XPlace Private
Privacy Policy

Effective Date: 9 August 2026

This Privacy Policy ("Policy") explains how Pontech Group L.L.C-FZ, operating as XPlace ("XPlace", "we", "us", or "our"), collects, uses, stores, shares, and protects your personal information when you access or use XPlace Private, including the client portal, website, card programme and concierge service (together, the "Service"). It also describes your rights regarding your personal data and how to exercise them.

This Policy applies to all clients of XPlace Private globally. Additional jurisdiction-specific disclosures for the European Economic Area ("EEA"), the United Kingdom, and California are set out in Sections 15, 16, and 17. Where those sections conflict with the general provisions, the jurisdiction-specific section governs for users in that jurisdiction.

By accessing or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree, you must discontinue use of the Service.

Contents

  1. Key definitions
  2. Data controller
  3. Information we collect
  4. How we use your information
  5. Lawful basis
  6. Data sharing
  7. International transfers
  8. Cookies
  9. Communications
  10. Children's privacy
  11. Data retention
  12. Your rights
  13. Data security
  14. Breach notification
  15. EEA users
  16. UK users
  17. California residents
  18. Third-party links
  19. Changes to this Policy
  20. Contact

1. KEY DEFINITIONS

"Biometric Data" means facial recognition data, liveness detection data, or other physiological identifiers collected during identity verification.

"Asset Data" means information relating to the assets you hold with your Institution which are taken into account when setting your limit, including asset types, values and confirmations. No assets are pledged, charged or blocked in connection with the Service.

"Institution" means the bank, broker, wealth manager, family office or other financial institution at which your assets are held.

"Introducing Partner" means the wealth manager, private bank, brokerage, family office or adviser through which you were introduced to the Service.

"KYC Data" means identity documents, proof of address, selfies, Biometric Data, and other information collected for Know Your Customer and Anti-Money Laundering compliance purposes.

"Personal Data" means any information relating to an identified or identifiable natural person.

"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, transfer, or deletion.

"Sensitive Personal Data" means data revealing racial or ethnic origin, political opinions, religious beliefs, health data, Biometric Data, or financial account details.

"Third-Party Provider" means any external service provider, including our Card Partner, KYC verification vendor, Institutions, funding providers, cloud infrastructure providers, and analytics services.

2. DATA CONTROLLER

The data controller responsible for your Personal Data is:

Pontech Group L.L.C-FZ
Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba
Dubai, United Arab Emirates
Email: privacy@x.place

Where XPlace acts as a data processor on behalf of a Third-Party Provider — for example, transmitting KYC data to our Card Partner for card issuance — that provider acts as the data controller for that processing activity. Your Institution and Introducing Partner are independent data controllers in respect of their own relationship with you.

3. INFORMATION WE COLLECT

3.1 Information you provide directly

CategoryExamples
Identity and onboarding dataFull legal name, date of birth, nationality, residency, email address, telephone number
KYC and identity verification dataGovernment-issued ID, proof of address, selfie, liveness detection and Biometric Data
Source of wealth and funds dataDocumentation evidencing the origin of your assets, where required by law or risk assessment
Asset DataInstitution name and account references, asset types, values and confirmations of asset value
Financial and card dataNominated settlement account details, transaction history, statement balances, limits. Card data is processed through the Card Partner's PCI-DSS compliant infrastructure; XPlace does not store full card numbers.
Communications dataConcierge messages, support requests, feedback, complaints and correspondence
Introduction dataThe identity of your Introducing Partner and the reference under which you were introduced

3.2 Information collected automatically

3.3 Concierge communications

Where you contact the concierge through WhatsApp or another messaging channel, the content of those messages, your display name, and your telephone number are processed by us to deliver the service and are retained in accordance with Section 11. Messaging platforms operate under their own privacy policies, over which XPlace has no control. Do not send full card numbers, passwords, or other sensitive credentials by message.

3.4 KYC and Biometric Data

XPlace collects Biometric Data as part of identity verification through a specialist verification provider. This may include facial recognition data and liveness detection scans collected to verify your identity against government-issued identification documents.

Biometric Data is Sensitive Personal Data. It is collected solely for KYC/AML compliance purposes, processed under data processing agreements, and not used for any commercial, marketing, or unrelated analytical purpose. It is retained only for the period required by applicable AML law and is then deleted or anonymised.

3.6 Information we do not collect

4. HOW WE USE YOUR INFORMATION

PurposeLawful basis
Onboarding, identity verification and account administrationContract performance; Legal obligation
KYC/AML compliance, sanctions and source-of-funds screeningLegal obligation
Verifying your assets with your InstitutionContract performance
Setting and reviewing your limitContract performance; Legitimate interests
Card issuance, authorisation and settlementContract performance
Transaction monitoring and fraud preventionLegal obligation; Legitimate interests
Concierge, support and dispute resolutionContract performance; Legitimate interests
Service security and abuse preventionLegitimate interests
Analytics and service improvementLegitimate interests
Legal compliance and regulatory reportingLegal obligation
Transactional and service communicationsContract performance; Consent where required

We do not use your Personal Data for targeted advertising, commercial profiling unrelated to the Service, or sale to third parties.

5. LAWFUL BASIS FOR PROCESSING

We process your Personal Data under the following lawful bases, consistent with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL"), the EU General Data Protection Regulation ("GDPR") where applicable, and equivalent frameworks:

Contract performance: processing necessary to provide the Service you have requested, including onboarding, card access, limit setting and settlement.

Legal obligation: processing required to comply with applicable law, including AML/CFT obligations, KYC requirements, sanctions screening, tax reporting, and regulatory record-keeping.

Legitimate interests: processing necessary for our legitimate business interests, including security, fraud prevention, credit risk management, and service improvement, provided those interests are not overridden by your rights and freedoms.

Consent: processing based on your freely given, specific, informed and unambiguous consent, including for optional marketing communications. You may withdraw consent at any time without affecting the lawfulness of prior processing.

Where we process Biometric Data or other Sensitive Personal Data, we rely on explicit consent and/or legal obligation as the lawful basis.

6. DATA SHARING AND DISCLOSURE

We do not sell, rent, or trade your Personal Data. We share it only in the following circumstances.

6.1 Card Partner

We share KYC Data, identity verification results, and transaction-related data with our licensed Card Partner as required to issue and manage your Card, conduct authorisation, clearing and settlement, comply with card network and regulatory requirements, and perform fraud prevention. The Card Partner acts as an independent data controller for card-related processing.

6.2 Institution

We share with your Institution such information as is necessary to verify that you hold assets with them above the applicable threshold and to confirm their value. We do not instruct your Institution in relation to your assets and take no security over them. Your Institution acts as an independent data controller in respect of its own relationship with you.

6.3 Introducing Partner

Where you were introduced by an Introducing Partner, we may confirm to that partner the status of your application and the existence of your account, and may share aggregate activity data for the purpose of administering the introduction arrangement. We do not share your transaction-level card activity with an Introducing Partner without your consent, except where required by law.

6.4 KYC verification provider

We share identity documents and Biometric Data with our identity verification provider solely for the purpose of verifying your identity against applicable AML/KYC requirements. The provider acts as a data processor under a data processing agreement and is prohibited from using your data for any other purpose.

6.5 Funding and infrastructure providers

We use third-party funding providers, cloud hosting services, database providers, and monitoring tools. These process Personal Data as data processors under our instructions and subject to data processing agreements.

6.6 Legal and regulatory disclosure

We may disclose Personal Data to government authorities, regulators, law enforcement agencies, or courts where required by applicable law, regulation, court order, or legal process. Where legally permitted, we will notify you of such disclosures.

6.7 Business transfers

In the event of a merger, acquisition, asset sale, corporate reorganisation, or insolvency proceeding, your Personal Data may be transferred to the acquiring or successor entity. We will provide notice through the Service and, where required by applicable law, seek your consent.

6.8 Professional advisers

We may share Personal Data with our legal, financial, and compliance advisers on a confidential basis where necessary to obtain professional advice or manage legal proceedings.

7. INTERNATIONAL DATA TRANSFERS

XPlace is operated from the United Arab Emirates. Your Personal Data may be transferred to, stored in, or processed in countries other than your country of residence, including the UAE, the United States, and other jurisdictions where our Third-Party Providers operate.

Where we transfer Personal Data outside the UAE or EEA, we ensure appropriate safeguards are in place, which may include Standard Contractual Clauses approved by the European Commission or equivalent UAE mechanisms, transfers to countries recognised as providing an adequate level of protection, or other legally recognised transfer mechanisms. You may request a copy of the applicable transfer mechanisms by contacting privacy@x.place.

8. COOKIES AND TRACKING TECHNOLOGIES

Cookie typePurpose · Can be declined?
Strictly necessaryEssential for operation: authentication, security, session management. No.
FunctionalRemember your preferences, language settings and session state. Yes.
AnalyticsAggregate usage statistics used to understand and improve the Service. Yes.

You may control cookies through the cookie preference centre available on the Service where required by applicable law, your browser settings, or your device settings. Disabling strictly necessary cookies may impair functionality.

9. COMMUNICATIONS

9.1 Transactional communications

We send the following without requiring separate consent, as they are necessary to operate your account:

You may not opt out of transactional communications without closing your account.

9.2 Marketing communications

We will only send marketing communications where you have provided explicit opt-in consent. You may withdraw consent at any time by using the unsubscribe link, updating your preferences, or contacting privacy@x.place. Withdrawal does not affect delivery of transactional communications.

10. CHILDREN'S PRIVACY

The Service is not directed at individuals under the age of 18 and XPlace does not knowingly collect Personal Data from minors. If we become aware that we have inadvertently collected Personal Data from an individual under 18, we will promptly delete that data and close the associated account. Contact privacy@x.place with any concern.

11. DATA RETENTION

Data categoryRetention period
Account and identity dataDuration of the relationship plus 5 years after closure (AML record-keeping)
KYC documents and Biometric DataDuration of the relationship plus 5 years, or longer where required by applicable AML law
Asset Data and confirmationsDuration of the relationship plus 6 years, or longer where required by law or for legal claims
Transaction and statement recordsMinimum 5 years from the date of transaction
Card dataAs required by the Card Partner and PCI-DSS; XPlace does not independently retain full card data
Concierge and support communications3 years from closure of the request
Usage and analytics dataUp to 24 months from collection; anonymised thereafter
Marketing consent recordsUntil consent is withdrawn plus 3 years

Following the applicable retention period, Personal Data will be securely deleted or irreversibly anonymised.

12. YOUR DATA SUBJECT RIGHTS

Subject to applicable law and certain exceptions, you have the right to: access a copy of the Personal Data we hold about you; request correction of inaccurate or incomplete data; request deletion, subject to legal retention obligations; receive a copy of data you provided in a structured, machine-readable format; object to processing based on legitimate interests; request restriction of processing in certain circumstances; and withdraw consent for consent-based processing at any time.

12.1 How to submit a request

Submit a written request to privacy@x.place including your full name, the email address associated with your account, the specific right you wish to exercise, and any information helping us locate your records. We will verify your identity before processing any request.

12.2 Response timeframe

We will respond within thirty (30) calendar days of receipt. Where a request is complex, we may extend this period by up to a further sixty (60) days with notice.

12.3 Right to lodge a complaint

We encourage you to contact us at privacy@x.place first, as we aim to resolve all complaints directly.

13. DATA SECURITY

No method of transmission over the internet is completely secure and we cannot guarantee absolute security. You are responsible for maintaining the security of your credentials and device access.

14. DATA BREACH NOTIFICATION

In the event of a personal data breach posing a high risk to your rights or freedoms, we will notify affected clients promptly and without undue delay once confirmed, notify the relevant supervisory authority within 72 hours of becoming aware where required by GDPR, the UAE PDPL, or equivalent law, and provide details of the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, and the measures taken.

Breach notification obligations arising from Card Partner, Institution or other third-party security incidents are subject to the incident response obligations of those parties. XPlace will coordinate with affected providers and notify clients to the extent reasonably practicable.

15. ADDITIONAL DISCLOSURES FOR EEA USERS (GDPR)

15.1 The lawful bases under which we process EEA clients' personal data are set out in Section 5. Where we rely on legitimate interests (Article 6(1)(f)), you may request details of our assessment by contacting privacy@x.place.

15.2 Biometric Data collected for KYC purposes constitutes special category data under Article 9 GDPR. We process it on the basis of explicit consent (Article 9(2)(a)) and, where applicable, for reasons of substantial public interest related to financial crime prevention (Article 9(2)(g)). Withdrawal of consent may result in our inability to complete verification, in which case we may be unable to provide the Service.

15.3 Certain KYC and sanctions screening processes may involve automated decision-making, including profiling. Where such processing produces legal or similarly significant effects, you have the right to request human review, express your point of view, and contest the decision. Contact privacy@x.place.

15.4 Transfers of EEA personal data to the UAE and other third countries are conducted pursuant to Standard Contractual Clauses adopted by the European Commission. You may request a copy by contacting privacy@x.place.

15.5 EEA clients have the full rights set out in Section 12, plus the right not to be subject to solely automated decisions with significant effects (Article 22 GDPR) and the right to lodge a complaint with their national supervisory authority.

16. ADDITIONAL DISCLOSURES FOR UK USERS (UK GDPR)

16.1 The UK GDPR and Data Protection Act 2018 apply to our processing of UK clients' personal data. References to the GDPR in this Policy mean the UK GDPR as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018.

16.2 International transfers from the UK are conducted pursuant to the International Data Transfer Agreement (IDTA) or equivalent UK-approved transfer mechanism.

16.3 The supervisory authority for UK clients is the Information Commissioner's Office (ICO), reachable at ico.org.uk. UK clients have the full rights set out in Section 12 and may lodge a complaint directly with the ICO.

17. ADDITIONAL DISCLOSURES FOR CALIFORNIA RESIDENTS (CCPA / CPRA)

This Section is provided pursuant to the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020.

17.1 In the preceding 12 months we may have collected the following categories of personal information: identifiers including name, email address, IP address and device identifiers; biometric information collected for KYC purposes; internet or other electronic network activity; approximate geolocation derived from IP address; commercial information relating to card activity; and fraud risk inferences generated from transaction monitoring.

17.2 California residents have the right to know the categories and specific pieces of personal information collected, the sources, business purposes, and categories of third parties with whom it was shared; to delete personal information subject to legal retention exceptions; to correct inaccurate information; to opt out of sale or sharing — XPlace does not sell personal information or share it for cross-context behavioural advertising; to limit the use of sensitive personal information; and to non-discrimination for exercising these rights.

17.3 Submit requests to privacy@x.place with the subject line "California Privacy Request." We will verify your identity and respond within 45 days, extendable by a further 45 days with notice.

18. THIRD-PARTY LINKS AND SERVICES

The Service may contain links to third-party websites or services. XPlace is not responsible for the privacy practices, data security, or content of those third parties. This Policy does not govern the data practices of Third-Party Providers acting as independent data controllers, including our Card Partner, Institutions, Introducing Partners, identity verification providers, and messaging platforms.

19. CHANGES TO THIS POLICY

We may update this Policy periodically to reflect changes in law, technology, our data practices, or business operations. When we make material changes we will publish the updated Policy at private.x.place with a revised effective date, notify you by email or through the Service, and, where required by applicable law, seek your consent before implementing material changes.

Your continued use of the Service after the effective date constitutes acceptance of the changes.

20. CONTACT AND DATA PROTECTION INQUIRIES

Pontech Group L.L.C-FZ
Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba
Dubai, United Arab Emirates
Email: privacy@x.place

We aim to respond to all inquiries within 30 calendar days.