شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Privacy

Privacy policy

This notice explains what personal data we collect through datasec.sa, why, who we share it with, how long we keep it and your rights under the Personal Data Protection Law (PDPL).

Last updated: 2 October 2026

Who we are (the controller)

The controller of the personal data collected through this website is Data Security for Cyber Security (DataSec), a Saudi company within the EXA Information Technology group whose activity is providing cybersecurity and IT services.

  • Commercial registration: 1010752666.
  • Unified establishment number: 7026307020.
  • Address: 3173 Al Abbas Ibn Abdulmutalib, At Taawun, Riyadh 12475, Kingdom of Saudi Arabia.
  • Contact, including privacy requests: info@datasec.sa, mobile and WhatsApp +966 59 750 4669.

This notice applies to datasec.sa and its forms only. Services we deliver to clients under contract are governed by each contract's data-processing agreement, and this website holds no operational client data.

What we collect and why

We collect data directly from you through the website's forms and indirectly through operational logs. Mandatory fields are marked on each form; everything else is optional.

Service and consultation requests

  • Data: name, job title, work email, mobile number, organisation, sector, description of the request, an RFP file if you attach one and your preferred contact channel.
  • Purpose: responding to your request, preparing a proposal and communicating with you about it.

General contact form

  • Data: name, email, mobile number if entered and the message text.
  • Purpose: responding to your enquiry.

Job applications

  • Data: CV, name, contact details, experience, your answers to role questions and your optional consent to join the talent network.
  • Purpose: assessing your application for the role you applied to. Details are in the candidate privacy notice.

Talent network

  • Data: the same application data, under a separate, unticked consent.
  • Purpose: contacting you about suitable roles in the future.

Data-subject requests

  • Data: name, email, request type and what is needed to verify your identity.
  • Purpose: verifying your identity, fulfilling your request and evidencing completion.

Website analytics

  • We use no analytics or visitor-tracking tools on this website.

Security logs

  • Data: a salted hash of the IP address, request time, path and browser type.
  • Purpose: protecting the site from abuse and automated attacks. The IP address is never stored in its original form.

Cookies

The public website uses no tracking or advertising cookies. Only cookies strictly necessary for the site to work, such as your language preference, may be used. Staff accounts in the admin console use necessary session cookies.

Who we share your data with

We do not sell your data or share it for third-party marketing. We share it with the following processors, to the extent needed for each purpose and under data-processing agreements:

  • Zoho CRM: managing service requests and the commercial relationship. Service-request data is transferred to our customer relationship management system to follow up on your request.
  • Microsoft 365: internal email and the notification and confirmation messages we send you.
  • LeaseWeb: the data-centre provider hosting the company server in the Netherlands, which runs the website and holds private files (CVs and attachments). DataSec's own team runs the server.
  • Neon: the website database, in Frankfurt, Germany.
  • Cloudflare: delivering the website and protecting it from attacks. Connections to the site pass through its network encrypted, and it keeps no copy of the site's pages or form data.
  • Anthropic (AI API): when automated CV reading is enabled in the recruitment system, the CV text is sent with identity fields removed to extract professional information, and the data is not used to train models. The output is advisory and a human decides.
  • Recruitment system (Zoho Recruit) when in use: managing applications and candidate communication.
  • WhatsApp (Meta): only if you choose to be contacted on WhatsApp, the conversation passes through Meta's servers outside the Kingdom.
  • Competent authorities: where the law requires disclosure.

None of these receives more data than its role requires, and none uses it for its own purposes.

Transfers outside the Kingdom

Website data is hosted in the European Union: the server and private files in the Netherlands, and the database in Frankfurt, Germany. Some of the processors listed above may process data outside the Kingdom. For these transfers we apply what the Regulation on Personal Data Transfer Outside the Kingdom, issued by SDAIA, requires:

  • A documented transfer risk assessment that is reviewed periodically.
  • Contractual clauses with each processor covering security, confidentiality, deletion at the end of the contract and the list of sub-processors.
  • Data minimisation: we collect no national ID numbers or sensitive data through the website.
  • All website components hosted in the European Union (the Netherlands and Germany).

We re-evaluate in-Kingdom hosting as suitable options become available with the current providers or with a cloud provider licensed in the Kingdom.

Retention periods

We keep data for as long as the purpose requires and then delete or anonymise it automatically:

  • Service and contact requests not converted to a contract: 24 months from the last contact.
  • Service requests converted to a contract: the term of the contract plus the statutory retention of commercial records.
  • Job applications: 12 months from the last activity on the application, after which the data is anonymised and the CV deleted. Data of hired candidates moves to the employee file.
  • Talent network: 24 months from the date of consent, unless you withdraw it earlier.
  • Data-subject requests and their completion record: five years, per the processing-records requirement.
  • Security logs (hashed IP addresses): the period needed to detect and investigate abuse, then deleted.

Deletion extends to copies held by processors under the processing agreements, allowing for backups that are overwritten in their normal cycle.

Your rights

The Personal Data Protection Law gives you the following rights, which we enable you to exercise free of charge:

  • To be informed: to know what we collect and why, which this notice explains.
  • Access: to obtain a copy of the personal data we hold about you.
  • Correction: to correct, complete or update inaccurate data.
  • Destruction: to request deletion of your data when the purpose no longer applies or consent is withdrawn, unless the law requires retention.
  • Withdrawal of consent: at any time, without affecting earlier processing.
  • Objection: to processing based on legitimate interest, and to marketing messages at any time.

We respond to verified requests within 30 days of receipt, as the Implementing Regulations require. If a request is complex or requests are numerous, we may extend the period once after informing you of the reason.

If you are not satisfied with how we handled your request, you have the right to lodge a complaint with the Saudi Data and AI Authority (SDAIA) as the competent authority.

How to exercise your rights

Use the "Request about my data" form on this page to submit an access, correction, deletion, consent-withdrawal or objection request. You can also write to info@datasec.sa from the email address you used with us.

  • We verify your identity before acting, to protect your data, and may ask for additional information for that purpose only.
  • You will receive a confirmation that the request was received, then a reply with the outcome.
  • To withdraw consent to update messages, use the unsubscribe link in any message.

Request about my data

Use this form to exercise your rights under the Personal Data Protection Law. We respond within the statutory period after verifying your identity.

How we protect your data

  • Encrypted connections to the site over HTTPS, and the database encrypted at rest.
  • Attached files kept on the company server in private storage that cannot be reached by a public link, opened only by authorised staff through the admin console.
  • IP addresses stored only as salted hashes.
  • An append-only audit log of every view, export or deletion performed by our staff.
  • Two-step verification for staff accounts and role-based permissions.
  • Network protection through Cloudflare, and rate limits on forms.
  • Automatic deletion when retention periods end.

More detail is available in the trust centre.

Data breach notification

If your personal data is leaked, destroyed or accessed unlawfully, we notify the Saudi Data and AI Authority within 72 hours of becoming aware of the incident, as the PDPL Implementing Regulations require, and we inform you without undue delay if the incident may cause harm to you or your data, explaining what happened, what we did and what we advise you to do.

Children

This website is intended for organisations and professionals and is not directed at persons under 18. We do not knowingly collect data from minors, and if we learn that a minor's data was collected without a guardian's consent we delete it.

Changes to this notice

We review this notice whenever our processing or the law changes, and we publish every substantive change here with its date. The date at the top of the page is the last update.

  • 2026-10-02: first version of this notice, published with the new website.