Website Privacy Notice - ECOVIS AL SABTI
1. Abbreviations
| Term | Definition |
|---|---|
| PDPL | Personal Data Protection Law |
2. Terminology and Definitions
| Term | Definition |
|---|---|
| Data Subject | The person or individual subject of data. |
| Personal Data | Data or Personal Data is any information in any form concerning an identified individual (applies to clients, employees, vendors, sub-contractors, or any stakeholders that the organization has a business relationship), be identified by reference, in particular, to his or her personal identification number, name, personal identification number, addresses, contact numbers, license numbers, records, personal property, bank account and credit card numbers, fixed or moving pictures of the individual, online identifier, or by reference to one or more factors specific to his or her physical, physiological, intellectual, cultural, economic, or social identity. In determining whether an individual is identifiable, all the means that the organization uses or may have access to, should be taken into consideration. |
| Processing | Processing means any operation or set of operations performed upon personal data by the organization or its representatives, whether by automatic means, including collecting, recording, organizing, classifying, storing, adapting, altering, retrieving, using, disclosing by transmission, dissemination, transference or otherwise making available for others, or combining, blocking, erasing, or destructing such data |
| Sensitive Personal Data | Personal data that may reveal directly or indirectly - an individual’s race, ethnical origin, political or philosophical opinions, religious beliefs, affiliation to a union, personal criminal record and security data, biometric data, genetic data, credit data, location data, and data that indicates that both parents of an individual or one of them is unknown or any information in relation to his health condition. |
| Data Controller | ECOVIS or its employees representing the organization who, determine the purposes and means of processing personal data which the organization processes. |
3. ECOVIS Website Privacy Notice
This Privacy Notice describes how ECOVIS Al Sabti collects, processes, uses, and protects personal data within the Kingdom of Saudi Arabia.
In this Notice “You” or “Your” refers to a data subject (client, job applicant, employee, website visitor, or contract staff) whose personal data is processed by ECOVIS . This notice also elaborates on how a data subject can exercise his/ her data privacy rights.
References to ECOVIS, “we, us, or our” includes, individually and collectively, all branches and electronic channels that collect and use your personal data within the Kingdom of Saudi Arabia.
3.1. Consequences and Risks of Not Providing Personal Data
Providing personal data is essential for us to offer certain services and fulfill our obligations under the law. If you choose not to provide the mandatory personal data required for specific purposes, you may experience the following consequences:
- Inability to access services: Without the necessary data, we may be unable to provide you with the products or services you have requested.
- Limited functionality: Certain features or functionalities, such as accessing restricted areas of our websites or receiving personalized content, may be unavailable if optional data is not provided.
- Inability to comply with legal or contractual obligations: In cases where the collection of personal data is required by law or contract, failure to provide such data may prevent us from fulfilling our legal or contractual responsibilities.
While you are free to withhold optional data, please be aware that this may limit our ability to offer the full range of services or provide personalized experience.
3.2. How does ECOVIS collect your Personal Data
3.2.1 Direct Interactions
You may give us your identity, contact, resume by filling in forms or by corresponding with us by phone, and email or otherwise. This includes the sharing of Personal Data for the following purposes:
- Records of your interactions with us, such as emails and other correspondence and your instructions to us.
- Providing your feedback.
- By filling in forms, for example, to download white papers and/or gather insights on case studies.
- By sharing your Personal Data, such as your resume for recruitment purposes.
- By interacting with us on social media platforms such as Facebook, Instagram and LinkedIn etc.
- By subscribing to our newsletter on ECOVIS website or other online medium/channel.
3.2.2 Use of Cookies
Log Files: Log information is data about your use of the service, such as IP (Internet Protocol) address, browser type, referring/exit pages, operating system, date/time stamps, and related data, which is stored in log files.
Cookies: To improve your experience, ECOVIS websites use a standard technology called “cookies” to collect information about how our websites are used, which may include your data. The use of cookies is essential for the operation of our websites.
Cookies may be used for many purposes, including to enable certain features of ECOVIS service and remember your preferences, your equipment, browsing actions, and patterns, to understand better how you interact with ECOVIS service, to provide you advertising on and off the service, and to monitor usage by visitors and online traffic routing. You may be able to instruct your browser, by changing its options, to stop accepting cookies or to prompt you before accepting a cookie from the online services you visit. If you do not accept cookies, however, you may not be able to use all portions of all functionality of ECOVIS service.
3.2.3 Third Parties or Publicly Available Sources
3.2.4 Social Media and other platforms such as:
- Analytics providers such as Google, Facebook;
- Social media platforms such as Facebook, Twitter, Instagram, Zoom info or LinkedIn
3.3. What Personal Data does ECOVIS collect?
- Data collected through application forms, questionnaires, or other documents or communications, such as the full name, date of birth, and ID numbers.
- Data on your products and transactions with us, such as account activity and product use.
- Data collected from your use of our services, websites (such as cookies).
- Data exchanged during ECOVIS communication with you, such as customer service requests and feedback received from you, either through ECOVIS websites, social media accounts, or any channel ECOVIS use to communicate with customers.
3.3.1 Sensitive Personal Data
ECOVIS may collect, store, or use the following Sensitive Personal Data regarding you such as:
- Information about your race or ethnicity, religious belief.
- Information about your health, including any medical condition, health and sickness records, medical records, and health professional information.
- Any criminal records information in relation to you.
- Biometric information about you, for example, fingerprints, and retina scans.
Our intent is not to collect or process any Sensitive Personal Data about you unless required by applicable laws. However, in certain circumstances, we may need to collect or request your sensitive Personal Data for employment-related purposes via resume shared, for example, data regarding your hobbies and preferences, gender, and disabilities for the purposes of equal opportunities monitoring to comply with anti-discrimination laws and for government reporting obligations.
3.4. How and why does ECOVIS use your personal data?
There are many contact points that help us collect your data. Below are a few examples:
- During onboarding and service utilization – When you use our services, become a client, and benefit from ECOVIS services.
- Information exchange – When you complete and upload a form to our website, email, or social media posts, or participate in promotional campaigns.
- Interaction (social media) – Any posts, messages, or interactions you carry out with us directly on our social media channels.
- Browsing patterns – Data on how you explore our website, the timing of your visits, the types of internet browsers you use, and how you were referred to our website.
- Surveys – Online web surveys that enable us to gather feedback on topics, such as what you like and dislike about the look of our website. Your valuable feedback enables us to improve the quality of the experience we provide to you.
- You personally or your authorized agent or legal representative.
- In legally accepted cases, from third parties and public sources. This includes government entities, credit information companies and agencies and ECOVIS member firms/affiliates.
ECOVIS may also use your Personal Data in the following situations, which are likely to be rare:
- Where we need to protect your interests (or someone else’s interests);
- Where it is needed in the public interest or for official purposes.
3.5. Legal basis and purposes for the collection and use of your personal data
We collect and use data as required by the nature of our services and business. In most cases, our legal basis and purposes include, but are not limited to:
- Complying with any obligations and requirements issued by legal and regulatory authorities within the Kingdom of Saudi Arabia.
- Providing products or services.
- Improving our products, services, and your experience across ECOVIS channels.
- Understanding your needs as a client and your eligibility for products and services.
We may use your personal data to promote new investments and financial products and services that may interest you; however, we will request your explicit consent before such promotions.
We may also use your Personal Data for other purposes that are not incompatible with the purposes we have disclosed to you (such as archiving purposes in the public interest, or statistical purposes) if and where this is permitted by applicable laws.
3.5.1 Change of Purpose
We will only use your Personal Data for the purposes for which we collected it unless we reasonably consider that it needs to be used for another reason, and that reason is compatible with the original purpose.
If we need to use your Personal Data for an unrelated purpose, we will notify you, and ECOVIS will explain the legal basis that allows us to do so.
If you wish to get an explanation as to how the Processing for the new purpose is compatible with the original purpose, please contact us using the contact details provided.
3.6. Disclosure of Your Personal Data
ECOVIS may share your data with any of the parties listed below:
- Any court or any governmental or regulatory entity to comply with any obligations and requirements issued by legal and regulatory authorities within the Kingdom of Saudi Arabia.
- Any debt collection agency or entity licensed to provide credit information services or insurance company.
- Any affiliated entity or any related service provider for the purpose of providing you with products or services, improving our products, services, and your experience across ECOVIS channels, and promoting new financial investment products and services that may be of interest to you.
- Any social media posts or comments you send to us: (on the our Facebook page, for instance) will be shared under the terms of the relevant social media platform (e.g., Facebook, Twitter, and LinkedIn) on which they’re written and could be made public.
- We may share your Personal Data with third parties that are based outside the country, and so their Processing of your Personal Data will involve a transfer of data outside the country of business. Whenever we transfer your Personal Data out of the country of business, we ensure a similar degree of protection is maintained.
Please contact us if you want further information on how ECOVIS transfer your Personal Data out of the Kingdom.
3.7. How does ECOVIS protect your personal data?
3.8. Storage and Destruction of Personal Data
Your personal data will be:
- Retained for as long as necessary to fulfil the purpose for which it was collected.
- Retained to meet any legal and regulatory requirements.
- Destroyed or anonymized in a manner that makes it impossible to identify you, in accordance with applicable laws, regulations, and industry best practices, ensuring that no unauthorized access or use of the data is possible after its retention period has expired.
3.9 What Are Your Data Protection Rights?
3.9.1 Your duty to inform us of changes
It is important that the Personal Data we hold about you is accurate and current. Please keep us informed if your Personal Data changes by keeping your details up to date and by sharing your updated details at: support@ecovisalsabti.com.
3.9.2 Your Rights under PDPL
Personal Data Protection Law (“PDPL”) provides certain rights in relation to your personal data.
- Right to be Informed: Data Subjects have the right to be informed about the legal basis and the purpose of the collection of their personal data.
- Right to Access: The right to access the Personal Data held by us.
- Right to Obtain Data in Readable Format: Data Subjects have the right to request obtaining their Personal Data held by us in a readable and clear format.
- Right to Data Deletion: Data Subjects have the right to request the destruction of their Personal Data held by us when such Personal Data is no longer needed.
- Right to Timely Responses: ECOVIS is obliged to respond to Data Subject requests pertaining to their rights within specified timeframes and using specified methods.
- Right to Rectify Data: Data Subjects have the right to request the correction, completion, or updating of their Personal Data held by us .
- Right to Withdraw Consent: Data Subjects have the right to withdraw their consent for processing their Personal Data at any time, given that it shouldn’t affect processing on a legal basis.
- Right to Complaint: On becoming aware of any privacy incident, the Data Subject may also complain to the competent authority within a period of 90 days from the date of such incident, providing the following information:
- Place and time of the violation;
- Name, identification, address, and telephone number of the complainant;
- Information about the complained entity; and
- Clear and specific description of the violation.
3.9.3 Fees for excessive or unreasonable requests
3.9.4 Time Limit to Respond
We try to respond to all legitimate requests within 30 days. Occasionally, it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case,we will notify you and keep you updated.
If you wish to exercise any of the rights set out above, please contact us at: support@ecovisalsabti.com.
3.9.5 What ECOVIS may need from You
We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it.
We may also contact you to ask you for further information in relation to your request to speed up ECOVIS response.
3.9.6 Indemnity and Limitation of Liability
You agree to defend, indemnify, and hold harmless ECOVIS, its officers, directors, and employees from and against any and all claims, liabilities, damages, losses, or expenses, including settlement amounts and reasonable legal fees and costs, arising out of or in any way connected with your access to or use of this site.
Although the organization shall make every attempt to keep the website free from viruses, it cannot guarantee that it is virus/ malware free. For your own protection, you should take necessary steps to implement appropriate security measures and utilize a virus scanner before downloading any information from the website.
ECOVIS, its officers, directors and employees, shall not be liable in any manner whatsoever for any direct, indirect, incidental, consequential, or punitive damage resulting from the use of, access of, or inability to use the information available on the website or the services provided by the organization. ECOVIS, its officers, directors and employees shall not be liable in any way for possible errors or omissions in the contents in the website.
3.9.7 Changes to the Privacy Notice
3.9.8 Contact Us
3.9.9 Effective Date
This Notice was last updated on 25, November 2025.