HALPOPTECH ("we," "us," or "our") is committed to protecting the privacy and personal data of our users in accordance with the Saudi Personal Data Protection Law (PDPL), issued by Royal Decree No. M/19, and its Implementing Regulations. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our SaaS platform (the "Service").
1. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person, directly or indirectly.
- Sensitive Personal Data: Data revealing race, ethnicity, political or philosophical opinions, religious beliefs, health, genetic data, or criminal records. We do not collect Sensitive Personal Data unless explicitly permitted by law.
- Data Subject: The natural person to whom the Personal Data relates.
- SDAIA: The Saudi Data and Artificial Intelligence Authority, the competent supervisory authority.
2. Data We Collect
We collect only the Personal Data necessary to provide and improve our SaaS services:
- Account Data: Name, email address, phone number, company name, and billing address.
- Payment Data: Credit card numbers or bank details (processed securely by our PCI-DSS compliant third-party payment processors; we do not store raw card data).
- Technical Data: IP address, device type, operating system, browser type, and unique device identifiers.
- Usage Data: Log-in times, features used, click patterns, and interaction data within the platform.
3. Legal Basis for Processing (PDPL Compliance)
Under the PDPL, we process your data only when legally permitted, including:
- Consent: Where you have given clear, explicit consent (e.g., for marketing emails).
- Contractual Necessity: To perform our contract with you, provide the SaaS platform, and maintain your account.
- Legal Obligation: To comply with applicable laws, regulations, or legal processes in the KSA.
- Legitimate Interests: For fraud prevention, network security, and internal analytics, provided it does not override your privacy rights.
4. Data Sharing and Third-Party Processors
We do not sell your Personal Data. We share data only with:
- Service Providers (Processors): Third parties that process data on our behalf (e.g., cloud hosting providers, email services, analytics tools). All processors are bound by Data Processing Agreements (DPAs) that mandate PDPL-level protection.
- Legal Authorities: If required by KSA law, court order, or governmental authority.
5. International Data Transfers
Your data is primarily stored within the Kingdom of Saudi Arabia. If it is necessary to transfer your data outside the KSA (e.g., to international sub-processors), we will ensure:
- The receiving country provides an adequate level of data protection as determined by SDAIA; or
- Appropriate safeguards are in place (e.g., Standard Contractual Clauses approved by SDAIA); or
- We have obtained your explicit consent for the specific transfer.
Note: We will not transfer your data to any jurisdiction that violates KSA sovereignty or fails to provide adequate data protection.
6. Data Retention and Deletion
We retain your Personal Data only for as long as necessary to:
- Fulfill the purposes outlined in this Policy.
- Meet our legal, tax, and accounting obligations under KSA law.
Upon account termination or a valid deletion request, we will securely erase your data within 30 days, unless retention is required by law. Backup data is overwritten according to our standard backup rotation cycles (not exceeding 90 days).
7. Data Subject Rights
Under the PDPL, you have the right to:
- Access: Request a copy of the Personal Data we hold about you.
- Correction: Request the correction of inaccurate or incomplete data.
- Deletion: Request the erasure of your data (subject to legal retention requirements).
- Restriction of Processing: Request that we limit how we use your data.
- Data Portability: Request your data in a structured, commonly used, and machine-readable format.
- Withdraw Consent: Withdraw your consent at any time where processing is based on consent.
- Object: Object to processing based on legitimate interests or for direct marketing.
How to Submit a Request: You may submit requests by emailing [email protected]. We will verify your identity and respond to your request within 20 business days as required by PDPL. We will not discriminate against you for exercising your rights.
8. Security Measures and Access Control
HALPOPTECH implements robust technical and organizational security measures to protect your data:
- Access Control: Role-Based Access Control (RBAC) ensures only authorized employees can access Personal Data, strictly on a need-to-know basis.
- Access Logging: We maintain comprehensive, immutable audit logs of all access to Personal Data. These logs are monitored by our security team to detect unauthorized access and support SDAIA compliance audits.
- Encryption: Data is encrypted in transit (TLS 1.3) and at rest (AES-256).
- Network Security: We utilize Web Application Firewalls (WAF), DDoS mitigation, and regular vulnerability scanning.
9. Data Breach Detection, Response, and Notification
We maintain strict data breach detection and response procedures:
- Detection: Automated monitoring tools and access logs alert our security team to anomalous activities.
- Response: Upon detecting a breach, our incident response team will immediately contain the breach, assess the risk, and eradicate the threat.
- Notification: If the breach poses a risk to your rights or privacy, we will notify the Saudi Data and Artificial Intelligence Authority (SDAIA) and affected Data Subjects without undue delay, and no later than 72 hours after becoming aware of the breach, in accordance with PDPL requirements.
10. Contact Us
For any privacy inquiries or to exercise your data subject rights, please contact our Data Protection Officer at: