Unified Policy for the Protection of Intellectual Property, Digital Assets and Smart Systems
Protection policy for code – systems – artificial intelligence – websites – data – digital assets
1. General Principle and Ownership
All works, assets, systems and technical and digital developments that are created, developed, designed, customised, trained, operated or activated for the Group or any of its affiliated companies, using the Group's resources, data, systems, devices, accounts, subscriptions, infrastructure or allocated working time, or on the basis of an assignment issued by it, are assets and rights belonging to the Group or to the relevant affiliated company, in accordance with the applicable contracts, agreements, policies and laws.
This includes anything developed wholly or partly by:
- Employees.
- Trainees.
- Officers.
- Managers.
- Programmers.
- Developers.
- Designers.
- Consultants.
- Contractors.
- Suppliers.
- Technology companies.
- Service providers.
- Independent contractors.
- Any person or entity working for the Group or using its resources, systems or data.
2. Scope of Digital Assets and Rights
Digital and technical assets include, without limitation:
- Software code.
- Source code.
- Executable code.
- Software and applications.
- Websites.
- Digital platforms and portals.
- Smart systems.
- Artificial intelligence models.
- AI tools that are developed or customised.
- AI agents.
- Smart assistants.
- Prompts.
- Smart instructions and rules.
- Algorithms.
- Automation systems.
- Automated operating systems.
- Databases.
- Database structures.
- Knowledge bases.
- Training data.
- Application programming interfaces (APIs).
- Software integrations.
- Dashboards.
- Electronic forms.
- Workflow systems.
- Business logic.
- Evaluation and classification systems.
- Analysis tools.
- Client and opportunity discovery systems.
- Data processing systems.
- Decision-making systems.
- Monitoring and alert systems.
- Smart reporting tools.
- Technical materials and documentation.
- Operating manuals.
- Training manuals.
- Written content.
- Original designs.
- User interfaces.
- Original graphics and images.
- Logos.
- Trademarks.
- Trade names.
- Visual identity.
- Operational plans.
- Customer journey maps.
- Confidential data.
- Unpublished technical and commercial information.
- Any other digital or technical asset or development created for the Group.
3. Development Using Group Resources
Any software, system, artificial intelligence model, tool, code, design or technical project developed wholly or partly:
- during working hours;
- or using the Group's devices;
- or using its accounts;
- or using its subscriptions;
- or using its data;
- or using its technical infrastructure;
- or using its platforms;
- or on the basis of an administrative or operational assignment issued by it;
- or for the business purposes of the Group or any of its affiliated companies;
is subject to the legal and contractual rights of the Group or of the relevant affiliated company.
The participation of any employee, trainee, developer, consultant or contractor in creating or developing a system does not constitute automatic permission for them to use, copy, exploit or reproduce it outside the scope of their work.
4. Joint and Partial Development
A project or system does not need to have been developed entirely within the Group for rights linked to the Group's contribution to arise.
If any of the following were used:
- The Group's resources.
- Its data.
- Its funding.
- Its employees.
- Its internal expertise.
- Its accounts.
- Its systems.
- Its tools.
- Its plans.
- Its operating rules.
- Or its approved assignments
in developing a project, system or digital asset, the related rights are governed by the contracts and agreements, the share of participation and the legal nature of each party's ownership.
5. Future Updates and Developments
To the extent permitted by contracts and laws, the Group's rights cover all:
- Updates.
- Improvements.
- New releases.
- Additions.
- Modifications.
- Customisations.
- Derivative developments.
- Artificial intelligence model training.
- Fine-tuning.
- Prompt optimisation.
- Algorithm development.
- Knowledge base development.
- Database updates.
- Automation system development.
- System restructuring.
- Addition of new features.
- Development of more advanced versions of the original system.
whenever this is done for the Group, using its resources, data or systems, or within approved tasks and assignments.
6. Restrictions on Employees, Trainees and Contractors
No person may, without prior written approval from the competent management:
- Copy any code.
- Copy a system or software.
- Copy an artificial intelligence model.
- Send code to a personal email.
- Store files on personal cloud accounts.
- Upload code to unauthorised devices.
- Transfer databases.
- Copy databases.
- Share confidential data.
- Share internal prompts.
- Share system settings.
- Share API keys.
- Share passwords.
- Share access tokens.
- Share user accounts.
- Photograph technical or confidential content without authorisation.
- Extract content from internal systems.
- Use Group assets in a personal project.
- Use them for another party.
- Use them for a competing company.
- Resell them.
- Relicense them.
- Publish them.
- Redistribute them.
- Create a copy of them for another activity.
- Transfer them to a third party.
- Keep copies of them after the end of employment, training or the contract.
7. Protection of Websites and Digital Platforms
The websites, platforms and digital portals of the Group and its affiliated companies form part of the Group's digital assets, with respect to the elements, content, systems and rights that the Group owns or is legally authorised to use.
Depending on each website or platform, this includes:
- Code.
- Content.
- Original designs.
- Electronic forms.
- Internal systems.
- Databases.
- Smart tools.
- Digital customer journeys.
- Request systems.
- Interactive tools.
- Reports.
- Marks.
- Logos.
- Names.
- Original visual elements.
8. Visitor Access to Websites
A visitor's mere access to any website or platform of the Group does not grant them any ownership right in the assets or rights on the website.
Nor does accessing or using the website constitute:
- A licence to copy the content.
- A licence to reproduce the systems.
- A licence for commercial use of the content.
- A waiver of intellectual property rights.
- Permission to use the trademarks.
- Permission to extract confidential data.
- Permission to recreate the technical systems.
Use of the website is limited to the lawful and ordinary use for which the website was made available, in accordance with the terms of use and the law.
9. Prohibition of Copying from Websites
Without prior written permission, it is prohibited to carry out any of the following acts where they relate to a protected asset or content belonging to the Group:
- Copying website content.
- Copying original texts.
- Copying protected designs.
- Copying original images and graphics.
- Copying electronic forms.
- Copying website pages for commercial reuse.
- Republishing content under another party's name.
- Copying code.
- Extracting databases without authorisation.
- Extracting confidential information.
- Copying smart tools.
- Copying internal prompts.
- Copying protected work systems or software.
- Removing ownership information.
- Removing the name of the rights holder.
- Altering or concealing copyright notices.
10. Imitation, Simulation and Unlawful Use
The Group and its affiliated companies reserve all their legal rights against any person or entity that, without legal basis or approved authorisation, imitates, uses or exploits protected assets belonging to the Group.
Depending on the nature of the right, this includes:
- Logos.
- Trademarks.
- Trade names.
- Visual identity.
- Original designs.
- Creative content.
- Code and software.
- Protected databases.
- Electronic forms.
- Software systems.
- Written materials.
- Protected digital tools or products.
It also includes presenting an asset or product of the Group as belonging to another person or company.
11. General Ideas and Unprotected Elements
This policy does not seek to claim ownership of general ideas, methods, functions or common practices in respect of which the law grants no exclusive right.
Rather, protection extends to the assets, rights, works, data, marks, trade secrets and contractual rights that the Group or its affiliated companies own or are legally authorised to use.
12. Unauthorised Access
Any person is prohibited from attempting to:
- Access a system they are not authorised to use.
- Enter internal pages they are not permitted to access.
- Exceed the level of permission granted to them.
- Bypass protection systems.
- Bypass authentication mechanisms.
- Use another person's account.
- Use passwords that do not belong to them.
- Obtain access tokens without authorisation.
- Access confidential data without permission.
- Extract internal data.
- Access source code without authorisation.
- Modify data without permission.
- Delete data without permission.
- Download data without authorisation.
- Tamper with the Group's systems.
- Disable systems.
- Deliberately affect the efficiency or operation of systems.
13. Reverse Engineering and Technology Extraction
To the extent permitted by law and contracts, it is prohibited to attempt to:
- Decompile or analyse systems without authorisation.
- Extract internal code.
- Extract system logic.
- Access components that are not available to the public.
- Bypass security controls.
- Extract databases without authorisation.
- Rebuild a protected system using materials or code obtained unlawfully.
14. Use of External Artificial Intelligence Tools
No confidential or technical information belonging to the Group may be entered into unapproved external artificial intelligence tools or accounts.
This includes:
- Source code.
- Confidential client data.
- Personal data not authorised for sharing.
- Databases.
- Confidential prompts.
- Internal knowledge bases.
- API keys.
- Passwords.
- Access tokens.
- Confidential contracts.
- Confidential legal information.
- Unpublished financial data.
- Strategic plans.
- Business plans.
- Internal documents.
- Unpublished operational information.
Approved accounts, tools and platforms must be used in accordance with the Group's information security and data protection policies.
15. Protection of Data and Knowledge Bases
Databases, knowledge bases and commercial, technical and operational information not available to the public are important assets of the Group.
Without approved authorisation, it is not permitted to:
- Copy them.
- Download them.
- Transfer them.
- Sell them.
- Share them.
- Publish them.
- Leak them.
- Use them for personal benefit.
- Use them in the interest of an external party.
- Use them to create a competing activity.
- Use them to train an external system.
- Use them outside the authorised purpose.
This applies with due regard to the rights of data subjects and the applicable data protection and privacy laws.
16. Confidentiality and Trade Secrets
All information not available to the public that relates to the Group's business and is confidential, commercial or technical in nature must be protected in accordance with the approved contracts, laws and policies.
It may include:
- Strategies.
- Market studies.
- Financial information.
- Client data.
- Expansion plans.
- Internal pricing rules.
- Business relationships.
- Supplier data.
- Client sources.
- Evaluation algorithms.
- Operating plans.
- Technical information.
- Code.
- Internal work procedures.
- Development documentation.
17. Group Accounts and Devices
The accounts, devices, services and subscriptions provided by the Group are corporate work tools.
It is not permitted to:
- Share accounts without authorisation.
- Grant an external party access rights.
- Change recovery details for personal purposes.
- Use a corporate account after its authorisation has expired.
- Transfer corporate data to a personal account.
- Keep passwords or access keys after the relationship ends.
- Use Group devices for purposes that put system security at risk.
18. Preservation of Digital Evidence
In accordance with the law and the applicable data protection and privacy policies, the Group reserves the right to use the technical means necessary to protect its systems and assets and to document related activities.
These means may include:
- Login records.
- User records.
- Permission records.
- Download records.
- Modification records.
- Upload records.
- API logs.
- System logs.
- Cybersecurity logs.
- Unauthorised access attempts.
- Backups.
- Technical data relating to devices and accounts where permitted by law.
These records may be used in internal investigations, to protect rights or in legal proceedings in accordance with the law.
19. Detection of Copying, Imitation or Unauthorised Use
If the Group discovers that a person or entity has copied, imitated, exploited or used any of its assets without authorisation, it is entitled to take appropriate measures to preserve its rights.
The violation need not have been committed by an employee or contractor.
Depending on the nature of the incident, the policy also covers any:
- Website visitor.
- Platform user.
- Company.
- Competitor.
- Service provider.
- Current or former employee.
- Contractor.
- Developer.
- Or any third party.
20. Group Measures in the Event of a Violation
If a violation or a serious suspicion of a violation is discovered, the Group and its affiliated companies reserve the right to take the necessary legal, technical and administrative measures, as each case requires.
These may include:
- Suspending access rights.
- Cancelling the account.
- Disabling the account or access keys.
- Protecting systems and data.
- Preserving digital evidence.
- Opening an internal investigation.
- Documenting the incident.
- Issuing an administrative warning.
- Issuing a legal warning.
- Requiring the person or entity to stop the use.
- Requesting removal of the infringing content.
- Requesting deletion of unauthorised copies.
- Demanding the return of assets or data.
- Contacting the hosting provider.
- Contacting the platform hosting the infringing content.
- Submitting removal or blocking requests where legally available.
- Filing a complaint with the competent authorities.
- Taking the civil, commercial or criminal action legally available.
- Filing lawsuits before the courts or competent authorities.
- Claiming compensation where the legal grounds exist.
- Taking any other measure permitted by law.
21. The Group's Right to Take Legal Action
The Group and its affiliated companies reserve the right to file lawsuits or take appropriate legal action against any natural or legal person proven to have unlawfully infringed any of their protected rights or assets.
Depending on the incident, this includes:
- Unlawful copying.
- Unauthorised use.
- Copyright infringement.
- Trademark infringement.
- Unlicensed use of digital assets.
- Unauthorised acquisition of confidential information.
- Unauthorised access to systems.
- Data leakage.
- Unlawful use of commercial or technical information.
- Or any other act constituting a violation under the applicable laws.
22. The Right to Claim Compensation
The Group and its affiliated companies reserve the right to claim compensation for damages and losses legally proven to have resulted from the infringement of their rights or assets.
Depending on the nature of the damage and what the law permits, the claim may include:
- Financial losses.
- Commercial damage.
- System recovery costs.
- Technical investigation costs.
- Costs of remedying a leak or breach.
- Damage resulting from unlawful use.
- Damage relating to the brand or business activity.
- Any other damages or expenses recognised by law and proven before the competent authority.
This policy does not constitute an automatic or advance determination of the amount of compensation.
Any claim is assessed in accordance with the contracts, evidence, laws and decisions issued by the competent judicial authorities.
23. Stopping a Violation Does Not Cancel the Right to Compensation
The fact that the violating person:
- deletes the copy;
- or removes the content;
- or stops the use;
- or closes the infringing website;
- or returns the data;
does not in itself extinguish the Group's rights to take legal action or to claim compensation for prior damage, where there is a legal basis for doing so.
24. No Waiver of Rights
The Group's failure to take immediate action against a particular violation does not constitute:
- A waiver of its rights.
- Acceptance of the violation.
- A licence to use the asset.
- A forfeiture of intellectual property.
- A forfeiture of the right to claim.
- Or implied consent to continued use.
The Group reserves the right to take appropriate action at the time permitted by law.
25. End of Employment, Training or Contractual Relationship
When any person's relationship with the Group ends, they must, in accordance with the contract and applicable policies:
- Hand over code.
- Hand over project files.
- Hand over documents.
- Hand over devices.
- Return assets.
- Hand over corporate accounts in accordance with approved procedures.
- Hand over access keys.
- Return data.
- Cooperate in knowledge transfer.
- Stop using permissions.
- Delete unauthorised copies held on personal devices or accounts.
- Not retain Group data outside authorised frameworks.
The Group may request a written or electronic acknowledgement that the handover has been completed.
26. Continuing Obligations After the Relationship Ends
Obligations relating to:
- Confidentiality.
- Data protection.
- Trade secrets.
- Intellectual property protection.
- Not retaining assets.
- Not using code and systems without authorisation.
- Returning assets.
- Protecting accounts and data.
remain in force after the end of the employment, training or contractual relationship, to the extent permitted by the applicable laws and contracts.
27. Precedence of Contracts and Policies
This policy is read together with:
- Employment contracts.
- Training contracts.
- Development contracts.
- Programmer contracts.
- Consultant contracts.
- Supplier contracts.
- Non-disclosure agreements (NDAs).
- Intellectual property rights agreements.
- Rights transfer agreements where needed.
- Website terms of use.
- The privacy policy.
- The data protection policy.
- The information security policy.
- The artificial intelligence use policy.
- Access and permission policies.
- Related commercial agreements.
In the event of a conflict, reference is made to the binding laws, agreements and contracts according to the nature of each case.
28. No Implied Rights
Access to any:
- Website.
- Platform.
- Dashboard.
- System.
- Account.
- Application.
- Database.
- File.
- Software.
does not grant any ownership right or licence beyond the limits of the expressly authorised use.
29. The Approved Corporate Rule
Anything built, developed, designed, customised, trained or operated for the Group using its resources, data, systems, accounts or technical infrastructure, or on the basis of an assignment approved by it, is an asset of the Group or of the relevant affiliated company, in accordance with the applicable contracts, agreements and laws.
Making any website, system, platform or content available to the public does not mean waiving the Group's rights in it, and does not grant anyone the right to copy, imitate, exploit or commercially reuse protected assets without authorisation or legal basis.
The Group and its affiliated companies reserve all their rights to protect their code, systems, data, websites, marks, content and digital assets, and to take appropriate administrative, technical and legal measures, including filing lawsuits and claiming compensation where the violation and damage are proven in accordance with the law.
30. Official UAE Legal Reference
Depending on the nature of each right or incident and the scope of application of the legislation, this policy is based on the laws and legislation in force in the United Arab Emirates, including:
- Federal Decree-Law No. (38) of 2021 on Copyright and Neighbouring Rights.
- Federal Decree-Law No. (36) of 2021 on Trademarks.
Federal Decree-Law No. (34) of 2021 on Combating Rumours and Cybercrimes also contains provisions relating to cybercrimes and to unlawful access to or dealing with certain data and information, including provisions on confidential data and information of financial, commercial and economic establishments, in accordance with the scope of application, conditions and elements set out in the law.
This policy is applied subject to any amendments, legislation, decisions or executive regulations in force now or in the future in the United Arab Emirates, and without conflicting with the applicable laws and regulations.
Final Legal Notice
This policy aims to regulate and protect the intellectual property and the digital and technical assets of the Group and its affiliated companies, and no provision of it shall be interpreted as granting the Group rights beyond those established by the applicable laws, contracts or licences.
Liability, measures and compensation in each case are determined on the basis of the nature of the incident, the evidence, the applicable contracts and legislation, and the decisions of the competent authorities.
All rights reserved to the Group and its affiliated companies in accordance with the law.