LEGAL FRAMEWORK

Privacy Policy

Unggul Axiom Group is committed to protecting the privacy and confidentiality of personal information entrusted to us by stakeholders, partners, and institutional counterparties.

Last Updated: June 19, 2026

1. Scope and Application

This Privacy Policy governs the collection, processing, storage, and disclosure of personal information by Unggul Bronto Sdn. Bhd. (Registration No: 202301027920) and its affiliated entities operating under the Unggul Axiom Group platform.

The Group operates as an investment holding company engaged in halal infrastructure development, including halal food production, halal agri-tech, pharmaceuticals, logistics, halal supply chain certification, smart agriculture systems, food security infrastructure, livestock integration, and agri-technology innovation. Additional activities encompass investment holding, venture building, project development, and strategic partnerships within the global halal economy.

This Policy applies to all individuals who interact with the Group, including but not limited to: institutional investors, strategic partners, suppliers, service providers, employees, contractors, and visitors to our digital platforms.

The Group operates in accordance with the Personal Data Protection Act 2010 (Malaysia), applicable international data protection regulations, and industry best practices governing institutional financial services and infrastructure operations.

2. Information We Collect

2.1 Corporate and Institutional Information

We collect corporate identification data, including company registration details, beneficial ownership structures, authorized representative information, corporate governance documentation, financial statements, and regulatory compliance records necessary for institutional due diligence and partnership evaluation.

2.2 Professional Contact Information

Business contact details including names, titles, corporate email addresses, office telephone numbers, and professional correspondence addresses are collected to facilitate institutional communication and partnership management.

2.3 Transaction and Investment Data

For accredited investors and institutional partners, we process investment documentation, transaction records, capital commitment details, distribution information, and related financial data required for investment management and regulatory reporting.

2.4 Technical and Platform Data

Our digital platforms collect standard technical information including IP addresses, browser types, device identifiers, access timestamps, and usage analytics to maintain platform security, optimize performance, and prevent unauthorized access.

3. Legal Basis for Processing

The Group processes personal information on the following legal grounds:

  • - Contractual Necessity: Processing required to execute partnership agreements, investment transactions, and commercial contracts.
  • - Legal Obligation: Compliance with regulatory requirements, anti-money laundering regulations, tax reporting obligations, and corporate governance mandates.
  • - Legitimate Business Interest: Due diligence procedures, risk management, fraud prevention, and operational efficiency improvements.
  • - Explicit Consent: Where specifically obtained for particular processing activities beyond core business operations.

4. Data Usage and Purpose

Personal information is processed exclusively for legitimate business purposes, including:

Partnership evaluation and due diligence procedures; investment transaction processing and management; regulatory compliance and reporting obligations; corporate governance and risk management; communication regarding business operations and strategic initiatives; platform security and fraud prevention; legal proceedings and dispute resolution; and operational analytics for business improvement.

The Group does not engage in consumer marketing activities. All communications are strictly business-to-business and institutional in nature.

5. Information Sharing and Disclosure

5.1 Internal Disclosure

Personal information may be shared among Unggul Axiom Group entities on a need-to-know basis for legitimate business operations, subject to equivalent data protection standards and confidentiality obligations.

5.2 Service Providers

We engage professional service providers including legal counsel, auditors, financial advisors, technology vendors, and administrative service providers. All third-party processors are bound by strict confidentiality agreements and data protection obligations.

5.3 Regulatory and Legal Disclosure

Information may be disclosed to regulatory authorities, government agencies, law enforcement bodies, and judicial institutions where required by law, court order, or regulatory mandate.

5.4 Corporate Transactions

In the event of merger, acquisition, restructuring, or asset transfer, personal information may be disclosed to prospective counterparties under appropriate confidentiality protections.

6. Data Security and Protection

The Group implements institutional-grade security measures to protect personal information against unauthorized access, disclosure, alteration, or destruction.

Security protocols include: encrypted data transmission and storage; multi-factor authentication systems; role-based access controls; regular security audits and penetration testing; incident response procedures; employee confidentiality training; and physical security measures for document storage.

While we maintain rigorous security standards, no system is entirely immune to risk. The Group cannot guarantee absolute security but commits to promptly addressing any identified vulnerabilities or security incidents.

7. Data Retention

Personal information is retained only for as long as necessary to fulfill the purposes for which it was collected, comply with legal and regulatory obligations, resolve disputes, and enforce contractual agreements.

Retention periods vary based on information type and applicable legal requirements. Investment and transaction records are typically retained for a minimum of seven years following transaction completion, in accordance with financial services regulations. Corporate governance documentation is retained for the duration of the business relationship plus applicable statutory periods.

Upon expiration of retention periods, personal information is securely destroyed or anonymized in accordance with data protection standards.

8. Individual Rights

Subject to applicable legal limitations, individuals have the right to:

  • - Access personal information held by the Group
  • - Request correction of inaccurate or incomplete information
  • - Object to processing based on legitimate interests
  • - Request deletion of information where legally permissible
  • - Withdraw consent where processing is consent-based
  • - Lodge complaints with relevant data protection authorities

Requests should be submitted in writing to the contact details provided below. The Group will respond within applicable statutory timeframes, typically 30 days from receipt of a valid request.

9. International Data Transfers

As an infrastructure platform operating within the global halal economy, the Group may transfer personal information across international borders to affiliated entities, service providers, and business partners located in various jurisdictions.

All international transfers are conducted in accordance with applicable data protection laws and are subject to appropriate safeguards, including standard contractual clauses, adequacy decisions, or other legally recognized transfer mechanisms.

Recipients of transferred data are contractually obligated to maintain equivalent data protection standards and comply with applicable privacy regulations.

10. Policy Updates

This Privacy Policy may be updated periodically to reflect changes in legal requirements, business operations, or data protection practices. Material changes will be communicated to affected parties through appropriate channels.

The "Last Updated" date at the top of this Policy indicates the most recent revision. Continued engagement with the Group following policy updates constitutes acceptance of the revised terms.

11. Contact Information

For privacy-related inquiries, requests to exercise individual rights, or concerns regarding data protection practices, please contact:

Data Protection Officer

Unggul Bronto Sdn. Bhd.

Kuala Lumpur, Malaysia

Email: privacy@unggulaxiom.com

The Group is committed to addressing privacy concerns promptly and transparently. All inquiries will receive a response within reasonable timeframes in accordance with applicable legal requirements.