top of page

Privacy Policy

Diment VA Exchange Services DMCC (“DVA”)

Last Edited: 25.02.2026

Introduction and Summary
 

Diment VA Exchange Services DMCC (“DVA”, “we”, “our”, or “us”) is a Virtual Asset Service Provider incorporated in the Dubai Multi Commodities Centre (DMCC) and regulated by the Virtual Assets Regulatory Authority (“VARA”) as a Broker-Dealer.
 

We are committed to protecting your privacy and ensuring the security and integrity of your personal data. As a regulated financial services firm operating within the virtual asset ecosystem, we maintain strict data protection standards consistent with applicable UAE data protection laws, VARA regulations, anti-money laundering and counter-terrorist financing requirements, and internationally recognised information security practices.

This Privacy Policy applies to all end users interacting with DVA, including clients (Retail, Qualified and Institutional), prospective clients, counterparties, website visitors, employees, and prospective employees. By accessing our website or utilising our services, you acknowledge and agree to the terms set out in this Privacy Policy.
 

Scope
 

This Privacy Policy applies to all users of DVA’s website, platform, products, and services. It governs personal data collected during interactions with us, whether online, through onboarding processes, or via direct communications.

This Policy does not apply to anonymised, aggregated, or de-identified information that cannot reasonably be used to identify an individual.

Legal Basis for Processing

We process personal information only where legally permitted to do so. Our legal bases for processing include:

Consent: Where you have provided explicit consent for specific processing activities, including certain marketing communications or location-based services. You may withdraw consent at any time, subject to regulatory limitations.

Performance of a Contract: Where processing is necessary to provide broker-dealer services, execute transactions, manage accounts, and fulfil our contractual obligations to you.

Legal Obligations: Where processing is required to comply with applicable laws and regulations, including VARA requirements, AML/CFT laws, sanctions screening obligations, regulatory reporting duties, and record-keeping requirements.

Legitimate Interests: Where processing is necessary for the purposes of fraud prevention, cybersecurity protection, risk management, service improvement, internal governance, or dispute resolution, provided such interests do not override your fundamental rights.

1. Information Collection

We collect information about you in order to provide regulated virtual asset broker-dealer services and to comply with our legal and regulatory obligations.

Personal Identification Information

This may include your full name, date of birth, nationality, residential address, email address, telephone number, government-issued identification documents, biometric verification data (where applicable), and any other information required to verify your identity.

Financial and Transaction Information

We may collect information relating to your bank accounts, wallet addresses, source of funds documentation, transaction history, trading activity, and other financial information necessary to facilitate virtual asset transactions, fiat on/off ramp services, and order execution.

Corporate and Institutional Information

For legal entities, we may collect company registration details, constitutional documents, information relating to directors and beneficial owners, authorised signatories, business activities, and ownership structures, together with supporting documentation required under applicable regulatory frameworks.

Technical and Usage Data

When you access our website or platform, we may collect technical information such as your IP address, browser type, device identifiers, operating system, referring pages, session duration, click patterns, and platform usage activity. This information assists us in improving security, performance, and user experience.

Geolocation Information

Certain platform features may rely on geolocation data. Where required, and with your consent, we may collect location-based information while the platform is in use. If you decline to provide geolocation data, some services or functionalities may be limited.

2. Individuals Under the Age of 18

DVA’s services are not intended for individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that personal data has been collected from an individual under 18 without appropriate authorisation, we will take steps to delete such information promptly.

3. Use of Information

We use your information to provide our regulated services and to maintain compliance with legal obligations. Specifically, your information may be used:

To verify your identity and conduct Know Your Customer (KYC) and due diligence procedures.

To classify clients as Retail, Qualified, or Institutional investors in accordance with regulatory requirements.

To execute, settle, and record virtual asset transactions and fiat conversions.

To conduct AML/CFT monitoring, sanctions screening, and suspicious activity detection.

To manage risk, including credit risk, liquidity risk, and operational risk.

To respond to regulatory inquiries, audits, and reporting obligations.

To investigate potential violations of our Terms of Service or applicable law.

To improve our services, enhance platform functionality, and develop internal analytics.

To communicate with you regarding your account, transactions, regulatory notices, or service updates.

We may also use aggregated or anonymised data for statistical analysis, internal research, and operational planning.

4. Storage and Retention

Your personal data may be stored within the United Arab Emirates or in other jurisdictions where our service providers operate, subject to appropriate safeguards.

We retain personal data for as long as necessary to provide services and fulfil regulatory requirements. In accordance with VARA and AML/CFT regulations, we retain client identification and transaction records for a minimum of five (5) years following termination of the business relationship. This period may be extended to up to ten (10) years or longer if required by regulatory authorities.

5. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encryption, access controls, secure infrastructure environments, multi-factor authentication, transaction monitoring systems, and cybersecurity protocols.

While we apply institutional-grade safeguards, the internet remains an open system and absolute security cannot be guaranteed. Users are encouraged to implement their own security precautions, including secure passwords and device protections.



6. Sensitive Personal Data

Where required for regulatory compliance, we may process special categories of personal data, including information relating to sanctions exposure, politically exposed person (PEP) status, or other risk-based classifications. Such data is processed strictly in accordance with applicable law and subject to enhanced safeguards.

7. Third-Party Websites

Our website may contain links to external websites. These links are provided for convenience only. DVA does not control and is not responsible for the privacy practices or content of third-party websites. Users are encouraged to review the privacy policies of those sites independently.

8. Law Enforcement and Regulatory Disclosure

As a VARA-regulated Broker-Dealer, we may disclose your information to regulatory authorities, courts, law enforcement agencies, or other competent bodies where required by law or regulatory mandate.

We may also disclose information where we reasonably believe that such disclosure is necessary to investigate illegal activities, enforce our rights, or comply with legal obligations. We are not obligated to notify you of such disclosures where prohibited by law.

9. Commercial and Non-Commercial Communications

If you provide us with contact details, we may send communications relating to your account, service updates, regulatory notices, or marketing materials. You may opt out of marketing communications at any time, though regulatory or account-related communications may still be required.

10. Third-Party Service Providers

In the course of providing regulated services, we may engage third-party service providers, including KYC providers, custodians, transaction monitoring providers, auditors, banking institutions, IT infrastructure providers, and compliance vendors.

These third parties are contractually bound to confidentiality obligations and are authorised to process personal data solely for the purposes of delivering services on our behalf. We remain responsible for ensuring that outsourcing arrangements comply with regulatory requirements.

11. Cookies and Tracking Technologies

We may use cookies and similar tracking technologies to enhance website performance, maintain session integrity, support security monitoring, and analyse site usage. By using our website, you consent to the use of cookies in accordance with this Policy. You may adjust cookie settings through your browser at any time.

12. International Data Transfers

Where necessary for operational or compliance purposes, personal data may be transferred outside your jurisdiction. In such cases, we ensure that appropriate safeguards are implemented to protect your data in accordance with applicable legal standards.

13. Data Subject Rights

Subject to applicable law, you may have the right to:

  • Request access to your personal data

  • Request correction of inaccurate information

  • Request deletion of personal data (subject to regulatory retention obligations)

  • Restrict or object to certain processing activities

  • Request data portability

  • Withdraw consent where processing is based on consent
     

Please note that certain rights may be limited where retention is required to comply with AML/CFT, VARA, or other financial regulations.

14. Automated Decision-Making

We may utilise automated systems for transaction monitoring, sanctions screening, and risk profiling in order to comply with AML/CFT obligations. These systems are subject to oversight and governance controls to ensure fairness and regulatory compliance.

15. Handling Data Subject Requests

Requests relating to personal data may be submitted to:

Data Protection Officer

Diment VA Exchange Services DMCC


Sunny Sahota - LinkedIn
sunny.sahota@dvaex.io

We will respond within the timeframes required by applicable law.

16. Changes to this Privacy Policy

This Privacy Policy may be amended from time to time. Any updates will be published on our website and reflected by an updated Effective Date. We encourage users to review this Policy periodically to remain informed of our data practices.

bottom of page