Ace Signal Hub

Privacy Policy

Ace Fortune Authorization System App and Related Services

Effective Date: 15 July 2026

1. Who We Are

ACE MATRIX TECHNOLOGIES L.L.C S.O.C (“ACE MATRIX”, the “Company”, “we”, “us”, or “our”) is the controller responsible for the personal data described in this Privacy Policy, except where a separate notice identifies another controller.

Company details:

Legal name: ACE MATRIX TECHNOLOGIES L.L.C S.O.C
Dubai, United Arab Emirates
Email: visa.respectcsp@gmail.com

This Privacy Policy applies to the Ace Fortune Authorization System App and related websites, portals, desktop or mobile applications, Signal Hub, AlertMarket, ACE-branded interfaces, and services that link to this Policy (collectively, the “Services”). A product-specific privacy notice may supplement this Policy and will govern the specific processing it describes.

2. Applicable Data-Protection Law

The Company processes personal data in accordance with applicable law, including Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data in the United Arab Emirates (the “UAE PDPL”). Where the processing falls within the territorial scope of another mandatory privacy law, such as the EU or UK GDPR, that law may also apply.

This Policy does not claim that every foreign privacy law applies to every User. Additional rights or disclosures apply only where the relevant law governs the processing.

3. Personal Data We May Collect

Depending on how you use the Services, we may collect:

3.1 Account and identity data

  • name, username, email address, telephone number, country, and profile information;
  • account status, email-verification status, and age or eligibility confirmation;
  • organisation name and representative authority for business Accounts; and
  • identifiers received from an identity provider if you choose a third-party sign-in method.

3.2 Authentication and licence data

  • password hashes and authentication tokens;
  • Licence Codes, product entitlements, membership status, and activation history;
  • login dates, session information, recovery requests, and security events; and
  • records of acceptance of Terms, Privacy Policy, or product-specific disclaimers.

3.3 Device and technical data

  • device identifiers, operating system, app and firmware versions, browser type, language, time zone, IP address, and approximate location derived from IP;
  • server, API, network, crash, error, and diagnostic logs;
  • push-notification tokens and delivery status; and
  • information about integrations, connectivity, and security settings.

3.4 Service-use and configuration data

  • features used, pages viewed, clicks, settings, preferences, backup and synchronisation data;
  • AI, strategy, signal, alert, indicator, symbol, timeframe, and notification configurations you choose to create or import;
  • Demo or Live Account status if the feature can detect it;
  • support requests, feedback, survey responses, and communications; and
  • data you upload, submit, or choose to connect through a Third-Party Service.

3.5 Transaction and consumer-service data

If a paid Service is offered, we may collect order details, invoice information, subscription status, payment result, refund or cancellation history, and limited payment metadata. Full payment-card details should be processed by the authorised payment provider unless a separate notice expressly states otherwise.

3.6 Marketing and communication data

We may collect communication preferences, message delivery and engagement information, and records of consent or objection to direct marketing.

3.7 Data we do not intentionally require

The Services are not designed to collect passports, Emirates IDs, financial-account credentials, private cryptographic keys, biometric data, health data, or other sensitive personal data unless a specific legally compliant process expressly requests it. Do not upload such information to free-text fields or support channels unless requested through an approved secure process.

4. How We Collect Personal Data

We collect personal data:

  • directly from you when you register, configure, purchase, contact us, or use the Services;
  • automatically from your device, browser, app, servers, and security systems;
  • from a third-party sign-in, cloud, broker, app-store, payment, or notification provider when you authorise the connection; and
  • from authorised business customers or representatives who create or manage Accounts.

5. Purposes and Legal Grounds for Processing

We process personal data for the following purposes:

5.1 Providing and administering the Services

To create and manage Accounts, verify Licence Codes, authenticate Users, maintain sessions, provide requested functions, synchronise settings, deliver notifications, process orders, and respond to support requests.

The legal ground may include your consent, processing necessary to enter into or perform a contract, processing necessary to take steps you request before entering a contract, or another ground permitted by applicable law.

5.2 Security, fraud prevention, and system integrity

To detect unauthorised access, abuse, malware, suspicious behaviour, technical faults, and violations; protect Users and systems; investigate incidents; and enforce legal rights.

The legal ground may include compliance with legal obligations, protection of rights and legal claims, processing necessary to perform the service securely, consent where required, or another ground permitted by the UAE PDPL. Where the GDPR applies, legitimate interests may also be relied on where those interests are not overridden by your rights.

5.3 Product operation, analytics, and improvement

To measure performance, diagnose errors, understand feature use, improve reliability and user experience, develop new functions, and conduct aggregated or anonymised analysis.

Where possible, we use aggregated or anonymised information. Where personal data is used, the legal ground may include consent, contract necessity, or another permitted ground. Where the GDPR applies, legitimate interests may also apply subject to balancing and your rights.

5.4 Communications

To send service messages, security alerts, policy updates, transaction notices, and support responses. We send promotional communications only where permitted and honour available opt-out rights.

5.5 Legal and regulatory compliance

To comply with lawful requests, tax and accounting requirements, consumer obligations, company records, dispute resolution, investigations, and other duties under applicable law.

5.6 Corporate transactions

To evaluate or complete a lawful merger, reorganisation, financing, sale, transfer, or acquisition, subject to confidentiality and applicable notice or consent requirements.

6. Consent

Where processing is based on consent, the request will be presented in clear and accessible language. You may withdraw consent through the relevant setting or by contacting us. A withdrawal does not affect processing that was lawful before the withdrawal and may prevent us from providing a feature that requires the data.

7. Automated Processing and AI

The Services may use automated systems to detect security events, deliver alerts, personalise settings, or generate technical outputs. We do not intend to make a decision producing legal or similarly significant effects solely by automated processing unless the process is disclosed, permitted by law, and accompanied by required safeguards.

Where applicable, you may request information about automated processing, object to a decision, or request human review in accordance with the UAE PDPL or other governing law.

8. Sharing and Recipients

We do not sell or rent personal data as a commodity. We may share personal data only as reasonably necessary with:

  • cloud-hosting, database, cybersecurity, analytics, backup, support, email, notification, identity, AI, app-store, and payment providers acting under contractual or legal controls;
  • Third-Party Services you choose to connect, subject to their terms and privacy notices;
  • professional advisers, auditors, insurers, and debt or fraud-prevention service providers;
  • competent courts, regulators, law-enforcement bodies, government entities, or other persons where disclosure is legally required or necessary to protect rights, safety, or security;
  • a buyer, successor, investor, or transferee in a lawful corporate transaction; and
  • another person where you have directed or consented to the disclosure.

Service providers may process data only for authorised purposes and must apply appropriate confidentiality and security obligations, subject to applicable law.

9. International and Cross-Border Transfers

Personal data may be processed in the UAE and in other countries where approved service providers, infrastructure, or Users are located.

For transfers from the UAE, the Company will apply the requirements of the UAE PDPL, including an approved protection level, applicable agreements and safeguards, explicit consent where legally sufficient, contract necessity, legal-claims necessity, public-interest grounds, or another permitted transfer mechanism.

Where another data-transfer regime applies, the Company will use an available lawful mechanism and supplementary safeguards appropriate to the risk.

10. Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, to provide the Services, maintain security, comply with law, resolve disputes, and enforce agreements.

Retention depends on the data category and may include:

  • Account data for the life of the Account and a limited period after closure;
  • Licence and acceptance records for the period needed to demonstrate entitlement and contract formation;
  • transaction and tax records for the legally required period;
  • security, access, and diagnostic logs for a limited risk-based period;
  • backup copies until overwritten through normal backup cycles; and
  • legal-hold data for as long as required for an investigation, claim, or proceeding.

When personal data is no longer required, it will be deleted, securely destroyed, or anonymised, subject to technical limitations and legal obligations.

11. Security

We use technical and organisational measures appropriate to the nature, scope, context, and risk of processing. Measures may include access controls, least-privilege permissions, encryption in transit and where appropriate at rest, password hashing, token expiry, pseudonymisation, logging, backups, vulnerability management, incident procedures, and staff confidentiality obligations.

No system is completely secure. You are responsible for using a strong unique password, protecting your device and Licence Code, installing security updates, and notifying us promptly of suspected compromise.

Where a personal-data breach requires notification under applicable law, the Company will notify the competent authority and affected individuals in the manner and timeframe required.

12. Your Rights

Subject to applicable law and lawful exceptions, you may have the right to:

  • receive information about the categories, purposes, recipients, retention criteria, transfer safeguards, and security measures relating to your personal data;
  • access personal data held about you;
  • receive or request transfer of data in a structured, commonly used, machine-readable format where the legal conditions are met;
  • correct inaccurate or complete incomplete data;
  • request erasure where the data is no longer necessary, consent is withdrawn, processing is unlawful, or another legal ground applies;
  • restrict or stop processing in circumstances provided by law;
  • object to direct marketing and related profiling;
  • object to certain automated decisions and request human review where available;
  • withdraw consent; and
  • lodge a complaint with the competent UAE data-protection authority or another supervisory authority that has jurisdiction.

We may need to verify your identity and authority before acting on a request. Rights may be limited where necessary to protect another person’s rights, information security, legal claims, judicial or regulatory processes, public interest, or another lawful exception.

13. Direct Marketing

You may opt out of promotional email or push messages through the unsubscribe mechanism, notification settings, or by contacting us. Service, security, transaction, and legal notices are not promotional and may still be sent while your Account remains active.

14. Cookies, SDKs, and Similar Technologies

Websites and apps may use cookies, local storage, software development kits, tokens, and similar technologies for authentication, preferences, security, performance, analytics, and notifications. Where consent is legally required for a non-essential technology, the Services will request it through an appropriate control.

A separate Cookies Policy or in-app notice should identify the technologies actually in use, their providers, purposes, and retention periods.

15. Third-Party Links and Integrations

A link or integration may take you to a service not controlled by the Company. That provider is responsible for its own processing. Review its privacy notice before providing personal data or connecting an Account.

16. Children

The Services are not intended for persons under eighteen (18). We do not knowingly collect personal data from a minor for trading-related or account-based Services. If you believe a minor has supplied personal data, contact us so that we can investigate and take appropriate action.

17. Changes to This Policy

We may update this Policy for legal, technical, security, or product changes. The updated version will show a new effective date. We will provide reasonable notice of a material change through the Services, by email, or on the relevant website where practicable.

18. Contact and Complaints

For privacy questions, rights requests, or complaints, contact:

Privacy Contact
ACE MATRIX TECHNOLOGIES L.L.C S.O.C
Office B2007-186, Latifa Tower
Trade Center First, Dubai, United Arab Emirates
Email: visa.respectcsp@gmail.com

Please identify the relevant product and Account and describe your request. Do not send a password, full payment-card number, private key, or unnecessary identity document by ordinary email.

If you are not satisfied with the response, you may submit a complaint to the competent data- protection authority where you have that right.

19. Governing Law

This Policy is governed by applicable UAE federal law and the laws in force in Dubai, without prejudice to mandatory data-protection rights or complaint mechanisms that apply in another jurisdiction.

To the extent required by mandatory UAE law, an approved Arabic version and the official Arabic text of applicable legislation prevail. Otherwise, the English version controls over unofficial translations.