JALTech JALTech
JALTech JALTech
  • Home
  • Privacy Policy
  • Your Rights
  • Contact
Contact Us
Personal Data Protection

Privacy Policy

This Policy explains how JALTech collects, uses, discloses, stores, transfers, secures, and destroys personal data, and how individuals may exercise their privacy rights.

Last updated: 27 July 2026 Saudi PDPL aligned Privacy and data protection
On this page
  • Introduction
  • Our Privacy Role
  • Data We Collect
  • Collection Methods
  • Purposes & Legal Bases
  • Cookies & Logs
  • Disclosure
  • Storage & Transfers
  • Retention & Destruction
  • Security
  • Your Rights
  • Rights Requests
  • Children
  • Contact & Complaints

JALTech respects and protects the privacy of website visitors, users, customers, client personnel, campaign participants, and other individuals whose personal data we process.

This Privacy Policy is intended to satisfy transparency requirements under applicable privacy and data-protection laws, including the Kingdom of Saudi Arabia Personal Data Protection Law issued by Royal Decree No. M/19, as amended by Royal Decree No. M/148, its Implementing Regulations, and the Regulation on Personal Data Transfer Outside the Kingdom (collectively, the “PDPL”).

This Policy applies to personal data collected through jaltech.org, JALTech applications and services, business communications, client projects, promotional platforms, and other authorised channels that link to or refer to this Policy.

01 JALTech’s Privacy Role

JALTech may process personal data in different capacities:

  • Data Controller: JALTech acts as the controller when it determines why and how personal data is processed, including for this website, enquiries, business relationships, recruitment, accounts, billing, security, analytics, and JALTech’s own services.
  • Data Processor: JALTech may act as a processor when it develops, hosts, supports, or operates an application, platform, digital campaign, or service on behalf of a client that determines the purposes and means of processing. In that situation, the client is generally the controller and its privacy notice also applies.

Where JALTech processes personal data solely on a client’s documented instructions, requests relating to that data may need to be directed to, or coordinated with, the relevant client.

02 Key Definitions

Personal Data
Any data, regardless of its source or form, that identifies an individual directly or indirectly.
Processing
Any operation performed on personal data by automated or manual means, including collection, recording, storage, use, disclosure, transfer, alteration, retrieval, restriction, or destruction.
Data Subject
The individual to whom personal data relates, or their authorised representative or legal guardian where applicable.
Sensitive Data
Personal data classified as sensitive under applicable law, including certain health, genetic, biometric, religious, criminal, or financial-credit information.

03 Personal Data We Collect

The personal data collected depends on how you interact with JALTech and the service involved. We apply data-minimisation principles and seek to collect only data that is adequate, relevant, and necessary for a stated purpose.

  • Identity and contact data: name, username, company, job title, postal address, email address, telephone number, and other contact details.
  • Account and authentication data: account identifiers, login records, access rights, authentication events, and security information.
  • Business and project data: organisation details, project requirements, contracts, communications, support requests, meeting records, files, and other information provided during a business relationship.
  • Payment and transaction data: billing details, transaction references, payment status, and tax or accounting information. Payment-card information may be processed directly by an authorised payment provider rather than stored by JALTech.
  • Campaign and application data: registration information, eligibility data, receipt or document uploads, entries, preferences, responses, reward-delivery information, and other data required by a client-authorised service or campaign.
  • Technical and usage data: IP address, device identifiers, browser type, operating system, language, time zone, referring and exit pages, date and time, clickstream, application events, crash logs, and security logs.
  • Communications: messages, enquiries, feedback, attachments, and records of correspondence with JALTech.
  • Marketing preferences: consent records, subscription preferences, opt-outs, and communication choices.

JALTech will not intentionally collect sensitive data unless it is necessary for a specific lawful purpose and the required legal basis, safeguards, notices, and explicit consent are in place.

04 How We Collect Personal Data

Directly from you

We may collect personal data when you visit or use our website or applications, create an account, submit a form, contact us, attend a meeting, sign a contract, request support, participate in an authorised campaign, provide documents, apply for a role, or otherwise communicate with JALTech.

Automatically

We may collect technical, usage, security, and analytics information through server logs, cookies, software development kits, pixels, tags, and similar technologies when you access our websites, applications, or services.

From clients and authorised third parties

We may receive personal data from enterprise clients, business partners, service providers, identity or payment providers, event organisers, public sources, or other authorised parties where lawful and relevant to the service.

Mandatory and optional information

Fields marked as required are necessary to provide the requested service, fulfil a legal or contractual requirement, or protect the service. If required information is not provided, JALTech may be unable to process a request, provide a service, create an account, or complete a transaction. Optional fields may be left blank.

05 Purposes and Legal Bases

JALTech processes personal data only for specific, clear, and lawful purposes. Depending on the context, the legal basis may be consent, performance of an agreement, compliance with a legal obligation, protection of a vital interest, a legitimate interest that does not override the data subject’s rights, or another basis permitted by the PDPL.

  • Providing services and performing agreements: to create and manage accounts, deliver software and professional services, operate applications or campaigns, process transactions, provide support, and fulfil contractual obligations.
  • Responding to enquiries: to communicate with you, answer questions, arrange meetings, prepare proposals, and manage business relationships.
  • Administration and records: to maintain financial, accounting, contractual, audit, and operational records.
  • Security and fraud prevention: to authenticate users, manage access, monitor systems, detect misuse, investigate incidents, prevent fraud, and protect individuals, JALTech, clients, and services.
  • Service improvement and analytics: to understand use, diagnose issues, measure performance, improve usability, develop features, and generate aggregated or anonymised insights.
  • Legal and regulatory compliance: to comply with applicable laws, lawful requests, court orders, regulatory duties, and the establishment, exercise, or defence of legal claims.
  • Direct marketing: to send promotional communications only where the required consent has been obtained. Each message will identify the sender and provide a simple, free method to withdraw consent or unsubscribe.

Withdrawing consent does not affect processing already lawfully performed before withdrawal and does not prevent processing that continues under another lawful basis.

06 Cookies, Log Files, Analytics, and Crawlers

JALTech may use cookies and similar technologies that are strictly necessary for security, session management, preferences, functionality, performance, and analytics. Where required, non-essential cookies will be used only after consent is obtained.

Server logs may record IP address, browser and device information, internet service provider, date and time, referring and exit pages, page interactions, and security events. This information is used to administer systems, detect threats, investigate faults, analyse trends, and understand aggregated usage.

Public pages may be indexed by search engines such as Google, Bing, or DuckDuckGo. Analytics services, including Google Analytics or Google Tag technologies where enabled, may process technical and usage data according to their own privacy terms and JALTech’s configured controls.

You may manage cookies through your browser or device settings. Disabling necessary cookies may prevent parts of a website or application from functioning correctly.

07 Disclosure and Sharing

JALTech does not sell personal data. Personal data may be disclosed only when lawful, necessary, and proportionate to the stated purpose, and only to the minimum extent required.

  • Clients: where JALTech operates a service or campaign for a client, relevant data may be made available to that client in accordance with the applicable agreement and privacy notice.
  • Authorised processors and service providers: cloud hosting, databases, communications, analytics, security, support, document storage, payment, reward fulfilment, and professional service providers that process data under appropriate contractual and confidentiality obligations.
  • Professional advisers: auditors, accountants, insurers, legal advisers, and consultants where necessary.
  • Corporate transactions: parties involved in a merger, acquisition, financing, reorganisation, or transfer of business, subject to lawful safeguards.
  • Authorities and legal recipients: regulators, courts, law-enforcement bodies, public authorities, or other recipients where disclosure is required or permitted by law.

JALTech records and controls disclosures where required, evaluates recipient necessity, and requires recipients to protect personal data and use it only for authorised purposes.

08 Data Storage, Hosting, and International Transfers

JALTech and its authorised providers may store and process personal data in the Kingdom of Saudi Arabia, Bahrain, Malaysia, or other approved locations depending on the service, client requirements, hosting architecture, and applicable data-residency obligations.

Where personal data subject to the PDPL is transferred or disclosed outside the Kingdom of Saudi Arabia, JALTech will make the transfer only where permitted by the PDPL and the Regulation on Personal Data Transfer Outside the Kingdom. Appropriate safeguards may include an adequacy basis, an applicable exemption, approved standard contractual clauses, binding common rules, transfer risk assessments, contractual controls, data minimisation, encryption, and access restrictions.

Information about the general geographical scope of processing may be requested through the contact channel below. Additional service-specific information may also be provided at the point of collection or in a client’s privacy notice.

09 Retention and Secure Destruction

JALTech retains personal data only for the period necessary to achieve the purpose for which it was collected, satisfy contractual and client instructions, maintain required business records, resolve disputes, enforce agreements, prevent fraud, and comply with legal or regulatory obligations.

Retention periods are determined using criteria including the type and sensitivity of the data, the service or campaign duration, the client’s documented instructions, the limitation period for claims, security needs, and applicable laws.

For client campaigns and activities, personal data is generally scheduled for secure deletion or irreversible anonymisation within 30 days after completion of the relevant activity, unless the client, reward process, contract, dispute, investigation, or applicable law requires a longer period.

When retention is no longer required, JALTech securely destroys, deletes, overwrites, or anonymises personal data so that it cannot reasonably be reconstructed. Where deletion from backups cannot occur immediately, the data is isolated from further use and removed through the normal secure backup lifecycle.

10 Security and Personal Data Breaches

JALTech applies reasonable and appropriate organisational, administrative, and technical measures proportionate to the nature, sensitivity, volume, and risks of the personal data processed. Measures may include:

  • segregated application environments and databases where appropriate;
  • encryption in transit using HTTPS/TLS and encryption at rest where supported;
  • role-based access control, least-privilege access, authentication, and account-management controls;
  • audit logging, monitoring, vulnerability management, backups, and recovery procedures;
  • confidentiality obligations, personnel awareness, supplier due diligence, and contractual safeguards;
  • incident response, containment, investigation, remediation, and lessons-learned procedures.

If a personal data breach subject to the PDPL may harm personal data or a data subject, or conflict with their rights or interests, JALTech will notify the competent authority within the legally required period, including within 72 hours of awareness where applicable. Affected data subjects will be notified without undue delay when required by law.

11 Your Rights Under the PDPL

Subject to the PDPL, its exceptions, and verification of identity, data subjects may have the following rights:

  • Right to be informed: to know the legal basis and purpose of collection, the data collected, how it is processed, stored, destroyed, and disclosed, and whether it may be transferred outside the Kingdom.
  • Right of access: to access personal data held by JALTech where the applicable conditions are satisfied.
  • Right to obtain a copy: to receive personal data in a clear, readable, and commonly used format where technically feasible and legally permitted.
  • Right to correction: to request correction, completion, or updating of inaccurate, incomplete, or outdated personal data.
  • Right to destruction: to request destruction of personal data that is no longer necessary, where the legal conditions are met and no lawful retention requirement applies.
  • Right to withdraw consent: to withdraw consent at any time where consent is the basis for processing.
  • Right to complain: to submit a complaint concerning application of the PDPL to JALTech and, where appropriate, to the Saudi Data & AI Authority (SDAIA).
  • Right to claim compensation: to seek compensation for material or moral harm resulting from a violation, as permitted by applicable law.

These rights are not absolute and may be restricted where permitted or required by law, including to protect the rights of others, confidential information, legal claims, security, or regulatory obligations.

12 Exercising Your Rights

To exercise a privacy right, submit a request through the JALTech contact channel identified below and clearly state:

  • your name and contact details;
  • the service, website, application, client project, or campaign concerned;
  • the right you wish to exercise and the personal data involved;
  • any information reasonably needed to verify your identity and locate the relevant records.

JALTech will act on a valid PDPL rights request without undue delay and normally within 30 days. Where implementation requires unexpected or disproportionate effort, or multiple requests are received, the period may be extended by up to an additional 30 days, and the requester will be informed of the extension and reasons.

JALTech generally does not charge a fee for exercising PDPL rights. A request may be refused or limited where it is repetitive, manifestly unfounded, requires disproportionate effort, cannot be verified, or another lawful restriction applies. JALTech will provide the reason where legally required.

13 Direct Marketing

JALTech will process personal data for direct marketing only after obtaining the consent required by law. At the time consent is requested, JALTech will identify the relevant data and marketing purpose.

Every direct-marketing message will clearly identify JALTech and include a simple, fast, and free method to withdraw consent or unsubscribe. JALTech will maintain appropriate consent records and stop direct-marketing communications without undue delay after a valid opt-out.

14 Children and Persons Lacking Legal Capacity

JALTech’s general business website and services are not directed to children. JALTech does not knowingly collect personal data from a child or a person who fully or partially lacks legal capacity without the involvement and legally valid authorisation of a parent, legal guardian, or authorised representative where required.

If you believe that personal data has been provided without appropriate authorisation, contact JALTech so that the circumstances can be investigated and the data restricted or destroyed where required.

15 External Websites and Third-Party Services

JALTech websites and applications may link to external websites, social networks, payment providers, reward providers, or third-party services. JALTech does not control those parties’ independent processing activities. Their privacy notices apply when you interact directly with them.

You should review the privacy information of each external service before providing personal data. A link does not imply that JALTech is responsible for the external service’s content, security, availability, or privacy practices.

16 Policy Updates

JALTech may update this Privacy Policy to reflect changes in law, regulatory guidance, technology, services, business operations, or data-processing practices. The revised Policy will be published on this page with an updated revision date.

Where a material change requires additional notice or consent, JALTech will provide that notice or obtain consent through an appropriate channel before the new processing begins.

17 Contact, Privacy Requests, and Complaints

For privacy enquiries, consent withdrawal, rights requests, or complaints, contact the JALTech Privacy Team through the official contact channel below. Where JALTech is acting solely as a processor, your request may be referred to the relevant client controller.

JALTech Privacy Team

Website: jaltech.org/#contact
Address: No. 16, Plaza Sentul 10, Jalan Sinar Sentul, Kuala Lumpur 51100, Malaysia

Submit a Request

Complaints to the Saudi authority

If your concern relates to personal data subject to the Saudi PDPL and you are not satisfied with JALTech’s response, you may submit a complaint to the Saudi Data & AI Authority (SDAIA) through the National Data Governance Platform at dgp.sdaia.gov.sa, subject to the procedures and time limits prescribed by law.

© JALTech | All rights reserved
Home Privacy Policy Privacy Rights Contact