在真实商业与数字资本之间,构建桥梁
法律文件

Privacy Policy

此页面的中文版本正在由专业金融翻译审校中,暂以英文提供。The Chinese version of this page is being reviewed by a professional financial translator and is provided in English for now.
工作草案 v0.1-draft——供审阅;最终文本以法律审阅后为准。

ARCBDS PRIVACY POLICY

Document No.: 6 of 14

Version: 1.0

Effective Date: [●]

Last Updated: [●]

1. INTRODUCTION

ARCBDS respects the privacy of individuals who visit our websites, create accounts, communicate with us, participate in the ARCBDS ecosystem, apply to the ARCBDS Founding Circle, complete identity verification, conduct transactions or otherwise interact with our services.

This Privacy Policy explains:

what Personal Data we collect;

how we collect it;

why we use it;

how we share it;

how long we retain it;

how we protect it;

how international transfers are handled;

how blockchain information is treated;

what rights individuals may have; and

how to contact us regarding privacy matters.

We are committed to processing Personal Data lawfully, fairly, transparently and securely.

2. WHO WE ARE

For purposes of this Privacy Policy, the entity responsible for determining how and why Personal Data is processed is:

Data Controller:

[ARCB Investment LLC / confirmed ARCBDS operating entity]

Jurisdiction:

Dubai, United Arab Emirates

Commercial Registration / Licence Number:

[●]

Registered Address:

[●]

Official Website:

www.arcbds.com

Privacy Contact:

[privacy@arcbds.com / ●]

Data Protection Officer:

[Name / title / ●]

DPO Contact:

[●]

The final execution version of this Privacy Policy must identify the actual entity or entities acting as Data Controller.

Where another ARCBDS group entity acts independently as a Controller, that entity may provide an additional privacy notice.

3. SCOPE OF THIS POLICY

This Privacy Policy applies to Personal Data processed through or in connection with:

a. www.arcbds.com;

b. ARCBDS subdomains;

c. ARCBDS member portals;

d. ARCBDS web or mobile applications;

e. Founding Circle applications;

f. account registration;

g. KYC and KYB procedures;

h. AML and sanctions screening;

i. source-of-funds and source-of-wealth checks;

j. blockchain and wallet verification;

k. Contributions and token allocations;

l. ARCBDS release and distribution;

m. Participant Protection Reserve Claims;

n. referrals and rewards;

o. customer support;

p. events;

q. business and partnership enquiries;

r. marketing communications;

s. surveys and feedback;

t. official ARCBDS social-media interactions;

u. regulatory and compliance processes; and

v. other interactions expressly covered by this Privacy Policy.

4. APPLICABLE DATA PROTECTION LAW

We process Personal Data in accordance with Applicable Law.

Depending on the activity and jurisdiction, this may include:

a. UAE Federal Decree-Law No. 45 of 2021 concerning the Protection of Personal Data;

b. regulations, decisions and guidance issued under that legislation;

c. applicable Dubai data-protection requirements;

d. applicable virtual-asset regulatory requirements;

e. sector-specific laws;

f. anti-money laundering and sanctions requirements; and

g. data-protection laws in other jurisdictions where those laws legally apply to our activities.

Where ARCBDS operates through a regulated Virtual Asset Service Provider, applicable VARA data-protection and confidentiality requirements shall also apply.

5. DEFINITIONS

For purposes of this Privacy Policy:

5.1 “Applicable Law”

means any applicable law, regulation, regulatory requirement, judicial order or legally binding rule relating to Personal Data, privacy, cybersecurity, AML, sanctions, virtual assets or related activities.

5.2 “Controller”

means the person or entity that determines the means and purposes of processing Personal Data.

5.3 “Data Subject”

means an identified or identifiable natural person to whom Personal Data relates.

5.4 “Personal Data”

means information relating to an identified or identifiable natural person, as defined under Applicable Law.

5.5 “Processing”

includes collecting, recording, organising, storing, adapting, retrieving, using, sharing, transferring, restricting, deleting or otherwise handling Personal Data.

5.6 “Processor”

means a person or entity processing Personal Data on behalf of a Controller.

5.7 “Sensitive Personal Data”

means Personal Data receiving enhanced legal protection under Applicable Law.

5.8 “Services”

means the websites, platforms, applications, Founding Circle programme and other ARCBDS services covered by this Privacy Policy.

6. DATA PROTECTION PRINCIPLES

Where required by Applicable Law, we seek to ensure that Personal Data is:

a. processed fairly, lawfully and transparently;

b. collected for clear and legitimate purposes;

c. limited to information reasonably required for those purposes;

d. accurate and updated where necessary;

e. retained only for an appropriate period;

f. appropriately secured;

g. processed in a manner respecting Data Subject rights; and

h. transferred internationally only through legally permitted mechanisms.

7. PERSONAL DATA WE MAY COLLECT

The Personal Data we collect depends on how you interact with ARCBDS.

It may include the following categories.

8. BASIC IDENTIFICATION INFORMATION

We may collect:

a. full legal name;

b. preferred name;

c. date of birth;

d. place of birth;

e. age;

f. gender where required or voluntarily provided;

g. nationality;

h. citizenship;

i. country of residence;

j. identification number; and

k. other identification information required by law.

9. CONTACT INFORMATION

We may collect:

a. residential address;

b. registered business address;

c. correspondence address;

d. email address;

e. telephone number;

f. mobile number;

g. country code;

h. communication preferences; and

i. other contact details.

10. IDENTITY DOCUMENTS

For verification purposes, we may collect copies or details of:

a. passport;

b. national identity card;

c. residence permit;

d. driving licence where accepted;

e. visa information;

f. company identification documents; and

g. other legally acceptable identity documents.

Identity-document data may include:

document number;

photograph;

nationality;

birth date;

issue date;

expiry date;

issuing authority; and

machine-readable information.

11. IDENTITY AND BIOMETRIC VERIFICATION

Where legally permitted and necessary for identity verification, KYC or fraud prevention, we or our authorised KYC providers may process:

a. selfie images;

b. facial images;

c. live video;

d. liveness-check results;

e. facial-comparison results; and

f. other verification information.

Where such information constitutes biometric or Sensitive Personal Data, we will process it according to applicable legal requirements.

We will not use biometric information for unrelated advertising purposes.

12. ACCOUNT INFORMATION

We may collect:

a. Account ID;

b. username;

c. registration date;

d. password hashes;

e. authentication status;

f. MFA configuration;

g. login history;

h. security events;

i. Account status;

j. referral code;

k. invitation code;

l. membership status; and

m. Account preferences.

We do not store passwords in readable plain-text form where appropriate security architecture is implemented.

13. CORPORATE AND KYB INFORMATION

Where a Participant is a company or other legal entity, we may collect:

a. company name;

b. incorporation number;

c. incorporation date;

d. registered jurisdiction;

e. registered address;

f. operating address;

g. constitutional documents;

h. shareholder information;

i. director information;

j. authorised-signatory information;

k. beneficial-owner information;

l. ownership percentages;

m. board resolutions;

n. business activity;

o. business licences;

p. tax information; and

q. other KYB information.

14. ULTIMATE BENEFICIAL OWNER INFORMATION

Where legally required, we may collect information concerning ultimate beneficial owners, including:

a. identity;

b. ownership interest;

c. control rights;

d. nationality;

e. address;

f. identification documents;

g. source of wealth; and

h. screening results.

15. FINANCIAL INFORMATION

Depending on the Services used, we may process:

a. Contribution amounts;

b. payment records;

c. refund records;

d. payment source information;

e. banking details where applicable;

f. stablecoin transaction details;

g. transaction references;

h. settlement details;

i. Protection Reserve settlement information; and

j. other financial transaction information.

We generally do not require users to disclose private banking passwords or digital-wallet private keys.

16. DIGITAL WALLET INFORMATION

We may collect:

a. public wallet address;

b. wallet network;

c. wallet type;

d. proof of wallet control;

e. wallet labels;

f. wallet transaction history;

g. blockchain-risk indicators;

h. transaction hashes;

i. sending wallet information;

j. receiving wallet information; and

k. other publicly or lawfully available blockchain data.

17. BLOCKCHAIN INFORMATION

Public blockchains may permanently record information including:

a. public wallet addresses;

b. transaction hashes;

c. asset amounts;

d. timestamps;

e. smart-contract interactions; and

f. transaction history.

Blockchain information may be public by design.

Although a public wallet address may not directly display your legal name, it may constitute or become Personal Data where it can reasonably be linked to you.

18. FOUNDER CIRCLE PARTICIPATION INFORMATION

Where you participate in the ARCBDS Founding Circle, we may process:

a. Participation Category;

b. Contribution amount;

c. fixed allocation price;

d. base ARCBDS allocation;

e. Alignment Reward;

f. total ARCBDS entitlement;

g. Cliff;

h. Release Period;

i. released allocation;

j. unreleased allocation;

k. Participation Confirmation;

l. acceptance records;

m. agreement versions;

n. transaction details;

o. participation date; and

p. related contractual records.

19. PARTICIPANT PROTECTION RESERVE INFORMATION

If you submit a Protection Reserve Claim, we may collect:

a. Claim ID;

b. Claim amount;

c. ARCBDS quantity subject to Claim;

d. evidence of ownership;

e. wallet records;

f. exchange statements;

g. attempted liquidation records;

h. order history;

i. market evidence;

j. claim communications;

k. identity verification;

l. fraud-screening results;

m. Reference Market Price information;

n. settlement information; and

o. Claim decision records.

20. SOURCE-OF-FUNDS INFORMATION

Where required, we may request evidence concerning the origin of funds used to participate.

Such information may include:

a. employment income;

b. business income;

c. investment proceeds;

d. asset-sale proceeds;

e. inheritance;

f. bank statements;

g. exchange statements;

h. wallet transaction records;

i. contractual evidence;

j. tax records; and

k. other supporting documentation.

21. SOURCE-OF-WEALTH INFORMATION

For higher-risk, larger or otherwise qualifying Participants, we may process information concerning how overall wealth was accumulated.

This may include information relating to:

a. business ownership;

b. employment;

c. investments;

d. property;

e. inheritance;

f. corporate distributions;

g. asset sales; and

h. other lawful sources.

22. AML AND SANCTIONS INFORMATION

We may process:

a. sanctions screening results;

b. politically exposed person screening;

c. adverse-media results;

d. watchlist results;

e. blockchain-risk information;

f. suspicious-activity indicators;

g. compliance-risk ratings;

h. enhanced due-diligence records;

i. investigation records; and

j. compliance decisions.

Such information may be obtained from third-party compliance providers or public sources.

23. TAX INFORMATION

Where required, we may collect:

a. tax residency;

b. tax identification number;

c. jurisdiction of tax residence;

d. corporate tax information; and

e. other legally required tax information.

24. TECHNICAL AND DEVICE INFORMATION

When you access our Website or Services, we may collect:

a. IP address;

b. browser type;

c. browser version;

d. operating system;

e. device type;

f. device identifiers;

g. language settings;

h. screen information;

i. network information;

j. time zone;

k. login timestamps;

l. session identifiers;

m. referring URLs;

n. pages visited;

o. interaction data;

p. error logs; and

q. security events.

25. APPROXIMATE LOCATION INFORMATION

We may infer approximate location from:

a. IP address;

b. device settings;

c. declared country;

d. KYC information; or

e. security information.

This may be used for:

eligibility;

jurisdiction screening;

security;

fraud prevention;

sanctions compliance; and

Website localisation.

We do not intend to continuously track precise physical location unless a feature specifically requires it and such processing is lawful and appropriately disclosed.

26. COOKIE AND SIMILAR TECHNOLOGY INFORMATION

We may receive information through:

a. cookies;

b. pixels;

c. SDKs;

d. local storage;

e. session storage;

f. analytics technologies; and

g. similar technologies.

Further details are provided in the ARCBDS Cookie Policy.

27. CUSTOMER SUPPORT INFORMATION

If you contact us, we may process:

a. contact details;

b. support-ticket information;

c. messages;

d. attachments;

e. screenshots;

f. complaint records;

g. call records where lawfully recorded;

h. issue history; and

i. resolution information.

28. BUSINESS AND PARTNERSHIP INFORMATION

If you contact ARCBDS as a:

business owner;

strategic partner;

service provider;

professional adviser;

institution;

media representative; or

potential ecosystem participant,

we may collect:

a. your name;

b. job title;

c. organisation;

d. contact details;

e. business proposal;

f. correspondence;

g. due-diligence information; and

h. other relevant professional information.

29. EVENT INFORMATION

If you register for or attend an ARCBDS event, we may collect:

a. name;

b. contact information;

c. organisation;

d. job title;

e. attendance information;

f. dietary or accessibility information voluntarily provided;

g. photographs or video where legally permitted;

h. event interactions; and

i. feedback.

Where photographs or recordings are used for promotional purposes, appropriate notices or consent will be provided where required.

30. MARKETING INFORMATION

We may process:

a. marketing consent;

b. subscription status;

c. preferred communication channels;

d. campaign interactions;

e. email opening or click data where lawfully used;

f. interests inferred from permitted interactions; and

g. unsubscribe history.

31. REFERRAL INFORMATION

Where referral programmes operate, we may process:

a. referral code;

b. referring Participant ID;

c. referred Participant ID;

d. referral relationship;

e. qualification status;

f. reward status;

g. rank or level where applicable;

h. commission or reward records; and

i. anti-abuse information.

Referral information will be processed subject to the ARCBDS Referral & Rewards Terms and Applicable Law.

32. INFORMATION FROM SOCIAL MEDIA

If you interact with official ARCBDS accounts on third-party social-media platforms, we may receive information made available by that platform, such as:

a. profile name;

b. public profile information;

c. comments;

d. messages;

e. reactions; and

f. other interaction data.

Your use of the third-party platform remains subject to that platform's own privacy terms.

33. INFORMATION YOU VOLUNTARILY PROVIDE

You may choose to provide additional information through:

a. surveys;

b. feedback;

c. event registrations;

d. business enquiries;

e. support requests;

f. complaints; or

g. communications with us.

Please avoid sending unnecessary Sensitive Personal Data.

34. HOW WE COLLECT PERSONAL DATA

We may collect Personal Data:

Directly from you

when you register, complete KYC, make a Contribution, submit documentation, contact us or use our Services.

Automatically

through Website, device, security and technical systems.

From blockchains

through publicly accessible blockchain records.

From service providers

including KYC, AML, sanctions, blockchain analytics and fraud-prevention providers.

From public sources

including corporate registries, sanctions lists and legally available public information.

From business partners

where permitted and appropriate.

From referrers

where a referral programme is used.

From regulators or authorities

where information is legally shared.

35. PURPOSES OF PROCESSING

We may process Personal Data for the following purposes.

36. ACCOUNT REGISTRATION AND ADMINISTRATION

We may process Personal Data to:

a. create Accounts;

b. authenticate users;

c. maintain Accounts;

d. provide dashboards;

e. administer account preferences;

f. provide transaction history;

g. maintain Participant records; and

h. respond to Account requests.

37. FOUNDER CIRCLE ADMINISTRATION

We may process Personal Data to:

a. assess applications;

b. confirm eligibility;

c. calculate allocations;

d. issue Participation Confirmations;

e. administer release schedules;

f. maintain entitlement records;

g. communicate programme updates;

h. enforce participation terms; and

i. manage Founding Circle relationships.

38. PAYMENT AND TRANSACTION PROCESSING

We may process Personal Data to:

a. verify Contributions;

b. identify blockchain transactions;

c. reconcile payments;

d. allocate ARCBDS;

e. process permitted withdrawals;

f. process refunds;

g. settle approved Claims; and

h. maintain transaction records.

39. KYC AND KYB

We process Personal Data to:

a. verify identity;

b. verify companies;

c. verify beneficial ownership;

d. determine authorised representatives;

e. detect impersonation;

f. satisfy legal obligations; and

g. protect ecosystem integrity.

40. AML, CFT AND SANCTIONS COMPLIANCE

We may process Personal Data to:

a. prevent money laundering;

b. prevent terrorism financing;

c. prevent proliferation financing where applicable;

d. conduct sanctions screening;

e. perform blockchain analytics;

f. detect suspicious activity;

g. perform enhanced due diligence;

h. submit legally required reports;

i. comply with regulator requests; and

j. comply with Applicable Law.

41. FRAUD PREVENTION

We may process information to detect or prevent:

a. identity fraud;

b. payment fraud;

c. Account takeover;

d. referral abuse;

e. duplicate Accounts;

f. fake Protection Reserve Claims;

g. manipulated transactions;

h. unauthorised access; and

i. other fraudulent activity.

42. SECURITY

We may process Personal Data to:

a. authenticate users;

b. detect malicious activity;

c. investigate incidents;

d. maintain access logs;

e. identify suspicious logins;

f. protect infrastructure;

g. prevent cyberattacks;

h. manage sessions;

i. enforce security controls; and

j. recover from security incidents.

43. PROTECTION RESERVE ADMINISTRATION

We may process Personal Data to:

a. evaluate Claims;

b. verify ownership;

c. verify token provenance;

d. confirm release status;

e. verify liquidation attempts;

f. determine eligibility;

g. prevent double Claims;

h. determine settlements;

i. process appeals; and

j. maintain Reserve records.

44. CUSTOMER SERVICE

We process information to:

a. answer enquiries;

b. provide technical support;

c. resolve transaction issues;

d. respond to complaints;

e. investigate disputes; and

f. improve service quality.

45. LEGAL AND REGULATORY COMPLIANCE

We may process and disclose Personal Data where reasonably necessary to:

a. comply with laws;

b. comply with court orders;

c. respond to regulators;

d. respond to competent authorities;

e. establish legal claims;

f. exercise legal rights;

g. defend legal claims;

h. conduct audits;

i. maintain required records; and

j. meet licensing or regulatory obligations.

46. BUSINESS OPERATIONS

We may process Personal Data for legitimate operational purposes permitted by Applicable Law, including:

a. financial accounting;

b. auditing;

c. risk management;

d. corporate governance;

e. service-provider management;

f. internal reporting;

g. business continuity;

h. record management;

i. corporate restructuring; and

j. service development.

47. SERVICE IMPROVEMENT

Where lawful, we may use information to:

a. understand Website performance;

b. identify technical issues;

c. improve usability;

d. develop features;

e. analyse aggregated usage;

f. improve security; and

g. improve customer support.

Where possible, analytics may use aggregated or de-identified information.

48. MARKETING

Where permitted, we may use Personal Data to send:

a. ecosystem updates;

b. event announcements;

c. educational content;

d. product updates;

e. partner updates;

f. Founding Circle-related information; and

g. promotional communications.

Where consent is legally required, marketing will be based on appropriate consent.

You may withdraw optional marketing consent at any time.

49. WE DO NOT SELL PERSONAL DATA

ARCBDS does not sell Personal Data to third-party data brokers for their independent advertising purposes.

We do not exchange KYC identity information for money with advertisers.

Where information is shared with service providers, it is shared for authorised operational, contractual, security or legal purposes.

50. LEGAL BASIS FOR PROCESSING

Depending on Applicable Law and the circumstances, Personal Data may be processed on one or more lawful grounds including:

a. your consent;

b. steps requested before entering a contract;

c. performance of a contract with you;

d. compliance with legal or regulatory obligations;

e. protection of legal rights;

f. establishment, exercise or defence of legal claims;

g. prevention or detection of unlawful activity where legally permitted;

h. protection of public interest where legally applicable; and

i. another lawful basis recognised under Applicable Law.

Where consent is the required legal basis, you may withdraw that consent, subject to Applicable Law.

51. CONSENT

Where we rely on consent:

51.1 consent should be informed and freely provided as required by Applicable Law;

51.2 consent may be collected electronically;

51.3 different processing activities may require separate consent;

51.4 optional marketing consent will be separated from mandatory contractual acceptance where required;

51.5 withdrawing consent does not automatically invalidate lawful Processing undertaken before withdrawal; and

51.6 certain Services may become unavailable where the relevant Personal Data is necessary to provide the Service.

52. MANDATORY INFORMATION

Certain Personal Data may be required to:

a. create an Account;

b. verify identity;

c. satisfy KYC requirements;

d. process a Founding Circle participation;

e. comply with AML obligations;

f. process a transaction;

g. administer a Protection Reserve Claim; or

h. meet legal requirements.

If required information is not provided, we may be unable to provide the relevant Service.

53. AUTOMATED PROCESSING

We may use automated systems to assist with:

a. identity verification;

b. fraud detection;

c. sanctions screening;

d. blockchain-risk analysis;

e. transaction monitoring;

f. Account security;

g. risk classification; and

h. compliance review.

Where Applicable Law provides rights concerning significant decisions based solely on automated Processing, those rights will be respected.

Where appropriate, decisions may be escalated for human review.

54. PROFILING

Where legally permitted, limited profiling may be used for:

a. financial-crime risk assessment;

b. security;

c. fraud detection;

d. jurisdiction eligibility;

e. Account-risk classification; and

f. compliance monitoring.

We do not intend to use KYC or Sensitive Personal Data to create unrelated commercial advertising profiles.

55. WHO WE MAY SHARE PERSONAL DATA WITH

Personal Data may be shared with recipients including the following where necessary and lawful.

56. ARCBDS GROUP AND AFFILIATED ENTITIES

Information may be shared with ARCBDS or ARCB-related entities where necessary for:

a. programme administration;

b. compliance;

c. accounting;

d. security;

e. legal support;

f. ecosystem operations; or

g. other lawful purposes described in this Policy.

Access should be limited to personnel with a legitimate need to know.

57. KYC AND IDENTITY PROVIDERS

We may share information with third-party providers performing:

a. document verification;

b. identity verification;

c. facial/liveness verification;

d. KYB;

e. beneficial-owner verification; or

f. related compliance services.

58. AML, SANCTIONS AND BLOCKCHAIN ANALYTICS PROVIDERS

We may use third parties for:

a. sanctions screening;

b. PEP screening;

c. adverse-media screening;

d. wallet-risk screening;

e. blockchain transaction tracing;

f. fraud detection; and

g. compliance monitoring.

59. PAYMENT AND FINANCIAL SERVICE PROVIDERS

Where applicable, information may be shared with:

a. banks;

b. payment processors;

c. stablecoin service providers;

d. digital-asset service providers;

e. settlement providers; or

f. financial institutions

to process lawful transactions.

60. CUSTODY AND WALLET PROVIDERS

If third-party custody or wallet infrastructure is used, information may be shared where necessary to:

a. create or administer wallets;

b. verify ownership;

c. facilitate transfers;

d. meet regulatory requirements; and

e. provide security.

61. TECHNOLOGY SERVICE PROVIDERS

We may use:

a. hosting providers;

b. cloud infrastructure;

c. database providers;

d. cybersecurity providers;

e. email providers;

f. messaging providers;

g. analytics providers;

h. support platforms;

i. document-management providers; and

j. software vendors.

Such providers should receive only information reasonably required for their services.

62. PROFESSIONAL ADVISERS

We may disclose Personal Data to:

a. lawyers;

b. accountants;

c. auditors;

d. consultants;

e. insurers where applicable;

f. compliance advisers; and

g. other professional advisers

where reasonably necessary.

63. REGULATORS AND AUTHORITIES

We may disclose Personal Data to:

a. VARA where applicable;

b. the UAE Data Office or other competent data-protection authority;

c. law-enforcement authorities;

d. courts;

e. tax authorities;

f. sanctions authorities;

g. AML authorities;

h. financial-intelligence authorities; and

i. other competent governmental or regulatory bodies

where required or lawfully requested.

64. LEGAL PROCESS

We may disclose information where necessary to:

a. comply with a subpoena or equivalent lawful process;

b. respond to a court order;

c. establish legal rights;

d. protect legal rights;

e. investigate fraud;

f. enforce agreements; or

g. defend legal claims.

We will not disclose information merely because an unauthorised third party requests it.

65. CORPORATE TRANSACTIONS

If the ARCBDS business undergoes:

a. merger;

b. acquisition;

c. financing;

d. corporate reorganisation;

e. sale;

f. transfer;

g. insolvency restructuring; or

h. other corporate transaction,

Personal Data may be disclosed to relevant advisers and counterparties subject to appropriate legal protections.

66. BUSINESS PARTNERS

We do not automatically share full KYC information with every business participating in the ARCBDS ecosystem.

Where a specific business service requires data sharing, we will limit information to what is reasonably necessary and legally permitted.

Additional notices or consent may be used where required.

67. REFERRERS AND COMMUNITY LEADERS

Referrers, community leaders and Participants should not receive unrestricted access to another Participant's:

a. KYC documents;

b. passport;

c. address;

d. source of funds;

e. source of wealth;

f. private wallet information; or

g. other confidential compliance records.

A referral programme may display limited information necessary to administer lawful referral relationships, subject to privacy controls.

68. INTERNATIONAL DATA TRANSFERS

ARCBDS may operate internationally and may use service providers located in different countries.

Personal Data may therefore be transferred outside the country in which it was originally collected.

Where international transfers are subject to legal restrictions, we will use transfer mechanisms permitted under Applicable Law.

These may include, as appropriate:

a. transfers to jurisdictions recognised as providing adequate protection;

b. contractual safeguards;

c. explicit consent where legally valid;

d. legally recognised exceptions;

e. regulatory mechanisms; or

f. another permitted transfer method.

69. DATA LOCATION

Depending on our infrastructure, Personal Data may be stored or processed:

a. in the UAE;

b. in approved cloud regions outside the UAE; or

c. by authorised international service providers.

The final infrastructure configuration should be reflected in ARCBDS's internal data inventory and transfer records.

70. PUBLIC BLOCKCHAIN DATA AND INTERNATIONAL AVAILABILITY

Blockchain networks may operate through globally distributed nodes.

A blockchain transaction may therefore become accessible internationally and may not have a single geographic storage location.

Before conducting blockchain transactions, Participants should understand that public blockchain records may be globally visible.

71. BLOCKCHAIN IMMUTABILITY

Public blockchain technology presents unique privacy limitations.

Where Personal Data or data linked to an individual is recorded on a public blockchain:

a. ARCBDS may not control all copies of that information;

b. the information may be permanently replicated;

c. deletion from the blockchain may be technically impossible;

d. correction of historical blockchain records may be technically impossible; and

e. ARCBDS may only be able to correct or delete information within systems that it controls.

For this reason, ARCBDS should avoid placing unnecessary direct identity information on public blockchains.

72. DATA MINIMISATION ON-CHAIN

Where reasonably possible, we aim to avoid publishing on public blockchain networks:

a. passport numbers;

b. residential addresses;

c. identity documents;

d. biometric information;

e. source-of-funds documentation;

f. confidential KYC records; or

g. other unnecessary sensitive information.

Public wallet addresses and transaction hashes may nevertheless be recorded by the blockchain itself.

73. DATA RETENTION

We retain Personal Data only for as long as reasonably necessary for:

a. the purposes for which it was collected;

b. performance of contractual obligations;

c. legal and regulatory requirements;

d. AML recordkeeping;

e. tax and accounting;

f. dispute resolution;

g. fraud prevention;

h. cybersecurity;

i. legal claims; and

j. other legitimate retention requirements recognised by Applicable Law.

74. RETENTION CRITERIA

Retention periods may depend on:

a. type of information;

b. whether you became a Participant;

c. duration of the relationship;

d. transaction history;

e. KYC requirements;

f. AML rules;

g. tax requirements;

h. regulatory requirements;

i. pending disputes;

j. investigations;

k. legal limitation periods; and

l. security requirements.

75. INDICATIVE RETENTION CATEGORIES

Subject to final legal and regulatory confirmation:

Account Data

Retained for the active Account period and for an appropriate period afterwards.

Participation Agreements

Retained for the contractual relationship and applicable legal recordkeeping period.

Transaction Records

Retained for the period required under applicable financial, AML, tax and regulatory laws.

KYC/KYB Records

Retained for the period required by applicable AML/CFT, sanctions and regulatory obligations.

Protection Reserve Claim Records

Retained for the period necessary for administration, audit, fraud prevention, legal defence and regulatory requirements.

Marketing Consent Records

Retained for the period necessary to demonstrate consent, withdrawal and compliance.

Security Logs

Retained according to risk, security and regulatory requirements.

Support Communications

Retained as reasonably necessary for support, dispute and quality-control purposes.

76. LEGAL HOLDS

Information may be retained beyond ordinary retention periods where necessary because of:

a. litigation;

b. investigation;

c. regulatory request;

d. law-enforcement request;

e. audit;

f. sanctions review;

g. fraud review; or

h. another legal hold.

Deletion may be suspended while a valid legal hold applies.

77. DELETION AND ANONYMISATION

At the end of the applicable retention period, Personal Data may be:

a. securely deleted;

b. anonymised;

c. irreversibly de-identified; or

d. otherwise handled in accordance with Applicable Law.

Anonymised information that can no longer identify an individual may be retained for statistical or analytical purposes where lawful.

78. DATA SECURITY

We take reasonable technical and organisational measures designed to protect Personal Data.

Measures may include:

a. access controls;

b. authentication;

c. encryption;

d. network security;

e. endpoint security;

f. monitoring;

g. logging;

h. secure-development practices;

i. vendor-management controls;

j. role-based access;

k. secure backup;

l. incident-response procedures;

m. staff training;

n. physical security; and

o. business-continuity measures.

79. ACCESS CONTROL

Access to Personal Data should be limited according to:

a. job responsibility;

b. legitimate business need;

c. compliance role;

d. security role; and

e. authorised access permissions.

Employees and contractors with access to confidential information should be subject to confidentiality requirements.

80. STAFF CONFIDENTIALITY

Staff must not access, use or disclose Participant information merely out of curiosity or for personal purposes.

Confidential Participant information must only be accessed for authorised business, compliance, security, legal or regulatory purposes.

81. VENDOR SECURITY

Where service providers process Personal Data on our behalf, we may assess factors including:

a. security capability;

b. confidentiality;

c. data-protection practices;

d. access controls;

e. incident response;

f. sub-processors;

g. international transfers;

h. deletion procedures; and

i. contractual protections.

82. NO SYSTEM IS COMPLETELY SECURE

Despite security measures, no digital system can be guaranteed completely secure.

Risks include:

a. cyberattack;

b. phishing;

c. malware;

d. employee misconduct;

e. third-party compromise;

f. infrastructure failure;

g. credential theft; and

h. zero-day vulnerabilities.

Participants should maintain appropriate security over their own Accounts, email addresses and devices.

83. PERSONAL DATA BREACHES

Where we become aware of a Personal Data breach, we will:

a. investigate the incident;

b. seek to contain it;

c. assess affected information;

d. assess risks to individuals;

e. take remediation measures;

f. maintain appropriate incident records; and

g. provide notifications required by Applicable Law.

84. NOTIFICATION OF DATA SUBJECTS

Where Applicable Law requires affected individuals to be notified of a Personal Data incident, notification may describe:

a. the nature of the incident;

b. categories of information affected;

c. potential consequences;

d. mitigation measures;

e. actions individuals may take; and

f. contact information.

Notifications may be withheld or modified where legally prohibited.

85. REGULATORY INCIDENT REPORTING

Where ARCBDS operates through an entity subject to VARA requirements, applicable Personal Data incident-reporting obligations to VARA will be followed in addition to other legally required notifications.

86. YOUR PRIVACY RIGHTS

Depending on Applicable Law and your circumstances, you may have rights concerning your Personal Data.

Such rights may include the following.

87. RIGHT TO INFORMATION

You may have the right to obtain information concerning:

a. types of Personal Data processed;

b. purposes of Processing;

c. Processing decisions;

d. recipients;

e. safeguards;

f. retention;

g. cross-border transfers; and

h. other matters required by Applicable Law.

88. RIGHT OF ACCESS

You may request access to Personal Data we hold about you, subject to:

a. identity verification;

b. rights of other individuals;

c. security considerations;

d. legal restrictions; and

e. other exceptions under Applicable Law.

89. RIGHT TO RECTIFICATION

You may request correction of inaccurate Personal Data.

You may also request completion of incomplete information where appropriate.

Participants should maintain accurate Account and KYC information.

90. RIGHT TO ERASURE

Where permitted by Applicable Law, you may request deletion of Personal Data.

However, we may be unable or not permitted to delete information where retention is necessary for:

a. AML requirements;

b. sanctions compliance;

c. regulatory obligations;

d. tax;

e. legal claims;

f. fraud prevention;

g. contractual records;

h. public interest;

i. security; or

j. another legally recognised reason.

Public blockchain data may also be technically impossible for ARCBDS to erase.

91. RIGHT TO RESTRICT OR STOP PROCESSING

Where provided by Applicable Law, you may request restriction or suspension of particular Processing activities.

This right may be limited where continued Processing is necessary for legal, regulatory, contractual, security or other legally recognised purposes.

92. RIGHT TO DATA PORTABILITY

Where Applicable Law provides a portability right, you may be able to receive certain Personal Data provided by you in a structured and machine-readable format.

Where technically feasible and legally required, you may request transfer to another Controller.

93. RIGHT TO WITHDRAW CONSENT

Where Processing is based on consent, you may withdraw consent.

Withdrawal may affect optional Services or communications.

Withdrawal does not necessarily require deletion of information that must be retained under another lawful basis.

94. RIGHT TO OBJECT

Where Applicable Law grants a right to object to certain Processing, you may submit an objection.

The applicability of the objection will depend on:

a. the Processing purpose;

b. legal basis;

c. legal requirements; and

d. whether overriding lawful grounds permit continued Processing.

95. DIRECT MARKETING RIGHTS

You may opt out of optional marketing at any time by:

a. using an unsubscribe link;

b. changing Account preferences where available; or

c. contacting us.

Opting out of marketing does not stop necessary:

security alerts;

contractual notices;

transaction communications;

regulatory notices;

Account communications; or

legal communications.

96. AUTOMATED DECISION RIGHTS

Where Applicable Law provides rights concerning automated decisions producing significant effects, you may request:

a. information concerning the automated Processing;

b. human review where legally required;

c. correction of relevant information; or

d. another remedy provided by Applicable Law.

97. RIGHT TO COMPLAIN

You may submit a privacy complaint directly to ARCBDS.

Where Applicable Law permits, you may also have the right to complain to the relevant data-protection regulator or other competent authority.

98. HOW TO EXERCISE YOUR RIGHTS

Requests may be submitted to:

Privacy Email: [●]

Data Protection Officer: [●]

Online Privacy Portal: [●]

Postal Address: [●]

Your request should include sufficient information to identify:

a. you;

b. the right being exercised; and

c. the Personal Data or Processing concerned.

99. IDENTITY VERIFICATION FOR PRIVACY REQUESTS

To protect Personal Data from unauthorised disclosure, we may verify your identity before processing a privacy request.

We will not ordinarily disclose confidential KYC records merely because someone has access to an email address associated with an Account.

Verification should be proportionate to the sensitivity of the request.

100. AUTHORISED REPRESENTATIVES

Where legally permitted, an authorised representative may submit a request on your behalf.

We may require:

a. proof of authority;

b. representative identification; and

c. confirmation of the Data Subject's identity.

101. REQUEST LIMITATIONS

Privacy rights may be subject to lawful limitations where, for example:

a. disclosure would prejudice an investigation;

b. disclosure would affect another person's privacy;

c. information must be retained under law;

d. a request is manifestly abusive or excessively repetitive;

e. disclosure would compromise security;

f. legal privilege applies; or

g. another statutory exception applies.

Any refusal will be handled according to Applicable Law.

102. RESPONSE PERIOD

We will respond to valid Data Subject requests within the period required by Applicable Law.

Where a request is complex or additional verification is required, the response period may be extended where legally permitted.

103. CHILDREN AND MINORS

The Founding Circle and transactional ARCBDS Services are not intended for persons under eighteen (18) years old or a higher applicable legal age.

We do not knowingly accept minors into the Founding Circle.

If we discover that a minor has provided Personal Data in violation of our eligibility requirements, we may:

a. suspend the Account;

b. decline participation;

c. delete information where legally permitted; and

d. retain information where legally required for fraud, legal or compliance purposes.

104. MARKETING TO MINORS

We do not intentionally target Founding Circle investment or digital-asset participation marketing at minors.

105. COOKIES

ARCBDS uses cookies and similar technologies in accordance with the ARCBDS Cookie Policy.

Cookie categories may include:

a. strictly necessary;

b. security;

c. functional;

d. preference;

e. analytics; and

f. marketing cookies.

Non-essential cookies will be handled according to applicable consent requirements.

106. THIRD-PARTY WEBSITES

The ARCBDS Website may link to third-party websites.

This Privacy Policy does not control independent third parties.

You should review their privacy policies before providing information.

107. SOCIAL-MEDIA PLATFORMS

ARCBDS may maintain pages on:

a. LinkedIn;

b. X;

c. YouTube;

d. Telegram; and

e. other platforms.

Those platforms independently determine aspects of their own Personal Data Processing.

ARCBDS is not responsible for the independent privacy practices of third-party social-media services.

108. EMAIL AND MESSAGING SECURITY

Email and messaging systems may not always provide end-to-end confidentiality.

Do not send:

a. private keys;

b. seed phrases;

c. passwords; or

d. unnecessary highly sensitive information

through ordinary messaging channels.

ARCBDS staff should never request a private key or seed phrase.

109. CALL RECORDING

Where customer-service or compliance calls are recorded, appropriate notice will be provided where required.

Recordings may be used for:

a. quality assurance;

b. compliance;

c. dispute resolution;

d. training;

e. fraud prevention; and

f. legal evidence.

110. ARTIFICIAL INTELLIGENCE AND ANALYTICS

ARCBDS may use automated analytics or AI-assisted tools for limited operational functions such as:

a. fraud detection;

b. security analysis;

c. customer-support assistance;

d. risk detection;

e. document classification;

f. compliance support; and

g. service improvement.

Sensitive KYC information should not be used to train unrelated public AI models without an appropriate legal basis and disclosure.

Where a third-party AI service processes Personal Data, appropriate vendor and privacy controls should apply.

111. AGGREGATED INFORMATION

We may generate aggregated statistics that do not reasonably identify an individual.

Examples may include:

a. total Participants;

b. geographic distribution at aggregate level;

c. aggregate transaction volumes;

d. Website usage statistics;

e. general ecosystem activity; and

f. aggregate claim information.

Properly anonymised information may fall outside Personal Data requirements where Applicable Law recognises such treatment.

112. PUBLIC LEADERBOARDS AND COMMUNITY FEATURES

If ARCBDS introduces:

a. rankings;

b. leaderboards;

c. referral statistics;

d. public usernames;

e. community achievements; or

f. similar features,

we will seek to avoid publicly displaying unnecessary legal identity information.

Appropriate display settings or notices should be provided where required.

113. PRIVACY OF REFERRAL NETWORKS

Referral participants should not automatically receive complete visibility over:

a. another Participant's Contribution balance;

b. KYC information;

c. wallet balance;

d. source-of-funds information; or

e. transaction history.

Any referral dashboard should display only information reasonably necessary for programme administration.

114. SECURITY OF KYC DOCUMENTS

KYC and KYB documents should be subject to enhanced controls because of their sensitivity.

Controls may include:

a. restricted access;

b. encrypted transmission;

c. encrypted storage;

d. monitoring;

e. secure vendor integrations;

f. access logging; and

g. retention controls.

115. ACCURACY OF INFORMATION

You should ensure Personal Data supplied to ARCBDS is accurate.

You must not provide:

a. another person's identity document without authority;

b. falsified records;

c. misleading beneficial-owner information;

d. false addresses;

e. false source-of-funds records; or

f. other intentionally inaccurate information.

116. ACCOUNT CLOSURE

Closing your Account does not necessarily result in immediate deletion of all Personal Data.

We may continue to retain information required for:

a. AML/CFT;

b. sanctions;

c. regulatory obligations;

d. accounting;

e. tax;

f. legal claims;

g. fraud prevention;

h. contractual records; or

i. blockchain transaction history.

Information no longer required will be deleted or anonymised in accordance with our retention practices.

117. DECEASED PARTICIPANTS

Where applicable, we may process information concerning a deceased Participant and their authorised representatives for purposes including:

a. estate administration;

b. inheritance;

c. transfer of lawful rights;

d. fraud prevention; and

e. legal compliance.

We may request documentation including:

a. death certificate;

b. probate documents;

c. court order;

d. estate documents; and

e. representative identification.

118. REGULATORY ACCESS

Where ARCBDS operates through a regulated entity, regulators may have legal rights to inspect records.

We may be required to provide regulators access to information concerning:

a. compliance;

b. Participants;

c. transactions;

d. Personal Data Processing;

e. cybersecurity;

f. AML;

g. complaints; or

h. other regulated matters.

Such disclosures will be made in accordance with Applicable Law.

119. LAW-ENFORCEMENT REQUESTS

We assess law-enforcement requests according to applicable legal requirements.

Where legally permitted and appropriate, we may require a request to be:

a. issued by a competent authority;

b. sufficiently specific;

c. legally valid; and

d. within the requesting authority's powers.

We may be prohibited from informing affected individuals of certain requests.

120. GOVERNMENT SANCTIONS AND ASSET FREEZES

Legal sanctions or asset-freeze requirements may prevent us from:

a. processing a transaction;

b. returning assets;

c. deleting particular records;

d. providing certain information; or

e. continuing a relationship.

Where such legal restrictions apply, they override inconsistent user instructions.

121. CONFIDENTIALITY OF PARTICIPANT INFORMATION

We recognise that Participant information may include confidential commercial and financial information in addition to Personal Data.

We seek to ensure that confidential information is used only for authorised purposes and is shared internally on an appropriate need-to-know basis.

122. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy because of:

a. changes in law;

b. regulatory requirements;

c. changes in ARCBDS services;

d. new technology;

e. new service providers;

f. new jurisdictions;

g. security developments; or

h. changes in our Processing activities.

123. MATERIAL CHANGES

Where required, material changes may be communicated through:

a. Website notice;

b. Account notice;

c. email;

d. platform notification; or

e. another reasonable method.

Where new consent is legally required, we will seek that consent before relying on it.

124. PRIVACY POLICY VERSION CONTROL

ARCBDS should maintain records including:

a. Policy version;

b. publication date;

c. effective date;

d. material changes;

e. previous versions; and

f. consent or acknowledgement records where applicable.

125. CONFLICT WITH OTHER DOCUMENTS

This Privacy Policy governs Personal Data Processing.

If another ARCBDS agreement contains privacy provisions, both documents should be interpreted consistently.

Mandatory data-protection law prevails over contractual language to the extent required by law.

126. INTERNATIONAL USERS

Individuals located outside the UAE may have additional rights under privacy laws applicable in their jurisdiction.

Where such laws legally apply to ARCBDS, we will seek to comply with those obligations.

This Policy does not waive rights that cannot legally be waived.

127. LANGUAGE

The official controlling version of this Privacy Policy shall be English to the extent legally permitted.

Translations may be provided for convenience.

Where Applicable Law requires another language version or gives another language precedence, that requirement shall apply.

128. CONTACT US

Questions or requests concerning privacy may be sent to:

ARCBDS PRIVACY OFFICE

Data Controller:

[●]

Data Protection Officer:

[●]

Privacy Email:

[●]

DPO Email:

[●]

Registered Address:

[●]

Website:

www.arcbds.com

129. PRIVACY COMPLAINTS

If you believe your Personal Data has been processed improperly, you may first contact:

Privacy / DPO: [●]

Please provide:

a. your name;

b. relevant Account ID where appropriate;

c. a description of the issue;

d. relevant dates; and

e. supporting information.

We will investigate complaints according to Applicable Law and applicable internal procedures.

Nothing prevents you from contacting a competent data-protection authority where you have a legal right to do so.

SCHEDULE 1

PERSONAL DATA COLLECTION SUMMARY

Category

Examples

Main Purposes

Identity

Name, date of birth, nationality

KYC, Account, eligibility

ID Documents

Passport, identity card

Verification, compliance

Contact

Email, mobile, address

Account, notices, support

Biometric Verification

Selfie, liveness check

Identity verification, fraud prevention

Corporate / KYB

Company records, directors, UBOs

Institutional onboarding

Financial

Contribution, payment, refund

Transaction processing

Wallet / Blockchain

Wallet address, hashes, transaction history

Payment, AML, allocation

Founding Circle

Category, allocation, release

Programme administration

Protection Reserve

Claim and liquidation evidence

Claim administration

Source of Funds

Statements, evidence of funding

AML

Source of Wealth

Business, investments, assets

Enhanced due diligence

Compliance

Sanctions, PEP, risk rating

Legal compliance

Technical

IP, device, logs

Security, fraud, analytics

Marketing

Consent, preferences

Optional communications

Referral

Referral code, relationship

Reward administration

Support

Messages and attachments

Customer service

SCHEDULE 2

PURPOSE AND LEGAL-BASIS FRAMEWORK

Subject to Applicable Law:

Processing

Potential Legal Basis

Account creation

Contract / pre-contractual processing

Founding Circle administration

Contract

KYC/KYB

Legal/regulatory obligation and other lawful grounds

AML/sanctions

Legal/regulatory obligation

Transaction processing

Contract / legal obligation

Protection Reserve Claims

Contract / legal obligation

Fraud prevention

Legal obligation / lawful permitted interest or equivalent lawful basis

Cybersecurity

Legal obligation / lawful permitted basis

Accounting and tax

Legal obligation

Regulatory reporting

Legal obligation

Legal claims

Establishment, exercise or defence of legal rights

Optional marketing

Consent or another lawful basis where permitted

Non-essential cookies

Consent where required

Service analytics

Consent or other lawful basis where permitted

Customer support

Contract / legitimate operational purpose recognised by Applicable Law

The precise legal basis must be determined according to the jurisdiction and circumstances.

SCHEDULE 3

DATA RECIPIENT CATEGORIES

Personal Data may be provided to:

ARCBDS operating entities;

KYC/KYB providers;

AML and sanctions providers;

blockchain analytics providers;

custody providers;

wallet infrastructure providers;

banks;

payment providers;

stablecoin transaction providers where applicable;

cloud service providers;

hosting providers;

cybersecurity providers;

communications providers;

customer-support providers;

professional advisers;

auditors;

regulators;

courts;

law-enforcement agencies;

tax authorities; and

other recipients lawfully required for ARCBDS operations.

The final operational version should maintain an internal processor/sub-processor register identifying actual providers.

SCHEDULE 4

DATA SUBJECT REQUEST FORM

Full Legal Name: [●]

Account ID: [●]

Registered Email: [●]

Country: [●]

REQUEST TYPE

☐ Access my Personal Data

☐ Correct my Personal Data

☐ Delete eligible Personal Data

☐ Restrict Processing

☐ Withdraw Consent

☐ Object to eligible Processing

☐ Request Data Portability

☐ Marketing Opt-Out

☐ Request Automated Decision Review

☐ Other: [●]

DETAILS OF REQUEST

[●]

IDENTITY VERIFICATION

[●]

SIGNATURE / ELECTRONIC CONFIRMATION

[●]

DATE

[●]

SCHEDULE 5

PERSONAL DATA BREACH RESPONSE PRINCIPLES

In the event of a suspected Personal Data breach, ARCBDS should:

identify the incident;

contain the incident;

preserve relevant evidence;

determine affected systems;

determine affected Personal Data;

assess affected Data Subjects;

assess likely consequences;

remediate vulnerabilities;

determine regulatory notification obligations;

determine Data Subject notification obligations;

document decisions;

monitor for misuse;

conduct root-cause analysis; and

implement measures to reduce recurrence.

SCHEDULE 6

PRIVACY REQUIREMENTS FOR ARCBDS WEBSITE AND PORTAL

The ARCBDS Website and participant portal should provide:

Registration

A visible link to the Privacy Policy.

KYC

A specific notice explaining identity-verification Processing.

Biometric Verification

An appropriate notice before facial or liveness verification where required.

Participation

Disclosure that transaction, wallet, allocation and agreement records will be retained.

Marketing

A separate optional marketing consent mechanism.

Cookies

A cookie preference interface where required.

Privacy Rights

A simple method for submitting Data Subject requests.

Account

A mechanism for updating basic Personal Data where appropriate.

Account Closure

Clear explanation that regulatory records may remain after Account closure.

SCHEDULE 7

KYC PRIVACY NOTICE

Before KYC begins, ARCBDS should display substantially the following:

Identity Verification Notice

To assess eligibility and comply with applicable legal, regulatory, AML and sanctions requirements, ARCBDS and its authorised verification providers will process identity and verification information that may include your name, date of birth, nationality, identity document, photograph, facial/liveness verification and related compliance information.

Your information may be checked against sanctions, politically exposed person and other legally permitted compliance databases.

Completion of identity verification does not guarantee acceptance into the ARCBDS Founding Circle.

Please review the ARCBDS Privacy Policy before continuing.

SCHEDULE 8

BLOCKCHAIN PRIVACY NOTICE

Before a Participant provides or connects a wallet, the Website should display substantially the following:

Blockchain Privacy Notice

Blockchain transactions may be public and permanent.

Your public wallet address, transaction history, transaction amounts and smart-contract interactions may be visible to other blockchain users and analytics providers.

If your wallet address is linked to your identity, blockchain activity associated with that address may potentially be linked to you.

ARCBDS cannot erase or modify information independently maintained on a public blockchain.

Do not use a wallet if you do not understand these characteristics.

SCHEDULE 9

MARKETING CONSENT

Where consent is required:

☐ I would like to receive ARCBDS news, ecosystem updates, event invitations and promotional communications by email or other selected communication channels.

Marketing consent is optional and is not required to create an Account or participate where participation is otherwise available.

Users may unsubscribe at any time.

SCHEDULE 10

DATA RETENTION REGISTER

ARCBDS should maintain an internal retention schedule covering at minimum:

Record Type

Owner

Retention Rule

Legal Basis

Disposal Method

Account Records

[●]

[●]

[●]

[●]

KYC Records

[●]

Applicable legal period

AML / Regulatory

Secure deletion

KYB Records

[●]

Applicable legal period

AML / Regulatory

Secure deletion

Transaction Records

[●]

Applicable legal period

Regulatory / Tax

Secure deletion

Participation Agreements

[●]

[●]

Contract / Legal

Secure deletion

Risk Acknowledgements

[●]

[●]

Regulatory / Contract

Secure deletion

Protection Reserve Claims

[●]

[●]

Contract / Regulatory

Secure deletion

Marketing Consent

[●]

[●]

Consent evidence

Secure deletion

Support Records

[●]

[●]

Operational / Legal

Secure deletion

Security Logs

[●]

[●]

Security

Secure deletion

Regulatory Reports

[●]

Applicable legal period

Regulatory

Secure deletion

Specific retention periods must be aligned with the applicable AML, virtual-asset, corporate, tax and data-protection requirements before launch.

FINAL PRIVACY NOTICE

ARCBDS processes Personal Data because identity, compliance, transaction security and participant administration are fundamental to the operation of the ecosystem.

We will not use the confidential information entrusted to us without purpose or authority.

Participants should nevertheless understand that digital assets involve technologies such as public blockchains where certain transaction information may be permanent and publicly accessible.

You should read this Privacy Policy before:

creating an ARCBDS Account;

completing KYC/KYB;

connecting or providing a wallet;

participating in the Founding Circle; or

submitting a Participant Protection Reserve Claim.

END OF ARCBDS PRIVACY POLICY

Privacy Policy — ARCB Digital Share