NEOM · Document 02

Privacy Policy

How Neom Triple A Information Technology LLC (NEOM Funded) collects, uses, stores, discloses, and protects personal data under the GDPR, UK GDPR, UAE PDPL, CCPA/CPRA, and PIPEDA. Covers data categories (including biometric KYC data), legal bases, recipients and international transfers, cookies and Google Consent Mode, retention, security, automated decision-making, and your privacy rights.

Aligned with the T&C v5.0 | Publication Date: 26 August 2026

This Privacy Policy (the "Policy") constitutes the authoritative English-language canonical version. In the event of any discrepancy between language versions, this English version prevails following its publication.

This Policy governs the collection, use, storage, disclosure, and protection of personal data in connection with the activities of Neom Triple A Information Technology LLC, operating under the brand NEOM Funded.

§1 Controller Identification and Contact Information

1.1 Data Controller. The data controller within the meaning of Regulation (EU) 2016/679 (GDPR), the UK GDPR as retained and amended under the Data Protection Act 2018, UAE Federal Decree by Law No. (45) of 2021 Concerning the Protection of Personal Data (the 'UAE PDPL'; commonly cited as 'UAE Federal Decree-Law No. 45 of 2021'), and other applicable data-protection legislation is:

Full legal name: Neom Triple A Information Technology LLC
Brand: NEOM Funded
Registered address: The Binary by Omniyat, Office 2114, Business Bay, Dubai, UAE
Website: neomfunded.com

1.2 Controller Contact Details. For all matters relating to this Policy and the processing of personal data in connection with the Services, Participants may contact the Company through the following dedicated channels:

  • Privacy enquiries, data-protection matters and exercise of data-subject rights (Privacy Contact; outsourced DPO engagement in progress — see §16.3): privacy@neomfunded.com
  • General enquiries and support: support@neomfunded.com

The Company aims to acknowledge all privacy-related communications promptly and will respond substantively within the timeframes prescribed by applicable law, as further detailed in §11 of this Policy.

1.3 Relationship to T&C. This Policy is a standalone document giving effect to the data-protection obligations set out in Chapter 26 of the Company's Terms and Conditions (the T&C, §§26.0–26.15). It must be read alongside the T&C. Where any conflict exists between this Policy and Chapter 26 of the T&C, the provisions of Chapter 26 of the T&C shall prevail. Details of the EU and UK Representatives and of the EU Data Act Representative are set out in §16 of this Policy, in accordance with §26.15 of the T&C. This Policy applies to all Participants who access or use the Services provided by NEOM Funded, regardless of the jurisdiction from which they access those Services.

§2 Regulatory Framework

2.1 Applicable Legal Frameworks. The processing of personal data by Neom Triple A Information Technology LLC is carried out in accordance with the following legislation, and the Company has implemented technical and organisational measures to support compliance with each applicable framework:

(a) Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR) — in respect of data subjects located in the EU/EEA. The GDPR establishes a comprehensive framework for the processing of personal data, including requirements regarding lawful bases for processing, data-subject rights, data transfers, breach notification, and accountability;

(b) UK GDPR (Regulation (EU) 2016/679 as retained and amended under the Data Protection Act 2018) — in respect of data subjects located in the United Kingdom. The UK GDPR substantially mirrors the EU GDPR in its requirements and is enforced by the Information Commissioner's Office (ICO);

(c) UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the 'UAE PDPL') and its Executive Regulations. As at the Publication Date of this Policy, the Executive Regulations to the UAE PDPL contemplated by Article 47 of the PDPL have not yet been issued by the UAE Cabinet. References in this Policy and in §6.6 of the T&C to the UAE PDPL and to "implementing regulations issued by the UAE Data Office" shall be construed accordingly. The Company will update its data-protection practices and this Policy in line with those Executive Regulations within the implementation period prescribed therein upon their issuance, and will publish a corresponding update to this Policy;

(d) The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act 2020 (CCPA/CPRA) — in respect of California residents. Additional rights specific to California residents are set out in §13 of this Policy;

(e) The Canadian Personal Information Protection and Electronic Documents Act (PIPEDA) — in respect of Canadian residents. Additional provisions applicable to Canadian residents are set out in §15 of this Policy.

2.2 Non-Derogation Principle. Nothing in this Policy operates to reduce any right of a data subject under any of the foregoing frameworks that is presently in force as at the Publication Date. Where any provision of this Policy is capable of more than one interpretation, it shall be interpreted in a manner that best gives effect to the applicable legal framework.

2.3 Territorial Scope. This Policy applies to the processing of personal data of individuals located in any jurisdiction from which they access the Services, regardless of the Company's place of incorporation, to the extent that the applicable law of that jurisdiction exercises extraterritorial effect.

§3 Categories of Personal Data We Collect

3.1 Categories Collected. We collect the following categories of personal data:

(a) Identity data: full name, date of birth, nationality, country of residence, government-issued identification documents (passport, national ID, driver's licence) — collected for KYC/AML compliance under §6.4 of the T&C;

(b) Contact data: email address, phone number, postal address, billing address;

(c) Account data: username, password (stored hashed and salted), account preferences, communication preferences, account status;

(d) Payment data: payment-instrument details (handled by third-party PSPs — see §6 of this Policy), billing history, transaction logs;

(e) Behavioural data: trading activity logs, dashboard interactions, IP address, device and browser characteristics, time-zone, log-in patterns;

(f) Compliance data: sanctions-screening results, source-of-funds declarations where required by law, fraud-prevention scoring, AML risk assessment;

(g) Communications data: support tickets, chat transcripts, email correspondence with the Company.

(h) Biometric data: biometric templates and features extracted from a live facial image (selfie or short video) and compared against the facial image on the identity document, generated during the KYC/AML customer due diligence procedure through the Sumsub identity-verification platform, for the purpose of uniquely identifying the Participant and preventing identity fraud, document forgery, and third-party impersonation.

3.2 Participant Responsibility. Where personal data is provided by the Participant, the Participant is responsible for ensuring the information is truthful, complete, and up to date, and shall promptly notify the Company of any changes. The provision of false, inaccurate, or misleading personal data may result in suspension or termination of the Participant's account in accordance with the T&C.

3.3 Special Category Data. The only category of special category personal data within the meaning of Article 9(1) GDPR processed by the Company is biometric data for the purpose of uniquely identifying a natural person, as described in §3.1(h) of this Policy. This processing arises exclusively during KYC/AML customer due diligence and consists of the extraction of a biometric template from a live facial image, and its comparison against a biometric template derived from the identity document, through the Sumsub platform (recipient category (ii) — see §6 of this Policy). Such processing constitutes "specific technical processing... allowing the unique identification of a natural person" within the meaning of Article 4(14) GDPR. The legal basis for this processing is set out in Purpose 2 of §5.1 of this Policy. The Company does not process any other category of special category personal data (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, health data, or data concerning sex life or sexual orientation). Where any such other special category data is provided by a Participant without solicitation, the Company will take reasonable steps to delete or quarantine such data promptly.

3.4 Data Minimisation. The Company adheres to the principle of data minimisation: only the personal data that is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed is collected and retained.

§4 Information Automatically Collected

4.1 Automatically Collected Data. During your visit, usage, or navigation of the Services, certain information is automatically collected by us. This information, while not revealing your specific identity (e.g. name or contact details), may include device and usage data such as IP address, browser and device specifications, operating system, language preferences, source URLs, device name, country, approximate location, usage information of our Services, and other technical details. This information is mainly utilised for ensuring the security and functioning of our Services, as well as for internal analysis and reporting purposes. Similar to other businesses, we also gather information through the use of cookies and similar technologies (see §7 of this Policy for further detail).

4.2 Log and Usage Data. Our servers automatically gather log and usage data when you access or utilise our Services. This data is stored in log files and may include details such as your IP address, device information, browser type and settings, and information about your activities within the Services (such as timestamps of usage, pages/files viewed, searches performed, and other actions such as feature usage), and device event information (such as system activity, error reports, and hardware configurations), depending on your interaction with us.

4.3 Purposes of Processing Automatically Collected Data. The data described in §4.1 and §4.2 is processed for the purposes of security monitoring, performance management, detection of anomalous trading activity and potential fraudulent behaviour, and fulfilment of legal obligations. The applicable legal bases are set out in §5 of this Policy. In particular, behavioural and log data may be used to identify patterns consistent with prohibited trading practices as defined in the T&C, including in connection with the Post-Crystallisation Compliance Review (§16.2 of the T&C).

4.4 No Sale of Automatically Collected Data. Automatically collected data is used solely for the operational, security, and analytical purposes described in this §4. The Company does not sell or transfer such data for purposes inconsistent with those set out in this Policy.

§5 Purposes of Processing and Legal Bases

5.1 The Company processes personal data on the following legal bases under Article 6(1) of the GDPR (and equivalent provisions under the UK GDPR and UAE PDPL), each tied to a specific purpose:

PURPOSE 1 — Account creation, authentication, and contract performance. Basis: Article 6(1)(b) GDPR (performance of contract). Processing is necessary to register the Participant, verify account credentials, provide access to the Services, and fulfil the Company's obligations under the Terms and Conditions. Without this processing, the Company cannot provide the Services.

PURPOSE 2 — KYC, AML, and sanctions compliance. Basis for non-special-category data:

(i) Article 6(1)(f) GDPR (legitimate interest in the prevention of fraud and money laundering, in compliance with anti-money-laundering and counter-terrorist-financing standards across the Company's operational jurisdictions, and in safeguarding the integrity of the Services and the Company's counterparties) — as the general basis applicable to KYC, AML, and sanctions-screening processing carried out by the Company as a UAE-incorporated entity; and

(ii) Article 6(1)(c) GDPR (legal obligation) — to the extent applicable EU, EU Member-State, or UK law imposes AML/CTF obligations directly on the Company, including, where applicable to EU-resident Participants, Regulation (EU) 2024/1624 (the "EU AMLR") and its implementing Regulatory Technical Standards (including customer due diligence, sanctions screening, and enhanced due diligence) and national anti-money-laundering laws transposing Directive (EU) 2018/843 (AMLD5); and, where applicable to UK-resident Participants, the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (SI 2017/692).

Processing carried out pursuant to obligations imposed on the Company under the law of the United Arab Emirates — including UAE Federal Decree-Law No. 10 of 2025 on anti-money laundering and counter-terrorism financing (superseding UAE Federal Decree-Law No. 20 of 2018), or any successor legislation, and the FATF Recommendations (in particular Recommendations 10, 12, and 19) as implemented in the UAE — is grounded in Article 6(1)(f) GDPR under limb (i) above, since Article 6(1)(c) GDPR requires an obligation under EU or EU Member-State law and does not extend to third-country legal obligations (see EDPB Guidelines 05/2020 on consent under Regulation 2016/679, paras 45–46, consistent with Article 29 Working Party WP259 rev.01).

Additional basis for the processing of biometric data described in §3.1(h) and §3.3 of this Policy: Article 9(2)(g) GDPR (substantial public interest in the prevention of money laundering and the financing of terrorism), on the basis of the Union, Member State, and international-standard legal instruments referenced in limb (ii) of the preceding paragraph, together with Article 6(1)(f) GDPR in respect of UAE-law obligations as explained in the preceding paragraph, and, to the extent applicable, Article 5(1)(c) of UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.

Processing includes identity-document verification, biometric liveness verification and face-match, sanctions-list screening, and AML risk assessment, carried out in part through KYC/AML provider Sumsub (recipient category (ii) — see §6 of this Policy). Failure to provide the necessary personal data for KYC/AML purposes will prevent the Company from onboarding the Participant.

PURPOSE 3 — Fraud prevention, platform integrity, and prohibited-trading detection. Basis: Article 6(1)(f) GDPR (legitimate interests of the Company in protecting platform integrity and the legitimate interests of other Participants and third parties), balanced against the rights and freedoms of the Participant. Processing includes monitoring of trading activity by automated systems and the conduct of the Post-Crystallisation Compliance Review (§16.2 of the T&C). The Participant's rights in relation to automated decisions are set out in §11.2(h) of this Policy.

PURPOSE 4 — Marketing communications. Basis: Article 6(1)(a) GDPR (consent obtained in accordance with §6.3(b) of the T&C). Consent may be withdrawn at any time; withdrawal does not affect the lawfulness of processing carried out prior to withdrawal. Participants who withdraw marketing consent will continue to receive transactional and service-related communications where necessary for the performance of the contract.

PURPOSE 5 — Cookies, analytics, and platform optimisation. Basis: Article 6(1)(a) GDPR (consent collected via cookie banner, where non-essential), in conjunction with the ePrivacy Directive 2002/58/EC. Strictly necessary cookies do not require consent. See §7 of this Policy for further detail on cookie categories and withdrawal of consent.

PURPOSE 6 — Legal claims, regulatory cooperation, and compliance with court orders. Basis: Article 6(1)(c) GDPR (legal obligation) and Article 6(1)(f) GDPR (legitimate interest in establishing, exercising, or defending legal claims). This includes cooperation with regulators, supervisory authorities, courts, and law-enforcement agencies where required by law, and compliance with judicial or administrative orders.

PURPOSE 7 — Customer support and dispute resolution. Basis: Article 6(1)(b) GDPR (performance of contract) and Article 6(1)(f) GDPR (legitimate interests in resolving disputes efficiently). Support interactions and correspondence are retained in accordance with the retention periods set out in §8 of this Policy.

5.2 Legitimate Interests Assessment. Where the Company relies on Article 6(1)(f) GDPR as a legal basis, the Company has carried out a Legitimate Interests Assessment (LIA) for each relevant processing activity. That assessment includes an evaluation of the necessity and proportionality of the processing and a balancing test against the interests, rights, and freedoms of the data subject. Documentation of the LIA is available on request at privacy@neomfunded.com.

5.3 Canadian Residents (PIPEDA). For Canadian residents, this §5 is supplemented by PIPEDA. The Company processes personal data of Canadian residents only with their express or implied consent, except where the law permits processing without consent (fraud investigation, legal compliance, etc.). See §15 of this Policy for further detail.

§6 Recipients and International Transfers

6.1 Categories of Recipients. The Company shares personal data with the following categories of recipients. Each recipient is bound by appropriate confidentiality and data-protection obligations through written contracts, including data-processing agreements where required by applicable law:

(i) Payment service providers (PSPs), including Vexapayments Technology Services FZCO (marketed under the product name Paymaxis) — for transaction processing, chargeback handling, and refunds;

(ii) KYC/AML and identity-verification service providers, including Sumsub — for conducting the customer identification procedure in accordance with §6.4 of the T&C;

(iii) Cloud infrastructure and content-delivery network (CDN) providers, including webfont-delivery CDNs (BunnyWay d.o.o. / Bunny Fonts) — for hosting the Services, ensuring their availability and performance, and serving web fonts to the Website;

(iv) Customer-support and helpdesk platforms, including Intercom R&D Unlimited Company — for managing and resolving Participant enquiries and support tickets;

(v) CRM, email-delivery, and marketing-automation providers — for managing communications and delivering marketing messages to Participants who have given their consent;

(v-bis) Digital-advertising and retargeting providers, including Meta Platforms Ireland Ltd and Meta Platforms, Inc. (Meta Pixel / Meta Advertising) and Google LLC (Google Ads) — for delivering targeted advertising, retargeting, and conversion measurement across third-party platforms, subject to prior consent to the Advertising cookie category (see Cookie Policy §4.4);

(vi) Analytics, observability, and platform-optimisation providers, including Ahrefs Pte. Ltd. — for monitoring platform performance, detecting anomalies, and improving the Services;

(vii) Trading-platform and market-data vendors (MetaQuotes / MetaTrader 5; TradeLocker; TradingView, Inc. charting widgets) — for operating the MT5 trading environment made available to Participants and providing embedded charting widgets and market-analysis tools on the Website;

(viii) Professional advisers (legal, accounting, audit, tax) — for obtaining professional advice and ensuring regulatory compliance;

(ix) Regulators, supervisory authorities, courts, and law-enforcement agencies where required by law — including in connection with legally mandated disclosures, court orders, or regulatory investigations;

(x) Successor entities in connection with a merger, acquisition, or sale of all or substantially all of the Company's assets — where personal data forms part of the assets transferred, subject to appropriate safeguards.

Participants may request a list of the specific service providers in each category at the time of the request by writing to privacy@neomfunded.com.

6.2 International Transfers of Personal Data. Cross-border transfers of personal data take place to the following identified recipients:

(i) MetaQuotes Ltd. (Cyprus) — for MT5 platform operation;

(ii) TradeLocker / Quadcode Solutions OÜ — relevant servers in Australia and EU — for TradeLocker platform operation;

(iii) Group entities and service providers located in the United Arab Emirates;

(iv) Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) — Google Analytics (measurement ID G-EZC1YFN5FP), Google Ads (conversion tracking ID AW-18330614498), and Google Tag Manager (container GTM-P4VFT72P) deployed on the Website. In accordance with the judgment of the Court of Justice of the European Union in Case C-40/17 (Fashion ID), the Company and Google LLC act as joint controllers within the meaning of Article 26 GDPR in respect of the collection of Personal Data via Google Analytics and Google Ads on the Website. Google LLC subsequently acts as an independent controller in respect of its own processing of that data for the operation, improvement, security, and aggregate benchmarking of its services. The essential terms of the joint-controller arrangement are set out in the Google Ads Data Processing Terms — Controller-Controller and in the Google Analytics — Measurement Controller-Controller Data Protection Terms;

(v) Ahrefs Pte. Ltd. (16 Raffles Quay #33-03, Hong Leong Building, Singapore 048581) — Ahrefs Web Analytics service, used to measure aggregated Website traffic and user-behaviour metrics. Ahrefs Pte. Ltd. acts as an independent controller in respect of the data collected via its Web Analytics service, as set out in the Ahrefs Privacy Policy. Transfers of personal data to Singapore are carried out under an appropriate transfer mechanism as described in the Ahrefs Data Processing Addendum;

(vi) Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA) — content-delivery network (CDN), DDoS protection, browser-integrity check, and Real User Monitoring (RUM) services on the Website (including the RUM beacon script loaded from static.cloudflareinsights.com). Cloudflare acts as a processor on behalf of the Company under the Cloudflare Customer Data Processing Addendum, which incorporates the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) for transfers of personal data to the United States.

(vii) Intercom R&D Unlimited Company (2nd Floor, Stephen Court, 18-21 St. Stephen's Green, Dublin 2, D02 PH42, Ireland) — for the purpose of providing in-app messaging, live chat, and help-desk services on the Website. Intercom R&D Unlimited Company acts as a processor on behalf of the Company. Data may be transferred to Intercom, Inc. (55 2nd Street, 4th Floor, San Francisco, CA 94105, USA) under Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2: controller-to-processor) as incorporated in the Intercom Data Processing Agreement.

(viii) TradingView, Inc. (222 Broadway, Floor 19, New York, NY 10038, USA) — for the purpose of providing embedded charting widgets, price data, and market-analysis tools loaded on the Website. TradingView, Inc. acts as an independent controller in respect of the data it collects through its widgets, pixel-tracking scripts, and Snowplow-based analytics. Transfers of personal data from the EEA or the United Kingdom to the United States are governed by TradingView's own privacy notice and any transfer mechanisms it operates as controller, as set out in the TradingView Privacy Policy.

(ix) BunnyWay d.o.o. (Cesta komandanta Staneta 4A, 4470 Jesenice, Slovenia) — for the purpose of serving web fonts to the Website from the fonts.bunny.net content-delivery network (Bunny Fonts). When a Participant's browser requests a font file, BunnyWay d.o.o. receives the Participant's IP address, User-Agent string, and standard HTTP request headers. Bunny Fonts is a cookieless service and does not set any cookies, tracking pixels, or profiling identifiers on the Participant's device. BunnyWay d.o.o. acts as a processor on behalf of the Company under the BunnyWay Data Processing Agreement.

(x-bis) Meta Platforms Ireland Ltd (Merrion Road, Dublin 4, D04 X2K5, Ireland) and Meta Platforms, Inc. (1 Meta Way, Menlo Park, CA 94025, USA) — for the purpose of operating the Meta Pixel (Facebook Pixel) and Meta Advertising services deployed on the Website for retargeting, conversion tracking, measurement of advertising-campaign effectiveness on Facebook and Instagram, and building Look-alike audiences. In accordance with the judgment of the Court of Justice of the European Union in Case C-40/17 (Fashion ID), the Company and Meta Platforms Ireland Ltd act as joint controllers within the meaning of Article 26 GDPR in respect of the collection of Personal Data via the Meta Pixel on the Website. Meta Platforms Ireland Ltd subsequently acts as an independent controller in respect of its own processing of that data for the operation, improvement, and monetisation of its services. The essential terms of the joint-controller arrangement are set out in the Meta Controller Addendum. Transfers of personal data from the EEA or the United Kingdom to Meta Platforms, Inc. in the United States are governed by Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) as incorporated in Meta's data-processing terms, without prejudice to the EU-U.S. Data Privacy Framework where applicable to Meta Platforms, Inc.

(x) Vexapayments Technology Services FZCO (Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, UAE; UAE Free Zone Registration No. 68981) — for the purpose of providing payment processing services on the Website (marketed under the product name Paymaxis). The Company transmits transaction data (amount, currency, order reference, and the Participant's contact and billing information) to Vexapayments Technology Services FZCO per transaction; card details are entered by the Participant directly on Paymaxis' hosted payment page and are never transmitted through the Company's systems. Vexapayments Technology Services FZCO acts as a processor on behalf of the Company under a signed services agreement that incorporates GDPR-aligned data protection commitments. Further details on the technical architecture, data flows, and absence of payment cookies on the Website are set out in the Cookie Policy §8.1(h).

Further details on the cookies, identifiers, and beacons operated by the recipients listed in items (iv), (v), (vi), (vii), (viii), (ix), (x), and (x-bis) — including specific processing purposes, retention periods, and the legal basis for each cookie category — are set out in the Cookie Policy §8.

6.3 Transfer Mechanisms. Each transfer is governed by Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) or applicable adequacy decisions, where required under Articles 44–49 GDPR. As a UAE-incorporated entity, the Company processes EU/EEA/UK personal data partly in the United Arab Emirates, which has not been the subject of an adequacy decision by the European Commission. The Company periodically reviews the legal frameworks applicable to international transfers and updates its transfer mechanisms as required.

6.4 Supplementary Measures. In the absence of an adequacy decision in respect of the UAE, the Company applies the following supplementary technical and organisational measures: encryption at rest (AES-256), encryption in transit (TLS 1.2+), access controls based on the principle of least privilege, audit logging, and contractual restrictions on onward transfer. These measures are designed to ensure that the level of protection of personal data transferred to the UAE is essentially equivalent to that guaranteed within the European Economic Area. The Company commits to completing an independent third-party technical security audit of these measures within ninety (90) calendar days of the Publication Date of this Policy and to publishing an executive summary of the audit findings (with appropriate redactions for security-sensitive details) on its website at neomfunded.com/legal/security-audit upon completion.

Participants may request a copy of the Standard Contractual Clauses and a description of the supplementary measures by writing to privacy@neomfunded.com.

§7 Cookies and Tracking Technologies

7.1 Use of Cookies. The use of cookies and other tracking technologies (e.g. web beacons, pixels, and non-cookie browser storage such as localStorage) may allow access to or storage of information on the Participant's device. This Policy does not constitute an exhaustive treatment of the Company's use of cookies: detailed information on the technologies employed, the duration of each cookie, and the options to decline certain categories of cookie is contained in the separate Cookie Policy (as defined in the T&C §1.5(yy)(ii) and published in the Legal section of the Company's website at neomfunded.com, with a direct link available in the website footer).

7.2 Categories of Cookies. The Company uses four categories of cookies, aligned with the categorisation set out in §4 of the Cookie Policy:

(a) Strictly necessary cookies — required for the functioning of the Services, including authentication, security, session management, and recording of cookie-consent preferences; do not require the Participant's consent (legal basis: Article 5(3) of Directive 2002/58/EC (ePrivacy Directive) as amended by Directive 2009/136/EC, exemption for strictly necessary cookies; and Article 6(1)(f) GDPR — legitimate interest);

(b) Functional cookies — used to remember Participant preferences, settings, and personalisation options (interface language, display settings, trading platform parameters), retaining them between visits; enhance convenience of use but are not strictly necessary. Set only upon receipt of explicit consent;

(c) Analytical cookies — used to analyse how Participants interact with and use the Services (number of visits, traffic sources, most visited pages, time spent on a page, and other behavioural metrics), enabling the Company to improve performance and user experience, including via Google Analytics (with IP-anonymisation feature enabled). Set only upon receipt of explicit consent;

(d) Marketing and advertising cookies — used to track user interactions with advertising materials, to deliver targeted advertising content on the Company's Website and on third-party platforms (retargeting), and to measure advertising-campaign effectiveness, including via Google Ads and Meta Advertising. May qualify as 'sharing' of personal information within the meaning of the CCPA/CPRA (see §4.4 of the Cookie Policy). Set only upon receipt of explicit consent.

7.3 Legal Basis. For non-essential cookies (categories (b), (c), and (d)), the legal basis is Article 6(1)(a) GDPR (the Participant's consent, obtained via cookie banner), in conjunction with the requirements of the ePrivacy Directive 2002/58/EC. Consent may be withdrawn at any time through the cookie-banner settings or in accordance with the instructions in the Cookie Policy.

7.4 Supersession of Prior Statements. All previously published statements indicating that the Company does not use cookies, tracking, or analytics technologies are hereby superseded by this §7 and §26.7 of the T&C. NEOM Funded uses cookie technologies in accordance with this §7.

7.5 Google Consent Mode. The Company deploys Google Consent Mode in its advanced configuration with Google Analytics 4 and Google Ads. This means Google tags load on Website arrival but store nothing on the Participant's device prior to a banner choice; Google LLC receives only cookieless pings during that period. Detailed disclosure of these pings, the ad-click redaction mechanism, and Enhanced Conversions processing after consent is set out in §7.6 of the Cookie Policy.

§8 Retention Periods

8.1 General Principle. The Company retains personal data only as long as necessary for the purposes for which it was collected, except where a longer period is required by law. After the applicable retention period, personal data is either deleted or irreversibly anonymised. Where deletion is not technically feasible (for example, in immutable backup snapshots), the Company securely segregates the data and restricts access until deletion becomes feasible. The Company conducts periodic reviews of the categories of personal data it holds in order to ensure that data is not retained beyond applicable retention periods.

8.2 Specific Retention Periods. The following retention periods apply to each category of personal data:

(a) KYC/AML records (identity documents, sanctions-screening results, source-of-funds declarations): five (5) years after the end of the business relationship with the Participant, as required by UAE Federal Decree-Law No. (10) of 2025 (which repealed and replaced Federal Decree-Law No. 20 of 2018), Cabinet Resolution No. 134 of 2025, and FATF Recommendation 11.

(b) Transaction records and payment data: seven (7) years from the date of the transaction, for tax, audit, and accounting purposes.

(c) Account data and trading activity logs: for the duration of the account plus three (3) years post-closure, for fraud-prevention, dispute-resolution, and legal-claim purposes.

(d) Marketing-consent records: until consent is withdrawn plus three (3) years (to demonstrate the lawfulness of historic processing under GDPR Art. 7(1)).

(e) Cookie payloads and analytics data: maximum thirteen (13) months (ad/analytics tier); session length for strictly necessary cookies.

(f) Customer-support tickets: three (3) years from closure.

(g) Backup data: rolling thirty (30) day backup cycle; full deletion of any record from backups within ninety (90) days of primary record deletion.

(h) Biometric templates and liveness recordings (KYC): biometric templates generated during the face-match step are retained by the KYC/IDV provider for the duration strictly necessary to complete the verification and — where technically required by the provider — up to thirty (30) days following successful verification, after which the templates are deleted. The verification result (pass/fail, confidence score) and the underlying liveness recording are retained together with other KYC records under category (a) above (five years post-termination) as required by UAE Federal Decree-Law No. (10) of 2025 Article 19(1)(f), Cabinet Resolution No. 134 of 2025 Article 25, and FATF Recommendation 11. The Participant may exercise data-subject rights in respect of biometric data in accordance with §11 of this Policy.

(i) Cookie-consent records (including GPC-specific fields): twenty-four (24) months from the date of the choice, to demonstrate compliance with the accountability principle under GDPR Art. 5(2) and the record-keeping obligation under GDPR Art. 7(1); this retention applies separately from the analytics-data retention set out in (e) above and is aligned with §5 of the Cookie Policy. See Cookie Policy §5 (Note on the consent-recording mechanism) and §7 for the specific record fields.

8.3 Legal Obligation to Retain. Where personal data is subject to a mandatory retention period under applicable law, the Company will retain that data for no shorter than the period required by law, regardless of any earlier request by the Participant for erasure or deletion. Participants are reminded that mandatory KYC/AML retention obligations under UAE Federal Decree-Law No. (10) of 2025 (which repealed and replaced Federal Decree-Law No. 20 of 2018), Cabinet Resolution No. 134 of 2025, and FATF Recommendation 11 constitute a lawful basis to decline erasure requests in respect of records falling within category (a) above.

§9 How We Keep Your Information Safe

9.1 Technical and Organisational Measures. The Company has taken necessary and reasonable technical and organisational measures to secure personal data in its possession. Those measures include, without limitation: encryption at rest (AES-256), encryption in transit (TLS 1.2+), access controls based on the principle of least privilege, access-audit logging, network segmentation, regular vulnerability assessments, and regular information-security risk reviews. The Company also imposes appropriate security obligations on its service providers through written contracts.

9.2 No Guarantee of Absolute Security. However, the Internet and information storage technology are not foolproof, and the Company cannot guarantee that personal data will not be accessed, stolen, or altered by unauthorised third parties. While the Company strives to protect Participants' personal data, it is the Participant's responsibility to ensure the safety of the information they transmit through the Services. Participants are advised to use the Services only in a secure environment, to use strong and unique passwords, and to notify the Company promptly of any suspected unauthorised access to their account.

9.3 Breach Notification. In the event of a personal-data breach likely to result in a high risk to the rights and freedoms of natural persons, the Company will notify affected Participants and, where required, the competent supervisory authority within the time limits prescribed by applicable law (including within 72 hours under Article 33 GDPR). Notifications will include, to the extent practicable, a description of the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences of the breach, and the measures taken or proposed to address it.

§10 Minors

10.1 Age Restriction. The Company does not knowingly collect data from or market to individuals under 18 years of age. By using the Services, the Participant affirms that they are at least 18 years old. The Services are not directed to individuals under the age of 18, and the Company does not knowingly permit minors to register for or use the Services.

10.2 Action on Discovery of Minor's Data. If the Company learns that personal data has been collected from a user under the age of 18, or that an account has been registered by or on behalf of a minor, it will delete that information and disable the associated account. If you become aware of any data the Company may have collected from a minor, please contact us immediately at privacy@neomfunded.com.

§11 Your Privacy Rights

11.1 Scope. Participants located in the EU/EEA, UK, or UAE have the rights in respect of their personal data set out in this §11 in accordance with the GDPR, UK-GDPR, and UAE PDPL, as applicable. California residents have the separate rights set out in §13 of this Policy in accordance with the CCPA/CPRA; the scope, timelines, and procedures set out in this §11 do not apply to California residents. The Company will respond to any request from a Participant located in the EU/EEA, UK, or UAE within one month of receipt, extendable by two further months where the request is complex or numerous (approximately ninety (90) calendar days in total), with notice to the Participant under Art. 12(3) GDPR. Where a request is received electronically, the Company will provide the response by electronic means where possible, unless the Participant requests otherwise.

11.2 List of Rights.

(a) Right of access (Art. 15 GDPR). The Participant may request confirmation of whether their personal data is being processed and obtain a copy of the data being processed, together with information about the purposes of processing, the categories of data concerned, the recipients or categories of recipients, the envisaged retention periods, the sources from which the data was collected, and the safeguards applied to any international transfers.

(b) Right to rectification (Art. 16 GDPR). The Participant may request the rectification of inaccurate personal data concerning them without undue delay, and, having regard to the purposes of the processing, may request the completion of incomplete personal data.

(c) Right to erasure / 'right to be forgotten' (Art. 17 GDPR). The Participant may request the erasure of their personal data where one of the grounds set out in Article 17 applies, unless processing is necessary for one of the reasons set out in that same Article, including compliance with the mandatory retention periods at §8.2 of this Policy (KYC/AML — 5 years, transactions — 7 years, etc.). Erasure requests will be assessed on a case-by-case basis and the Company will notify the Participant of its decision and the reasons therefor.

(d) Right to restriction of processing (Art. 18 GDPR). The Participant may request the restriction of processing of their personal data in the circumstances provided for in Article 18, including where the accuracy of the data is contested, where the processing is unlawful, where the Participant has objected to processing, or where the personal data is no longer needed for the purposes of processing but is required by the Participant for the establishment, exercise, or defence of legal claims.

(e) Right to data portability (Art. 20 GDPR). The Participant may receive their personal data in a structured, commonly used, and machine-readable format, and may request its transmission to another controller, where processing is based on consent or contract and is carried out by automated means. This right does not apply where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.

(f) Right to object (Art. 21 GDPR). The Participant may at any time object to the processing of their personal data based on the Company's legitimate interests (Art. 6(1)(f) GDPR), including profiling on that basis. Upon receipt of such an objection, the Company will cease processing unless it demonstrates compelling legitimate grounds which override the interests, rights, and freedoms of the Participant, or unless the processing is necessary for the establishment, exercise, or defence of legal claims.

(g) Right to withdraw consent (Art. 7(3) GDPR). The Participant may withdraw consent to the processing of personal data at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal. To withdraw marketing consent, use the unsubscribe link in the relevant communication or send a request to privacy@neomfunded.com. To withdraw cookie consent, refer to the cookie-banner settings or the Cookie Policy (published in the Legal section of the Company's website at neomfunded.com, with a direct link available in the website footer).

(h) Right not to be subject to solely automated decision-making (Art. 22 GDPR).

(h)(i) General right. Subject to the exceptions in Article 22(2) GDPR, the Participant has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning the Participant or similarly significantly affects the Participant.

(h)(ii) Scope of automated decision-making by the Company. Automated decision-making by the Company is limited to processing permitted under Article 22(2) GDPR, namely: (A) contract-necessary processing (Art. 22(2)(a) GDPR) — including trading-pattern anomaly detection and the Post-Crystallisation Compliance Review under §16.2 of the T&C; and (B) legal-obligation processing (Art. 22(2)(b) GDPR) — including automated sanctions-list screening and biometric identity verification through Sumsub under UAE Federal Decree-Law No. 20 of 2018 (as superseded by Federal Decree-Law No. 10 of 2025), Regulation (EU) 2024/1624 (EU AMLR), Directive (EU) 2018/843 (AMLD5), and the UK Money Laundering Regulations 2017 (SI 2017/692). The Company does not rely on explicit consent under Article 22(2)(c) as a basis for automated decisions.

(h)(iii) Human review for contract-necessary decisions (Art. 22(2)(a)). No decision to suspend, terminate, claw back, or set off, taken under Article 22(2)(a) above, shall be taken solely on the basis of automated output. Every case flagged by the trading-pattern anomaly detection system or the Post-Crystallisation Compliance Review is reviewed by a qualified member of the Company's risk team before any adverse action is taken. This provides the human intervention required by Article 22(3) GDPR before the decision becomes final.

(h)(iv) Legal-obligation decisions (Art. 22(2)(b)). Automated measures taken under Article 22(2)(b) above may be applied immediately where a legal obligation requires action without prior human intervention, in particular where a confirmed sanctions-list match, a confirmed adverse-media hit relevant to money-laundering risk, or a Sumsub biometric-verification rejection has occurred. In such cases, the Participant retains the right to (A) request individual review of a sanctions name-match hit by writing to compliance@neomfunded.com; and (B) request post-factum human review of any other decision taken under Article 22(2)(b) by writing to privacy@neomfunded.com.

(h)(v) Article 22(3) rights. In relation to all automated decisions taken by the Company under Article 22(2), the Participant has the right (A) to obtain human intervention on the part of the Company; (B) to express his or her point of view on the automated decision; and (C) to contest the automated decision. Requests under (A), (B), and (C) shall be submitted in writing to privacy@neomfunded.com or, in relation to sanctions and AML matters, to compliance@neomfunded.com. The Company will respond within one (1) month of receipt in accordance with Article 12(3) GDPR.

(h)(vi) Special-category data. In accordance with Article 22(4) GDPR, automated decisions taken by the Company shall not be based on special categories of personal data referred to in Article 9(1) GDPR, unless the processing is necessary for reasons of substantial public interest under Article 9(2)(g) GDPR on the basis of Union law or Member State law. This exception applies to (X) automated biometric identity verification carried out through the Sumsub identity-verification platform for the purpose of preventing identity fraud, document forgery, third-party impersonation, and money laundering, and (Y) automated sanctions-list screening. The legal instruments constituting the basis in Union, Member State, and third-country law for such processing are set out in Purpose 2 of §5.1 of this Policy, and include Regulation (EU) 2024/1624, Directive (EU) 2018/843, the UK Money Laundering Regulations 2017 (SI 2017/692), and UAE Federal Decree-Law No. 20 of 2018 (as superseded by Federal Decree-Law No. 10 of 2025).

(h)(vii) Safeguards. The Company has implemented suitable technical and organisational measures to safeguard the Participant's rights and freedoms, including access controls, data-minimisation, retention limits in accordance with §8.2 of this Policy, and the human-review safeguards set out above in this paragraph (h).

(h)(viii) Detailed logic. Meaningful information about the logic involved in each of the four automated decision-making processes described above, together with the significance and the envisaged consequences for the Participant, is set out in §26.11.1 of the Terms and Conditions.

(i) Right to lodge a complaint with a supervisory authority. The Participant may lodge a complaint with the supervisory authority of their habitual residence. The following list is illustrative and non-exhaustive:

  • Spain: Agencia Española de Protección de Datos (AEPD) — www.aepd.es
  • France: Commission Nationale de l'Informatique et des Libertés (CNIL) — www.cnil.fr
  • Germany: Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) — www.bfdi.bund.de
  • United Kingdom: Information Commissioner's Office (ICO) — www.ico.org.uk
  • UAE: UAE Data Office — www.tdra.gov.ae

Where a Participant submits a complaint to a supervisory authority, they are encouraged to inform the Company simultaneously so that the Company may have the opportunity to address the matter before the supervisory authority's investigation concludes.

11.3 Manifestly unfounded or excessive requests. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, the Company may, in accordance with Art. 12(5) GDPR, charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested, or refuse to act on the request, in each case with notice to the Participant. The Company bears the burden of demonstrating the manifestly unfounded or excessive character of the request.

11.4 Verification of Identity. To protect the security of personal data and to prevent unauthorised access, the Company may request reasonable verification of the identity of any person submitting a data-subject request before fulfilling that request.

11.5 How to Exercise Rights. Participants may exercise the rights set out above through either of the following channels, at their option:

(a) Direct contact: privacy@neomfunded.com.

(b) Trust Center (Prighter PRM). The Company provides Participants with an easy way to submit privacy-related requests such as access or erasure requests through the Privacy Rights Manager (PRM) workflow operated by its Representative, Prighter Group. To make use of data-subject rights via this channel, visit the Trust Center at https://app.prighter.com/portal/neomfunded.

Both channels are functionally equivalent and trigger the response timelines set out in §11.1.

§12 Do-Not-Track and Global Privacy Control

12.1 Do-Not-Track (DNT). Most web browsers and some mobile operating systems include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. There is no uniform standard for recognising and implementing DNT signals, and therefore, the Company does not currently respond to DNT signals. This position will be reviewed should a uniform technological standard emerge.

12.2 Global Privacy Control (GPC). The Company honours Global Privacy Control (GPC) signals as a valid opt-out request under California Consumer Privacy Act §1798.135 and the California Attorney General's guidance. Participants may exercise their right to opt out of the sale or sharing of personal information, including for cross-context behavioural advertising, under CCPA §1798.120. Where a GPC signal is detected, the Company shall treat it as an opt-out from the sale and sharing of personal information under the CCPA/CPRA and process the request accordingly. Detailed technical implementation of the GPC signal (including consent-log fields, denial of Google Consent Mode advertising signals, and the cookie-banner behaviour where a GPC signal is detected) is set out in the Cookie Policy §10.2, §7.4, and §7.7.

12.3 Limit Use of Sensitive Personal Information. Participants also have the right to limit the use and disclosure of their sensitive personal information (including geolocation data and government-issued identifiers) to uses reasonably necessary to perform the requested Services, under CCPA §1798.121. To exercise this right, contact privacy@neomfunded.com with the subject line "Limit Use of Sensitive PI".

§13 California Residents Privacy Rights

13.1 Applicability. This §13 applies exclusively to California residents (United States) in accordance with the CCPA/CPRA. If you are a California resident, you are entitled to the rights set out below in addition to those set out in §11 of this Policy.

13.2 Rights of California Residents. If you are a California resident, you are entitled to the following rights:

(a) Right to know. You may request information about the categories and specific pieces of personal data that have been collected about you, the sources from which it was collected, the purposes for which it was collected, the third parties to whom it was disclosed, and the categories of those third parties. You may make such a request up to twice in any twelve-month period.

(b) Right to deletion. You may request the deletion of personal data collected about you by the Company, subject to the applicable exceptions under the CCPA, including where the Company is required to retain the data to comply with a legal obligation or to complete a transaction for which the personal information was collected.

(c) Right to opt out of sale or sharing. You may opt out of the sale or sharing of your personal data. The Company does not sell Participants' personal data to third parties within the meaning of the CCPA. However, as the Company uses digital advertising tools (Google Ads, Meta Advertising), the transfer of data via cookies in the context of cross-context behavioural advertising may qualify as "sharing" within the meaning of the CCPA/CPRA. To opt out of such sharing, you may use the GPC mechanism described in §12.2 or adjust your preferences through the cookie-banner settings.

(d) Right to non-discrimination. The Company will not discriminate against you in the provision of Services for exercising any right granted under the CCPA, including by denying goods or services, charging different prices, or providing a different level of service.

13.3 How to Submit a Request. To exercise California privacy rights, contact support@neomfunded.com with the subject line "California Privacy Rights". The Company will acknowledge receipt of your request within ten (10) business days and will respond substantively within forty-five (45) calendar days, extendable by a further forty-five (45) days where necessary.

§14 UAE Personal Data Protection Law (PDPL)

14.1 Applicability. This §14 applies to the processing of personal data under UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the 'UAE PDPL') and §6.6 of the T&C. As a UAE-incorporated entity, the Company processes personal data under the UAE PDPL in addition to the other applicable frameworks set out in §2 of this Policy.

14.2 Data-Subject Rights under UAE PDPL. Individuals whose personal data is processed under the UAE PDPL have rights of access, rectification, erasure (subject to lawful exemptions), restriction of processing, and objection to processing, to the extent provided under the UAE PDPL. These rights are exercised in the manner set out in §11 of this Policy, subject to the following:

(a) UAE PDPL Obligations. The Company fulfils its obligations under the UAE PDPL, including registration with the UAE Data Office, application of standard contractual clauses for cross-border transfers of data originating from the UAE, and adoption of technical and organisational measures meeting UAE PDPL standards.

(b) Pending Executive Regulations. As at the Publication Date of this Policy, the Executive Regulations to the UAE PDPL have not been issued by the UAE Cabinet. As stated in §2.1(c) of this Policy, the Company will update its data-processing practices and this Policy in accordance with those Regulations following their issuance, within the implementation period prescribed therein.

(c) Supervisory Authority. Compliance with the UAE PDPL is supervised by the UAE Data Office. Requests and complaints may be directed to the UAE Data Office via its official portal at www.tdra.gov.ae.

§15 Canada (PIPEDA)

15.1 Applicability. This §15 applies to Canadian residents whose personal data is processed by the Company in the course of commercial activities, in accordance with the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA). Where applicable provincial legislation provides a higher standard of protection, the Company will comply with such higher standard.

15.2 PIPEDA Processing Principles. In addition to §5 of this Policy, the Company observes the following PIPEDA accountability principles in respect of Canadian residents:

(a) Consent. The Company processes personal data of Canadian residents only with their express or implied consent, except where applicable law permits processing without consent (fraud investigation, legal compliance, emergency situations, etc.). Participants may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice, and the Company will inform the Participant of the implications of such withdrawal.

(b) Purpose limitation. Personal data is collected only for specified and documented purposes and is not processed in ways incompatible with those purposes. The purposes for which personal data is collected are identified before or at the time of collection.

(c) Accuracy. The Company takes reasonable steps to ensure that personal data is accurate, complete, and up to date for the purposes for which it is processed, and will promptly correct inaccurate data upon the Participant's request.

(d) Supervisory authority. Compliance with PIPEDA in Canada is overseen by the Office of the Privacy Commissioner of Canada (OPC). Canadian residents may lodge a complaint with the OPC at www.priv.gc.ca.

§16 EU and UK Representatives, EU Data Act Representative, and Data Protection Officer

16.1 Privacy Representative under Article 27 GDPR and Article 27 UK-GDPR. In accordance with Article 27 GDPR and Article 27 of the UK General Data Protection Regulation (UK-GDPR), the Company values your privacy and your rights as a data subject and has therefore designated in writing separate privacy representatives for each of the following regions:

(a) EU Representative — European Economic Area. The Company has appointed Prighter GmbH (Paragon 1, Schwarzenbergplatz 4, 1030 Vienna, Austria) as its EU Representative under Article 27 GDPR for Participants located in the European Economic Area. Prighter GmbH is mandated in writing to be addressed by supervisory authorities and data subjects, in addition to or instead of the Company, on all issues related to the processing of personal data of Participants located in the European Economic Area, in accordance with Article 27(4) GDPR.

(b) UK Representative — United Kingdom. The Company has appointed Prighter Ltd (20 Mortlake High Street, London, SW14 8JN, United Kingdom; Companies House № 12854033) as its UK Representative under Article 27 UK-GDPR for Participants located in the United Kingdom. Prighter Ltd is mandated in writing to be addressed by the Information Commissioner's Office (ICO) and data subjects, in addition to or instead of the Company, on all issues related to the processing of personal data of Participants located in the United Kingdom, in accordance with Article 27(4) UK-GDPR.

Prighter Group provides Participants with an easy way to exercise privacy-related rights (e.g. requests to access or erase personal data). To contact the Company via its EU Representative or UK Representative, or to make use of data-subject rights, please visit the dedicated Trust Center at https://app.prighter.com/portal/neomfunded.

Participants may also send Article 27 requests by email to privacy@neomfunded.com with the subject line "EU Representative — Art. 27 GDPR Request" or "UK Representative — Art. 27 UK-GDPR Request", as applicable, and the Company will forward the request to the relevant Representative.

16.2 EU Data Act Representative under Article 37 Data Act ((EU) 2023/2854). NEOM TRIPLE A INFORMATION TECHNOLOGY LLC has appointed Prighter Group as its legal representative according to Art. 37 Data Act. Prighter Group serves as the addressee for competent authorities, users and other stakeholders in the European Union on all matters related to the Data Act. To contact Prighter Group please visit the digital governance portal at https://app.prighter.com/portal/12944912068 with all information on the contact details.

16.3 Data Protection Officer — Engagement in Progress. The Company is actively engaging an outsourced Data Protection Officer service provider for the purposes of Article 37 GDPR, pursued in good faith and on commercially reasonable timeframes. Pending completion of that engagement, all data-protection queries, data-subject access requests under Articles 15–22 GDPR, and any other matters relating to the processing of personal data are handled centrally by the Company's Legal & Compliance team and may be addressed to:

  • Privacy Contact: privacy@neomfunded.com
  • Postal address: Neom Triple A Information Technology LLC, The Binary by Omniyat, Office 2114, Business Bay, Dubai, UAE

Data-subject rights requests are answered within the statutory response periods (one calendar month under Article 12(3) GDPR, extendable by two further months where necessary under Article 12(3), with the data subject informed within the initial month).

Upon completion of the engagement, the contact details of the outsourced Data Protection Officer will be published on this page and notified to the competent supervisory authority pursuant to Article 37(7) GDPR within thirty (30) calendar days of the effective date of the engagement (such notification, where required, being effected through the Company's EU and UK Representative under Article 27 GDPR).

16.4 Reassessment. The Company reassesses its DPO engagement arrangements at least annually and shall update this Policy (i) upon completion of the outsourced engagement referred to in §16.3, (ii) upon any material change to the Company's processing activities that would trigger a new assessment under Article 37(1) GDPR or Article 10 of the UAE PDPL, or (iii) upon any change of outsourced provider.

§17 Changes to This Policy

17.1 Right to Amend. The Company reserves the right to amend this Policy at any time. The current version of the Policy is always available at neomfunded.com. Each version of the Policy is identified by a version number and Publication Date in the document header. Participants are encouraged to review this Policy periodically to remain informed of the Company's data-protection practices.

17.2 Notification of Material Changes. Where amendments materially affect the rights of data subjects or the manner in which their personal data is processed (material changes), the Company will notify Participants in advance by:

(a) sending a notification to the email address provided upon account registration; and/or

(b) publishing a prominent notice on neomfunded.com.

Continued use of the Services after the effective date of any amended Policy constitutes acceptance of those amendments to the extent permitted by applicable law. Where applicable law requires explicit consent for the amendment to take effect, the Company will obtain such consent before the amended Policy is applied to the relevant processing activity.

17.3 Archive Versions. Previous versions of this Policy are available on request at privacy@neomfunded.com.

§18 Contact Information

18.1 Contact Details. For any questions, comments, or requests relating to this Policy or to the processing of personal data by the Company, you may contact us through the following channels:

  • Privacy enquiries, data-protection matters and exercise of data-subject rights (Privacy Contact; outsourced DPO engagement in progress — see §16.3): privacy@neomfunded.com
  • General enquiries and support: support@neomfunded.com
  • Website: neomfunded.com
  • Registered address: Neom Triple A Information Technology LLC The Binary by Omniyat, Office 2114 Business Bay, Dubai, UAE

18.2 Data-Subject Rights Requests. Requests to exercise data-subject rights (§11 of this Policy) should be directed to privacy@neomfunded.com. The Company may request additional information to verify the identity of the requesting person before fulfilling a request. The Company does not charge a fee for the first copy of personal data provided in response to an access request.

18.3 California Resident Requests. Requests from California residents should be directed to support@neomfunded.com with the subject line "California Privacy Rights" (§13 of this Policy).

18.4 Response Times. The Company aims to acknowledge all requests within five (5) business days of receipt and to respond substantively within the timeframes prescribed by applicable law, as set out in §11 and §13 of this Policy.

This Policy supersedes all prior versions of the privacy policy published by Neom Triple A Information Technology LLC under the brand NEOM Funded.

Privacy Policy v5.0 | Neom Triple A Information Technology LLC (NEOM Funded) | Publication Date: 26 August 2026