Cookie Policy
ARCBDS COOKIE POLICY
Document No.: 7 of 14
Version: 1.0
Effective Date: [●]
Last Updated: [●]
1. INTRODUCTION
This Cookie Policy explains how ARCBDS uses cookies and similar technologies when you visit or interact with:
www.arcbds.com;
ARCBDS subdomains;
ARCBDS member portals;
Founding Circle participation interfaces;
ARCBDS dashboards;
web-based applications; and
other digital services expressly governed by this Cookie Policy,
collectively referred to as the “Website.”
This Cookie Policy should be read together with the:
ARCBDS Privacy Policy;
ARCBDS Website Terms of Use; and
other applicable ARCBDS legal documents.
2. WHO WE ARE
The Website is operated by:
Legal Entity:
[ARCB Investment LLC / confirmed ARCBDS operating entity]
Jurisdiction:
Dubai, United Arab Emirates
Commercial Licence / Registration No.:
[●]
Registered Address:
[●]
Official Website:
www.arcbds.com
Privacy Contact:
[●]
Cookie / Data Protection Contact:
[●]
The final published version must identify the actual entity responsible for operating the Website and processing information obtained through cookies and similar technologies.
3. PURPOSE OF THIS POLICY
This Policy explains:
a. what cookies are;
b. what similar technologies ARCBDS may use;
c. why those technologies are used;
d. which technologies are necessary for the Website;
e. which technologies may be optional;
f. when consent may be requested;
g. how users can change their preferences;
h. how third-party technologies are handled;
i. how long cookies may remain on a device; and
j. how cookie-related Personal Data is protected.
4. WHAT IS A COOKIE?
A cookie is a small file or piece of information that a website may place or access on a user's:
a. computer;
b. smartphone;
c. tablet; or
d. other internet-connected device.
Cookies can help websites:
function properly;
remember preferences;
maintain secure sessions;
recognise returning browsers;
understand Website usage;
detect security threats; and
provide permitted analytics or advertising functionality.
5. SIMILAR TECHNOLOGIES
This Policy also applies, where relevant, to technologies that perform similar functions to cookies, including:
a. local storage;
b. session storage;
c. pixels;
d. web beacons;
e. tracking tags;
f. SDKs;
g. scripts;
h. browser identifiers;
i. device identifiers;
j. conversion tags;
k. API-based tracking;
l. server-side tracking;
m. embedded technologies; and
n. other storage or access technologies.
References to “cookies” in this Policy may include these technologies unless the context requires otherwise.
6. PERSONAL DATA AND COOKIES
Some cookies may process information that constitutes Personal Data.
Depending on the technology, this may include:
a. IP address;
b. browser information;
c. device type;
d. operating system;
e. approximate geographic location;
f. session identifier;
g. Account status;
h. pages viewed;
i. time spent on pages;
j. referral source;
k. interactions;
l. language preferences;
m. security events;
n. consent preferences; and
o. other online identifiers.
Personal Data obtained through cookies is handled in accordance with the ARCBDS Privacy Policy and Applicable Law.
7. APPLICABLE LAW
ARCBDS uses cookies and similar technologies in accordance with applicable privacy and electronic communications requirements.
Depending on the user, Website activity and jurisdiction, this may include:
a. UAE Federal Decree-Law No. 45 of 2021 concerning the Protection of Personal Data;
b. applicable UAE regulations and decisions;
c. applicable Dubai regulatory requirements;
d. applicable VARA requirements where ARCBDS operates through a regulated Virtual Asset Service Provider;
e. applicable foreign privacy laws where those laws legally apply; and
f. applicable rules relating to cookies, device storage, electronic communications and online tracking.
Where different jurisdictions impose different requirements, ARCBDS may operate jurisdiction-specific consent controls.
8. OUR APPROACH TO COOKIE CONSENT
ARCBDS intends to distinguish between:
A. Cookies necessary to operate, secure or provide the Website; and
B. Optional cookies used for purposes such as analytics, personalisation or marketing.
Where Applicable Law requires consent before an optional cookie or similar technology is used, ARCBDS will seek appropriate consent before activating that technology.
9. STRICTLY NECESSARY COOKIES
Strictly Necessary Cookies are used where necessary to:
a. operate core Website functions;
b. establish secure user sessions;
c. authenticate users;
d. maintain login status;
e. prevent fraud;
f. protect Website infrastructure;
g. maintain load balancing;
h. manage transaction security;
i. remember legally required privacy preferences;
j. prevent cross-site request forgery;
k. maintain essential Account functionality; or
l. provide another function required for a service expressly requested by the user.
Where Applicable Law permits, these cookies may operate without optional consent because the Website or requested service cannot function properly without them.
Users should still be informed about their use.
10. SECURITY COOKIES
Security technologies may be used to:
a. detect suspicious login behaviour;
b. prevent Account takeover;
c. maintain authentication;
d. detect bots;
e. prevent malicious requests;
f. identify abnormal session activity;
g. support multi-factor authentication;
h. prevent fraud;
i. enforce geographic access restrictions; and
j. protect ARCBDS infrastructure.
Some security cookies may be classified as Strictly Necessary where they are essential to protect the service.
11. FUNCTIONAL COOKIES
Functional Cookies may help the Website remember choices such as:
a. language;
b. region;
c. preferred display settings;
d. interface preferences;
e. accessibility preferences;
f. dashboard preferences; and
g. other user-selected settings.
Depending on Applicable Law and the specific function, these cookies may require consent.
12. ANALYTICS COOKIES
Analytics Cookies may help ARCBDS understand:
a. how many users visit the Website;
b. which pages are viewed;
c. how users navigate the Website;
d. which Website functions are used;
e. where technical errors occur;
f. which devices or browsers are used;
g. general traffic sources;
h. Website performance; and
i. aggregated user behaviour.
Analytics information may be used to improve:
Website performance;
content;
navigation;
user experience;
accessibility; and
system design.
Where required by Applicable Law, Analytics Cookies will not be activated until the user consents.
13. PERFORMANCE COOKIES
Performance technologies may be used to measure:
a. page load times;
b. server response times;
c. application errors;
d. browser compatibility;
e. Website availability;
f. API performance; and
g. technical stability.
Depending on how such technologies operate, they may be classified as necessary or optional.
14. PERSONALISATION COOKIES
Where implemented, Personalisation Cookies may be used to tailor:
a. Website content;
b. language;
c. dashboard layouts;
d. educational content;
e. user journeys; or
f. other Website features
according to permitted information about user interactions or preferences.
Personalisation should not use confidential KYC information for unrelated behavioural advertising.
15. MARKETING AND ADVERTISING COOKIES
Where ARCBDS uses digital advertising, Marketing Cookies may be used for purposes including:
a. measuring advertising campaigns;
b. attribution;
c. measuring conversions;
d. limiting repeated advertising;
e. understanding campaign performance;
f. creating permitted advertising audiences; and
g. displaying relevant promotional material.
Where required by Applicable Law, these technologies will only operate after appropriate user consent.
16. SOCIAL MEDIA TECHNOLOGIES
ARCBDS may provide links or embedded features relating to platforms such as:
a. LinkedIn;
b. X;
c. YouTube;
d. Telegram; and
e. other social-media platforms.
Third-party social-media providers may use cookies or similar technologies when embedded content is loaded.
Where necessary, embedded third-party functionality may be blocked until applicable consent has been obtained.
17. VIDEO EMBEDS
The Website may embed video content from third-party platforms.
Loading an embedded video may allow the third party to receive information such as:
a. IP address;
b. browser information;
c. Website page viewed; and
d. interactions with the video.
Where required, optional video embeds may be subject to user consent before loading.
18. THIRD-PARTY ANALYTICS
ARCBDS may use approved third-party analytics services.
Before deployment, each analytics provider should be assessed for:
a. information collected;
b. cookie duration;
c. international data transfers;
d. security;
e. privacy terms;
f. sub-processors;
g. advertising functionality;
h. data retention; and
i. applicable consent requirements.
Actual providers must be listed in the final Cookie Register.
19. FIRST-PARTY COOKIES
A First-Party Cookie is generally set by the domain the user is visiting.
ARCBDS may use First-Party Cookies for:
a. authentication;
b. Website functionality;
c. security;
d. preferences;
e. analytics; and
f. consent management.
20. THIRD-PARTY COOKIES
A Third-Party Cookie may be set or accessed by a third-party service integrated into the Website.
Potential third parties may include providers of:
a. analytics;
b. video services;
c. support tools;
d. security services;
e. advertising;
f. KYC interfaces;
g. payment functionality; or
h. other embedded services.
Third-party cookies remain subject to applicable privacy controls.
21. SESSION COOKIES
Session Cookies are typically temporary.
They generally expire when:
a. the browser is closed;
b. the session ends; or
c. a short technical period expires.
Session Cookies may be used for:
a. login sessions;
b. navigation;
c. transaction workflows;
d. security; and
e. temporary Website state.
22. PERSISTENT COOKIES
Persistent Cookies remain on a device for a specified period or until deleted.
They may be used for:
a. consent preferences;
b. language settings;
c. remembered functionality;
d. analytics; or
e. other permitted purposes.
Cookie duration should not exceed the period reasonably necessary for the relevant purpose.
23. COOKIE DURATION
Each cookie should be assigned an appropriate duration.
Cookies may expire:
a. when the browser closes;
b. after minutes or hours;
c. after days;
d. after months; or
e. at another defined expiry point.
ARCBDS should periodically review persistent cookie durations and avoid retaining tracking identifiers longer than reasonably necessary.
24. COOKIE CONSENT PLATFORM
Where required or operationally appropriate, ARCBDS shall implement a Cookie Consent Management Platform or equivalent system.
The system should allow users to:
Accept All
Enable all permitted optional cookie categories.
Reject Non-Essential
Disable optional cookie categories while retaining necessary cookies.
Manage Preferences
Select individual optional categories.
25. NO PRE-TICKED OPTIONAL CONSENT
Where affirmative consent is required, optional cookie categories should not be treated as accepted merely because:
a. a box was pre-ticked;
b. a user continued browsing;
c. the user ignored the banner;
d. the user scrolled a page; or
e. the user created an Account.
Consent should involve an appropriate affirmative choice where required by law.
26. NO BUNDLED COOKIE CONSENT
Where consent is legally required, optional cookie consent should not be bundled unnecessarily with:
a. Website Terms of Use;
b. Privacy Policy acknowledgement;
c. Founding Circle Participation Agreement;
d. KYC consent;
e. Protection Reserve Terms; or
f. other unrelated contractual acceptance.
A Participant should not be required to accept optional marketing cookies merely to participate where those cookies are not necessary for the service.
27. REJECTING OPTIONAL COOKIES
Where applicable, users should be able to reject optional cookies without losing access to core Website services that do not depend on those cookies.
Rejecting optional cookies may affect:
a. personalised features;
b. embedded content;
c. analytics;
d. advertising functionality; or
e. certain non-essential conveniences.
It should not disable essential Account security merely because a user rejected advertising cookies.
28. CHANGING COOKIE PREFERENCES
Users may change their cookie choices at any time through:
Cookie Settings
or another clearly accessible preference tool.
The Website footer should contain a persistent link such as:
Cookie Settings
or:
Manage Cookies
29. WITHDRAWING CONSENT
Where Processing relies on consent, users may withdraw that consent.
Withdrawal should:
a. stop future use of affected optional technologies where technically possible;
b. not invalidate lawful Processing that occurred before withdrawal; and
c. be reasonably easy to perform.
Previously stored cookies may need to be deleted through:
a. the consent tool;
b. Website code;
c. browser controls; or
d. user device settings,
depending on the technology.
30. COOKIE PREFERENCE RECORDS
ARCBDS may record cookie-consent information such as:
a. anonymous or pseudonymous consent identifier;
b. consent categories;
c. consent date;
d. consent version;
e. consent timestamp;
f. policy version;
g. country or region where required;
h. withdrawal record; and
i. preference changes.
Such information may be retained to demonstrate compliance and respect future user choices.
31. COOKIE CONSENT EXPIRY
Cookie preferences may be requested again where:
a. the consent record expires;
b. material new cookie purposes are introduced;
c. new third parties are introduced;
d. law requires renewed consent;
e. consent settings can no longer be reliably identified; or
f. the user clears browser data.
The appropriate re-consent period shall be determined according to Applicable Law and operational requirements.
32. DIFFERENT DEVICES AND BROWSERS
Cookie preferences may be device- or browser-specific.
If you:
a. change browsers;
b. use another device;
c. clear browser storage;
d. use private browsing; or
e. reset browser settings,
you may need to set your preferences again.
33. LOGGED-IN USERS
Where technically and legally appropriate, ARCBDS may associate a consent preference with a logged-in Account to provide consistent privacy preferences across sessions or devices.
Where this occurs, the practice should be disclosed and implemented according to Applicable Law.
34. COOKIES AND ACCOUNT SECURITY
ARCBDS may use cookies to help maintain secure Account sessions.
Security cookies may:
a. confirm authentication;
b. maintain sessions;
c. protect forms;
d. detect session hijacking;
e. identify abnormal login activity; and
f. protect transaction workflows.
Blocking essential security cookies may prevent login or transaction functionality from working correctly.
35. KYC AND COOKIE TECHNOLOGIES
Third-party KYC or identity-verification interfaces may use technical cookies necessary to:
a. maintain verification sessions;
b. secure document uploads;
c. perform fraud prevention;
d. manage identity flows; or
e. protect verification services.
Where the KYC provider independently deploys cookies, applicable information about those technologies should be reflected in the Cookie Register or linked provider documentation.
36. PAYMENT AND BLOCKCHAIN WORKFLOWS
Technical storage may be used during blockchain or payment workflows to:
a. maintain transaction state;
b. remember selected network;
c. protect the transaction session;
d. prevent duplicate submission;
e. confirm transaction status; and
f. maintain security.
Necessary transaction technologies are not intended for unrelated behavioural advertising.
37. WALLET CONNECTIONS
If the Website provides wallet-connect functionality, technical identifiers or session information may be used to:
a. establish a connection;
b. remember connection status;
c. maintain network selection;
d. protect against unauthorised requests; and
e. process requested blockchain interactions.
A connected-wallet function must not store a user's private key or seed phrase in ordinary Website cookies.
38. PRIVATE KEYS AND SEED PHRASES
ARCBDS must not intentionally use cookies, pixels, analytics services or marketing technologies to store:
a. wallet private keys;
b. seed phrases;
c. recovery phrases; or
d. equivalent wallet-control credentials.
Users should never provide such information to ARCBDS.
39. KYC INFORMATION AND ADVERTISING
ARCBDS does not intend to use confidential KYC information such as:
a. passport details;
b. identity documents;
c. biometric verification;
d. source-of-funds documents;
e. source-of-wealth information; or
f. sanctions-screening results
for unrelated targeted advertising.
40. ANALYTICS AND PARTICIPANT DATA
Where Website analytics are used, ARCBDS should seek to avoid unnecessary linkage between behavioural analytics and highly sensitive Participant compliance information.
Analytics access should be limited according to legitimate business needs.
41. IP ADDRESSES
Cookie and Website systems may process IP addresses for:
a. cybersecurity;
b. fraud prevention;
c. approximate location;
d. jurisdiction controls;
e. analytics;
f. network troubleshooting; and
g. compliance.
Where an IP address constitutes Personal Data under Applicable Law, it will be handled accordingly.
42. GEOLOCATION
ARCBDS may use approximate geolocation technologies to:
a. determine jurisdiction;
b. implement geo-restrictions;
c. satisfy legal requirements;
d. prevent fraud;
e. enforce sanctions controls; or
f. localise content.
Precise continuous physical-location tracking is not intended unless a specific function requires it and is separately disclosed.
43. DEVICE FINGERPRINTING
Certain security providers may use device characteristics to detect:
a. fraud;
b. Account takeover;
c. automated abuse;
d. malicious devices; or
e. repeated attempts to circumvent restrictions.
Device fingerprinting should be limited to a legitimate purpose and subject to applicable privacy requirements.
It should not be used for unrelated advertising without appropriate legal justification and consent where required.
44. SERVER-SIDE TECHNOLOGIES
Not all tracking or analytics technologies operate through browser cookies.
ARCBDS may use server-side information such as:
a. access logs;
b. API logs;
c. request headers;
d. authentication logs;
e. security events; and
f. transaction logs.
Where such information constitutes Personal Data, it remains subject to the ARCBDS Privacy Policy even if it is not technically a cookie.
45. WEB LOGS
Website servers may automatically record information including:
a. IP address;
b. request time;
c. requested page;
d. browser information;
e. response codes;
f. errors; and
g. security indicators.
Logs may be necessary for:
security;
technical operations;
investigations; and
regulatory compliance.
46. EMAIL TRACKING
ARCBDS marketing emails may, where lawfully implemented, use technologies to determine whether:
a. an email was delivered;
b. an email was opened;
c. a link was clicked; or
d. a campaign generated Website traffic.
Where consent or another legal condition is required, ARCBDS shall comply with that requirement.
Users who opt out of optional marketing will not be required to receive promotional email solely because they remain an ARCBDS Participant.
47. CONTRACTUAL EMAILS
Emails necessary for:
a. Account security;
b. KYC;
c. transactions;
d. Founding Circle administration;
e. legal notices;
f. risk disclosures;
g. Protection Reserve Claims; or
h. regulatory communications
are different from optional marketing communications.
Users may not be able to opt out of essential contractual or legal communications while maintaining the relevant relationship.
48. THIRD-PARTY ADVERTISING
If ARCBDS uses third-party advertising platforms, the final Cookie Register should identify:
a. provider;
b. purpose;
c. data categories;
d. cookie names;
e. duration;
f. consent category;
g. provider privacy policy; and
h. international-transfer implications.
No advertising provider should be integrated into production without appropriate privacy and compliance review.
49. REMARKETING
Where legally permitted and consented to where required, ARCBDS may use remarketing technology to reach users who previously interacted with ARCBDS content.
Remarketing must not be used to create misleading financial promotions or evade applicable virtual-asset marketing restrictions.
50. ADVERTISING AUDIENCES
Where supported by Applicable Law, ARCBDS may use limited Website interaction data to create or measure permitted advertising audiences.
ARCBDS should not upload confidential KYC, AML or source-of-funds information to advertising platforms for audience targeting.
51. SOCIAL-MEDIA PIXELS
If social-media advertising pixels are deployed, they must be:
a. identified in the Cookie Register;
b. classified appropriately;
c. blocked before consent where required;
d. periodically reviewed; and
e. removed when no longer necessary.
52. COOKIE WALLS
ARCBDS should not unnecessarily condition general Website access or Founding Circle participation on acceptance of optional advertising or analytics cookies where such consent would not be freely given under Applicable Law.
Essential technologies necessary for secure participation may remain required.
53. CHILDREN
The Founding Circle and transactional ARCBDS services are not intended for minors.
ARCBDS does not intend to use advertising cookies to intentionally target minors for ARCBDS participation.
Where additional requirements apply to children's online data, ARCBDS shall comply with those requirements.
54. DO NOT TRACK SIGNALS
Some browsers provide a “Do Not Track” setting.
There is no single universally implemented technical standard governing every such signal.
Where ARCBDS is legally required to recognise a browser or device privacy signal, or elects to support such a signal, it will seek to honour it in accordance with Applicable Law and technical feasibility.
55. GLOBAL PRIVACY CONTROL
Where ARCBDS becomes subject to a jurisdiction requiring recognition of Global Privacy Control or another legally recognised opt-out signal, ARCBDS will configure applicable systems accordingly.
Such signals do not necessarily disable cookies that are strictly necessary for requested services or Website security.
56. BROWSER CONTROLS
Most browsers allow users to:
a. view cookies;
b. block cookies;
c. delete cookies;
d. block third-party cookies; or
e. configure site-specific cookie settings.
Blocking all cookies may cause some ARCBDS functionality to stop working.
57. MOBILE DEVICE CONTROLS
Mobile operating systems may provide controls relating to:
a. tracking;
b. advertising identifiers;
c. app permissions;
d. browser storage; and
e. privacy settings.
Users may manage such settings through their device.
58. THIRD-PARTY OPT-OUT TOOLS
Some third-party providers may provide their own:
a. preference controls;
b. privacy dashboards;
c. advertising opt-outs; or
d. cookie controls.
Using a third-party opt-out does not necessarily update the ARCBDS Cookie Preference Centre, and vice versa.
59. EFFECT OF DELETING COOKIES
If a user deletes cookies:
a. saved Website preferences may be lost;
b. the user may be logged out;
c. language choices may reset;
d. cookie consent settings may need to be selected again; and
e. some features may behave as though the user is visiting for the first time.
60. COOKIE SECURITY
Cookie security controls may include:
a. Secure attributes;
b. HttpOnly attributes;
c. SameSite controls;
d. limited cookie scope;
e. short session duration;
f. token rotation;
g. encryption or signing where appropriate; and
h. session revocation.
Security configurations should be reviewed periodically.
61. COOKIE IDENTIFIERS
ARCBDS should avoid placing unnecessary direct Personal Data such as:
a. full legal name;
b. passport number;
c. residential address;
d. full telephone number;
e. private wallet keys; or
f. KYC document content
directly inside ordinary cookie values.
Pseudonymous technical identifiers should be preferred where practicable.
62. COOKIE DATA RETENTION
Information generated through cookies should be retained only for as long as reasonably necessary for its purpose and in accordance with the ARCBDS Privacy Policy.
Retention periods should be documented in the Cookie Register.
63. ANALYTICS RETENTION
Analytics platforms should be configured with appropriate retention settings.
ARCBDS should not select an indefinite retention period merely because a provider technically permits it.
64. ACCESS TO COOKIE DATA
Access to cookie-derived Personal Data should be limited to authorised personnel and approved service providers requiring access for purposes such as:
a. Website operations;
b. security;
c. analytics;
d. marketing where permitted;
e. compliance; or
f. technical support.
65. SHARING COOKIE DATA
Cookie-derived information may be shared with approved service providers in accordance with the ARCBDS Privacy Policy.
Possible recipients may include:
a. cloud providers;
b. cybersecurity providers;
c. analytics providers;
d. consent-management providers;
e. customer-support providers;
f. marketing providers;
g. social-media platforms where permitted; and
h. regulators or authorities where legally required.
66. INTERNATIONAL TRANSFERS
Certain cookie providers may process information outside the UAE.
Where Personal Data is transferred internationally, ARCBDS will apply the transfer requirements described in the ARCBDS Privacy Policy and Applicable Law.
67. THIRD-PARTY RESPONSIBILITY
Third-party providers may independently determine aspects of their own data processing.
Users should review applicable third-party privacy and cookie information.
ARCBDS will seek to use reputable providers but cannot control every independent activity of a third party.
68. COOKIE AUDIT
ARCBDS should conduct periodic cookie and tracking-technology reviews.
A review should identify:
a. active cookies;
b. active scripts;
c. pixels;
d. local-storage items;
e. embedded content;
f. third-party integrations;
g. purposes;
h. data collected;
i. durations;
j. consent categories; and
k. whether each technology remains necessary.
69. UNAUTHORISED COOKIES
Website development teams must not deploy new optional tracking technology directly into production without appropriate:
a. technical review;
b. privacy review;
c. security review;
d. consent classification;
e. Cookie Register update; and
f. regulatory review where appropriate.
70. TAG MANAGEMENT
Where a tag-management platform is used, ARCBDS should configure it so that optional tags do not fire before consent where consent is required.
Tag-management access should be restricted.
71. CONSENT MODE
Where supported, ARCBDS may configure integrated tools so that advertising or analytics functions respect the user's consent status.
A consent-mode technology must not be assumed to satisfy Applicable Law merely because a vendor calls it “consent mode.”
ARCBDS remains responsible for its own compliance assessment.
72. COOKIE BANNER DESIGN
Where a consent banner is required, the banner should:
a. clearly state that cookies or similar technologies are used;
b. distinguish necessary from optional technologies;
c. provide meaningful choice;
d. link to this Policy;
e. provide access to Cookie Settings;
f. avoid misleading interface design; and
g. allow consent to be withdrawn.
73. DARK PATTERNS
Cookie interfaces should not be intentionally designed to manipulate users into accepting optional tracking.
ARCBDS should avoid practices such as:
a. hiding the rejection option;
b. making rejection unnecessarily difficult;
c. misleading button wording;
d. repeatedly requesting consent after a clear refusal without legitimate reason;
e. preselecting optional categories where affirmative consent is required; or
f. presenting optional tracking as technically mandatory when it is not.
74. COOKIE PREFERENCE CENTRE
The Cookie Preference Centre should normally provide separate controls for:
Strictly Necessary
Always Active where legally permitted and technically required.
Functional
On / Off where optional.
Analytics
On / Off.
Marketing
On / Off.
Social Media / Embedded Content
On / Off where separately appropriate.
75. DEFAULT SETTINGS
Where prior consent is legally required:
Strictly Necessary: Active
Functional: Off until consent, if optional
Analytics: Off until consent
Marketing: Off until consent
Social / Advertising Tracking: Off until consent
Jurisdiction-specific lawful exceptions may apply.
76. CONSENT RECORD
The consent-management system should retain sufficient information to demonstrate:
a. what the user was told;
b. which choices were offered;
c. what the user selected;
d. when the choice occurred;
e. which version of the cookie notice applied; and
f. whether consent was later withdrawn.
77. COOKIE POLICY UPDATES
This Cookie Policy may be amended where:
a. Website technology changes;
b. new providers are introduced;
c. cookies are removed;
d. purposes change;
e. Applicable Law changes;
f. regulatory guidance changes; or
g. privacy practices change.
78. MATERIAL COOKIE CHANGES
Where a material new optional purpose is introduced, existing consent may need to be obtained again where required by Applicable Law.
ARCBDS should not assume that prior consent for one purpose automatically covers a materially different purpose.
79. VERSION CONTROL
ARCBDS should maintain records of:
a. Cookie Policy version;
b. effective date;
c. publication date;
d. cookie-banner version;
e. Cookie Register version;
f. consent categories;
g. material changes; and
h. consent records.
80. CONTACT
Questions concerning this Cookie Policy may be sent to:
ARCBDS PRIVACY OFFICE
Legal Entity: [●]
Privacy Contact: [●]
Data Protection Officer: [●]
Email: [●]
Registered Address: [●]
Website: www.arcbds.com
81. PRIVACY RIGHTS
Information obtained through cookies may form part of Personal Data subject to rights described in the ARCBDS Privacy Policy.
Depending on Applicable Law, those rights may include:
a. access;
b. correction;
c. deletion;
d. restriction;
e. withdrawal of consent;
f. objection; or
g. other applicable rights.
Requests should be submitted through the privacy contact identified above.
SCHEDULE 1
COOKIE CATEGORIES
Category
Purpose
Default
Strictly Necessary
Security, sessions, authentication, requested services
Active where legally permitted
Security
Fraud prevention and platform protection
Active where necessary
Functional
Preferences and enhanced functionality
Optional where required
Analytics
Website measurement and improvement
Consent where required
Performance
Technical performance analysis
Depends on implementation
Personalisation
Tailored Website experience
Consent where required
Marketing
Advertising and campaign measurement
Consent where required
Social / Embedded Media
Third-party embedded content
Consent where required
SCHEDULE 2
ARCBDS COOKIE REGISTER
IMPORTANT: This register must be populated from the actual production Website before launch. Cookie names must not be invented.
Cookie / Technology
Provider
First / Third Party
Purpose
Category
Personal Data
Duration
Consent Required?
[●]
ARCBDS
First
Session authentication
Strictly Necessary
Session identifier
[●]
No, where exempt
[●]
ARCBDS
First
CSRF protection
Strictly Necessary
Security identifier
[●]
No, where exempt
[●]
ARCBDS
First
Cookie preference
Strictly Necessary
Consent status
[●]
No, where exempt
[●]
[●]
[●]
KYC session
Strictly Necessary / Security
[●]
[●]
[●]
[●]
[●]
[●]
Analytics
Analytics
Usage information
[●]
Yes where required
[●]
[●]
[●]
Performance
Performance
Technical data
[●]
[●]
[●]
[●]
[●]
Advertising attribution
Marketing
Online identifiers
[●]
Yes where required
[●]
[●]
[●]
Embedded video
Media
IP / interaction
[●]
[●]
[●]
[●]
[●]
Customer support
Functional
Session / support data
[●]
[●]
The production Cookie Register should identify every active cookie, pixel, tag or comparable technology.
SCHEDULE 3
WEBSITE COOKIE BANNER
RECOMMENDED PRIMARY BANNER
Your Privacy Choices
ARCBDS uses necessary cookies to operate and secure this Website. With your permission, we may also use optional analytics, functional and marketing technologies to understand Website usage and improve your experience.
You can accept optional cookies, reject non-essential cookies, or manage your preferences.
Buttons:
Accept All
Reject Non-Essential
Manage Preferences
Link: Cookie Policy
SCHEDULE 4
COOKIE PREFERENCE CENTRE
STRICTLY NECESSARY COOKIES
Always Active
These technologies are required for core Website functions such as Account authentication, security, transaction sessions, fraud prevention and remembering your privacy choices.
FUNCTIONAL COOKIES
Optional
These technologies help remember settings and provide enhanced Website functionality.
Toggle: ON / OFF
ANALYTICS COOKIES
Optional
These technologies help us understand how the Website is used so that we can measure performance and improve our services.
Toggle: ON / OFF
MARKETING COOKIES
Optional
These technologies may help measure permitted promotional campaigns and deliver or assess relevant advertising.
Toggle: ON / OFF
SOCIAL MEDIA / EMBEDDED CONTENT
Optional where applicable
These technologies enable content from approved external platforms. Those providers may receive information when their content is loaded.
Toggle: ON / OFF
Buttons:
Save Preferences
Accept All
Reject Non-Essential
SCHEDULE 5
COOKIE PREFERENCE FOOTER
Every appropriate Website page should contain persistent access to:
Privacy Policy
Cookie Policy
Cookie Settings
Terms of Use
Where applicable:
Do Not Sell or Share My Personal Information
or another jurisdiction-specific control should be displayed only where legally applicable.
SCHEDULE 6
COOKIE DEPLOYMENT CHECKLIST
Before deploying any cookie, pixel, SDK, tracking script or similar technology, ARCBDS should confirm:
☐ What technology is being deployed?
☐ Who provides it?
☐ Is it first-party or third-party?
☐ What is its purpose?
☐ What information does it collect?
☐ Is Personal Data involved?
☐ Does it process wallet or Participant information?
☐ Is it necessary for a service requested by the user?
☐ Is consent required?
☐ Is it blocked before consent where required?
☐ How long does it remain active?
☐ Where is the information processed?
☐ Does it involve an international transfer?
☐ Does the provider use information for its own purposes?
☐ Has the provider been privacy reviewed?
☐ Has the provider been security reviewed?
☐ Is a processing agreement required?
☐ Is it recorded in the Cookie Register?
☐ Is the Cookie Policy updated?
☐ Is the Cookie Preference Centre updated?
SCHEDULE 7
PROHIBITED COOKIE PRACTICES
ARCBDS personnel, developers and service providers must not intentionally use Website cookies or similar technologies to:
store wallet private keys;
store seed phrases;
store readable Account passwords;
expose complete identity documents;
expose source-of-funds documents;
transmit KYC records to advertising companies for unrelated marketing;
activate optional advertising trackers before required consent;
circumvent a user's cookie rejection;
reactivate rejected trackers without a lawful reason;
create hidden advertising profiles from compliance records;
misrepresent optional cookies as mandatory;
deploy unapproved trackers;
retain tracking information indefinitely without justification;
circumvent jurisdiction-specific privacy requirements; or
use dark patterns to force consent.
SCHEDULE 8
COOKIE AUDIT REGISTER
The ARCBDS privacy and technology teams should maintain an audit record containing:
Audit Date: [●]
Website Version: [●]
Auditor: [●]
Consent Platform: [●]
Number of Active Cookies: [●]
Number of First-Party Cookies: [●]
Number of Third-Party Cookies: [●]
Analytics Providers: [●]
Advertising Providers: [●]
Embedded Content Providers: [●]
Unclassified Cookies Identified: [●]
Unauthorised Cookies Identified: [●]
Actions Required: [●]
Completion Date: [●]
SCHEDULE 9
CONSENT RECORD REQUIREMENTS
Where consent is relied upon, records should include where reasonably appropriate:
Consent ID: [●]
Date / Time: [●]
Policy Version: [●]
Banner Version: [●]
Necessary Cookies: Active
Functional Cookies: Accepted / Rejected
Analytics Cookies: Accepted / Rejected
Marketing Cookies: Accepted / Rejected
Social / Media Cookies: Accepted / Rejected
Jurisdiction / Region: [●]
Consent Withdrawn: Yes / No
Withdrawal Date: [●]
Consent records should themselves be protected as Personal Data where they can be linked to an identifiable individual.
SCHEDULE 10
INTERNAL GOVERNANCE
Responsibility for cookie compliance should be shared appropriately between:
Privacy / DPO
legal classification;
privacy assessment;
user notices;
consent requirements;
Data Subject rights.
Compliance
regulatory requirements;
virtual-asset marketing implications;
jurisdiction controls.
Information Security
security cookies;
authentication;
session management;
vendor security.
Technology
deployment;
tag management;
consent enforcement;
Cookie Register accuracy.
Marketing
advertising pixels;
attribution tools;
campaign technology;
consent compliance.
No individual team should deploy optional tracking outside the approved process.
FINAL COOKIE NOTICE
ARCBDS uses technology necessary to operate and secure its Website.
Optional tracking should not be confused with technology required to:
protect your Account;
authenticate you;
perform KYC;
secure transactions; or
remember your privacy choices.
Where consent is required, you may decide whether ARCBDS uses optional analytics, marketing and similar technologies.
You may review or change your choices through Cookie Settings.
For more information about how ARCBDS processes Personal Data, please review the ARCBDS Privacy Policy.
END OF ARCBDS COOKIE POLICY