Website Legal Policies

Privacy Policy

A notice explaining how Al-Itqan International Consulting Company collects, processes, and protects personal data, and the rights granted to data subjects.

Version

1.0

Effective Date and Last Updated

26 July 2026

Controller

Al-Itqan International Consulting Company

Scope

The website, forms, and covered services

Al-Itqan International Consulting Company respects the privacy of its website visitors and service users.

The Company processes personal data in accordance with the Personal Data Protection Law of the Kingdom of Saudi Arabia and its Implementing Regulations, in a manner that ensures lawfulness, transparency, and data minimisation. This Policy explains the types of data we may collect, how we collect it, the purposes for which it is processed, the parties to whom it may be disclosed, retention periods, protection and disposal controls, and how data subjects may exercise their rights.

Important notice: This Policy does not constitute general or unlimited consent to all processing activities. Where consent is legally required, the Company will request clear, specific, and separate consent for each purpose and will allow it to be withdrawn in accordance with applicable law.

Identity and Contact Details of the Controller

Al-Itqan International Consulting Company is the controller of the personal data it collects and processes through the website and services covered by this Policy.

Address Kingdom of Saudi Arabia - Riyadh - Al Rawabi District - Imam Al-Shafi'i Road - Short Address RQWA4329
Telephone, Mobile, and Fax +966 56 944 8331

Scope of the Policy

This Policy applies to the main website of Al-Itqan International Consulting Company, contact and quotation-request forms, newsletter subscriptions, and any digital service that expressly states that it is subject to this Policy.

The website may contain links to other platforms or websites, such as Al-Itqan International Training Center, the Al-Itqan System online portal, the customer services platform, or third-party websites. Those platforms are governed by their own published privacy policies unless they expressly state that this Policy applies.

Key Terms

Personal Data Any data, regardless of its source or form, that may specifically identify an individual or make the individual identifiable, directly or indirectly.
Processing Any operation performed on personal data, including collection, recording, storage, organisation, alteration, use, disclosure, transfer, linking, restriction, and destruction.
Data Subject The individual to whom the personal data relates, such as a website visitor, a customer representative, or a newsletter subscriber.
Processor Any entity that processes personal data for and on behalf of the Company and in accordance with its instructions.

Categories of Personal Data We May Collect

The Company collects only the data necessary to achieve the purposes specified in this Policy. Depending on the service used, this may include:

  • Identity and contact data: Full name, email address, telephone or mobile number, and job title if provided by the user.
  • Professional and organisational data: Name of the establishment or entity, professional capacity, business activity, and type of service requested.
  • Enquiry and communication data: Message subject, content, request details, subsequent correspondence, and follow-up outcomes.
  • Quotation request data: Name, telephone number, email address, establishment name, type of quotation, requested services, details of the need, and any attachments the user chooses to submit.
  • Newsletter and direct marketing data: Email address, consent record, subscription preferences, and records of cancellation or consent withdrawal.
  • Account or customer platform data: When using a service covered by this Policy, this may include the email address, authentication information, login records, permissions, and the history of account-related activities.
  • Technical usage data: Internet Protocol (IP) address, browser type, operating system, device and language, pages visited, visit time and duration, referring links, and error and security logs.
  • Cookie data: Session identifiers, language and display preferences, and performance or analytics indicators according to consent settings.
  • Professional or contractual transaction data: Contract, project, invoice, payment, and correspondence data, and information concerning customer representatives, where the relationship develops into the provision of services or a contract.
  • Content authorised for publication: Such as reviews, testimonials, photographs, or media materials, subject to appropriate consent or agreement.
The Company does not ask website visitors to enter sensitive data, identity documents, or data relating to other parties through public forms, except where legally and professionally necessary and after directing them to an appropriate channel. The sender is responsible for having the lawful authority to submit any data relating to another person.

Methods of Data Collection

  • Directly from the data subject when completing the “Contact Us” form, requesting a quotation, subscribing to the newsletter, or creating an account for a service covered by this Policy.
  • Through correspondence and communications initiated by the user with the Company by email, telephone, or official channels.
  • Automatically when the website is used, through server logs, cookies, and similar technologies, depending on the technology and consent settings.
  • From a representative of an establishment or customer who discloses data relating to employees or representatives for contracting or service-delivery purposes, provided that a lawful basis for disclosure exists.
  • From publicly available sources or legally authorised entities, where permitted by law and where collection is necessary for a specific legitimate purpose.

Purposes of Processing and Lawful Bases

The Company processes data for the purpose for which it was collected and only to the extent necessary. Processing relies on one or more appropriate lawful bases, including the data subject’s consent, performance of a contract or taking steps at the data subject’s request before contracting, compliance with a legal obligation, or pursuit of a legitimate interest that does not prejudice the data subject’s rights or interests and does not involve sensitive data.

Responding to enquiries, messages, complaints, and contact requests.
Assessing service requests, preparing quotations, and communicating about them.
Managing customer relationships and delivering contracts, projects, and services.
Managing customer accounts, access, permissions, and technical support.
Sending newsletters or marketing materials after obtaining the required consent.
Operating the website, improving its performance and user experience, and diagnosing faults.
Protecting the website and systems, preventing fraud and misuse, and responding to incidents.
Managing records and complying with legal, regulatory, and accounting obligations.
Establishing transactions and rights and resolving claims and disputes.
Conducting aggregated analytics or statistics that do not identify individuals.

Mandatory and Optional Data

Forms identify mandatory fields, if any, using a clear mark, while providing other data is optional. Failure to provide mandatory data may prevent submission of the form or make it impossible for the Company to respond, prepare a quotation, or provide the requested service.

Subscription to the newsletter and receipt of marketing materials remain optional. Refusing or cancelling them will not result in denial of services unrelated to that purpose.

Cookies and Similar Technologies

The website uses cookies and similar technologies to support operation and security and remember preferences, and it may use analytics or marketing technologies when enabled.

The Company does not treat continued browsing as consent to non-essential cookies. When such cookies are used, the Company provides an appropriate mechanism to accept or reject them, manage preferences, and withdraw consent. Users may also configure their browsers to block or delete certain cookies, noting that this may affect some website functions.

Disclosure of Personal Data

The Company does not sell or rent personal data. It may disclose such data, to the extent necessary and for a specific legitimate purpose, to:

  • Website operation, hosting, and electronic-system providers, including the website-management and technical-services provider (Babil ERP), and support and maintenance providers.
  • Email, newsletter, communications, and customer relationship management providers, where their services are used and to the extent necessary.
  • Consultants, lawyers, auditors, accountants, and other professionals bound by confidentiality.
  • Contractors, experts, or partners whose participation is required by the nature of the service, after applying confidentiality and data-protection controls and defining the scope of disclosure.
  • Government, regulatory, judicial, and law-enforcement authorities where there is a request or lawful basis.
  • Any other party to whom the data subject gives valid and specific consent for disclosure.

When selecting a processor, the Company verifies that it provides sufficient guarantees to protect data and specifies in its agreement the purposes of processing, data categories, duration, confidentiality and security obligations, incident notification, and the handling of sub-processors.

Transfer of Personal Data Outside the Kingdom

Some hosting, email, technical support, or digital-tool services may require data to be processed by a service provider inside or outside the Kingdom. Where this results in transferring personal data outside the Kingdom or disclosing it to an entity abroad, the Company complies with the Personal Data Protection Law and the Regulations on Personal Data Transfer Outside the Kingdom, including determining the purpose and lawful basis, limiting transfer to the minimum necessary, assessing protection levels and risks where required, and applying appropriate safeguards such as standard contractual clauses or other approved mechanisms.

Data Retention and Disposal

The Company retains data for the period necessary to achieve the purpose for which it was collected, for any period required by a lawful basis, or for as long as needed to establish rights or address a claim or dispute.

  • Enquiries and quotations: For the period required to assess the request, communicate, and conduct reasonable follow-up; this period extends in accordance with applicable requirements if the request develops into a contractual relationship.
  • Newsletter and marketing materials: Until consent is withdrawn or the subscription is cancelled, while retaining the minimum information needed to demonstrate cancellation and prevent unwanted re-subscription.
  • Accounts, contracts, invoices, and projects: For the duration of the relationship and thereafter in accordance with legal or professional retention periods and limitation periods.
  • Usage data, security logs, and cookies: For a period proportionate to the operation or security purpose or the stated cookie duration, after which the data is deleted, aggregated, or anonymised.
  • Consent records, rights requests, and privacy incidents: For the period necessary to demonstrate compliance and the required legal response.
When the purpose ends and no lawful basis for retention remains, the Company securely destroys the data in a manner that prevents retrieval or identification of the data subject, or anonymises it so that re-identification is not possible. Some copies may remain temporarily in backups until replaced under the secure backup cycle, while being prevented from use for any other purpose.

Data Security, Confidentiality, and Accuracy

Personal Data Security The Company applies organisational, administrative, and technical measures appropriate to the nature of the data and processing risks. These may include permission management, access restriction, communication protection, backups, system updates, log monitoring, supplier management, awareness, and incident response. No electronic method is entirely risk-free.
Confidentiality of Professional and Third-Party Data Confidential documents, sensitive data, or personal data relating to third parties should not be submitted through public forms unless there is a lawful basis and authority to disclose them and an appropriate secure channel has been agreed with the Company. The Company may request that unnecessary data be removed or redacted.
Data Accuracy and User Responsibility Users must provide accurate, complete, and up-to-date data and update it when it changes. The Company takes reasonable steps to verify accuracy and may request limited information or documents to verify identity or correct data when rights are exercised.

Rights of the Personal Data Subject

Subject to the exceptions and restrictions provided in the Law and its Regulations, the data subject has the following rights:

Right to be informed: To know the lawful basis, purpose, categories, methods of collection and retention, recipients of disclosure, and whether data will be transferred outside the Kingdom.
Right of access: To access the personal data available to the Company in accordance with applicable legal controls.
Right to obtain data: To request a readable and clear copy in a commonly used electronic format where possible.
Right to rectification: To request correction of inaccurate data, completion of incomplete data, or updating of outdated data.
Right to request destruction: To request destruction of data where the legal conditions are met, subject to lawful obligations requiring retention.
Right to withdraw consent: To withdraw consent where it is the sole lawful basis, without affecting the lawfulness of prior processing.
Right to lodge a complaint: To submit a complaint to the Company and then to the competent authority in accordance with applicable procedures and time limits.

How to Exercise Your Rights

The data subject may exercise rights or submit an enquiry or objection through info@itqanconsult.com with “Personal Data Request” in the email subject line, through the “Contact Us” page, or using the contact details set out below.

Request Content Name, contact method, the right to be exercised, and a sufficient description of the relevant data.
Identity Verification Appropriate information may be requested to protect data from unauthorised access, without collecting more than necessary.
Response Period Within no more than 30 days and without delay, in accordance with applicable legal controls.

If implementation requires unexpected or unusual additional effort, or if the Company receives multiple requests from the data subject, the period may be extended by no more than an additional 30 days, provided the data subject is notified in advance of the extension and its reasons.

Withdrawal of Consent and Unsubscription

Consent to processing based on consent may be withdrawn at any time through the email address above or by using the “Unsubscribe” link in marketing messages where available. The minimum necessary data may continue to be retained where another lawful basis exists, such as compliance with a legal obligation or keeping a record demonstrating unsubscription.

Personal Data Breach Incidents

In the event of a breach, unauthorised access, or damage to data, the Company takes the necessary measures to contain and investigate the incident and limit its effects. Where the legal conditions apply, the competent authority will be notified within no more than 72 hours from the time the Company becomes aware of the incident, and the data subject will be notified without undue delay if the incident is likely to cause harm to the data or conflict with the data subject’s rights or interests, together with appropriate information and recommendations.

Data of Children and Persons with Limited or No Legal Capacity

The website is primarily intended for business organisations, professionals, and adults and does not target the collection of children’s data. If a specific service requires processing the data of a person with limited or no legal capacity, the Company obtains the consent of the legal guardian or relies on an appropriate lawful basis and applies the necessary additional safeguards. If data is found to have been collected without a lawful basis, the Company takes appropriate steps to stop processing and destroy it.

Automated Decisions

In its current form, the website does not rely on decisions based entirely on automated processing that produce a legal effect or a similarly significant effect on the user. If such processing is introduced, the Company will update this Policy, provide the necessary information, and obtain explicit consent where required.

External Links and Services

The website may contain links to websites, applications, or services not operated by the Company. The Company does not control their privacy practices, and users should review the relevant entity’s privacy policy before providing personal data. This Policy does not apply to processing carried out by a third party on its own behalf as an independent controller.

Complaints and Competent Authority

The Company invites the data subject first to contact it through info@itqanconsult.com to investigate and address any privacy complaint or observation. If the data subject is dissatisfied with the outcome, a complaint may be submitted to the Saudi Data and Artificial Intelligence Authority, as the competent authority, through the National Data Governance Platform within 90 days from the date of the incident giving rise to the complaint or from the date the data subject became aware of it, unless the competent authority accepts the complaint after that period for reasons it considers appropriate.

Open the National Data Governance Platform

Policy Updates, Applicable Law, and Governing Language

The Company may update this Policy when laws, processing practices, or technical services change. The updated version will be published on this page with the date of the latest update, and an additional notification method may be used if the change is material or requires renewed consent. Amendments take effect from the date stated in the published version without affecting the lawfulness of prior processing.

This Policy is governed by the laws and regulations in force in the Kingdom of Saudi Arabia, particularly the Personal Data Protection Law and its Implementing Regulations. If a translation of this Policy is published, the Arabic version prevails in the event of any discrepancy, unless otherwise required by applicable law.

Privacy Contact

Do you have a request or enquiry concerning your data?

Contact us to exercise a right or submit an enquiry or complaint concerning this Policy or the processing of personal data.

Telephone, Mobile, and Fax +966 56 944 8331
Address Riyadh - Al Rawabi District - Imam Al-Shafi'i Road - RQWA4329
Go to the Contact Us page

Version 1.0 — Effective Date and Last Updated: 26 July 2026