Privacy Notice

Last updated: 15/04/2026

FC Holdings Limited (Fajr Capital) and its affiliated entities respect your privacy and are committed to protecting personal data in accordance with the DIFC Data Protection Law No. 5 of 2020 (as amended) (the DIFC DP Law) and, where applicable, international data protection standards.

This Privacy Notice explains how we collect, use, store, share and protect personal data when you visit our website, contact us, subscribe to updates, submit an enquiry, apply for a role, or otherwise interact with us.

For the purposes of applicable data protection laws, the data controller is: FC Holdings Limited of Level 3, Gate Village 5, Dubai International Financial Centre (DIFC), P.O. Box 506738, Dubai, United Arab Emirates.

If you have any questions about this Privacy Notice or wish to exercise your privacy rights, please contact our Privacy Team at privacy@fajrcapital.com, call +971 4 373 5900, or write to Level 3, Gate Village 5, Dubai International Financial Centre (DIFC), P.O. Box 506738, Dubai, United Arab Emirates.

 

1. Personal data we may collect

We may collect and process the following categories of personal data:

Information you provide directly

Your name, email address, telephone number, company or organisation name, job title, enquiry details, messages, subscription preferences, and any other information you choose to provide to us.

Recruitment-related information

If you apply for a role with us, we may collect your CV or résumé, employment history, education, qualifications, references, interview records, and other information relevant to your application.

Technical and usage information

We may also collect technical and usage data such as your IP address, browser type, device information, pages visited, time spent on the website and similar analytical data.

Information from other sources

We may receive personal data from publicly available sources, professional networking platforms, recruitment partners, service providers, advisers, your employer or representative, and regulatory or compliance sources where appropriate.

We do not intentionally collect Special Categories of Personal Data unless strictly necessary and lawful.

2. How we collect personal data

We may collect personal data directly from you when you contact us, submit a form, subscribe to updates, or apply for a role.

We may also collect certain data automatically when you use our website through cookies, server logs, analytics tools, and similar technologies.

In some cases, where lawful to do so, we may receive personal data from third parties, such as recruitment agencies, professional advisers, service providers, public sources, or a person acting on your behalf.

3. Why we use personal data

Where required by applicable law, we process personal data on one or more of the following legal bases:

  • your consent;
  • contractual necessity or
  • pre-contract steps;
  • legal or regulatory obligation, including DFSA requirements;
  • legitimate interests, including:
    • operating and improving our website;
    • managing communications and relationships;
    • ensuring IT and information security;
    • administering recruitment; and
    • protecting our legal and business interests.

Where Special Category Data is processed, we rely on conditions set out in the DIFC DP Law.

Where we rely on consent, you may withdraw that consent at any time. Withdrawal will not affect processing already carried out before that point.

4. Why we use personal data

We may use personal data for:

  • website operation, security and analytics;
  • handling enquiries and communications;
  • investor, stakeholder and business relationship management;
  • recruitment and talent management;
  • compliance with DFSA rules, anti-money laundering obligations and other regulatory requirements; and
  • legal proceedings, claims and investigations.

We do not process personal data for purposes incompatible with those described above.

5. Sharing personal data

We may share personal data, where appropriate, with our affiliates and related entities, website hosting and IT service providers, security providers, analytics and mailing service providers, recruitment platforms and agencies, professional advisers, auditors, regulators, law enforcement bodies, courts, and other governmental authorities where required or permitted by law.

We may also share personal data with counterparties, advisers or service providers involved in our corporate, investment, governance, administrative or operational activities where that is relevant and lawful.

We do not sell personal data.

6. International transfers

Fajr Capital operates across multiple jurisdictions. Personal data may therefore be stored in or accessed from countries outside the DIFC and outside the UAE.

Where personal data is transferred outside the DIFC, we comply with Part 4 (Transfers of Personal Data) of the DIFC DP Law, including:

  • transfers to jurisdictions with an adequate level of protection (Article 27)
  • appropriate safeguards such as Standard Contractual Clauses (Article 28)
  • transfers necessary for legal or regulatory purposes (Article 30)

We apply a risk-based approach aligned with DFSA expectations for outsourcing and data handling.

7. Cookies and similar technologies

Our website may use cookies and similar technologies to support essential functionality, security, performance and analytics.

Where required, we will provide appropriate notice and, where necessary, consent in relation to non-essential cookies or similar technologies. You can also manage cookies through your browser settings, although doing so may affect certain website functions.

If our website includes embedded third party content, such as videos, maps, or social media features, those third parties may collect data about your interaction with that content in accordance with their own privacy practices.

8. Data retention

We keep personal data only for as long as necessary for the purposes described in this Privacy Notice, including to satisfy legal, regulatory, compliance, record-keeping (including DFSA obligations), dispute resolution, security requirements and legitimate business purposes.

Retention periods may vary depending on the nature of the data, the reason it was collected, whether it remains necessary for that purpose, and whether we are required to retain it under applicable law or regulation.

Where personal data is no longer required, we will delete it, anonymise it, or securely archive it in accordance with applicable requirements.

9. Your rights

Subject to applicable law, you may have the right to request access to personal data we hold about you, request rectification of inaccurate or incomplete personal data, request deletion of personal data in certain circumstances, request restriction of processing, object to certain processing, withdraw consent where processing is based on consent, and request transfer or portability of personal data where applicable. You may also have the right to object to direct marketing and, where applicable law provides, to request review of significant decisions made solely by automated means.

These rights are subject to statutory limitations, including where processing is required for regulatory compliance.

Requests can be made using the contact details set out in this Privacy Notice. We may ask for information necessary to verify your identity before acting on your request. DIFC law provides rights and remedies for individuals, and the DIFC Commissioner of Data Protection is the supervisory and enforcement authority for the DIFC regime.

10. Direct marketing

Where we send updates, newsletters or other communications, we will do so in accordance with applicable law and DFSA conduct requirements. You may opt out of marketing communications at any time by using the unsubscribe link in the relevant message or by contacting us directly.

11. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, misuse, alteration or disclosure. Our controls include information security governance, access controls, incident management and third party risks.

However, no website, system or transmission is entirely secure, and we cannot guarantee absolute security.

12. Data breaches

We maintain procedures to identify, assess and respond to personal data breaches in accordance with the DIFC DP Law. A “personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

In the event of a personal data breach, we will:

  • promptly investigate and assess the nature of the breach, including the categories and volume of personal data affected, the likely consequences and the risk to individuals;
  • take appropriate remedial and containment measures to mitigate any adverse effects and prevent recurrence; and
  • maintain internal records of the breach, as required under the DIFC DP Law.

Where required, we will notify the DIFC Commissioner of Data Protection. Where the breach is likely to result in a high risk to the rights of individuals, we will notify affected individuals. We may delay or limit notification to the extent permitted by law, including where notification would prejudice regulatory, law enforcement or legal proceedings.

Our incident response processes are aligned with our broader information security framework and, where applicable, DFSA regulatory expectations regarding incident reporting, operational resilience and outsourcing.

13. Third party websites

Our website may contain links to third party websites or services. We are not responsible for the privacy practices, content or security of those third parties. We encourage you to review their privacy policies before providing personal data to them.

14. Changes to this Privacy Notice

We may update this Privacy Notice from time to time to reflect changes in our practices, website functionality, legal or regulatory requirements or business operations. Any updates will be posted on this page effective on the date of publication.

15. Contact and complaints

If you have questions, concerns or requests relating to this Privacy Notice or our handling of personal data, please contact:

Privacy Team
Email: privacy@fajrcapital.com
Telephone: +971 4 373 5900
Postal address: Level 3, Gate Village 5, Dubai International Financial Centre (DIFC), P.O. Box 506738, Dubai, United Arab Emirates

You may also have the right to complain to the relevant supervisory authority, including the DIFC Commissioner of Data Protection, where applicable.