PRIVACY POLICY – GREENBULL CLUB
In force as of 16 July 2026
ARTICLE 1 – PREAMBLE
The terms defined in the Terms and Conditions of Sale (T&Cs) have the same meaning in this Privacy Policy when used with a capital letter.
This Privacy Policy is intended to inform the users (the “Users”) of the website https://gbclub2026.webflow.io (the “Website”) and, where applicable, of the Greenbull Club community application (the “Application”) (collectively referred to as the “Platform”), of the manner in which their personal data may be collected and processed, in accordance with the applicable regulations on the protection of personal data.
It is established in particular with regard to:
- Regulation (EU) 2016/679 of 27 April 2016 on the protection of personal data (GDPR), for Users located in the European Union;
- Federal Decree-Law No. 45/2021 on the protection of personal data of the United Arab Emirates;
- As well as, where applicable, other local legislation applicable according to the User’s place of residence.
The Website allows the submission of an application to join the Greenbull Club. The Platform allows, after acceptance of the application and payment of the Membership, the creation of a personal account (“Account”) and access to the Services (community, opportunities, events, benefits and the ARYA Wealth tool, which is governed by its own terms and conditions and its own privacy policy, to which reference should be made. The data processing carried out within this tool is not governed by this Policy).
This Policy complements the Legal Notice, the Terms of Use (T&U), the Terms and Conditions of Sale (T&Cs) and the Cookie Policy, accessible at any time on the Platform.
ARTICLE 2 – DATA CONTROLLER
The processing of personal data carried out in connection with the operation of the Platform is performed under the responsibility of:
GREENBULL TECHNOLOGY FZCO, a company incorporated under the laws of the United Arab Emirates, and specifically under the authority of the DMCC Free Zone, with a share capital of AED 100,000, whose registered office is located at Office 3004-3009, 30th Floor, Platinum Tower, Jumeirah Lakes Towers, Dubai, United Arab Emirates, holder of licence No. DMCC-747038 issued by the Dubai Multi Commodities Centre (hereinafter “Greenbull” or the “Data Controller”).
Email: contact@greenbull.club.
Telephone: +971 50 822 0143
As the Data Controller is established outside the European Union, it has appointed, in accordance with Article 27 of the GDPR, the company GREENBULL GROUP, a simplified joint-stock company (société par actions simplifiée) under French law, with a share capital of EUR 1,282,389.05, whose registered office is located at 400, Promenade des Anglais, 06200 – Nice (France), registered with the Nice Trade and Companies Register under No. 834 111 122, as its representative within the European Union. Data subjects residing in the Union may contact it, for any question relating to the processing of their data, at contact@greenbull.com or by post at the above address.
ARTICLE 3 – SCOPE OF THE PROCESSING CARRIED OUT VIA THE PLATFORM
3.1 Application, account creation and access to the Services
The Platform allows the submission of an application to join the Greenbull Club, by means of the form provided for that purpose. It does not allow the direct creation of an Account or a Membership.
The creation of an Account and access to the Services (access to the community, opportunities, events, benefits and the ARYA Wealth tool) take place on the Platform, after acceptance of the application and payment of the price of the Services by the User.
To this end, the Data Controller processes personal data necessary for:
- The processing and assessment of applications;
- The creation and management of the Account;
- The management of payments and Membership;
- The provision of the Services and support;
- Securing the Platform and preventing fraud.
3.2 Data processed during browsing
When browsing the Platform, the Data Controller may also process personal data, in particular:
- Technical data (IP address, logs, browser type, technical identifiers);
- Audience data (via cookies/trackers, subject to consent);
- Data voluntarily transmitted via forms (contact, support).
3.3 Partner platforms and third-party providers
Certain functionalities may involve third-party providers (hosting, payment, support tools, analytics, server providers, etc.). These providers act in principle as processors of the Data Controller, unless otherwise stated (e.g. if a partner processes data for its own purposes, it may be a separate data controller).
The User is invited to consult the privacy policies of these third parties where applicable.
ARTICLE 4 – CATEGORIES OF DATA PROCESSED AND PURPOSES
In connection with the operation of the Platform, the Data Controller processes personal data exclusively for the purposes described below.
The assessment of applications is subject to an individual review and does not rely on any solely automated decision-making within the meaning of Article 22 of the GDPR.
4.1 Data processed directly by the Data Controller
| Purpose of processing | Legal basis | Categories of data concerned |
| Processing and assessment of Memberships | Pre-contractual measures / Legitimate interest | Surname, first name, email, country of residence, professional activity, order of magnitude of assets and/or income, investment experience, any referral, motivation |
| Creation and management of the Account | Performance of the contract / pre-contractual measures | Surname, first name, email, telephone, identifiers |
| Provision of the Services (access to the Greenbull Club, the community, the content and the ARYA Wealth tool) | Performance of the contract | Account data, usage data (logs, settings), technical information |
| Organisation and management of the Club’s private events | Performance of the contract | Identification data, registrations, dietary preferences or specific constraints, participation information |
| Management of Memberships and invoicing | Performance of the contract / Legal obligation | Identification data, subscription history, invoices |
| Payments (via provider) | Performance of the contract / Legitimate interest (anti-fraud) | Data required for payment (token, status), anti-fraud |
| Customer support | Performance of the contract / Legitimate interest | Support history, email, logs useful for diagnosis |
| Security, fraud prevention, abuse, incidents | Legitimate interest | IP, logs, technical traces, account data |
| Audience measurement and statistics | Consent (where required) / Legitimate interest (essential cookies) | Browsing data, cookies |
| Marketing / newsletters | Consent | Email, preferences, interaction history |
| Handling of requests to exercise rights | Legal obligation | Data necessary for the request (identity, contact) |
| Defence of rights / disputes | Legitimate interest | Data strictly necessary for litigation |
| Capture, use and dissemination of images at Greenbull Club events (photographs, videos), in particular for the communication and promotion of the Club | Consent | Image, voice, surname and first name, role, participation in the event |
Important: bank card data is not stored in clear text by the Data Controller; it is processed by a secure payment provider.
4.2 Retention periods
Personal data is retained for a period not exceeding that strictly necessary to achieve the purposes pursued.
The applicable retention periods are detailed in ARTICLE 7 of this Privacy Policy.
ARTICLE 5 – RECIPIENTS OF PERSONAL DATA
The personal data processed via the Platform is intended exclusively for:
- The strictly authorised internal departments of the Data Controller;
- Technical providers acting as processors (hosting, maintenance, payment, support, emailing/CRM, analytics, etc.);
- Where applicable, the affiliated companies of the group, where necessary for the performance of the Services and in compliance with applicable regulations.
The Data Controller does not sell personal data.
Data is not used for advertising/marketing purposes where consent is required and has not been given.
Payment provider: Payments made via the payment link sent after acceptance of the application are processed by Stripe Payments Europe Ltd and/or its affiliated entities (hereinafter “Stripe”), acting as a payment services provider.
In connection with the processing of payments:
- Bank card and payment method data is collected and processed directly by Stripe;
- The Data Controller does not store full bank card numbers;
- Only the information necessary for the management of the subscription (payment status, transaction identifier, masked partial information) may be transmitted to the Data Controller.
Stripe acts as a processor for payment operations and may, depending on its own organisation, process certain data outside the European Union.
Where data of Users located in the European Union is transferred outside the EU, such transfers are governed by appropriate safeguards in accordance with the GDPR, in particular through the implementation of Standard Contractual Clauses (SCC).
Users are invited to consult Stripe’s privacy policy for more information on the processing of their data:
https://stripe.com/privacy
ARTICLE 6 – INTERNATIONAL DATA TRANSFERS
Given:
- The location of the Data Controller in the United Arab Emirates;
- The use of international technical providers (hosting, payment, SaaS tools);
personal data may be transferred and processed outside the User’s country of residence, including outside the European Union.
As the Data Controller is itself established in the United Arab Emirates, a country which does not benefit from an adequacy decision of the European Commission, the data of Users located in the European Union is transferred to the United Arab Emirates for the purpose of providing the Services. This transfer is governed by appropriate safeguards within the meaning of Articles 44 et seq. of the GDPR, in particular the conclusion of Standard Contractual Clauses (SCC) and, where applicable, reliance on the derogations provided for in Article 49 of the GDPR, in particular where the transfer is necessary for the performance of the contract concluded with the data subject or the implementation of pre-contractual measures taken at their request.
Where data of Users located in the European Union is transferred to another third country which does not benefit from an adequacy decision of the European Commission, such transfers are governed in accordance with Articles 44 et seq. of the GDPR, in particular through:
- The conclusion of Standard Contractual Clauses (SCC);
- The implementation of additional technical and organisational measures where necessary (encryption, access restriction, pseudonymisation).
The User may obtain additional information on these safeguards, as well as a copy or the location of the safeguards implemented, by contacting the Data Controller or its representative within the European Union.
ARTICLE 7 – RETENTION PERIOD
The personal data collected and processed via the Website and the Platform is retained for a period not exceeding that strictly necessary to achieve the purposes pursued.
Unless otherwise required by law or regulation, the retention periods applied are as follows:
- Data relating to the User Account: retained for the duration of use of the Account, then 3 years from the last activity.
- Contractual and invoicing data (orders, invoices, proof of payment): retained for 10 years, in accordance with applicable legal and accounting obligations.
- Customer support data (emails, tickets, exchanges): retained for 3 years from the last exchange.
- Marketing / commercial prospecting data: retained for 3 years from the User’s last active contact.
- Technical data and security logs: retained for a maximum period of 12 months.
- Cookies and trackers: retained in accordance with the Cookie Policy, within the generally applicable maximum limit of 13 months for non-essential cookies.
At the end of these periods, the data is deleted or anonymised, unless otherwise required by law or necessary for the establishment, exercise or defence of legal claims.
ARTICLE 8 – DATA HOSTING
The Website is hosted by Webflow Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, United States.
The community Application is an application installed on the User’s device and is not subject to separate hosting. The data processed via the Application is hosted on servers located in Amsterdam (Netherlands), within the European Union, through the infrastructure provider Railway Corp., 548 Market Street, Suite 68956, San Francisco, California 94104, United States (team@railway.com), with which the Data Controller has concluded a data processing agreement including Standard Contractual Clauses. The representative of Railway Corp. within the European Union, within the meaning of Article 27 of the GDPR, is the company DP-Dock GmbH, Attn.: Railway Corporation, Ballindamm 39, 20095 Hamburg, Germany.
Any transfers outside the European Union are governed in accordance with Article 6 of this Policy.
ARTICLE 9 – USERS’ RIGHTS
In accordance with applicable regulations, and in particular the GDPR where it applies, every User has the following rights:
- Right of access;
- Right of rectification;
- Right to erasure;
- Right to restriction;
- Right to object;
- Right to data portability;
- Right to withdraw consent at any time where processing is based on consent.
Requests may be sent to: dpo@greenbull.com
The Data Controller will respond within one (1) month of receipt of the request, except in cases of particular complexity.
In the event of reasonable doubt as to the identity of the applicant, identity verification may be requested.
ARTICLE 10 – COMPLAINTS
The User may:
- Send a request directly to the Data Controller;
- Refer the matter to the competent data protection authority:
- For Users located in the European Union: the supervisory authority of their State of residence (e.g. the CNIL in France);
- For Users located in the United Arab Emirates: the competent authority for personal data protection.
ARTICLE 11 – UPDATING OF THE POLICY
This Privacy Policy may be amended at any time to reflect legal, regulatory, technical or organisational developments.
The applicable version is the one published on the Platform on the date of consultation.
In the event of a substantial modification, Users may be informed by any appropriate means.
ARTICLE 12 – SECURITY AND CONFIDENTIALITY
The Data Controller implements appropriate technical and organisational measures in order to ensure a level of security appropriate to the risks, in particular:
- Strict control of access to data;
- Encryption of passwords;
- Securing of infrastructure and servers;
- Security audits and regular updates;
- Contractual framework for providers.
However, the User is informed that no transmission of data via the Internet can be guaranteed to be completely secure.