Privacy Policy

Introduction This policy aims to clarify and regulate the procedures and processes for the protection of personal data. The policy includes defining the basic obligations and requirements to ensure data protection in accordance with the security and privacy standards adopted and required in the Personal Data Protection Law and its implementing regulations. Therefore, Taajeer finance is committed to protecting the privacy ofbeneficiaries and maintaining the confidentiality of personal data in accordance with the legal controls in the Kingdom of Saudi Arabia. In this context, the company approved the privacy policy to explain how we collect, use, and process this data and all its procedures. Goal Collect and process personal data lawfully in accordance with specific and legitimate purposes in accordance with the regulations in force in Saudi Arabia in order to enhance transparency and trust with customers. Tariffs In this policy text, unless the context otherwise requires, the following terms referred to have the following meanings:
  1. The subject of personal data is the individual to whom the personal data relates, his representative, or the person who has legitimate jurisdiction over it that is collected and/or processed by the Company.
  2. Personal Data means data that may lead to the identification of a person, directly or indirectly, including but not limited to first name, last name or surname, Saudi national ID number, addresses, and telephone number.
  3. Data controller (controller) means any individual or entity that determines the purpose of processing personal data, whether the data is processed by it or by the data processor.
  4. Data processor (processor) means any individual or entity that processes personal data for and on behalf of the data controller.
  5. The company is Taajeer finance Company.
Range Applies to all personal data collected or processed by the company containing the following data:
  • Individual Data: Personal information that relates to an individual including name, address, date of birth, gender, and marital status.
  • Sensitive Data: Information that relates to sensitive personal aspects of individuals such as health, race, religion as well as security and criminal data and biometric features that require special protection.
  • Financial Data: Includes bank account details, credit card numbers, income and expense details, and other financial records collected and used for the purposes of providing financing services, collection services, legal advice, and others.
  • Technical Data: Including the user’s IP address, which is the IP address used to link the personal account to the Internet and cookies.
Legal basis and purposes of collection and use of your personal data Taajeer finance collects and uses data as required based on the nature of the services and business. In most cases, its legal basis and purposes include, but are not limited to:
  • Allow us to provide products or services, advertisements, and incentives.
  • To protect you from fraud by conducting identity and credit checks or verifying that there is no conflict and protecting the security of the network and information.
  • Improve our products, services, and your experience provided across our channels.
  • Understand your needs as a customer and your eligibility for products and services.
  • Promote new investment and financial products and services that may interest you.
  • Collect and retain only the minimum amount of personal data to achieve the purpose of the processing.
  • Meet certain legal and regulatory requirements within Saudi Arabia.
  • The purpose should not be contrary to any of the regulations in the Kingdom.
How data is collected Taajeer finance collects and processes personal data, obtained directly or indirectly, using various methods, including:
  • When establishing a relationship and benefiting from the service – when you use our services, become a customer, benefit from our products, and when the customer signs all pages of the contract.
  • Exchange of information – when completing a form and uploading it to our website, mobile applications, email, by calling the customer center, visiting a branch, participating in promotions or advertisements, and attracting potential customers.
  • Social Media – Any posts, interaction, communication, or contests you conduct with us directly on social media channels.
  • Loyalty Program – Existing customers who fall under the loyalty program.
  • Browsing pattern – Data about how you explore our website, when you visit, types of internet browser, and how you were referred to our website.
  • Surveys – Online web surveys that enable us to gather opinions on topics. For example, your likes and dislikes about the look and feel of our website and mobile apps. Your valuable feedback enables us to improve the quality of the experience we provide to you as an organization.
  • From you personally, your legal guardian, your authorized agent, or your legal representative after fulfilling all the relevant requirements.
  • Administrative transactions – Renewal of form, transfer of ownership, addition of delegate, internal and external delegation, geographical expansion.
  • In legally acceptable cases, from third parties and public sources. This includes government agencies, credit information companies, and agencies.
  • Security awareness campaigns to educate employees about cybersecurity and phishing awareness campaigns.
  • To achieve a realized interest – when a realized interest is achieved for the personal data subject and the personal data subject cannot be contacted and accessed.
Sensitive Data Health Data Processing Taajeer finance Company is committed to taking all organizational, technical, and administrative measures to protect health data from unauthorized access and misuse. Implementing the conditions and controls issued by the competent authorities, which relate to the organization of health services and health insurance, documenting all stages of health data processing, and providing the possibility of identifying the person responsible for each stage. Credit Data Processing Taajeer Finance Company is committed to taking all measures to ensure the protection of credit data from unauthorized access and misuse. The company is obligated to obtain the consent of the owner of personal data and notify him when there is any request to disclose his credit data. Processing sensitive data Taajeer Finance Company is committed to protecting personal data related to racial or ethnic origin, genetic data, criminal or judicial data. The company is committed to taking the necessary measures to ensure the protection of this data and is committed to processing it in accordance with the legal and security requirements of each type. Data processing for other purposes Taajeer Finance Company specifies the purposes of processing personal data specifically and clearly when using the data for purposes other than those for which it was collected and documents the procedures for determining the content of the data in accordance with the specified purposes.
  • The Company also takes the necessary measures to collect personal data to the minimum extent necessary to achieve the specified purposes while ensuring that the processing is carried out in accordance with the stated purposes and with the minimum data required.
Protection and security of personal data In accordance with the Personal Data Protection Law, its implementing regulations, and related articles, appropriate technical and organizational security measures have been implemented to protect personal data and prevent its use, unauthorized access, alteration, or accidental disclosure. The Company is committed to implementing measures to protect the personal data it holds, limiting access to the personal data of employees, regulators, agents, companies, and other third parties whose work needs to have access to that data.
  • These measures also include specifying the purpose of the processing, the categories of data, the duration of the processing, and the obligation of these parties to notify the company in the event of data leakage. It should be clarified whether the said entities are subject to international regulations, and the impact of this on compliance with the local system, and not require prior approval from the company for the mandatory disclosure of personal data. The Company shall be responsible for periodically verifying the compliance of these entities with the Law and its Regulations, and appointing an independent party to review when needed.
  • Best practices for anonymity are also applied when necessary to ensure that personal information is processed based on appropriate instructions and procedures, while adhering to the duty of confidentiality and taking the necessary organizational, administrative, technical, and cyber measures to ensure the security of personal data and the privacy of its owners, and to reduce the security risks of personal data leakage or illegal access.
How long personal data is retained The Company only stores personal data when necessary to achieve the purposes for which it was collected, which is usually for a period of 10 years. The Company can also retain personal data for a longer period in the event of a complaint or the possibility of litigation in relation to the Company’s relationship with the data subject. Data Destruction The Company is committed to securely destroying personal data when it is no longer necessary to keep it, using procedures such as paper shredding or secure digital deletion. Legal requirements are complied with to ensure that the destruction is appropriately documented and appropriate actions are taken to notify third parties. Data Sharing Personal data may be shared with relevant government or private entities, where it is shared for a legitimate approach based on achieving public interest goals without harming national interests, the activities of entities, the privacy of individuals, or the safety of the environment – with the exception of data and entities excluded by high orders. Data storage Protecting personal data and ensuring that it is handled correctly and securely is one of Taajeer finance core priorities, as the company applies the highest standards of security in storing, processing, and archiving personal data within the geographical borders of the Kingdom of Saudi Arabia to ensure the preservation of the digital national sovereignty of this data.
  • If you would like more information about data transfers, please contact us using the details in the section “Communication Channels” below.
Photocopying or copying official documents Avoid photocopying or copying official documents except with the consent of the data subject and according to the relevant regulations and legislation. Data subject rights in relation to the processing of personal data Under the Personal Data Protection Policy, the subject of personal data has the rights listed below:
  • Right to know, which includes informing the data subject of the legal justification for the collection of his personal data and the purpose for which it was collected. If personal data is collected from a person other than the owner directly, he will be notified of this within a period not exceeding 30 days.
  • The right to access his/her available personal data, in accordance with the controls and procedures that are determined.
  • The right to request access to his/her personal data available to the company in a readable and clear format, in accordance with the controls and procedures to be determined.
  • The right to request the correction, completion, or updating of his personal data available with the company, and the parties to whom he previously disclosed the personal data will be notified after correcting it.
  • The right to request the destruction of his personal data available to the company from what is no longer needed, without prejudice to the provisions of the Law.
It is taken into account that the exercise of the personal data subject’s right to obtain their data does not adversely affect the rights of third parties, such as intellectual property rights, trade secrets, or the disclosure of personal data that identifies another individual. Disclosure of your personal data The Company may share User Data with any of the parties listed below:
  • Any court or any governmental or regulatory body to comply with any obligations and requirements issued by legal and regulatory bodies within Saudi Arabia.
  • You may be contacted and/or notified via various channels such as SMS, email, and/or telephone.
  • If disclosure is necessary to protect the public interest, public safety, or the life or interest of a particular individual or individuals.
  • If the disclosure will be limited to the processing of data in a way that does not specifically identify the owner of the personal data or any other individual. They will not be circulated, replaced, or sold to any third party without your prior consent.
  • The disclosure should be limited to a minimum amount of personal data to achieve its purpose.
  • Take due care to protect the privacy of the personal data subject.
  • Balancing the rights of the data subject and the other person in each case and encoding personal data that indicates the identity of the other person.
  • Include disclosures in records of personal data processing and documentation activities.
Your personal information will not be published if any of the following conditions are met:
  • Represents a threat to security, damages the reputation of the Kingdom, or conflicts with its interests.
  • Affects the Kingdom’s relations with other countries.
  • Prevents the disclosure of a crime, violates the rights of the accused to a fair trial, or affects the integrity of existing criminal proceedings.
  • Endangers the safety of the individual or individuals.
  • It is an invasion of the privacy of another individual who is not the owner of the personal data, as defined in the Regulations.
  • Conflicts with an incomplete or incapacitated interest.
  • Violates applicable professional obligations.
  • Involves a breach of an obligation, procedure, or judgment of a court.
  • Reveals a confidential source of information that should not be disclosed in the public interest.
Impact Assessment The Company assesses the impact and potential risks on the rights of personal data subjects prior to data processing. Evaluation includes determining the purpose and systemic justification of the processing, describing the nature of the processing, the scope of the processing, the context of the processing, and appropriate measures to ensure the minimum data required. It also includes assessing the severity of potential impacts and preventive measures to reduce risk. Changes to the Privacy Policy The Company reserves the right to modify this Privacy Policy at any time. The effective date of the Privacy Policy, as stated below, refers to the date on which this Privacy Policy was most recently revised or modified. Checking the effective date below allows you to determine if there have been changes since the last time you revised the Privacy Policy. Therefore, we advise you to periodically check this Privacy Policy to ensure that you are aware of the updated version. Consent to the Privacy Policy The Privacy Policy has been published in the means of collecting and processing personal data of the Company, and therefore you acknowledge that you have read this Policy and agree to all its terms and conditions. Your agreement to this policy implies a precondition of contracting. Therefore, the lack of agreement will affect the provision of the requested services. It may also include the termination of the requested services. Complaint or objection In case of concerns or if the Company does not comply with the Privacy Policy, you can submit a complaint to the Company’s Data Management Office using one of the following channels: Communication Channels In case of any questions, you can contact us through any of our branches, email, social media, or through our website.
  • Website: taajeerfin.com
  • Email: customer.care@taajeerfin.com
Disclaimer This Privacy Policy is not intended to create any contractual rights of any kind or any other legal rights, or create any obligations on us with respect to any other party or on behalf of any party. When you log in to any third party’s websites, this Privacy Policy will not apply. In addition, we are not responsible for the content of any third-party websites and do not represent any third party. Therefore, we recommend that you review the privacy and security policy for each link you sign in to.
Scroll to Top