At Ezhalha we treat your personal data the way we treat your store: as something held in trust on your behalf. This policy explains what data we process, the legal basis for processing it, who we share it with, how long we keep it, and what rights you have and how to exercise them.
1. The controller
The controller of personal data processed through this site is:
- Registered legal name
- DataWork Company
- Legal form
- Limited Liability Company
- Unified national number
- 7054675868
- Register status
- Active
- Head office
- Riyadh, Kingdom of Saudi Arabia
- Official email
- support@ezhalha.store
These details match the commercial registration certificate issued by the Ministry of Commerce and can be verified there using the unified national number.
For any question or request about your personal data, write to support@ezhalha.store with “personal data request” in the subject line.
2. Scope of this policy
This policy covers personal data we process as a controller — that is, data about site visitors, subscribers, and representatives of contracting entities.
Personal data we process as a processor on behalf of our clients — such as data about your store’s buyers that we encounter while operating your store — is processed only on the client’s documented instructions and for the agreed purpose. It is governed by that store’s own privacy policy rather than this one, and we apply the same security measures to it.
3. Data we process
1. Contact and identification data
Name, email address, mobile number, entity or store name, job title, and any information you send us voluntarily through contact forms or support channels.
2. Subscription and billing data
Chosen plan, subscription and renewal dates, invoice history, payment status, and your tax number if you provide it. Bank card details are processed directly by the licensed payment gateway; we neither receive nor store them on our servers under any circumstances.
3. Technical data
IP address, browser, operating system and device type, pages visited and time spent, referral source, and error and access logs.
4. Operational access data
When you grant us permissions on your platforms, logins and actions performed are logged for traceability and accountability. We always work on the principle of least sufficient privilege and never request a permission the service does not need.
4. Purposes and legal basis
We do not process your data without a lawful basis. These are the purposes and the basis for each:
- Performance of a contract: providing the services, managing your subscription and renewals, and communicating about your orders.
- Legal obligation: issuing invoices, keeping accounting records, and responding to requests from competent authorities.
- Legitimate interest: securing the site and preventing fraud, and improving services and measuring performance in aggregate — where this does not prejudice your fundamental rights.
- Consent: sending newsletters and marketing offers, and non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
5. Sources of data
We obtain your data mostly from you directly. We may obtain technical data automatically as you browse the site, or publicly available entity data held by official authorities in order to verify contracting details. We do not purchase personal-data lists from anyone.
6. We do not sell your data
Your data is not a commodity. We do not sell, rent or trade your personal data with any third party for marketing or commercial purposes. This is a standing commitment with no exceptions.
7. Disclosure and sharing
We share the minimum necessary data with a limited set of recipients, and only for a defined operational purpose:
- Hosting and cloud infrastructure providers — to run the site and store data.
- Security and content-delivery providers — to repel attacks and speed up access.
- Licensed payment gateways — to process payments securely.
- Measurement and analytics tools — to understand site performance, with as little identifying data as possible.
- Email and notification providers — to send invoices and operational messages.
- Competent authorities — where a legal obligation or judicial order applies, and only to the extent required.
Every provider is bound by a processing agreement setting the purpose, duration and security measures, and prohibiting use of the data for their own purposes.
8. Transfers outside the Kingdom
Some data may be processed on servers outside the Kingdom by global providers. Where that happens we comply with the Law and the Regulations on Personal Data Transfer outside the Kingdom: we limit transfers to a legitimate purpose, verify that the receiving party affords an adequate level of protection, put the necessary contractual safeguards in place, and transfer the minimum data, without the transfer affecting national security or the Kingdom’s vital interests.
9. Retention periods
- Subscription and invoice data: for the term of the engagement, then for the period required by accounting and tax law.
- Contact and enquiry data: until the purpose of the correspondence ends, then for no more than twenty-four months.
- Technical and access logs: a short period sufficient for security and incident investigation.
- Data tied to marketing consent: until you withdraw your consent.
When the purpose of collection ends we destroy the data without delay or anonymise it so that you can no longer be identified, unless a statutory retention obligation applies.
10. Data security
We apply organisational and technical measures proportionate to the level of risk, including:
- Encryption of data in transit over TLS across the whole site.
- Restricting access to those who need it to do their work, with periodic permission reviews.
- Two-step verification on sensitive administrative accounts.
- Regular backups and a tested restore plan.
- Regular security updates for platforms and extensions.
- Contractual confidentiality obligations on everyone who works for or with us.
11. Personal data breach notification
If a leak, corruption or unauthorised access to personal data occurs, we will notify SDAIA within seventy-two hours of becoming aware of it, and will notify affected data subjects without undue delay where the incident is likely to cause serious harm to them or their data — stating the nature of the incident, the steps we have taken, and what we recommend you do.
12. Your rights
The Personal Data Protection Law grants you rights that cannot be waived by any contract or agreement:
- Right to be informed: to know the legal basis for collecting your data and the purpose of collection — which this policy provides.
- Right of access: to see the personal data we hold about you.
- Right to obtain a copy: to receive it in a clear, machine-readable format.
- Right to rectification: to have your data corrected, updated or completed.
- Right to destruction: to have your data destroyed once it is no longer needed for the purpose it was collected for, unless a statutory retention obligation applies.
- Withdrawal of consent: to withdraw consent to processing based on it, such as marketing messages, at any time.
13. How to exercise your rights
Send your request to support@ezhalha.store. We may ask for proof of identity to protect your data from disclosure to someone else. We respond within thirty days of receipt, extendable by a further thirty days where the request requires exceptional effort, in which case we tell you and explain why. The service is free, except for unreasonably repetitive requests where we may charge a reasonable amount covering actual cost.
If you consider that our processing breaches the Law, you have the right to complain to the Saudi Data & Artificial Intelligence Authority (SDAIA) through its official national data-governance platform.
14. Cookies
We use three kinds: essential cookies needed for the site, cart and login, which cannot be disabled; preference cookies that remember choices such as language; and analytics cookies that help us measure performance. Full details, the list and the durations are in the Cookies Policy.
15. Direct marketing
We send marketing messages only with your consent, and every message carries an unsubscribe link that works immediately. Unsubscribing from marketing does not stop essential operational messages such as invoices and outage notices, because those form part of performing the contract.
16. Children’s data
Our services are aimed at businesses and business owners. We do not target anyone under eighteen and do not knowingly collect their data. If we learn that we have collected a minor’s data without a lawful basis, we destroy it without delay.
17. Automated decisions
We do not take decisions producing legal effects on you based solely on automated processing without human involvement. Where we use artificial-intelligence tools to analyse store performance or forecast demand, their outputs remain recommendations reviewed by a person before any decision is taken.
18. Changes to this policy
We may update this policy to keep pace with our services or regulatory requirements. The updated version is published on this page with the “last updated” date revised, and subscribers are notified of material changes by email before they take effect.
19. Contact
For any question about this policy or how we handle your data: support@ezhalha.store — or via the contact page.
Want a store that is compliant with the data protection law?
We build the technical compliance layer: consent capture, processing records, permission control, and a channel for exercising rights.
