Skip to main content

Search companies and services

Unified policy for the protection of intellectual property, digital assets and smart systems

Code protection policy - systems - artificial intelligence - websites - data - digital assets

1. General principle and ownership

All technical and digital works, assets, systems and developments created, developed, designed, customized, trained, operated or activated for the Group or any of its subsidiaries, using the Group’s resources, data, systems, devices, accounts, subscriptions, infrastructure or allocated working time, or pursuant to an assignment from it, constitute assets and rights of the Group or the relevant subsidiary, in accordance with applicable contracts, agreements, policies and laws.

This includes those developed in whole or in part by:

  • Staff.
  • Trainees.
  • Officials.
  • Managers.
  • Programmers.
  • Developers.
  • Designers.
  • Advisors.
  • Contractors.
  • Suppliers.
  • Technology companies.
  • Service providers.
  • Independent contractors.
  • Or any person or entity working for the group or using its resources, systems or data.

2. The scope of digital assets and rights

Digital and technology assets include, but are not limited to:

  • Software codes.
  • Source code.
  • Executable code.
  • Programs and applications.
  • Websites.
  • Digital platforms and portals.
  • Intelligent systems.
  • Artificial intelligence models.
  • Artificial intelligence tools that are developed or customized.
  • AI Agents.
  • Intelligent assistants.
  • Prompts.
  • Smart instructions and rules.
  • Algorithms.
  • Automation systems.
  • Automation systems.
  • Databases.
  • Database structures.
  • Knowledge bases.
  • Training data.
  • Application programming interfaces (APIs).
  • Software integrations.
  • Control panels.
  • Electronic forms.
  • Workflow systems.
  • Business Logic.
  • Evaluation and classification systems.
  • Analysis tools.
  • Customer and opportunity discovery systems.
  • Data processing systems.
  • Decision making systems.
  • Monitoring and alerts systems.
  • Smart reporting tools.
  • Technical materials and documentation.
  • Operation manuals.
  • Training manuals.
  • Written content.
  • Original designs.
  • User interfaces.
  • Original graphics and photos.
  • Logos.
  • Trademarks.
  • Trade names.
  • Visual identity.
  • Operational plans.
  • Customer journey maps.
  • Confidential data.
  • Unpublished technical and commercial information.
  • And any other digital or technical asset or development created for the benefit of the Group.

3. Development using group resources

Every program, system, artificial intelligence model, tool, code, design or technical project developed in whole or in part:

  • During working time;
  • or using group devices;
  • or using its accounts;
  • or by using its subscriptions;
  • or using its data;
  • Or using its technical structure;
  • or using its platforms;
  • Or based on an administrative or operational assignment issued by it;
  • or for the purposes of the business of the Group or any of its subsidiaries;

It is subject to the legal and contractual rights of the group or the relevant subsidiary.

The participation of any employee, trainee, developer, consultant or contractor in creating or developing the system does not automatically constitute permission for him to use, copy, exploit or reproduce it outside the scope of the work.

4. Joint and partial development

The project or system does not have to be entirely developed within the group for the rights associated with the group's contribution to it to arise.

If any of the following are used:

  • Group resources.
  • Its data.
  • Its funding.
  • Its employees.
  • Its internal expertise.
  • Its accounts.
  • Its systems.
  • Its tools.
  • Its plans.
  • Its operational rules.
  • Or its approved assignments

in developing a project, system or digital asset, the associated rights are governed by the contracts, agreements, proportion of participation and nature of each party’s legal ownership.

5. Future updates and developments

The Group's rights, as permitted by contracts and laws, include all:

  • Updates.
  • Improvements.
  • New releases.
  • Additions.
  • Amendments.
  • Customizations.
  • Derivative developments.
  • Artificial intelligence model training processes.
  • Fine-Tuning.
  • Improving prompts.
  • Algorithm development.
  • Developing knowledge bases.
  • Update databases.
  • Development of automation systems.
  • System restructuring.
  • Add new features.
  • Develop more advanced versions of the original system.

Whenever this is done for the benefit of the group or using its resources, data, or systems, or within the approved tasks and assignments.

6. The ban on employees, trainees and contractors

Without prior written approval from the competent management, no person may:

  • Copy any code.
  • Copying a system or program.
  • Copy an artificial intelligence model.
  • Send codes to a personal email.
  • Store files on personal cloud accounts.
  • Uploading codes to unauthorized devices.
  • Database transfer.
  • Copy databases.
  • Share confidential data.
  • Sharing internal prompts.
  • Share systems settings.
  • Share API keys.
  • Share passwords.
  • Share access codes.
  • Share user accounts.
  • Filming technical or confidential content without permission.
  • Extracting content from internal systems.
  • Use group assets in a personal project.
  • Use it for the benefit of another party.
  • Use it for the benefit of a competing company.
  • Resell it.
  • Relicense them.
  • Publish them.
  • Redistribute it.
  • Create a copy of it for another activity.
  • Transfer it to a third party.
  • Keep copies of it after the end of work, training or contracting.

7. Protecting websites and digital platforms

The websites, platforms and digital portals of the Group and its subsidiaries are considered part of the Group's digital assets, in relation to the elements, contents, systems and rights that the Group owns or is legally authorized to use.

This includes, depending on each site or platform:

  • Codes.
  • Content.
  • Original designs.
  • Electronic forms.
  • Internal systems.
  • Databases.
  • Intelligent tools.
  • Digital journeys for customers.
  • Ordering systems.
  • Interactive tools.
  • Reports.
  • Trademarks.
  • Logos.
  • Names.
  • Original visual elements.

8. Visitor access to websites

The mere entry of any visitor to one of the group’s websites or platforms does not grant him any ownership right in the assets or rights on the site.

Accessing or using the site does not constitute:

  • License to copy content.
  • A license to reproduce the systems.
  • A license to make commercial use of the content.
  • Waiver of intellectual property rights.
  • Permission to use trademarks.
  • Permission to extract confidential data.
  • Permission to rebuild technical systems.

Use of the site is limited to the legitimate and normal use for which the site was made available, and in accordance with the terms of use and the law.

9. Prohibiting copying from websites

It is prohibited, without prior written authorization, to do any of the following actions whenever it relates to a protected asset or content of the group:

  • Copy website content.
  • Copy the original texts.
  • Copy protected designs.
  • Copies of original photos and drawings.
  • Copying electronic forms.
  • Copy pages of the website for the purpose of commercial reuse.
  • Republish the content under the name of another party.
  • Copy codes.
  • Unauthorized extraction of databases.
  • Extract confidential information.
  • Copy intelligent tools.
  • Copy internal prompts.
  • Copying working systems or protected software.
  • Remove ownership notices.
  • Remove the name of the right holder.
  • Change or hide copyright notices.

10. Imitation, replication and unlawful use

The Group and its subsidiaries reserve all their legal rights towards any person or entity that, without legal authority or approved permission, imitates, uses or exploits the Group’s protected assets.

This includes, depending on the nature of the right:

  • Logos.
  • Trademarks.
  • Trade names.
  • Visual identity.
  • Original designs.
  • Creative content.
  • Codes and programs.
  • Protected databases.
  • Electronic forms.
  • Software systems.
  • Written materials.
  • Protected digital tools or products.

This also includes presenting a group asset or product as belonging to another person or company.

11. General ideas and unprotected elements

This policy is not intended to claim ownership of common ideas, methods, functions or practices over which exclusive rights are not granted by law.

Rather, protection extends to assets, rights, works, data, trademarks, trade secrets, and contractual rights that the group or its subsidiaries own or are legally authorized to use.

12. Unauthorized access

It is prohibited for anyone to attempt:

  • Accessing a system that you are not authorized to use.
  • Accessing unauthorized internal pages.
  • Exceeding the level of authority granted to him.
  • Bypassing protection systems.
  • Bypass authentication mechanisms.
  • Use someone else's account.
  • Use passwords that are not owned by him.
  • Obtaining access codes without authorization.
  • Accessing confidential data without authorization.
  • Internal data extraction.
  • Accessing source codes without permission.
  • Modifying data without authorization.
  • Deleting data without authorization.
  • Downloading data without permission.
  • Tampering with group systems.
  • Disable systems.
  • Intentionally affecting the efficiency or operation of systems.

13. Reverse engineering and technology extraction

It is prohibited, within the limits permitted by law and contracts, to attempt:

  • Unauthorized decryption or analysis of systems.
  • Extracting internal codes.
  • Extract system logic.
  • Access to components not available to the public.
  • Bypass security controls.
  • Extraction of unauthorized databases.
  • Rebuilding a protected system using illegally obtained materials or code.

14. Using external artificial intelligence tools

No confidential or technical information belonging to the Group may be entered into unauthorized external AI tools or accounts.

This includes:

  • Source code.
  • Confidential customer data.
  • Personal data that is not authorized to be shared.
  • Databases.
  • Secret prompts.
  • Internal knowledge bases.
  • API keys.
  • Passwords.
  • Access codes.
  • Confidential contracts.
  • Confidential legal information.
  • Unpublished financial data.
  • Strategic plans.
  • Business plans.
  • Internal documents.
  • Unpublished operating information.

Approved accounts, tools and platforms must be used in accordance with the group’s information security and data protection policies.

15. Data protection and knowledge bases

Databases, knowledge bases, commercial, technical and operational information not available to the public are important assets of the Group.

It is not permissible, without an approved permit:

  • Copy it.
  • Download it.
  • Transfer it.
  • Sell ​​it.
  • Share it.
  • Publish them.
  • Leaking it.
  • Use it for personal benefit.
  • Use it for the benefit of a third party.
  • Use them to create competing activity.
  • Use them to train an external system.
  • Use it outside of its authorized purpose.

This is taking into account the rights of data subjects and applicable data protection and privacy laws.

16. Confidentiality and trade secrets

All information that is not available to the public and related to the Group's business, and which is of a confidential, commercial or technical nature, is considered information that must be protected in accordance with approved contracts, laws and policies.

They may include:

  • Strategies.
  • Market studies.
  • Financial information.
  • Customer data.
  • Expansion plans.
  • Internal pricing rules.
  • Commercial relations.
  • Supplier data.
  • Customer sources.
  • Evaluation algorithms.
  • Operating plans.
  • Technical information.
  • Codes.
  • Internal work procedures.
  • Development documents.

17. Group accounts and devices

The accounts, devices, services and subscriptions provided by the group are considered corporate business tools.

It is not permissible:

  • Sharing accounts without permission.
  • Granting an outside party access.
  • Changing recovery data for personal purposes.
  • Using the corporate account after expiration.
  • Transfer institutional data to a personal account.
  • Keep passwords or access keys after the relationship ends.
  • Using group devices for purposes that compromise the security of the systems.

18. Preserving digital evidence

The Group reserves the right, in accordance with the law and applicable data protection and privacy policies, to use the necessary technical means to protect its systems and assets and document activities related to them.

These methods may include:

  • Login records.
  • User records.
  • Permission logs.
  • Download logs.
  • Modification logs.
  • Upload records.
  • API logs.
  • Systems logs.
  • Cybersecurity logs.
  • Unauthorized entry attempts.
  • Backups.
  • Technical data relating to devices and accounts where permitted by law.

These records may be used for internal investigations, protection of rights, or legal actions in accordance with the law.

19. Discovery of copying, imitation, or unauthorized use

If the Group discovers that a person or entity has copied, imitated, exploited or used one of its assets without authorization, it may take appropriate measures to protect its rights.

It is not required that the violation be committed by an employee or contractor.

Depending on the circumstances, the policy also applies to any:

  • Site visitor.
  • User of the platform.
  • Company.
  • Competitor.
  • Service provider.
  • Current or former employee.
  • Contractor.
  • Developer.
  • Or any third party.

20. Group procedures in the event of a violation

In the event of discovery of a violation or serious suspicion of a violation, the Group and its subsidiaries reserve the right to take the necessary legal, technical and administrative measures, according to each case.

They may include:

  • Disable access.
  • Cancel account.
  • Disable account or access keys.
  • Protect systems and data.
  • Preserving digital evidence.
  • Open an internal investigation.
  • Documenting the incident.
  • Issuing an administrative warning.
  • Issuing a legal warning.
  • Requesting the person or entity to stop use.
  • Request removal of violating content.
  • Request to delete unauthorized copies.
  • Request the return of assets or data.
  • Contact the hosting provider.
  • Contact the platform hosting the infringing content.
  • Submit removal or blocking requests whenever legally possible.
  • Submit a complaint to the competent authorities.
  • Take legally available civil, commercial or criminal actions.
  • Filing lawsuits before the courts or competent authorities.
  • Claim compensation whenever legal reasons exist.
  • Take any other measure permitted by law.

21. The Group’s right to bring legal proceedings

The Group and its subsidiaries reserve the right to file lawsuits or take appropriate legal measures against any natural or legal person proven to have committed an unlawful attack on one of its protected rights or assets.

Depending on the incident, this includes:

  • Illegal copying.
  • Unauthorized use.
  • Copyright infringement.
  • Trademark infringement.
  • Unauthorized use of digital assets.
  • Unauthorized access to confidential information.
  • Unauthorized access to systems.
  • Data leak.
  • Illegal use of commercial or technical information.
  • Or any other act that constitutes a violation according to applicable laws.

22. The right to claim compensation

The Group and its subsidiaries reserve the right to claim compensation for damages and losses that are legally proven to have resulted from an infringement on their rights or assets.

The claim may include, depending on the nature of the damage and what the law allows:

  • Financial losses.
  • Commercial damages.
  • Systems recovery costs.
  • Technical investigation costs.
  • Costs of remediating a leak or breach.
  • Damage resulting from illegal use.
  • Damage related to the mark or commercial activity.
  • And any other damages or expenses recognized by law and proven before the competent authority.

This policy is not an automatic or pre-determined determination of compensation.

Any claim is assessed in accordance with contracts, evidence, laws and decisions issued by the competent judicial authorities.

23. Stopping the violation does not cancel the right to compensation

The fact that the person responsible for the violation:

  • deletes the copy;
  • removes the content;
  • stops the use;
  • closes the infringing website;
  • or returns the data;

does not, in itself, extinguish the Group’s rights to take legal action or claim compensation for earlier damage, where a legal basis exists.

24. No waiver of rights

The Group’s failure to take immediate action regarding a violation is not considered:

  • A waiver of its rights.
  • Acceptance of the violation.
  • A license to use the asset.
  • A waiver of intellectual property rights.
  • Waiver of the right to claim.
  • Or implied consent to continued use.

The Group reserves the right to take appropriate action at the time permitted by law.

25. End of the work, training or contracting relationship

When any person’s relationship with the group ends, he is obligated, in accordance with the contract and applicable policies, to:

  • Delivery of codes.
  • Delivery of project files.
  • Delivery of documents.
  • Delivery of devices.
  • Return of assets.
  • Handing over institutional accounts according to approved procedures.
  • Handing over access keys.
  • Return data.
  • Cooperation in transferring knowledge.
  • Stop using permissions.
  • Delete unauthorized copies on devices or personal accounts.
  • Do not keep group data outside authorized frameworks.

The group may request written or electronic acknowledgment of the completion of the delivery process.

26. Continuation of obligations after the end of the relationship

Obligations relating to:

  • Confidentiality.
  • Data protection.
  • Trade secrets.
  • Intellectual property protection.
  • Not retaining assets.
  • Do not use codes and systems in an unauthorized manner.
  • Return of assets.
  • Protect accounts and data.

Existing after the end of the employment, training or contracting relationship, to the extent permitted by applicable laws and contracts.

27. Priority of contracts and policies

This policy is read in conjunction with:

  • Employment contracts.
  • Training contracts.
  • Development contracts.
  • Programmer contracts.
  • Consultant contracts.
  • Supplier contracts.
  • NDA Confidentiality Agreements.
  • Intellectual property rights agreements.
  • Rights transfer agreements when needed.
  • Terms of use of the sites.
  • Privacy policy.
  • Data protection policy.
  • Information security policy.
  • Artificial intelligence use policy.
  • Access policies and permissions.
  • Relevant trade agreements.

In the event of a conflict, reference will be made to binding laws, agreements and contracts depending on the nature of each case.

28. No implied rights

Access to any of the following does not grant:

  • Website.
  • platform.
  • Control panel.
  • system.
  • account.
  • application.
  • database.
  • file.
  • program.

any ownership right or license beyond the limits of expressly authorized use.

29. The established corporate principle

Everything built, developed, designed, customized, trained or operated for the Group using its resources, data, systems, accounts or technical infrastructure, or pursuant to an approved assignment from it, constitutes an asset of the Group or the relevant subsidiary, in accordance with applicable contracts, agreements and laws.

Making any website, system, platform or content available to the public does not mean a waiver of the group’s rights therein, and does not grant any person the right to copy, imitate, exploit or commercially re-use protected assets without permission or legal basis.

The group and its subsidiaries reserve all their rights to protect their codes, systems, data, websites, brands, content and digital assets, and to take appropriate administrative, technical and legal measures, including filing lawsuits and demanding compensation whenever violations and damage are proven in accordance with the law.

30. Official UAE legal references

This policy is based, depending on the nature of each right or fact and the scope of application of the legislation, on the laws and legislation in force in the United Arab Emirates, including:

Federal Decree Law No. (38) of 2021 regarding copyright and related rights.

Federal Decree Law No. (36) of 2021 regarding trademarks.

It also includes:

Federal Decree Law No. (34) of 2021 regarding combating rumors and cybercrimes provides provisions related to cybercrimes and illegal access or dealing with some data and information, including provisions related to confidential data and information of financial, commercial and economic establishments, in accordance with the scope of application and the conditions and pillars specified in the law.

This policy is applied taking into account any applicable or subsequent amendments, legislation, decisions or executive regulations in the United Arab Emirates, and in a manner that does not conflict with applicable laws and regulations.

31. Final legal notice

This policy aims to regulate and protect the intellectual property, digital and technical assets of the Group and its subsidiaries, and none of its provisions shall be construed in a way that grants the Group rights beyond what are determined by applicable laws, contracts or licenses.

Liability, procedures, and compensation are determined in each case based on the nature of the incident, evidence, contracts, applicable legislation, and decisions of the competent authorities.

All rights are reserved to the group and its subsidiaries in accordance with the law