在真实商业与数字资本之间,构建桥梁
法律文件

Cookie Policy

此页面的中文版本正在由专业金融翻译审校中,暂以英文提供。The Chinese version of this page is being reviewed by a professional financial translator and is provided in English for now.
工作草案 v0.1-draft——供审阅;最终文本以法律审阅后为准。

ARCBDS COOKIE POLICY

Document No.: 7 of 14

Version: 1.0

Effective Date: [●]

Last Updated: [●]

1. INTRODUCTION

This Cookie Policy explains how ARCBDS uses cookies and similar technologies when you visit or interact with:

www.arcbds.com;

ARCBDS subdomains;

ARCBDS member portals;

Founding Circle participation interfaces;

ARCBDS dashboards;

web-based applications; and

other digital services expressly governed by this Cookie Policy,

collectively referred to as the “Website.”

This Cookie Policy should be read together with the:

ARCBDS Privacy Policy;

ARCBDS Website Terms of Use; and

other applicable ARCBDS legal documents.

2. WHO WE ARE

The Website is operated by:

Legal Entity:

[ARCB Investment LLC / confirmed ARCBDS operating entity]

Jurisdiction:

Dubai, United Arab Emirates

Commercial Licence / Registration No.:

[●]

Registered Address:

[●]

Official Website:

www.arcbds.com

Privacy Contact:

[●]

Cookie / Data Protection Contact:

[●]

The final published version must identify the actual entity responsible for operating the Website and processing information obtained through cookies and similar technologies.

3. PURPOSE OF THIS POLICY

This Policy explains:

a. what cookies are;

b. what similar technologies ARCBDS may use;

c. why those technologies are used;

d. which technologies are necessary for the Website;

e. which technologies may be optional;

f. when consent may be requested;

g. how users can change their preferences;

h. how third-party technologies are handled;

i. how long cookies may remain on a device; and

j. how cookie-related Personal Data is protected.

4. WHAT IS A COOKIE?

A cookie is a small file or piece of information that a website may place or access on a user's:

a. computer;

b. smartphone;

c. tablet; or

d. other internet-connected device.

Cookies can help websites:

function properly;

remember preferences;

maintain secure sessions;

recognise returning browsers;

understand Website usage;

detect security threats; and

provide permitted analytics or advertising functionality.

5. SIMILAR TECHNOLOGIES

This Policy also applies, where relevant, to technologies that perform similar functions to cookies, including:

a. local storage;

b. session storage;

c. pixels;

d. web beacons;

e. tracking tags;

f. SDKs;

g. scripts;

h. browser identifiers;

i. device identifiers;

j. conversion tags;

k. API-based tracking;

l. server-side tracking;

m. embedded technologies; and

n. other storage or access technologies.

References to “cookies” in this Policy may include these technologies unless the context requires otherwise.

6. PERSONAL DATA AND COOKIES

Some cookies may process information that constitutes Personal Data.

Depending on the technology, this may include:

a. IP address;

b. browser information;

c. device type;

d. operating system;

e. approximate geographic location;

f. session identifier;

g. Account status;

h. pages viewed;

i. time spent on pages;

j. referral source;

k. interactions;

l. language preferences;

m. security events;

n. consent preferences; and

o. other online identifiers.

Personal Data obtained through cookies is handled in accordance with the ARCBDS Privacy Policy and Applicable Law.

7. APPLICABLE LAW

ARCBDS uses cookies and similar technologies in accordance with applicable privacy and electronic communications requirements.

Depending on the user, Website activity and jurisdiction, this may include:

a. UAE Federal Decree-Law No. 45 of 2021 concerning the Protection of Personal Data;

b. applicable UAE regulations and decisions;

c. applicable Dubai regulatory requirements;

d. applicable VARA requirements where ARCBDS operates through a regulated Virtual Asset Service Provider;

e. applicable foreign privacy laws where those laws legally apply; and

f. applicable rules relating to cookies, device storage, electronic communications and online tracking.

Where different jurisdictions impose different requirements, ARCBDS may operate jurisdiction-specific consent controls.

8. OUR APPROACH TO COOKIE CONSENT

ARCBDS intends to distinguish between:

A. Cookies necessary to operate, secure or provide the Website; and

B. Optional cookies used for purposes such as analytics, personalisation or marketing.

Where Applicable Law requires consent before an optional cookie or similar technology is used, ARCBDS will seek appropriate consent before activating that technology.

9. STRICTLY NECESSARY COOKIES

Strictly Necessary Cookies are used where necessary to:

a. operate core Website functions;

b. establish secure user sessions;

c. authenticate users;

d. maintain login status;

e. prevent fraud;

f. protect Website infrastructure;

g. maintain load balancing;

h. manage transaction security;

i. remember legally required privacy preferences;

j. prevent cross-site request forgery;

k. maintain essential Account functionality; or

l. provide another function required for a service expressly requested by the user.

Where Applicable Law permits, these cookies may operate without optional consent because the Website or requested service cannot function properly without them.

Users should still be informed about their use.

10. SECURITY COOKIES

Security technologies may be used to:

a. detect suspicious login behaviour;

b. prevent Account takeover;

c. maintain authentication;

d. detect bots;

e. prevent malicious requests;

f. identify abnormal session activity;

g. support multi-factor authentication;

h. prevent fraud;

i. enforce geographic access restrictions; and

j. protect ARCBDS infrastructure.

Some security cookies may be classified as Strictly Necessary where they are essential to protect the service.

11. FUNCTIONAL COOKIES

Functional Cookies may help the Website remember choices such as:

a. language;

b. region;

c. preferred display settings;

d. interface preferences;

e. accessibility preferences;

f. dashboard preferences; and

g. other user-selected settings.

Depending on Applicable Law and the specific function, these cookies may require consent.

12. ANALYTICS COOKIES

Analytics Cookies may help ARCBDS understand:

a. how many users visit the Website;

b. which pages are viewed;

c. how users navigate the Website;

d. which Website functions are used;

e. where technical errors occur;

f. which devices or browsers are used;

g. general traffic sources;

h. Website performance; and

i. aggregated user behaviour.

Analytics information may be used to improve:

Website performance;

content;

navigation;

user experience;

accessibility; and

system design.

Where required by Applicable Law, Analytics Cookies will not be activated until the user consents.

13. PERFORMANCE COOKIES

Performance technologies may be used to measure:

a. page load times;

b. server response times;

c. application errors;

d. browser compatibility;

e. Website availability;

f. API performance; and

g. technical stability.

Depending on how such technologies operate, they may be classified as necessary or optional.

14. PERSONALISATION COOKIES

Where implemented, Personalisation Cookies may be used to tailor:

a. Website content;

b. language;

c. dashboard layouts;

d. educational content;

e. user journeys; or

f. other Website features

according to permitted information about user interactions or preferences.

Personalisation should not use confidential KYC information for unrelated behavioural advertising.

15. MARKETING AND ADVERTISING COOKIES

Where ARCBDS uses digital advertising, Marketing Cookies may be used for purposes including:

a. measuring advertising campaigns;

b. attribution;

c. measuring conversions;

d. limiting repeated advertising;

e. understanding campaign performance;

f. creating permitted advertising audiences; and

g. displaying relevant promotional material.

Where required by Applicable Law, these technologies will only operate after appropriate user consent.

16. SOCIAL MEDIA TECHNOLOGIES

ARCBDS may provide links or embedded features relating to platforms such as:

a. LinkedIn;

b. X;

c. YouTube;

d. Telegram; and

e. other social-media platforms.

Third-party social-media providers may use cookies or similar technologies when embedded content is loaded.

Where necessary, embedded third-party functionality may be blocked until applicable consent has been obtained.

17. VIDEO EMBEDS

The Website may embed video content from third-party platforms.

Loading an embedded video may allow the third party to receive information such as:

a. IP address;

b. browser information;

c. Website page viewed; and

d. interactions with the video.

Where required, optional video embeds may be subject to user consent before loading.

18. THIRD-PARTY ANALYTICS

ARCBDS may use approved third-party analytics services.

Before deployment, each analytics provider should be assessed for:

a. information collected;

b. cookie duration;

c. international data transfers;

d. security;

e. privacy terms;

f. sub-processors;

g. advertising functionality;

h. data retention; and

i. applicable consent requirements.

Actual providers must be listed in the final Cookie Register.

19. FIRST-PARTY COOKIES

A First-Party Cookie is generally set by the domain the user is visiting.

ARCBDS may use First-Party Cookies for:

a. authentication;

b. Website functionality;

c. security;

d. preferences;

e. analytics; and

f. consent management.

20. THIRD-PARTY COOKIES

A Third-Party Cookie may be set or accessed by a third-party service integrated into the Website.

Potential third parties may include providers of:

a. analytics;

b. video services;

c. support tools;

d. security services;

e. advertising;

f. KYC interfaces;

g. payment functionality; or

h. other embedded services.

Third-party cookies remain subject to applicable privacy controls.

21. SESSION COOKIES

Session Cookies are typically temporary.

They generally expire when:

a. the browser is closed;

b. the session ends; or

c. a short technical period expires.

Session Cookies may be used for:

a. login sessions;

b. navigation;

c. transaction workflows;

d. security; and

e. temporary Website state.

22. PERSISTENT COOKIES

Persistent Cookies remain on a device for a specified period or until deleted.

They may be used for:

a. consent preferences;

b. language settings;

c. remembered functionality;

d. analytics; or

e. other permitted purposes.

Cookie duration should not exceed the period reasonably necessary for the relevant purpose.

23. COOKIE DURATION

Each cookie should be assigned an appropriate duration.

Cookies may expire:

a. when the browser closes;

b. after minutes or hours;

c. after days;

d. after months; or

e. at another defined expiry point.

ARCBDS should periodically review persistent cookie durations and avoid retaining tracking identifiers longer than reasonably necessary.

24. COOKIE CONSENT PLATFORM

Where required or operationally appropriate, ARCBDS shall implement a Cookie Consent Management Platform or equivalent system.

The system should allow users to:

Accept All

Enable all permitted optional cookie categories.

Reject Non-Essential

Disable optional cookie categories while retaining necessary cookies.

Manage Preferences

Select individual optional categories.

25. NO PRE-TICKED OPTIONAL CONSENT

Where affirmative consent is required, optional cookie categories should not be treated as accepted merely because:

a. a box was pre-ticked;

b. a user continued browsing;

c. the user ignored the banner;

d. the user scrolled a page; or

e. the user created an Account.

Consent should involve an appropriate affirmative choice where required by law.

26. NO BUNDLED COOKIE CONSENT

Where consent is legally required, optional cookie consent should not be bundled unnecessarily with:

a. Website Terms of Use;

b. Privacy Policy acknowledgement;

c. Founding Circle Participation Agreement;

d. KYC consent;

e. Protection Reserve Terms; or

f. other unrelated contractual acceptance.

A Participant should not be required to accept optional marketing cookies merely to participate where those cookies are not necessary for the service.

27. REJECTING OPTIONAL COOKIES

Where applicable, users should be able to reject optional cookies without losing access to core Website services that do not depend on those cookies.

Rejecting optional cookies may affect:

a. personalised features;

b. embedded content;

c. analytics;

d. advertising functionality; or

e. certain non-essential conveniences.

It should not disable essential Account security merely because a user rejected advertising cookies.

28. CHANGING COOKIE PREFERENCES

Users may change their cookie choices at any time through:

Cookie Settings

or another clearly accessible preference tool.

The Website footer should contain a persistent link such as:

Cookie Settings

or:

Manage Cookies

29. WITHDRAWING CONSENT

Where Processing relies on consent, users may withdraw that consent.

Withdrawal should:

a. stop future use of affected optional technologies where technically possible;

b. not invalidate lawful Processing that occurred before withdrawal; and

c. be reasonably easy to perform.

Previously stored cookies may need to be deleted through:

a. the consent tool;

b. Website code;

c. browser controls; or

d. user device settings,

depending on the technology.

30. COOKIE PREFERENCE RECORDS

ARCBDS may record cookie-consent information such as:

a. anonymous or pseudonymous consent identifier;

b. consent categories;

c. consent date;

d. consent version;

e. consent timestamp;

f. policy version;

g. country or region where required;

h. withdrawal record; and

i. preference changes.

Such information may be retained to demonstrate compliance and respect future user choices.

31. COOKIE CONSENT EXPIRY

Cookie preferences may be requested again where:

a. the consent record expires;

b. material new cookie purposes are introduced;

c. new third parties are introduced;

d. law requires renewed consent;

e. consent settings can no longer be reliably identified; or

f. the user clears browser data.

The appropriate re-consent period shall be determined according to Applicable Law and operational requirements.

32. DIFFERENT DEVICES AND BROWSERS

Cookie preferences may be device- or browser-specific.

If you:

a. change browsers;

b. use another device;

c. clear browser storage;

d. use private browsing; or

e. reset browser settings,

you may need to set your preferences again.

33. LOGGED-IN USERS

Where technically and legally appropriate, ARCBDS may associate a consent preference with a logged-in Account to provide consistent privacy preferences across sessions or devices.

Where this occurs, the practice should be disclosed and implemented according to Applicable Law.

34. COOKIES AND ACCOUNT SECURITY

ARCBDS may use cookies to help maintain secure Account sessions.

Security cookies may:

a. confirm authentication;

b. maintain sessions;

c. protect forms;

d. detect session hijacking;

e. identify abnormal login activity; and

f. protect transaction workflows.

Blocking essential security cookies may prevent login or transaction functionality from working correctly.

35. KYC AND COOKIE TECHNOLOGIES

Third-party KYC or identity-verification interfaces may use technical cookies necessary to:

a. maintain verification sessions;

b. secure document uploads;

c. perform fraud prevention;

d. manage identity flows; or

e. protect verification services.

Where the KYC provider independently deploys cookies, applicable information about those technologies should be reflected in the Cookie Register or linked provider documentation.

36. PAYMENT AND BLOCKCHAIN WORKFLOWS

Technical storage may be used during blockchain or payment workflows to:

a. maintain transaction state;

b. remember selected network;

c. protect the transaction session;

d. prevent duplicate submission;

e. confirm transaction status; and

f. maintain security.

Necessary transaction technologies are not intended for unrelated behavioural advertising.

37. WALLET CONNECTIONS

If the Website provides wallet-connect functionality, technical identifiers or session information may be used to:

a. establish a connection;

b. remember connection status;

c. maintain network selection;

d. protect against unauthorised requests; and

e. process requested blockchain interactions.

A connected-wallet function must not store a user's private key or seed phrase in ordinary Website cookies.

38. PRIVATE KEYS AND SEED PHRASES

ARCBDS must not intentionally use cookies, pixels, analytics services or marketing technologies to store:

a. wallet private keys;

b. seed phrases;

c. recovery phrases; or

d. equivalent wallet-control credentials.

Users should never provide such information to ARCBDS.

39. KYC INFORMATION AND ADVERTISING

ARCBDS does not intend to use confidential KYC information such as:

a. passport details;

b. identity documents;

c. biometric verification;

d. source-of-funds documents;

e. source-of-wealth information; or

f. sanctions-screening results

for unrelated targeted advertising.

40. ANALYTICS AND PARTICIPANT DATA

Where Website analytics are used, ARCBDS should seek to avoid unnecessary linkage between behavioural analytics and highly sensitive Participant compliance information.

Analytics access should be limited according to legitimate business needs.

41. IP ADDRESSES

Cookie and Website systems may process IP addresses for:

a. cybersecurity;

b. fraud prevention;

c. approximate location;

d. jurisdiction controls;

e. analytics;

f. network troubleshooting; and

g. compliance.

Where an IP address constitutes Personal Data under Applicable Law, it will be handled accordingly.

42. GEOLOCATION

ARCBDS may use approximate geolocation technologies to:

a. determine jurisdiction;

b. implement geo-restrictions;

c. satisfy legal requirements;

d. prevent fraud;

e. enforce sanctions controls; or

f. localise content.

Precise continuous physical-location tracking is not intended unless a specific function requires it and is separately disclosed.

43. DEVICE FINGERPRINTING

Certain security providers may use device characteristics to detect:

a. fraud;

b. Account takeover;

c. automated abuse;

d. malicious devices; or

e. repeated attempts to circumvent restrictions.

Device fingerprinting should be limited to a legitimate purpose and subject to applicable privacy requirements.

It should not be used for unrelated advertising without appropriate legal justification and consent where required.

44. SERVER-SIDE TECHNOLOGIES

Not all tracking or analytics technologies operate through browser cookies.

ARCBDS may use server-side information such as:

a. access logs;

b. API logs;

c. request headers;

d. authentication logs;

e. security events; and

f. transaction logs.

Where such information constitutes Personal Data, it remains subject to the ARCBDS Privacy Policy even if it is not technically a cookie.

45. WEB LOGS

Website servers may automatically record information including:

a. IP address;

b. request time;

c. requested page;

d. browser information;

e. response codes;

f. errors; and

g. security indicators.

Logs may be necessary for:

security;

technical operations;

investigations; and

regulatory compliance.

46. EMAIL TRACKING

ARCBDS marketing emails may, where lawfully implemented, use technologies to determine whether:

a. an email was delivered;

b. an email was opened;

c. a link was clicked; or

d. a campaign generated Website traffic.

Where consent or another legal condition is required, ARCBDS shall comply with that requirement.

Users who opt out of optional marketing will not be required to receive promotional email solely because they remain an ARCBDS Participant.

47. CONTRACTUAL EMAILS

Emails necessary for:

a. Account security;

b. KYC;

c. transactions;

d. Founding Circle administration;

e. legal notices;

f. risk disclosures;

g. Protection Reserve Claims; or

h. regulatory communications

are different from optional marketing communications.

Users may not be able to opt out of essential contractual or legal communications while maintaining the relevant relationship.

48. THIRD-PARTY ADVERTISING

If ARCBDS uses third-party advertising platforms, the final Cookie Register should identify:

a. provider;

b. purpose;

c. data categories;

d. cookie names;

e. duration;

f. consent category;

g. provider privacy policy; and

h. international-transfer implications.

No advertising provider should be integrated into production without appropriate privacy and compliance review.

49. REMARKETING

Where legally permitted and consented to where required, ARCBDS may use remarketing technology to reach users who previously interacted with ARCBDS content.

Remarketing must not be used to create misleading financial promotions or evade applicable virtual-asset marketing restrictions.

50. ADVERTISING AUDIENCES

Where supported by Applicable Law, ARCBDS may use limited Website interaction data to create or measure permitted advertising audiences.

ARCBDS should not upload confidential KYC, AML or source-of-funds information to advertising platforms for audience targeting.

51. SOCIAL-MEDIA PIXELS

If social-media advertising pixels are deployed, they must be:

a. identified in the Cookie Register;

b. classified appropriately;

c. blocked before consent where required;

d. periodically reviewed; and

e. removed when no longer necessary.

52. COOKIE WALLS

ARCBDS should not unnecessarily condition general Website access or Founding Circle participation on acceptance of optional advertising or analytics cookies where such consent would not be freely given under Applicable Law.

Essential technologies necessary for secure participation may remain required.

53. CHILDREN

The Founding Circle and transactional ARCBDS services are not intended for minors.

ARCBDS does not intend to use advertising cookies to intentionally target minors for ARCBDS participation.

Where additional requirements apply to children's online data, ARCBDS shall comply with those requirements.

54. DO NOT TRACK SIGNALS

Some browsers provide a “Do Not Track” setting.

There is no single universally implemented technical standard governing every such signal.

Where ARCBDS is legally required to recognise a browser or device privacy signal, or elects to support such a signal, it will seek to honour it in accordance with Applicable Law and technical feasibility.

55. GLOBAL PRIVACY CONTROL

Where ARCBDS becomes subject to a jurisdiction requiring recognition of Global Privacy Control or another legally recognised opt-out signal, ARCBDS will configure applicable systems accordingly.

Such signals do not necessarily disable cookies that are strictly necessary for requested services or Website security.

56. BROWSER CONTROLS

Most browsers allow users to:

a. view cookies;

b. block cookies;

c. delete cookies;

d. block third-party cookies; or

e. configure site-specific cookie settings.

Blocking all cookies may cause some ARCBDS functionality to stop working.

57. MOBILE DEVICE CONTROLS

Mobile operating systems may provide controls relating to:

a. tracking;

b. advertising identifiers;

c. app permissions;

d. browser storage; and

e. privacy settings.

Users may manage such settings through their device.

58. THIRD-PARTY OPT-OUT TOOLS

Some third-party providers may provide their own:

a. preference controls;

b. privacy dashboards;

c. advertising opt-outs; or

d. cookie controls.

Using a third-party opt-out does not necessarily update the ARCBDS Cookie Preference Centre, and vice versa.

59. EFFECT OF DELETING COOKIES

If a user deletes cookies:

a. saved Website preferences may be lost;

b. the user may be logged out;

c. language choices may reset;

d. cookie consent settings may need to be selected again; and

e. some features may behave as though the user is visiting for the first time.

60. COOKIE SECURITY

Cookie security controls may include:

a. Secure attributes;

b. HttpOnly attributes;

c. SameSite controls;

d. limited cookie scope;

e. short session duration;

f. token rotation;

g. encryption or signing where appropriate; and

h. session revocation.

Security configurations should be reviewed periodically.

61. COOKIE IDENTIFIERS

ARCBDS should avoid placing unnecessary direct Personal Data such as:

a. full legal name;

b. passport number;

c. residential address;

d. full telephone number;

e. private wallet keys; or

f. KYC document content

directly inside ordinary cookie values.

Pseudonymous technical identifiers should be preferred where practicable.

62. COOKIE DATA RETENTION

Information generated through cookies should be retained only for as long as reasonably necessary for its purpose and in accordance with the ARCBDS Privacy Policy.

Retention periods should be documented in the Cookie Register.

63. ANALYTICS RETENTION

Analytics platforms should be configured with appropriate retention settings.

ARCBDS should not select an indefinite retention period merely because a provider technically permits it.

64. ACCESS TO COOKIE DATA

Access to cookie-derived Personal Data should be limited to authorised personnel and approved service providers requiring access for purposes such as:

a. Website operations;

b. security;

c. analytics;

d. marketing where permitted;

e. compliance; or

f. technical support.

65. SHARING COOKIE DATA

Cookie-derived information may be shared with approved service providers in accordance with the ARCBDS Privacy Policy.

Possible recipients may include:

a. cloud providers;

b. cybersecurity providers;

c. analytics providers;

d. consent-management providers;

e. customer-support providers;

f. marketing providers;

g. social-media platforms where permitted; and

h. regulators or authorities where legally required.

66. INTERNATIONAL TRANSFERS

Certain cookie providers may process information outside the UAE.

Where Personal Data is transferred internationally, ARCBDS will apply the transfer requirements described in the ARCBDS Privacy Policy and Applicable Law.

67. THIRD-PARTY RESPONSIBILITY

Third-party providers may independently determine aspects of their own data processing.

Users should review applicable third-party privacy and cookie information.

ARCBDS will seek to use reputable providers but cannot control every independent activity of a third party.

68. COOKIE AUDIT

ARCBDS should conduct periodic cookie and tracking-technology reviews.

A review should identify:

a. active cookies;

b. active scripts;

c. pixels;

d. local-storage items;

e. embedded content;

f. third-party integrations;

g. purposes;

h. data collected;

i. durations;

j. consent categories; and

k. whether each technology remains necessary.

69. UNAUTHORISED COOKIES

Website development teams must not deploy new optional tracking technology directly into production without appropriate:

a. technical review;

b. privacy review;

c. security review;

d. consent classification;

e. Cookie Register update; and

f. regulatory review where appropriate.

70. TAG MANAGEMENT

Where a tag-management platform is used, ARCBDS should configure it so that optional tags do not fire before consent where consent is required.

Tag-management access should be restricted.

71. CONSENT MODE

Where supported, ARCBDS may configure integrated tools so that advertising or analytics functions respect the user's consent status.

A consent-mode technology must not be assumed to satisfy Applicable Law merely because a vendor calls it “consent mode.”

ARCBDS remains responsible for its own compliance assessment.

72. COOKIE BANNER DESIGN

Where a consent banner is required, the banner should:

a. clearly state that cookies or similar technologies are used;

b. distinguish necessary from optional technologies;

c. provide meaningful choice;

d. link to this Policy;

e. provide access to Cookie Settings;

f. avoid misleading interface design; and

g. allow consent to be withdrawn.

73. DARK PATTERNS

Cookie interfaces should not be intentionally designed to manipulate users into accepting optional tracking.

ARCBDS should avoid practices such as:

a. hiding the rejection option;

b. making rejection unnecessarily difficult;

c. misleading button wording;

d. repeatedly requesting consent after a clear refusal without legitimate reason;

e. preselecting optional categories where affirmative consent is required; or

f. presenting optional tracking as technically mandatory when it is not.

74. COOKIE PREFERENCE CENTRE

The Cookie Preference Centre should normally provide separate controls for:

Strictly Necessary

Always Active where legally permitted and technically required.

Functional

On / Off where optional.

Analytics

On / Off.

Marketing

On / Off.

Social Media / Embedded Content

On / Off where separately appropriate.

75. DEFAULT SETTINGS

Where prior consent is legally required:

Strictly Necessary: Active

Functional: Off until consent, if optional

Analytics: Off until consent

Marketing: Off until consent

Social / Advertising Tracking: Off until consent

Jurisdiction-specific lawful exceptions may apply.

76. CONSENT RECORD

The consent-management system should retain sufficient information to demonstrate:

a. what the user was told;

b. which choices were offered;

c. what the user selected;

d. when the choice occurred;

e. which version of the cookie notice applied; and

f. whether consent was later withdrawn.

77. COOKIE POLICY UPDATES

This Cookie Policy may be amended where:

a. Website technology changes;

b. new providers are introduced;

c. cookies are removed;

d. purposes change;

e. Applicable Law changes;

f. regulatory guidance changes; or

g. privacy practices change.

78. MATERIAL COOKIE CHANGES

Where a material new optional purpose is introduced, existing consent may need to be obtained again where required by Applicable Law.

ARCBDS should not assume that prior consent for one purpose automatically covers a materially different purpose.

79. VERSION CONTROL

ARCBDS should maintain records of:

a. Cookie Policy version;

b. effective date;

c. publication date;

d. cookie-banner version;

e. Cookie Register version;

f. consent categories;

g. material changes; and

h. consent records.

80. CONTACT

Questions concerning this Cookie Policy may be sent to:

ARCBDS PRIVACY OFFICE

Legal Entity: [●]

Privacy Contact: [●]

Data Protection Officer: [●]

Email: [●]

Registered Address: [●]

Website: www.arcbds.com

81. PRIVACY RIGHTS

Information obtained through cookies may form part of Personal Data subject to rights described in the ARCBDS Privacy Policy.

Depending on Applicable Law, those rights may include:

a. access;

b. correction;

c. deletion;

d. restriction;

e. withdrawal of consent;

f. objection; or

g. other applicable rights.

Requests should be submitted through the privacy contact identified above.

SCHEDULE 1

COOKIE CATEGORIES

Category

Purpose

Default

Strictly Necessary

Security, sessions, authentication, requested services

Active where legally permitted

Security

Fraud prevention and platform protection

Active where necessary

Functional

Preferences and enhanced functionality

Optional where required

Analytics

Website measurement and improvement

Consent where required

Performance

Technical performance analysis

Depends on implementation

Personalisation

Tailored Website experience

Consent where required

Marketing

Advertising and campaign measurement

Consent where required

Social / Embedded Media

Third-party embedded content

Consent where required

SCHEDULE 2

ARCBDS COOKIE REGISTER

IMPORTANT: This register must be populated from the actual production Website before launch. Cookie names must not be invented.

Cookie / Technology

Provider

First / Third Party

Purpose

Category

Personal Data

Duration

Consent Required?

[●]

ARCBDS

First

Session authentication

Strictly Necessary

Session identifier

[●]

No, where exempt

[●]

ARCBDS

First

CSRF protection

Strictly Necessary

Security identifier

[●]

No, where exempt

[●]

ARCBDS

First

Cookie preference

Strictly Necessary

Consent status

[●]

No, where exempt

[●]

[●]

[●]

KYC session

Strictly Necessary / Security

[●]

[●]

[●]

[●]

[●]

[●]

Analytics

Analytics

Usage information

[●]

Yes where required

[●]

[●]

[●]

Performance

Performance

Technical data

[●]

[●]

[●]

[●]

[●]

Advertising attribution

Marketing

Online identifiers

[●]

Yes where required

[●]

[●]

[●]

Embedded video

Media

IP / interaction

[●]

[●]

[●]

[●]

[●]

Customer support

Functional

Session / support data

[●]

[●]

The production Cookie Register should identify every active cookie, pixel, tag or comparable technology.

SCHEDULE 3

WEBSITE COOKIE BANNER

RECOMMENDED PRIMARY BANNER

Your Privacy Choices

ARCBDS uses necessary cookies to operate and secure this Website. With your permission, we may also use optional analytics, functional and marketing technologies to understand Website usage and improve your experience.

You can accept optional cookies, reject non-essential cookies, or manage your preferences.

Buttons:

Accept All

Reject Non-Essential

Manage Preferences

Link: Cookie Policy

SCHEDULE 4

COOKIE PREFERENCE CENTRE

STRICTLY NECESSARY COOKIES

Always Active

These technologies are required for core Website functions such as Account authentication, security, transaction sessions, fraud prevention and remembering your privacy choices.

FUNCTIONAL COOKIES

Optional

These technologies help remember settings and provide enhanced Website functionality.

Toggle: ON / OFF

ANALYTICS COOKIES

Optional

These technologies help us understand how the Website is used so that we can measure performance and improve our services.

Toggle: ON / OFF

MARKETING COOKIES

Optional

These technologies may help measure permitted promotional campaigns and deliver or assess relevant advertising.

Toggle: ON / OFF

SOCIAL MEDIA / EMBEDDED CONTENT

Optional where applicable

These technologies enable content from approved external platforms. Those providers may receive information when their content is loaded.

Toggle: ON / OFF

Buttons:

Save Preferences

Accept All

Reject Non-Essential

SCHEDULE 5

COOKIE PREFERENCE FOOTER

Every appropriate Website page should contain persistent access to:

Privacy Policy

Cookie Policy

Cookie Settings

Terms of Use

Where applicable:

Do Not Sell or Share My Personal Information

or another jurisdiction-specific control should be displayed only where legally applicable.

SCHEDULE 6

COOKIE DEPLOYMENT CHECKLIST

Before deploying any cookie, pixel, SDK, tracking script or similar technology, ARCBDS should confirm:

☐ What technology is being deployed?

☐ Who provides it?

☐ Is it first-party or third-party?

☐ What is its purpose?

☐ What information does it collect?

☐ Is Personal Data involved?

☐ Does it process wallet or Participant information?

☐ Is it necessary for a service requested by the user?

☐ Is consent required?

☐ Is it blocked before consent where required?

☐ How long does it remain active?

☐ Where is the information processed?

☐ Does it involve an international transfer?

☐ Does the provider use information for its own purposes?

☐ Has the provider been privacy reviewed?

☐ Has the provider been security reviewed?

☐ Is a processing agreement required?

☐ Is it recorded in the Cookie Register?

☐ Is the Cookie Policy updated?

☐ Is the Cookie Preference Centre updated?

SCHEDULE 7

PROHIBITED COOKIE PRACTICES

ARCBDS personnel, developers and service providers must not intentionally use Website cookies or similar technologies to:

store wallet private keys;

store seed phrases;

store readable Account passwords;

expose complete identity documents;

expose source-of-funds documents;

transmit KYC records to advertising companies for unrelated marketing;

activate optional advertising trackers before required consent;

circumvent a user's cookie rejection;

reactivate rejected trackers without a lawful reason;

create hidden advertising profiles from compliance records;

misrepresent optional cookies as mandatory;

deploy unapproved trackers;

retain tracking information indefinitely without justification;

circumvent jurisdiction-specific privacy requirements; or

use dark patterns to force consent.

SCHEDULE 8

COOKIE AUDIT REGISTER

The ARCBDS privacy and technology teams should maintain an audit record containing:

Audit Date: [●]

Website Version: [●]

Auditor: [●]

Consent Platform: [●]

Number of Active Cookies: [●]

Number of First-Party Cookies: [●]

Number of Third-Party Cookies: [●]

Analytics Providers: [●]

Advertising Providers: [●]

Embedded Content Providers: [●]

Unclassified Cookies Identified: [●]

Unauthorised Cookies Identified: [●]

Actions Required: [●]

Completion Date: [●]

SCHEDULE 9

CONSENT RECORD REQUIREMENTS

Where consent is relied upon, records should include where reasonably appropriate:

Consent ID: [●]

Date / Time: [●]

Policy Version: [●]

Banner Version: [●]

Necessary Cookies: Active

Functional Cookies: Accepted / Rejected

Analytics Cookies: Accepted / Rejected

Marketing Cookies: Accepted / Rejected

Social / Media Cookies: Accepted / Rejected

Jurisdiction / Region: [●]

Consent Withdrawn: Yes / No

Withdrawal Date: [●]

Consent records should themselves be protected as Personal Data where they can be linked to an identifiable individual.

SCHEDULE 10

INTERNAL GOVERNANCE

Responsibility for cookie compliance should be shared appropriately between:

Privacy / DPO

legal classification;

privacy assessment;

user notices;

consent requirements;

Data Subject rights.

Compliance

regulatory requirements;

virtual-asset marketing implications;

jurisdiction controls.

Information Security

security cookies;

authentication;

session management;

vendor security.

Technology

deployment;

tag management;

consent enforcement;

Cookie Register accuracy.

Marketing

advertising pixels;

attribution tools;

campaign technology;

consent compliance.

No individual team should deploy optional tracking outside the approved process.

FINAL COOKIE NOTICE

ARCBDS uses technology necessary to operate and secure its Website.

Optional tracking should not be confused with technology required to:

protect your Account;

authenticate you;

perform KYC;

secure transactions; or

remember your privacy choices.

Where consent is required, you may decide whether ARCBDS uses optional analytics, marketing and similar technologies.

You may review or change your choices through Cookie Settings.

For more information about how ARCBDS processes Personal Data, please review the ARCBDS Privacy Policy.

END OF ARCBDS COOKIE POLICY

Cookie Policy — ARCB Digital Share