Privacy Statement
How Tamayouz collects, uses, discloses, stores, transfers, and protects your personal data, and the rights you have under Saudi Arabia’s PDPL.
Effective 21 June 2026 · Last updated 21 June 2026 · Version 1.0
This Privacy Statement is reviewed periodically and updated as needed to keep it accurate and aligned with the PDPL and our practices.
1. Introduction
Tamayouz Business Solutions Co. (“Tamayouz,” “we,” “us,” or “our”) is committed to protecting your privacy and handling your personal data responsibly. This Privacy Statement explains how we collect, use, disclose, store, transfer, and protect your personal data, and the rights you have over it.
We process personal data in accordance with the Personal Data Protection Law of the Kingdom of Saudi Arabia, issued by Royal Decree No. (M/19) dated 09/02/1443 AH and amended by Royal Decree No. (M/148) dated 05/09/1444 AH (the “PDPL” or the “Law”), together with its Implementing Regulation and the Regulation on Personal Data Transfer outside the Kingdom (collectively, the “Regulations”).
This Statement applies to personal data we collect through our website www.tamayouz.sa, our digital channels, and any related services, communications, or interactions (collectively, the “Services”). It applies to you as a visitor to our website and to anyone who contacts us or otherwise interacts with us through these channels.
Please read this Statement carefully. By using our Services, you acknowledge that you have read and understood it.
Our Privacy Commitments
In handling your personal data, we are guided by the core data protection principles underpinning the PDPL:
- Lawfulness, fairness, and transparency — we process personal data on a valid legal basis and explain clearly how it is used.
- Purpose limitation — we collect personal data only for specified, documented purposes.
- Data minimization — we collect only what we need for those purposes.
- Storage limitation — we keep personal data only for as long as necessary.
- Accuracy — we take reasonable steps to keep personal data accurate, complete, and up to date.
- Integrity and confidentiality — we apply appropriate technical and organizational measures to safeguard personal data.
- Accountability — we maintain the records and measures needed to demonstrate our compliance.
2. Who We Are (Data Controller)
For the purposes of the PDPL, the Data Controller responsible for your personal data is:
- Legal name: Tamayouz Business Solutions Co.
- Commercial Registration (CR) No.: 101042807
- Registered address: 4728 King Abdullah Road, Riyadh 13216, Kingdom of Saudi Arabia
- Privacy contact: PrivacyOffice@tamayouz.sa
We determine the purposes and means of processing your personal data, whether that processing is carried out by us directly or by a Processor acting on our behalf.
3. Privacy Office
Privacy matters at Tamayouz are handled by our Privacy Office, which oversees our compliance with the PDPL and acts as the point of contact for any questions or requests relating to your personal data.
- Privacy Office contact: PrivacyOffice@tamayouz.sa
4. The Personal Data We Collect
Depending on how you interact with us, we may collect the following categories of personal data:
- Identity and contact data: your name, email address, telephone number, and the organization you represent, when you contact us or book a call through our website.
- Communication content: the contents of the messages, inquiries, and correspondence you send us, and our responses.
- Technical and usage data: IP address, device and browser information, and analytics data about how you use our website. This is collected only after you accept analytics cookies (see Section 11).
We collect only the minimum amount of personal data necessary to achieve the purpose for which it is collected, consistent with the data minimization principle.
Sensitive, Health, and Credit Data
We do not collect or process sensitive data (such as data revealing racial or ethnic origin; religious, intellectual, or political belief; criminal or security data; biometric or genetic data; health data; or data indicating that one or both parents are unknown), health data, or credit data through our website. If, in the course of a professional engagement, it becomes necessary to process such data, we will do so only on a valid lawful basis, with your explicit consent where required, and subject to the additional controls required by the Regulations.
Data Relating to Deceased Individuals
Where we process data of a deceased person that could lead to identifying that person or a living member of their family, we protect it in line with the PDPL to the extent applicable.
5. How We Collect Your Personal Data
We collect personal data:
- Directly from you — when you fill in forms, create an account, contact us, subscribe to communications, or use our Services.
- Automatically — through cookies and similar technologies as you interact with our website (see Section 11).
- From third parties or publicly available sources — only where this is lawful under the PDPL, necessary and proportionate to a specified purpose, and does not adversely affect your rights and interests.
Where we are required to collect certain personal data by law or to provide a service, we will indicate which data is mandatory and which is optional, and the consequences of not providing mandatory data (for example, that we may be unable to provide the requested service).
6. Purposes and Legal Bases for Processing
We process your personal data only for specific, clear, and explicit purposes, and only where we have a lawful basis to do so under the PDPL. Our purposes and legal bases include:
| Purpose | Legal basis under the PDPL |
|---|---|
| Providing and managing the Services you request | Performance of an agreement to which you are a party; your consent |
| Responding to your inquiries, requests, and complaints | Your consent; our legitimate interest |
| Operating, securing, and improving our website and Services | Our legitimate interest (e.g., network and information security) |
| Sending marketing or awareness materials (where you have opted in) | Your prior consent |
| Complying with legal, regulatory, and judicial obligations | Compliance with another law / judicial requirements |
| Protecting your vital interests or those of others | Vital/actual interest where contacting you is impossible or difficult |
We rely on legitimate interest only where it is necessary, balanced against your rights and interests, does not involve sensitive data, and falls within your reasonable expectations. Where we rely on legitimate interest, we conduct and document an assessment as required by the Regulations.
We will not process your personal data for a new purpose that is incompatible with the original purpose without first informing you and, where required, obtaining your consent.
Automated Decision-Making
We do not make decisions that produce significant effects on you based solely on the automated processing of your personal data.
7. Consent and Withdrawal of Consent
Where we rely on your consent to process your personal data:
- Consent is given freely, is specific to each processing purpose, and is obtained without misleading methods.
- We obtain explicit consent where the processing involves sensitive data, credit data, or decisions made solely on the basis of automated processing.
- You have the right to withdraw your consent at any time, through any of the channels listed in Section 14. The withdrawal process is as easy as the process for giving consent.
- Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal, and does not affect processing based on another lawful basis.
If you are a legal guardian providing consent on behalf of a person who fully or partially lacks legal capacity, you confirm that you are authorized to do so and that you act in that person’s best interests.
8. Your Rights as a Data Subject
Subject to the conditions and exceptions set out in the PDPL, you have the following rights:
- Right to be informed — to know the legal basis and purpose for collecting your personal data.
- Right of access — to access the personal data we hold about you.
- Right to obtain a copy — to receive your personal data in a readable and clear, commonly used electronic format (a printed copy may be requested where feasible).
- Right to correction — to request that we correct, complete, or update inaccurate, incomplete, or outdated personal data.
- Right to destruction — to request deletion of your personal data where it is no longer necessary, where you withdraw consent that was the sole basis for processing, or where processing is unlawful (subject to legal retention requirements).
- Right to withdraw consent — as described in Section 7.
- Right to lodge a complaint — to complain to the Competent Authority, as described in Section 15.
- Right to claim compensation — to seek compensation through the competent court for material or moral damage suffered as a result of a violation of the PDPL or its Regulations.
We will act on your request without delay and within 30 days. This period may be extended by up to a further 30 days where the request is complex or where we receive multiple requests from you; we will notify you in advance of any extension and the reasons for it.
We may need to verify your identity before acting on a request. We may decline to act on requests that are repetitive, manifestly unfounded, or require disproportionate effort, in which case we will explain our reasons.
To exercise any of these rights, contact us at PrivacyOffice@tamayouz.sa.
9. Disclosure of Personal Data
We may disclose your personal data to:
- Service providers and Processors who process personal data on our behalf under written agreements that require them to protect it and to process it only on our instructions and for specified purposes.
- Public authorities and regulators where disclosure is required for security purposes, to implement another law, to satisfy judicial requirements, or to protect public health, public safety, or the life or health of specific individuals.
- Other parties where you have consented or where another lawful basis applies.
When we disclose personal data, we limit it to the minimum necessary, take care to protect your privacy, and maintain records of disclosure. We do not sell your personal data.
The categories of third-party service providers that may process personal data on our behalf include:
- Cloud email and productivity providers — used to receive and manage your communications.
- Enterprise resource planning (ERP) and customer relationship management (CRM) providers — used to manage business contacts and engagements.
- Website hosting, content delivery, and security providers — used to operate and protect our website.
- Web analytics providers — used to understand how our site is used, only after you accept analytics cookies.
- Contact-form processing providers — used to handle submissions made through our website.
Each such provider is engaged under a written agreement requiring it to protect personal data and process it only on our instructions.
10. Transfer of Personal Data Outside the Kingdom
Some of the service providers we use process personal data outside the Kingdom of Saudi Arabia (for example, certain cloud, hosting, and analytics providers operate global infrastructure). Where we transfer your personal data outside the Kingdom, or disclose it to a party outside the Kingdom, we do so only in accordance with the PDPL and the Regulation on Personal Data Transfer outside the Kingdom. Specifically, we ensure that:
- The transfer does not prejudice national security or the vital interests of the Kingdom and does not violate any other law in the Kingdom.
- The transfer is limited to the minimum amount of personal data necessary to achieve the purpose.
- One of the following applies: an adequate level of protection exists in the destination country, sector, or international organization; appropriate safeguards are in place (such as binding common rules, standard contractual clauses, approved certifications, or binding codes of conduct); or the transfer falls within a permitted exemption under the Regulation.
- Where required, we conduct and document a risk assessment of the transfer.
11. Cookies and Similar Technologies
Our website uses cookies and similar technologies to operate the site and to understand how it is used.
- Essential cookies are necessary for the website to function and are always active.
- Analytics cookies (provided through Google Analytics) help us understand how visitors use our site so we can improve it.
We use a consent banner that lets you Accept or Decline analytics cookies. Analytics cookies do not load until you choose to accept them, so no non-essential cookies are placed without your consent. You can change your choice at any time by clearing your browser cookies for our site and revisiting it, or through your browser settings. Declining analytics cookies does not affect your ability to use the website.
12. Marketing and Awareness Communications
We will only send you advertising, marketing, or awareness materials where you have given your prior consent (or where there is a prior interaction permitting it under the Regulations). When we do:
- We clearly identify ourselves as the sender.
- We provide an easy, free mechanism to opt out at any time, which is at least as easy as opting in.
- We stop sending such materials promptly upon your request.
We do not use sensitive data for marketing purposes under any circumstances, even with your consent.
You can opt out at any time using the unsubscribe link in our communications or by emailing PrivacyOffice@tamayouz.sa.
13. Data Retention, Security, and Breach Notification
Retention. We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required to comply with legal, regulatory, accounting, or reporting obligations. When personal data is no longer needed, we securely destroy it, unless a legal basis requires us to retain it for a specific period. As a general guide:
| Type of data | Retention period |
|---|---|
| Contact and inquiry data (where no engagement results) | Up to 48 months from your last contact with us, then deleted |
| Business correspondence relating to an engagement | Duration of the engagement plus any period required by law |
| Website analytics data | As configured in Google Analytics (typically up to 14 months) |
Security. We implement appropriate organizational, administrative, and technical measures to protect your personal data against unauthorized access, disclosure, alteration, loss, or destruction, including during transfer. Our measures align with applicable controls and standards, including those issued by the National Cybersecurity Authority where relevant.
Breach notification. In the event of a personal data breach, we will notify the Competent Authority within the timeframes required by the Regulations and will notify affected data subjects without undue delay where the breach may cause harm to their data or prejudice their rights and interests.
14. How to Contact Us
For any questions, requests, or concerns regarding this Privacy Statement or your personal data, or to exercise any of your rights, please contact our Privacy Office:
- Email: PrivacyOffice@tamayouz.sa
- Postal address: 4728 King Abdullah Road, Riyadh 13216, Kingdom of Saudi Arabia
We will respond within the timeframes set out in Section 8.
15. Right to Lodge a Complaint
If you believe your personal data has not been handled in accordance with the PDPL, we encourage you to contact us first at PrivacyOffice@tamayouz.sa so we can address your concern.
You also have the right to file a complaint with the Competent Authority (the Saudi Data & AI Authority – SDAIA) within 90 days of becoming aware of the incident, in accordance with the procedures set out by the Competent Authority.
16. Changes to This Privacy Statement
We may update this Privacy Statement from time to time to reflect changes in our practices, technology, or legal requirements. We will post the updated version on our website and revise the version number and “Last updated” date above. Where required by law, we will notify you of material changes.
This Privacy Statement is provided for transparency and compliance purposes. Where there is any conflict between this Statement and the PDPL or its Regulations, the Law and Regulations prevail.