of premises and equipment;

7.2.8. Contractual confidentiality and data protection obligations for employees, contractors, and suppliers;

7.2.9. staff training and regular review of internal procedures;

7.2.10. assessment of supplier and sub-processor risks;

7.2.11. Privacy by design and privacy by default in the development and modification of products and processes.

7.3. The Company maintains records of processing activities (RoPA), documentation on legal bases, consents, processor agreements, data storage locations, DPIAs, security breaches, and retention periods as required by DIFC DP Law and the Data Protection Regulations.

7.4. The Company shall notify the Commissioner of Data Protection of a notifiable Personal Data Breach without undue delay after becoming aware of the breach, in accordance with Article 41 of the DIFC DP Law and the Data Protection Regulations.

7.5. If a breach is likely to create a high risk to the security or rights of a Data Subject, the Company shall notify the affected Data Subject in the manner and within the timeframes required by DIFC DP Law, or act in accordance with the instructions of the Commissioner of Data Protection.

7.6. Where the Company acts as a Processor, it shall notify the relevant Controller of a Personal Data Breach without undue delay and within the timeframe established by the agreement, providing the information necessary for the Controller to fulfil its own obligations.

08

Rights of Data Subjects

8.1. In accordance with the DIFC DP Law, and subject to the conditions, limitations, and exceptions provided therein, a Data Subject has the right to:

8.1.1. to receive information regarding the processing of his/her personal data;

8.1.2. to request access to their personal data and a copy of the data being processed;

8.1.3. to request the correction of inaccurate or incomplete data;

8.1.4. to request the deletion of personal data in cases provided for by law;

8.1.5. to request the restriction of processing where applicable;

8.1.6. to receive the data provided by them in a structured, commonly used, and machine-readable format and, where applicable, to request their transfer to another Controller;

8.1.7. to object to the processing where such a right is provided for by law;

8.1.8. to withdraw consent, where processing is based on consent;

8.1.9. to exercise rights related to automated processing and decision-making, including the right to contest the relevant outcome in cases provided for by law;

8.1.10. not to be subjected to unlawful discrimination for the good-faith exercise of data protection rights;

8.1.11. to lodge a complaint with the Commissioner of Data Protection and to seek judicial remedy or compensation in cases provided for under the DIFC DP Law.

8.2. To exercise their rights, the Data Subject may submit a request to the email address info@onekyc.io or to the registered address of Finext Technology Ltd, as specified in Section 1 of the Policy.

8.3. The Company may request reasonably necessary information to verify the identity of the applicant and prevent unauthorized disclosure of data.

8.4. Where no applicable exemption applies, the Company will respond to a properly submitted request within the timeframe stipulated by the DIFC DP Law; for access, rectification, and erasure requests, this is generally one month from receipt of the request and sufficient verification of identity. Where permitted by law, this period may be extended, with notice provided to the applicant.

8.5. Where the Company processes data solely as a Processor on behalf of a client, a Data Subject request may be forwarded to the relevant client acting as Controller, and the Company shall provide reasonable assistance to that client in fulfilling the request.

09

Roles, Governance, and Accountability

9.1. The Company maintains a data protection compliance program that is proportionate to the nature, scope, context, and risks of its processing activities, and is able to demonstrate the measures implemented upon request by a competent authority.

9.2. The Company appoints a Data Protection Officer (DPO) where such appointment is required under DIFC DP Law, and in other cases designates a responsible contact person or department for data protection matters.

9.3. Employees and contractors with access to personal data are required to comply with the Policy, internal procedures, confidentiality requirements, and established access restrictions.

9.4. Vendors, Processors, and Sub-processors shall be liable, to the extent required by applicable law and the agreements in place, for processing data in breach of instructions, confidentiality requirements, security requirements, or any other obligations.

9.5. Violations of the Policy requirements may result in disciplinary, contractual, civil, administrative, or other liability in accordance with applicable DIFC and UAE legislation.

9.6. The DIFC Commissioner of Data Protection oversees and enforces the DIFC DP Law, holding the authority to conduct inspections, issue binding directives, handle complaints, and impose sanctions in accordance with the DIFC DP Law.

10

Publication and Updates to the Policy

10.1. The Policy is developed and maintained by Finext Technology Ltd and comes into effect upon approval by the Company.

10.2. The Policy is a publicly available document and may be published on the Internet at https://onekyc.io, as well as made available in any other form at the Company's discretion.

10.3. Web forms, interfaces, and other personal data collection tools used by the Company as a Controller must either contain or provide access to the necessary information regarding the relevant processing activities and this Policy.

10.4. The Company periodically reviews this Policy to reflect changes in legislation, products, technologies, and data processing practices. A new version takes effect on the date of its publication or such other date as may be expressly specified in the document.

10.5. Questions, requests, and comments regarding personal data processing may be sent to: info@onekyc.io.

[ End of document · REV 2026-08-14 ]