Privacy Policy
First draft — pending legal review, not yet approved
This policy describes how Fursan Al-Amn Security Company ("the Company", "we") collects, processes, and protects personal data through its website and the Client & Guard digital portal, in line with Saudi Arabia's Personal Data Protection Law (PDPL) and its implementing regulations.
By using this website or portal, you acknowledge that you have read this policy. If you have any questions, please contact us using the details at the end of this page.
1. Data We Collect
We collect the following categories of data depending on how you interact with us:
- Consultation request form data: full name, organization name (if any), phone number, email, sector, and any additional details you provide.
- Client/Guard portal account data: name, email, role (client or guard), and related operational data (secured sites or shifts).
- Authentication data: your password (stored as a bcrypt hash, never in plain text), and your two-factor (TOTP) secret when enabled (stored encrypted with AES-256-GCM).
- Technical security logs: IP address, timestamp, and event type (e.g. sign-in or a failed sign-in attempt), used solely for security and audit purposes.
- General contact details when you reach out to us directly by phone or email.
2. Purposes of Processing
- Providing our security services and responding to consultation requests.
- Creating and managing Client/Guard portal accounts and showing each user the operational data within their permissions.
- Protecting the website and portal from abuse, through rate limiting, temporary account lockout after repeated failed sign-in attempts, and two-factor authentication.
- Complying with regulatory obligations tied to our first-category security licensing.
- Improving the quality of our digital services based on actual platform usage.
3. Legal Basis for Processing
We process your data based on one or more of the following: performance of a contract with you or your organization, your explicit consent when submitting a consultation request, our legitimate interest in protecting our systems and users, or compliance with an applicable legal or regulatory obligation.
4. Data Sharing and Disclosure
We do not sell or rent your personal data to any third party for marketing purposes.
We may share your data with trusted technical service providers (such as our cloud hosting provider) to the extent necessary to operate the website and portal, and under contractual data-protection obligations.
We may disclose your data where required by applicable law or a competent authority's order.
5. Data Retention
We retain your data for as long as necessary to fulfil the purposes described above, or as required by law, whichever is longer. Unactioned consultation requests and inactive account data are periodically deleted per the Company's internal retention policy.
6. Security Measures
We apply a set of technical controls to protect your data, including:
- Encryption of sensitive fields (such as contact details and the two-factor secret) with AES-256-GCM at rest.
- Password hashing with bcrypt — no employee can view your actual password.
- Optional two-factor authentication (MFA) via standard authenticator apps (TOTP).
- Sign-in rate limiting and temporary account lockout after repeated failed attempts.
- An audit log recording sensitive sign-in and access events for security review.
7. Your Rights Under the PDPL
Under the Personal Data Protection Law and its implementing regulations, you have the right to:
- Request access to the personal data we hold about you.
- Request correction of any inaccurate or incomplete data.
- Request deletion or destruction of your data once the purpose for collecting it no longer applies, within the cases permitted by law.
- Withdraw your consent to processing at any time, without affecting the lawfulness of processing carried out before the withdrawal.
- Lodge a complaint with the Saudi Data & AI Authority (SDAIA) if you believe we have breached our obligations under the law.
8. Cookies
The website uses a single essential cookie for the Client/Guard portal sign-in session. It is required for the portal to function and is not used for marketing or advertising tracking.
9. Children's Privacy
Our digital services are not directed at minors, and we do not knowingly collect personal data from individuals under the legal age without parental consent.
10. Changes to This Policy
We may update this policy from time to time to reflect changes in our services or in legal requirements. Any update will be posted on this page along with its last-updated date.
11. Privacy Contact
For any question about this policy, or to exercise any of your rights, please contact us at: info@fursanalamn.com or +966 11 494 3628.
