Privacy Policy
Our Privacy Policy
Learn how we handle your personal information and ensure your privacy and data security on our platform.
Last Updated on 22 August 2026
1. Who we are and what this Policy covers
Maly Tech Ltd ("Maly", "we", "us") is a technology company registered in the Dubai International Financial Centre (DIFC), United Arab Emirates. This Privacy Policy explains how we collect, use, share, and protect personal data when you use the Maly mobile app, our websites, and Maly products and services, including Maly UAE, Maly Boutique, MoMo+, and the Maly Payments API, whether we deliver them directly or in partnership with regulated financial institutions and mobile money operators.
Some Maly products operate in partnership with regulated financial institutions, such as Ruya Community Islamic Bank in the UAE, or with licensed mobile money operators in other countries. Where a partner institution holds the regulatory licence for the service, that institution processes your personal data in its own capacity under its own privacy policy and applicable banking or payment regulations. We encourage you to read the partner institution's privacy policy alongside this one.
2. Legal framework
We process personal data in accordance with:
the DIFC Data Protection Law, DIFC Law No. 5 of 2020, and its regulations, which apply to Maly Tech Ltd as a DIFC-registered entity;
UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the UAE PDPL) and its implementing regulations, which apply to our processing of personal data of individuals in the UAE outside the DIFC;
applicable regulations, standards, and directives of the Central Bank of the UAE (CBUAE), including consumer protection and record-keeping requirements that apply to services delivered with our partner bank; and
the data protection laws of each country where we deploy a product or service directly or through a regulated partner, including, where applicable, the Nigeria Data Protection Act 2023, Law No. 29-2019 on the protection of personal data of the Republic of Congo, and Law No. 2017-20 on the Digital Code of the Republic of Benin.
Where more than one law applies, we apply the standard that gives you the stronger protection.
3. Personal data we collect
We collect personal data directly from you, from your use of our services, and from third parties. This includes:
• Identity data: name, date of birth, nationality, gender, identity document details (including Emirates ID and passport data), and photographs;
• Biometric data: facial images and liveness data captured during identity verification (see Section 4);
• Contact data: mobile number, email address, and place of residence;
• Employment and financial data: employer, occupation, income information, and source of funds where required for onboarding;
• Account and transaction data: details of your Maly accounts, wallets, vouchers, payments, and transfers;
• Device and usage data: device identifiers, app usage, log data, and cookie information;
• Permissions data: photos, contacts, and push notification access, only where you grant permission to enable a specific app feature; and
• Third-party data: information from credit bureaus, identity verification services, sanctions and fraud databases, government authorities, and our partner financial institutions.
4. UAE Pass and biometric data
In the UAE, you can onboard to the Maly app using UAE Pass, the national digital identity. When you authenticate with UAE Pass, we receive verified identity attributes from the UAE Pass system, such as your name, Emirates ID number, date of birth, nationality, and contact details, with your authorisation given through UAE Pass. We use these attributes to verify your identity and open your account. UAE Pass is operated by UAE government authorities under their own terms and privacy notices.
Biometric data is sensitive personal data under the DIFC Data Protection Law and the UAE PDPL. We collect facial images and liveness checks solely to verify your identity, prevent fraud and impersonation, and meet the know-your-customer (KYC) and anti-money-laundering (AML) obligations that apply to us and to our partner regulated bank under CBUAE rules. We collect biometric data with your explicit consent and where the law requires or permits it. We do not use biometric data for any other purpose, and we do not sell it or share it for marketing.
5. Legal bases for processing
We rely on the following legal bases, as applicable in your jurisdiction:
• Contract: to open and operate your account and deliver the services you request;
• Legal and regulatory obligation: to meet KYC, AML, counter-terrorist financing, sanctions, tax, and record-keeping obligations under CBUAE rules, DIFC law, UAE federal law, and the laws of countries where our services operate;
• Consent: for biometric verification, marketing communications, optional device permissions, and cookies that are not strictly necessary;
• Legitimate interests: to secure our systems, prevent fraud, improve our products, and manage our business, balanced against your rights; and
• Public interest and vital interests: in the limited cases the law allows.
Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect processing already carried out, and we may still process your data where another legal basis applies.
6. How we use your personal data
We use your personal data to:
• verify your identity and open, manage, and close your account;
• enable and route transactions with financial institutions, correspondents, payment intermediaries, card schemes, mobile money operators, and other commercial partners ("Partners");
• provide customer support and resolve problems;
• notify you of service updates, faults, and changes to terms;
• monitor, secure, and improve our applications, products, and websites;
• detect, investigate, and report suspicious transactions and prevent fraud, money laundering, terrorist financing, and tax evasion;
• meet our regulatory obligations and those of our Partners, including onboarding checks, ongoing monitoring, and reporting to competent authorities;
• invoice you and manage the status of orders; and
• with your consent, send you marketing about Maly and approved partner products, offers, contests, and surveys. You can opt out at any time in the app or by email.
We use analytics providers, such as Google Analytics, to measure usage and improve our services. Analytics data is minimised and used only for this purpose.
We do not make decisions that produce legal or similarly significant effects on you based solely on automated processing without human review, except where the law permits and we tell you first. Automated screening supports our fraud and compliance checks; adverse outcomes are reviewed by our team.
7. Sharing and disclosure
We do not sell, rent, or trade your personal data. We share it only with:
• our partner regulated financial institutions, including Ruya Community Islamic Bank in the UAE, to deliver the services and meet their regulatory obligations;
• Partners that process transactions, including banks, payment intermediaries, card schemes, and mobile money operators;
• identity verification, credit reference, fraud prevention, and sanctions screening providers;
• service providers that host, support, and secure our systems under contracts that restrict their use of your data;
• professional advisers, auditors, and insurers under duties of confidentiality;
• regulators, law enforcement, courts, and government authorities where the law requires or permits disclosure; and
• a buyer or successor if we sell or restructure our business, subject to this Policy.
8. International transfers
We operate across the DIFC, the UAE, Africa, and other markets, so your personal data may be transferred to and processed in countries other than your own. Where we transfer personal data outside the DIFC or the UAE, we do so only where the destination provides an adequate level of protection or where we apply appropriate safeguards, such as approved contractual clauses, and we meet the transfer conditions of the DIFC Data Protection Law, the UAE PDPL, and the local law of the country where you use our services.
9. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls, network segregation, logging and monitoring, staff confidentiality obligations, and vendor due diligence. No system is completely secure. If a personal data breach creates a risk to your rights, we will notify the competent authority and, where required, you, within the timelines the applicable law sets.
10. Retention
We keep personal data only as long as necessary for the purposes described in this Policy and to meet legal and regulatory obligations. Records connected to regulated financial services, including identity verification and transaction records, are retained for the minimum periods that CBUAE rules, DIFC law, and local laws require, generally at least five years after the end of the relationship or transaction. We then delete or irreversibly anonymise the data unless the law requires longer retention or we need it to establish, exercise, or defend legal claims.
11. Your rights
Subject to the law that applies to you, you have the right to:
• access your personal data and receive a copy;
• correct inaccurate or incomplete data;
• request erasure of data we no longer need;
• restrict or object to processing, including processing for direct marketing;
• receive your data in a portable format;
• withdraw consent at any time;
• object to decisions based solely on automated processing; and
• complain to a data protection authority (see Section 15).
You can view and update your profile in the Maly app. For other requests, contact us using the details in Section 15. We respond within the timelines the applicable law sets and verify your identity first. We do not charge for requests unless the law permits a fee. Some rights are limited where we must retain data to meet AML, KYC, and record-keeping obligations.
12. Cookies
Our websites and app use cookies and similar technologies. Strictly necessary cookies run without consent because the service does not function without them. We use all other cookies, including analytics and marketing cookies, only with your consent, which you can give, refuse, or withdraw through our cookie settings. If you refuse non-essential cookies, some features may not be available.
13. Children
Our services are not directed at individuals under 18. We do not knowingly collect personal data from minors except where a partner regulated institution permits accounts for minors under guardian consent and applicable law. If you believe a minor has provided us data without authorisation, contact us and we will delete it.
14. Third-party sites and apps
Our app and websites may link to third-party sites and applications that operate under their own privacy policies. We do not control them and accept no responsibility for their processing. Review their policies before you share personal data with them.
15. Contact, complaints, and supervisory authorities
To exercise your rights, ask questions, or complain, contact our Data Protection Officer through our first level support team at contact@maly.ai or write to Maly Tech Ltd, 702 Innovation One DIFC, Dubai, UAE.
If you are not satisfied with our response, you may complain to the DIFC Commissioner of Data Protection, to the UAE Data Office for processing subject to the UAE PDPL, or to the data protection authority of the country where you use our services.
16. Changes to this Policy
We update this Policy when our products, the law, or our practices change. The version published in the app and on our website is the current version. We will notify you of material changes through the app or by email before they take effect, and where the law requires, we will seek fresh consent.