← Back
ORION Capital

Website Privacy Policy

Last Updated: July 17, 2026 · Version 1.0

This Privacy Policy describes how ORION Capital (“we,” “our,” or “us”) collects, processes, stores, and protects your personal and financial data in compliance with the Dubai International Financial Centre (DIFC) Data Protection Law 2020.

Because ORION Capital is currently in a pre-licensed Research & Development (R&D) phase, this site and our services are strictly closed to the general public. This policy applies solely to our vetted internal participants and builders who have executed physical legal agreements with us.

1. Data We Collect

We collect the following categories of data to manage our internal testing program and prepare for DFSA licensing:

  • Personal Identification Information: Full legal name, date of birth, nationality, residential address, email address, telephone number, and copies of government-issued identification documents.
  • Financial Data: Bank account details, blockchain wallet addresses, historical transaction logs, net worth verifications, and source of wealth documentation.
  • Professional & Suitability Data: Employment history, CV/resumé, and suitability assessment questionnaires to verify Professional Client status.
  • Technical and Activity Logs: IP addresses, login data, device details, and full operational logs of your interactions with our trading systems and automated communication platforms.

2. How We Process Your Data

Your data is processed strictly for the following purposes:

  • Verifying participant eligibility and suitability under pre-license professional criteria.
  • Managing trade execution, performance reporting, and administrative updates.
  • Maintaining our immutable regulatory compliance audit ledger.
  • Training and refining our internal proprietary trading and communication algorithms.

Third-Party AI Processing: We utilize third-party Artificial Intelligence (AI) service providers to assist with administrative drafting and system-internal analysis. All personal and financial data sent to these providers is routed strictly through secure, enterprise-level, non-training tunnels. These tunnels operate under zero-data-retention (ZDR) policies, ensuring your data is never used by third parties to train external models.

3. Data Retention

We retain all personal data, financial records, signed suitability forms, and system communication logs for a minimum of six (6) years from the date of creation. This data is stored in a secure, indexed, and unalterable format to satisfy DFSA and VARA regulatory audit obligations.

4. Security Measures

We implement rigorous technical and organizational security measures to prevent unauthorized access, alteration, disclosure, or destruction of your data. These measures include:

  • End-to-end encryption of all database communications and database storage tables at rest.
  • Strict role-based access controls restricting client data access to designated system operators.
  • Secure database firewalls and automated threat-monitoring protocols.

5. Your Data Subject Rights

Under the DIFC Data Protection Law 2020, you possess the following legal rights regarding your data:

  • Right of Access: The right to request a copy of the personal and financial data we hold on you.
  • Right to Rectification: The right to request correction of inaccurate or incomplete records.
  • Right to Erasure (“Right to be Forgotten”): The right to request deletion of your data, subject to our overriding 6-year regulatory record-keeping retention requirements.
  • Right to Restrict or Object to Processing: The right to limit how we process your data or object to specific automated decision-making processes.

To exercise any of these rights, please contact our Compliance Officer directly.

ORION Capital · Privacy Policy v1.0 · July 17, 2026