Siyolah understands the importance of privacy and personal-data protection. This Privacy Policy explains how Siyolah ("Siyolah", "we", or "us") collects, uses, shares, transfers, retains, and protects personal data when you browse or use our websites, applications, accounts, analytical tools, communications, and support services (together, the "Service").
This Policy applies to all Siyolah services that link to it. A feature may provide an additional notice when it collects personal data for a specific purpose. This Policy applies from the date it is published with the Service.
In this Policy, "personal data" means information that identifies you or could reasonably make you identifiable, directly or indirectly. "You" means a person who visits or uses the Service.
1. What personal data do we collect?
The data we collect depends on how you use the Service. It may include:
- Account and contact data: name, email address, language, profile, preferences, account status, subscription plan, and organization or seat details.
- Authentication and security data: password hash, sign-in or identity-provider identifiers, sessions, login events, device and browser information, IP address or an IP-derived identifier, and fraud or abuse signals.
- Subscription and payment data: plan, entitlements, payment status, transaction references, invoices, tax records, and billing or support correspondence.
- Feature data you provide: watchlists, alerts, saved screens, portfolio or holding inputs, filters, notes, reports, exports, and support requests. Some features store data only in your browser; others synchronize it to your account.
- Usage and device data: pages and features used, event times, language, general device or browser class, cookie or local-storage identifiers, consent choices, and diagnostic information.
- Communications: messages sent to support, operational and security communications, notification preferences, and any marketing consent.
- Public professional market data: names, roles, holdings, and transactions contained in Saudi Exchange disclosures, issuer filings, public registers, or other lawful public sources.
We collect data directly from you, automatically when you use the Service, from providers that help us operate it, from an organization that manages your access, and from lawful public sources.
Required fields are identified when collected. If you do not provide data needed to create or secure an account, complete a subscription, verify a request, or provide a feature, we may be unable to provide that part of the Service.
2. Why do we collect and use personal data?
We process personal data to:
- provide, personalize, and administer the Service and your account;
- authenticate users and manage subscription access;
- save or synchronize requested features and generate reports or exports;
- process payments, invoices, renewals, cancellations, and billing support;
- communicate about accounts, security, transactions, support, and material Service changes;
- maintain, troubleshoot, measure, and improve the Service;
- prevent, detect, investigate, and respond to fraud, abuse, unauthorized access, and security incidents;
- provide historical market research based on lawful public professional disclosures;
- generate a summary or other model-assisted output that you request, where that feature is enabled;
- comply with legal, tax, accounting, regulatory, and authority requirements; and
- establish, exercise, or defend legal claims and enforce our terms and policies.
Marketing messages are sent only where permitted and, where required, with your prior consent. You may unsubscribe at any time.
Siyolah provides general information and analytical tools. It does not use personal data to execute transactions. Siyolah does not allow a fully automated system, without human involvement, to make a decision that affects your legal rights or has another similarly important effect on you.
3. What is our legal basis for processing?
Depending on the purpose, we process personal data on one or more of these bases:
- Contract: processing needed to provide the Service or take steps you request before entering a subscription or other agreement.
- Consent: for processing that requires your prior permission, such as optional marketing and, where applicable, optional analytics or session replay. You may withdraw consent at any time without affecting earlier lawful processing.
- Legal obligation: processing needed to meet duties under applicable law, including tax, accounting, data-protection, security, and authority requirements.
- Legitimate interests: processing needed for a lawful operational, security, service-improvement, or professional-research purpose, where permitted, necessary, proportionate, and not overridden by your rights and interests.
We will not use personal data for a materially incompatible new purpose without an appropriate legal basis and notice.
4. How do we use cookies and similar technologies?
The Service uses cookies, local storage, and similar technologies to keep you signed in, remember language and preferences, record consent choices, protect the Service, and support requested features. Clearing essential storage may sign you out or reset a feature.
Where enabled, analytics may record pseudonymous usage events, routes, language, general device information, feature interactions, and an IP-derived identifier. Session replay may record how a page is used, with sensitive fields masked or excluded. Where the law requires consent, optional analytics and session replay operate only after consent and may be disabled through the available privacy controls.
We may briefly process an IP address and session activity for security, abuse prevention, service delivery, and restricted operational alerts. We do not design analytics or replay to capture passwords, full payment-card details, or the contents of sensitive form fields.
Siyolah does not use third-party advertising cookies to sell personal data or build advertising profiles.
5. Who can access or receive your personal data?
Access is limited to people and organizations that need the data for the purposes described above. They may include:
- authorized Siyolah personnel;
- the organization that provides your business account or manages its authorized users;
- providers of hosting, content delivery, security, authentication, payment processing, email, customer support, analytics, session replay, monitoring, and model inference, where those services are active;
- professional advisers, auditors, and insurers under appropriate duties;
- courts, regulators, public authorities, or law-enforcement bodies where disclosure is required or permitted by law;
- a successor or prospective successor in a merger, financing, reorganization, or transfer of the Service, subject to appropriate confidentiality and data-protection measures; and
- another person where you ask us to share data or give valid consent.
Where an external model provider assists with a feature you request, we limit the information sent to what is reasonably needed for that feature. Do not submit passwords, full card details, national identifiers, health data, confidential third-party information, or material non-public information unless a feature expressly and lawfully requests it.
We do not sell personal data.
6. Where is personal data processed?
Personal data may be processed in Saudi Arabia and in other countries where our service providers operate. When personal data is transferred outside Saudi Arabia, we apply the requirements of the Saudi Personal Data Protection Law and the Personal Data Transfer Regulations, including any required assessment, contractual protection, approval, or lawful exception.
7. How are payments handled?
Paid features use the payment processor identified at checkout. Full card details should be entered only in that processor's secure payment interface and are handled under its own privacy policy and terms. Siyolah retains the transaction references, invoices, subscription access, and billing records needed to administer the purchase and meet legal obligations.
8. How long do we keep personal data?
We keep personal data only as long as needed for the purpose for which it was collected, to operate or secure the Service, to resolve a dispute, or to meet a legal obligation. In general:
- account and synchronized feature data is kept while the account is active and for a limited period needed for closure, security, disputes, or legal requirements;
- browser-only data remains until you, your browser, or the feature clears it;
- analytics, security-event, and closed visitor-operation records are generally kept for up to 90 days, unless an incident or legal hold requires longer;
- raw network identifiers used for a live security or operational response are kept only for the short period needed for that response, then deleted or de-identified where the system permits;
- invoices, billing-audit, tax, and compliance records may be kept for up to seven years, or longer where applicable law requires;
- public professional market-disclosure data may be retained for lawful historical research while the purpose, source rights, and legal basis remain valid; and
- protected backups are deleted through the ordinary backup-rotation cycle.
When retention is no longer justified, data is securely destroyed or irreversibly anonymized. Deletion may not be immediate in backups, and a lawful retention duty or legal hold may delay destruction.
9. How do we protect personal data?
We use reasonable technical, administrative, and organizational safeguards appropriate to the data and risk. These include access controls, password hashing, security logging, secure-development practices, provider oversight, and incident-response procedures.
No internet service can guarantee absolute security. Keep your credentials confidential and contact us promptly if you suspect unauthorized access. If a personal-data breach meets a legal notification threshold, we will notify the competent authority and affected people as required by law.
10. What are your rights?
Subject to the conditions and limits of the Saudi Personal Data Protection Law, you may have the right to:
- be informed of the legal basis and purpose for collecting your personal data;
- access personal data held about you;
- receive a clear and readable copy of that data;
- request correction, completion, or updating of inaccurate, incomplete, or outdated data;
- request destruction of data where the legal conditions apply;
- withdraw consent for processing based on consent; and
- complain to the competent authority and seek any remedy available under law.
To exercise a right, email support@siyolah.sa. We may request information reasonably necessary to verify your identity and protect other people. We respond without undue delay and ordinarily within 30 days; where the Implementing Regulations permit, we may extend that period by up to a further 30 days and will explain why.
You may also submit a complaint to the Saudi Data & AI Authority through the National Data Governance Platform.
11. Children and legal capacity
The Service is not directed to children or to a person who lacks the legal capacity required to use it without valid guardian authorization. If you believe personal data was provided without valid authorization, contact us so we can review and take appropriate action.
12. Third-party services and links
The Service may link to or rely on an independent payment processor, identity provider, authority, issuer, data source, or other third party. An independent third party processes personal data under its own privacy policy. Please review that policy before providing data directly to it. This does not remove Siyolah's responsibility for processing or disclosures that we control.
13. How may this Policy change?
We may update this Policy to reflect legal, regulatory, security, provider, or Service changes. We will post the revised Policy with a new "Last updated" date and give reasonable notice of a material change. If a new activity requires consent, we will request that consent before it begins.
14. Contact us
For privacy questions, rights requests, complaints, or concerns about your account, contact:
support@siyolah.sa