Data Protection & Privacy Policy

Entity: Varni Labs FZE
Brand: Roma
Regulatory status: Licensed by VARA for VA Broker-Dealer Services (Reference VL/23/10/001)
Version: July 2026
Effective date: 31-July-2026
Policy Owner: Sandeep Hodkasia, Data Protection Officer

1. Introduction, Scope and Who We Are

Varni Labs FZE (“Varni Labs”, “Roma”, “we”, “us” or “our”) is a virtual asset service provider licensed by the Dubai Virtual Assets Regulatory Authority (VARA) to provide VA Broker-Dealer Services (VARA Reference VL/23/10/001). We facilitate conversion between fiat currency and Virtual Assets — principally USDT and USDC — through on-ramp, off-ramp and over-the-counter (OTC) services. We do not custody client Virtual Assets other than transiently in the course of executing a conversion.

This Policy explains how we collect, use, disclose, transfer, store and otherwise process Personal Data, and the rights available to Data Subjects. For the purposes of applicable data protection law, Varni Labs FZE acts as the Data Controller of the Personal Data described in this Policy.

This Policy applies to Personal Data relating to: (a) our clients and prospective clients (including individual representatives, directors, shareholders and ultimate beneficial owners of institutional clients); (b) visitors to and users of our website, applications and platforms; (c) counterparties, vendors and their personnel; and (d) any other individuals whose Personal Data we process in connection with our services.
Governing law and standards
This Policy is governed by, and is intended to comply with, UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL") and any executive regulations issued under it, together with the data protection, data security and record-keeping expectations applicable to us as a VARA licensee, including under the VARA Technology and Information Rulebook.

As a matter of good practice, Roma also has regard to internationally recognised data protection standards (such as those reflected in the EU General Data Protection Regulation (GDPR) and Canada's PIPEDA) in designing its privacy programme. However, the governing law for this Policy and for our processing of Personal Data is the UAE PDPL. Nothing in this Policy is intended to grant rights beyond, or to conflict with, applicable UAE law.

2. Definitions

In this Policy, the following terms have the meanings given to them in the PDPL. The summaries below are provided for convenience only; the statutory definitions prevail.

  • Personal Data: any data relating to an identified natural person, or a natural person who can be identified, directly or indirectly, by reference to an identifier such as a name, identification number, location data, an online identifier, or one or more factors specific to that person's identity.
  • Sensitive Personal Data: Data which directly or indirectly reveals a person's family or ethnic origin, political or philosophical opinions, religious beliefs, criminal record, biometric data, or any data relating to that person's health or physical, psychological, mental, genetic or sexual condition, as defined in the PDPL.
  • Biometric Data: Personal Data resulting from processing of physical, physiological or behavioural characteristics that allow the unique identification of a natural person, such as facial images used for identity verification.
  • Processing: any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, transfer, restriction, erasure or destruction.
  • Data Controller (Controller): the person or entity that, alone or jointly with others, determines the purposes and means of Processing Personal Data. Varni Labs FZE is the Controller for the Processing described in this Policy.
  • Data Processor (Processor): a person or entity that Processes Personal Data on behalf of and under the instructions of the Controller.
  • Data Subject: the natural person to whom the Personal Data relates.
  • Consent: a Data Subject's freely given, specific and unambiguous indication, by statement or clear affirmative action, agreeing to the Processing of their Personal Data, in the form required by the PDPL.
  • Cross-Border Transfer: the transfer of Personal Data to a recipient located outside the United Arab Emirates.
  • UAE Data Office: the federal authority established under UAE law to supervise and enforce the PDPL. The PDPL refers to this authority as the "Bureau" or "UAE Data Bureau"; references in this Policy to the Data Office mean that authority.
  • VARA: the Dubai Virtual Assets Regulatory Authority, our virtual-asset regulator.
  • Virtual Asset (VA): a digital representation of value that may be digitally traded or transferred, as defined under the applicable VARA regulations, including the stablecoins USDT and USDC.

3. Personal Data We Collect

The categories of Personal Data we collect depend on the nature of your relationship with us. They typically include the following.
Identity and KYC data
  • Full name, date and place of birth, gender, nationality and residential address.
  • Government-issued identification documents (e.g. passport, Emirates ID) and the data they contain.
  • Photographs, selfies and liveness-check imagery captured during identity verification.
  • For institutional clients: identity data of directors, authorised signatories, shareholders and ultimate beneficial owners; corporate documents, and other relevant data containing Personal Data.
Contact data
  • Email address, correspondence address and communication preferences.
Financial and transaction data
  • Bank account details (including accounts used to fund or receive fiat via our banking partner), source of funds and source of wealth information.
  • Transaction records for fiat and Virtual Asset legs of conversions, including amounts, timestamps, counterparties, Virtual Asset wallet addresses and transaction identifiers.
Compliance and screening data
  • Results of sanctions, politically exposed person (PEP) and adverse media screening; risk ratings; records of AML/CFT reviews and, where applicable, information relating to suspected financial crime. Some of this data (for example, data revealing a criminal record) may constitute Sensitive Personal Data under the PDPL.
Device, technical and usage data
  • IP address, device identifiers, browser type, operating system, log-in records, approximate location and activity logs relating to your use of our website, applications and platforms.
  • Cookies and similar technologies.
Communications data
  • Records of your communications with us, including support requests, chat messages and emails.

We ask that you do not provide us with Sensitive Personal Data unless we specifically request it. Where we process Sensitive Personal Data (for example, biometric identity-verification data or criminal-record screening data), we do so only as permitted by the PDPL and, where required, with your explicit consent.

Our services are intended for persons aged 18 and over. We do not knowingly offer services to, or collect Personal Data of, anyone under the age of 18. If we become aware that we hold Personal Data of a person under 18, we will delete it unless we are required by law to retain it.

4. How We Collect Personal Data

  • Directly from you — when you register or apply for an account, complete KYC onboarding, execute transactions, contact our support team, or otherwise interact with us.
  • Automatically from your use of our services — through our website, applications, platforms, and cookies or similar technologies, which generate device, technical and usage data.
  • From third parties — including but not limited to identity-verification and screening providers, our banking partner, Virtual Asset infrastructure providers, publicly available registers and sources, sanctions and watchlist databases, credit or fraud-prevention agencies, introducers or referral partners and regulators or law-enforcement authorities.
  • From your employer or the institution you represent — where you interact with us as a director, signatory, beneficial owner or representative of an institutional client.

5. Purposes of Processing and Lawful Bases

Under the PDPL, Personal Data may be processed with the Data Subject's consent or on the other lawful bases and exceptions set out in the PDPL, including where processing is necessary for the performance of a contract to which the Data Subject is party, to comply with applicable law and the Controller's legal obligations, or in other circumstances permitted by the PDPL. We rely on the following bases for the purposes described below.
To provide our services (performance of a contract)
  • Opening, administering and closing your account; executing fiat-to-Virtual-Asset and Virtual-Asset-to-fiat conversions (on-ramp, off-ramp and OTC); settling fiat through our banking partner; providing client support; and communicating with you about your account and transactions.
To comply with our legal and regulatory obligations
  • Conducting customer due diligence, enhanced due diligence, sanctions/PEP screening and ongoing transaction monitoring under UAE anti-money-laundering and counter-terrorist-financing (AML/CFT) laws and VARA's rulebooks.
  • Reporting to, and responding to requests from, VARA, the UAE Financial Intelligence Unit (FIU), the UAE Data Office, law-enforcement agencies, courts and other competent authorities.
  • Complying with record-keeping obligations, including the requirement applicable to us as a VARA licensee to retain records (which include Personal Data) for a minimum period of eight years (see Section 9).
  • Complying with the applicable travel rule requirements and other Virtual Asset transfer information-sharing requirements applicable to VA transactions.
  • Protecting the security and integrity of our systems, services and client data, and detecting, preventing and investigating fraud, market abuse and other misuse, in line with our obligations under the VARA Compliance and Risk Management and Technology and Information Rulebooks.
  • Establishing, exercising or defending legal claims, and responding to judicial or security procedures.
  • Meeting our statutory audit obligations.
With your consent
  • Sending you direct marketing and promotional communications.
  • Any other processing for which we ask for, and you give, consent.
  • Analysing website and platform usage to maintain and improve our services, including through cookies and similar technologies.

Where processing is required by law (for example AML/CFT obligations), providing the relevant Personal Data is mandatory: if you do not provide it, we will not be able to onboard you or provide services to you.

6. Consent and Withdrawal of Consent

Where we rely on your consent, we will seek it in a clear, specific and unambiguous manner, in the form required by the PDPL, and we will keep a record of it. You may refuse consent without affecting your access to services that do not depend on that consent.

You may withdraw your consent at any time by contacting us using the details in Section 17 (or, for marketing messages, by using the unsubscribe mechanism provided in the message). Withdrawal of consent:

  • takes effect prospectively and does not affect the lawfulness of processing carried out before withdrawal; and
  • does not prevent us from continuing processing that is based on another lawful basis — in particular, we must by law continue to retain and, where required, process KYC, transaction and compliance records even after you withdraw consent or close your account.

7. Sharing, Disclosure and Processors

We do not sell Personal Data. We share Personal Data only as described below, and we require third parties that process Personal Data on our behalf to do so under written contracts imposing confidentiality, security and data protection obligations consistent with the PDPL.

  • Service providers and processors: including our banking partner, Virtual Asset wallet and transfer infrastructure providers, identity-verification and sanctions/PEP/adverse-media screening providers, and cloud hosting, communications and analytics providers.
  • Regulators, authorities and legal disclosures: VARA, the UAE Financial Intelligence Unit, the UAE Data Office, the UAE Central Bank (where relevant), law-enforcement agencies, courts, tax authorities and other competent authorities, where disclosure is required or permitted by applicable law, regulation or court order.
  • Members of our corporate group: entities within our corporate group, located both inside and outside the UAE, for intra-group administration, compliance, risk management and support functions. Where such sharing involves a transfer of Personal Data outside the UAE, it is subject to the safeguards described in Section 8.
  • Counterparties: Counterparties and their banks or VASPs, to the extent required to execute, settle or trace a transaction (including under travel-rule requirements).

Other disclosures: includes professional advisers (legal, audit, accounting, insurance) under duties of confidentiality.

8. Cross-Border Transfers of Personal Data

The PDPL permits Cross-Border Transfers of Personal Data where the destination jurisdiction is considered to provide an adequate level of protection, or otherwise where appropriate safeguards or conditions set out in the PDPL are satisfied — for example, contractual arrangements imposing PDPL-consistent obligations on the recipient, or the Data Subject's express consent, or where the transfer is otherwise permitted by the PDPL.

When we transfer Personal Data outside the UAE, we rely on contractual data protection clauses imposing PDPL-consistent obligations on the recipient, supported by vendor due diligence and, where required, your express consent.

9. Data Retention

We retain Personal Data only for as long as necessary for the purposes for which it was collected, and thereafter as required or permitted by applicable law.

  • Regulatory record-keeping: as a VARA licensee subject to UAE AML/CFT requirements, we are required to retain client due diligence records, transaction records and related documentation (which include Personal Data) for a minimum of eight (8) years, generally calculated from the end of the client relationship or the completion of the relevant transaction, or such longer period as a competent authority may require.
  • Legal claims: we may retain Personal Data for longer where necessary for the establishment, exercise or defence of legal claims, or where required by a regulator, court or law-enforcement authority.
  • Other data: retention periods for non-regulatory data (e.g. marketing preferences, website analytics, recruitment data) are set out in our internal retention schedule.

When Personal Data is no longer required, we securely delete, destroy or irreversibly anonymise it.

10. Data Security

We implement appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration or disclosure, consistent with the PDPL and with the technology governance, information security and data protection expectations applicable to us under the VARA Technology and Information Rulebook. These measures include:

  • Encryption of Personal Data in transit and at rest, and pseudonymisation of Personal Data where appropriate.
  • Role-based access controls, least-privilege access, and multi-factor authentication for systems containing Personal Data.
  • Segregation of environments, secure key-management practices for Virtual Asset infrastructure, network security controls, logging and monitoring.
  • Vendor due diligence and contractual security requirements for processors and other service providers.
  • Staff confidentiality obligations, background screening where permitted, and periodic data protection and security training.
  • Business continuity, disaster recovery and incident response arrangements, tested periodically.

No transmission or storage system can be guaranteed to be completely secure. If you suspect any misuse, loss of, or unauthorised access to your Personal Data, please contact us immediately using the details in Section 17.

11. Your Rights as a Data Subject

Subject to the conditions and exceptions set out in the PDPL, you have the following rights in relation to your Personal Data:

  • Right to access and receive information — to obtain confirmation of whether we process your Personal Data and to receive information about that processing, including the purposes, the categories of data, the recipients, and available safeguards for cross-border transfers.
  • Right to data portability — to receive the Personal Data you provided to us in a structured, machine-readable format, and to have it transferred to another controller where technically feasible, in the circumstances contemplated by the PDPL.
  • Right to rectification — to have inaccurate or incomplete Personal Data corrected or completed.
  • Right to erasure — to request deletion of your Personal Data in the circumstances contemplated by the PDPL (noting the important limits described below).
  • Right to restrict processing — to request that we limit the processing of your Personal Data in the circumstances contemplated by the PDPL.
  • Right to request cessation of processing — to object to, and request that we stop, certain processing, including processing for direct marketing purposes.
  • Rights in relation to automated processing — to object to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects concerning you, and to request human review (see Section 12).
  • Right to withdraw consent — as described in Section 6.
  • Right to complain — to lodge a complaint with us and with the competent supervisory authority (see Section 15).
How to exercise your rights
  1. Submit your request to our privacy contact using the details in Section 13 or Section 17, describing the right you wish to exercise.
  2. We may need to verify your identity before acting on your request, to protect your Personal Data from unauthorized disclosure.

Important limits: because we are subject to AML/CFT and VARA record-keeping obligations, we are legally required to retain certain KYC, transaction and compliance records for the periods described in Section 9. To that extent, requests for erasure, restriction or cessation of processing may be refused or only partially fulfilled, as permitted by the PDPL. We will inform you where this is the case, unless the law prohibits us from doing so (for example, in connection with suspicious transaction reporting, where “tipping off” is prohibited).

12. Automated Processing and Profiling

We use automated tools as part of our compliance and security controls — for example, automated sanctions and watchlist screening, transaction monitoring, fraud detection and client risk scoring.

Our current practice is that adverse decisions with significant effects (such as declining onboarding, rejecting or holding funds, or restricting an account) are reviewed by a human before being finalised. Where the PDPL grants you rights in relation to decisions based solely on automated processing, you may object and request human review by contacting us using the details in Section 13.

13. Data Protection Officer Contact

DPO: Sandeep Hodkasia


Postal address: Data Protection Officer, Varni Labs FZE, Sheikh Rashid Tower, DM Building No. 14, Dubai World Trade Centre, Dubai, United Arab Emirates

The DPO is responsible for overseeing our compliance with this Policy and the PDPL, acting as the point of contact for Data Subjects, and liaising with the UAE Data Office and other competent authorities.

14. Personal Data Breach Handling and Notification

We maintain an incident response plan for identifying, containing, assessing and remediating Personal Data breaches, which forms part of our wider security incident management framework.

Where a Personal Data breach occurs, we will:

  1. contain the breach and assess its nature, scope and likely consequences for affected Data Subjects;
  2. notify the UAE Data Office and, where required, affected Data Subjects;
  3. assess and make any incident notifications required of us as a VARA licensee, including under the VARA Technology and Information Rulebook and any applicable VARA incident-reporting timelines; and
  4. document the breach, our response and remediation, and apply lessons learned to prevent recurrence.

Where we act as a processor for another controller (if applicable), or where our processors suffer a breach affecting our data, contractual arrangements require prompt notification so that statutory notification duties can be met.

15. Complaints and Your Right to Complain to the Authority

If you have a concern or complaint about how we handle your Personal Data, please contact us first using the details in Section 13 or Section 17. We take complaints seriously and will investigate and respond in accordance with our complaints-handling procedures, as set out in our Complaints Policy published on ae.roma.global.

If you are not satisfied with our response, or if you believe our processing of your Personal Data infringes the PDPL, you have the right to lodge a complaint with the UAE Data Office (the federal authority responsible for supervising and enforcing the PDPL) or such other authority as may be competent.

Information and Channels

16. Changes to This Policy

We may update this Policy from time to time to reflect changes in our services, our processing activities, or applicable law and regulation (including the issuance or amendment of the PDPL executive regulations and VARA rulebooks). The current version will always be available on our website (ae.roma.global) and, on request, from our privacy contact.

Where changes are material, we will notify you through appropriate means (for example, by email or in-platform notice) before they take effect, and where the change relates to processing based on consent, we will seek fresh consent where the PDPL requires it.

Effective date of this version: 31-July-2026

Last reviewed: 31-July-2026

17. Contact Details

  • Controller: Varni Labs FZE (brand: Roma)
  • Registered office: Sheikh Rashid Tower, DM Building No. 14, Dubai World Trade Centre, Dubai, United Arab Emirates
  • VARA licence reference: VL/23/10/001 (VA Broker-Dealer Services)
  • General enquiries: support@roma.global
  • Website: ae.roma.global