SIMODI GOLD FZCO Privacy Policy
1. Introduction
This Privacy Policy explains how SIMODI GOLD FZCO ("SIMODI GOLD", "we", "us", or "our"), a company registered with the Dubai Multi Commodities Centre ("DMCC"), with its registered address at 1902, The Dome Tower, Cluster N, JLT, Dubai, United Arab Emirates, collects, uses, stores, shares, and protects personal data when users access or use the SIMODI GOLD mobile application (the "App"), website (the "Website"), and related products and services (the "Services").
SIMODI GOLD acts as the data controller responsible for determining the purposes and means of processing personal data collected through the Services. We process personal data in accordance with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "UAE PDPL") together with any applicable regulations, decisions and guidance issued thereunder, as amended from time to time and any other applicable data protection or regulatory requirements, including requirements applicable to SIMODI GOLD as a DMCC-registered Dealer in Precious Metals and Stones. Where a specific activity is separately regulated (for example, payment processing or AML/CFT obligations), those requirements apply in addition to this Policy.
This Privacy Policy should be read together with the SIMODI GOLD Terms and Conditions, Cookie Policy, and any other legal documents made available through the App and Website.
The Version and Effective Date shown above identify the current version of this Privacy Policy.
2. Information We Collect
SIMODI GOLD may collect personal data directly from users, automatically through the App or Website, or from third-party service providers. This may include:
- Identity information: name, date of birth, nationality, identity documents, and verification records.
- Contact information: address, email address, and phone number.
- Verification information: selfie images, biometric-linked verification outputs where facial or liveness checks are performed by third-party KYC providers, KYC records, AML/CFT/CPF screening results, source of funds, source of wealth, and tax information. SIMODI GOLD does not itself generate biometric templates; capture and matching is performed by third-party KYC providers, and SIMODI GOLD reviews verification outcomes for compliance purposes.
- Corporate and beneficial-ownership information: where corporate or legal-entity onboarding is made available, information relating to the entity and its directors, shareholders, beneficial owners, authorised signatories and other connected persons, including identification, ownership and verification information.
- Account and transaction information: account or customer identifiers, account status, gold and silver holdings, account balances, Wallet balances, transaction history, order records, settlement records, transfers, redemption records, delivery addresses, delivery instructions, proof of delivery, delivery records and related account activity.
- Financial and payment information: bank details, masked payment identifiers, transaction history, order records, settlement records, Wallet funding and withdrawal records, and redemption records. Sensitive cardholder data such as full card numbers, CVV, and expiry dates are not stored by SIMODI GOLD and are handled by licensed payment processors.
- Technical information: device information, device identifiers, IP address, app usage data, location information where collected, login activity, cookies or similar technologies (see the Cookie Policy), and security logs.
- Communications information: support requests, complaints, customer service records, compliance correspondence, and other messages sent to or received from us.
- Marketing and preference information: communication preferences, marketing consents, opt-out preferences, and related records.
3. How We Use Personal Data
- To create, verify, administer, and secure user accounts.
- To perform KYC verification, AML/CFT/CPF screening, sanctions checks, fraud monitoring, risk assessment, and compliance reviews.
- To process orders, payments, purchases, sales, transfers, storage instructions, redemption requests, deliveries, refunds, withdrawals, and customer transactions.
- To support custody, storage, audit, reconciliation, and operational processes related to gold, silver, and other services made available through the Services.
- To provide customer support, handle complaints, respond to inquiries, and send service-related notices.
- To protect SIMODI GOLD, users, the Services, and third parties from fraud, abuse, unauthorised access, cyber threats, errors, and unlawful activity.
- To comply with applicable laws, DMCC and UAE regulatory requirements, court orders, tax obligations, audit requirements, and lawful requests from authorities.
- To maintain records of transactions, instructions and account activity, resolve disputes, establish or defend legal claims, and protect the legal rights of SIMODI GOLD, users and third parties.
- To improve the App, Website and Services, develop services, troubleshoot issues, analyse usage, and maintain platform performance.
- To send marketing or promotional communications where permitted by law and where the user has not opted out.
4. Legal Bases for Processing
Under the UAE PDPL, SIMODI GOLD must have a valid legal basis for each processing activity. Depending on the activity, we rely on one or more of the following:
- Consent: where the user has given specific, informed consent, for example for certain marketing communications or the processing of biometric-linked verification outputs. Consent may be withdrawn at any time as described in Section 9.
- Performance of a contract: where processing is necessary to open and operate the user's account, execute transactions, and provide the Services requested.
- Compliance with a legal obligation: where processing is necessary to meet KYC, AML/CFT/CPF, sanctions, tax, accounting, audit, or other regulatory requirements applicable to SIMODI GOLD as a DMCC-registered DPMS/DNFBP.
- Public interest, protection of rights, and legal claims: where processing is necessary to protect the public interest, protect the interests of the user or, where applicable, the rights of third parties, or establish, exercise, or defend legal claims, including in connection with judicial or security procedures.
Where SIMODI GOLD processes sensitive personal data within the meaning of the UAE PDPL (for example, biometric-linked verification outputs), it does so on the basis of explicit consent or another applicable legal basis, and maintains records of its personal data processing activities as required by applicable law, which will be made available to the UAE Data Office where required.
5. Sharing of Personal Data
SIMODI GOLD may share personal data where necessary and lawful with:
- Regulators, courts, law enforcement authorities, government bodies (including DMCC and UAE tax and AML authorities), and other competent authorities.
- Banks, payment providers, card schemes, settlement providers, and financial service providers.
- KYC vendors, AML vendors, sanctions-screening providers, fraud prevention providers, identity verification providers, and compliance service providers.
- Vault providers, logistics providers, delivery providers, insurers, auditors, legal advisers, tax advisers, compliance advisers, and professional consultants.
- Cloud hosting providers, technology vendors, cybersecurity vendors, analytics providers, customer support tools, affiliates, and other operational service providers.
Third-party service providers that process personal data on SIMODI GOLD's behalf are contractually required to use it only in accordance with our documented instructions, and to apply appropriate confidentiality, security, and data protection measures. SIMODI GOLD does not sell personal data.
6. International Data Transfers
Personal data may be transferred outside the United Arab Emirates where necessary for cloud hosting, payment processing, compliance screening, customer support, audit, logistics, legal, regulatory, or operational purposes. Such transfers take place only where permitted under the UAE PDPL, namely, where the receiving country ensures an adequate level of protection recognised under the UAE PDPL, where appropriate contractual safeguards are in place reflecting UAE PDPL requirements, or where a limited exception applies (including explicit consent or necessity for performance of a contract with the user or the establishment, exercise, or defence of legal claims). SIMODI GOLD will take appropriate steps to ensure that any cross-border transfer is carried out in accordance with the UAE PDPL.
7. Data Retention
SIMODI GOLD retains personal data only for as long as necessary to fulfil the purposes described in this Policy, unless a longer period is required or permitted by applicable law, including AML/CFT record-keeping obligations, tax and accounting requirements, statutory audit, and dispute resolution. When determining retention periods, SIMODI GOLD considers the amount, nature, and sensitivity of the data, the risk of harm from unauthorised access or disclosure, and applicable legal and regulatory requirements. Where data is no longer required, SIMODI GOLD will securely delete, anonymise, or archive it in accordance with applicable law and internal retention procedures.
8. Data Security
SIMODI GOLD implements technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure, including encryption in transit and at rest, role-based access controls, multi-factor authentication, monitoring, and periodic security review. No electronic transmission or storage method is completely secure, and use of the Services is at the user's own risk in this respect. In the event of a personal data breach, SIMODI GOLD will notify the UAE Data Office where required and within the applicable period, and will notify affected individuals where the breach would prejudice the privacy, confidentiality or security of their personal data, in each case in accordance with the UAE PDPL.
9. Your Privacy Rights
Subject to applicable law, users may have the right to:
- request access to, and a copy of, the personal data SIMODI GOLD holds about them;
- request correction of inaccurate or incomplete personal data;
- request deletion or restriction of processing, where legally permitted;
- object to certain types of processing, including processing for direct marketing purposes and related profiling, where applicable;
- receive their personal data in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted to another controller (data portability);
- object to a decision resulting from automated processing, including profiling, that produces legal effects or similarly significantly affects them; and
- withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
These rights may be limited where retention or processing is required for legal, regulatory, AML/CFT, sanctions, fraud-prevention, tax, audit, or dispute-resolution purposes. Requests can be made to info@simodigold.com; SIMODI GOLD will respond within the period prescribed by the UAE PDPL and may ask the user to verify their identity before acting on a request.
10. Do We Collect Information From Minors?
SIMODI GOLD does not knowingly collect, solicit data from, or market to persons under 18 years of age, and the Services are not intended for such persons. By using the Services, the user represents that they are at least 18 years old. If SIMODI GOLD learns that personal data from a person under 18 has been collected, it will deactivate the associated account and take reasonable steps to delete such data, subject to any legal or compliance retention requirements.
11. Marketing Communications
SIMODI GOLD may send marketing communications where permitted by law. Users may opt out at any time using the unsubscribe method provided in the communication or by contacting SIMODI GOLD. Service, security, compliance, and transaction-related messages may continue even where a user has opted out of marketing.
12. Lodging a Complaint with the Supervisory Authority
If a user believes SIMODI GOLD's processing of their personal data infringes the UAE PDPL, the user has the right to lodge a complaint with the UAE Data Office, the competent supervisory authority established under Federal Decree-Law No. 44 of 2021. SIMODI GOLD encourages users to raise concerns with it first at info@simodigold.com so that it has the opportunity to address them.
13. Updates to This Policy
SIMODI GOLD may update this Privacy Policy to remain compliant with applicable law, reflect operational changes, or update disclosures relating to features or third-party providers. The updated version will show a revised Version number and Effective Date. Where a material change is made, SIMODI GOLD will provide notice within the App, on the Website, or by direct communication where legally required or appropriate.
14. Contact Us
For privacy, personal data, or compliance-related queries, please contact:
SIMODI GOLD FZCO
1902, The Dome Tower, Cluster N, JLT
Dubai, United Arab Emirates
Support Email: info@simodigold.com
Website: Simodigold.com