Privacy Policy
NAZZTEC treats personal data with the same rigour we apply to our clients' systems. This notice explains what personal data we collect, why we collect it, how long we keep it, who we share it with, and the rights available to you.
This notice applies to NAZZTEC INFORMATION TECHNOLOGY COMPANY, Riyadh, Kingdom of Saudi Arabia and to the NAZZTEC websites, proposals, service delivery and recruitment activity operated by it. It is written to comply with the Saudi Personal Data Protection Law (PDPL), issued by Royal Decree M/19 of 1443H, together with its Implementing Regulations and the rules issued by the Saudi Data & AI Authority (SDAIA).
If anything here is unclear, contact us at privacy@nazztec.com.sa and a member of our privacy team will respond.
1. Who we are and how to contact us
Data controller: NAZZTEC INFORMATION TECHNOLOGY COMPANY.
Registered address: Regus, Hamad Tower, 4th Floor, King Fahd Branch Road, Al Olaya, Riyadh 12212, Kingdom of Saudi Arabia.
Privacy contact: privacy@nazztec.com.sa
Data Protection Officer: DPO@nazztec.com
NAZZTEC operates through separate legal entities in the Kingdom of Saudi Arabia, India and the United States. Where you engage a specific entity, that entity is the controller for the personal data processed under that engagement. The entities share common privacy standards and an intra-group data transfer agreement.
2. The personal data we collect
We collect only what we need for a defined purpose. We do not sell personal data, and we do not use it to train third-party artificial intelligence models.
| Category | Examples | Where it comes from |
|---|---|---|
| Contact and enquiry data | Name, business email, telephone number, employer, job title, country, the content of your enquiry | Provided directly by you through our contact form, email, telephone or at events |
| Client engagement data | Contract and billing details, named stakeholder contacts, correspondence, meeting notes, project documentation | Provided by you or your organisation during an engagement |
| Technical and usage data | IP address, browser and device type, operating system, referring page, pages visited, session duration, approximate city-level location | Collected automatically by our website and analytics tools, subject to your cookie choices |
| Recruitment data | CV, employment and education history, certifications, right-to-work and visa status, references, interview notes, salary expectations | Provided by you, by a recruitment agency acting for you, or from public professional profiles |
| Supplier and partner data | Contact details of individuals at our suppliers, subcontractors and technology partners, due diligence responses | Provided by the supplier or partner organisation |
| Security and access data | Access logs, authentication records, security monitoring data, CCTV at our offices where applicable | Generated automatically by our systems and premises |
| Marketing preference data | Subscription status, consent records, engagement with our communications | Provided by you and recorded when you interact with us |
Data encountered during service delivery. When delivering security testing, audits, managed services or staffing, we may encounter personal data held within your systems. In that context you are the controller and NAZZTEC acts as a processor on your documented instructions, governed by the data processing terms in our engagement contract. We do not use that data for any purpose other than delivering the contracted service.
Sensitive personal data. We do not seek special-category or sensitive personal data through our website. Where recruitment or visa processing requires it — for example medical fitness or biometric information required by immigration authorities — we collect it only where lawfully required, with appropriate safeguards and, where applicable, your explicit consent.
Children. Our services and website are directed at businesses and professionals. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact privacy@nazztec.com.sa and we will delete it.
3. Why we process your data and our lawful basis
Under the PDPL we must have a valid legal basis for each processing activity. The table below sets out our purposes and the basis relied on for each.
| Purpose | Lawful basis |
|---|---|
| Responding to your enquiry and providing information you requested | Your consent, and the necessity of taking steps at your request before entering a contract |
| Delivering contracted services and managing the client relationship | Performance of a contract to which you or your organisation is a party |
| Invoicing, payment collection and financial record keeping | Performance of a contract and compliance with statutory obligations |
| Operating, securing and improving our website | Our legitimate interests in running a secure and effective website |
| Analytics and measuring website performance | Your consent, given through our cookie banner |
| Sending marketing communications and insights | Your consent, withdrawable at any time |
| Recruitment and candidate assessment | Steps taken at your request prior to an employment contract, and your consent for talent-pool retention |
| Protecting our systems, detecting fraud and investigating security incidents | Our legitimate interests in security, and compliance with regulatory obligations |
| Meeting regulatory, tax, audit and statutory reporting obligations | Compliance with legal obligations in the Kingdom |
| Establishing, exercising or defending legal claims | Our legitimate interests and the protection of legal rights |
Where we rely on legitimate interests, we have carried out a balancing assessment to confirm that our interests do not override your rights and freedoms. You may request a summary of that assessment at privacy@nazztec.com.sa.
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
4. Who we share your data with
We share personal data only where there is a clear need, and always under contractual controls. We do not sell, rent or trade personal data.
- NAZZTEC group entities in Saudi Arabia, India and the United States, where necessary to deliver a service or manage the relationship, under an intra-group data transfer agreement.
- Service providers acting as processors on our behalf — cloud hosting, email and collaboration platforms, customer relationship management, analytics, recruitment systems, payroll and accounting. Each is bound by a written data processing agreement requiring confidentiality, security and deletion or return of data on termination.
- Professional advisers — lawyers, auditors, insurers and accountants, where necessary and under professional duties of confidentiality.
- Subcontractors and associate consultants, where they form part of a delivery team, under equivalent confidentiality and data protection obligations.
- Regulators, law enforcement and courts, where we are legally required to disclose or where disclosure is necessary to establish or defend legal claims.
- A purchaser or successor entity, in the event of a merger, acquisition or reorganisation, under confidentiality obligations and with notice to affected individuals where required.
A current list of our material processors is available on request from privacy@nazztec.com.sa.
5. International transfers of personal data
NAZZTEC operates in the Kingdom of Saudi Arabia, India and the United States. Where personal data is transferred outside the Kingdom, we do so only in accordance with the PDPL and its Implementing Regulations, and only where one of the permitted conditions applies.
- Transfer to a jurisdiction recognised by the competent authority as providing an adequate level of protection.
- Transfer subject to appropriate safeguards and a transfer risk assessment, as required by the Implementing Regulations.
- Transfer necessary to perform a contract to which you are a party.
- Transfer with your explicit consent, where no other basis applies.
- Data residency: where a client engagement or regulatory obligation requires personal data to remain within the Kingdom, we design the engagement so that it does. We can contract for in-Kingdom hosting and in-Kingdom delivery where required. Tell us at the outset if this applies to you.
6. How long we keep your data
We retain personal data only for as long as necessary for the purpose it was collected, plus any period required by law, regulation or the defence of legal claims. Our retention schedule is reviewed annually.
| Data category | Retention period |
|---|---|
| Website enquiries that do not become an engagement | 24 months from last contact, then deleted |
| Client engagement records and correspondence | Duration of the engagement plus 7 years, to meet contractual, tax and audit obligations |
| Contracts and statements of work | Duration plus 10 years, for limitation-period purposes |
| Financial and tax records | As required by ZATCA and Saudi statutory requirements, currently a minimum of 10 years |
| Security testing reports and findings | As agreed in the engagement contract; deleted or returned on request, and by default within 12 months of closure unless retention is contractually agreed |
| Unsuccessful candidate records | 12 months from the hiring decision, or longer with your consent for our talent pool |
| Successful candidate and employee records | Duration of employment plus the period required by applicable employment law |
| Marketing consent records | Until consent is withdrawn, plus 3 years to evidence the consent position |
| Website analytics data | Up to 14 months in aggregated form |
| Security and access logs | 12 months, or longer where required for an active investigation |
Where data is no longer required, it is securely deleted or irreversibly anonymised. Backup copies are overwritten in the ordinary backup cycle.
7. Your rights
Under the PDPL you have the following rights in relation to your personal data.
- Right to be informed — to know the legal basis and purpose for which your data is collected.
- Right of access — to request access to your personal data held by us.
- Right to obtain a copy — to receive your personal data in a readable, commonly used format.
- Right to rectification — to have inaccurate, incomplete or outdated data corrected or updated.
- Right to destruction — to request deletion of your personal data where it is no longer required for the purpose collected, subject to our legal retention obligations.
- Right to withdraw consent — where processing is based on consent, to withdraw it at any time.
How to exercise your rights. Email privacy@nazztec.com.sa or our Data Protection Officer at DPO@nazztec.com with your request. We may ask for information to verify your identity, which we use only for that purpose. We will respond within 30 days. There is no charge unless a request is manifestly unfounded or excessive, in which case we will tell you before proceeding.
Complaints. If you are not satisfied with our response, you may lodge a complaint with the Saudi Data & AI Authority (SDAIA).
8. How we protect your data
Information security is our profession, and we hold ourselves to the standards we ask our clients to meet. Our controls include:
- Encryption of data in transit (TLS 1.2 or above) and at rest.
- Multi-factor authentication on all corporate and administrative accounts.
- Role-based access control applied on a least-privilege basis, with periodic access reviews.
- Centralised logging and 24x7 security monitoring of our own environment.
- Endpoint protection, patch management and hardened device configuration baselines.
- Segregation of client engagement data, with separate access controls per engagement.
- Confidentiality obligations and background verification for personnel, proportionate to their role.
- Security awareness training, including phishing simulation, for all staff.
- Written data processing agreements and security due diligence for every material supplier.
- A documented incident response plan, tested through exercises.
- Secure disposal of media and certified destruction of decommissioned equipment.
Breach notification. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Saudi Data & AI Authority (SDAIA) within 72 hours of becoming aware of it where required, and notify affected individuals without undue delay where the risk is high.
No absolute guarantee. No system can be made completely secure. While we apply controls proportionate to the risk, we cannot guarantee the security of information transmitted to us over the internet, and any transmission is at your own risk.
9. Cookies and similar technologies
Our website uses cookies and similar technologies. Non-essential cookies are set only with your consent, which you may change at any time through the cookie preferences link in our footer. Full detail is set out in our Cookie Policy.
10. Third-party links
Our website contains links to third-party sites, including our technology partners, regulators and standards bodies. We provide these for your convenience and because linking to authoritative sources is good practice. We are not responsible for the privacy practices or content of those sites, and we encourage you to read their privacy notices.
11. Changes to this notice
We review this notice at least annually and whenever our processing changes materially. The effective date is shown at the top of the page and a summary of material changes is published alongside it. Where a change materially affects how we use your data, we will notify you directly if we hold contact details for you and the change requires it.
12. Contact us
For any privacy question, request or complaint:
Email: privacy@nazztec.com.sa
Data Protection Officer: DPO@nazztec.com
Post: Privacy Team, NAZZTEC INFORMATION TECHNOLOGY COMPANY, Regus, Hamad Tower, 4th Floor, King Fahd Branch Road, Al Olaya, Riyadh 12212, Kingdom of Saudi Arabia
We aim to acknowledge every privacy enquiry within two business days.
Questions about this policy?
Our privacy team responds to every enquiry. Email privacy@nazztec.com.sa or use the contact form.
We aim to acknowledge every privacy enquiry within two business days.