Skip to content
Legal

Data protection,security and retention.

What we collect, why we hold it, how it is protected, how long it stays, and what you can require of us. Written to be read rather than to be defensible.

Effective
1 January 2026
Last reviewed
20 September 2026
Framework
Saudi PDPL

This policy is a template pending legal review. It describes intended practice and is not yet a published commitment.

01 — Scope

Who this applies to

This policy covers everyone whose personal data EmaLite handles: visitors to this website, current and prospective clients, business partners, and anyone who contacts us.

EmaLite is an enterprise technology company headquartered in Riyadh, Saudi Arabia. We design, build, secure and operate network, data centre and cloud infrastructure, and we develop and run BranchConnect, our own branch connectivity platform.

We operate under the Kingdom of Saudi Arabia Personal Data Protection Law (PDPL) and its implementing regulations. Where a client relationship brings other frameworks into scope, those obligations are set out in the engagement agreement rather than here.

  • Website visitors

    Anyone browsing emalite.com or bc.emalite.com, whether or not they contact us.

  • Clients and prospects

    Organisations we work with, are in discussion with, or have worked with previously.

  • Partners and suppliers

    Vendors, distributors and professional advisors whose staff we deal with.

Data held inside a client's own environment is different. Where we operate or support infrastructure on your behalf, we process whatever it contains strictly under the engagement agreement and on your documented instructions — as a processor, not a controller. This policy governs EmaLite's own activities.

02 — Collection

What we collect

Three sources, and nothing beyond what the purpose requires.

  • What you give us

    Name, job title and organisation. Work email, telephone number and business address. The content of enquiries and support requests. Documents shared during an engagement.

  • Collected automatically

    IP address and approximate region. Browser and operating system. Pages requested, time on page and referring URL. Session identifiers.

  • From third parties

    Business contacts introduced by a partner or referral. Publicly available professional information. Account details verified by a distributor.

We do not collect sensitive personal data — health, biometric, genetic, religious or similar — without explicit, specific consent. Our services do not require it.

03 — Purpose

How we use it, and on what basis

Each purpose below rests on a specific lawful basis: performance of a contract, a legitimate interest, a legal obligation, or your consent.

  • Delivering the service

    Designing, building, securing and operating what the engagement agreement covers. Basis: performance of a contract.

  • Communication and support

    Answering enquiries, raising and resolving tickets, and reporting on work in progress. Basis: contract, or legitimate interest before one exists.

  • Security

    Detecting, investigating and preventing unauthorised access, fraud and abuse of our systems. Basis: legitimate interest.

  • Site analytics

    Understanding which pages are used so the site can be improved. Aggregated, never used to build a profile of an individual. Basis: legitimate interest.

  • Legal and regulatory

    Meeting statutory obligations, keeping accounting records, resolving disputes and enforcing agreements. Basis: legal obligation.

  • Service updates

    Occasional notes about capabilities relevant to your organisation. Only with prior consent, and every message carries an unsubscribe link. Basis: consent.

We do not make automated decisions that produce legal or similarly significant effects, and we do not profile individuals for advertising.

04 — Disclosure

Who else sees it

EmaLite does not sell, rent or trade personal data. It is shared only in the five circumstances below, and only to the extent each one requires.

  • Technology vendors

    Licence registration, entitlement checks, technical support cases and warranty claims with the platforms an engagement uses. Limited to the contact details a case requires.

  • Infrastructure providers

    Hosting, email and monitoring services that run our own systems. Each is bound by a data processing agreement, with encryption in transit and at rest.

  • Professional advisors

    Legal, audit and accounting professionals, under professional confidentiality obligations.

  • Authorities

    Regulators, law enforcement or courts, where Saudi law or a valid order requires it. Disclosure is limited strictly to what is compelled, and we notify you unless prohibited from doing so.

  • Business transfer

    In a merger, acquisition or sale of assets — subject to confidentiality undertakings and advance notice to those affected.

Every recipient acting on our instructions is contractually required to handle data in line with the PDPL and this policy, and is reviewed before engagement and periodically afterwards.

05 — Protection

How it is protected

We sell security architecture. Applying it to our own estate is the minimum credible standard, so the controls below are the ones we run internally.

  • Encryption

    TLS 1.2 or higher for everything in transit. AES-256 for data at rest. No unencrypted transport is accepted on any EmaLite system.

  • Access control

    Multi-factor authentication on every internal system, with role-based access and least privilege. Access is reviewed on a schedule and revoked on the day someone leaves.

  • Segmentation

    Client-facing systems are segmented from corporate systems. A compromise in one is not a compromise in both.

  • Monitoring

    Availability, integrity and security events monitored continuously, with defined escalation and named owners rather than a shared inbox.

  • Testing

    Vulnerability assessment on a cycle, independent penetration testing, and patching against defined service levels by severity.

  • People

    Security awareness training for all staff, confidentiality obligations in every contract, and background verification appropriate to the role.

Breach notification — where a personal data breach is likely to affect your rights, we notify the competent authority within 72 hours of becoming aware of it, and affected individuals without undue delay, as the PDPL requires. Our incident response procedure is tested, not merely written down.

06 — Retention

How long we keep it

Personal data is kept only as long as the purpose it was collected for requires, or as long as the law obliges us to keep it — whichever is longer. When a period ends, records are deleted or irreversibly anonymised.

  • Client contractual records

    10 years after the contract ends

    Commercial, tax and statutory record-keeping obligations

  • Project and as-built documentation

    10 years after the contract ends

    Held with the contract; an estate's design history outlives the engagement that produced it

  • Enquiries and prospect contact data

    3 years from the last interaction

    Legitimate interest in continuity of a business relationship

  • Support tickets and correspondence

    5 years from closure

    Service history, dispute resolution and recurring-fault analysis

  • Security incident records

    5 years from closure

    Audit, regulatory reporting and trend analysis

  • System and access logs

    12 months, then aggregated

    Security investigation. Aggregates carry no identifier.

  • Website analytics

    12 months, then anonymised

    Understanding site usage without retaining identifiable visitors

  • Marketing preferences

    Until consent is withdrawn

    Record of consent, and evidence of it being honoured

  • Job applications (unsuccessful)

    12 months

    Answering follow-up questions and considering future roles, with consent

  • Backups

    Up to 90 days beyond the source record

    Backup cycles cannot be edited selectively; deletion propagates as the cycle rolls

Deletion from live systems is immediate at the end of a period. Backups are not selectively edited — a record deleted from production persists in backup media only until that cycle expires, and is never restored into production once its period has ended.

Data we hold as a processor inside a client environment is governed by that engagement agreement, not by this schedule. At the end of an engagement it is returned or destroyed as the agreement specifies, and a certificate of destruction is issued on request.

07 — PDPL rights

Your rights over your data

Under the Saudi Personal Data Protection Law you hold the following rights. Exercising any of them is free, and we will not treat you differently for doing so.

To exercise a right, write to the contact address at the foot of this page. We verify identity first — answering a data request to the wrong person is itself a breach — then respond within 30 days. If a request is complex enough to need longer, we will tell you why inside those 30 days.

  • Be informed — know why your data is collected and how it will be used, before it is.
  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have data deleted where no lawful reason to keep it remains.
  • Restriction — limit how we use your data while a question about it is resolved.
  • Portability — receive your data in a structured, commonly used, machine-readable format.
  • Object — object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent — where processing rests on consent, withdraw it at any time, without affecting what was lawful before.

If you are not satisfied with how we have handled a request, you may escalate it to the Saudi Data and Artificial Intelligence Authority (SDAIA) at sdaia.gov.sa. We would rather you raised it with us first, but the route is yours to choose.

08 — Tracking

Cookies and tracking

This site is built to need very little. There are no third-party advertising cookies, no tracking pixels and no cross-site identifiers — fonts and assets are served from our own domain, so no third party sees your visit.

Every browser lets you view, block and delete cookies. Blocking the essential ones will break parts of the site; blocking the others will not.

  • Essential

    Keep the site working — security, load balancing, remembering that you dismissed a notice.

    No. Nothing personal is stored and the site cannot function without them.

  • Analytics

    Count page views and understand which content is used. Aggregated and anonymised.

    Yes, through your browser settings.

  • Preference

    Remember choices such as a selected tab, so the site behaves as you left it.

    Yes, through your browser settings.

  • Advertising

    Not used.

    Not applicable — we set none.

09 — External services

Third-party services and links

This policy covers EmaLite's own activities. It does not cover platforms operated by anyone else, even where we link to them or integrate with them on your behalf.

Our sites link to vendor documentation, and our engagements frequently integrate platforms operated by technology vendors. Where a third-party component forms part of a managed service we deliver, that provider is bound by a data processing agreement, assessed before engagement and reviewed periodically.

Where you follow a link to a site we do not operate, that site's own policy applies. We are not responsible for the content or the privacy practices of external websites, and we would encourage you to read their terms before providing anything.

Vendor assurance — every third party that receives personal data on our instructions is contractually obliged to handle it in accordance with the PDPL and this policy, and to notify us of any incident without delay.

10 — Updates

Changes to this policy

We update this policy when our services, our obligations or our practice change. Three things happen every time.

Continuing to use our website or services after a change takes effect means the updated policy applies. If a change is one you cannot accept, the contact details below are the place to say so.

  • The date changes

    The 'last reviewed' date at the top of this page is updated the day the change is made, whether the change is material or not.

  • Clients are told

    Where a change materially affects rights or obligations, active clients are notified by email rather than left to notice it.

  • A notice is posted

    A visible notice stays on this page for at least 30 days after a material change.

11 — Contact

Any question about this policy, any request to exercise a right, and any concern about how we have handled data — all go to the same place.

Organisation
EmaLite
Data protection contact
hello@emalite.com
Address
Building 0000, King Fahd RoadAl Olaya, Riyadh 12333Saudi Arabia

We respond to rights requests within 30 days. If you are not satisfied with the outcome, you may escalate to the Saudi Data and Artificial Intelligence Authority (SDAIA) at sdaia.gov.sa.