Data protection,security and retention.
What we collect, why we hold it, how it is protected, how long it stays, and what you can require of us. Written to be read rather than to be defensible.
- Effective
- 1 January 2026
- Last reviewed
- 20 September 2026
- Framework
- Saudi PDPL
This policy is a template pending legal review. It describes intended practice and is not yet a published commitment.
01 — Scope
Who this applies to
This policy covers everyone whose personal data EmaLite handles: visitors to this website, current and prospective clients, business partners, and anyone who contacts us.
EmaLite is an enterprise technology company headquartered in Riyadh, Saudi Arabia. We design, build, secure and operate network, data centre and cloud infrastructure, and we develop and run BranchConnect, our own branch connectivity platform.
We operate under the Kingdom of Saudi Arabia Personal Data Protection Law (PDPL) and its implementing regulations. Where a client relationship brings other frameworks into scope, those obligations are set out in the engagement agreement rather than here.
Website visitors
Anyone browsing emalite.com or bc.emalite.com, whether or not they contact us.
Clients and prospects
Organisations we work with, are in discussion with, or have worked with previously.
Partners and suppliers
Vendors, distributors and professional advisors whose staff we deal with.
Data held inside a client's own environment is different. Where we operate or support infrastructure on your behalf, we process whatever it contains strictly under the engagement agreement and on your documented instructions — as a processor, not a controller. This policy governs EmaLite's own activities.
02 — Collection
What we collect
Three sources, and nothing beyond what the purpose requires.
What you give us
Name, job title and organisation. Work email, telephone number and business address. The content of enquiries and support requests. Documents shared during an engagement.
Collected automatically
IP address and approximate region. Browser and operating system. Pages requested, time on page and referring URL. Session identifiers.
From third parties
Business contacts introduced by a partner or referral. Publicly available professional information. Account details verified by a distributor.
We do not collect sensitive personal data — health, biometric, genetic, religious or similar — without explicit, specific consent. Our services do not require it.
03 — Purpose
How we use it, and on what basis
Each purpose below rests on a specific lawful basis: performance of a contract, a legitimate interest, a legal obligation, or your consent.
Delivering the service
Designing, building, securing and operating what the engagement agreement covers. Basis: performance of a contract.
Communication and support
Answering enquiries, raising and resolving tickets, and reporting on work in progress. Basis: contract, or legitimate interest before one exists.
Security
Detecting, investigating and preventing unauthorised access, fraud and abuse of our systems. Basis: legitimate interest.
Site analytics
Understanding which pages are used so the site can be improved. Aggregated, never used to build a profile of an individual. Basis: legitimate interest.
Legal and regulatory
Meeting statutory obligations, keeping accounting records, resolving disputes and enforcing agreements. Basis: legal obligation.
Service updates
Occasional notes about capabilities relevant to your organisation. Only with prior consent, and every message carries an unsubscribe link. Basis: consent.
We do not make automated decisions that produce legal or similarly significant effects, and we do not profile individuals for advertising.
05 — Protection
How it is protected
We sell security architecture. Applying it to our own estate is the minimum credible standard, so the controls below are the ones we run internally.
Encryption
TLS 1.2 or higher for everything in transit. AES-256 for data at rest. No unencrypted transport is accepted on any EmaLite system.
Access control
Multi-factor authentication on every internal system, with role-based access and least privilege. Access is reviewed on a schedule and revoked on the day someone leaves.
Segmentation
Client-facing systems are segmented from corporate systems. A compromise in one is not a compromise in both.
Monitoring
Availability, integrity and security events monitored continuously, with defined escalation and named owners rather than a shared inbox.
Testing
Vulnerability assessment on a cycle, independent penetration testing, and patching against defined service levels by severity.
People
Security awareness training for all staff, confidentiality obligations in every contract, and background verification appropriate to the role.
Breach notification — where a personal data breach is likely to affect your rights, we notify the competent authority within 72 hours of becoming aware of it, and affected individuals without undue delay, as the PDPL requires. Our incident response procedure is tested, not merely written down.
06 — Retention
How long we keep it
Personal data is kept only as long as the purpose it was collected for requires, or as long as the law obliges us to keep it — whichever is longer. When a period ends, records are deleted or irreversibly anonymised.
| Record | Retained for | Why |
|---|---|---|
| Client contractual records | 10 years after the contract ends | Commercial, tax and statutory record-keeping obligations |
| Project and as-built documentation | 10 years after the contract ends | Held with the contract; an estate's design history outlives the engagement that produced it |
| Enquiries and prospect contact data | 3 years from the last interaction | Legitimate interest in continuity of a business relationship |
| Support tickets and correspondence | 5 years from closure | Service history, dispute resolution and recurring-fault analysis |
| Security incident records | 5 years from closure | Audit, regulatory reporting and trend analysis |
| System and access logs | 12 months, then aggregated | Security investigation. Aggregates carry no identifier. |
| Website analytics | 12 months, then anonymised | Understanding site usage without retaining identifiable visitors |
| Marketing preferences | Until consent is withdrawn | Record of consent, and evidence of it being honoured |
| Job applications (unsuccessful) | 12 months | Answering follow-up questions and considering future roles, with consent |
| Backups | Up to 90 days beyond the source record | Backup cycles cannot be edited selectively; deletion propagates as the cycle rolls |
Client contractual records
10 years after the contract ends
Commercial, tax and statutory record-keeping obligations
Project and as-built documentation
10 years after the contract ends
Held with the contract; an estate's design history outlives the engagement that produced it
Enquiries and prospect contact data
3 years from the last interaction
Legitimate interest in continuity of a business relationship
Support tickets and correspondence
5 years from closure
Service history, dispute resolution and recurring-fault analysis
Security incident records
5 years from closure
Audit, regulatory reporting and trend analysis
System and access logs
12 months, then aggregated
Security investigation. Aggregates carry no identifier.
Website analytics
12 months, then anonymised
Understanding site usage without retaining identifiable visitors
Marketing preferences
Until consent is withdrawn
Record of consent, and evidence of it being honoured
Job applications (unsuccessful)
12 months
Answering follow-up questions and considering future roles, with consent
Backups
Up to 90 days beyond the source record
Backup cycles cannot be edited selectively; deletion propagates as the cycle rolls
Deletion from live systems is immediate at the end of a period. Backups are not selectively edited — a record deleted from production persists in backup media only until that cycle expires, and is never restored into production once its period has ended.
Data we hold as a processor inside a client environment is governed by that engagement agreement, not by this schedule. At the end of an engagement it is returned or destroyed as the agreement specifies, and a certificate of destruction is issued on request.
07 — PDPL rights
Your rights over your data
Under the Saudi Personal Data Protection Law you hold the following rights. Exercising any of them is free, and we will not treat you differently for doing so.
To exercise a right, write to the contact address at the foot of this page. We verify identity first — answering a data request to the wrong person is itself a breach — then respond within 30 days. If a request is complex enough to need longer, we will tell you why inside those 30 days.
- Be informed — know why your data is collected and how it will be used, before it is.
- Access — obtain a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have data deleted where no lawful reason to keep it remains.
- Restriction — limit how we use your data while a question about it is resolved.
- Portability — receive your data in a structured, commonly used, machine-readable format.
- Object — object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent — where processing rests on consent, withdraw it at any time, without affecting what was lawful before.
If you are not satisfied with how we have handled a request, you may escalate it to the Saudi Data and Artificial Intelligence Authority (SDAIA) at sdaia.gov.sa. We would rather you raised it with us first, but the route is yours to choose.
09 — External services
Third-party services and links
This policy covers EmaLite's own activities. It does not cover platforms operated by anyone else, even where we link to them or integrate with them on your behalf.
Our sites link to vendor documentation, and our engagements frequently integrate platforms operated by technology vendors. Where a third-party component forms part of a managed service we deliver, that provider is bound by a data processing agreement, assessed before engagement and reviewed periodically.
Where you follow a link to a site we do not operate, that site's own policy applies. We are not responsible for the content or the privacy practices of external websites, and we would encourage you to read their terms before providing anything.
Vendor assurance — every third party that receives personal data on our instructions is contractually obliged to handle it in accordance with the PDPL and this policy, and to notify us of any incident without delay.
10 — Updates
Changes to this policy
We update this policy when our services, our obligations or our practice change. Three things happen every time.
Continuing to use our website or services after a change takes effect means the updated policy applies. If a change is one you cannot accept, the contact details below are the place to say so.
The date changes
The 'last reviewed' date at the top of this page is updated the day the change is made, whether the change is material or not.
Clients are told
Where a change materially affects rights or obligations, active clients are notified by email rather than left to notice it.
A notice is posted
A visible notice stays on this page for at least 30 days after a material change.
11 — Contact
Who to write to
Any question about this policy, any request to exercise a right, and any concern about how we have handled data — all go to the same place.
- Organisation
- EmaLite
- Data protection contact
- hello@emalite.com
- Address
- Building 0000, King Fahd RoadAl Olaya, Riyadh 12333Saudi Arabia
- Telephone
- +966 11 000 0000
We respond to rights requests within 30 days. If you are not satisfied with the outcome, you may escalate to the Saudi Data and Artificial Intelligence Authority (SDAIA) at sdaia.gov.sa.