Privacy Notice
InnovWayz Technologies Company is a provider of IT services and consulting solutions.
By accessing or using InnovWayz's services, you acknowledge and agree to the practices described in this Privacy Notice. If you have any inquiries or require further information regarding our privacy practices, you may contact us at the contact details provided below.
Contact Details
Involved Department/Team:
Legal Department
Address:
Office # 2, Building # 9353
Shaddad Al Fahri Street,
AL MALAZ District
Riyadh, Saudi Arabia
12642
Phone Number: +966 11 400 1502
E-mail: dataprotection@innovwayz.com
Date of Last Update
The Privacy Policy was last updated on September 15, 2024
1. What is the purpose of this Privacy Notice?
This Privacy Notice informs you how InnovWayz Technologies, as the controller of your personal data, manages, protects, and processes your personal data. It applies to all personal data collected via our website, business interactions, or through other interactions for our IT services and consulting solutions.
We adhere to transparency and safeguard the rights of our clients, partners, employees, and vendors, complying with the Kingdom of Saudi Arabia’s Personal Data Protection Law, enacted by Royal Decree No. (M/19) on 16/09/2021 and amended by Royal Decree No. (M/148) on 27/03/2023.
2. Who is the Controller of your Personal Data?
InnovWayz Technologies is the legal entity responsible for the collection, use, and protection of your personal data. As the data controller, we determine the purposes and means of processing your personal data.
3. What Personal Data do we collect about you?
At InnovWayz, we collect specific personal data from our clients, employees and other stakeholders, such as:
-
From Clients, Business Partners and Third-Party Vendors
-
Personal Information: Names, email addresses, phone numbers, physical addresses, job titles, and organization details.
-
Professional Information: Job titles, roles within the organization, and professional qualifications.
-
Service and Interaction Details: Information related to personal data shared during service provision, such as performance feedback, communication logs, and technical support requests from clients and employees.
-
Online Interaction Data: This includes browsing history, preferences, cookie consent, and interactions with our digital platforms, as well as device information such as the types and specifications of devices used.
-
From Employees
-
Personal Information: Names, email addresses, phone numbers, national identification numbers, home address, gender, age, nationality, etc.
-
Dependents Information: Information related to dependents of employees, such as names, dates of birth, iqama, health information, gender, age, nationality. Health Info
-
Employment Data: CVs, Employment history, job titles, performance metrics, training records, etc.
-
Legal Identifiers: Iqama numbers, passport details, visa information.
-
Sensitive Data: Health data used for insurance and medical benefits administration.
-
Financial Information: Bank details and payment information for payroll and billing purposes.
-
Legal Data: Contracts, compliance documentation, and any other legal agreements or documentation required for employment.
-
Security Information: CCTV footage in our premises, to ensure the safety and security of employees and visitors.
Methods of Data Collection
InnovWayz employs multiple methods to collect personal data, ensuring accuracy and compliance with legal regulations:
-
Direct Collection: Through interactions with our website, services, communications, and during onboarding or project engagements.
-
Automated Collection: Using cookies to gather information about your interaction with our website and services.
-
Third-Party Sources: We may receive your personal data from business partners, public databases, and third-party vendors to support and improve the services we provide. This includes information obtained through marketing activities.
4. How do we use your Personal Data?
InnovWayz uses the personal data we collect for the following purposes, aligned with our operational, regulatory, and strategic goals:
-
Service Delivery and Project Management: To effectively deliver our IT services and consulting solutions, ensuring project milestones are met and client expectations are fulfilled.
-
Security and System Integrity: To protect our IT infrastructure and ensure the security of client data and our systems through appropriate measures, including monitoring and safeguards.
-
Marketing and Client Communications: To send relevant communications regarding our services, industry updates, and offers.
-
HR Management and Employment Processing: We use employee data for HR functions such as recruitment, onboarding, payroll processing, and performance management, as well as to administer employment benefits, such as health insurance and travel allowance.
-
Operational Excellence and Legal Compliance: We use your data to optimize service efficiency, manage employment contracts, and ensure compliance with labor laws, tax regulations, and other legal obligations.
-
Security and Safety: To ensure the safety of our employees and visitors, we use CCTV footage to monitor our premises.
5. Legal Bases for Processing your Data
InnovWayz processes personal data based on several legal grounds to ensure compliance with the law:
-
Consent: We obtain explicit consent for certain processing activities, especially those not directly related to the fulfillment of contracts or legal obligations.
-
Contractual Necessity: Data is processed as necessary for the performance of a contract to which you are a party, or to take steps at your request before entering into a contract.
-
Legal Obligation: Processing necessary to comply with our legal obligations, including but not limited to labor, tax and corporate laws.
-
Legitimate Interests: We process personal data based on our legitimate business interests, such as ensuring network and information security, optimizing service delivery, and managing our business operations, provided that such processing does not override your rights and freedoms.
-
Vital Interests: In rare cases, we process personal data to protect the vital interests of individuals, such as in medical emergency situations.
6. How do we protect your Personal Data?
At InnovWayz, safeguarding your personal data is a priority we take very seriously. We are committed to implementing comprehensive security measures—both technical and organizational—to protect your data from unauthorized access, alteration, and misuse.
Technical Security Measures:
-
Storage Encryption: All sensitive personal data transmitted to and stored on our systems is encrypted using advanced encryption technologies.
-
Access Controls: We strictly limit access to personal data to authorized personnel only, based on their role and necessity to engage with the data.
-
Secure Infrastructure: Our network and data storage solutions are protected with industry-standard firewall and antivirus software, alongside intrusion detection systems to prevent unauthorized access.
-
Security Assessments: We conduct periodic security assessments and penetration testing to identify and address potential security vulnerabilities.
Organizational Security Measures:
-
Data Privacy Policies and Training: We enforce comprehensive data privacy policies and ensure that all employees are trained regularly on the importance of personal data protection and security best practices.
-
Confidentiality Agreements: All our employees, contractors, and third-party service providers are required to sign confidentiality agreements that bind them to maintain the secrecy and security of all personal data.
-
Physical Security: Our facilities are secured with ID cards and constant surveillance to ensure that only authorized personnel can access data sensitive areas.
-
Vendor Management: Third-party vendors are rigorously screened and bound by contracts that enforce our data protection standards.
7. Who do we share your Data with?
InnovWayz shares your personal data with specific categories of recipients to facilitate business operations and comply with legal requirements:
-
Clients and Business Partners: We may share necessary employment and professional data with clients and business partners who require this information to integrate our employees into their projects effectively.
-
Service Providers: This includes IT service providers, such as cloud hosting services cybersecurity solutions and privacy management platforms, who assist us with our business operations.
-
Financial Institutions and Payment Processors: For processing transactions and managing financial operations.
-
Government and Regulatory Authorities: To comply with legal obligations or in response to legal requests.
Third-Party Transfers
Data shared with third parties is strictly governed by privacy agreements that ensure these parties adhere to confidentiality and data protection standards comparable to those followed by InnovWayz. We ensure that:
-
All third parties are carefully vetted and bound by contractual safeguards such as Data Processing Agreements (DPAs) to ensure data protection.
-
Data transfers are limited to what is necessary for the services they provide.
International Transfers
In instances where your personal data is transferred across borders, InnovWayz takes the following precautions:
When transferring personal data internationally, we employ strict safeguards to ensure the protection of your data across borders. We enter into Data Processing Agreements (DPAs) with all third parties handling your data outside the Kingdom of Saudi Arabia (KSA), requiring them to maintain the same level of data protection that InnovWayz adheres to.
Additionally, we transfer data only to countries recognized by the Saudi Data and Artificial Intelligence Authority (SDAIA) as having adequate data protection laws. For countries without such recognition, we conduct Transfer Impact Assessments (TIAs) to evaluate and mitigate risks and use Standard Contractual Clauses (SCCs) approved by regulatory authorities to ensure compliance with KSA standards.
8. How long will your Personal Data be retained by us?
InnovWayz retains your personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. Here’s how we determine retention periods for different types of personal data:
-
Operational Necessity: We retain your data for as long as needed to provide you with services and to conduct our business operations efficiently.
-
Legal Compliance: Certain types of data are retained for specific periods as required by law or other regulatory guidelines.
-
Marketing and Communications: Data used for marketing purposes is kept until you request that we stop contacting you. After this point, your data will be securely deleted.
Upon expiration of the retention period, personal data is securely deleted or anonymized, ensuring it can no longer be linked back to an individual.
9. How do we use Cookies?
At InnovWayz’s Website, we utilize cookies to enhance your experience, maintain the functionality of our websites, and improve our services:
-
Essential Cookies:
These cookies include those necessary for managing compliance with data protection regulations. They store your consent preferences and ensure that the website adheres to legal requirements.
-
Performance Cookies:
Used for tracking site usage and performance, these cookies help us gather insights into how visitors use the corporate website. This data is used to optimize site functionality and improve the user experience.
Managing Cookie Preferences
You can manage your cookie preferences through your browser settings at any time. Here’s how you can control or opt out of cookies:
-
Browser Settings: Most browsers allow you to refuse cookies or delete cookies through their settings preferences. However, disabling cookies may affect the functionality and service offering on our websites.
-
Consent Management: On your first visit to our website, you will be prompted to accept or reject non-essential cookies. You can change your preferences at any time by accessing the cookie settings available on our website.
10. What are your Rights regarding the processing of your Personal Data?
At InnovWayz we respect your privacy and provide you with the ability to exercise them according to the Kingdom of Saudi Arabia's Personal Data Protection Law (KSA PDPL). Following are the rights available to you:
-
Right to be Informed
You have the right to be informed about how we collect your personal data, the legal basis for collection and processing, how such data is processed, stored, destroyed, and to whom it will be disclosed. You can access all these details through our Privacy Policy or contact us for further information.
-
Right to Access to Your Personal Data
You have the right to access your personal data that we hold through means provided by us that allow for automatic access without needing to make a formal request.
-
Right to Request Access to Your Personal Data
You can request to obtain your personal data held by InnovWayz at any time and obtain a copy of this data in a clear and readable format.
-
Right to Correct Personal Data
If you find that any of the personal data that we hold about you is inaccurate, incomplete, or outdated, you have the right to request its correction or update.
-
Right to Request Destruction of Personal Data
You may request the destruction of your personal data when it is no longer needed for the purposes for which it was collected. We will review such requests and take appropriate action, adhering to legal and regulatory requirements.
-
Right to Withdraw Consent
You may withdraw your consent for the processing of your personal data at any time, unless there is a legal basis that requires otherwise. This withdrawal will not affect the lawfulness of processing based on your consent before its withdrawal.
-
Right to File a Complaint
If you believe that InnovWayz has not complied with the Personal Data Protection Law, you have the right to file a complaint with us. If you are not satisfied with the outcome, you may escalate your complaint to the Saudi Data & Artificial Intelligence Authority (SDAIA).
-
Right to Claim Compensation:
You are entitled to claim compensation for any material or moral damage resulting from a violation of the Personal Data Protection Law and its implementing regulations.
Exercising Your Rights
To exercise any of these rights, please contact us via dataprotection@innovwayz.com.
We may request specific information from you to help us confirm your identity and facilitate your right to access your personal data (or to exercise any of your other rights).
You will not be required to pay any fees in return for exercising your rights. In case of submitting a request for exercising your rights, you will receive a response within 30 days from the date of receipt of your request.
11. What if you have questions or want further information?
For further details regarding the processing of your Personal Data and how to exercise your rights, you can contact the Cyber Security and Data Privacy Department at InnovWayz using the below mentioned contact details.
12. Complaint or Objection Filing Method
If you have any concerns, or if we do not comply with the Personal Data Protection Law, you can file a complaint with our IT Department using the following channel:
Email: dataprotection@innovwayz.com
If you are not satisfied with how we process your complaint, or if we fail to respond within 30 days, you can file a complaint to the Competent Authority Saudi Data & AI Authority (SDAIA).
SDAIA Address:
Kingdom of Saudi Arabia, Riyadh
SDAIA Website:
Saudi Data & AI Authority (sdaia.gov.sa)
National Data Governance Platform “DGP” (dgp.sdaia.gov.sa)
13. Changes in Privacy Notice
InnovWayz reserves the right to update or modify this Privacy Notice at any time to reflect changes in our data processing practices, changes in law, or adjustments in our business operations.