International Privacy Notice
How Satmz handles personal data for clients outside Saudi Arabia, including United Kingdom and European Economic Area data subjects.
Remote support means your data reaches Saudi Arabia. We say so plainly, and we set out the safeguards, because a compliance team finding that out for themselves at renewal is a worse outcome for everyone.
Last updated: 5 September 2026
On this page
01Who we are
This notice explains how Satmz (SAT Microsystems) (“Satmz”, “we”, “us”) handles personal data for clients and enquirers outside Saudi Arabia. If you are in Saudi Arabia or the GCC, our main privacy policy applies instead.
Satmz is established in the Kingdom of Saudi Arabia, with its head office at Al Aqsa Business Park, Prince Mitab Street, Jeddah 21572, and a second operations centre in Riyadh. All services described on this part of the site are delivered remotely from those two locations.
For enquiries and for the personal data of your own staff that we hold in order to run a support desk, we are the controller. For data inside the systems we monitor on your behalf, we are a processor and you remain the controller — see When we act as your processor.
02Which law applies to you
Satmz is a Saudi company, but data protection law follows the person rather than the company. Where you are in the United Kingdom or the European Economic Area, the UK GDPR or the EU GDPR applies to our handling of your personal data, and this notice is written to meet them.
Where you are elsewhere, we apply the same standards as a matter of practice, alongside any local law that applies to you.
Saudi law also applies to us
As a Saudi-established company we remain subject to the Saudi Personal Data Protection Law (PDPL) and to SAMA cyber-security expectations. Where two regimes both apply, we follow the stricter requirement.03What we collect
We collect three distinct kinds of data, and they are worth separating.
1. Enquiry and account data
- Name, work email, telephone number, company name and job role
- What you configured on this site — device counts, categories, the support level chosen, and the resulting quotation
- Correspondence with us, including support tickets you raise
- Billing contact details and invoice records
2. Service telemetry from your estate
- Device inventory: make, model, operating system, patch level, serial
- Health and performance metrics, alerts, and event logs
- User account names and sign-in events, where identity is in scope
- Backup job status and retention records
3. Website data
- Pages viewed and actions taken, via a privacy-respecting analytics setup. See our cookie disclosure
- The country your request came from, used only to offer you the right version of this site. It is not stored against you as an individual
- IP address, for security, rate limiting and abuse prevention
What we do not take
We do not need access to your business content — documents, mailboxes, databases, customer records — in order to monitor and maintain the systems holding it, and we do not take it. Where a specific support task genuinely requires access to content, we ask first and it is recorded.04Our lawful basis for using it
Under the UK and EU GDPR we must have a lawful basis for each purpose. Ours are:
- Contract. Delivering the support services you have bought, operating the service desk, invoicing, and administering your account.
- Legitimate interests. Responding to your enquiry, securing our own systems, preventing abuse of our forms, and improving the service. We have weighed these against your rights and consider them proportionate; you may object at any time — see Your rights.
- Consent. Non-essential analytics cookies, and any marketing email. You can withdraw consent at any time, and withdrawing it is as easy as giving it.
- Legal obligation. Tax, accounting and record-keeping requirements that apply to us.
We do not sell personal data, and we do not use it for automated decision-making that produces legal or similarly significant effects.
05Where your data goes
This is the section most likely to matter to your own compliance team, so it is stated plainly.
Delivering remote support means your data is transferred to Saudi Arabia. Our engineers, our monitoring platform and our service desk are all operated from Jeddah and Riyadh. Telemetry from your estate reaches systems there continuously, and that is inherent to the service rather than incidental to it.
Saudi Arabia is not the subject of a UK or EU adequacy decision. Transfers from the UK or EEA therefore require appropriate safeguards, and those safeguards are put in place as part of the agreement we sign with you:
- Standard Contractual Clauses — the EU SCCs, together with the UK International Data Transfer Addendum where the UK GDPR applies — executed alongside your service agreement before we begin monitoring anything
- A transfer risk assessment covering the destination’s legal regime, provided with them
- Technical measures that reduce what is transferred in the first place: encryption in transit and at rest, least-privilege access, and a scope that excludes your business content
Enquiring through this website is a different matter. When you send us your details through a form, you are providing them to us directly rather than having them transferred on your behalf, and the safeguards above attach to the service agreement rather than to an enquiry.
Raise it during scoping, not at renewal
If your organisation runs a transfer-impact assessment, tell us early. We would rather answer it once, properly, before anything is signed.A small number of sub-processors operate elsewhere — our hosting, email delivery and CRM providers. Each is bound by a data processing agreement and appropriate transfer safeguards. A current list is available on request.
06When we act as your processor
For personal data inside the systems we look after — your staff’s accounts, the contents of a mailbox we back up, an access log we monitor — you are the controller and we act on your instructions.
In that role we commit to:
- Process personal data only on your documented instructions
- Ensure everyone with access is bound by confidentiality
- Apply appropriate technical and organisational security measures
- Engage sub-processors only under equivalent terms, and tell you before adding or replacing one
- Assist you with data subject requests and with your own impact assessments
- Notify you without undue delay on becoming aware of a personal data breach
- Delete or return the data at the end of the engagement, at your choice
These commitments are set out in full in a Data Processing Agreement executed alongside your service agreement. Ask for it during scoping and we will put it in front of you before you commit to anything.
07How long we keep it
We keep personal data for as long as there is a reason to, and no longer. Rather than quote a single figure that would be wrong for half the cases, here is how each period is actually decided:
- Enquiries that do not become clients — while a conversation is live and for a reasonable period afterwards, in case you come back to it. Reviewed periodically and cleared when it is plainly finished
- Client account and contract records — for the life of the engagement, then for as long as tax, accounting and limitation rules require us to be able to evidence what was agreed
- Support tickets and correspondence — while they remain useful for supporting you, since a recurring fault is often only visible across its own history
- Service telemetry and logs — for as long as it takes to spot a trend and investigate an incident, which is a matter of months rather than years, and no longer than your contract specifies
- Backups — exactly as long as the retention policy you set, which is yours to decide and ours to apply
If you want a specific period written into your contract, ask and we will agree it. You can also ask us at any time what we hold about you and have it deleted — see Your rights.
08Your rights
If the UK or EU GDPR applies to you, you have the right to access your personal data; to have inaccurate data corrected; to have it erased; to restrict or object to how we use it; to receive it in a portable form; and to withdraw consent where consent is the basis we rely on.
Write to connect@satmz.com and we will respond within one month. There is no charge, and we will not ask you to justify the request.
You also have the right to complain to a supervisory authority — the Information Commissioner’s Office in the UK, or your national authority in the EEA. We would rather you came to us first, but that is your choice and not a condition.
09How we protect it
Satmz is ISO 27001 certified and ITIL-aligned. In practice that means encryption in transit and at rest, role-based access on a least-privilege basis, multi-factor authentication on every administrative account, logging of administrative actions, and regular review of who has access to what.
No security is absolute, and we will not claim otherwise. If a breach affects your personal data we will tell you without undue delay, tell you what we know, and tell you what we are doing about it — including where the news is bad.
10Contact us
For any question about this notice, about what we hold, or to exercise a right:
Questions about this document can be sent to privacy@satmz.com, or by post to Satmz (SAT Microsystems), Al Aqsa Business Park, Prince Mitab Street, Jeddah 21572, Kingdom of Saudi Arabia. You can also reach us through our contact page.
If you are enquiring about a support plan rather than about privacy, the international contact page reaches the right team faster.
