Privacy Policy
Last Updated on: 24 September 2026
1. Introduction & Identity of the Controller
Money Protects Capital Limited ("MPCL", "we", "us", "our") is a Category 3C firm regulated by the Dubai Financial Services Authority (DFSA), incorporated in the Dubai International Financial Centre (DIFC), Dubai, United Arab Emirates (License #7741).
MPCL is the Data Controller for personal data collected through moneyprotects.com, its sub-domains, the Money Protects App, the OptimizerAI tools, the MONIDR AI platform (chat and voice), the Knowledge Centre, the consultation booking system, the careers portal and our official communication channels (together, the "Platforms").
We process personal data in accordance with the DIFC Data Protection Law No. 5 of 2020 (as amended) and its Regulations, and with applicable DFSA conduct of business and anti-money-laundering rules.
Group entities. Money Protects Financial Services L.L.C (MPFS, UAE onshore) and Money Protects India Private Limited (MPI, India) may process personal data as separate controllers or as processors on our behalf, in each case under intra-group data-transfer arrangements and the law applicable to them (including, for MPI, India's Digital Personal Data Protection Act, 2023). Where a group entity is the controller for a specific service, this will be made clear at the point of collection.
Questions about this Policy or your personal data: [email protected].
2. What Personal Data We Collect
- Identity Data: full name, nationality, date of birth, Emirates ID or passport details (for KYC/AML and client classification).
- Contact Data: email address, telephone/WhatsApp number, postal address.
- Financial & Suitability Data: mortgage and loan details, property information and valuations, income and net-worth indicators, investment objectives and experience — where required to classify you as a Professional Client and to assess product suitability.
- Tool Input Data: figures you enter into OptimizerAI or the Money Protects App (loan amounts, rates, tenors, rental figures) and the scenarios generated from them.
- Communications Data: emails, enquiry-form submissions, consultation notes and recordings (where notified), and transcripts of chat or voice interactions with the MONIDR AI platform.
- Consultation Data: bookings, attendance, product interests and follow-ups.
- Careers Data: CVs and supporting information submitted through the careers portal.
- Technical Data: IP address, browser and device identifiers, pages visited, referral source, time and duration of visits — collected via cookies and similar technologies only in accordance with your consent choices (see our Cookie Policy).
We do not intentionally collect special-category data. If you volunteer such information (for example in a consultation), we process it only to the extent necessary and with your explicit consent where the law requires it.
3. How We Collect Your Personal Data
We collect personal data when you visit or use our Platforms; submit an enquiry or contact form; interact with MONIDR by chat or voice; use OptimizerAI or the Money Protects App; book a consultation; download a brochure or gated document; apply for a role through the careers portal; correspond with us by email, telephone or messaging; or become a client (subject to a separate Client Agreement).
We may also receive personal data from KYC and screening providers, credit-reference agencies, introducers and our regulated business partners, and from publicly available sources, in each case where permitted by law.
4. Legal Basis for Processing
Under Article 10 of the DIFC DP Law we rely on the following lawful bases:
| Purpose | Legal basis |
|---|---|
| Responding to enquiries, providing pre-contractual information and delivering financial services | Art. 10(1)(b) — Contractual necessity |
| Client classification, KYC/AML, sanctions screening and regulatory reporting | Art. 10(1)(c) — Legal obligation |
| Operating OptimizerAI, MONIDR and the App at your request | Art. 10(1)(b) — Contractual necessity / Art. 10(1)(a) — Consent |
| Recruitment and assessment of applicants | Art. 10(1)(b) — Pre-contractual steps / Art. 10(1)(f) — Legitimate interests |
| Security, fraud prevention, service improvement and aggregated analytics | Art. 10(1)(f) — Legitimate interests |
| Marketing communications and non-essential cookies | Art. 10(1)(a) — Consent (withdrawable at any time) |
5. How We Use Your Personal Data
- To determine whether you qualify as a Professional Client and to assess suitability for MESP — Mortgage EMI Sleeping Period™, ERDR — Equity Release–Double Rental™ and FEFL — Fixed EMI for Life™, and our treasury and wealth-advisory services.
- To conduct AML, KYC, sanctions and investor-suitability checks required by DFSA Rules and UAE federal law.
- To generate the indicative scenarios, reports and term-sheet drafts you request through OptimizerAI, MONIDR or the App.
- To schedule, hold, record (where notified) and follow up consultations.
- To respond to enquiries and to communicate with you about services you have shown interest in, with the ability to opt out at any time.
- To assess job applications and maintain a talent pool for the period stated in Section 9.
- To secure, monitor and improve our Platforms using aggregated or anonymised analytics.
- To comply with our legal and regulatory obligations and to establish, exercise or defend legal claims.
6. Artificial Intelligence & Automated Processing
Some of our Platforms use artificial intelligence. OptimizerAI and the Money Protects App generate indicative financial scenarios from the figures you enter. MONIDR provides conversational chat and voice assistance using speech-to-text, language-model and text-to-speech technology supplied by third-party providers under data-processing agreements.
- No solely automated decisions with legal effect. AI outputs are indicative and informational. Any decision about your eligibility, classification, suitability or the terms of any product is reviewed and made by our authorised personnel. You have the right under Article 38 of the DIFC DP Law not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and to request human review.
- Voice and chat interactions may be transcribed and stored to provide the service, ensure quality and meet regulatory record-keeping duties. You will be informed when you are interacting with an AI agent.
- No model training on your data. We do not permit our AI providers to use your personal data to train their general models.
- Limitations. AI systems can be inaccurate. Please verify important information with our team before acting on it.
7. Sharing Your Personal Data
We do not sell personal data. We share it only as follows:
- Regulators and authorities: the DFSA, the DIFC Commissioner of Data Protection, the UAE Financial Intelligence Unit, courts and law-enforcement agencies, where required by law.
- Group entities: MPFS and MPI, for the purposes described in this Policy and under intra-group data-transfer agreements.
- Service providers acting as processors: including Microsoft (Teams, email and productivity), ElevenLabs (AI voice and conversation), Google (analytics, consent-gated), Meta (advertising measurement, consent-gated), transactional email delivery, Cloudflare (security and content delivery), and our cloud-hosting and application-platform providers — all bound by written data-processing agreements and appropriate security obligations.
- Professional advisers: legal, compliance, audit and tax firms, under confidentiality obligations.
- Banks, custodians and financial counterparties: solely for the delivery of a product or service you have contracted.
- Business transfers: in connection with a merger, acquisition or reorganisation, subject to confidentiality and continuity of this Policy.
8. International Data Transfers
Some recipients are located outside the DIFC and the UAE, including in the United States, the European Economic Area, the United Kingdom and India. Where we transfer personal data outside the DIFC we rely on Article 26 (adequacy decisions of the DIFC Commissioner) or Article 27 (appropriate safeguards, including the DIFC Standard Contractual Clauses) of the DIFC DP Law, together with transfer-risk assessments and supplementary technical measures such as encryption.
Visitors from the EEA, the United Kingdom and India. If you access our Platforms from these jurisdictions you may have rights under the EU or UK General Data Protection Regulation or India's Digital Personal Data Protection Act, 2023. We honour requests to exercise those rights to the extent they apply, through the contact details in Section 15. Our services are directed at Professional Clients and we do not target consumers in those jurisdictions.
9. Data Retention
| Category | Retention period |
|---|---|
| Client, KYC and transaction records | Minimum 6 years after the end of the relationship, as required by DFSA record-keeping rules; longer where litigation or regulatory enquiry requires |
| Website enquiries and prospect communications | 2 years from last interaction |
| Consultation records, MONIDR transcripts and OptimizerAI inputs (non-client) | 3 years |
| Careers applications (CVs) | 12 months from submission, unless you request earlier removal (Section 12) |
| Cookie consent records | 12 months |
When data is no longer required it is securely deleted or irreversibly anonymised.
10. Your Rights
As a data subject under the DIFC DP Law you have the right to: access your personal data; rectify inaccurate or incomplete data; erase data where there is no lawful ground for continued processing; restrict processing in certain circumstances; object to processing based on legitimate interests and to direct marketing at any time; receive your data in a portable, machine-readable format (portability); withdraw consent at any time without affecting prior lawful processing; and not be subject to solely automated decision-making with legal or similarly significant effects.
To exercise any right contact [email protected]. We will respond within one month of receipt, extendable in complex cases as permitted by the DIFC DP Law. We may need to verify your identity before acting. Exercising your rights is free of charge except where requests are manifestly unfounded or excessive.
11. Security & Breach Notification
We apply technical and organisational measures appropriate to the risk, including TLS encryption in transit, encryption of sensitive data at rest, role-based access controls, multi-factor authentication for administrative access, one-time-passcode gating for private portals, logging and monitoring, vendor due diligence and periodic security reviews. No method of transmission or storage is entirely secure; please do not send us sensitive information through unsecured channels.
In the event of a personal-data breach that is likely to result in a risk to your rights, we will notify the DIFC Commissioner of Data Protection as soon as practicable in accordance with Article 41 of the DIFC DP Law, and will notify you without undue delay where the breach is likely to result in a high risk to you.
12. Careers & Job Applicants
CVs are accepted only through the careers form on our website and are stored in a secure, access-controlled vault. We do not accept CVs by email. To withdraw your application and have your CV removed at any time, email [email protected] quoting your application reference; that mailbox is used solely for removal requests. Applicant data is used only for recruitment, is not shared outside the group and its professional advisers, and is deleted in line with Section 9.
13. Cookies & Similar Technologies
We use strictly necessary cookies to run the Platforms and, only with your consent, analytics and marketing cookies. Non-essential tags (including Google Analytics and Meta Pixel) are disabled by default and load only after you accept them. You can accept, reject or customise cookies through the banner on your first visit and change your choice at any time. Rejecting is as easy as accepting. Full details are in our Cookie Policy.
14. Children
Our Platforms and services are directed at adults aged 18 or over who are, or may qualify as, Professional Clients. We do not knowingly collect personal data from anyone under 18. If you believe we hold such data, please contact us and we will delete it.
15. Contact, Complaints & Changes
Data Protection Officer
Money Protects Capital Limited
Office P5-10, Damac Park Towers, Tower A, DIFC, Dubai, United Arab Emirates
Email: [email protected]
Customer care: [email protected]
If you are dissatisfied with our response you may lodge a complaint with the DIFC Commissioner of Data Protection (difc.ae) or, where applicable, with the supervisory authority in your jurisdiction.
We review this Policy at least annually and whenever our processing changes. Material changes will be highlighted on this page with a new effective date. The version published here is the current one.