PRIVACY POLICY

1. Introduction and Scope

This Privacy Policy explains how Mal Digital Ltd (“Mal”), an entity incorporated in the Abu Dhabi Global Market (“ADGM”), collects, uses, processes, discloses, and protects your Personal Data (as defined below) when you use our mobile application (the “Platform”), and related services (the “Services”).

Mal is committed to processing your Personal Data in compliance with the ADGM Data Protection Regulations 2021 (“DPR 2021”) and the applicable data protection laws of the United Arab Emirates.

By accessing or using the Services, you acknowledge that you have read, understood, and agreed to the terms of this Privacy Policy.

2. The Data Mal Collects

Mal collects various categories of Personal Data necessary to provide the Services, comply with regulatory obligations (such as Know Your Customer (KYC) and Anti-Money Laundering (AML) requirements), and manage our business operations.

“Personal Data” means any information relating to an identified or identifiable natural person, which may include certain “Sensitive Personal Data” such as biometric data (if used for login/authentication) and potentially data revealing criminal convictions (for screening/AML compliance).

The data Mal may collect includes:

Category of Personal Data

Examples of Data Collected

Identity and Contact Data

Full name, date of birth, nationality, gender, Emirates ID details, passport details, address, email address, phone number.

Financial and Transactional Data

Bank account details, payment card information, transaction history, credit card numbers and information, credit score reports, sources of wealth/funds.

Technical and Usage Data

IP address, device type, operating system, app usage statistics, log-in data, cookies, and other tracking technologies.

Verification and Compliance Data

Photographs (for identity verification/KYC), biometric data (if used for login/security), video recordings (if part of onboarding/KYC), occupation, employer name. Biometric data such as face scans or fingerprints.

Marketing and Communications Data

Your preferences in receiving marketing from us and your communication preferences.

Customer Support Data

Information you provide when contacting our support team (e.g., in a request, email, or chat).

3. How Mal Collects Your Personal Data

Mal collects data from the following sources:

  • Directly from you: When you register for an account, complete KYC procedures, use the Platform, input transaction details, communicate with us, or respond to our surveys.

  • From third parties: This includes:

    • Financial Institutions/Payment Processors: To facilitate transactions.

    • Identity and Verification Providers: To comply with AML/KYC obligations.

    • Credit Reference Agencies: To perform necessary credit checks.

    • Publicly Available Sources: To verify information.

4. Purposes and Lawful Bases for Processing

Mal will only process your Personal Data when Mal has a legal basis to do so under the ADGM DPR 2021 and applicable UAE law. Our purposes and corresponding lawful bases are:

Purpose of Processing

Lawful Basis (ADGM DPR 2021)

To provide and manage the Services (Account setup, transactions, customer support).

Performance of a contract with you or taking steps at your request to enter into such a contract.

To meet our legal and regulatory obligations (KYC, AML, sanctions screening, financial crime prevention).

Compliance with a legal obligation to which Mal is subject.

To improve the App and user experience (Analytics, troubleshooting, security monitoring).

Legitimate interests (to keep our Services running efficiently and securely).

To send you marketing communications about the Services, where permitted.

Consent (if required) or Legitimate interests (for existing customers and soft opt-in).

To ensure the security of our systems (Fraud prevention, system protection).

Legitimate interests (to protect our business and customers from harm).

Where Mal relies on consent as the legal basis, you have the right to withdraw your consent at any time, but this will not affect the lawfulness of processing carried out before you withdraw your consent.

5. Disclosure and Sharing of Personal Data

Mal may share your Personal Data with the following parties:

  • Group Companies: Other entities within our corporate group, provided they comply with adequate data protection standards.

  • Regulators and Authorities: The ADGM Registration Authority, the ADGM Office of Data Protection (“ODP”), law enforcement, and other governmental or regulatory bodies as required by law or judicial process.

  • Service Providers: Third parties that provide services to us, such as cloud hosting, IT infrastructure, payment processing, KYC/AML verification, and professional services (e.g., lawyers, auditors). Mal ensures these processors are bound by contractual data protection obligations.

  • Third Parties: Banks and other partners involved in providing the services or products Mal offers on the Platform or processing payments in connection therewith, where processing of Personal Data is required by law or required in order to provide the services that you have requested through the Platform.

6. International Data Transfers

As an ADGM company, Mal may transfer your Personal Data outside of the ADGM or the UAE. Mal will only do so in compliance with Chapter 5 of the ADGM DPR 2021 and other applicable laws. Mal will ensure that such transfers are subject to appropriate safeguards, such as:

  • Transferring to a jurisdiction deemed “adequate” by the ADGM Commissioner of Data Protection.

  • Implementing Standard Contractual Clauses approved by the ADGM ODP.

  • Relying on a specific derogation (e.g., the transfer is necessary for the performance of a contract with you or with your explicit consent).

7. Data Security and Retention

  • Security: Mal has implemented appropriate technical and organisational security measures, including encryption, access controls, and regular audits, to prevent your Personal Data from being accidentally lost, used, or accessed in an unauthorized way.

  • Retention: Mal will retain your Personal Data only for as long as necessary to fulfil the purposes for which Mal collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements (e.g., regulatory requirements often mandate a minimum retention period for financial data and KYC records).

8. Your Data Protection Rights

Under the ADGM DPR 2021, you have the following rights regarding your Personal Data:

  1. Right to be Informed: The right to be provided with clear, transparent, and easily understandable information about how Mal uses your data (which this Privacy Policy does).

  2. Right of Access: The right to obtain a copy of the Personal Data Mal holds about you.

  3. Right to Rectification: The right to have inaccurate Personal Data corrected.

  4. Right to Erasure: The right to request the deletion or removal of your Personal Data in certain circumstances.

  5. Right to Restriction of Processing: The right to block or suppress further use of your Personal Data in certain circumstances.

  6. Right to Data Portability: The right to receive your Personal Data in a structured, commonly used, and machine-readable format.

  7. Right to Object to Processing: The right to object to processing where it is based on our legitimate interests or for direct marketing purposes.

  8. Rights in Relation to Automated Decision Making and Profiling: The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

You can exercise these rights by contacting us using the details in Section 10. Mal may need to verify your identity before responding to your request.

9. Changes to this Policy

Mal may update this Privacy Policy from time to time. Any changes will be posted on this page and, where appropriate, notified to you through the Platform or by email. The updated Policy will be effective as of the date of publication.

10. Contact Information and Complaints

If you have any questions about this Privacy Policy, wish to exercise any of your rights, or wish to make a complaint, please contact us at contact@mal.ai

Email for Privacy Matters: privacy@mal.ai

Supervisory Authority: ADGM

You also have the right to lodge a complaint with the ADGM Commissioner of Data Protection (ODP) if you believe your rights under the DPR 2021 have been infringed.


Contact Details for ADGM ODP: Email: data.protection@adgm.com | Telephone: +971 23338888

Get in touch

Mal HQ

21st floor, Sky Tower

Al Reem Island

Abu Dhabi, UAE

contact@mal.ai

contact@mal.ai

contact@mal.ai

Copyright © 2025. All rights reserved