Skip to content
Skip to main content
maivis

Privacy Policy

Version 2.12 | Last Updated: July 2026

Cross-ref: Terms of Service v2.11, Cookie Policy v2.6, DPA v2.6

1. Who We Are

maivis is operated by Mango Technologies Ltd., a company registered at the Dubai International Financial Centre (DIFC) Innovation Hub, Gate Avenue, Dubai, UAE (Company Number: CL5222). Mango Technologies Ltd. is the Data Controller responsible for your personal data under the DIFC Data Protection Law 2020.

maivis is a private financial intelligence platform for cross-border families, providing account and document aggregation, Structural Integrity scoring, and intelligence, accessible at maiviswealth.com. maivis is not a financial advisory service, investment manager, bank, or regulated financial institution.

Two things worth stating plainly, because they shape what data we hold at all. First, maivis is free: signup is open, and we do not collect a card or any other payment method, so we hold no payment-instrument data of yours. Second, maivis is read-only over your financial data and never moves money: maivis does not and cannot initiate, authorize, schedule, or execute a payment, transfer, deposit, withdrawal, or trade. Where you connect a bank account, the connection retrieves account identifiers, balances, and transaction history and nothing else. We therefore process financial information about transactions you have already made; we never process a transaction ourselves.

Data Controller:
Mango Technologies Ltd., DIFC Innovation Hub, Gate Avenue, Dubai, UAE
Privacy Enquiries:
privacy@maiviswealth.com
Data Protection Officer:
dpo@maiviswealth.com. Our Data Protection Officer can be contacted directly by data subjects and supervisory authorities.
EU Representative (GDPR Art. 27):
For EU/EEA residents, contact: legal@maiviswealth.com, response within 72 hours. maivis is established in the DIFC and does not currently have an establishment in the EU. We have not appointed a representative under Article 27, relying on the exemption in Article 27(2)(a): our processing of EU residents' data is occasional, is not large-scale, and does not involve special-category data. We will appoint a representative established in an EU member state, and name them here, if that ceases to be the case, including if we begin marketing to EU residents at scale.
UK Representative (UK GDPR Art. 27):
For UK residents, contact: legal@maiviswealth.com, response within 72 hours. The same position and the same commitment apply under UK GDPR Article 27.
Legal General:
legal@maiviswealth.com

2. Scope and Applicable Law

This Privacy Policy applies to all members globally. It complies simultaneously with: DIFC Data Protection Law 2020 (as amended by DIFC Laws Amendment Law No. 1 of 2025) as primary; the Digital Personal Data Protection Act 2023 (India, DPDP Act) and, until May 2027, the SPDI Rules under IT Act Section 43A; UK GDPR and Data Protection Act 2018; EU GDPR (Regulation 2016/679); CCPA/CPRA (California); and PIPEDA (Canada). Where these regimes impose different requirements, we apply the stricter standard.

India (DPDP Act 2023): For users who are Indian citizens or whose data is processed in India, we comply with the Digital Personal Data Protection Act 2023. As a Data Fiduciary, we collect and process personal data only for specified lawful purposes with your consent. You have the right to access, correct, and erase your personal data, and to nominate a representative for data-related matters.

3. Data We Collect

3.1 Data Collected Directly From You

Identity Data: name, date of birth, phone number, email address, nationality, country of residence. We collect your date of birth to provide age-appropriate allocation education (for example, illustrating how a suitable mix commonly shifts with time horizon). It is not used for advertising or profiling. Financial Asset Data: property values, gold holdings, investment portfolios, cash balances (manually entered). Documents: passport, visa, property deeds, insurance certificates (encrypted on your device before upload via AES-256-GCM; maivis stores only ciphertext). Family Member Data: names, relationships, phone numbers of family members you add (see Section 12). Entity Ownership Data: names and types of legal entities (trusts, holding companies, SPVs, foundations, partnerships) and asset ownership percentages linked to them.

3.2 Data Collected Indirectly From Third Parties (GDPR Article 14)

We obtain read-only financial data from your bank accounts through: Lean Technologies (UAE banks) and Plaid (US, UK, Canadian banks). This data is obtained after you provide explicit consent during the banking connection flow. Categories: account identifiers, balances, and transaction history. Financial transaction data may inadvertently reveal special category data (political donations, religious tithing, medical payments); we process this on the basis of your explicit consent.

3.3 Free Access and Demo Showcase

maivis is currently offered free of charge, with full access for your whole family and no card required to register. Pricing may be introduced in the future; if it is, registered families will be notified in advance. The processing described in this Policy applies to all registered accounts regardless of whether a fee is charged. The public demo at maiviswealth.com/demo is an anonymized product showcase built on fictional family data. It requires no registration and collects no personal data beyond the analytics described in Section 3.4.

3.4 Usage and Analytics Data

maivis uses two analytics systems: PostHog Cloud EU for in-product analytics including feature interactions, screen views, funnel completion, heatmaps, and session replay on a small number of pre-login pages; and Firebase Analytics (GA4) for the maiviswealth.com landing page, tracking page views, scroll depth, and CTA clicks. Both are optional and neither runs until you accept analytics cookies. PostHog is a third-party processor: your events are transmitted to and stored by PostHog on its EU infrastructure under a Data Processing Agreement, and PostHog sets a first-party analytics cookie in your browser. Session replay masks all form inputs, so values you type are not captured. GA4 data is processed by Google within the EEA with IP anonymisation enabled. Neither system receives your name, email, account numbers, or financial values.

4. Legal Basis for Processing

Contractual Necessity (DIFC Art. 10(1)(b), GDPR Art. 6(1)(b)): Account creation, financial data aggregation, net worth calculation, core service functionality.

Explicit Consent (DIFC Art. 10(1)(a), GDPR Art. 6(1)(a), DPDPA Section 6): Sensitive financial data, document vault, banking connections, family member data, analytics cookies. Consent is specific-purpose, and withdrawable.

Legitimate Interest (DIFC Art. 10(1)(f), GDPR Art. 6(1)(f)): Pseudonymized product analytics (engagement signals keyed by a hashed family ID), fraud prevention, security monitoring. Not applicable to India members (DPDPA does not recognize legitimate interest).

5. How We Use Artificial Intelligence

maivis performs automated analysis of your financial data to provide educational insights. We use AI services (Google Gemini Enterprise Agent Platform with Gemini Flash, Anthropic Claude via Google Cloud Model Garden, and Google Search Grounding for real-time market context) to generate intelligence, briefings, portfolio analysis, financial summaries, allocation guidance, expert-model comparison, fee analytics, document intelligence, debt and recovery analysis, portfolio signals, scenario modelling, tax-loss harvesting alerts, currency hedging analysis, lifestyle benchmarks, and private market valuations. These outputs are general educational information, not personal financial advice or a recommendation to transact in any specific product. We employ a Privacy Gateway that strips all personally identifiable information before any data reaches AI providers. AI services receive your financial values (asset holdings, property values, spending amounts, jurisdictions) because meaningful analysis requires them. AI services never receive your name, email, phone number, account numbers, passport numbers, government IDs, or any other personal identifier.

In practice: AI sees “$2.3M in real estate across UAE and India” but never “[Name], Emirates NBD account 4521.” Every AI call is logged to an audit trail recording provider, data scope, token count, and PII redaction count.

The Gemini Enterprise Agent Platform operates under contractual Zero Data Retention (ZDR). Under our agreement with Google, your data is processed but not stored or used for training by Google's AI systems. This is a contractual commitment, not a technical impossibility; data transits Google infrastructure for processing. Anthropic Claude is accessed via Google Cloud Model Garden under the same ZDR terms. No Anthropic API key is used. No data is sent directly to Anthropic. Google Search Grounding receives only generic market queries (e.g. “wealth management considerations for families with assets in UAE and India”) with no family-specific financial data. The AI Data Gateway ensures compliance with the data minimisation principle under DIFC Article 11, GDPR Article 5(1)(c), and DPDPA Section 6.

6. Data Residency and Cross-Border Transfers

6.1 Storage Locations

Personal data is stored on a single regional database in Google Cloud region me-central1 (Doha, Qatar), with backups and Cloud KMS keys in the same region. This applies to all members regardless of residence. We do not currently operate regional databases in India or the United States. AI processing is a separate activity (see Section 6.3) and is not storage.

6.2 Cross-Border Transfer Mechanisms

All stored personal data resides in me-central1 (Doha, Qatar) under DIFC law; the mechanisms below govern transfers from a member's jurisdiction to that region (and onward to the global ZDR AI compute described in Section 6.3).

  • EU → DIFC: EU SCCs (June 2021, Module 2 C-to-P) + Transfer Impact Assessment.
  • UK → DIFC: UK IDTA or UK Addendum to EU SCCs + Transfer Risk Assessment.
  • US/Canada → DIFC: DIFC Standard Contractual Clauses.
  • India → DIFC: DIFC SCCs. The DPDP Act 2023 permits cross-border transfers by default (no negative list). We do not store Indian members' data in India; it is held in Doha under DIFC law. We do not process payment-system data subject to RBI localisation (card processing is handled by Stripe under its own controllership).
  • UAE onshore → DIFC: Onshore UAE is a "Third Country" under DIFC law. Transfers require DIFC SCCs or Article 27 derogations.

Where these clauses live. maivis is the controller of your data, not a processor of someone else's. The transfer clauses above operate between maivis and each processor we use, under that processor's own data-processing terms, principally the Google Cloud Data Processing Addendum. The information those clauses annex, meaning who processes your data, what they receive, where they hold it, and on which transfer mechanism, is published in Section 8 of this policy and in Section 3 of our Data Processing Agreement rather than in a separate annex. If you need the underlying documents for a diligence or compliance review, contact legal@maiviswealth.com.

6.3 Data Residency & Jurisdiction

Your stored personal data (account records, financial values, encrypted documents, database records, and backups) is held on Google Cloud regional infrastructure in me-central1 (Doha, Qatar) for all members; we do not maintain a separate India or US storage region.

AI processing is a distinct activity from storage. Our AI workloads run on the Google Gemini Enterprise Agent Platform. For technical processing, generated requests may transit Google compute regions in the US and EU. This processing operates under contractual Zero Data Retention: your data is processed but is not stored or used to train Google's models in any region. Only de-identified financial values reach the AI platform. Your name, email, phone number, account numbers, and government identifiers are stripped by our Privacy Gateway before any AI call, as described in Section 5.

Storage and processing of your data are governed primarily by the DIFC Data Protection Law 2020. For Indian members, processing in India is additionally governed by the Digital Personal Data Protection Act 2023. Where these regimes impose different requirements, we apply the stricter standard, as stated in Section 2.

7. Encrypted Document Vault

Each family's documents are protected by an encryption key unique to that family: a dedicated Cloud KMS key (a Customer-Managed Encryption Key), provisioned automatically for your family and never shared with any other family's data. Key material is generated inside Google Cloud KMS, is held within that service, and cannot be exported from it. Keys provisioned for new families use the Cloud KMS software protection level. Some keys provisioned earlier use a higher protection level. maivis makes no representation as to the protection level of any particular key. Documents are encrypted using AES-256-GCM, or an algorithm of equivalent or greater strength, before storage. The document encryption key (DEK) is wrapped under your family's dedicated key and stored alongside the ciphertext. The plaintext DEK is never persisted to disk or database; it exists only transiently in server memory during a wrap or unwrap operation.

We decrypt a document only for a purpose tied to your own use of maivis: for example, when you or a family member views or downloads it, or when it is processed to power document search, asset matching, and AI-driven intelligence. Personal identifiers (name, email, phone number, account and government ID numbers) are stripped from document content before anything reaches an AI model, and AI providers receive only de-identified financial values (see Section 5, “How We Use Artificial Intelligence”). Every decrypt and access event is logged in an append-only access log, and a Merkle root can be generated over your vault on request to evidence that no stored document has been altered since.

This design is built to withstand a breach of storage or backup infrastructure. If a storage bucket, database, or backup were ever exposed or stolen, what would be taken is ciphertext and a wrapped key, not readable documents; decrypting them still requires a separate, authenticated KMS unwrap operation tied to your family's own key, which a stolen backup cannot itself perform. This protection is specific to storage and backup systems. It does not extend to a compromise of the running maivis application itself, which holds the capability to decrypt documents on your behalf by design (the same capability that lets you view your own vault); that scenario is addressed by our application security, access controls, and monitoring described elsewhere in this Policy, not by encryption of data at rest. You can disable your family's key at any time by sealing your vault in Settings, which blocks all decryption, including by maivis, until you unseal it again.

8. Third-Party Data Processors

We share data with the following processors, each under documented instructions and a Data Processing Agreement. See DPA v2.6 for detailed per-provider status.

ProcessorPurposeData CategoriesJurisdictionDPA Status
Google Cloud PlatformCompute, storage, KMS, DBAll member data (encrypted)UAE (me-central1, Doha) for storage; global (US/EU) for ZDR AI computeGCP DPA (CDPA)
Firebase AuthAuthenticationUID, phone, emailUS (Google LLC)Via GCP DPA
Firebase Analytics (GA4)Web landing page analyticsAnonymized page views, CTA clicksEEA (Google)Via GCP DPA
StripePayment processing for the maivis subscription only. Currently dormant (maivis is free; no charges are made and no payment method is collected). Retained for historical account records and for a possible future paid plan. Never used to move money in your own accounts.Billing name, email, subscription metadata. Raw card numbers never reach maivis.USStripe DPA
Lean TechnologiesUAE banking aggregationBank accounts, transactionsUAE (G42)Custom DPA
PlaidUS/UK/CA bankingBank accounts, transactionsUS/UK/CAPlaid DPA
Anthropic (via Google Cloud Gemini Enterprise Agent Platform Model Garden)AI language model processing (complex analysis)Pseudonymized financial data only (financial values + jurisdictions; direct identifiers stripped by the Privacy Gateway; no PII)Global (contractual ZDR via Gemini Enterprise Agent Platform; no data stored by Google or Anthropic)Covered by Google Cloud DPA (ZDR). No direct Anthropic API.
Google Search GroundingReal-time market contextGeneric market queries only (no personal data)GCP / EEAVia GCP DPA (ZDR)
PostHogProduct analytics: events, funnels, heatmaps, session replay (inputs masked)Pseudonymized usage events keyed by a hashed identifier. No names, emails, account numbers, or financial values.EU (PostHog Cloud EU)PostHog DPA. Consent-gated (DIFC DPL 2020 Art. 11).
Mango Intelligence (mango-intelligence-492117)Behavioral analytics pipeline. Aggregated engagement signals for product intelligence.Pseudonymized family IDs (hashed, but a re-linking key exists, so this is pseudonymized rather than anonymous), event types (session_started, asset_added, frs_band_change, upgrade_completed, chat_message_sent), is_demo flag, is_free_tier flag, event timestamps. No names, emails, financial values, or direct identifiers.GCP BigQuery (US multi-region)Internal sub-processor (same corporate group, Mango Technologies Ltd.)

We do not sell your personal data. For members in the US: we do not "sell" or "share" (as defined under CCPA/CPRA) your personal information. For members who connect via Plaid: Plaid's privacy policy is available at plaid.com/legal.

8A. Aggregate Marketing and Advertising Audience Insights

To decide how we run marketing and advertising campaigns (for example, which broad demographic or interest categories to target on an advertising platform), we may analyze aggregate, anonymized patterns across our user base as a whole, such as general demographic ranges, cross-border footprint, or broad asset-holding characteristics. This analysis produces derived, non-identifying audience characteristics only; it never produces, and is never based on, a list of individuals.

We do not upload, share, or match any individual member's personal contact information (name, email address, phone number, or any other direct identifier) with any third-party advertising platform for audience targeting, and we do not use “Customer Match”, “Custom Audience”, or any equivalent contact-list-upload feature offered by an advertising platform. Any audience targeting we configure on an advertising platform relies on that platform's own general demographic, interest, or geographic categories, informed by our aggregate analysis, never on a list of our members' identities. This aggregate analysis is separate from, and does not rely on, any cross-site tracking or retargeting cookie; see our Cookie Policy for the cookies used on maiviswealth.com.

9. Data Retention

  • Financial data: Seven years (UAE Commercial Transactions Law).
  • Identity and active account data, where no deletion request is made: Lifetime of the account, plus up to three years after the account becomes inactive.
  • Deleted account data: A deletion request opens a 30-day grace period (cancellable during that window); data is then permanently purged, except for a category subject to a named statutory minimum below. A deletion request governs: the three-year period above does not apply to data you have asked us to delete. Deletion is actioned within 30 days under Article 19 of the DIFC Data Protection Law 2020.
  • Authentication logs: 90 days rolling.
  • Encrypted vault documents: Retained until you request deletion.
  • Banking access tokens: Purged within 24 hours of disconnection.
  • Canadian members (FINTRAC): Financial transaction records retained 5 years.
  • Breach records (PIPEDA): Retained 24 months.
  • Pseudonymized event analytics: Retained no longer than the retention window configured with the analytics provider, and in any case no longer than 14 months for event-level records.
  • Aggregate, non-identifying counts: Retained indefinitely. These are totals and trends that cannot be linked back to you or your family.

How these periods compose. If you ask us to delete your data, the 30-day purge governs and the three-year period does not apply to you. Where a statutory minimum above (for example the seven-year UAE financial-data period, or the five-year FINTRAC period for Canadian members) is longer than the 30-day purge, that statutory minimum governs for that category of data and that category alone, and we will tell you which category we are retaining and why. The three-year period applies only to an account that becomes inactive without a deletion request. Section 5 of our Data Processing Agreement carries the same list.

10. Your Rights

10.1 All Members (DIFC DP Law Arts. 31-39)

Access (Art. 31); rectification (Art. 32); erasure (Art. 33); restriction (Art. 34); portability in machine-readable format (Art. 35); objection (Art. 36); objection to automated decision-making (Art. 38); withdrawal of consent (Art. 12(5)); complaint to Commissioner (Art. 60).

10.2 India (DPDPA Sections 11-14)

Access summary (Section 11); correction and erasure (Section 12); grievance redressal (Section 13); nomination right: nominate a person to exercise your rights on death or incapacity (Section 14, unique to Indian law). Response: 7 days per DPDP Rules 2025, Rule 14.

Significant Data Fiduciary status. maivis has not been notified as a Significant Data Fiduciary under Section 10 of the DPDP Act 2023. That designation is made by the Central Government, not self-assessed. If maivis is so notified, we will comply with the additional obligations that follow, including appointing a Data Protection Officer based in India, appointing an independent data auditor, and carrying out periodic Data Protection Impact Assessments, and we will update this policy to say so.

10.3 California (CCPA/CPRA)

Right to know (categories and specific PI collected in 12 months); delete; correct; opt out of sale/sharing (maivis does not sell/share PI); limit use of Sensitive PI (financial data = SPI under §1798.140(ae)). We honor Global Privacy Control (GPC) browser signals automatically.

California Shine the Light (Civ. Code §1798.83). We do not disclose your personal information to third parties for those third parties' own direct-marketing purposes, and we have not done so in the preceding calendar year. See Section 8A for how our advertising audience insights work without sharing any member's identity.

10.4 EU/UK (GDPR Arts. 15-22)

Access; rectification; erasure; restriction; portability; objection; automated decision-making rights. AI-generated intelligence involves automated processing. You may obtain human intervention, express your viewpoint, and contest automated decisions.

10.5 Response Timelines

JurisdictionResponse TimelineExtension
DIFC30 daysExtendable with reasons
EU/UK GDPR1 monthExtendable by 2 months
India DPDPA7 days (DPDP Rule 14)No extension
CCPA/CPRA45 daysExtendable by 45 days
Canada PIPEDA30 daysExtendable with notice

10.6 How We Verify Your Identity

We must be satisfied that a request comes from you before we act on it, and we aim to do that without asking you for data we do not already hold.

  • Primary route: make the request from inside your authenticated maivis account. Your passkey sign-in is itself the verification, and we ask for nothing further.
  • By email: a request from the email address registered on the account is normally sufficient. We will confirm it from that address before acting.
  • Where we have reasonable doubt: for example a request from an unrecognised address, or a request for bulk export of financial records, we may ask you to complete a step-up authentication in the app, or to confirm limited details we already hold. We will explain what we need and why.

We will not ask you for a copy of a government identity document unless there is no less intrusive way to resolve a genuine doubt. If we do, we use it only to verify that one request, and we delete it once the request is closed. If we cannot verify you, we will tell you why and what would resolve it, rather than simply refusing.

11. Data Breach Notification

In the event of a personal data breach, we will notify affected users and relevant supervisory authorities (including the DIFC Commissioner of Data Protection) within 72 hours of becoming aware of the breach, in accordance with DIFC DPL 2020, GDPR Article 33, and applicable data protection laws. We will also notify you directly if the breach is likely to result in a high risk to your rights and freedoms.

Internal standard: 72-hour regulator notification with immediate CERT-In escalation for India incidents.

JurisdictionRegulator NotificationIndividual NotificationThreshold
DIFCAs soon as practicable (72h recommended)As soon as practicable if high riskCompromises confidentiality/security/privacy
EU GDPR72 hours to lead supervisory authorityWithout undue delay if likely high riskRisk to rights and freedoms
UK GDPR72 hours to ICOWithout undue delay if likely high riskSame as EU GDPR
India DPDPA72h to DPB + 6h to CERT-InWithout delay to each individualNo materiality threshold
California15 days to AG (if 500+ affected)Within 30 days of discoveryUnauthorized access to unencrypted PI
Canada PIPEDAAs soon as feasible to OPCAs soon as feasible if RROSHReal risk of significant harm

12. Automated Decision-Making and AI

maivis uses AI to generate Intelligence: Structural Integrity, asset analysis, subscription auditing, daily briefings. Models used: Gemini Flash (primary, ~93% of requests), Claude Sonnet via Google Cloud Model Garden (~5%), Google Search Grounding for real-time market data (~2%, generic market queries only, no personal data transferred). All AI processing routes through the Gemini Enterprise Agent Platform under Google's Zero Data Retention terms. Under GDPR Article 22 and DIFC Article 38, you may request human review, express your viewpoint, or contest any AI output. Contact privacy@maiviswealth.com.

12.1 What the Automation Does, and What It Cannot Do

Purposes. We use automated processing to organize what you give us and to surface what we think deserves your attention: aggregating balances and assets, ranking daily briefing items, extracting fields from documents you upload, flagging concentration and expiry risks, and answering your questions about your own position.

What it cannot do. No automated process in maivis produces a decision with a legal effect on you or an equivalently significant effect. maivis makes no decision about your credit, insurance, employment, eligibility, or access to any product or service. It cannot move, invest, or commit your money. Your Structural Integrity score is calculated by a deterministic formula, not by an AI model, so the same inputs always produce the same score.

Risks we have identified, and what we do about them. The main risks are that an AI output is wrong or fabricated, that it is treated as advice, and that data reaches a model that should not have it. Against the first, every AI surface is presented as educational, is bounded by a deterministic engine wherever a number matters, and is disclaimed as capable of containing fabricated values. Against the second, the product does not make personal recommendations and does not execute anything. Against the third, direct identifiers are stripped by our Privacy Gateway before any model call, all inference runs under contractual Zero Data Retention, and no model is trained on your data.

Residual risk. An AI output may still be inaccurate. That is why you can always request human review, and why nothing in maivis should be acted on without confirming it independently.

13. Information About Family Members

When you add family members, we inform each via email invitation (containing this Privacy Policy link) per GDPR Article 14. Your consent cannot substitute for adult family members' own consent. Each must accept the invitation. For minors: we require confirmation from the account holder that appropriate parental or guardian consent has been obtained before adding any family member under 18. We do not independently verify this consent but reserve the right to remove accounts where this requirement has not been met. COPPA threshold is 13 (US); UK/EU GDPR threshold is 13-16. maivis applies the strictest applicable standard.

14. Communications

maivis may communicate with you via email (via Gmail API), push notifications, and in-app messaging, based on your channel preferences. You may manage preferences at any time via Settings → Notifications.

Each platform's own data processing terms apply to message delivery metadata. maivis does not store message content on third-party platforms beyond delivery requirements. All communications are archived for regulatory compliance.

15. Cookies

maivis uses: Firebase Auth session cookies (strictly necessary); Firebase Analytics GA4 cookies on maiviswealth.com (optional, require consent for EU/UK); a PostHog first-party analytics cookie (optional, consent required); Stripe payment session cookies (functional, checkout only); CSRF protection tokens (strictly necessary). Full details in our Cookie Policy at maiviswealth.com/legal/cookie-policy.

16. Children's Data

maivis is not directed at individuals under 18. No behavioral monitoring or targeted advertising directed at children. See Section 13 for guardian consent requirements.

17. Your Right to Compensation (DIFC)

The DIFC Laws Amendment Law No. 1 of 2025 introduced a private right of action allowing data subjects to bring compensation claims directly in DIFC Courts for financial and non-financial damage, in addition to complaints to the Commissioner.

18. Identity Verification and KYC

maivis does not collect government-issued identity documents for identity verification (KYC) as part of account registration. Documents uploaded to the Vault (such as passports, visas, or ID cards) are stored encrypted for your own record-keeping purposes and are not used for KYC verification. Users are responsible for ensuring their use of the platform complies with applicable anti-money-laundering and tax reporting obligations in their jurisdictions. maivis is not an identity verification service and does not substitute for KYC processes required by regulated financial institutions.

19. Changes to This Policy

Material changes are notified by email to your registered address and by in-app notification, at least 30 days before they take effect.

Where a change is material and to your detriment, we will present it to you for acceptance rather than apply it by default. Where a change relies on your consent, that consent is asked for and can be withdrawn; it is never inferred from your continued use. For all other changes, continued use after the effective date constitutes acceptance. You may delete your account at any time if you disagree.

19A. Language

This policy is published in English. English is the controlling language: if we or anyone else provides a translation, including an automatic browser translation, and it differs from this English text, the English text prevails. Mango Technologies Ltd. is established in the Dubai International Financial Centre, an English-language jurisdiction, and the service is provided in English.

20. Contact Us

Privacy Enquiries:
privacy@maiviswealth.com
Data Protection Officer:
dpo@maiviswealth.com
Legal Matters:
legal@maiviswealth.com
Postal:
Mango Technologies Ltd., DIFC Innovation Hub, Gate Avenue, Dubai, UAE

We are an online-only service with a direct relationship with our members, so requests reach us by email or from inside your account, and we do not operate a telephone line for privacy or legal matters. Every route above is monitored, and a request made from inside your authenticated account is the fastest, because it needs no separate identity check.

Complaints: DIFC Commissioner of Data Protection; Data Protection Board of India; ICO (UK); your EU supervisory authority; California Attorney General; Office of the Privacy Commissioner of Canada.

Privacy Policy v2.12 · July 2026