Data Privacy Policy
1. Our Commitment to Data Privacy
Tawrid Financial Solutions Company (referred to as “Tawrid”, “we”, “our”, “us”) is fully committed to protecting your privacy and personal data. We operate in full compliance with:
• Saudi Arabia’s Personal Data Protection Law (PDPL)
• SAMA Cybersecurity Framework
• National Cybersecurity Authority (NCA) Cloud Cybersecurity Controls
• Global best practices such as GDPR (where relevant to cross-border activities)
2. What Personal Data We Collect
We may collect and process the following types of data depending on your relationship with Tawrid:
Category Examples
Identity Information Name, National ID/Iqama, CR Number
Contact Information Email, phone number, business address
Usage Data Logins, feature usage, time stamps
Transaction Data Invoices, payment records, and KYC verification docs
Device Data IP address, browser type, cookies, geolocation (when consented)
3. Why We Collect Your Data
We use your data only when necessary and lawful, including:
• Account Creation & Identity Verification
To register and authenticate users under platform roles (e.g., Corporate Admin, Signatory)
• Transaction Processing
To process invoice submissions, disbursements, and settlements securely
• Regulatory Compliance
To meet obligations under PDPL, SAMA, AML, KYC, and financial reporting rules
• User Support & Communication
To respond to inquiries, provide onboarding support, or deliver service updates
• Platform Optimization
To analyze performance, identify bugs, and enhance user experience
4. Lawful Basis for Processing
We process your data based on one or more of the following legal bases:
• Consent: You have given explicit consent for processing (e.g., cookie preferences)
• Contractual Obligation: Data is needed to fulfill a service or agreement with you
• Legal Obligation: We must comply with regulatory requirements
• Legitimate Interest: To improve services and protect the platform’s integrity
5. Data Sharing and Third Parties
Tawrid does not sell or monetize your data. However, we may share limited data with:
• Authorized financial institutions and funding partners
• SAMA-regulated audit and compliance bodies
• Regulatory bodies (e.g., GAZT, Ministry of Commerce) if legally required
• Third-party service providers (e.g., STC Sayen for e-signatures) under binding DPAs
Confidentiality agreements and strict access controls underpin all data sharing and management.
6. International Data Transfers
Cross-border data transfers (if applicable) will:
• Be minimized and only occur with proper legal safeguards
• Be subject to user consent or data localization exemptions under PDPL Article 29
• Use data protection mechanisms such as Standard Contractual Clauses (SCCs)
7. Your Rights Under PDPL
You have the following rights, subject to lawful exceptions:
• Access: You may request to view the data we hold about you
• Rectification: You may correct inaccurate or incomplete data
• Erasure: You may request deletion unless retention is legally required
• Objection: You may object to processing where consent is the legal basis
• Data Portability: Upon request, we can transfer your data to another controller
Submit requests via: privacy@tawrid.com.sa
8. Data Retention & Archiving
We retain data only as long as:
• Required by Saudi laws and financial recordkeeping (e.g., SAMA’s 10-year requirement)
• Necessary for business or contractual purposes
• Required to comply with audit, dispute resolution, or legal holds
Upon expiration of retention periods, data is securely deleted or anonymized.
9. Cookies and Tracking
We use first-party cookies to:
• Maintain secure logins
• Improve platform navigation
• Track session behavior (anonymously)
We do not use third-party advertising or marketing trackers.
Users can manage their cookie preferences through browser settings or platform controls.
10. Security Controls
Tawrid’s data security is anchored in:
• Encryption (data-at-rest and in-transit)
• Multi-factor authentication
• Role-based access management
• Regular vulnerability assessments & penetration testing
• Compliance with SAMA, NCA, and ISO 27001 frameworks
11. Children’s Data
Tawrid services are not intended for individuals under the age of 18. We do not knowingly collect data from individuals under the age of 18.
12. Policy Updates
This policy may be updated periodically. We will notify users via email or platform notices of material changes.
Last updated: [Insert Date]
13. Contact Us
For questions, complaints, or exercising your data rights, contact:
