Legal

Privacy Policy

How Sagebrush Wealth FZE collects, uses, and protects your personal data.

Effective Date: 15th June, 2026

Sagebrush Wealth FZE (“Sagebrush”, “we”, “our” or “us”) respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how we collect, use, disclose, transfer, store, protect and retain personal data when you visit our website, communicate with us, apply to become a client, or use our virtual asset management and investment services.

Sagebrush Wealth FZE is established in the Dubai World Trade Centre Free Zone, United Arab Emirates. Sagebrush intends to provide virtual asset management and investment services, subject to applicable regulatory approvals, licensing conditions and ongoing compliance obligations.

This Privacy Policy should be read together with any applicable client agreement, product terms, risk disclosures, cookie notice, terms of service and other notices provided to you.

Who This Policy Applies To

  • Website visitors
  • Persons who contact us or submit enquiries
  • Newsletter, event or marketing subscribers
  • Prospective, current and former clients
  • Retail, professional and institutional clients
  • Investors, beneficial owners and authorised representatives
  • Directors, officers, employees, contractors, vendors and service providers
  • Business partners, counterparties and professional advisers
  • Any other individual whose personal data we process in connection with our business

Personal Data We Collect

2.1 Identification and Verification Data

This may include name, date of birth, nationality, passport details, Emirates ID, residential address, tax identification number, proof of address, photographs, identity documents, corporate ownership information, beneficial ownership information, authorised representative details and verification records.

2.2 Financial, Investment and Suitability Data

This may include bank account details, payment information, source of funds, source of wealth, financial statements, tax information, investment objectives, investment experience, risk profile, liquidity needs, investor classification, suitability information, asset holdings and related supporting documents.

2.3 Virtual Asset and Transaction Data

This may include wallet addresses, transaction hashes, blockchain transaction history, deposits, withdrawals, conversions, asset transfers, trading activity, custody activity, staking activity, yield-related information, portfolio activity, source of funds indicators, source of wealth indicators, KYT alerts, blockchain analytics outputs, sanctions screening results, risk scores, transaction monitoring records and internal compliance assessments.

2.4 Technical, Security and Website Data

This may include IP address, device identifiers, browser type, operating system, website usage data, login records, authentication records, access logs, geolocation information where legally permitted, cookies, pixels, analytics identifiers, cybersecurity monitoring data and related technical information.

2.5 Communication Data

This may include emails, telephone recordings, chat messages, contact forms, support requests, complaint submissions, instructions, meeting notes, call notes and other communications with or relating to Sagebrush.

2.6 Marketing and Preference Data

This may include newsletter subscriptions, event registrations, marketing preferences, consent records, opt-out records, communication preferences and engagement with Sagebrush content.

2.7 Employee, Contractor and Vendor Data

Where applicable, this may include information used for recruitment, onboarding, access management, payroll, contract administration, security, compliance, regulatory filings, vendor management and internal governance.

2.8 Sensitive or Higher-Risk Data

Where necessary and permitted by law, we may process sensitive or higher-risk personal data for identity verification, AML/CFT compliance, sanctions screening, fraud prevention, security, employment administration, legal claims or regulatory purposes. Access to such data will be restricted and subject to appropriate safeguards.

How We Collect Personal Data

  • Directly from you when you visit our website, contact us, complete forms, subscribe to communications, apply for services, provide documents, or communicate with us
  • From client entities, beneficial owners, authorised representatives, counterparties, banks, custodians, exchanges, payment providers and other service providers
  • From identity verification, KYC, KYT, transaction monitoring, Travel Rule, sanctions screening, fraud prevention and blockchain analytics providers
  • From public blockchains, public databases, public registers, corporate registers, media sources and other publicly available sources
  • From regulators, courts, law enforcement agencies and competent authorities
  • From professional advisers, auditors, insurers, technology providers and cybersecurity providers
  • Through internal analysis, risk scoring, compliance reviews, transaction monitoring, wallet screening, investigations and client relationship management

How We Use Personal Data

  • Respond to enquiries and communicate with you
  • Assess whether we can onboard you or provide services to you
  • Verify identity, ownership, authority, eligibility and client classification
  • Assess source of funds, source of wealth, investment objectives, suitability and risk profile
  • Conduct KYC, CDD, EDD, sanctions, PEP, adverse media, KYT, wallet screening, Travel Rule and transaction monitoring checks
  • Open, maintain and administer client accounts and client relationships
  • Provide virtual asset management, investment, portfolio, staking, auto-invest, yield-related or other services where available
  • Process, monitor, review or support deposits, withdrawals, conversions, transactions and asset transfers
  • Support custody, banking, liquidity, wallet and operational arrangements
  • Provide reporting, account administration, customer support and complaint handling
  • Detect, prevent, assess and investigate fraud, money laundering, terrorist financing, proliferation financing, sanctions evasion, market abuse, cybersecurity threats, suspicious transactions and misuse of services
  • Comply with legal, regulatory, AML/CFT, sanctions, tax, audit, court, law enforcement and regulatory reporting obligations
  • Comply with Travel Rule-related obligations where applicable
  • Manage disputes, investigations, audits, insurance, legal claims, risk management and internal governance
  • Maintain our website, systems, cybersecurity controls, access logs, audit trails and business continuity arrangements
  • Manage vendors, business partners, professional advisers and operational counterparties
  • Send service updates, client notices, legal notices, regulatory communications, security alerts, newsletters, event invitations, market commentary, educational materials or marketing communications where permitted by law
  • Maintain records required for legal, regulatory, audit, risk management and financial crime prevention purposes

Legal Bases for Processing

We process personal data where one or more legal bases applies, including where:

  • you have provided consent
  • processing is necessary to perform or enter into a contract with you
  • processing is required to comply with legal or regulatory obligations
  • processing is necessary for legitimate business interests
  • processing is necessary for public interest, regulatory or financial crime prevention purposes
  • processing is necessary to establish, exercise or defend legal claims
  • processing is otherwise permitted under applicable law

Where we rely on consent, you may withdraw consent at any time. Withdrawal of consent will not affect processing carried out before withdrawal, or processing that we are required or permitted to continue for legal, regulatory, AML/CFT, sanctions, contractual, audit, investigation, dispute resolution or legitimate business reasons.

Virtual Asset and Blockchain Data

Because Sagebrush operates in the virtual asset sector, we may process blockchain-related data, including wallet addresses, transaction hashes, blockchain transaction history, asset flows, counterparty wallet exposure, source of funds indicators, source of wealth indicators, sanctions exposure, risk scores, KYT alerts, typology indicators, blockchain analytics outputs and related compliance assessments.

We may use blockchain analytics, wallet screening, KYT, sanctions screening, Travel Rule and transaction monitoring tools to assess blockchain activity and identify potential financial crime, sanctions, fraud, market abuse, cybersecurity, operational or regulatory risks.

Blockchain-related data may be used for onboarding, client due diligence, enhanced due diligence, transaction monitoring, sanctions compliance, fraud prevention, investigations, regulatory reporting, internal risk management, audit, legal claims and compliance with applicable legal or regulatory obligations.

Data recorded on public blockchains may be publicly visible, independently verifiable, replicated across decentralised networks and not capable of deletion, alteration or restriction by Sagebrush. Our ability to erase, restrict or modify blockchain-related data may therefore be limited where such data exists on public blockchain networks or must be retained for legal, regulatory, AML/CFT, sanctions, audit, investigation or dispute resolution purposes.

Automated Screening and Risk Tools

We may use automated or semi-automated tools to support identity verification, proof of address checks, sanctions screening, PEP screening, adverse media screening, wallet screening, KYT, Travel Rule compliance, transaction monitoring, fraud detection, cybersecurity monitoring and risk assessment.

Outputs from these tools may support internal decisions relating to onboarding, client classification, risk rating, enhanced due diligence, transaction review, account restrictions, suspicious activity review, regulatory reporting or refusal to onboard or continue a relationship.

Where required by applicable law, internal policy or the nature of the decision, appropriate human review will be applied.

Sharing Personal Data

We may share personal data where necessary for legal, regulatory, compliance, operational, service delivery or business purposes.

  • VARA and other regulators
  • The UAE Central Bank, the UAE Financial Intelligence Unit, law enforcement agencies, courts and competent authorities
  • Banks, payment providers, custodians, wallet infrastructure providers, exchanges and liquidity providers
  • Identity verification, KYC, KYT, Travel Rule, transaction monitoring, blockchain analytics, fraud prevention and sanctions screening providers
  • Technology, cloud, hosting, cybersecurity, data storage and business continuity providers
  • Auditors, legal advisers, tax advisers, consultants, insurers and other professional advisers
  • Administrators, business partners, counterparties, intermediaries and other operational service providers
  • Group companies, affiliates or related parties where applicable and lawful
  • Other parties where required or permitted by applicable law

We take reasonable steps to ensure that third parties handling personal data are subject to appropriate confidentiality, data protection, information security and breach notification obligations.

Vendor and Service Provider Controls

Where third-party service providers process personal data on our behalf or in connection with our services, we apply proportionate due diligence and oversight.

This may include reviewing the provider’s data protection, cybersecurity, confidentiality, resilience, regulatory status, operational controls, subcontracting arrangements, business continuity arrangements and incident response processes.

Where appropriate, contracts with service providers will include restrictions on use of personal data, confidentiality obligations, information security requirements, breach notification obligations, audit or oversight rights, sub-processor controls, return or deletion obligations and cooperation obligations in relation to data subject requests, incidents, investigations and regulatory enquiries.

International Transfers

We may transfer personal data outside the UAE where necessary for onboarding, compliance screening, KYT, Travel Rule compliance, custody, transaction processing, cloud hosting, technology infrastructure, professional advisory services, regulatory reporting, business administration or service delivery.

Where we transfer personal data internationally, we apply appropriate contractual, technical and organisational safeguards. These may include data processing agreements, confidentiality obligations, access restrictions, encryption, vendor due diligence, transfer risk assessments, security controls and restrictions on onward transfers.

Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including service delivery, legal and regulatory compliance, AML/CFT obligations, internal governance, audit, dispute resolution, investigations and financial crime prevention.

KYC, CDD, EDD, source of funds, source of wealth, transaction monitoring, wallet screening, sanctions screening, Travel Rule records, communications, complaint records and other AML/CFT-related records will be retained for a minimum period of five years from the end of the client relationship or completion of the relevant transaction, whichever is later, unless a longer period is required by law, regulation, court order, regulatory request, investigation, audit or internal risk management requirement.

Where deletion is requested, we may decline or defer deletion where continued retention is required or permitted for legal, regulatory, AML/CFT, sanctions, tax, audit, litigation, investigation, dispute resolution or risk management purposes.

After the applicable retention period ends, personal data will be securely deleted, anonymised or archived in accordance with our internal procedures.

Information Security

We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, disclosure or destruction.

  • Access controls
  • Multi-factor authentication
  • Privileged access monitoring
  • Encryption of data at rest and in transit
  • Logging and monitoring
  • Cybersecurity controls
  • Vulnerability management
  • Secure storage
  • Vendor due diligence
  • Staff training
  • Incident response procedures
  • Periodic review of security measures

No website, transmission method or technology system is completely secure. You are responsible for keeping your own devices, credentials, wallets, email accounts and authentication methods secure.

Your Rights

Subject to applicable law, you may have rights to:

  • request access to personal data we hold about you
  • request correction of inaccurate or incomplete data
  • request deletion where legally permissible
  • request restriction of processing
  • request portability of personal data
  • withdraw consent where processing is based on consent
  • object to processing in circumstances permitted by law
  • lodge a complaint with a competent data protection authority, where applicable

To exercise your rights, please contact us using the details below. We may require reasonable information to verify your identity and authority before processing your request.

We may decline, limit or delay a request where permitted or required by law, including where the request conflicts with AML/CFT obligations, sanctions compliance, regulatory recordkeeping, court orders, legal privilege, investigations, cybersecurity, dispute resolution or the rights of others.

Cookies and Similar Technologies

Our website may use cookies, pixels and similar technologies to operate the website, improve functionality, support security, analyse usage and support marketing where permitted.

Cookies may include essential cookies, functional cookies, security cookies, analytics cookies, performance cookies and marketing cookies.

Where required by law, we will provide notice and obtain consent before using non-essential cookies. You may manage cookie settings through your browser or any cookie preference tool made available on our website.

Disabling certain cookies may affect the functionality or security of our website or digital platforms.

Marketing Communications

We may send newsletters, event invitations, service updates, educational materials, market commentary or marketing communications where permitted by law.

You may opt out of marketing communications at any time by using the unsubscribe link in the communication or by contacting us.

We may still send non-marketing communications relating to account administration, legal notices, regulatory matters, security alerts, service updates, contractual matters or compliance obligations.

Data Breaches

We maintain procedures for identifying, assessing, escalating, containing, investigating, remediating and documenting actual or suspected personal data breaches.

Where required by applicable law or regulation, we will notify the relevant regulator and/or affected individuals.

Children’s Privacy

Our website and services are not intended for minors. We do not knowingly provide services to minors or knowingly collect personal data from individuals under the age permitted by applicable law.

If we become aware that we have collected personal data from a minor without an appropriate legal basis or consent, we will take reasonable steps to delete or restrict such data, subject to legal and regulatory requirements.

Third-Party Websites

Our website may contain links to third-party websites, platforms, plug-ins or services. We are not responsible for the privacy practices, security or content of third-party websites or services.

You should review the privacy policies of any third-party websites or services you access.

Updates to this Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be posted on our website or otherwise made available where appropriate.

The effective date at the top of this Privacy Policy indicates when it was last updated.

Contact Us

Questions, requests or concerns regarding this Privacy Policy may be directed to:

Compliance Team

Sagebrush Wealth FZE

Dubai World Trade Centre

Dubai, United Arab Emirates

Email: compliance@sagebrushwealth.com