PRIVACY POLICY

Janus Digital Global FZE
Effective Date: 1 May 2026

This Privacy Policy applies to your use of the Janus Digital mobile application (the “App”), whether downloaded from the Apple App Store, Google Play Store, or any other authorised distribution channel. By downloading, installing, or using the App, you agree to the practices described in this Privacy Policy.

This Privacy Policy describes how Janus Digital Global FZE (“Janus Digital”, “we”, “our”, or “us”) collects, uses, stores, and protects your personal information when you use the App, and how we address your rights in relation to that information. Please read this Privacy Policy carefully.

Important: You must be at least eighteen (18) years of age to create an account and use the App. By registering, you confirm that you are 18 or older.

1. Data We Collect

When you download and register for the Janus Digital App, we collect and process the following categories of personal data:

1.1 Account Data

Your personal mobile phone number, which serves as your unique identifier for registration, login authentication, and password recovery.

1.2 Technical and Usage Data

In the course of operating the App, we may automatically collect limited technical data necessary for the App’s security, stability, and performance, including: IP address (collected transiently during server communication), device operating system and version, App version, crash logs and diagnostic data, and session activity timestamps. This data is collected in accordance with the data categories disclosed in the Apple App Store Privacy Nutrition Labels and Google Play Data Safety section.

1.3 In-App Consent

Before collecting your Account Data, the App will present you with a clear, prominent disclosure within the application interface explaining what data is being collected and how it will be used. You must provide affirmative consent (for example, by tapping an “Agree” or “Continue” button) before the App processes your phone number. If you decline, you may continue to browse any features of the App that do not require account registration.

2. Lawful Basis for Processing and How We Use Your Personal Data

2.1 Lawful Basis for Processing

We process your personal data on the following lawful bases:

  1. Performance of a contract (Article 6(1)(b) GDPR): the collection of your phone number is necessary to provide you with the App’s core services, including account creation, login authentication, and password recovery. Because the phone number is the sole means of accessing the App, this processing is performed on the basis of contractual necessity, not consent.
  2. Legitimate interests (Article 6(1)(f) GDPR): the collection of Technical and Usage Data (Section 1.2) is necessary for our legitimate interests in maintaining the security, stability, and performance of the App, provided such interests are not overridden by your rights and freedoms.
  3. Legal obligation (Article 6(1)(c) GDPR): where we are required to process or retain your data to comply with applicable law, regulation, or court order.
  4. Consent (Article 6(1)(a) GDPR / Section 13 PDPA): where we process personal data for any purpose not covered by the bases above (for example, optional analytics or future marketing communications), we will obtain your prior, freely given, and informed consent. You may withdraw such consent at any time without affecting the lawfulness of prior processing.

2.2 How We Use Your Personal Data

We use your Account Data to:

  1. verify your identity at registration and login; and
  2. provide password recovery functionality.

We use your Technical and Usage Data to:

  1. monitor and improve the App’s performance, stability, and security; and
  2. generate anonymised, aggregated analytics that cannot be used to identify you.

2.3 Third-Party Data Sharing and Recipients

Janus Digital will not provide, sell, rent, share, or trade your personal information to any unrelated third party unless we have obtained your prior consent, except in the following circumstances:

  1. SMS Verification Providers: To deliver SMS one-time passwords (OTPs) for account verification and password recovery, your phone number is securely shared with third-party telecommunications or SMS gateway providers (for example, Twilio, AWS SNS, or equivalent). These providers act as data processors on our behalf and are contractually prohibited from using your phone number for any purpose other than delivering the verification message.
  2. Service Providers: We may share data with service providers who process data strictly on our behalf and under our documented instructions (for example, cloud hosting infrastructure). These providers are bound by data processing agreements and are prohibited from using your data for their own purposes.
  3. Corporate Transactions: In the event that Janus Digital undergoes a reorganisation, merger, or sale, personal data may be transferred to the relevant third party, provided that (i) the transfer is necessary for the purposes of the transaction, (ii) the acquiring party assumes equivalent data protection obligations, and (iii) you are notified of the transfer and any change in data controller before or at the time of the transfer.

If a third party provides services to you jointly with or on behalf of Janus Digital, that third party will be prohibited from accessing any such information, including information it previously had access to, once the service has ended.

3. Personal Information Security

Ensuring the security of your data is of paramount importance to us. When you register and enter personal information in the Janus Digital App, we encrypt that information using industry-standard protocols.

During both data transmission and data storage, we protect the information you submit to us using widely accepted industry standards, including HTTPS/TLS encryption in transit, AES-256 encryption at rest, firewalls, and compliance with applicable data privacy laws.

However, no method of Internet transmission or electronic storage is 100% secure. Therefore, while we use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.

4. How Long We Retain Personal Data

Janus Digital retains your personal data in accordance with the following retention schedule:

  1. Account Data: retained for the duration of your active use of the App.
  2. Technical and Usage Data: retained for a maximum of twelve (12) months from the date of collection, after which it is permanently deleted or irreversibly anonymised.
  3. Inactive Accounts: If your account remains inactive (i.e. no login activity) for twenty-four (24) consecutive months, we will send a notification to your registered phone number. If no action is taken within thirty (30) days of that notification, your account and all associated personal data will be automatically and permanently deleted.
  4. Post-Deletion: Upon account deletion (whether self-initiated, automatic, or requested via the web-based process described in Section 5), all associated personal data will be permanently deleted within thirty (30) calendar days, unless a longer retention period is required by applicable law (for example, anti-money laundering, regulatory audit, or fraud prevention obligations).

5. Your Rights and How to Exercise Them

5.1 Data Subject Rights

Depending on your jurisdiction, you have the following rights in relation to your personal data. These rights apply under the EU GDPR, the UK GDPR, the UAE PDPL, and the Singapore PDPA, subject to certain conditions and exceptions under each regime:

  1. Right of access (GDPR Art. 15 / UK GDPR Art. 15): the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of that data together with information about how it is processed.
  2. Right to rectification (GDPR Art. 16 / UK GDPR Art. 16 / PDPA s.22): the right to have inaccurate personal data corrected and incomplete data completed.
  3. Right to erasure (GDPR Art. 17 / UK GDPR Art. 17): the right to request deletion of your personal data, subject to the conditions set out in Sections 5.4–5.6 below.
  4. Right to restriction of processing (GDPR Art. 18 / UK GDPR Art. 18): the right to request that we limit how we process your personal data in certain circumstances.
  5. Right to data portability (GDPR Art. 20 / UK GDPR Art. 20): the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
  6. Right to object (GDPR Art. 21 / UK GDPR Art. 21): the right to object to processing based on legitimate interests or for direct marketing purposes.
  7. Right to withdraw consent (GDPR Art. 7(3) / PDPA s.16): where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at privacy@janusd.com. We will respond to your request within thirty (30) days, or within the timeframe required by applicable law.

5.2 Right to Lodge a Complaint with a Supervisory Authority

If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority in your jurisdiction:

  1. EU/EEA: the data protection authority in the EU/EEA Member State of your habitual residence, place of work, or place of the alleged infringement (GDPR Article 77).
  2. United Kingdom: the Information Commissioner’s Office (ICO) at ico.org.uk (UK GDPR Article 77).
  3. United Arab Emirates: the UAE Data Office established under Federal Decree-Law No. 45 of 2021.
  4. Singapore: the Personal Data Protection Commission (PDPC) at pdpc.gov.sg.

We encourage you to contact us first so that we may attempt to resolve your concern directly.

5.3 US State Privacy Rights

If you are a resident of California or another US state with applicable consumer privacy legislation (including the CCPA/CPRA, Virginia CDPA, Colorado CPA, Connecticut CTDPA, or similar state laws), you may have additional rights, including:

  1. the right to know what personal information we collect, use, and disclose;
  2. the right to request deletion of your personal information;
  3. the right to opt out of the “sale” or “sharing” of personal information for cross-context behavioural advertising; and
  4. the right to non-discrimination for exercising your privacy rights.

Janus Digital does not sell your personal information. Janus Digital does not share your personal information for cross-context behavioural advertising. If you wish to exercise any of the rights above, please contact us at privacy@janusd.com.

5.4 Updating Your Information

If your personal details change, you may update and modify your profile to keep it current by logging in to the App using your registered credentials.

5.5 In-App Account Deletion

At any time, you may delete your account and all associated personal data directly within the App. This option is accessible from the primary account settings screen. Deleting your account will permanently remove your personal profile and all records from our systems, subject to the retention timeline set out in Section 4.

5.6 Web-Based Account Deletion

If you have uninstalled the App or otherwise cannot access the in-app deletion function, you may request account and data deletion via our dedicated web portal at https://privacy.janusd.com/delete, or by emailing privacy@janusd.com with the subject line “Account Deletion Request”. Upon verification of your identity, we will process your deletion request within thirty (30) calendar days.

5.7 Scope of Deletion

A request to delete your account will result in the deletion of all associated personal data as disclosed in this Privacy Policy and in the applicable app store Data Safety / Privacy Nutrition Label declarations, including your Account Data (phone number), profile data, and Technical and Usage Data. We may retain limited data solely where required by law for fraud prevention, security auditing, or regulatory compliance, and will disclose any such retention at the time of your request.

6. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, Janus Digital will:

  1. notify the competent supervisory authority without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach (GDPR Article 33 / UK GDPR Article 33), unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons;
  2. notify the Personal Data Protection Commission (PDPC) in Singapore within three (3) calendar days of assessing that the breach is a notifiable data breach under the PDPA;
  3. notify the UAE Data Office in accordance with the timelines prescribed under UAE Federal Decree-Law No. 45 of 2021 and its implementing regulations; and
  4. notify you directly and without undue delay where the breach is likely to result in a high risk to your rights and freedoms (GDPR Article 34 / UK GDPR Article 34), or where required under the PDPA or UAE PDPL, providing a description of the nature of the breach, the likely consequences, and the measures taken or proposed to mitigate its effects.

7. Legal Disclosure

We may disclose your personal information where required by law, including to comply with a legal obligation, judicial proceedings, or court order, or to respond to a lawful request from a competent public authority.

Janus Digital will not disclose your personal information on the basis of its own commercial or operational interests alone. Any disclosure outside of a legal obligation will only be made where strictly necessary and proportionate, and on a lawful basis recognised under applicable data protection law.

8. Data Processing Jurisdictions and Cross-Border Transfers

Janus Digital Global FZE is headquartered at One Central, Dubai World Trade Centre Free Zone, United Arab Emirates, with operations in Singapore (Janus Digital Singapore Pte Ltd) and the United Kingdom. Your personal data may be processed and stored in any of these jurisdictions.

8.1 Applicable Data Protection Regimes

Where applicable, Janus Digital complies with the following data protection frameworks:

  1. the EU General Data Protection Regulation (Regulation (EU) 2016/679);
  2. the UK General Data Protection Regulation (as retained under the European Union (Withdrawal) Act 2018 and the Data Protection Act 2018);
  3. the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL); and
  4. Singapore’s Personal Data Protection Act 2012 (PDPA), as amended by the Personal Data Protection (Amendment) Act 2020.

8.2 UK GDPR Obligations

For users in the United Kingdom, Janus Digital processes personal data in accordance with the UK GDPR. Your data subject rights under the UK GDPR are set out in Section 5.1 above. Complaints may be directed to the Information Commissioner’s Office (ICO) as set out in Section 5.2(b). If Janus Digital is required to appoint a UK representative under Article 27 of the UK GDPR, details of the appointed representative will be published at privacy.janusd.com and updated in this Privacy Policy.

8.3 EU Representative

Janus Digital does not currently maintain a physical establishment in the European Union. Where the processing of personal data of EU data subjects triggers the appointment obligation under Article 27 of the GDPR, Janus Digital will appoint an EU Representative and publish their contact details at privacy.janusd.com and in this Privacy Policy. [To be updated upon appointment.]

8.4 Cross-Border Transfer Mechanisms

Where your personal data is transferred from one jurisdiction to another, we rely on legally recognised transfer mechanisms, including:

  1. Standard Contractual Clauses (SCCs) adopted by the European Commission, or the UK International Data Transfer Agreement / Addendum, as applicable;
  2. adequacy decisions issued by the European Commission or the UK Secretary of State; or
  3. other appropriate safeguards recognised under the applicable data protection regime, including binding corporate rules or your explicit consent where no other mechanism is available.

9. Age Requirement and Children’s Privacy

The Janus Digital App is intended solely for users aged 18 and over. You must be at least eighteen (18) years of age to create an account and use the App. In the Google Play Console, the App’s Target Audience is set to “18 and over”, and the App is not enrolled in Google’s Designed for Families programme.

Because the App is restricted to adults, the obligations under the U.S. Children’s Online Privacy Protection Act (COPPA), Article 8 of the GDPR, and equivalent international child data protection provisions do not apply to the App’s intended use. Notwithstanding the above, if we become aware that we have inadvertently collected personal information from any person under the age of 18, we will take steps to delete that information promptly.

10. Changes to This Privacy Policy

Janus Digital may update this Privacy Policy from time to time in accordance with applicable laws and regulations. Before any material modifications take effect, Janus Digital will notify you of the policy changes through the App’s in-app notification system, so that you are aware of how we collect and use your personal information, who may access such information, and under what circumstances we may disclose it.

Janus Digital reserves the right to modify this Privacy Policy at any time. We encourage you to review it periodically. The “Effective Date” at the top of this document indicates the date of the most recent revision.

11. App Store Platform Terms

The Janus Digital App is made available through the Apple App Store and Google Play Store. The following additional terms apply to users who download or use the App from these platforms.

11.1 Apple App Store

For users who download the App from the Apple App Store: this Privacy Policy is concluded between you and Janus Digital only, and not with Apple Inc. (“Apple”). Janus Digital, not Apple, is solely responsible for the App and the content and data practices described herein.

In compliance with Apple’s App Store Guidelines and the App Tracking Transparency framework, Janus Digital collects only the data categories disclosed in the App Store product page’s Privacy Nutrition Labels. We do not track you across other companies’ apps or websites without your permission. The App includes a Privacy Manifest (PrivacyInfo.xcprivacy) that declares all accessed system APIs and data types in accordance with Apple’s Required Reason API policy.

11.2 Google Play Store

For users who download the App from the Google Play Store: this Privacy Policy is concluded between you and Janus Digital only, and not with Google LLC (“Google”). Janus Digital, not Google, is solely responsible for the App and the content and data practices described herein.

In compliance with Google Play’s User Data policy and Data Safety requirements, Janus Digital has accurately disclosed data collection, usage, and sharing practices in the Google Play Store listing’s Data Safety section. Your phone number is declared as Personal and Sensitive User Data collected for App Functionality and linked to your identity. A Prominent Disclosure and affirmative consent mechanism is presented within the App before this data is collected.

In accordance with Google Play’s Account Deletion requirements, users may request account and data deletion both within the App and via the web-based process described in Section 5.6. The web deletion URL registered in the Play Console is: https://privacy.janusd.com/delete.

11.3 Third-Party Data Sharing

Janus Digital does not share your personal data with third-party advertising networks or analytics providers beyond what is strictly necessary for the operation of the App, unless you have given your explicit consent. We do not sell your personal data to any third party.

11.4 Data Collection Transparency

Janus Digital is committed to transparency regarding data collection. The data we collect is limited to what is disclosed in the respective app store listing (Apple App Store Privacy Nutrition Labels and Google Play Data Safety section). We collect the minimum data necessary for the App to function as intended.

11.5 Third-Party SDKs and Supply Chain Integrity

Janus Digital conducts regular audits of all third-party software development kits (SDKs) integrated into the App. All SDK data collection and system API usage is accurately reflected in our Apple Privacy Manifest and Google Play Data Safety declarations. We do not integrate third-party SDKs that engage in undisclosed data collection, device fingerprinting, or cross-app tracking.

12. Data Controller, Data Protection Officer, and Contact Information

12.1 Data Controller

The data controller responsible for your personal data is:

Janus Digital Global FZE
One Central, Dubai World Trade Centre Free Zone
P.O. Box [to be inserted], Dubai, United Arab Emirates
Email: privacy@janusd.com

12.2 Data Protection Officer

In accordance with Singapore’s Personal Data Protection Act (which mandates the designation of a Data Protection Officer) and as a matter of best practice across all jurisdictions in which we operate, Janus Digital has appointed a Data Protection Officer (DPO). The DPO may be contacted at: dpo@janusd.com.

12.3 EU Representative

Janus Digital does not currently maintain a physical establishment in the European Union. Where required under GDPR Article 27, Janus Digital will appoint an EU Representative and publish their name and contact details at privacy.janusd.com and in this Privacy Policy. [To be updated upon appointment.]

12.4 UK Representative

Where required under Article 27 of the UK GDPR, details of Janus Digital’s appointed UK representative will be published at privacy.janusd.com and updated in this Privacy Policy. [To be updated upon appointment.]