1Introduction & Scope
The UAE Gold Infrastructure Network ("UGIN", "we", "us", or "our") is a sovereign-grade financial infrastructure platform operated under the regulatory oversight of the Central Bank of the UAE (CBUAE) and the UAE Financial Intelligence Unit (FIU). This Privacy Policy governs the collection, processing, storage, and transfer of personal data by UGIN in connection with your use of the platform accessible at ugin.ae and all associated subdomains.
This policy is issued pursuant to and in compliance with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL), the AML Law No. 20 of 2019, CBUAE regulations on data governance, and applicable DIFC data protection rules.
This policy applies to all UGIN participants including traders, refineries, vaults, banks, insurers, logistics providers, auditors, investors, government entities, and international corridor partners.
2Information We Collect
Identity & KYC Data: Full legal name, Emirates ID / passport, trade licence, beneficial ownership declarations, politically exposed person (PEP) status, sanctions screening data.
Gold Asset Data: UGIN asset IDs, purity fineness, weight, origin country, serial numbers, refinery certificates, assay reports, chain-of-custody records.
Transaction Data: Settlement amounts, DvP records, corridor transactions, FX rates used, financing terms, insurance policies, billing invoices.
Technical Data: IP addresses, browser fingerprints, API key usage logs, session tokens, login timestamps, device identifiers.
Communication Data: Contact form submissions, support tickets, compliance communications, SAR-related correspondence.
- All document uploads are encrypted at rest using AES-256-GCM
- Biometric data is not collected by UGIN directly
- Children under 18 are not eligible to use this platform
3How We Use Your Information
Platform Operation: Processing gold registrations, verifications, certifications, settlements, financing, insurance, and custody operations as core platform functions.
AML/CFT Compliance: Sanctions screening against OFAC SDN, UN Security Council, UAE Executive Office, and FATF grey/black lists. Real-time transaction monitoring, suspicious activity detection using Atavus Air-Gapped AI anomaly detection, and SAR generation.
Regulatory Reporting: Mandatory reporting to UAE FIU under AML Law No. 20 of 2019, CBUAE prudential reporting, customs integration for import/export declarations, and government analytics dashboards.
Billing & Revenue: Fee calculation, invoice generation, VAT compliance at 5%, revenue sharing with government pursuant to corridor agreements.
Security & Fraud Prevention: Network graph analysis to detect suspicious transaction patterns, risk scoring, and AI-powered anomaly detection.
4Legal Basis for Processing
All data processing by UGIN is grounded in one or more lawful bases under UAE law.
- Legal Obligation: AML Law No. 20 of 2019; CBUAE Circular No. 2/BS/2020; Federal Decree-Law No. 20 of 2018 on AML/CFT; UAE Cabinet Decision No. 10 of 2019
- Contractual Necessity: Processing required to perform the Participant Agreement and deliver platform services
- Legitimate Interests: Fraud prevention, network security, platform integrity, financial crime detection
- Consent: Marketing communications (withdrawable at any time), optional analytics participation
- Public Interest: National gold registry operations mandated by UAE regulatory framework
Legal framework references: UAE PDPL — Fed. Decree-Law 45/2021AML Law 20/2019CBUAE RegulationsDIFC DPL 2020
5Data Sharing & Disclosure
UGIN does not sell personal data. Data is shared only as required:
- UAE Financial Intelligence Unit (FIU): Suspicious Activity Reports (SARs), threshold transaction reports as legally mandated
- Central Bank of the UAE (CBUAE): Prudential returns, AML/CFT supervision, regulatory examinations
- UAE Customs Authority: Import/export declarations, clearance status updates via bi-directional API integration
- International Corridor Partners: Certificate recognition data shared with partner jurisdiction regulators (India IOSCO, Switzerland FINMA, Singapore MAS, GCC framework) under bilateral data sharing agreements with Standard Contractual Clauses
- Law Enforcement: Pursuant to valid legal process, court order, or mutual legal assistance treaty (MLAT)
- Auditors & Assessors: Third-party auditors under strict confidentiality agreements for platform integrity assessments
6International Data Transfers
UGIN's primary infrastructure is hosted within the UAE. Cross-border data transfers to corridor partner systems are governed by:
- Standard Contractual Clauses (SCCs) approved by the UAE TDRA for transfers to non-adequate jurisdictions
- Bilateral Data Sharing Agreements with UAE-IND (India), UAE-CHE (Switzerland), UAE-SGP (Singapore), UAE-GCC (Saudi Arabia), UAE-ZAF (South Africa), UAE-JPN (Japan), UAE-HKG (Hong Kong), UAE-AUS (Australia), UAE-BRA (Brazil), UAE-TUR (Turkey), UAE-MEX (Mexico) corridors
- Adequacy Decisions: Switzerland and Singapore are treated as adequate jurisdictions
All AI processing (anomaly detection, SAR drafting) is performed on-premise using Atavus Air-Gapped AI infrastructure — no data leaves UAE jurisdiction for AI computation.
7Data Retention
- Financial transaction records: 7 years (UAE Federal Law No. 1 of 2004 — Commercial Transactions Law)
- KYC/KYB documents: 5 years post-relationship termination (AML Law requirement)
- SAR and compliance case files: 10 years (FIU retention requirement)
- Certificate chain-of-custody: Indefinite (immutable audit trail, append-only)
- Technical logs: 2 years
- Marketing preferences: Until consent withdrawn + 1 year
Deletion requests are honoured subject to overriding legal retention obligations. Where deletion is legally prevented, data is restricted from processing for commercial purposes.
8Your Rights
Under the UAE PDPL (Federal Decree-Law No. 45 of 2021), you have the right to:
- Access: Request a copy of your personal data held by UGIN (response within 30 days)
- Correction: Request correction of inaccurate or incomplete data
- Restriction: Request restriction of processing in specified circumstances
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Deletion: Request erasure subject to legal retention obligations
- Withdraw Consent: Withdraw marketing or optional processing consent at any time
To exercise your rights: dpo@ugin.ae | Response guaranteed within 30 calendar days.
Complaints may be submitted to the UAE Telecommunications and Digital Government Regulatory Authority (TDRA) at tdra.gov.ae.
9Security Measures
- Encryption at Rest: AES-256-GCM for all stored documents and sensitive data fields
- Encryption in Transit: TLS 1.3 minimum for all API communications; certificate pinning on mobile clients
- Air-Gapped AI: All machine learning inference (Atavus Air-Gapped AI) runs on dedicated on-premise hardware with no internet connectivity — financial data never leaves UAE jurisdiction
- Access Controls: Role-Based Access Control (RBAC) with 9 permission levels (L0–L9); principle of least privilege enforced
- Penetration Testing: Annual third-party penetration tests; quarterly vulnerability assessments
- Incident Response: 72-hour breach notification to TDRA and affected participants as required by UAE PDPL
- ISO 27001: Certification roadmap in progress; controls implemented to ISO 27001:2022 standard
- Immutable Audit Logs: All data access events are written to an append-only, cryptographically-chained audit log
10Contact & Data Protection Officer
For all privacy-related queries, data subject rights requests, or to report a data incident:
📧 Data Protection Officer
dpo@ugin.ae
📍 Address
Gate District, Level 15
Dubai International Financial Centre
Dubai, UAE
We will acknowledge your request within 5 business days and provide a substantive response within 30 calendar days, extendable by a further 30 days for complex requests with notice.