General Principle and Ownership
All technical and digital works, assets, systems and developments that are created, developed, designed, customized, trained, operated or activated for the Group or any of its subsidiaries, using the Group's resources, data, systems, devices, accounts, subscriptions, infrastructure or allocated working time, or pursuant to an assignment issued by it, are assets and rights belonging to the Group or to the relevant subsidiary, in accordance with the applicable contracts, agreements, policies and laws.
This includes anything developed, wholly or partly, by:
- Employees
- Trainees
- Officers
- Managers
- Programmers
- Developers
- Designers
- Consultants
- Contractors
- Suppliers
- Technology companies
- Service providers
- Independent contractors
- Any other person or entity working for the Group or using its resources, systems or data
Scope of Digital Assets and Rights
Digital and technical assets include, without limitation:
- Software code
- Source code
- Executable code
- Software and applications
- Websites
- Digital platforms and portals
- Smart systems
- Artificial intelligence models
- AI tools that are developed or customized
- AI agents
- Smart assistants
- Prompts
- Smart instructions and rules
- Algorithms
- Automation systems
- Automated operation systems
- Databases
- Database structures
- Knowledge bases
- Training data
- Application programming interfaces (APIs)
- Software integrations
- Dashboards
- Electronic forms
- Workflow systems
- Business logic
- Evaluation and classification systems
- Analysis tools
- Customer and opportunity discovery systems
- Data processing systems
- Decision-making systems
- Monitoring and alert systems
- Smart reporting tools
- Technical materials and documentation
- Operating manuals
- Training manuals
- Written content
- Original designs
- User interfaces
- Original graphics and images
- Logos
- Trademarks
- Trade names
- Visual identity
- Operational plans
- Customer journey maps
- Confidential data
- Unpublished technical and commercial information
- Any other digital or technical asset or development created for the Group
Development Using Group Resources
Any software, system, AI model, tool, code, design or technical project developed wholly or partly:
- during working hours;
- or using the Group's devices;
- or using its accounts;
- or using its subscriptions;
- or using its data;
- or using its technical infrastructure;
- or using its platforms;
- or pursuant to an administrative or operational assignment issued by it;
- or for the business purposes of the Group or any of its subsidiaries;
is subject to the legal and contractual rights of the Group or the relevant subsidiary.
The participation of any employee, trainee, developer, consultant or contractor in creating or developing a system does not automatically authorize them to use, copy, exploit or reproduce it outside the scope of their work.
Joint and Partial Development
A project or system does not need to have been developed entirely within the Group for the rights linked to the Group's contribution to it to arise.
Where any of the following has been used:
- The Group's resources
- Its data
- Its funding
- Its employees
- Its internal expertise
- Its accounts
- Its systems
- Its tools
- Its plans
- Its operating rules
- Or its approved assignments
in developing a project, system or digital asset, the related rights are governed by the contracts and agreements, each party's share of participation, and the nature of each party's legal ownership.
Updates and Future Developments
To the extent permitted by contracts and law, the Group's rights extend to all:
- Updates
- Improvements
- New releases
- Add-ons
- Modifications
- Customizations
- Derivative developments
- AI model training
- Fine-tuning
- Prompt optimization
- Algorithm development
- Knowledge base development
- Database updates
- Automation system development
- System restructuring
- New features
- More advanced versions of the original system
where this is done for the Group, using its resources, data or systems, or within approved tasks and assignments.
Restrictions on Employees, Trainees and Contractors
No person may, without prior written approval from the competent management:
- Copy any code
- Copy a system or software
- Copy an AI model
- Send code to a personal email address
- Store files in personal cloud accounts
- Load code onto unauthorized devices
- Transfer databases
- Copy databases
- Share confidential data
- Share internal prompts
- Share system configurations
- Share API keys
- Share passwords
- Share access tokens
- Share user accounts
- Photograph technical or confidential content without authorization
- Extract content from internal systems
- Use Group assets in a personal project
- Use them for another party
- Use them for a competing company
- Resell them
- Re-license them
- Publish them
- Redistribute them
- Create a copy of them for another activity
- Transfer them to a third party
- Keep copies of them after the end of employment, training or engagement
Protection of Websites and Digital Platforms
The websites, platforms and digital portals of the Group and its subsidiaries form part of the Group's digital assets, with respect to the elements, content, systems and rights that the Group owns or is legally entitled to use.
Depending on each website or platform, this includes:
- Code
- Content
- Original designs
- Electronic forms
- Internal systems
- Databases
- Smart tools
- Customer digital journeys
- Request systems
- Interactive tools
- Reports
- Marks
- Logos
- Names
- Original visual elements
Visitor Access to Websites
A visitor's mere access to any website or platform of the Group does not grant them any ownership right in the assets or rights on that website.
Nor does accessing or using the website constitute:
- A license to copy content
- A license to reproduce systems
- A license to use content commercially
- A waiver of intellectual property rights
- Permission to use trademarks
- Permission to extract confidential data
- Permission to recreate technical systems
Use of the website is limited to the lawful and ordinary use for which it was made available, in accordance with the terms of use and the law.
Prohibition on Copying from Websites
Without prior written permission, any of the following acts is prohibited where it concerns a protected asset or content belonging to the Group:
- Copying website content
- Copying original texts
- Copying protected designs
- Copying original images and graphics
- Copying electronic forms
- Copying website pages for commercial reuse
- Republishing content under another party's name
- Copying code
- Extracting databases without authorization
- Extracting confidential information
- Copying smart tools
- Copying internal prompts
- Copying protected work systems or software
- Removing ownership information
- Removing the right holder's name
- Altering or hiding copyright notices
Imitation, Simulation and Unlawful Use
The Group and its subsidiaries reserve all their legal rights against any person or entity that, without legal basis or approved authorization, imitates, uses or exploits protected assets belonging to the Group.
Depending on the nature of the right, this includes:
- Logos
- Trademarks
- Trade names
- Visual identity
- Original designs
- Creative content
- Code and software
- Protected databases
- Electronic forms
- Software systems
- Written materials
- Protected digital tools or products
It also includes presenting an asset or product of the Group as belonging to another person or company.
General Ideas and Unprotected Elements
This policy does not seek to claim ownership of general ideas, methods, functions or common practices over which the law grants no exclusive right.
Rather, protection extends to the assets, rights, works, data, marks, trade secrets and contractual rights that the Group or its subsidiaries own or are legally entitled to use.
Unauthorized Access
No person may attempt to:
- Access a system they are not authorized to use
- Enter internal pages they are not permitted to access
- Exceed the level of permission granted to them
- Bypass protection systems
- Bypass authentication mechanisms
- Use another person's account
- Use passwords that do not belong to them
- Obtain access tokens without authorization
- Access confidential data without permission
- Extract internal data
- Access source code without authorization
- Modify data without permission
- Delete data without permission
- Download data without authorization
- Tamper with the Group's systems
- Disable systems
- Deliberately affect the efficiency or operation of systems
Reverse Engineering and Technology Extraction
To the extent permitted by law and contracts, it is prohibited to attempt to:
- Decompile or analyze systems without authorization
- Extract internal code
- Extract system logic
- Access components that are not available to the public
- Bypass security controls
- Extract databases without authorization
- Rebuild a protected system using materials or code obtained unlawfully
Use of External AI Tools
No confidential or technical information belonging to the Group may be entered into unapproved external AI tools or accounts.
This includes:
- Source code
- Confidential customer data
- Personal data not authorized for sharing
- Databases
- Confidential prompts
- Internal knowledge bases
- API keys
- Passwords
- Access tokens
- Confidential contracts
- Confidential legal information
- Unpublished financial data
- Strategic plans
- Business plans
- Internal documents
- Unpublished operational information
Approved accounts, tools and platforms must be used in line with the Group's information security and data protection policies.
Protection of Data and Knowledge Bases
Databases, knowledge bases and commercial, technical and operational information that is not available to the public are important assets of the Group.
Without approved authorization, they may not be:
- Copied
- Downloaded
- Transferred
- Sold
- Shared
- Published
- Leaked
- Used for personal benefit
- Used for the benefit of an external party
- Used to set up a competing activity
- Used to train an external system
- Used outside the authorized purpose
This applies with due regard to the rights of data subjects and to the applicable data protection and privacy laws.
Confidentiality and Trade Secrets
All information that is not available to the public, relates to the Group's business and is confidential, commercial or technical in nature must be protected in accordance with the approved contracts, laws and policies.
This may include:
- Strategies
- Market studies
- Financial information
- Customer data
- Expansion plans
- Internal pricing rules
- Business relationships
- Supplier data
- Customer sources
- Evaluation algorithms
- Operating plans
- Technical information
- Code
- Internal work procedures
- Development documentation
Group Accounts and Devices
Accounts, devices, services and subscriptions provided by the Group are institutional work tools.
It is not permitted to:
- Share accounts without authorization
- Grant access to an external party
- Change recovery details for personal purposes
- Use an institutional account after access has expired
- Move institutional data to a personal account
- Keep passwords or access keys after the relationship ends
- Use Group devices for purposes that put system security at risk
Preservation of Digital Evidence
In accordance with the law and the applicable data protection and privacy policies, the Group reserves the right to use the technical means necessary to protect its systems and assets and to document the related activity.
These means may include:
- Login records
- User records
- Permission records
- Download records
- Modification records
- Upload records
- API logs
- System logs
- Cybersecurity logs
- Unauthorized access attempts
- Backups
- Technical data relating to devices and accounts, where permitted by law
These records may be used in internal investigations, to protect rights, or in legal proceedings, in accordance with the law.
Detection of Copying, Imitation or Unauthorized Use
If the Group discovers that a person or entity has copied, imitated, exploited or used any of its assets without authorization, it is entitled to take appropriate action to preserve its rights.
The violation need not have been committed by an employee or contractor.
Depending on the nature of the incident, the policy also covers any:
- Website visitor
- Platform user
- Company
- Competitor
- Service provider
- Current or former employee
- Contractor
- Developer
- Or any other third party
Group Measures in the Event of a Violation
If a violation is discovered or seriously suspected, the Group and its subsidiaries reserve the right to take the necessary legal, technical and administrative measures, as each case requires.
These may include:
- Suspending access rights
- Canceling the account
- Disabling the account or access keys
- Protecting systems and data
- Preserving digital evidence
- Opening an internal investigation
- Documenting the incident
- Issuing an administrative warning
- Issuing a legal notice
- Requiring the person or entity to stop the use
- Requesting removal of the infringing content
- Requesting deletion of unauthorized copies
- Demanding the return of assets or data
- Contacting the hosting provider
- Contacting the platform hosting the infringing content
- Filing takedown or blocking requests where legally available
- Filing a complaint with the competent authorities
- Taking the civil, commercial or criminal action available under the law
- Bringing proceedings before the courts or competent authorities
- Claiming compensation where the legal grounds exist
- Taking any other measure permitted by law
The Group's Right to Bring Legal Action
The Group and its subsidiaries reserve the right to bring legal action or take appropriate legal measures against any natural or legal person proven to have unlawfully infringed any of their protected rights or assets.
Depending on the facts, this includes:
- Unlawful copying
- Unauthorized use
- Copyright infringement
- Trademark infringement
- Unlicensed use of digital assets
- Unauthorized acquisition of confidential information
- Unauthorized access to systems
- Data leakage
- Unlawful use of commercial or technical information
- Or any other act that constitutes a violation under the applicable laws
Right to Claim Compensation
The Group and its subsidiaries reserve the right to claim compensation for damage and losses that are legally proven to have resulted from an infringement of their rights or assets.
Depending on the nature of the damage and what the law permits, a claim may cover:
- Financial losses
- Commercial damage
- Costs of restoring systems
- Costs of technical investigation
- Costs of remedying a leak or breach
- Damage resulting from unlawful use
- Damage to the brand or business
- Any other damage or expenses recognized by law and proven before the competent authority
This policy does not automatically or in advance set the amount of compensation.
Any claim is assessed in accordance with the contracts, the evidence, the laws and the decisions of the competent judicial authorities.
Stopping a Violation Does Not Cancel the Right to Compensation
Where the infringing person:
- deletes the copy;
- or removes the content;
- or stops the use;
- or closes the infringing website;
- or returns the data;
this does not in itself extinguish the Group's rights to take legal action or to claim compensation for past damage, where there is a legal basis for doing so.
No Waiver of Rights
The Group's failure to take immediate action on a particular violation shall not be deemed:
- A waiver of its rights
- Acceptance of the violation
- A license to use the asset
- A relinquishment of intellectual property
- A relinquishment of the right to claim
- Or implied consent to continued use
The Group reserves the right to take appropriate action at any time permitted by law.
End of Employment, Training or Engagement
When any person's relationship with the Group ends, they must, in accordance with their contract and the applicable policies:
- Hand over code
- Hand over project files
- Hand over documents
- Hand over devices
- Return assets
- Hand over institutional accounts following the approved procedures
- Hand over access keys
- Return data
- Cooperate in knowledge transfer
- Stop using their access rights
- Delete unauthorized copies held on personal devices or accounts
- Not retain Group data outside the authorized frameworks
The Group may request a written or electronic acknowledgment that the handover has been completed.
Obligations That Continue After the Relationship Ends
Obligations relating to:
- Confidentiality
- Data protection
- Trade secrets
- Protection of intellectual property
- Not retaining assets
- Not using code and systems without authorization
- Returning assets
- Protection of accounts and data
remain in force after the end of employment, training or engagement, to the extent permitted by the applicable laws and contracts.
Precedence of Contracts and Policies
This policy is read together with:
- Employment contracts
- Training contracts
- Development contracts
- Programmer contracts
- Consultant contracts
- Supplier contracts
- Non-disclosure agreements (NDAs)
- Intellectual property agreements
- Rights assignment agreements, where required
- Website terms of use
- The privacy policy
- The data protection policy
- The information security policy
- The AI use policy
- Access and permissions policies
- Relevant commercial agreements
In the event of a conflict, reference is made to the binding laws, agreements and contracts according to the nature of each case.
No Implied Rights
No access to any:
- Website
- Platform
- Dashboard
- System
- Account
- Application
- Database
- File
- Software
grants any ownership right or license beyond the limits of the expressly authorized use.
The Approved Institutional Rule
Everything built, developed, designed, customized, trained or operated for the Group using its resources, data, systems, accounts or technical infrastructure, or pursuant to an approved assignment from it, is an asset of the Group or of the relevant subsidiary, in accordance with the applicable contracts, agreements and laws.
Making any website, system, platform or content available to the public does not mean that the Group waives its rights in it, and does not give anyone the right to copy, imitate, exploit or commercially reuse protected assets without authorization or legal basis.
The Group and its subsidiaries reserve all their rights to protect their code, systems, data, websites, marks, content and digital assets, and to take appropriate administrative, technical and legal measures, including bringing legal action and claiming compensation once the violation and the damage are proven in accordance with the law.
Official UAE Legal Framework
Depending on the nature of each right or incident and the scope of application of the legislation, this policy is based on the laws and legislation in force in the United Arab Emirates, including:
- Federal Decree-Law No. (38) of 2021 on Copyright and Neighboring Rights
- Federal Decree-Law No. (36) of 2021 on Trademarks
In addition, Federal Decree-Law No. (34) of 2021 on Combating Rumors and Cybercrimes contains provisions relating to cybercrime and to unlawful access to, or handling of, certain data and information, including provisions on the confidential data and information of financial, commercial and economic establishments, in accordance with the scope of application, conditions and elements set out in that law.
This policy is applied subject to any amendments, legislation, decisions or implementing regulations in force now or in the future in the United Arab Emirates, and without conflict with the applicable laws and regulations.
Final Legal Notice
This policy aims to regulate and protect the intellectual property and the digital and technical assets of the Group and its subsidiaries. No provision of it shall be interpreted as granting the Group rights beyond those established by the applicable laws, contracts or licenses.
Liability, measures and compensation in each case are determined based on the nature of the incident, the evidence, the contracts, the applicable legislation and the decisions of the competent authorities.
All rights reserved to the Group and its subsidiaries in accordance with the law.

