Information Security and Privacy

Information Security and Privacy

Privacy Policy

 

Introduction

Derayah Financial respects your privacy and is committed to protecting your personal data and preserving your privacy. This privacy notice was created to assist you in understanding the types of personal data collected by Derayah Financial, the purpose of collecting it, and how it is processed by us, in accordance with the applicable laws in the Kingdom of Saudi Arabia.

This Privacy Notice shall be governed by and construed in accordance with the applicable laws of the Kingdom of Saudi Arabia.

 

Who we are

Company Name: Derayah Financials
Commercial Registration No: 1010266977
Registered Address: RHOA6775, Al takhasasi, Al Olaya Dist. 12331

In this Privacy Notice, “we”, “us” and “our” refer to Derayah Financial, and is addressed to individuals outside our organization with whom we interact, including customers, visitors to our websites, vendors, investors, and other recipients of our services (together “you”, “your”).

We provide details on how to contact us in the ‘How to Contact Us’ section at the end of this notice.

 

Changes to this privacy notice

To ensure that we continue to offer the best possible experience and the highest level of protection to you and your personal data that is held by us, we reserve the right to update this Privacy Notice as and when necessary and appropriate, for example to comply with new laws or requirements.

Any update to this privacy notice will be available here so we encourage you to periodically check it.

This privacy notice was last updated on 14/09/2024.

WHAT PERSONAL DATA WE COLLECT AND HOW WE COLLECT IT

We will collect personal data from you through your direct interaction with us or our services, and indirectly through other means. These include but are not limited to:

  • Identification information which you provide when registering with any of our services (such as your name, date of birth, gender, passport information, national identification)
  • Contact information necessary when collecting feedback to improve our services and addressing complaints, such as national address, email address, telephone number
  • Account and financial information such as details of account information, subscriptions
  • Browser usage information collected while you use our websites or applications, such as browsing data, timestamps, cookies, and usage statistics.
  • Legal and regulatory information required for compliance, such as information required by us for performing due diligence and anti-money laundering checks.
  • In some cases, we collect certain data based on your consent, which ensures that we use your data only in ways that you agreed to and were not mentioned during or before the beginning of the contractual agreement.

Personal data will not be processed in a manner inconsistent with its collection purpose or to the extent permitted by the law.

WHAT IS THE PURPOSE AND USE OF YOUR PERSONAL DATA

We process your personal data for the following purposes, as necessary to provide you relevant and tailored services, including but not limited to:

  • Providing you with relevant services: To offer investment, asset management, wealth management, trading, local and international brokerage and any other services we offer.
  • Improving our services offered to you: To address your inquiries, concerns, and ensure a high-quality investment experience.
  • Safety and security: Ensuring your security through fraud prevention and cybersecurity measures.
  • Notifications: To provide you with timely notification regarding changes in your account or portfolio, or other notifications related to your operations (such as a deposits, subscriptions or account updates)
  • Guidance and awareness communication: Informing you about security measures, precautions, and best practices to safeguard your accounts and personal data.


WHEN WE DISCLOSE YOUR PERSONAL DATA

In keeping with the requirements of the Personal Data Protection Law (PDPL), we may disclose your personal data in the following cases:

  • When we have your explicit consent.
  • When a public entity has requested disclosure, and the request is for security purposes, to implement another law, or to meet judicial requirements in accordance with the provisions set out by the regulations.
  • When the disclosure is necessary to protect public health or safety, or to protect the life or health of a particular individual(s).
  • When the disclosure is necessary to achieve legitimate interests of Derayah, without prejudice to your rights and interests.

 

LEGAL BASIS FOR PROCESSING YOUR PERSONAL DATA

At Derayah Financial, we will only process your personal data if we have a lawful basis to do so. The following are lawful basis for processing personal data:

  • Your consent that you provide to process your personal information for a specific purpose that we communicate to you.
  • Processing required by applicable laws and is performed in accordance with them
  • Processing performed as part of a contractual obligation of which you are a party
  • Processing necessary for the purpose of our legitimate interest
  • When the Processing achieves a definite interest to you.

 

HOW WE STORE YOUR PERSONAL DATA

We safeguard the confidentiality of your data to make sure that your personal data is stored securely. We have appropriate technical and organizational security measures, policies, and procedures to protect your personal data from accidental loss, unauthorized access, use, alteration, and disclosure.

HOW LONG WE STORE YOUR PERSONAL DATA

We keep your personal data for specific business purposes and for as long as necessary to achieve the intended purposes, taking into consideration our purposes outlined above or to comply with requirements under applicable laws. We will keep your personal data for a defined period after your relationship ends with us, and the period for which we keep it might change based on our regulatory requirements.


YOUR RIGHTS REGARDING PROCESSING OF YOUR PERSONAL DATA

You have the following rights under the PDPL, which primarily depend on the purpose of personal data collection and processing:

  • The right to be informed about the collection and usage of your personal data, including why and how we collect your personal data, the purpose of such collection and processing, and whom it will be shared with.
  • The right to request access to your personal data held by Derayah Financial, to review it or obtain a clear copy of it.
  • The right to update any of your personal data that you find inaccurate, incorrect, or incomplete.
  • The right to request deletion, unless there is a legal provision specifying a particular retention period or contractual requirements.
  • The right to withdraw your consent for the processing of your personal data at any time unless there are legitimate purposes requiring

You can avail these rights by submitting your request by emailing us at: privacy@derayah.com.

In case of submitting a request for exercising your rights, you will receive a response within 30 days as of the request receiving date, and this period may be extended if unexpected or unusual effort is required, or if multiple requests are submitted by you.

For further details regarding the processing of your Personal Data and how to exercise your rights, you can contact our Personal Data Protection Officer using the below mentioned contact details:

Data Protection Officer

E-mail: dpo@derayah.com

 

HOW TO CONTACT US

If you have any questions, inquiries, complaints or wish to contact us about the contents of this Privacy Notice in the first instance, please contact us through: privacy@derayah.com.

 

 

Still need some help?

If you have some questions or comments, feel free to let us know and we will respond as quickly as possible