Privacy Statement for Customers
V1.0 – 28-10-2024
Introduction
This Privacy Statement explains how ROSHN Group Company (“ROSHN,” “we,” “our,” or “us”), a national real estate developer one of the Public Investment Fund giga projects that develop integrated living communities, collects, processes, uses, protects, and deletes your personal data. Roshn is committed to complying with the provisions of the Personal Data Protection Law in the Kingdom of Saudi Arabia, issued by Royal Decree No. (M/19) dated 09/02/1443 AH, corresponding to September 16, 2021, as amended by Royal Decree No. (M/147) dated 05/09/1444 AH, corresponding to March 27, 2023, and its implementing regulations when processing your personal data for the purposes outlined in this statement.
This Customer Privacy Statement (“Statement”) applies to individuals residing in the Kingdom of Saudi Arabia ("you" or "your") who are subject to this Statement.
"Personal data" refers to any information relating to you or that allows us to identify you. This includes information such as your name, address, and telephone number.
This Privacy Statement is intended for:
- Our individual customers or clients, and
- Managers, trustees, members, shareholders, employees, partners, and/or controllers of legal entities or partnerships (such as public and private companies, cooperatives, limited liability partnerships, limited partnerships, charities, etc.)
ROSHN collects and processes various categories of your personal data, including identification and identity verification data, contact data, employment data, financial data, biometric and electronic biometric data, civil status data, health data, and any other information necessary to manage our relationship.
We may collect this data directly from you or through third parties. The table below outlines the specific data we collect and the purposes for which we collect it:
Purpose | Legal Basis | Retention Period |
Contract Management | Fulfillment of Contractual Obligation | 10 years after the end of contract validity |
Assessment of Credit Worthiness | Your explicit consent, which you can withdraw at any time without affecting processing carried out on other lawful bases. To do so, you can contact us through the contact information below. | 2 years from date of consent |
Customer Support | Fulfillment of Contractual Obligation | 2 years after the support request |
Digital Platform Usage | Fulfillment of Contractual Obligation | 2 years after deactivation of account |
License Issuance | Legal Obligation | 10 years after the end of relationship |
Internal Control and Audit | Legitimate Interest | 10 years after the end of relationship |
Internal Reporting | Legitimate Interest | 10 years after the end of relationship |
Payment Processing | Fulfillment of Contractual Obligation | 10 years after the end of contract validity |
Property Handover | Fulfillment of Contractual Obligation | 10 years after the end of contract validity |
Property Reservation | Fulfillment of Contractual Obligation | 10 years after the end of relationship |
Advertising & Marketing | Your explicit consent, which you can withdraw at any time without affecting processing carried out on other lawful bases. To do so, you can contact us through the contact information below. | 2 years from date of consent |
Use of any photographs, audio recordings, audio-visual recordings, video clips, or the like of you, or images taken of you by us or any third party while you are attending Roshn Company events, for marketing or business development purposes. | Your explicit consent, which you can withdraw at any time without affecting processing carried out on other lawful bases. To do so, you can contact us through the contact information below. | 2 years from the date of consent |
To the extent that any personal data we collect includes sensitive personal data, such as data relating to racial or ethnic origin, religious or philosophical beliefs, political opinions, security and criminal data, biometric data used for identification purposes, genetic data, health data, or data indicating a person's status as an orphan, we will only process such data with your explicit consent.
Sharing Data with Controllers and Processors
ROSHN Group may share the personal data it collects with trusted suppliers, service providers, and subcontractors carefully selected to process data on ROSHN’s behalf. ROSHN ensures that sharing personal data with any third party we deal with (controllers or processors) is based on legal grounds. While disclosure will generally be based on your consent as outlined in this statement, disclosure may occur without your consent if the personal data was collected from a publicly available source, or if the party requesting disclosure is a government entity and the collection or processing of the personal data is necessary for public interest, security purposes, legal enforcement, or to comply with court orders. Disclosure may also occur without your consent if it is necessary to protect public health, public safety, or the life or health of specific individuals. Additionally, disclosure without consent is possible if it is limited to further processing in a way that makes it impossible to identify you directly or indirectly, or if it is necessary to achieve our legitimate interests, provided that the disclosed information does not include any sensitive data.
Data Storage and Disposal
All collected data is securely stored using the highest security standards to protect against unauthorized access, modification, or disclosure. We retain your personal data only for as long as necessary to fulfill the purposes for which we collected it or as required by law. Once the purposes are fulfilled and the need has lapsed, your personal data will be securely disposed of in accordance with applicable regulations and best practices. We will delete or de-identify your personal data as soon as the purpose for its collection has been fulfilled or the legal requirements to retain it have expired to prevent its reconstruction or retrieval.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data; the potential risks of unauthorized use or disclosure of your personal data; the purposes for which we process your personal data and whether we can achieve those purposes through other means; and applicable legal requirements.
Maintaining the Confidentiality of Your Personal Data
Roshn is committed to taking the necessary administrative, technical, and regulatory measures to protect your personal data from leakage, damage, or unauthorized access. In addition, the sharing of your personal data will be limited to authorized employees and any other third party under the purposes described in this Customer Privacy Statement. Accordingly, they will be obligated to take all measures stipulated herein to ensure the protection of your personal data. Roshn has also developed internal procedures to deal with any suspected breach of your personal data. Accordingly, regulatory authorities and data subjects will be notified if there is a legal obligation to do so.
Your Rights Under the Personal Data Protection Law
Under the Personal Data Protection Law, you have the following rights, which depend primarily on the purpose for which we collect and process your personal data:
- Right to be Informed: This includes informing you about the legal basis for collecting your personal data, how it is processed, stored, and deleted, and to whom it will be disclosed.
- Right of Access to Your Personal Data: You have the right to request a copy of your personal data from us via the email address provided below.
- Right to Request a Copy of Your Personal Data: You have the right to request your personal data available with the controller in a readable and clear format whenever technically feasible.
- Right to Request Correction, Completion, or Update of Your Personal Data: You have the right to request the correction of your personal data that you believe is inaccurate, incorrect, or incomplete.
- Right to Request the Deletion of Your Personal Data: You have the right to request the deletion of your personal data unless it conflicts with legal justifications and the rules regarding the right to deletion.
Right to Withdraw Your Consent to the Processing of Your Personal Data: You have the right to withdraw your consent to the processing of your personal data – at any time – unless there are legal justifications that require otherwise.
Except as otherwise provided by law, you will not be required to pay any fees for exercising these rights. If a request is made to exercise any of these rights, you will be responded to within thirty days from the date of receipt of the complete request.
Direct Marketing and Advertisements
We will not process sensitive data for marketing purposes under any circumstances.
Direct Marketing
Any personal data we use for marketing purposes will be collected directly from you and processed for direct marketing purposes based on your prior consent (for example, via email, text messages, or automated calls), without prejudice to your right to object or withdraw consent to receive communications for direct marketing purposes at any time through [Add Mechanism]. In this case, we will endeavor to fulfill your request without undue delay on our part.
Advertisements
We will request your consent before sending you any advertising and awareness materials in cases where there is no prior interaction between us and you. As with direct marketing, we will provide you with a free mechanism to object or withdraw consent from receiving advertising materials in an easy and simplified manner. If you object or request to withdraw consent regarding receiving advertising materials from us, we will stop sending these materials immediately.
Amendments to this Statement
We may update or amend this Privacy Statement from time to time to reflect changes in our practices or for legal or regulatory reasons. You are advised to visit our website regularly for any amendments. You will be notified of any amendments to this Privacy Statement through updates available on our website.
Contact Us
If you have any questions about this Privacy Statement or if you would like to claim any of your data rights, you can contact our Data Privacy Office via:
- Email address: [email protected]
- Phone number: 920022288
In the event that the problem is not resolved or a response is not received within thirty working days, you can file a complaint with the Saudi Authority for Data and Artificial Intelligence through the National Data Governance Platform, which can be accessed through this link: National Data Governance Platform (sdaia.gov.sa)