Legal
Privacy Policy
Effective Date: 26 July 2026 · Last Updated: 26 July 2026
PRIVACY POLICY
Effective Date: 26 July 2026
Last Updated: 26 July 2026
1. About This Privacy Policy
This Privacy Policy explains how OCTOPUS PRIME GLOBAL F.Z.E collects, uses, stores, shares and protects personal data through the Octopus Prime BFCO website, client portal, internal customer relationship management system, registration process, communications and related services.
It also explains the rights available to individuals whose personal data we process.
This Privacy Policy applies to:
- visitors to our website;
- individuals who submit an inquiry;
- registered users of the Octopus Prime BFCO platform;
- prospective and active clients;
- authorised representatives;
- family members, dependants, employees, shareholders and other persons whose information is provided in connection with a user or client request;
- persons who communicate with us by email, telephone, WhatsApp or other communication channels.
By creating an account, submitting information or using our platform, you acknowledge that you have read this Privacy Policy.
Acceptance of this Privacy Policy does not itself activate any paid service, create a professional engagement or oblige us to accept a registered user as an active client.
2. Who We Are
The controller responsible for personal data processed under this Privacy Policy is:
OCTOPUS PRIME GLOBAL F.Z.E
Free Zone Establishment – Limited Liability
Registration and Licence No. 55289
Premises No. B.C. 1308431
Ajman Free Zone C1 Building
Ajman Free Zone
Emirate of Ajman
United Arab Emirates
Makani No. 4442612247
Email: mail@octopus-prime.net
OCTOPUS PRIME GLOBAL F.Z.E operates the Octopus Prime Business & Family Coordination Office under the commercial name Octopus Prime BFCO.
References in this Privacy Policy to "Octopus Prime BFCO", "Octopus Prime", "we", "us" or "our" mean OCTOPUS PRIME GLOBAL F.Z.E.
3. Nature of Our Activities
Octopus Prime BFCO provides services within the scope of its UAE business licence, including management consultancy, office and administrative services, document preparation and specialised office support, data preparation, project management, companies representation, client care, reservation-related services, public relations management, market research and related coordination activities.
Where a user requires legal, tax, accounting, audit, immigration, banking, insurance, medical, investment, real estate brokerage or another regulated professional service, such service may be provided by an appropriately licensed independent third-party provider.
We may assist with selection, introductions, document collection, communications, administration and project coordination. An independent provider may process personal data as a separate controller under its own privacy policy.
4. Our Platform and Technology Providers
Our website, client portal, internal CRM and related workflows are operated through a system developed using the Base44 platform and made available through our own domain.
We may use third-party technology providers to operate particular platform functions, including:
- Base44 for platform infrastructure, database functionality, account management, workflows and internal CRM functionality;
- Resend for email delivery and email verification messages;
- WhatsApp and related WhatsApp communication infrastructure for communications and verification messages;
- Stripe for online payment processing;
- banks and payment service providers for payments made by bank transfer.
These providers may process limited personal data on our behalf or as independent controllers, depending on the service and the circumstances.
Their processing may also be governed by their own privacy terms.
5. Personal Data We Collect
The personal data we collect depends on how you use the platform and which services you request.
5.1 Account and contact information
We may collect:
- full name;
- email address;
- telephone number;
- country of residence;
- preferred language;
- account identifier;
- password or authentication credentials in protected form;
- email and telephone verification status;
- account status;
- communication preferences.
5.2 Identity and verification information
For onboarding, verification, compliance or service coordination, we may collect:
- date and place of birth;
- nationality and citizenship;
- passport details;
- copies of passports;
- national identity documents;
- Emirates ID;
- residence permits and visas;
- photographs;
- residential address;
- proof of address;
- signatures;
- tax identification numbers;
- information showing that a person is authorised to act for another person or organisation.
5.3 Family and household information
Where relevant to family administration, relocation, education, insurance, healthcare or another requested service, we may collect:
- marital or relationship status;
- details of spouses or partners;
- details of children and dependants;
- household composition;
- family requirements and preferences;
- school and education information;
- relocation plans;
- emergency contact details.
A user providing personal data about another person must have a lawful basis and appropriate authority to provide that information.
5.4 Business and corporate information
We may collect:
- occupation and employment details;
- professional background;
- company ownership and management information;
- business activities;
- commercial objectives;
- company incorporation documents;
- trade licences;
- registers of shareholders or beneficial owners;
- memoranda and articles of association;
- contracts;
- corporate resolutions;
- invoices;
- business correspondence;
- details of employees, directors, shareholders, representatives and advisers.
5.5 Financial, banking, tax and source-of-funds information
Where relevant to onboarding, compliance or a requested service, we may collect:
- bank account details;
- bank statements;
- payment records;
- transaction information;
- income information;
- details of assets and liabilities;
- source-of-funds information;
- source-of-wealth information;
- tax residency information;
- tax returns and tax-related documents;
- accounting records;
- invoices and receipts;
- investment or transaction budgets;
- property purchase, sale, rental and ownership information.
We do not ask users to provide online banking passwords, payment card PINs or complete authentication credentials for third-party financial accounts.
5.6 Health, medical and insurance information
Where a user requests healthcare navigation, insurance support, medical coordination, claims assistance or another relevant service, we may collect:
- medical reports;
- insurance policies;
- insurance applications;
- insurance claims;
- diagnoses disclosed in documents;
- treatment and prescription information;
- healthcare provider information;
- medical appointment information;
- other health-related documents supplied by the user.
Health information is sensitive personal data. We process it only where relevant to the requested service and where a lawful basis is available, including explicit consent where required.
Octopus Prime BFCO does not provide medical diagnosis, treatment or medical advice.
5.7 Property, relocation and lifestyle information
We may collect:
- property ownership or rental information;
- intended property purchases or sales;
- budgets and payment preferences;
- preferred locations;
- accommodation requirements;
- relocation timelines;
- education requirements;
- reservation and travel information;
- household and lifestyle preferences;
- documents relevant to property, relocation or reservation processes.
5.8 Communications and service records
We may collect and retain:
- inquiry forms;
- onboarding questionnaires;
- emails;
- WhatsApp messages;
- telephone call notes;
- meeting notes;
- documents uploaded to the platform;
- instructions and requests;
- internal task and project records;
- recommendations and reports;
- complaints;
- feedback;
- support requests;
- records of communications with third-party providers.
Calls or online meetings will not be recorded without notice where notice or consent is legally required.
5.9 Technical, device and security data
When you access or use the website or platform, we may collect:
- IP address;
- device type;
- browser type;
- operating system;
- login dates and times;
- attempted logins;
- account activity;
- security alerts;
- authentication events;
- email OTP records;
- WhatsApp OTP records;
- records showing that an email address or telephone number was verified;
- session information;
- application and system logs;
- information about pages and features used;
- error and performance logs;
- records of document acceptance;
- the version of an agreement or policy accepted;
- date, time and method of acceptance.
We use this information to authenticate users, operate the platform, protect accounts, investigate suspicious activity and preserve evidence of electronic transactions.
5.10 Payment information
Where a user makes an online payment, payment processing may be carried out through Stripe.
Stripe may receive payment card and transaction information directly. We may receive transaction status, payer information, payment amount, payment reference and related records, but we do not ordinarily receive or store complete payment card details.
Where payment is made by bank transfer, we may process:
- payer name;
- bank account information shown in the transfer;
- transaction amount;
- payment date;
- payment reference;
- payment confirmation;
- related invoices and correspondence.
5.11 Information received from other sources
We may receive personal data from:
- family members;
- authorised representatives;
- companies and employers;
- shareholders or directors;
- professional advisers;
- accountants, lawyers and consultants;
- banks and payment providers;
- insurers;
- healthcare providers;
- property developers, owners, brokers and agents;
- educational institutions;
- immigration or relocation providers;
- government authorities;
- public registers;
- identity verification and compliance sources;
- referral partners;
- other parties involved in a user's request or transaction.
6. How We Use Personal Data
We may use personal data to:
- create and administer user accounts;
- verify email addresses and telephone numbers;
- authenticate users;
- maintain platform security;
- prevent unauthorised access, misuse and fraud;
- register a user on the platform;
- maintain the user's profile;
- receive and respond to inquiries;
- conduct preliminary qualification;
- assess whether we can assist with a request;
- conduct onboarding and identity verification;
- conduct conflict, risk and compliance checks;
- request missing documents or information;
- understand personal, family and business requirements;
- provide management consultancy;
- provide administrative and project coordination;
- prepare research, reports and recommendations;
- coordinate documents, applications, transactions, reservations and communications;
- coordinate property-related processes;
- coordinate business and corporate matters;
- coordinate banking, payment, tax, accounting and compliance matters;
- coordinate insurance and healthcare matters;
- identify and introduce suitable independent providers;
- communicate with third-party providers on a user's behalf where authorised;
- manage active client relationships;
- manage internal projects and tasks;
- provide technical and customer support;
- administer invoices and payments;
- maintain accounting, legal and business records;
- preserve evidence of user instructions and electronic acceptance;
- investigate complaints, security incidents and disputes;
- establish, exercise or defend legal claims;
- comply with legal, regulatory, judicial and governmental requirements;
- improve our internal processes and platform;
- send operational, account, security and service-related communications;
- send marketing communications where permitted and where required consent has been obtained.
7. Legal Bases for Processing
Depending on the circumstances and applicable law, we process personal data on one or more of the following bases:
- the user's consent;
- explicit consent for sensitive personal data where required;
- steps taken at the user's request before entering into a contract;
- performance of a contract;
- compliance with legal, regulatory, accounting or compliance obligations;
- protection of the rights and interests of the user or another person;
- establishment, exercise or defence of legal claims;
- prevention and investigation of fraud or security incidents;
- protection of our platform, operations and users;
- our legitimate interests or those of a third party, where recognised by applicable law and not overridden by the rights of the individual;
- another lawful ground available under applicable data protection law.
Consent is not used as the sole legal basis where processing is necessary for an account, requested service, legal obligation, security purpose or contractual relationship.
Where processing is based on consent, consent may be withdrawn at any time. Withdrawal does not affect processing already lawfully carried out.
We may continue to retain or process information after withdrawal where another lawful basis applies.
8. Sensitive Personal Data
Sensitive personal data may include health information, medical documents, financial information, identity documents and other information that requires enhanced protection under applicable law.
We process sensitive personal data only where:
- it is relevant and reasonably necessary for a requested service;
- the user has deliberately supplied it;
- the required consent has been obtained where applicable;
- another lawful basis permits the processing;
- appropriate access restrictions and safeguards are applied.
Users should not upload sensitive personal data that is unrelated to a current or reasonably anticipated request.
9. Requirement to Provide Data
Some information is optional. Other information may be required to:
- create or secure an account;
- verify email or telephone details;
- verify identity;
- complete onboarding;
- conduct compliance checks;
- assess a request;
- activate a service;
- make or receive a payment;
- coordinate a transaction or professional service;
- comply with applicable law.
Where necessary information is not supplied, we may be unable to activate an account, accept a user as an active client or proceed with a request.
10. User Status and Service Activation
Creating an account and accepting the platform agreement gives the person the status of a registered user only.
Registration does not:
- activate a paid service;
- create a subscription;
- confirm acceptance as an active client;
- require us to perform a review;
- oblige us to provide professional or coordination services;
- appoint us as an authorised representative;
- create authority to act or sign on behalf of the user.
Additional information may be requested before onboarding or service activation.
11. Automated Processing
We may use software workflows and automated rules to:
- organise inquiries;
- identify incomplete fields;
- classify service requests;
- assign internal tasks;
- detect potential account or security risks;
- support preliminary qualification;
- generate reminders and status notifications.
We do not make decisions producing legal or similarly significant effects solely through automated processing unless this is permitted by law and appropriate safeguards are used.
Client acceptance and service activation are made or reviewed by authorised personnel.
12. How We Share Personal Data
We may share personal data where reasonably necessary with:
- authorised members of our team;
- contractors working under confidentiality obligations;
- Base44 and related platform infrastructure providers;
- database, storage and hosting providers;
- CRM and workflow technology providers;
- Resend for email delivery and email OTP messages;
- WhatsApp and related providers for messaging and WhatsApp OTP;
- Stripe for payment processing;
- banks and payment institutions;
- IT support and cybersecurity providers;
- accountants and auditors;
- legal advisers;
- insurers;
- independent licensed professional providers;
- healthcare providers;
- property developers, property owners, brokers and transaction parties;
- immigration and relocation providers;
- educational institutions;
- government authorities;
- courts and law-enforcement bodies;
- Ajman Free Zone and other competent UAE authorities;
- parties involved in a potential restructuring, acquisition, transfer or sale of the business;
- other recipients authorised or instructed by the user.
We do not sell or rent personal data.
We disclose only the information reasonably required for the relevant purpose.
13. Independent Third-Party Providers
Some external professionals and organisations receive personal data to provide their own services directly to a user.
Examples may include:
- lawyers;
- tax advisers;
- accountants;
- auditors;
- banks;
- payment institutions;
- insurers;
- healthcare providers;
- immigration advisers;
- property brokers;
- property developers;
- educational institutions.
Such providers may act as independent controllers and determine their own purposes, legal bases and retention periods.
Users should review the privacy notice and engagement terms of each provider.
14. International Data Transfers
Our business is based in the United Arab Emirates and operates internationally.
Personal data may be stored, accessed or processed in the UAE, the European Economic Area, the United States and other countries in which our technology providers, banks, payment providers, professional partners or relevant counterparties operate.
For example, use of Base44, Resend, WhatsApp and Stripe may involve processing through infrastructure or entities located outside the user's country of residence.
Where required by applicable law, we use appropriate safeguards for international transfers. These may include:
- contractual data protection clauses;
- data processing agreements;
- access restrictions;
- confidentiality obligations;
- security assessments;
- encryption and authentication controls;
- legally recognised transfer mechanisms;
- other technical and organisational safeguards.
Users may contact us for further information about safeguards relevant to a particular transfer.
15. Data Security
We use technical and organisational measures designed to protect personal data against accidental or unlawful loss, destruction, alteration, disclosure, misuse or unauthorised access.
Measures may include:
- authenticated user accounts;
- email and telephone verification;
- one-time verification codes;
- access controls;
- role-based permissions;
- restricted internal access;
- encryption in transit;
- encryption at rest where supported by the relevant system;
- system, access and activity logs;
- secure backups;
- document access restrictions;
- confidentiality obligations;
- incident response procedures;
- internal data-handling rules;
- service-provider review;
- separation of access according to job responsibilities.
No online platform or storage system can be guaranteed to be completely secure.
Users must:
- keep passwords and OTP codes confidential;
- use secure devices and networks;
- avoid sharing account access;
- notify us promptly of suspected unauthorised access;
- ensure that uploaded documents are relevant to the requested service.
16. Data Retention
We retain personal data only for as long as reasonably required for the purposes described in this Privacy Policy and for legal, accounting, compliance, security and dispute-resolution purposes.
The applicable period depends on the data and circumstances.
Generally:
- unverified or abandoned registrations may be deleted after a reasonable period of inactivity;
- inactive registered-user data may be reviewed and deleted where no continuing purpose exists;
- inquiry records may generally be retained for up to 24 months after the most recent meaningful interaction;
- active client records may be retained throughout the client relationship;
- contractual, payment, accounting and service records may be retained after the relationship ends for the period required by applicable law or reasonably necessary for claims and compliance;
- identity, compliance, source-of-funds and source-of-wealth records may be retained where required for regulatory, fraud-prevention or legal purposes;
- records of electronic acceptance, OTP verification and relevant communications may be retained as evidence of the transaction;
- medical and insurance documents may be deleted or restricted when no longer required for the relevant service, unless continued retention is legally necessary;
- security and technical logs may be retained for a shorter operational period unless required for investigation;
- data in backups may remain until the relevant backup cycle is completed.
When personal data is no longer required, it will be deleted, anonymised or securely isolated in accordance with our procedures.
17. Account Closure
A registered user may request closure of their account by contacting us.
Closing an account does not necessarily result in immediate deletion of all information.
We may retain information where necessary for:
- completed or ongoing services;
- legal and accounting obligations;
- payments and refunds;
- security investigations;
- dispute resolution;
- prevention of duplicate or fraudulent accounts;
- establishment, exercise or defence of legal claims;
- proof of electronic acceptance and instructions.
18. Marketing Communications
Acceptance of this Privacy Policy or the platform agreement does not automatically constitute consent to marketing.
Where required, consent to receive marketing communications will be collected separately.
Users may unsubscribe from marketing messages at any time by:
- using an unsubscribe link where provided;
- changing available communication settings;
- contacting us at mail@octopus-prime.net.
Account, security, contractual, payment and service-related messages are operational communications and may continue where reasonably necessary.
19. Cookies and Similar Technologies
At the effective date of this Privacy Policy, we do not use:
- Google Analytics;
- Meta Pixel;
- reCAPTCHA;
- embedded video tracking tools.
The platform may use cookies, local storage or similar technologies that are technically necessary to:
- maintain user sessions;
- authenticate users;
- remember security and account settings;
- operate platform functions;
- prevent fraud and unauthorised access;
- maintain platform stability.
If we introduce non-essential analytics, advertising, personalisation or tracking technologies, we will update the relevant notices and obtain consent where required.
Browser settings may allow users to block or remove cookies, but disabling technically necessary technologies may prevent parts of the platform from operating correctly.
20. Children and Dependants
Accounts are intended for persons aged 18 or over.
A parent, legal guardian or appropriately authorised adult may provide information concerning children or dependants where necessary for:
- relocation;
- education;
- insurance;
- healthcare coordination;
- family administration;
- another legitimate family-related request.
Children must not create accounts or submit instructions independently.
The person providing a child's data must have legal authority to do so.
21. Your Rights
Subject to applicable law and any relevant exceptions, individuals may have the right to:
- receive information about how their personal data is processed;
- request access to personal data;
- request correction of inaccurate or incomplete data;
- request deletion of personal data;
- request restriction or cessation of certain processing;
- object to processing in certain circumstances;
- withdraw consent;
- request transfer or portability of eligible information;
- request information about recipients;
- request information about international transfer safeguards;
- object to or request review of certain automated decisions;
- submit a complaint to a competent data protection authority.
These rights are not absolute.
A request may be refused or limited where permitted by law, including where retention is required for legal obligations, payments, security, fraud prevention, claims or the rights of another person.
The UAE PDPL provides rights concerning access, correction, deletion, restriction, objection, portability and complaints, while GDPR provides related rights for individuals where it applies.
22. Exercising Your Rights
Requests should be sent to:
mail@octopus-prime.net
The request should explain:
- the identity of the person making the request;
- the relevant account or contact information;
- the nature of the request;
- the data or processing concerned.
We may request additional information to verify identity and authority before disclosing, changing, transferring or deleting information.
This is necessary to prevent unauthorised access to another person's data.
We will respond within the period required by applicable law.
23. Complaints
We encourage users to contact us first so that we can investigate and resolve any concern.
A person may also have the right to complain to:
- the competent UAE data protection authority;
- a competent supervisory authority in the European Economic Area, where GDPR applies;
- another competent regulator in the person's jurisdiction.
The UAE PDPL expressly provides a mechanism for complaints relating to decisions or actions of a controller or processor.
24. Personal Data Breaches
We maintain procedures to identify, assess and respond to suspected personal data breaches.
Where required by applicable law, we will notify the competent authority and affected persons where the incident meets the applicable notification threshold.
We may also require affected users to reset credentials or take other protective measures.
25. Third-Party Websites and Services
The platform may contain links to third-party websites, payment services, professional providers or communication platforms.
We are not responsible for the privacy practices of independent third parties.
Users should review the relevant third party's privacy policy before providing information directly to it.
26. Changes to This Privacy Policy
We may update this Privacy Policy where necessary to reflect changes in:
- our platform;
- technology providers;
- service scope;
- internal processes;
- applicable law;
- security requirements;
- categories of personal data processed.
The latest version will be published on our website with its effective date.
Where a change materially affects registered users or the way their data is processed, we may provide additional notice by email, through the platform or by another appropriate method.
Continued use of the platform after publication does not replace any consent that must be obtained separately under applicable law.
27. Contact Details
Questions, requests and complaints concerning this Privacy Policy or the processing of personal data should be sent to:
OCTOPUS PRIME GLOBAL F.Z.E
Registration and Licence No. 55289
Ajman Free Zone
United Arab Emirates
Email: mail@octopus-prime.net