Unified Policy for the Protection of Intellectual Property, Digital Assets and Smart Systems
Protection policy for code, systems, artificial intelligence, websites, data and digital assets
1. General Principle and Ownership
All works, assets, systems and technical or digital developments that are created, developed, designed, customized, trained, operated or activated for the Group or any of its subsidiaries — using the Group's resources, data, systems, devices, accounts, subscriptions, infrastructure or allocated working time, or on the basis of an assignment issued by it — are assets and rights of the Group or of the relevant subsidiary, in accordance with the applicable contracts, agreements, policies and laws. This includes anything developed wholly or partly by:
- Employees
- Trainees
- Officers
- Managers
- Programmers
- Developers
- Designers
- Consultants
- Contractors
- Suppliers
- Technology companies
- Service providers
- Independent contractors
- Or any person or entity working for the Group or using its resources, systems or data
2. Scope of Digital Assets and Rights
Digital and technical assets include, without limitation:
- Program code
- Source code
- Executable code
- Programs and applications
- Websites
- Digital platforms and portals
- Smart systems
- Artificial intelligence models
- AI tools that are developed or customized
- AI agents
- Smart assistants
- Prompts
- Smart instructions and rules
- Algorithms
- Automation systems
- Automated operating systems
- Databases
- Database structures
- Knowledge bases
- Training data
- APIs
- Software integrations
- Dashboards
- Electronic forms
- Workflows
- Business logic
- Evaluation and classification systems
- Analysis tools
- Client and opportunity discovery systems
- Data processing systems
- Decision-making systems
- Monitoring and alerting systems
- Smart reporting tools
- Technical materials and documents
- Operating manuals
- Training manuals
- Written content
- Original designs
- User interfaces
- Original graphics and images
- Logos
- Trademarks
- Trade names
- Visual identity
- Operating plans
- Customer journey maps
- Confidential data
- Unpublished technical and commercial information
- And any other digital or technical asset or development created for the Group
3. Development Using the Group's Resources
Every program, system, AI model, tool, code, design or technical project developed wholly or partly:
- During working hours
- Or using the Group's devices
- Or using its accounts
- Or using its subscriptions
- Or using its data
- Or using its technical infrastructure
- Or using its platforms
- Or on the basis of an administrative or operational assignment issued by it
- Or for the business purposes of the Group or any of its subsidiaries
is subject to the legal and contractual rights of the Group or of the relevant subsidiary. The participation of any employee, trainee, developer, consultant or contractor in creating or developing a system is not an automatic authorization to use, copy, exploit or reproduce it outside the scope of work.
4. Joint and Partial Development
A project or system does not have to be developed entirely inside the Group for rights connected to the Group's contribution to arise. Where the following were used:
- The Group's resources
- Its data
- Its funding
- Its employees
- Its internal expertise
- Its accounts
- Its systems
- Its tools
- Its plans
- Its operating rules
- Or its approved assignments
in developing a project, system or digital asset, the related rights are governed by the contracts, the agreements, the share of participation and the nature of each party's legal ownership.
5. Updates and Future Developments
The Group's rights include, as permitted by contracts and laws, all:
- Updates
- Improvements
- New versions
- Add-ons
- Modifications
- Customizations
- Derivative developments
- AI model training processes
- Fine-tuning
- Prompt optimization
- Algorithm development
- Knowledge base development
- Database updates
- Automation system development
- System restructuring
- Addition of new features
- Development of more advanced versions of the original system
whenever these are carried out for the Group, using its resources, data or systems, or within approved tasks and assignments.
6. Prohibitions on Employees, Trainees and Contractors
No person may, without prior written approval from the competent management:
- Copy any code
- Copy a system or program
- Copy an AI model
- Send code to a personal email address
- Store files on personal cloud accounts
- Upload code to unauthorized devices
- Transfer databases
- Copy databases
- Share confidential data
- Share internal prompts
- Share system configurations
- Share API keys
- Share passwords
- Share access tokens
- Share user accounts
- Photograph technical or confidential content without authorization
- Extract content from internal systems
- Use the Group's assets in a personal project
- Use them for the benefit of another party
- Use them for the benefit of a competing company
- Resell them
- Re-license them
- Publish them
- Redistribute them
- Create a copy of them for another activity
- Transfer them to a third party
- Keep copies of them after the end of employment, training or contract
7. Protection of Websites and Digital Platforms
The websites, platforms and digital portals of the Group and its subsidiaries are part of the Group's digital assets, with respect to the elements, content, systems and rights that the Group owns or is legally authorized to use. Depending on each site or platform, this includes:
- Code
- Content
- Original designs
- Electronic forms
- Internal systems
- Databases
- Smart tools
- Digital customer journeys
- Order systems
- Interactive tools
- Reports
- Marks
- Logos
- Names
- Original visual elements
8. Visitor Access to the Websites
A visitor's mere access to any of the Group's websites or platforms grants no ownership right in the assets or rights present on the site. Nor does accessing or using the site constitute:
- A license to copy the content
- A license to reproduce the systems
- A license for commercial use of the content
- A waiver of intellectual property rights
- Authorization to use the trademarks
- Authorization to extract confidential data
- Authorization to recreate the technical systems
Use of the site is limited to the lawful and ordinary use for which the site was made available, and in accordance with the terms of use and the law.
9. Prohibition of Copying from the Websites
Without prior written authorization, the following acts are prohibited where they concern a protected asset or content of the Group:
- Copying website content
- Copying original texts
- Copying protected designs
- Copying original images and graphics
- Copying electronic forms
- Copying site pages for commercial reuse
- Republishing content under another party's name
- Copying code
- Extracting databases without authorization
- Extracting confidential information
- Copying smart tools
- Copying internal prompts
- Copying protected work systems or software
- Removing ownership right data
- Removing the rights holder's name
- Altering or concealing copyright notices
10. Imitation, Simulation and Unlawful Use
The Group and its subsidiaries retain all their legal rights against any person or entity that, without legal basis or approved authorization, imitates, uses or exploits protected assets of the Group. Depending on the nature of the right, this includes:
- Logos
- Trademarks
- Trade names
- Visual identity
- Original designs
- Creative content
- Code and programs
- Protected databases
- Electronic forms
- Software systems
- Written materials
- Protected digital tools or products
It also includes presenting an asset or product belonging to the Group as belonging to another person or company.
11. General Ideas and Unprotected Elements
This policy does not seek to claim ownership of general ideas, methods, functions or common practices over which the law grants no exclusive right.
Protection extends only to the assets, rights, works, data, marks, trade secrets and contractual rights owned by the Group or its subsidiaries, or which they are legally authorized to use.
12. Unauthorized Access
No person may attempt to:
- Access a system they are not authorized to use
- Enter internal pages they are not permitted to access
- Exceed the level of permission granted to them
- Bypass protection systems
- Bypass authentication mechanisms
- Use another person's account
- Use passwords that do not belong to them
- Obtain access tokens without authorization
- Access confidential data without permission
- Extract internal data
- Access source code without authorization
- Modify data without permission
- Delete data without permission
- Download data without authorization
- Tamper with the Group's systems
- Disable systems
- Deliberately affect the efficiency or operation of systems
13. Reverse Engineering and Technology Extraction
Within the limits permitted by law and contract, it is prohibited to attempt to:
- Decompile or analyse systems without authorization
- Extract internal code
- Extract system logic
- Access components not available to the public
- Bypass security controls
- Extract databases without authorization
- Rebuild a protected system using materials or code obtained unlawfully
14. Use of External Artificial Intelligence Tools
No confidential or technical information belonging to the Group may be entered into unapproved external AI tools or accounts. This includes:
- Source code
- Confidential client data
- Personal data not authorized for sharing
- Databases
- Confidential prompts
- Internal knowledge bases
- API keys
- Passwords
- Access tokens
- Confidential contracts
- Confidential legal information
- Unpublished financial data
- Strategic plans
- Business plans
- Internal documents
- Unpublished operational information
Approved accounts, tools and platforms must be used in accordance with the Group's information security and data protection policies.
15. Protection of Data and Knowledge Bases
Databases, knowledge bases and commercial, technical and operational information not available to the public are important assets of the Group. Without approved authorization, they may not be:
- Copied
- Downloaded
- Transferred
- Sold
- Shared
- Published
- Leaked
- Used for personal benefit
- Used for the benefit of an external party
- Used to create a competing activity
- Used to train an external system
- Used outside the authorized purpose
This applies with due regard to the rights of data subjects and the applicable data protection and privacy laws.
16. Confidentiality and Trade Secrets
All information relating to the Group's business that is not available to the public and that is confidential, commercial or technical in nature must be protected in accordance with the applicable contracts, laws and approved policies. It may include:
- Strategies
- Market studies
- Financial information
- Client data
- Expansion plans
- Internal pricing rules
- Commercial relationships
- Supplier data
- Client sources
- Evaluation algorithms
- Operating plans
- Technical information
- Code
- Internal work procedures
- Development documentation
17. The Group's Accounts and Devices
The accounts, devices, services and subscriptions provided by the Group are corporate work tools. It is not permitted to:
- Share accounts without authorization
- Grant an external party access rights
- Change recovery details for personal purposes
- Use a corporate account after the expiry of its validity
- Transfer corporate data to a personal account
- Keep passwords or access keys after the end of the relationship
- Use the Group's devices for purposes that endanger system security
18. Retention of Digital Evidence
In accordance with the law and the applicable data protection and privacy policies, the Group reserves the right to use the technical means necessary to protect its systems and assets and to document related activity. These means may include:
- Login records
- User records
- Permission records
- Download records
- Modification records
- Upload records
- API logs
- System logs
- Cyber security logs
- Unauthorized access attempts
- Backups
- Technical data relating to devices and accounts, where the law permits
These records may be used in internal investigations, in protecting rights or in legal proceedings, in accordance with the law.
19. Detection of Copying, Imitation or Unauthorized Use
If the Group discovers that a person or entity has copied, imitated, exploited or used one of its assets without authorization, it is entitled to take appropriate measures to preserve its rights. The violation need not have been committed by an employee or contractor. Depending on the nature of the incident, this policy also covers any:
- Site visitor
- Platform user
- Company
- Competitor
- Service provider
- Current or former employee
- Contractor
- Developer
- Or any third party
20. The Group's Measures in the Event of a Violation
Where a violation is discovered or seriously suspected, the Group and its subsidiaries reserve the right to take the necessary legal, technical and administrative measures, according to each case. These may include:
- Suspending access rights
- Cancelling the account
- Disabling the account or access keys
- Protecting systems and data
- Preserving digital evidence
- Opening an internal investigation
- Documenting the incident
- Issuing an administrative warning
- Issuing a legal notice
- Requiring the person or entity to cease use
- Requesting removal of the infringing content
- Requesting deletion of unauthorized copies
- Demanding the return of assets or data
- Contacting the hosting provider
- Contacting the platform hosting the infringing content
- Submitting takedown or blocking requests where legally available
- Filing a complaint with the competent authorities
- Taking the civil, commercial or criminal measures available by law
- Filing claims before the courts or competent authorities
- Claiming compensation where its legal grounds are met
- Taking any other measure permitted by law
21. The Group's Right to File Claims
The Group and its subsidiaries reserve the right to file claims or take appropriate legal action against any natural or legal person proven to have unlawfully infringed one of their rights or protected assets. Depending on the incident, this includes:
- Unlawful copying
- Unauthorized use
- Infringement of copyright
- Infringement of trademarks
- Unlicensed use of digital assets
- Unauthorized acquisition of confidential information
- Unauthorized access to systems
- Data leakage
- Unlawful use of commercial or technical information
- Or any other act constituting a violation under the applicable laws
22. The Right to Claim Compensation
The Group and its subsidiaries reserve the right to claim compensation for damages and losses legally proven to result from infringement of their rights or assets. Depending on the nature of the damage and what the law permits, a claim may include:
- Financial losses
- Commercial damages
- System restoration costs
- Technical investigation costs
- Costs of handling a leak or breach
- Damages resulting from unlawful use
- Damages relating to the brand or commercial activity
- And any other damages or expenses recognized by law and proven before the competent authority
This policy does not constitute an automatic or advance determination of the value of compensation. Any claim is assessed in accordance with the contracts, the evidence, the laws and the decisions issued by the competent judicial authorities.
23. Ceasing a Violation Does Not Extinguish the Right to Compensation
Where the violating person:
- Deletes the copy
- Or removes the content
- Or ceases the use
- Or closes the infringing site
- Or returns the data
this does not in itself extinguish the Group's rights to take legal action or to claim compensation for prior damages, where these have a legal basis.
24. No Waiver of Rights
The Group's failure to take immediate action against a particular violation is not considered:
- A waiver of its rights
- Acceptance of the violation
- A license to use the asset
- A forfeiture of intellectual property
- A forfeiture of the right to claim
- Or implied consent to continued use
The Group retains the right to take appropriate action at the time permitted by law.
25. End of the Employment, Training or Contractual Relationship
When any person's relationship with the Group ends, they are bound, in accordance with the contract and the applicable policies, to:
- Hand over the code
- Hand over project files
- Hand over documents
- Hand over devices
- Return assets
- Hand over corporate accounts in accordance with the approved procedures
- Hand over access keys
- Return data
- Cooperate in knowledge transfer
- Stop using permissions
- Delete unauthorized copies held on personal devices or accounts
- Not retain the Group's data outside authorized frameworks
The Group may request a written or electronic acknowledgement that the handover has been completed.
26. Survival of Obligations After the Relationship Ends
Obligations relating to:
- Confidentiality
- Data protection
- Trade secrets
- Intellectual property protection
- Not retaining assets
- Not using code and systems without authorization
- Returning assets
- Protecting accounts and data
remain in force after the employment, training or contractual relationship ends, to the extent permitted by the applicable laws and contracts.
27. Precedence of Contracts and Policies
This policy is read together with:
- Employment contracts
- Training contracts
- Development contracts
- Programmer contracts
- Consultant contracts
- Supplier contracts
- Non-disclosure agreements (NDA)
- Intellectual property rights agreements
- Rights transfer agreements where required
- Website terms of use
- The privacy policy
- The data protection policy
- The information security policy
- The artificial intelligence use policy
- Access and permission policies
- Related commercial agreements
In the event of a conflict, reference is made to the binding laws, agreements and contracts according to the nature of each case.
28. No Implied Rights Granted
Access to any:
- Website
- Platform
- Dashboard
- System
- Account
- Application
- Database
- File
- Program
grants no ownership right or license beyond the limits of the expressly authorized use.
29. The Approved Corporate Rule
Everything built, developed, designed, customized, trained or operated for the Group using its resources, data, systems, accounts or technical infrastructure, or on the basis of an approved assignment from it, is an asset of the Group or of the relevant subsidiary, in accordance with the applicable contracts, agreements and laws.
Making any site, system, platform or content available to the public does not mean a waiver of the Group's rights in it, and grants no person the right to copy, imitate, exploit or commercially reuse protected assets without authorization or legal basis. The Group and its subsidiaries retain all their rights to protect their code, systems, data, sites, marks, content and digital assets, and to take appropriate administrative, technical and legal measures, including filing claims and seeking compensation where the violation and damage are established in accordance with the law.
30. Official UAE Legal Framework
Depending on the nature of each right or incident and the scope of application of the legislation, this policy is based on the laws and legislation in force in the United Arab Emirates, including:
- Federal Decree-Law No. (38) of 2021 on Copyright and Neighbouring Rights
- Federal Decree-Law No. (36) of 2021 on Trademarks
- Federal Decree-Law No. (34) of 2021 on Combating Rumours and Cybercrime
Federal Decree-Law No. (34) of 2021 contains provisions relating to cybercrime and to unlawful access to or handling of certain data and information, including provisions on confidential data and information of financial, commercial and economic institutions, in accordance with the scope of application, conditions and elements specified in the law. This policy applies with due regard to any amendments, legislation, decisions or implementing regulations in force or subsequently issued in the United Arab Emirates, and in a manner not conflicting with the applicable laws and regulations.
Closing Legal Notice
This policy is intended to regulate and protect the intellectual property and the digital and technical assets of the Group and its subsidiaries. No provision of it shall be construed as granting the Group rights exceeding those established by the applicable laws, contracts or licences.
Liability, procedures and compensation are determined in each case on the basis of the nature of the incident, the evidence, the contracts, the applicable legislation and the decisions of the competent authorities. All rights are reserved to the Group and its subsidiaries in accordance with the law.
