Privacy Policy
This policy explains the data we may collect when you use our website, products, or security services, how we use, protect, and retain it, and the rights available to you in relation to that data.
Last updated: August 2026
Data we collect
We may collect the contact details you send us, such as your name, company name, and email address, along with the information needed to deliver the service requested.
We may also collect information about the technical scope you ask us to test, such as the domains, system addresses, applications, and assets that fall within the agreed scope.
We do not request your end users’ data for purposes separate from the service. Some of it may nonetheless appear in test results if it exists in the environment we were authorised to assess.
Testing data
Depending on the service, we may access source code, configuration files, logs, application responses, scan results, and other technical information required to carry out the assessment.
We treat this material as confidential and use it only as far as needed to deliver the agreed service, analyse the findings, produce the reports, and provide the related support.
How we use data
We use the data we collect in order to:
- Deliver the security services and testing requested.
- Analyse findings and produce reports.
- Correspond with you about the service or support requests.
- Operate, maintain, and secure our products and systems.
- Meet applicable legal and regulatory obligations.
We do not sell your data, and we do not use testing data or the source code provided to us for advertising purposes.
Retention and protection
We apply reasonable technical and organisational measures to protect the data we process, including encrypting sensitive material and limiting access to those who need it to perform their service-related duties.
We retain assessment results and related material for the term of the engagement, then for up to twelve months after the service ends, unless the law requires a longer period or a different period is agreed in writing.
After the retention period ends, we delete the data or render it unidentifiable, unless retention is required by a legal obligation.
You may also request deletion of your data as far as the applicable regulations allow.
Sharing
We do not sell your data or share it for marketing purposes.
We may share data as far as necessary with the technical providers who help us run our infrastructure or deliver the services, under arrangements appropriate to protect confidentiality and data.
We may disclose data where required by law or by an order or request from a competent authority.
Your rights
Depending on the nature of the data and the applicable regulations, you may have the right to request:
- To know what data we hold about you.
- To obtain a copy of your data.
- To have inaccurate data corrected.
- To have data deleted where that is possible.
- To object to or restrict certain processing, where applicable.
- To withdraw consent where processing is based on it.
You may contact us using the details at the bottom of this page to make any request concerning your data.
Data security
We use appropriate controls and procedures to protect data against unauthorised access, alteration, disclosure, or loss.
No method of transmitting or storing data can be guaranteed to be absolutely secure.
Changes to this policy
We may update this policy as our services, our data processing practices, or the applicable regulations change.
We will publish the updated version on this page and revise the “last updated” date. We will give appropriate notice of material changes where that is required or appropriate.
Contact us
If you have questions about this policy or wish to make a request concerning your data, you can reach us at:
- Safina
- Email: privacy@safina.sa
- Website: safina.sa
Questions about privacy?
Write to our data protection contact and we will reply within five business days.
privacy@safina.sa
