Effective Date: 9 August 2026
This Privacy Policy ("Policy") explains how Pontech Group L.L.C-FZ, operating as XPlace ("XPlace", "we", "us", or "our"), collects, uses, stores, shares, and protects your personal information when you access or use XPlace Private, including the client portal, website, card programme and concierge service (together, the "Service"). It also describes your rights regarding your personal data and how to exercise them.
This Policy applies to all clients of XPlace Private globally. Additional jurisdiction-specific disclosures for the European Economic Area ("EEA"), the United Kingdom, and California are set out in Sections 15, 16, and 17. Where those sections conflict with the general provisions, the jurisdiction-specific section governs for users in that jurisdiction.
By accessing or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree, you must discontinue use of the Service.
Contents
"Biometric Data" means facial recognition data, liveness detection data, or other physiological identifiers collected during identity verification.
"Asset Data" means information relating to the assets you hold with your Institution which are taken into account when setting your limit, including asset types, values and confirmations. No assets are pledged, charged or blocked in connection with the Service.
"Institution" means the bank, broker, wealth manager, family office or other financial institution at which your assets are held.
"Introducing Partner" means the wealth manager, private bank, brokerage, family office or adviser through which you were introduced to the Service.
"KYC Data" means identity documents, proof of address, selfies, Biometric Data, and other information collected for Know Your Customer and Anti-Money Laundering compliance purposes.
"Personal Data" means any information relating to an identified or identifiable natural person.
"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, transfer, or deletion.
"Sensitive Personal Data" means data revealing racial or ethnic origin, political opinions, religious beliefs, health data, Biometric Data, or financial account details.
"Third-Party Provider" means any external service provider, including our Card Partner, KYC verification vendor, Institutions, funding providers, cloud infrastructure providers, and analytics services.
The data controller responsible for your Personal Data is:
Pontech Group L.L.C-FZ
Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba
Dubai, United Arab Emirates
Email: privacy@x.place
Where XPlace acts as a data processor on behalf of a Third-Party Provider — for example, transmitting KYC data to our Card Partner for card issuance — that provider acts as the data controller for that processing activity. Your Institution and Introducing Partner are independent data controllers in respect of their own relationship with you.
| Category | Examples |
|---|---|
| Identity and onboarding data | Full legal name, date of birth, nationality, residency, email address, telephone number |
| KYC and identity verification data | Government-issued ID, proof of address, selfie, liveness detection and Biometric Data |
| Source of wealth and funds data | Documentation evidencing the origin of your assets, where required by law or risk assessment |
| Asset Data | Institution name and account references, asset types, values and confirmations of asset value |
| Financial and card data | Nominated settlement account details, transaction history, statement balances, limits. Card data is processed through the Card Partner's PCI-DSS compliant infrastructure; XPlace does not store full card numbers. |
| Communications data | Concierge messages, support requests, feedback, complaints and correspondence |
| Introduction data | The identity of your Introducing Partner and the reference under which you were introduced |
Where you contact the concierge through WhatsApp or another messaging channel, the content of those messages, your display name, and your telephone number are processed by us to deliver the service and are retained in accordance with Section 11. Messaging platforms operate under their own privacy policies, over which XPlace has no control. Do not send full card numbers, passwords, or other sensitive credentials by message.
XPlace collects Biometric Data as part of identity verification through a specialist verification provider. This may include facial recognition data and liveness detection scans collected to verify your identity against government-issued identification documents.
Biometric Data is Sensitive Personal Data. It is collected solely for KYC/AML compliance purposes, processed under data processing agreements, and not used for any commercial, marketing, or unrelated analytical purpose. It is retained only for the period required by applicable AML law and is then deleted or anonymised.
| Purpose | Lawful basis |
|---|---|
| Onboarding, identity verification and account administration | Contract performance; Legal obligation |
| KYC/AML compliance, sanctions and source-of-funds screening | Legal obligation |
| Verifying your assets with your Institution | Contract performance |
| Setting and reviewing your limit | Contract performance; Legitimate interests |
| Card issuance, authorisation and settlement | Contract performance |
| Transaction monitoring and fraud prevention | Legal obligation; Legitimate interests |
| Concierge, support and dispute resolution | Contract performance; Legitimate interests |
| Service security and abuse prevention | Legitimate interests |
| Analytics and service improvement | Legitimate interests |
| Legal compliance and regulatory reporting | Legal obligation |
| Transactional and service communications | Contract performance; Consent where required |
We do not use your Personal Data for targeted advertising, commercial profiling unrelated to the Service, or sale to third parties.
We process your Personal Data under the following lawful bases, consistent with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL"), the EU General Data Protection Regulation ("GDPR") where applicable, and equivalent frameworks:
Contract performance: processing necessary to provide the Service you have requested, including onboarding, card access, limit setting and settlement.
Legal obligation: processing required to comply with applicable law, including AML/CFT obligations, KYC requirements, sanctions screening, tax reporting, and regulatory record-keeping.
Legitimate interests: processing necessary for our legitimate business interests, including security, fraud prevention, credit risk management, and service improvement, provided those interests are not overridden by your rights and freedoms.
Consent: processing based on your freely given, specific, informed and unambiguous consent, including for optional marketing communications. You may withdraw consent at any time without affecting the lawfulness of prior processing.
Where we process Biometric Data or other Sensitive Personal Data, we rely on explicit consent and/or legal obligation as the lawful basis.
We do not sell, rent, or trade your Personal Data. We share it only in the following circumstances.
We share KYC Data, identity verification results, and transaction-related data with our licensed Card Partner as required to issue and manage your Card, conduct authorisation, clearing and settlement, comply with card network and regulatory requirements, and perform fraud prevention. The Card Partner acts as an independent data controller for card-related processing.
We share with your Institution such information as is necessary to verify that you hold assets with them above the applicable threshold and to confirm their value. We do not instruct your Institution in relation to your assets and take no security over them. Your Institution acts as an independent data controller in respect of its own relationship with you.
Where you were introduced by an Introducing Partner, we may confirm to that partner the status of your application and the existence of your account, and may share aggregate activity data for the purpose of administering the introduction arrangement. We do not share your transaction-level card activity with an Introducing Partner without your consent, except where required by law.
We share identity documents and Biometric Data with our identity verification provider solely for the purpose of verifying your identity against applicable AML/KYC requirements. The provider acts as a data processor under a data processing agreement and is prohibited from using your data for any other purpose.
We use third-party funding providers, cloud hosting services, database providers, and monitoring tools. These process Personal Data as data processors under our instructions and subject to data processing agreements.
We may disclose Personal Data to government authorities, regulators, law enforcement agencies, or courts where required by applicable law, regulation, court order, or legal process. Where legally permitted, we will notify you of such disclosures.
In the event of a merger, acquisition, asset sale, corporate reorganisation, or insolvency proceeding, your Personal Data may be transferred to the acquiring or successor entity. We will provide notice through the Service and, where required by applicable law, seek your consent.
We may share Personal Data with our legal, financial, and compliance advisers on a confidential basis where necessary to obtain professional advice or manage legal proceedings.
XPlace is operated from the United Arab Emirates. Your Personal Data may be transferred to, stored in, or processed in countries other than your country of residence, including the UAE, the United States, and other jurisdictions where our Third-Party Providers operate.
Where we transfer Personal Data outside the UAE or EEA, we ensure appropriate safeguards are in place, which may include Standard Contractual Clauses approved by the European Commission or equivalent UAE mechanisms, transfers to countries recognised as providing an adequate level of protection, or other legally recognised transfer mechanisms. You may request a copy of the applicable transfer mechanisms by contacting privacy@x.place.
| Cookie type | Purpose · Can be declined? |
|---|---|
| Strictly necessary | Essential for operation: authentication, security, session management. No. |
| Functional | Remember your preferences, language settings and session state. Yes. |
| Analytics | Aggregate usage statistics used to understand and improve the Service. Yes. |
You may control cookies through the cookie preference centre available on the Service where required by applicable law, your browser settings, or your device settings. Disabling strictly necessary cookies may impair functionality.
We send the following without requiring separate consent, as they are necessary to operate your account:
You may not opt out of transactional communications without closing your account.
We will only send marketing communications where you have provided explicit opt-in consent. You may withdraw consent at any time by using the unsubscribe link, updating your preferences, or contacting privacy@x.place. Withdrawal does not affect delivery of transactional communications.
The Service is not directed at individuals under the age of 18 and XPlace does not knowingly collect Personal Data from minors. If we become aware that we have inadvertently collected Personal Data from an individual under 18, we will promptly delete that data and close the associated account. Contact privacy@x.place with any concern.
| Data category | Retention period |
|---|---|
| Account and identity data | Duration of the relationship plus 5 years after closure (AML record-keeping) |
| KYC documents and Biometric Data | Duration of the relationship plus 5 years, or longer where required by applicable AML law |
| Asset Data and confirmations | Duration of the relationship plus 6 years, or longer where required by law or for legal claims |
| Transaction and statement records | Minimum 5 years from the date of transaction |
| Card data | As required by the Card Partner and PCI-DSS; XPlace does not independently retain full card data |
| Concierge and support communications | 3 years from closure of the request |
| Usage and analytics data | Up to 24 months from collection; anonymised thereafter |
| Marketing consent records | Until consent is withdrawn plus 3 years |
Following the applicable retention period, Personal Data will be securely deleted or irreversibly anonymised.
Subject to applicable law and certain exceptions, you have the right to: access a copy of the Personal Data we hold about you; request correction of inaccurate or incomplete data; request deletion, subject to legal retention obligations; receive a copy of data you provided in a structured, machine-readable format; object to processing based on legitimate interests; request restriction of processing in certain circumstances; and withdraw consent for consent-based processing at any time.
Submit a written request to privacy@x.place including your full name, the email address associated with your account, the specific right you wish to exercise, and any information helping us locate your records. We will verify your identity before processing any request.
We will respond within thirty (30) calendar days of receipt. Where a request is complex, we may extend this period by up to a further sixty (60) days with notice.
We encourage you to contact us at privacy@x.place first, as we aim to resolve all complaints directly.
No method of transmission over the internet is completely secure and we cannot guarantee absolute security. You are responsible for maintaining the security of your credentials and device access.
In the event of a personal data breach posing a high risk to your rights or freedoms, we will notify affected clients promptly and without undue delay once confirmed, notify the relevant supervisory authority within 72 hours of becoming aware where required by GDPR, the UAE PDPL, or equivalent law, and provide details of the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, and the measures taken.
Breach notification obligations arising from Card Partner, Institution or other third-party security incidents are subject to the incident response obligations of those parties. XPlace will coordinate with affected providers and notify clients to the extent reasonably practicable.
15.1 The lawful bases under which we process EEA clients' personal data are set out in Section 5. Where we rely on legitimate interests (Article 6(1)(f)), you may request details of our assessment by contacting privacy@x.place.
15.2 Biometric Data collected for KYC purposes constitutes special category data under Article 9 GDPR. We process it on the basis of explicit consent (Article 9(2)(a)) and, where applicable, for reasons of substantial public interest related to financial crime prevention (Article 9(2)(g)). Withdrawal of consent may result in our inability to complete verification, in which case we may be unable to provide the Service.
15.3 Certain KYC and sanctions screening processes may involve automated decision-making, including profiling. Where such processing produces legal or similarly significant effects, you have the right to request human review, express your point of view, and contest the decision. Contact privacy@x.place.
15.4 Transfers of EEA personal data to the UAE and other third countries are conducted pursuant to Standard Contractual Clauses adopted by the European Commission. You may request a copy by contacting privacy@x.place.
15.5 EEA clients have the full rights set out in Section 12, plus the right not to be subject to solely automated decisions with significant effects (Article 22 GDPR) and the right to lodge a complaint with their national supervisory authority.
16.1 The UK GDPR and Data Protection Act 2018 apply to our processing of UK clients' personal data. References to the GDPR in this Policy mean the UK GDPR as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018.
16.2 International transfers from the UK are conducted pursuant to the International Data Transfer Agreement (IDTA) or equivalent UK-approved transfer mechanism.
16.3 The supervisory authority for UK clients is the Information Commissioner's Office (ICO), reachable at ico.org.uk. UK clients have the full rights set out in Section 12 and may lodge a complaint directly with the ICO.
This Section is provided pursuant to the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020.
17.1 In the preceding 12 months we may have collected the following categories of personal information: identifiers including name, email address, IP address and device identifiers; biometric information collected for KYC purposes; internet or other electronic network activity; approximate geolocation derived from IP address; commercial information relating to card activity; and fraud risk inferences generated from transaction monitoring.
17.2 California residents have the right to know the categories and specific pieces of personal information collected, the sources, business purposes, and categories of third parties with whom it was shared; to delete personal information subject to legal retention exceptions; to correct inaccurate information; to opt out of sale or sharing — XPlace does not sell personal information or share it for cross-context behavioural advertising; to limit the use of sensitive personal information; and to non-discrimination for exercising these rights.
17.3 Submit requests to privacy@x.place with the subject line "California Privacy Request." We will verify your identity and respond within 45 days, extendable by a further 45 days with notice.
The Service may contain links to third-party websites or services. XPlace is not responsible for the privacy practices, data security, or content of those third parties. This Policy does not govern the data practices of Third-Party Providers acting as independent data controllers, including our Card Partner, Institutions, Introducing Partners, identity verification providers, and messaging platforms.
We may update this Policy periodically to reflect changes in law, technology, our data practices, or business operations. When we make material changes we will publish the updated Policy at private.x.place with a revised effective date, notify you by email or through the Service, and, where required by applicable law, seek your consent before implementing material changes.
Your continued use of the Service after the effective date constitutes acceptance of the changes.
Pontech Group L.L.C-FZ
Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba
Dubai, United Arab Emirates
Email: privacy@x.place
We aim to respond to all inquiries within 30 calendar days.