Unified Policy for the Protection of Intellectual Property, Digital Assets and Intelligent Systems
Policy for the protection of code – systems – artificial intelligence – websites – data – digital assets
This policy governs the protection of the intellectual property and the digital and technical assets of the Group and its subsidiaries. It is read together with the applicable contracts, agreements, policies and laws.
1. General Principle and Ownership
All works, assets, systems and technical and digital developments that are created, developed, designed, customised, trained, operated or activated for the benefit of the Group or any of its subsidiaries — using the Group's resources, data, systems, devices, accounts, subscriptions, infrastructure or allocated working time, or pursuant to an assignment issued by it — constitute assets and rights belonging to the Group or to the relevant subsidiary, in accordance with the applicable contracts, agreements, policies and laws.
This includes anything developed wholly or partly by:
- Employees.
- Trainees.
- Officers.
- Managers.
- Programmers.
- Developers.
- Designers.
- Consultants.
- Contractors.
- Suppliers.
- Technology companies.
- Service providers.
- Independent contractors.
- Or any person or entity working for the Group or using its resources, systems or data.
2. Scope of Digital Assets and Rights
Digital and technical assets include, by way of example and not limitation:
- Program code.
- Source code.
- Executable code.
- Programs and applications.
- Websites.
- Digital platforms and portals.
- Intelligent systems.
- Artificial intelligence models.
- AI tools that are developed or customised.
- AI agents.
- Intelligent assistants.
- Prompts.
- Intelligent instructions and rules.
- Algorithms.
- Automation systems.
- Automated operating systems.
- Databases.
- Database structures.
- Knowledge bases.
- Training data.
- APIs.
- Software integrations.
- Dashboards.
- Electronic forms.
- Workflows.
- Business logic.
- Evaluation and classification systems.
- Analysis tools.
- Client and opportunity discovery systems.
- Data processing systems.
- Decision-making systems.
- Follow-up and alert systems.
- Intelligent reporting tools.
- Technical materials and documents.
- Operating manuals.
- Training manuals.
- Written content.
- Original designs.
- User interfaces.
- Original graphics and images.
- Logos.
- Trademarks.
- Trade names.
- Visual identity.
- Operational plans.
- Customer journey maps.
- Confidential data.
- Unpublished technical and commercial information.
- And any other digital or technical asset or development created for the benefit of the Group.
3. Development Using the Group's Resources
Every program, system, artificial intelligence model, tool, code, design or technical project developed wholly or partly:
- During working hours;
- Or using the Group's devices;
- Or using its accounts;
- Or using its subscriptions;
- Or using its data;
- Or using its technical infrastructure;
- Or using its platforms;
- Or pursuant to an administrative or operational assignment issued by it;
- Or for the business purposes of the Group or any of its subsidiaries;
is subject to the legal and contractual rights of the Group or of the relevant subsidiary.
The participation of any employee, trainee, developer, consultant or contractor in creating or developing a system does not constitute automatic authorisation for them to use, copy, exploit or reproduce it outside the scope of work.
4. Joint and Partial Development
A project or system need not have been developed entirely within the Group for rights connected to the Group's contribution to arise.
Where any of the following were used:
- The Group's resources.
- Its data.
- Its funding.
- Its employees.
- Its internal expertise.
- Its accounts.
- Its systems.
- Its tools.
- Its plans.
- Its operating rules.
- Or its approved assignments.
in developing a project, system or digital asset, the related rights are governed by the contracts, the agreements, the share of participation and the nature of each party's legal ownership.
5. Updates and Future Developments
The Group's rights extend, to the extent permitted by contracts and laws, to all of the following:
- Updates.
- Improvements.
- New versions.
- Additions.
- Modifications.
- Customisations.
- Derivative developments.
- Artificial intelligence model training.
- Fine-tuning.
- Prompt optimisation.
- Algorithm development.
- Knowledge base development.
- Database updates.
- Automation system development.
- System restructuring.
- Addition of new features.
- Development of more advanced versions of the original system.
whenever carried out for the benefit of the Group, or using its resources, data or systems, or within approved tasks and assignments.
6. Prohibitions on Employees, Trainees and Contractors
No person may, without prior written approval from the competent management, do any of the following:
- Copy any code.
- Copy a system or program.
- Copy an artificial intelligence model.
- Send code to a personal email address.
- Store files on personal cloud accounts.
- Upload code to unauthorised devices.
- Transfer databases.
- Copy databases.
- Share confidential data.
- Share internal prompts.
- Share system configurations.
- Share API keys.
- Share passwords.
- Share access tokens.
- Share user accounts.
- Photograph technical or confidential content without authorisation.
- Extract content from internal systems.
- Use the Group's assets in a personal project.
- Use them for the benefit of another party.
- Use them for the benefit of a competing company.
- Resell them.
- Sub-license them.
- Publish them.
- Redistribute them.
- Create a copy of them for another activity.
- Transfer them to a third party.
- Retain copies of them after the end of employment, training or contract.
7. Protection of Websites and Digital Platforms
The websites, platforms and digital portals of the Group and its subsidiaries form part of the Group's digital assets, in respect of the elements, content, systems and rights that the Group owns or is legally authorised to use.
This includes, depending on the site or platform:
- Code.
- Content.
- Original designs.
- Electronic forms.
- Internal systems.
- Databases.
- Intelligent tools.
- Digital customer journeys.
- Order systems.
- Interactive tools.
- Reports.
- Marks.
- Logos.
- Names.
- Original visual elements.
8. Visitor Access to the Websites
Merely visiting any website or platform belonging to the Group grants the visitor no ownership right in the assets or rights present on that site.
Accessing or using the site is likewise not:
- A licence to copy the content.
- A licence to reproduce the systems.
- A licence for commercial use of the content.
- A waiver of intellectual property rights.
- Authorisation to use the trademarks.
- Authorisation to extract confidential data.
- Authorisation to recreate the technical systems.
Use of the site is limited to the lawful and ordinary use for which the site was made available, consistent with the terms of use and the law.
9. Prohibition on Copying from the Websites
Without prior written authorisation, the following acts are prohibited wherever they relate to a protected asset or content belonging to the Group:
- Copying website content.
- Copying original texts.
- Copying protected designs.
- Copying original images and graphics.
- Copying electronic forms.
- Copying site pages for commercial reuse.
- Republishing content under another party's name.
- Copying code.
- Extracting databases without authorisation.
- Extracting confidential information.
- Copying intelligent tools.
- Copying internal prompts.
- Copying protected work systems or software.
- Removing ownership metadata.
- Removing the name of the rights holder.
- Altering or concealing copyright notices.
10. Imitation, Emulation and Unlawful Use
The Group and its subsidiaries reserve all their legal rights against any person or entity that, without legal basis or approved authorisation, imitates, uses or exploits protected assets belonging to the Group.
This includes, according to the nature of the right:
- Logos.
- Trademarks.
- Trade names.
- Visual identity.
- Original designs.
- Creative content.
- Code and software.
- Protected databases.
- Electronic forms.
- Software systems.
- Written materials.
- Protected digital tools or products.
It also includes presenting an asset or product belonging to the Group as belonging to another person or company.
11. General Ideas and Unprotected Elements
This policy does not seek to claim ownership of general ideas, methods, functions or common practices in respect of which the law grants no exclusive right.
Protection extends instead to the assets, rights, works, data, marks, trade secrets and contractual rights owned by the Group or its subsidiaries, or which they are legally authorised to use.
13. Reverse Engineering and Technology Extraction
Within the limits permitted by law and contract, it is prohibited to attempt to:
- Decompile or analyse the systems without authorisation.
- Extract internal code.
- Extract system logic.
- Access components not available to the public.
- Bypass security controls.
- Extract databases without authorisation.
- Rebuild a protected system using materials or code obtained unlawfully.
14. Use of External Artificial Intelligence Tools
No confidential or technical information belonging to the Group may be entered into unapproved external artificial intelligence tools or accounts.
This includes:
- Source code.
- Confidential client data.
- Personal data that may not be shared.
- Databases.
- Confidential prompts.
- Internal knowledge bases.
- API keys.
- Passwords.
- Access tokens.
- Confidential contracts.
- Confidential legal information.
- Unpublished financial data.
- Strategic plans.
- Business plans.
- Internal documents.
- Unpublished operational information.
Approved accounts, tools and platforms must be used in accordance with the Group's information security and data protection policies.
15. Protection of Data and Knowledge Bases
Databases, knowledge bases and commercial, technical and operational information that is not publicly available are considered important assets of the Group.
Without approved authorisation, they may not be:
- Copied.
- Downloaded.
- Transferred.
- Sold.
- Shared.
- Published.
- Leaked.
- Used for personal benefit.
- Used for the benefit of an external party.
- Used to establish a competing activity.
- Used to train an external system.
- Used outside the authorised purpose.
This applies with due regard to the rights of data subjects and to the applicable data protection and privacy laws.
16. Confidentiality and Trade Secrets
All information relating to the Group's business that is not publicly available and that is confidential, commercial or technical in nature is information that must be protected in accordance with the approved contracts, laws and policies.
This may include:
- Strategies.
- Market studies.
- Financial information.
- Client data.
- Expansion plans.
- Internal pricing rules.
- Commercial relationships.
- Supplier data.
- Client sources.
- Evaluation algorithms.
- Operating plans.
- Technical information.
- Code.
- Internal work procedures.
- Development documentation.
17. Group Accounts and Devices
The accounts, devices, services and subscriptions provided by the Group are institutional work tools.
It is not permitted to:
- Share accounts without authorisation.
- Grant an external party access rights.
- Change recovery details for personal purposes.
- Use an institutional account after its validity has ended.
- Transfer institutional data to a personal account.
- Retain passwords or access keys after the relationship has ended.
- Use the Group's devices for purposes that endanger the security of the systems.
18. Preservation of Digital Evidence
In accordance with the law and the applicable data protection and privacy policies, the Group reserves the right to use the technical means necessary to protect its systems and assets and to document the activities relating to them.
These means may include:
- Login logs.
- User logs.
- Permission logs.
- Download logs.
- Modification logs.
- Upload logs.
- API logs.
- System logs.
- Cyber security logs.
- Unauthorised access attempts.
- Backups.
- Technical data relating to devices and accounts, where permitted by law.
These logs may be used in internal investigations, in the protection of rights, or in legal proceedings, in accordance with the law.
19. Detecting Copying, Imitation or Unauthorised Use
If the Group discovers that a person or entity has copied, imitated, exploited or used one of its assets without authorisation, it is entitled to take the appropriate measures to safeguard its rights.
The violation need not have been committed by an employee or contractor.
Depending on the nature of the incident, this policy also covers any:
- Website visitor.
- Platform user.
- Company.
- Competitor.
- Service provider.
- Current or former employee.
- Contractor.
- Developer.
- Or any third party.
20. The Group's Measures in the Event of a Violation
Where a violation is discovered, or seriously suspected, the Group and its subsidiaries reserve the right to take whatever legal, technical and administrative measures are required in each case.
These may include:
- Suspending access rights.
- Cancelling the account.
- Disabling the account or access keys.
- Protecting the systems and data.
- Preserving digital evidence.
- Opening an internal investigation.
- Documenting the incident.
- Issuing an administrative warning.
- Issuing a legal notice.
- Requiring the person or entity to cease use.
- Requesting removal of the infringing content.
- Requesting deletion of unauthorised copies.
- Demanding the return of the assets or data.
- Contacting the hosting provider.
- Contacting the platform hosting the infringing content.
- Filing takedown or blocking requests where legally available.
- Filing a complaint with the competent authorities.
- Taking the civil, commercial or criminal measures available at law.
- Filing claims before the courts or competent authorities.
- Claiming compensation where its legal grounds are met.
- Taking any other measure permitted by law.
21. The Group's Right to Bring Claims
The Group and its subsidiaries reserve the right to bring claims or take appropriate legal action against any natural or legal person proven to have unlawfully infringed one of their rights or protected assets.
Depending on the incident, this includes:
- Unlawful copying.
- Unauthorised use.
- Infringement of copyright.
- Infringement of trademarks.
- Unlicensed use of digital assets.
- Unauthorised acquisition of confidential information.
- Unauthorised access to the systems.
- Data leakage.
- Unlawful use of commercial or technical information.
- Or any other act constituting a violation under the applicable laws.
22. The Right to Claim Compensation
The Group and its subsidiaries reserve the right to claim compensation for damages and losses legally proven to have resulted from the infringement of their rights or assets.
Depending on the nature of the damage and what the law permits, a claim may cover:
- Financial losses.
- Commercial damages.
- System restoration costs.
- Technical investigation costs.
- Costs of handling a leak or breach.
- Damages resulting from unlawful use.
- Damages relating to the brand or the commercial activity.
- And any other damages or expenses recognised by law and established before the competent authority.
This policy does not constitute an automatic or advance determination of the value of compensation.
Each claim is assessed in accordance with the contracts, the evidence, the laws and the decisions issued by the competent judicial authorities.
23. Ceasing the Violation Does Not Extinguish the Right to Compensation
Where the infringing person:
- Deletes the copy;
- Or removes the content;
- Or ceases the use;
- Or shuts down the infringing site;
- Or returns the data;
that does not in itself extinguish the Group's rights to take legal action or to claim compensation for prior damages, where there is a legal basis for doing so.
24. No Waiver of Rights
The Group's failure to take immediate action in respect of a particular violation does not constitute:
- A waiver of its rights.
- Acceptance of the violation.
- A licence to use the asset.
- A forfeiture of intellectual property.
- A forfeiture of the right to claim.
- Or implied consent to continued use.
The Group reserves the right to take the appropriate action at such time as the law permits.
25. End of the Employment, Training or Contractual Relationship
On the end of any person's relationship with the Group, they are obliged, in accordance with the contract and the applicable policies, to:
- Hand over the code.
- Hand over project files.
- Hand over documents.
- Hand over devices.
- Return the assets.
- Hand over institutional accounts in accordance with the approved procedures.
- Hand over access keys.
- Return the data.
- Cooperate in the transfer of knowledge.
- Cease using their permissions.
- Delete unauthorised copies held on personal devices or accounts.
- Not retain Group data outside the authorised frameworks.
The Group may request a written or electronic acknowledgement that the handover has been completed.
26. Continuation of Obligations After the Relationship Ends
The obligations relating to:
- Confidentiality.
- Data protection.
- Trade secrets.
- Protection of intellectual property.
- Not retaining the assets.
- Not using code and systems without authorisation.
- Returning the assets.
- Protecting accounts and data.
remain in force after the end of the employment, training or contractual relationship, to the extent permitted by the applicable laws and contracts.
27. Priority of Contracts and Policies
This policy is read together with:
- Employment contracts.
- Training contracts.
- Development contracts.
- Programmers' contracts.
- Consultants' contracts.
- Suppliers' contracts.
- Non-disclosure agreements (NDAs).
- Intellectual property rights agreements.
- Rights assignment agreements, where required.
- Website terms of use.
- The privacy policy.
- The data protection policy.
- The information security policy.
- The artificial intelligence usage policy.
- Access and permission policies.
- The relevant commercial agreements.
In the event of a conflict, reference is made to the binding laws, agreements and contracts according to the nature of each case.
28. No Implied Rights Granted
Access to any of the following does not grant:
- A website.
- A platform.
- A control panel.
- A system.
- An account.
- An application.
- A database.
- A file.
- A program.
any ownership right or licence beyond the limits of the expressly authorised use.
29. The Approved Institutional Rule
Everything built, developed, designed, customised, trained or operated for the benefit of the Group using its resources, data, systems, accounts or technical infrastructure, or pursuant to an assignment approved by it, is an asset of the Group or of the relevant subsidiary, in accordance with the applicable contracts, agreements and laws.
Making any site, system, platform or content available to the public does not mean a waiver of the Group's rights in it, and grants no person the right to copy, imitate, exploit or commercially reuse the protected assets without authorisation or legal basis.
The Group and its subsidiaries reserve all their rights to protect their code, systems, data, sites, marks, content and digital assets, and to take the appropriate administrative, technical and legal measures, including bringing claims and seeking compensation once the violation and the damage are established in accordance with the law.
30. Official UAE Legal Reference
According to the nature of each right or incident and the scope of application of the legislation, this policy is based on the laws and legislation in force in the United Arab Emirates, including:
- Federal Decree-Law No. (38) of 2021 on Copyright and Neighbouring Rights.
- Federal Decree-Law No. (36) of 2021 on Trademarks.
- Federal Decree-Law No. (34) of 2021 on Combating Rumours and Cybercrime.
Federal Decree-Law No. (34) of 2021 contains provisions relating to cybercrime and to the unlawful access to, or handling of, certain data and information, including the provisions concerning confidential data and information of financial, commercial and economic institutions, in accordance with the scope of application and the conditions and elements specified in the law.
This policy applies subject to any amendments, legislation, decisions or implementing regulations in force or subsequently issued in the United Arab Emirates, and in a manner that does not conflict with the applicable laws and regulations.
Final Legal Notice
This policy aims to regulate and protect the intellectual property and the digital and technical assets of the Group and its subsidiaries. No provision of it is to be construed as granting the Group rights exceeding what the applicable laws, contracts or licences provide.
Liability, procedures and compensation are determined in each case on the basis of the nature of the incident, the evidence, the contracts, the applicable legislation and the decisions of the competent authorities.
All rights reserved to the Group and its subsidiaries in accordance with the law.

