Legal & disclosures.
The documents this website publishes, in full.
Privacy Policy
How OneAsset collects, uses, stores and protects personal data.
1INTRODUCTION AND WHO WE ARE
OneAsset FZCO (OneAsset, the Company, we, us or our) is a company established in the Dubai Multi Commodities Centre free zone in Dubai, United Arab Emirates. We operate a platform for the tokenisation of real-world assets (the Platform).
The Company has applied for the licenses to operate as a virtual asset service provider with the Dubai Virtual Asset Regulatory Authority (“VARA”) and those applications are currently under review and pending VARA’s approval.
This privacy policy (this Policy) describes how the Company collects, uses, discloses, stores and otherwise processes personal data, also referred to as personal information, being any information relating to an identified or identifiable person (Personal Data, and the individual to whom it relates, a Data Subject), and it explains the rights available to you in respect of your Personal Data.
This Policy applies to the Personal Data we process through our website, our Platform and the products and services we provide, and during our dealings with website visitors, applicants, clients and the individuals connected with our corporate clients and business partners.
This Policy forms part of, and should be read together with, the other policies and terms that apply to your use of our website, our Platform and our services, including our Platform Risk Disclaimer, each as amended or updated from time to time.
This Policy applies to Personal Data that we process in connection with public content, searches, investigations, restrictions and enforcement actions. Information made publicly available through the Platform may also be visible to other users and may be copied or used by them independently of OneAsset.
This Policy governs the Personal Data of our website visitors, applicants, clients and business contacts, investors, distribution partners, property managers and their representatives, beneficial owners and authorised signatories, individuals connected with our corporate clients and business partners. The Personal Data of our personnel and job applicants is dealt with separately in our internal privacy notices.
We use Personal Data to operate accounts, verify users, comply with applicable regulations, offer a secure Platform, process and record transactions, communicate with users. Some part of the Platform activity is recorded on the blockchain. The blockchain records are permanent and cannot be modified, altered or deleted.
Any question relating to this Policy, or any request to exercise the rights described in paragraph 12, should be addressed in writing to our Data Protection Officer at [email protected], using the subject line “Data Protection Inquiry” together with a reference code where one is available.
2OUR DATA PROTECTION PRINCIPLES
We are committed to protecting your Personal Data wherever you are located. The data protection law that applies to our processing of your Personal Data depends on your jurisdiction: where you are located in the United Arab Emirates, United Arab Emirates data protection law applies; where you are located in the European Economic Area or the United Kingdom, the data protection law of that jurisdiction applies; and, more generally, we comply with the data protection law applicable to you in each relevant jurisdiction. Whichever law applies, we process Personal Data in accordance with the following principles, which are reflected throughout this Policy:
lawfulness, fairness and transparency: we process Personal Data lawfully and fairly, only where we have a valid legal basis for doing so, and we are transparent with you about how, and the purposes for which, we process it;
purpose limitation: we collect Personal Data for specified, explicit and legitimate purposes, and we do not further process it in a manner that is incompatible with those purposes;
data minimisation: we collect and process only the Personal Data that is adequate, relevant and limited to what is necessary for the purposes for which it is processed;
accuracy: we take reasonable steps to ensure that Personal Data is accurate and, where necessary, kept up to date, and to correct or delete inaccurate Personal Data without undue delay;
storage limitation: we retain Personal Data in a form that permits your identification only for as long as is necessary for the purposes for which it is processed (see paragraph 9);
integrity and confidentiality: we process Personal Data in a manner that ensures its appropriate security, including its confidentiality, integrity and availability, and its protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical and organisational measures (see paragraph 10);
proportionality and necessity: where we rely on a legal basis other than your consent, we process Personal Data only to the extent necessary and proportionate to the purpose concerned; and
accountability: we take responsibility for our processing of Personal Data, and we maintain the policies, records and governance necessary to demonstrate our compliance with these principles.
3THE PERSONAL DATA WE COLLECT
We collect and process Personal Data from a number of sources, namely Personal Data that you provide to us directly, Personal Data that we collect automatically through your use of our website and Platform, and Personal Data that we obtain from third parties and publicly available sources (such as business partners, service providers, analytics providers and public registers), in each case to the extent permitted under applicable law. The categories of Personal Data we process, and a description of each, are set out below.
Identity and verification data. Your full name, date of birth, gender, nationality, government-issued identification and the documents and information required to verify your identity and to satisfy our know-your-customer, due diligence and eligibility obligations.
Contact data. Your email address, telephone number and postal address, which we use to communicate with you and to provide notifications relating to our services.
Financial and transaction data. Your bank account and payment details, your source of funds and source of wealth, your wallet addresses, and your holdings, balances and transaction history on the Platform, including your token and USDC balances, blockchain events and, where required for regulatory purposes, payout and commission records, which we process to operate your account and to effect and record transactions.
Background and screening data. Information relevant to our risk-based due diligence, such as your employment or occupation, your source-of-wealth profile, whether you are a politically exposed person or otherwise politically exposed, and the results of the sanctions, politically-exposed-person and adverse-media screening that we carry out on you and, in the case of corporate clients, on their beneficial owners.
Special category data. Biometric data and other special categories of Personal Data, which we collect only where legally necessary, for example in connection with identity verification, and which we safeguard with appropriate additional measures.
Communications data. Records of your correspondence and communications with us, including customer-support enquiries and responses to surveys, which we retain for the purposes of managing our relationship with you, resolving queries and disputes, and demonstrating our regulatory compliance.
Technical and usage data. Your internet protocol (IP) address, device and browser type, unique device identifiers, approximate location (for example, country or city), login information and details of your interactions with our website and Platform, which we collect through cookies and similar technologies (see paragraphs 5 and 7).
Corporate client data. In respect of our corporate clients and partners: registered name, registration particulars, legal form and jurisdiction, beneficial ownership and control information, and related regulatory and compliance documentation, together with the identity and contact details of connected individuals.
Property Manager, partner and business information. This may include corporate registration information, licences, ownership and control information, proof of authority, professional and financial contacts, supporting documents, referral attribution, commission information, and records relating to properties, SPVs or reports administered through the Platform.
Where we request Personal Data from you, we will indicate whether the provision of that Personal Data is mandatory and the consequences of any failure to provide it. Where you do not provide Personal Data that we require in order to verify your identity, to satisfy our legal and regulatory obligations, or to provide our services, we may be unable to open or maintain your account or to permit you to transact.
4THE PURPOSES FOR WHICH WE PROCESS PERSONAL DATA, AND OUR LEGAL BASIS
We process your Personal Data only for specified purposes and only where we have a lawful basis for doing so. The lawful bases available to us differ according to the data protection regime that applies to you. We process your Personal Data for the following purposes, on the legal bases described:
Communicating with you. We process your identity and contact data to respond to your enquiries and to communicate with you. The legal basis is your consent and, where applicable, the taking of steps at your request prior to entering into a contract.
Identity verification and financial-crime compliance. We process your identity, verification, background and screening data to verify your identity and to carry out know-your-customer, anti-money-laundering, sanctions-screening and related due diligence, including by cross-referencing your Personal Data with third-party and public data sources. The legal basis is compliance with a legal obligation.
Providing our services. We process your account, financial and transaction data to establish, operate and administer your account and to provide our services to you. The legal basis is the performance of our contract with you.
Operating and improving our website and Platform. We process your technical and usage data to operate, secure, maintain and improve our website and Platform. The legal basis is your consent, in respect of non-essential cookies, and, under the European Economic Area or United Kingdom regime, our legitimate interests in maintaining a secure and functional service.
Risk, fraud and security. We process your Personal Data to assess and score risk, to monitor for and detect fraud, market abuse, money laundering and security threats, and to maintain records. The legal basis is compliance with a legal obligation and, under the European Economic Area or United Kingdom regime, our legitimate interests.
Legal and regulatory compliance. We process your Personal Data to comply with our legal and regulatory obligations, to respond to lawful requests from public authorities and our regulator, and to establish, exercise or defend legal claims. The legal basis is compliance with a legal obligation and another ground permitted under applicable law.
Marketing. Where you have requested them, we process your identity and contact data to send you marketing communications concerning OneAsset. The legal basis is your consent.
Where we rely upon your consent, you may withdraw that consent at any time, and any such withdrawal will not affect the lawfulness of processing carried out prior to the withdrawal. You have an absolute right to require us to cease processing your Personal Data for the purposes of direct marketing, which we will give effect to without undue delay and at no cost to you (see paragraph 12).
5COOKIES AND SIMILAR TECHNOLOGIES
We use cookies and similar technologies on our website and Platform in order to enable core functionality, to maintain security, to remember your preferences, to conduct analytics and to improve our services. Such technologies may be strictly necessary, functional, analytical or performance related.
Non-essential cookies, including analytics cookies, are deployed only with your consent, which you may give or withdraw at any time, whether through your browser settings or, where available, our cookie preference tool. Restricting strictly necessary cookies may impair the operation of certain features.
Some browsers offer a “Do Not Track” setting. As there is at present no common industry standard for how such signals should be interpreted, we respond to them in accordance with our cookie settings and applicable law.
6DISCLOSURE OF PERSONAL DATA AND OUR USE OF SERVICE PROVIDERS
We engage third-party service providers to perform certain functions on our behalf, and we disclose Personal Data to them strictly on a need-to-know basis and for legitimate business, contractual and regulatory purposes.
Such providers act solely on our documented instructions, under written contracts that require them to protect the Personal Data disclosed to them, to process it only for the purposes we specify, and that provide for due diligence, confidentiality, security, audit rights and the regulatory access described in paragraph 8. We disclose Personal Data to the following categories of recipient:
Identity-verification and compliance providers. We use specialist third-party providers to carry out identity verification and know-your-customer, screening and due diligence checks. These checks are performed by our third-party verification provider.
Other service providers and Group companies. Providers of hosting, information technology, security, communications and analytics services, and members of our corporate group, in each case where necessary for the purposes described in this Policy.
Professional advisers. Our legal, accounting, audit and other professional advisers, where necessary and subject to duties of confidentiality.
Regulators, authorities and law enforcement. VARA and other regulatory and supervisory authorities, courts, law enforcement agencies and other public bodies, where we are required or permitted by applicable law to make such disclosure, or where it is necessary in order to protect our rights or to prevent or detect unlawful activity.
We may also disclose Personal Data in connection with a corporate transaction, such as a reorganisation, merger or transfer of our business or assets, subject to appropriate confidentiality protections. We remain accountable for the protection of your Personal Data notwithstanding any such engagement of a service provider. We do not sell your Personal Data, and we do not provide your Personal Data to third parties for their own marketing purposes.
7THIRD-PARTY TECHNOLOGIES AND SERVICE PROVIDERS
To provide, secure, operate and improve our website, our Platform and our services, we engage a number of third-party service providers, and we may incorporate technologies provided by third parties, including software development kits (SDKs) and similar technologies. Depending on the services we use from time to time, these providers may include, among others, providers of identity verification and screening, hosting and cloud infrastructure, data storage, information security, fraud prevention, payment processing, analytics, attribution, communications and customer support.
Such third parties may collect or process Personal Data on our behalf, or in certain cases as controllers in their own right, in accordance with their own privacy policies and applicable law. Where they process Personal Data on our behalf, they act on our documented instructions under written contracts requiring them to protect the Personal Data and to use it only for the purposes we specify, consistent with paragraph 6.
The third parties we engage, and the technologies we use, may change from time to time as our services evolve.
8INTERNATIONAL TRANSFERS, STORAGE AND REGULATORY ACCESS
We, and the service providers who process Personal Data on our behalf, may store and process Personal Data both within and outside the United Arab Emirates. Certain of our providers, including our verification provider referred to in paragraph 6, may process Personal Data outside the United Arab Emirates. Where we transfer Personal Data outside the United Arab Emirates, we do so only where permitted under applicable law. We apply further safeguards including access controls, encryption, data minimisation and the due diligence of recipients.
Irrespective of where Personal Data is stored, and of the format or medium in which it is held, we maintain arrangements, including appropriate contractual and technical measures, designed to ensure that our regulator is able to access Personal Data relevant to our regulatory compliance.
9RETENTION OF PERSONAL DATA
We retain Personal Data only for so long as is necessary for the purposes for which it was collected, and in order to satisfy our legal, regulatory and record-keeping obligations, including the minimum retention periods required by applicable law and by our regulator, and to establish, exercise or defend legal claims.
Unless a longer period is required or permitted by applicable law, we retain Personal Data for the baseline period specified in our records-retention arrangements, following which it is securely deleted, destroyed or irreversibly anonymised.
10SECURITY AND STORAGE OF PERSONAL DATA
We maintain a documented programme of technical and organisational measures designed to protect the confidentiality, integrity and availability of Personal Data, and to protect it against accidental or unlawful loss, alteration, and unauthorised access, use or disclosure, having regard to the nature of the Personal Data and the risks associated with its processing.
These measures include the classification of information according to its sensitivity, access controls administered on a need-to-know and role-based basis, the encryption of Personal Data in transit and, where appropriate, at rest, secure authentication, network security, logging and monitoring, regular testing and review, and the imposition of confidentiality obligations and training upon our personnel.
No system or method of storage can be guaranteed to be entirely secure. Whilst we cannot warrant that Personal Data will be protected against every possible threat, we implement measures designed to reduce the associated risks to a level that is reasonable and appropriate. If you become aware of any security vulnerability affecting our website or Platform, or you suspect that your account or Personal Data has been compromised, please notify us promptly at [email protected] so that we may take appropriate action.
In the event of a personal data breach that is likely to give rise to a risk to your rights, we will notify the competent authority and, where required, affected Data Subjects, within the periods and in the manner required by applicable law. In addition, where we notify a data-protection authority or an affected Data Subject of an incident affecting Personal Data, we will notify our regulator within twenty-four (24) hours, providing a summary and, where the relevant authority is in the United Arab Emirates, a copy of the report, unless prohibited by applicable law.
11AUTOMATED DECISION-MAKING AND PROFILING
In operating the Platform and meeting our regulatory obligations, we may carry out automated processing of Personal Data, including profiling. For example, we may use automated processing to assess and score risk, to screen for and detect fraud, money laundering and sanctions concerns, and to assess eligibility.
Where we make a decision about you based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you, we do so only where permitted by applicable law, for example where it is necessary for entering into or performing a contract with you, where it is required or authorised by law, or where you have given your explicit consent.
In such cases, and where applicable law so provides, you may object to the decision, and you may request that a member of our personnel reviews it, express your point of view and contest it. We apply appropriate measures to safeguard your rights, freedoms and legitimate interests throughout.
Where we use artificial-intelligence or machine-learning tools to support these or other functions, any output of such tools is used only for the purposes described in this Policy, and such tools support, rather than replace, human oversight where applicable law so requires.
12YOUR RIGHTS
Subject to the conditions and exceptions provided for under applicable law, you are entitled, as a Data Subject, to exercise the following rights in respect of your Personal Data:
the right of access: to obtain confirmation as to whether we process your Personal Data and, where we do, a copy of that Personal Data and information as to how it is processed;
the right to rectification: to have inaccurate Personal Data corrected and incomplete Personal Data completed without undue delay;
the right to erasure: to require the deletion of your Personal Data where it is no longer necessary, where you have withdrawn your consent and no other basis applies, or where the processing is unlawful, subject to any grounds upon which we are required or entitled to retain it;
the right to restriction: to require us to restrict the processing of your Personal Data in certain circumstances, for example whilst its accuracy is verified;
the right to object: to object to certain processing of your Personal Data, including an absolute right to object to its use for the purposes of direct marketing;
the right to data portability: where applicable, to receive certain Personal Data in a portable format or to have it transmitted to another party;
rights in relation to automated decision-making: as described in paragraph 11; and
the right to withdraw consent: where our processing is based upon your consent, to withdraw that consent at any time, without affecting the lawfulness of processing carried out prior to the withdrawal.
To exercise any of these rights, please contact our Data Protection Officer at [email protected]. We may require you to verify your identity before we give effect to your request, and we will respond within the period required by applicable law. Where permitted by applicable law, we may decline or limit a request, or charge a reasonable fee, where it is manifestly unfounded or excessive, or where compliance would adversely affect the rights of another person or our ability to comply with a legal or regulatory obligation, and we will explain the basis for any such refusal or limitation.
Should you consider that we have not handled your Personal Data in accordance with applicable law, you are entitled to lodge a complaint with the UAE Data Office, the supervisory authority for data protection in the United Arab Emirates. Where the data protection law of the European Economic Area or the United Kingdom applies to you, you may instead complain to your local supervisory authority or, in the United Kingdom, to the Information Commissioner’s Office. We would, however, welcome the opportunity to address your concerns in the first instance.
13CHILDREN
Our website, Platform and services are intended for persons who have attained the age of eighteen (18) years, and we do not knowingly collect Personal Data relating to any person below that age. Should we become aware that we have collected Personal Data relating to a minor, we will take steps to delete it, save where we are required to retain it under applicable law. If you believe that a minor has provided us with Personal Data, please contact us at [email protected].
14THIRD-PARTY WEBSITES AND LINKS
Our website and Platform may contain links to websites, platforms or resources operated by third parties. We do not control such third parties and are not responsible for their privacy or security practices, and this Policy does not apply to them. Upon leaving our website or Platform, you become subject to the privacy notices and terms of the relevant third party, and we would encourage you to review those notices before providing any Personal Data.
15HOW TO CONTACT US
All questions, concerns and requests relating to this Policy or to our processing of Personal Data should be addressed, in writing, to our Data Protection Officer:
Recipient: The Data Protection Officer. Email: [email protected]. Subject line: “Data Protection Inquiry”, together with a reference code where applicable.
16BLOCKCHAIN RECORDS
Certain information relating to transactions on the Platform may be recorded on a blockchain. Information written to a blockchain is, by its nature, generally incapable of being altered or deleted. We minimise the Personal Data written to a blockchain and, wherever practicable, hold Personal Data off-chain with only a reference recorded on-chain. Where we are unable to delete blockchain data in response to a request for erasure, we will explain this to you and will take such steps as are available to us, including severing the links between blockchain data and the Personal Data by which you are identified that we hold off-chain.
17NATURE OF VIRTUAL ASSETS AND RISK
This Policy concerns the processing of your Personal Data. It is not a solicitation or an offer, and it does not constitute financial, investment, legal or tax advice.
Dealing in virtual assets, including tokenised and other digital assets, involves significant risk. The value of such assets can be volatile, and you may lose some or all of the amount that you commit. You should ensure that you understand the nature of the products and transactions available through the Platform, and the risks involved, before you proceed.
Full details of these risks are set out in our Platform Risk Disclaimer, which is available on our website and which you should read carefully before using the Platform.
18CHANGES TO THIS POLICY
We may amend this Policy from time to time to reflect changes in our practices, our services or applicable law, and we review it at least annually. Where we make a material amendment, we will update the “Last updated” date set out above and, where appropriate, bring the amendment to your attention through our website or other channels. Your continued use of our website, Platform and services following any such amendment constitutes your acknowledgement of the amended Policy. We would encourage you to review this Policy periodically.
Risk Disclaimers
The material risks of acquiring, holding and transferring ARVAs.
PLATFORM RISK DISCLAIMER
Version No. 1 Last updated: 8 September 2026
1ABOUT THIS RISK DISCLAIMER
1.1Please read this Risk Disclaimer carefully. OneAsset FZCO (OneAsset or the Company) issues and makes available Asset-Referenced Virtual Assets (ARVAs): digital assets whose value is linked to the economic performance of underlying real estate assets. This Risk Disclaimer describes the material risks of acquiring, holding and transferring ARVAs through the Company's platform (the Platform).
1.2This Risk Disclaimer forms part of the contractual documentation governing your access to and use of the Platform, together with the Company's Terms and Conditions and its Client Agreement. By accessing or using the Platform, or by applying for, acquiring, holding or transferring ARVAs, you acknowledge that you have read, understood and agree to this Risk Disclaimer. In the event of any conflict between this Risk Disclaimer and the Client Agreement in respect of the matters they each address, the Client Agreement prevails.
1.3Words and expressions defined in the Client Agreement or the Terms and Conditions have the same meaning when used in this Risk Disclaimer, unless otherwise defined here.
1.4This Risk Disclaimer provides a general description of the risks associated with ARVAs. It does not describe every possible risk, and it does not take account of your personal circumstances, financial situation or objectives. You should read it in full, together with the Company's other ARVA documentation, before making any decision in relation to ARVAs. If you do not understand any part of it, or the risks it describes, you should obtain independent professional advice before proceeding.
2REGULATORY STATUS
2.1OneAsset is registered with the Dubai Multi Commodities Centre (the DMCC) and has applied for licenses with Dubai’s Virtual Asset Regulatory Authority (‘VARA’), which are under review and pending for VARA’s approval.
2.2Neither the grant of any licence nor the issuance of ARVAs constitutes an endorsement, approval or recommendation by VARA or any other governmental or regulatory authority. Authorisation relates to the conduct of the Company's activities and does not mean that any ARVA is a safe or suitable investment, or that the risks described in this Risk Disclaimer are reduced or removed.
3NO OFFER, NO SOLICITATION AND NO ADVICE
3.1This Risk Disclaimer is provided for information only. It does not constitute, and must not be relied upon as, an offer, invitation, inducement or solicitation to buy, subscribe for, sell or deal in any ARVA or any other virtual asset in any jurisdiction in which such an offer or solicitation would be unlawful.
3.2Nothing in this Risk Disclaimer constitutes financial, investment, legal, tax, accounting or other professional advice, and it does not take account of any person's particular circumstances or objectives. Prospective investors should obtain their own independent financial, legal and tax advice before making any decision in relation to ARVAs.
4WHAT ARE ARVA TOKENS?
4.1The economic value of ARVAs is linked to underlying real estate assets held through a legally structured SPV. ARVAs represent a digital entitlement to economic interests linked to the performance of those assets through the SPV structure.
4.2Acquiring or holding ARVAs does not confer direct legal or beneficial ownership of the underlying real estate assets, of the SPV, or of any share in the SPV. An investor's rights are the contractual and economic rights described in the Company's ARVA documentation, and not the rights of a direct property owner.
4.3The value, transferability and legal status of ARVAs may be affected by circumstances beyond the Company's control, including fluctuations in market conditions, changes in law or regulation, technological developments and shifts within the real estate sector.
5RISK FACTORS
5.1The risk factors described below may manifest independently or concurrently. The occurrence of one or more risks may exacerbate others, resulting in a cumulative adverse impact that could materially impair the valuation, liquidity or transferability of ARVAs. The Company has identified and described the risk factors it considers material, but this Risk Disclaimer does not purport to list every possible risk. Additional risks, including those not currently known or presently considered immaterial, may also exist and may affect ARVAs.
5.2Virtual Asset Market Risk. Virtual asset markets are inherently volatile and subject to rapid and sometimes unpredictable price fluctuations. The value of ARVAs may be affected by speculative trading activity, technological innovation or disruption, macroeconomic developments, regulatory announcements and cybersecurity incidents affecting market participants. These factors, individually or in combination, can lead to significant and sudden changes in the value of ARVAs.
5.3Capital Loss Risk. ARVAs are speculative and there can be no assurance of capital preservation. The value of ARVAs may decline significantly and an investor could lose part or all the capital invested. ARVAs are not bank deposits, government-backed financial instruments or insured assets, and do not benefit from any guarantee or protection against loss.
5.4Real Estate Market Risk. The value of ARVAs is closely linked to the performance of the underlying real estate assets, which are subject to market and operational risks. Macroeconomic factors such as inflation, employment and general economic conditions may influence property values; changes in interest rates may affect financing costs and valuations; and property values may be affected by oversupply, regulatory or zoning changes or economic downturns. Operational risks may arise from tenant defaults, maintenance costs or inefficiencies in property management.
5.5Valuation Risk. Real estate valuations involve inherent uncertainties and rely on professional judgment, assumptions and established methodologies, and may vary between independent valuers. There can be no assurance that any valuation will fully reflect the value that could be realised on a sale of the underlying property. Valuations are typically periodic and may not reflect real-time changes in market conditions, so the value attributed to ARVAs may not always correspond to short-term movements in the value of the underlying assets.
5.6Liquidity and Redemption Risk. There may be no active or liquid market for ARVAs. ARVAs may be tradable only within, and subject to the rules of, the Platform, and there is no assurance that any secondary market will develop or be maintained, or that an investor will be able to sell or otherwise realise value from ARVAs at any particular time, at a particular price, or at all. Investors should be prepared to hold ARVAs for an indefinite period and should not acquire ARVAs on the basis of any expected exit or liquidity.
ARVAs are high-risk virtual assets. ARVAs may lose their value in part or in full and are subject to extreme volatility. You may lose all of the money or other value you invest, and you will not benefit from any form of financial protection, compensation scheme or deposit guarantee in respect of ARVAs. ARVAs may not be liquid, may not always be transferable, and some transfers may be irreversible. ARVAs are recorded on a public blockchain and are not private. ARVAs may be subject to fraud, manipulation, theft (including through cyber-attacks) and other schemes, and may not benefit from the legal protections that apply to regulated traditional financial instruments. ARVAs are suitable only for persons who understand these risks and are able to bear the loss of their entire investment.
5.7Investment-Related Risk. ARVAs do not provide guaranteed income, dividends or capital appreciation, and past performance should not be treated as indicative of future results. Investors may face constraints when exiting positions due to limited trading venues, Platform restrictions or lock-up periods, which may affect liquidity and the timing of realisable returns. ARVAs are linked to specific real estate assets, and concentration in particular assets may increase exposure to asset-specific risks. The performance, solvency and conduct of service providers involved in the ARVA ecosystem may also materially affect the value or operability of the investment.
5.8Structural and SPV Risk. The underlying real estate assets are held through an SPV intended to ring-fence those assets from the general liabilities of the Company. While the SPV structure is intended to mitigate certain risks, it cannot eliminate all legal or structural uncertainties. Risks may arise from legal disputes affecting SPV ownership or contractual arrangements, governance or management issues within the SPV, insolvency or operational disruption, or disagreements with service providers. Such events could materially affect the economic interests associated with ARVAs and the ability of investors to realise returns in accordance with the intended structure.
5.9Regulatory and Legal Risk. The regulatory and legal environment for ARVAs is evolving and may change over time. Changes in laws, regulations or guidance issued by VARA or other authorities may affect the legality of ARVA transactions, the eligibility of investors, trading and transferability, and taxation. Such changes, individually or collectively, could materially affect the value, liquidity, transferability or overall usability of ARVAs, and compliance with new requirements may impose additional obligations or restrictions that affect the timing or execution of transactions and distributions.
5.10Custody and Wallet Risk. OneAsset provides each verified investor with an individual, Platform-provisioned non-custodial embedded wallet through its third-party wallet-infrastructure provider. Investors cannot connect an external wallet, and each investor is the primary controller of their own wallet and the transactions it authorises. OneAsset does not hold or reconstruct investor private keys and does not have the unilateral ability to move investor-held ARVAs. Investors remain responsible for safeguarding their authentication and recovery credentials. Loss of access to those credentials, or compromise of a wallet, may result in the permanent loss of access to the associated ARVAs, and the recovery mechanisms available may not restore access in every case. ARVAs also depend on a third-party wallet and key-management provider, and the performance, security or failure of that provider is a risk beyond the investor's control. Separately, and as described under paragraph 5.11, the Platform's governance controls permit ARVA transfers to be suspended and, through a governed multi-party process, permit ARVAs to be recovered from inaccessible wallets in defined circumstances.
5.11Transferability and Enforcement Risk. ARVAs are subject to transfer restrictions enforced at the infrastructure level, including eligibility and whitelisting controls, so that ARVAs may only be transferred to persons who satisfy the Company's onboarding and compliance requirements. The Company's governance controls further permit ARVA transfers and marketplace operations to be suspended, and permit ARVAs to be frozen or, through a governed multi-party process, to be recovered from or reissued in respect of inaccessible or non-compliant wallets, in defined circumstances and in accordance with Platform rules, legal requirements and regulatory obligations. The exercise of these controls may prevent, delay or reverse a transfer, or restrict an investor's ability to deal in or access their ARVAs. In addition, a transaction recorded on a blockchain is generally irreversible once confirmed, and a transfer made in error may not be capable of being undone.
5.12Technology and Smart Contract Risk. ARVAs rely on digital infrastructure and automated mechanisms, including smart contract or similar programmable logic, to support the issuance and lifecycle management of the tokens. Such technologies may expose ARVAs to coding vulnerabilities, software errors, system malfunctions, protocol changes or other technical disruptions. Any failure, error or exploitation of these components could adversely affect the functioning, availability or integrity of ARVAs. Although testing, governance and technical controls may be implemented, technological risks associated with digital token infrastructure cannot be completely eliminated.
5.13Cybersecurity Risk. ARVAs and related systems may be exposed to cybersecurity threats, including hacking, phishing, malware and distributed denial-of-service attacks. Such incidents could disrupt operations, compromise the integrity of transactions or result in the permanent loss of ARVAs. No system is completely immune to cyber risk, and the security of digital assets depends in part on both the Company's measures and the investor's own practices.
5.14On-chain Transparency and Limited Privacy Risk. ARVAs are issued and recorded on a public, distributed ledger. Wallet addresses, balances and transaction histories are publicly visible and are not private, and a wallet address that can be linked to an identified investor may constitute personal data. Information written to a public blockchain generally cannot be altered or deleted, which may limit the extent to which certain data can be corrected or erased. Investors should consider these transparency and data-related characteristics before acquiring ARVAs.
5.15Fraud, Market Manipulation and Theft Risk. Virtual assets, and the systems and markets in which they are held and traded, may be subject to fraud, market manipulation, theft and other targeted schemes, including through cyber-attacks, phishing and social engineering. Investors may not benefit from the legal protections that apply to regulated traditional financial instruments, and losses arising from such events may not be recoverable.
5.16Operational Risk. Operational risks may arise from failures or deficiencies in internal systems, processes or personnel, including administrative errors, operational disruptions or governance failures, any of which could adversely affect the issuance and management of ARVAs. The Company's risk-mitigation measures cannot eliminate all such risks.
5.17Key Person Risk. The operation and management of ARVAs depend on the expertise and continued involvement of certain key individuals within the Company or the SPV. The loss, departure or incapacity of such persons could materially affect the performance of the underlying assets, the operation of the Platform or the functioning and value of ARVAs.
5.18Third-Party Risk. The management, custody and operation of ARVAs involve third-party service providers. The failure, insolvency, misconduct or underperformance of any such third party could materially and adversely affect the value, liquidity or operational integrity of ARVAs. Reliance on external parties introduces risks that are beyond the Company's control.
5.19System Failure Risk. The operation of ARVAs relies on technological systems, including the Platform and supporting blockchain infrastructure. Failures or interruptions arising from technical issues, software errors, cyber-attacks or other operational problems may disrupt the issuance, transfer or management of ARVAs and could result in financial loss or loss of access to tokens. No technological system is entirely immune to failure, and such events may materially affect the usability and value of ARVAs.
5.20Limited Acceptance Risk. ARVAs may be tradable exclusively within the Platform ecosystem, and there is no assurance that they will be accepted, recognised or tradable outside that environment. This limitation may affect the marketability of ARVAs, and investors may encounter challenges in exiting positions or realising value outside the Platform.
5.21Force Majeure Risk. The performance and value of ARVAs may be affected by extraordinary events beyond the Company's control, including natural disasters, geopolitical conflicts, pandemics or systemic financial crises. Such events may disrupt the operation of the Platform, affect the underlying real estate assets, or otherwise materially affect the value, liquidity and transferability of ARVAs.
5.22Taxation Risk. The tax treatment of acquiring, holding, transferring or realising ARVAs, and of any distributions in respect of them, is uncertain, may differ between jurisdictions and may change, including with retrospective effect. The Company does not provide tax advice. Each investor is responsible for their own tax position and should obtain independent tax advice before acquiring ARVAs.
6ELIGIBILITY AND ACCESS
6.1ARVAs are made available only to investors who have been accepted through the Company's onboarding process, who satisfy the Company's eligibility and applicable investor-classification requirements, and who have passed the Company's identity verification, sanctions screening and anti-money-laundering checks.
6.2ARVAs are not offered to, and may not be acquired by, any person in any jurisdiction where the offer, holding or transfer of ARVAs would be unlawful or would require a registration or licence that OneAsset does not hold, and are not available to sanctioned or otherwise restricted persons. It is each investor's responsibility to ensure that their acquisition and holding of ARVAs is lawful in their jurisdiction.
7SUITABILITY AND YOUR RESPONSIBILITY
7.1ARVAs are intended only for investors who understand the risks associated with virtual assets and blockchain technology, are familiar with the dynamics of the real estate market and have the financial capacity to bear substantial losses. ARVAs are not suitable for persons seeking guaranteed returns, capital protection or short-term liquidity.
7.2Prospective investors should carefully assess their own financial situation, investment objectives and risk tolerance, read this Risk Disclaimer and the Company's other ARVA documentation in full, and obtain independent professional advice where appropriate, before acquiring ARVAs. No investment should be made in ARVAs without a full understanding of the risks described in this Risk Disclaimer and of the economic structure of the underlying assets.
8CONFLICTS OF INTEREST
8.1Investors may be exposed to conflicts of interest arising from the activities of the Company, its subsidiaries and officers (together, Related Parties), as well as from the actions or holdings of other investors. Such conflicts may arise in a number of ways, including:
(a) fee arrangements or proprietary holdings of Related Parties that may influence decisions affecting ARVA performance or allocation;
(b) the selection, acquisition or management of underlying real estate assets held through SPVs;
(c) the appointment or oversight of service providers such as valuers, auditors, property managers or other vendors;
(d) the timing, priority or terms of any redemptions or other investor allocations;
(e) governance, cashflow or structural decisions within an SPV that could benefit Related Parties;
(f) concentrated holdings or influence by individual investors or groups of investors, including those connected to the Company or service providers, which could affect decision-making or perceived fairness; and
(g) voting or consent rights granted to investors that may be exercised in a way that advantages certain investors over others.
8.2These conflicts could affect the value, liquidity or fairness of ARVAs if not appropriately managed. To mitigate them, the Company maintains a governance framework, including policies, reporting protocols, oversight mechanisms and due-diligence procedures.
9FORWARD-LOOKING STATEMENTS
9.1This Risk Disclaimer may contain statements that are forward-looking, including as to the intended structure, operation and performance of ARVAs and the underlying assets. Forward-looking statements are subject to known and unknown risks and uncertainties, are not guarantees of future performance, and actual outcomes may differ materially. The Company does not undertake to update any forward-looking statement except as required by applicable law.
10CHANGES TO THIS RISK DISCLAIMER
10.1The Company may amend this Risk Disclaimer from time to time. The version in force is the version published or provided by the Company at the relevant time, and each version is identified by the version number and date shown on it. Last updated: [date].
11COMPLAINTS AND CONTACT
11.1Any questions about this Risk Disclaimer, and any complaint, may be raised with the Company at [email protected]. Complaints are handled in accordance with the Company's Complaints Handling Policy.
12YOUR ACKNOWLEDGEMENT
By acquiring ARVAs, you confirm that you have carefully read, understood and considered this Risk Disclaimer in its entirety. You acknowledge that ARVAs are speculative, digital and real estate-backed instruments whose value may fluctuate significantly and that there is a risk of partial or total loss of the capital invested. You understand that the performance, liquidity, transferability and legal treatment of ARVAs may be affected by factors beyond the Company's control, including the performance of the underlying property, blockchain technology and smart contract functionality, market conditions, regulatory developments, third-party service providers, and extraordinary events. You confirm that you have made your investment decision independently, based on your own assessment and due diligence and, where appropriate, after seeking professional advice, and that you voluntarily accept all associated risks and that the investment aligns with your financial capacity, risk tolerance and investment objectives.
Privacy enquiries
For questions about this Privacy Policy or the handling of personal data, please contact OneAsset.
