A policy for the protection of code, systems, artificial intelligence, websites, data and digital assets.
General principle and ownership
All technical and digital work, assets, systems and developments that are created, developed, designed, customised, trained, operated or activated for the benefit of the Group or any of its subsidiaries — using the Group's resources, data, systems, devices, accounts, subscriptions or infrastructure, or the working time allocated to it, or pursuant to an assignment issued by it — are assets and rights belonging to the Group or to the relevant subsidiary, in accordance with the applicable contracts, agreements, policies and laws.
This includes anything developed wholly or partly by:
- Employees.
- Trainees.
- Officers.
- Managers.
- Programmers.
- Developers.
- Designers.
- Consultants.
- Contractors.
- Suppliers.
- Technology companies.
- Service providers.
- Independent contractors.
- Or any person or entity working for the benefit of the Group or using its resources, systems or data.
Scope of digital assets and rights
Digital and technical assets include, by way of example and not limitation:
- Program code.
- Source code.
- Executable code.
- Software and applications.
- Websites.
- Digital platforms and portals.
- Intelligent systems.
- Artificial-intelligence models.
- Artificial-intelligence tools that are developed or customised.
- AI agents.
- Intelligent assistants.
- Prompts.
- Intelligent instructions and rules.
- Algorithms.
- Automation systems.
- Automated operating systems.
- Databases.
- Database structures.
- Knowledge bases.
- Training data.
- APIs.
- Software integrations.
- Control panels.
- Electronic forms.
- Workflows.
- Business logic.
- Assessment and classification systems.
- Analysis tools.
- Client and opportunity discovery systems.
- Data-processing systems.
- Decision-making systems.
- Monitoring and alerting systems.
- Intelligent reporting tools.
- Technical materials and documentation.
- Operating manuals.
- Training manuals.
- Written content.
- Original designs.
- User interfaces.
- Original graphics and images.
- Logos.
- Trade marks.
- Trade names.
- Visual identity.
- Operational plans.
- Client journey maps.
- Confidential data.
- Unpublished technical and commercial information.
- And any other digital or technical asset or development created for the benefit of the Group.
Development using the Group's resources
Every program, system, artificial-intelligence model, tool, item of code, design or technical project developed wholly or partly:
- During working time;
- Or using the Group's devices;
- Or using its accounts;
- Or using its subscriptions;
- Or using its data;
- Or using its technical infrastructure;
- Or using its platforms;
- Or pursuant to an administrative or operational assignment issued by it;
- Or for the purposes of the business of the Group or any of its subsidiaries;
is subject to the legal and contractual rights of the Group or of the relevant subsidiary.
The participation of any employee, trainee, developer, consultant or contractor in creating or developing a system does not of itself constitute authorisation for that person to use, copy, exploit or reproduce it outside the scope of their work.
Joint and partial development
A project or system need not have been developed entirely within the Group for rights connected to the Group's contribution to it to arise.
Where any of the following has been used:
- The Group's resources.
- Its data.
- Its funding.
- Its personnel.
- Its internal expertise.
- Its accounts.
- Its systems.
- Its tools.
- Its plans.
- Its operational rules.
- Or its approved assignments.
in developing a project, system or digital asset, the rights relating to it are governed by the contracts and agreements in place, the proportion of each party's participation, and the nature of each party's legal ownership.
Updates and future developments
The Group's rights extend, to the extent permitted by contract and law, to all:
- Updates.
- Improvements.
- New releases.
- Additions.
- Modifications.
- Customisations.
- Derivative developments.
- Training of artificial-intelligence models.
- Fine-tuning.
- Prompt refinement.
- Algorithm development.
- Knowledge-base development.
- Database updates.
- Automation-system development.
- System restructuring.
- Addition of new features.
- Development of more advanced versions of the original system.
whenever this is done for the benefit of the Group, using its resources, data or systems, or within approved duties and assignments.
Prohibitions on employees, trainees and contractors
No person may, without the prior written and approved consent of the competent management:
- Copy any code.
- Copy a system or program.
- Copy an artificial-intelligence model.
- Send code to a personal email address.
- Store files in personal cloud accounts.
- Load code onto unauthorised devices.
- Transfer databases.
- Copy databases.
- Share confidential data.
- Share internal prompts.
- Share system configurations.
- Share API keys.
- Share passwords.
- Share access tokens.
- Share user accounts.
- Photograph technical or confidential content without authorisation.
- Extract content from internal systems.
- Use the Group's assets in a personal project.
- Use them for the benefit of another entity.
- Use them for the benefit of a competing company.
- Resell them.
- Re-license them.
- Publish them.
- Redistribute them.
- Create a copy of them for the benefit of another activity.
- Transfer them to a third party.
- Retain copies of them after the end of employment, training or engagement.
Protection of websites and digital platforms
The websites, platforms and digital portals of the Group and its subsidiaries form part of the Group's digital assets, in respect of the elements, content, systems and rights that the Group owns or is legally authorised to use.
This includes, depending on the website or platform concerned:
- Code.
- Content.
- Original designs.
- Electronic forms.
- Internal systems.
- Databases.
- Intelligent tools.
- Clients' digital journeys.
- Request systems.
- Interactive tools.
- Reports.
- Marks.
- Logos.
- Names.
- Original visual elements.
Visitor access to the websites
A visitor's mere access to any of the Group's websites or platforms confers no ownership right in the assets or rights present on the site.
Nor does accessing or using the site constitute:
- A licence to copy the content.
- A licence to reproduce the systems.
- A licence to use the content commercially.
- A waiver of intellectual-property rights.
- Authorisation to use the trade marks.
- Authorisation to extract confidential data.
- Authorisation to recreate the technical systems.
Use of the site is limited to the lawful and ordinary use for which it was made available, consistent with the terms of use and with the law.
Prohibition on copying from the websites
The following acts are prohibited without prior written authorisation, wherever they concern a protected asset or protected content belonging to the Group:
- Copying website content.
- Copying original texts.
- Copying protected designs.
- Copying original images and graphics.
- Copying electronic forms.
- Copying site pages for the purpose of commercial re-use.
- Republishing content in the name of another party.
- Copying code.
- Extracting databases without authorisation.
- Extracting confidential information.
- Copying intelligent tools.
- Copying internal prompts.
- Copying protected working systems or software.
- Removing ownership-rights data.
- Removing the name of the rights holder.
- Altering or concealing copyright notices.
Imitation, emulation and unlawful use
The Group and its subsidiaries reserve all of their legal rights against any person or entity that, without legal basis or approved authorisation, imitates, uses or exploits protected assets belonging to the Group.
This includes, according to the nature of the right:
- Logos.
- Trade marks.
- Trade names.
- Visual identity.
- Original designs.
- Creative content.
- Code and software.
- Protected databases.
- Electronic forms.
- Software systems.
- Written materials.
- Protected digital tools or products.
It also includes presenting an asset or product belonging to the Group as belonging to another person or company.
General ideas and unprotected elements
This policy does not seek to claim ownership of general ideas, methods, functions or common practices in which the law grants no exclusive right.
Protection extends instead to the assets, rights, works, data, marks, trade secrets and contractual rights that the Group or its subsidiaries own or are legally authorised to use.
Unauthorised access
No person may attempt to:
- Access a system they are not authorised to use.
- Enter internal pages they are not authorised to view.
- Exceed the level of permission granted to them.
- Circumvent protection systems.
- Circumvent authentication mechanisms.
- Use another person's account.
- Use passwords that do not belong to them.
- Obtain access tokens without authorisation.
- Access confidential data without permission.
- Extract internal data.
- Access source code without authorisation.
- Modify data without permission.
- Delete data without permission.
- Download data without authorisation.
- Tamper with the Group's systems.
- Disable the systems.
- Deliberately affect the efficiency or operation of the systems.
Reverse engineering and extraction of technology
It is prohibited, within the limits permitted by law and by contract, to attempt to:
- Decompile or analyse the systems without authorisation.
- Extract internal code.
- Extract the logic of a system.
- Access components that are not publicly available.
- Circumvent security controls.
- Extract databases without authorisation.
- Rebuild a protected system using materials or code obtained unlawfully.
Use of external artificial-intelligence tools
No confidential or technical information belonging to the Group may be entered into unapproved external artificial-intelligence tools or accounts.
This includes:
- Source code.
- Confidential client data.
- Personal data that may not be shared.
- Databases.
- Confidential prompts.
- Internal knowledge bases.
- API keys.
- Passwords.
- Access tokens.
- Confidential contracts.
- Confidential legal information.
- Unpublished financial data.
- Strategic plans.
- Business plans.
- Internal documents.
- Unpublished operational information.
Approved accounts, tools and platforms must be used in accordance with the Group's information-security and data-protection policies.
Protection of data and knowledge bases
Databases, knowledge bases and commercial, technical and operational information that is not publicly available are important assets of the Group.
Without approved authorisation, they may not be subject to:
- Copying.
- Downloading.
- Transfer.
- Sale.
- Sharing.
- Publication.
- Disclosure or leaking.
- Use for personal benefit.
- Use for the benefit of an external party.
- Use to establish a competing activity.
- Use to train an external system.
- Use outside the authorised purpose.
This applies with due regard to the rights of data subjects and to the applicable data-protection and privacy laws.
Confidentiality and trade secrets
All information that is not publicly available and relates to the Group's business, and that is confidential, commercial or technical in nature, is information that must be protected in accordance with the applicable contracts, laws and approved policies.
It may include:
- Strategies.
- Market studies.
- Financial information.
- Client data.
- Expansion plans.
- Internal pricing rules.
- Commercial relationships.
- Supplier data.
- Client sources.
- Assessment algorithms.
- Operating plans.
- Technical information.
- Code.
- Internal working procedures.
- Development documentation.
The Group's accounts and devices
The accounts, devices, services and subscriptions provided by the Group are corporate working tools.
It is not permitted to:
- Share accounts without authorisation.
- Grant an external party access rights.
- Change recovery details for personal purposes.
- Use a corporate account after the expiry of its validity.
- Transfer corporate data to a personal account.
- Retain passwords or access keys after the end of the relationship.
- Use the Group's devices for purposes that put the security of the systems at risk.
Retention of digital evidence
The Group reserves the right, in accordance with the law and with the applicable data-protection and privacy policies, to use the technical means necessary to protect its systems and assets and to document the activities relating to them.
Those means may include:
- Sign-in logs.
- User logs.
- Permission logs.
- Download logs.
- Modification logs.
- Upload logs.
- API logs.
- System logs.
- Cybersecurity logs.
- Records of unauthorised access attempts.
- Backups.
- Technical data relating to devices and accounts, where the law permits.
These records may be used in internal investigations, in the protection of rights, or in legal proceedings, in accordance with the law.
Discovery of copying, imitation or unauthorised use
If the Group discovers that a person or entity has copied, imitated, exploited or used one of its assets without authorisation, it is entitled to take appropriate measures to preserve its rights.
It is not a requirement that the breach was committed by an employee or contractor.
This policy also extends, according to the nature of the incident, to any:
- Site visitor.
- Platform user.
- Company.
- Competitor.
- Service provider.
- Current or former employee.
- Contractor.
- Developer.
- Or any third party.
The Group's measures in the event of a breach
Where a breach is discovered or seriously suspected, the Group and its subsidiaries reserve the right to take such legal, technical and administrative measures as are necessary, according to each case.
These may include:
- Suspending access rights.
- Cancelling the account.
- Disabling the account or the access keys.
- Protecting the systems and data.
- Preserving digital evidence.
- Opening an internal investigation.
- Documenting the incident.
- Issuing an administrative warning.
- Issuing a legal warning.
- Requiring the person or entity to cease use.
- Requesting removal of the infringing content.
- Requesting deletion of unauthorised copies.
- Demanding the return of the assets or data.
- Contacting the hosting provider.
- Contacting the platform hosting the infringing content.
- Submitting takedown or blocking requests where legally available.
- Filing a complaint with the competent authorities.
- Taking the civil, commercial or criminal measures available in law.
- Bringing proceedings before the courts or the competent authorities.
- Claiming compensation where the legal grounds for it are established.
- Taking any other measure permitted by law.
The Group's right to bring proceedings
The Group and its subsidiaries reserve the right to bring proceedings or take appropriate legal measures against any natural or legal person shown to have unlawfully infringed one of their protected rights or assets.
This includes, according to the incident:
- Unlawful copying.
- Unauthorised use.
- Infringement of copyright.
- Infringement of trade marks.
- Unlicensed use of digital assets.
- Unauthorised obtaining of confidential information.
- Unauthorised access to the systems.
- Data leakage.
- Unlawful use of commercial or technical information.
- Or any other act constituting a breach under the applicable laws.
The right to claim compensation
The Group and its subsidiaries reserve the right to claim compensation for damage and loss legally shown to have resulted from an infringement of their rights or assets.
A claim may cover, according to the nature of the damage and to the extent permitted by law:
- Financial losses.
- Commercial damage.
- The costs of restoring the systems.
- The costs of technical investigation.
- The costs of addressing a leak or breach.
- Damage resulting from unlawful use.
- Damage connected to the brand or the commercial activity.
- And any other damage or expense recognised by law and established before the competent authority.
This policy does not constitute an automatic or advance determination of the value of compensation.
Any claim is assessed in accordance with the contracts, the evidence, the law and the decisions issued by the competent judicial authorities.
Ceasing a breach does not extinguish the right to compensation
Where the infringing person:
- Deletes the copy;
- Or removes the content;
- Or ceases the use;
- Or closes the infringing site;
- Or returns the data;
that does not of itself extinguish the Group's rights to take legal measures or to claim compensation for earlier damage, where there is a legal basis for doing so.
No waiver of rights
The Group's not taking immediate action in respect of a particular breach does not constitute:
- A waiver of its rights.
- Acceptance of the breach.
- A licence to use the asset.
- A relinquishment of intellectual property.
- A relinquishment of the right to claim.
- Or implied consent to continued use.
The Group reserves the right to take appropriate action at such time as the law permits.
End of employment, training or engagement
On the end of any person's relationship with the Group, that person is obliged, in accordance with their contract and the applicable policies, to:
- Hand over code.
- Hand over project files.
- Hand over documents.
- Hand over devices.
- Return assets.
- Hand over corporate accounts in accordance with the approved procedures.
- Hand over access keys.
- Return data.
- Cooperate in the transfer of knowledge.
- Cease using their permissions.
- Delete unauthorised copies held on personal devices or accounts.
- Not retain the Group's data outside the authorised frameworks.
The Group may require a written or electronic acknowledgement that the handover has been completed.
Continuation of obligations after the relationship ends
The obligations relating to:
- Confidentiality.
- Data protection.
- Trade secrets.
- Protection of intellectual property.
- Not retaining assets.
- Not using code and systems without authorisation.
- Returning assets.
- Protecting accounts and data.
continue after the end of the employment, training or contractual relationship, to the extent permitted by the applicable laws and contracts.
Precedence of contracts and policies
This policy is to be read together with:
- Employment contracts.
- Training contracts.
- Development contracts.
- Programmers' contracts.
- Consultants' contracts.
- Suppliers' contracts.
- Non-disclosure agreements (NDAs).
- Intellectual-property rights agreements.
- Rights-assignment agreements, where required.
- Website terms of use.
- The privacy policy.
- The data-protection policy.
- The information-security policy.
- The artificial-intelligence use policy.
- Access and permission policies.
- The relevant commercial agreements.
In the event of a conflict, reference is made to the binding laws, agreements and contracts according to the nature of each case.
No implied rights are granted
Access to any of the following does not grant:
- A website.
- A platform.
- A control panel.
- A system.
- An account.
- An application.
- A database.
- A file.
- A program.
any ownership right or licence going beyond the limits of the use expressly authorised.
The approved corporate rule
Everything built, developed, designed, customised, trained or operated for the benefit of the Group, using its resources, data, systems, accounts or technical infrastructure, or pursuant to an assignment approved by it, constitutes an asset of the Group or of the relevant subsidiary, in accordance with the applicable contracts, agreements and laws.
Making any website, system, platform or content available to the public does not mean that the Group waives its rights in it, and does not grant any person the right to copy, imitate, exploit or commercially re-use protected assets without authorisation or legal basis.
The Group and its subsidiaries reserve all of their rights to protect their code, systems, data, websites, marks, content and digital assets, and to take appropriate administrative, technical and legal measures, including bringing proceedings and claiming compensation where the breach and the damage are established in accordance with the law.
Official UAE legal basis
This policy is founded, according to the nature of each right or incident and the scope of application of the legislation, on the laws and legislation in force in the United Arab Emirates, including:
- Federal Decree-Law No. (38) of 2021 on Copyright and Neighbouring Rights.
- Federal Decree-Law No. (36) of 2021 on Trade Marks.
Federal Decree-Law No. (34) of 2021 on Combating Rumours and Cybercrime also contains provisions relevant to cybercrime and to unlawful access to, or dealing with, certain data and information, including the provisions concerning confidential data and information of financial, commercial and economic institutions, in accordance with the scope of application, conditions and constituent elements specified in that law.
This policy applies with due regard to any amendments, legislation, decisions or implementing regulations in force or subsequently issued in the United Arab Emirates, and so as not to conflict with the applicable laws and regulations.
Closing legal notice
The purpose of this policy is to regulate and protect the intellectual property and the digital and technical assets of the Group and its subsidiaries. No provision of it is to be construed as granting the Group rights beyond those established by the applicable laws, contracts or licences.
Liability, measures and compensation are determined in each case on the basis of the nature of the incident, the evidence, the contracts, the applicable legislation and the decisions of the competent authorities.
All rights are reserved to the Group and its subsidiaries in accordance with the law.
