Al-Khaber Public Services
Privacy Policy & Client Data Protection
This policy outlines the types of data collected by the Al-Khaber Office website, the purposes of its use, the mechanism of storing and sharing it, the rights of data subjects, and the procedures followed to protect information when using the site or requesting a service.
- Limiting collection to data necessary for the service
- Clarifying the purposes of collecting and using information
- Never requesting passwords or verification codes
- Empowering users to exercise their data rights
Please do not send passwords, verification codes, or confidential bank details via our website forms or communication channels.
Introduction to the Privacy Policy
The management of the Al-Khaber Public Services website respects the privacy of site users and clients. We process personal data in an organized, purpose-specific manner, and only to the extent necessary to inquire about services, evaluate transactions, or execute and track them.
This policy applies to data collected through the website, contact forms, client portal, communication channels associated with the service, and information provided by the client during the study or execution of their transaction.
Last Updated: September 2026How Do We Handle Your Data?
We use information within the limits of the purpose for which it was collected, and restrict access only to those who need it to perform the service or fulfill a legal requirement.
User-Provided Data
Such as name, contact method, transaction details, and necessary documents when requesting a service.
Purpose-Specific Use
To evaluate requests, provide and track services, protect the site, and fulfill legal obligations.
Disclosure When Needed
Necessary data may be shared with a competent authority or a service provider assisting in executing the client’s request.
Stored for a Necessary Period
Data is kept for the period necessary for the purpose and legal requirements, then destroyed or anonymized when applicable.
Privacy Policy Terms
The following terms explain how personal data is collected, processed, stored, disclosed, and the options available to the user.
Scope of Policy Application
This policy applies to users of the Al-Khaber website, clients communicating to request a service, users of the client portal, and individuals providing their data for inquiries, evaluation, execution, or tracking of a transaction.
This policy does not govern the practices of external websites and platforms accessible via links on our site; those sites are subject to their own privacy policies.
Personal Data We May Collect
The required data varies depending on the type of communication or service. Mentioning a category of data does not mean we collect it from all users.
Identity and Contact Data
- Name or establishment name.
- Phone number and email address.
- City or region when relevant to the service.
- Data of the authorized person or legal representative when applicable.
Transaction and Service Data
- Type of transaction and the competent authority.
- Request or transaction number, date, and status.
- Notes, reasons for rejection, or completion requests.
- Documents necessary to evaluate or execute the service.
- Correspondence, instructions, and approvals related to the request.
Technical Data
- IP address automatically.
- Device type, browser, and operating system.
- Pages visited and time of visit.
- Security and technical error logs.
- Cookies when used or approved according to their type.
Payment Data
The office may retain transaction details such as the amount, date, and transfer or invoice reference. The client is never asked to send the card’s secret PIN, verification code, or bank account login details.
Sources of Data Collection
Data is collected in ways appropriate to the nature of the service and communication, primarily:
- Data sent by the user via the contact form.
- Information shared by the client through approved communication channels.
- Data entered by the user in the client portal.
- Documents and information provided during service execution.
- Technical data generated when using the site.
- Official or public sources when necessary to verify information related to a client’s request in a lawful manner.
Purposes of Data Collection and Use
We process personal data to achieve a clear purpose related to the nature of user communication or the requested service, including:
- Receiving and responding to inquiries.
- Evaluating the feasibility of providing the service and determining its scope.
- Verifying the client’s identity or capacity when needed.
- Reviewing documents and organizing the transaction file.
- Executing the service, tracking the request, and updating the client on developments.
- Managing the relationship with the client and issuing quotes and invoices.
- Providing technical support and managing the client portal.
- Improving site performance and user experience.
- Protecting the site and accounts, and preventing fraud and unauthorized use.
- Complying with legal requirements and responding to requests issued by competent authorities.
- Managing complaints, privacy requests, and dispute resolution.
Legal Basis for Processing
Data is processed according to the appropriate legal basis for each case, which may include:
- Consent of the data subject when consent is the appropriate basis.
- Taking steps at the client’s request prior to contracting or executing the service agreement.
- Executing obligations related to the agreed-upon service.
- Fulfilling a legal obligation binding upon the office.
- Protecting the legitimate interests of the office or users without prejudicing the rights of data subjects.
- Establishing, exercising, or defending a legal claim when necessary.
When processing relies solely on consent, the data subject may withdraw their consent, without affecting the lawfulness of processing carried out before the withdrawal.
Mandatory and Optional Data
Some data is necessary for the office to respond to an inquiry, verify a request, or execute a service, while other data is optional and used to provide additional details or improve communication.
Failure to provide essential data may result in the inability to evaluate the transaction, provide the service, or track the request. The required data will be clarified according to the case whenever possible.
Data Disclosure and Sharing
Personal data is not disclosed unless there is a legitimate purpose, a necessity related to the service, or a legal requirement, and only to the extent necessary to achieve the purpose.
Specific data may be shared with the following categories:
- Government entities or official platforms associated with the client’s request.
- Hosting, technical service, and tech support providers.
- Payment and billing service providers when used.
- Translation, authentication, or shipping offices when the client requests the associated service.
- Professional or legal advisors when there is a legitimate need.
- Competent authorities when there is a legal obligation or a binding request.
- Parties the client agrees to share with to achieve a specific purpose.
Al-Khaber Office does not sell personal data, nor does it treat it as an independent commercial product.
Processing Data Outside the Kingdom
Some technical services, such as hosting, email, or cloud storage, may rely on providers with technical infrastructure inside or outside the Kingdom of Saudi Arabia.
When transferring personal data or disclosing it to an entity outside the Kingdom, legal requirements and appropriate safeguards applicable to data transfer are observed, and only to the extent necessary to provide the service or operate the site.
Data Storage and Retention Period
Data is stored using operational systems and means relied upon by the office or contracted service providers, taking appropriate measures to limit unauthorized access.
The retention period varies according to the type of data, the purpose of collection, the nature of the service, and legal, accounting, or contractual requirements.
- Inquiry data is kept for the period necessary for reply and follow-up.
- Client files are kept throughout the execution of the service and for a necessary period after its completion.
- Financial records are kept according to applicable legal requirements.
- Specific data may be kept to manage a claim, dispute, or legal obligation.
- Data is deleted, destroyed, or anonymized when the need for it ends, unless there is a legitimate reason to retain it.
Data Protection Measures
The office takes appropriate administrative, organizational, and technical measures depending on the nature of the data and the associated risks, which may include:
- Restricting access to data based on functional need.
- Using protective measures for accounts and systems.
- Updating used software and technical components.
- Backing up data when operationally needed.
- Reviewing permissions and revoking unnecessary ones.
- Raising awareness not to share passwords and verification codes.
- Handling security incidents and taking appropriate action upon discovery.
No electronic transmission or storage method guarantees absolute security, so the user must also protect their device and accounts and not share login details.
Cookies and Similar Technologies
The site may use cookies or similar technologies to operate pages, save certain preferences, enhance security, and measure site performance when analytics tools are enabled.
Essential Cookies
These help operate the basic functions of the site or client portal, and some parts may not work correctly when disabled.
Preference Cookies
These help remember some of the user’s choices to improve the browsing experience.
Analytics Cookies
These may be used to understand how pages are used and improve performance, when analytics services are enabled and subject to available consent settings.
The user can manage cookies through browser settings, though disabling some may affect certain site functionalities.
Client Portal and Accounts
When using the Client Portal, the user is responsible for maintaining the confidentiality of their account details and for the usage that occurs through it.
- Use a strong, unique password.
- Do not share account details with an unauthorized person.
- Log out when using a shared device.
- Notify the office if unauthorized access is suspected.
- Update the phone number or email when they change.
Correspondence and Marketing Communication
The office may use contact data to send updates related to the client’s request or requested service, such as completion requests, transaction status, appointments, or invoices.
Marketing messages are only sent according to the appropriate basis, and the user can request to stop them through the available communication method, while necessary messages for an ongoing service or legal obligation will continue.
Data of Minors and Representatives
The site is primarily directed at persons capable of requesting services or their legal representatives. When a transaction involves a minor, the data must be provided by their guardian, legal representative, or a person with a legitimate capacity.
Documents of a minor or another person should not be sent without a need related to the service and a valid capacity allowing for their sharing.
External Links and Services
The site may contain links to government entities, payment platforms, maps, communication services, or independent websites. The use of these services is subject to their own policies and terms, and Al-Khaber Office does not control how they process data.
The user must verify the official domain before entering sensitive data and read the privacy policy of the external service.
Data Accuracy and Updating
The user must provide correct and up-to-date data and inform the office when information related to the service changes, such as a phone number, email, or transaction status.
The office may request a supporting document when needing to verify a correction or update request, which will be handled within the limits of the required purpose.
Data-Related Incidents
Upon discovering an incident affecting personal data, the office works to evaluate, contain, and take appropriate action, including notifying authorities or data subjects when notification is required by applicable regulations.
The user can notify the office if they suspect unauthorized access or a fraudulent message impersonating the office through the Contact Us page.
Updating the Privacy Policy
This policy may be updated when services, processing methods, systems, or technical tools change. The updated version will be published on this page with an amended update date.
Users are advised to review the policy periodically, especially before providing new data or requesting an additional service.
Submitting a Privacy Request or Inquiry
The data subject can submit a request to inquire about their data or exercise a right through the Contact Us page, providing the necessary information to verify their identity and determine the request.
- Name of the data subject.
- Communication method associated with the request.
- Type of request or right to be exercised.
- Service or transaction associated with the data.
- Any information helping to locate the requested record.
The office may request additional information to verify identity and protect data from disclosure to an unauthorized person.
To submit a privacy-related request, use the Contact Us page.
Your Rights Regarding Personal Data
These rights are exercised in accordance with the Personal Data Protection Law and its implementing regulations, and some requests may be subject to exceptions or legal verification requirements.
Right to be Informed
Knowing why data is collected, its purpose, how it is used, and the entities it may be disclosed to.
Right to Access
Requesting to view the personal data available at the office subject to legal controls.
Right to Request Data
Requesting a copy of personal data in a clear and readable format when executing this is feasible.
Right to Correction
Requesting the correction of inaccurate data, or completing or updating it when it changes.
Right to Destruction
Requesting the destruction of data that is no longer needed, considering legal retention cases.
Withdrawing Consent
Withdrawing consent when it is the sole basis for processing, according to applicable controls.
It may not be possible to execute some requests fully or partially when the law requires data retention, prohibits its disclosure, or when the request affects another person’s rights.
Personal Data Protection Law
You can refer to official sources to verify data protection provisions, data subject rights, and legal obligations.
Frequently Asked Questions About Data Protection
What data does Al-Khaber Office collect?
Does the office ask for the Nafath password?
Is my data shared with a government entity?
Does the office sell client data?
How long is data retained?
How do I request to correct my data?
Can I request to delete my data?
Al-Khaber Office Pages
Links to essential pages, legal information, and communication services.