Privacy Policy

    VAF Compliance  |  www.vaf.global

    Effective date: 22 September 2026

    1. Who we are and what this policy covers

    This Privacy Policy explains how VAF Compliance ("we", "us" or "our") collects, uses, discloses, retains and protects personal data in connection with www.vaf.global, our communications and our services.

    This policy applies to website visitors, people who contact us, prospective and existing clients, client representatives, business contacts and individuals whose information is included in an engagement. Personal data is information that identifies an individual, directly or indirectly.

    We act as a data controller where we determine why and how personal data is processed. Where we process information solely on a client's documented instructions, we act as a processor; the client's privacy notice and our data-processing agreement also apply. Separate notices may supplement this policy for particular services or interactions.

    2. Personal data we may collect

    Contact and professional information: Your name, business email address, telephone number, job title, organisation, address and the contents of enquiries, correspondence and other communications.

    Client and engagement information: Where necessary for an engagement or a legal requirement, identification documents, nationality, date of birth, address verification, company and beneficial-ownership records, source-of-funds or source-of-wealth evidence, financial records and relevant case materials. Case information may include allegations, sanctions-related information or other sensitive personal data, which require particular care.

    Blockchain and screening information: Public wallet addresses, transaction hashes, transaction histories, counterparty links and information connecting those records to an individual. Screening results, attribution labels, risk indicators, analytical findings and related reports may also contain personal data.

    Payment and administration information: Billing details, invoices, payment amounts, transaction references and payment status. Where a third-party payment service is used, that provider also handles information under its own privacy notice.

    Technical and preference information: Depending on the technologies used, IP address, browser and device information, pages visited, referral information, timestamps, website interaction logs, security records and cookie or communication preferences.

    Important Notice:

    Please provide only information relevant to your enquiry or engagement. Never send private keys, wallet recovery or seed phrases, passwords or authentication codes. Contact us to agree an appropriate transfer method before sending identity documents or sensitive case files.

    3. How we obtain personal data

    We may receive information directly from you through website forms, email, telephone, meetings, messaging channels and service engagements. We may also receive relevant information from our clients, authorised representatives, professional advisers, referral partners and service providers.

    Where lawful and necessary, information may come from public blockchains, corporate registers, official sanctions sources, publicly available reporting and third-party identity, screening or blockchain-analytics sources. Public availability does not by itself mean that personal data can be used without restriction.

    When providing another person's information, you should have a lawful basis to disclose it and provide any notice or obtain any permission required by law. This does not replace our own data-protection responsibilities.

    4. Why we use personal data and our legal basis

    We use relevant information to respond to enquiries; assess and manage engagements; provide agreed services, including, where applicable, crypto wallet screening, blockchain investigations, source-of-funds analysis, forensic reporting, advisory support and training; and communicate about those services.

    We also use information as necessary to administer payments and records, maintain website and information security, address complaints and disputes, comply with applicable obligations, and establish or defend legal claims. Optional analytics and marketing are addressed below.

    We process personal data in accordance with applicable data-protection law, including UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, where it applies. Depending on the activity, we rely on consent or a specifically applicable legal exception, such as performing a contract with the individual concerned, taking pre-contract steps at that individual's request, meeting a legal obligation or establishing or defending legal claims.

    Where we act only as a processor, the client determines the lawful basis for its processing, and we follow lawful documented instructions. We will not treat a visit to our website as consent to all processing. Where consent is required, we obtain it separately and explain how to withdraw it. Declining information necessary for a requested service may prevent us from providing that service; optional marketing consent is not a condition of an enquiry.

    5. Blockchain analysis and automated processing

    Screening and analytical tools may identify transaction patterns, possible associations and risk indicators. These outputs may involve inferences and may be incomplete or inaccurate; an automated match or risk label does not, by itself, establish wrongdoing. You may contact us about information you believe is inaccurate.

    Where automated processing is used to make a decision with legal or similarly significant effects, we will provide the information and safeguards required by applicable law, including applicable opportunities to contest the decision and request human review. A client that uses our reports to make its own decisions may be a separate controller for that use.

    6. When we share personal data

    We share personal data only where there is an appropriate lawful basis and to the extent necessary for the relevant purpose. Recipients may include hosting, communications, document-management, IT support, security, payment, identity-verification, screening and blockchain-analytics providers supporting the relevant activity.

    For an engagement, relevant information and reports may be provided to the commissioning client and authorised recipients, such as its legal advisers, banks or other institutions, where disclosure is within the agreed scope and lawful. Professional advisers, auditors and insurers may receive information where necessary for their work. Where a recipient acts as our processor, we require appropriate contractual instructions, confidentiality and data-protection safeguards.

    We may disclose information to competent authorities, courts or regulators when required or permitted by applicable law, or as necessary for legal proceedings. We may also disclose limited information to advisers or prospective successors in a genuine business restructuring or transfer, subject to appropriate confidentiality and legal safeguards. This policy does not authorise unrestricted disclosure or override statutory confidentiality obligations.

    7. International transfers

    Some service providers or authorised recipients may be located outside the UAE, so relevant personal data may be stored in or accessed from another country. We make such transfers only where applicable legal requirements are met, using an authorised transfer mechanism and appropriate safeguards, such as recognised adequate protection, legally compliant contractual arrangements or another permitted exception. Information about the safeguards relevant to your data is available on request.

    8. How long we keep personal data

    We retain personal data only for as long as necessary for its lawful purpose. Retention depends on the nature of the information, whether an enquiry or engagement remains active, service-delivery needs, applicable record-keeping obligations, relevant claim periods and any lawful preservation requirement.

    We review the need to retain information and delete it or irreversibly anonymise it when retention is no longer justified. Records subject to a legal hold remain protected and restricted to the relevant purpose. Backup copies are protected pending removal through the applicable backup-deletion cycle. We may keep a minimal suppression record to respect a marketing opt-out.

    We cannot alter or remove transactions recorded on independently operated public blockchains. This does not remove our responsibility to assess requests relating to personal data, copies, labels or other records within our control.

    9. Security and personal data incidents

    We apply technical and organisational safeguards appropriate to the information and risks involved, including controls over access, confidentiality, storage, transmission and handling by service providers. No system or internet transmission can be guaranteed completely secure.

    Where we become aware of a suspected personal data breach, we assess it, take appropriate containment and remedial steps, and notify the competent authority and affected individuals where required, within applicable legal time limits. Please report suspected misuse of your information to the contact in section 15.

    10. Cookies and similar technologies

    Our website may use cookies or similar technologies for essential functionality and security, to remember preferences and, where implemented with any required consent, to measure usage or support marketing. Essential technologies are distinguished from optional analytics or advertising technologies.

    Where consent is required, optional technologies will not be enabled unless you opt in. You can decline optional technologies without declining those necessary for the website to function. You may also use browser controls to block or delete cookies, although this can affect website features and may not control every tracking technology.

    11. Marketing and communication preferences

    We may send newsletters, service information, training invitations or other promotional communications only where permitted by law and with consent where required. You can stop marketing communications using the unsubscribe facility provided or by emailing info@vaf.global with your request.

    Withdrawing marketing consent or opting out does not affect necessary non-promotional communications, such as replies to your enquiries, engagement updates, invoices or legal notices. Withdrawal does not affect processing lawfully carried out before it took effect.

    12. Your rights and complaints

    Subject to applicable law and the circumstances, you may request information about and access to your personal data; correction or completion; erasure; restriction of processing; objection to certain uses, including direct marketing; and a portable copy or transfer where the applicable conditions are met. You may withdraw consent and exercise applicable rights concerning automated decisions, including requesting human review.

    To make a request, contact info@vaf.global with the subject "Privacy Request" and enough information to identify the relevant interaction or engagement. We may request proportionate evidence of identity or authority where necessary. Please do not send identification documents unless we request them and agree an appropriate transfer method.

    We respond without undue delay and within applicable legal deadlines, free of charge where required by law. Rights may be limited where a legal obligation, protected third-party information, an authorised investigation or legal proceedings justify a restriction. We will explain our response to the extent permitted by law. Where we act only for a client, we will assist or refer your request to the relevant controller as appropriate.

    You may raise a concern with us or complain to the competent data-protection authority, including the UAE Data Office where it has jurisdiction, through the applicable complaint procedure. You are not required to contact us first before exercising an available regulatory complaint right.

    13. Children and third-party services

    Our website is directed at adult business users, not children under 18. Information about a child should not be submitted unless necessary for a lawful engagement and appropriate arrangements have been agreed. Any such processing requires an appropriate legal basis and safeguards.

    External websites, social platforms, messaging tools, payment services and other independent third parties may have their own privacy practices. Review their notices when using their services. This does not limit our responsibility for personal data that we disclose or otherwise process.

    14. Changes to this policy

    We may update this policy to reflect changes in our activities, technologies or legal requirements. The version published on our website will show its effective or last-updated date. We will provide additional notice or obtain fresh consent for changes where required by law. Publishing an updated policy does not itself provide consent for a new use of personal data.

    15. Contact us

    VAF Compliance

    Attention: Privacy Enquiries

    Email: info@vaf.global

    Telephone: +971 50 906 7550

    Address: Unit No. UT-11-CEO-10, DMCC Business Centre, Level 11, Uptown Tower, Dubai, United Arab Emirates.

    Website: www.vaf.global