Pre-launch draft

Privacy Policy

HEDVARA follows data minimization: collect only what is needed to operate, secure and improve the service, then explain purpose, retention and recipients.

Public registration and the simulated dashboard are available. Commercial analytics access still requires administrator approval, and checkout remains disabled until launch terms are finalized.

1. Controller identity

HEDVARA is a pre-incorporation project. The legal operator, registered address and privacy contact will be added before commercial launch. This draft is not a final notice from an unnamed controller.

2. Data we may process

We may process name, email address, mobile number, account preferences, consent history and support records, together with essential technical data such as IP address, browser type, request time, errors and security identifiers. A mobile number is used to complete the account profile and for essential service communications. Full card details will be handled by an approved payment provider and not stored on HEDVARA servers.

3. Purposes and legal bases

Purposes include security, abuse prevention, account operation, support, contract performance, legal compliance and reliability improvement. Optional marketing will require a separate choice and will not be bundled into core access where consent is required.

4. Cookies and analytics

Essential session and security technologies run by default. Optional Google Analytics 4 page and product-interaction measurement starts only after the user allows analytics; email addresses and mobile numbers are not sent as analytics-event fields. Refusing measurement does not disable core account functions.

5. Processors and sharing

Limited data may be shared with contracted hosting, security, email, support and accounting providers. We do not sell personal data. Providers may not use it for independent purposes unless transparently disclosed and legally permitted.

6. International transfers and retention

Cloud infrastructure can involve cross-border processing. Before launch, locations and safeguards will be documented under the Saudi PDPL and GDPR where applicable. Each category is retained only as long as needed, then deleted or de-identified subject to legal and dispute holds.

7. Your rights

Depending on applicable law, rights can include notice, access, copy, correction, deletion, restriction, objection, withdrawal of consent, portability and complaint. We will provide a verified request channel and respond within statutory time limits.

8. Security and incidents

Controls include service isolation, least privilege, encryption in transit, security logging, backups and access review. No system is perfectly secure; incidents will be assessed and notified where law requires.

9. Children and changes

The service is for adults and is not designed for children. Material changes will be announced and dated. Paid accounts will not launch before a complete policy is published.

Official references

Saudi Personal Data Protection Law — officialSDAIA Data ProtectionOfficial GDPR text