Privacy Policy

Version 1.0 · Effective from the date of publication.

Note:This is CastleEx's initial published version, prepared in good faith to reflect how the Platform handles data. It has not yet been reviewed by an external data-protection specialist; CastleEx intends to have it reviewed against the applicable laws (UAE PDPL and the data-protection laws of the African markets served — Nigeria (NDPA), Kenya (DPA), Ghana (DPA)) and, where appropriate, revised. It is not a substitute for professional legal advice.

1. Who We Are

CastleEx Limited ("CastleEx", "we") operates the CastleEx platform (the "Platform") and is the controller of the personal data described here. For AML/CFT purposes CastleEx acts as a Designated Non-Financial Business or Profession (DNFBP). Contact: privacy@castleex.com.

2. The Data We Collect

  • Account data: name, email, phone/WhatsApp, country, role, password (stored hashed by our authentication provider).
  • Identity & verification data (sensitive): for professionals and where required — passport copy, national identity document (e.g. NIN, Ghana Card, Huduma), and bank/financial verification details used to confirm identity. Where such verification is enabled, this may also include facial-image and liveness-check data used solely to confirm that the person presenting an identity document is its genuine holder.
  • Professional data: licence numbers, agency/company details, specialisation, listings, and related records.
  • Transaction & enquiry data: buyer requirements and enquiries, leads, offers, viewings, messages, and deal records.
  • Financial data: payment and payout information, processed largely through third-party payment providers; we generally do not store full card numbers.
  • Usage & device data: log data, IP address, device/browser information, pages viewed, and actions taken, including security events and audit logs.
  • Communications: messages sent through the Platform and correspondence with us.
  • Cookies/similar technologies: see §11.

3. Why We Use Your Data (and Our Legal Bases)

We use personal data to:

  • provide the Platform and your account, and match buyers with professionals and listings — performance of a contract;
  • verify identity and comply with AML/CFT and other legal obligations, including screening, monitoring, record-keeping, and reporting — legal obligation;
  • process payments, commissions, and payouts — contract / legal obligation;
  • secure the Platform — authentication, 2FA/MFA, fraud and abuse prevention, audit logging, and enforcing our Terms — legitimate interests / legal obligation;
  • communicate service messages, and (with consent where required) marketing — contract / consent / legitimate interests;
  • improve and analyse the Platform — legitimate interests.

Where we rely on consent (e.g. certain marketing or optional cookies), you may withdraw it at any time.

4. How Your Information Is Shared

  • With real-estate professionals through the Platform: a buyer's contact details are masked by default and are revealed to a professional only under the Platform's rules (including the capability-gated process). Professionals receive buyer requirements needed to serve the enquiry.
  • With Operating Companies / brokers involved in your transaction, and with lawyers engaged in a specific deal.
  • With service providers who process data on our behalf (hosting, database, identity/verification, communications, mapping, analytics) under appropriate confidentiality and data-processing terms.
  • With payment providers to process payments and payouts.
  • With authorities, regulators, and law enforcement where required by law or to comply with AML/CFT obligations, prevent fraud, or protect rights and safety.
  • In a corporate transaction (e.g. merger, financing, or transfer to a successor or Operating Company), subject to this Policy.

We do not sell your personal data.

5. Identity Documents — Special Handling

Identity documents and verification data are treated as sensitive. Access is restricted to authorised personnel and systems on a need-to-know basis, protected by database row-level security and access controls, and served via short-lived signed links rather than public URLs. They are used only for identity verification, compliance, fraud prevention, and legal purposes, and are retained as described in §6.

6. How Long We Keep Data

  • AML/compliance records (including identity and transaction records) are retained for the period required by law — at least five (5) years after the end of the business relationship or transaction, or longer where required.
  • Account and Platform data are retained while your account is active and for a reasonable period afterwards, subject to the retention above and to resolving disputes and enforcing agreements.
  • When retention is no longer required, data is deleted or anonymised. Note that CastleEx may, for security reasons, reset the Platform and delete accounts; legally required records are retained even then.

7. Cross-Border Transfers

CastleEx operates across the UAE and Africa and serves an international/diaspora audience, so your data may be processed in, or accessed from, countries other than your own (including the UAE). Where we transfer personal data internationally, we rely on appropriate safeguards permitted under applicable law — for example, transferring to a country recognised as providing an adequate level of protection, putting in place contractual data-protection commitments with the recipient, or relying on your explicit consent — so as to provide a level of protection consistent with this Policy.

8. Security

We use technical and organisational measures to protect your data, including encryption in transit, hashed credentials, row-level security, access controls, two-factor authentication (2FA/MFA) for privileged and professional accounts, audit logging, and rate limiting. No system is perfectly secure, but we work to protect your information and to respond to incidents appropriately.

9. Your Rights

Subject to applicable law and to our legal retention obligations, you may request to: access your data; correct inaccurate data; delete data (except records we must retain, e.g. for AML); object to or restrict certain processing; withdraw consent; and receive certain data in a portable form. To exercise these rights, contact privacy@castleex.com. You may also have the right to complain to your local data-protection authority.

10. Automated Processing

The Platform uses automated logic to score and match leads and to assist professionals (for example, quality scoring and matching, and AI-assisted tools). These support human decision-making and the Platform's matching; we do not use solely-automated processing to make decisions that produce legal or similarly significant effects about you without human involvement. Where you disagree with an outcome that affected you, you may contact us to have it reviewed by a person.

11. Cookies & Similar Technologies

We use cookies and similar technologies for authentication and security (including bot-protection such as Cloudflare Turnstile), to remember preferences, and to measure and improve the Platform (analytics, and marketing measurement where applicable). You can control non-essential cookies through your browser or any cookie controls we provide; essential cookies are required for the Platform to function.

12. Children

The Platform is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided data, contact us and we will delete it.

13. Changes to This Policy

We may update this Policy. We will update the version and effective date and, for material changes, provide notice. Continued use after an update constitutes acceptance where permitted by law.

14. Contact

Questions or requests: privacy@castleex.com — CastleEx Limited, RAK Innovation City, Ras Al Khaimah, UAE.