Privacy Policy
Your trust is the foundation of everything we do. This policy explains, in plain language, what personal data we collect and why — and how our service model is built so that your live business data stays beyond our reach.
We handle data in line with the Saudi Personal Data Protection Law (PDPL) and SAMA cyber-security expectations.
Last updated: 27 June 2026
On this page
- 1. Overview & who we are
- 2. The personal data we collect
- 3. Our no-access principle — we cannot access your data
- 4. How we use personal data
- 5. Our legal basis under the PDPL
- 6. Sharing & disclosure
- 7. International transfers & data residency
- 8. How long we keep data
- 9. How we protect data
- 10. Your rights under the PDPL
- 11. Cookies & analytics
- 12. Children's data
- 13. Changes to this policy
- 14. Contact & complaints
01Overview & who we are
This Privacy Policy explains how Satmz (SAT Microsystems) (“Satmz”, “we”, “us”, “our”) collects, uses, discloses, and protects personal data when you visit satmz.com, request a quote, purchase a service, or use our client portal. We are the data controller for the personal data described in this policy.
Satmz is established in the Kingdom of Saudi Arabia, with its head office at Al Aqsa Business Park, Prince Mitab Street, Jeddah 21572.
We handle personal data in accordance with the Saudi Personal Data Protection Law (PDPL), issued by Royal Decree No. M/19 and its Implementing Regulations, as supervised by the Saudi Data & Artificial Intelligence Authority (SDAIA). We operate in a secure, compliant environment aligned with the National Cybersecurity Authority (NCA) controls, the Saudi Central Bank (SAMA) Cyber Security Framework, ISO/IEC 27001 (Information Security Management), and SOC 2(Security, Availability & Confidentiality) principles.
This policy draws an important distinction that runs throughout the document:
- Account & contact data — information you give us directly so we can sell, deliver, bill, and support a service (name, work email, company, order details). We process this to run our business with you.
- Your business data & systems— the data inside your IT environment, networks, devices, and applications. This is yours. As explained in section 3, our operating model is built so that we are structurally unable to access it.
02The personal data we collect
We limit collection to what we genuinely need. The categories are:
- Identity & contact data — name, job title, company name, work email, phone number, and office address.
- Commercial & order data — services quoted or purchased, configurator selections, scope, and order history.
- Billing data — billing entity, VAT number, and invoice history. We do not store full card numbers. Card payments are processed by Stripe; we only ever see a token and the last four digits.
- Account & portal data — login email, hashed password, project status, deliverable documents you choose to download, and support messages.
- Assessment & enquiry data — answers you submit to the IT assessment and details you include in contact or emergency-support forms.
- Technical & usage data— IP address, device and browser type, and pages viewed, collected through strictly necessary and (with consent) analytics cookies. See section 11.
We do not intentionally collect special-category personal data (such as health, religious, or biometric data) through this website, and we ask that you do not submit it through our forms.
03Our no-access principle — we cannot access your data
Satmz delivers managed and implementation work for IT, cloud, and security environments. Naturally, clients ask the most important question first: “when you work in our systems, can you see our data?” In the Kingdom of Saudi Arabia the regulatory bar for this is exceptionally strict, and we have engineered our service model to meet it.
We are structurally unable to access your business data.
Your business data stays inside your tenancy, on your infrastructure, under your control. We do not hold standing access, we do not retain your credentials, and we do not keep copies of your data. We cannot read, copy, or export it — no matter what.
This is not a promise of good behaviour; it is how the system is built:
- You own the tenancy. Your Microsoft 365, cloud, and infrastructure tenants belong to you. We operate within them under your governance, never on a shared Satmz-owned store of your data.
- No standing access. We hold no permanent administrative access to your environment. Any access is just-in-time: explicitly granted by you, scoped to a single task, time-limited, and automatically revoked when the task ends.
- You hold the keys. Where work touches encrypted systems, the encryption keys remain under your control. Without them, data is unreadable to us by design.
- No credential retention. We do not store your passwords, keys, or tokens after a piece of work is complete.
- Everything is logged on your side. Because access is granted by you, every action we take is recorded in your audit logs, which you can review and revoke at any time.
- Data stays in the Kingdom. Client data is kept within Saudi Arabia (or a destination you approve) and is never moved out of region for our convenience. See section 7.
The narrow, deliberate exception is the account and contact data you give us directly — your name, email, order, and the deliverable documents we prepare for you. We obviously process that information to run the relationship, and the rest of this policy explains exactly how. The principle above governs your business data and live systems, which are a different thing entirely.
04How we use personal data
We use the personal data described in section 2 to:
- respond to enquiries, prepare quotes, and provide pricing and scope;
- set up your account, process orders, and deliver the services you buy;
- issue invoices, process payments through Stripe, and meet our tax and accounting obligations;
- operate the client portal — project status, document access, and support messages;
- provide the IT assessment result and, where you ask, recommendations and follow-up;
- send service and transactional emails (order confirmations, renewal reminders, security notices);
- improve and secure the website, prevent fraud and abuse, and keep our own systems safe;
- send marketing communications where you have consented, which you can withdraw at any time.
05Our legal basis under the PDPL
Under the PDPL we rely on one or more of the following bases to process personal data:
- Performance of a contract — to deliver a service you have requested or purchased, and to manage your account.
- Legal obligation — to comply with tax, accounting, anti-fraud, and other statutory duties in the Kingdom.
- Legitimate interests — to secure our services, prevent abuse, and operate our business, balanced against your rights and interests.
- Consent — for optional analytics cookies and for marketing communications. You may withdraw consent at any time without affecting the lawfulness of earlier processing.
07International transfers & data residency
Our default is to keep personal data within the Kingdom of Saudi Arabia. Where a processor stores or processes data outside the Kingdom, we transfer it only in line with the PDPL and the SDAIA Regulation on Personal Data Transfer Outside the Kingdom — that is, to a jurisdiction recognised as providing an adequate level of protection, or under an approved safeguard such as Standard Contractual Clauses, Binding Corporate Rules, or an accredited certification.
As set out in section 3, your live business data and systems are not part of this — they remain in your environment, in the region you choose.
08How long we keep data
We keep personal data only as long as necessary for the purpose it was collected, and then for any period required by law:
- Enquiry & assessment data — up to 24 months from last contact, unless you become a client.
- Account & project data — for the life of your relationship with us and a reasonable period afterwards.
- Invoices & financial records — retained for the period required by Saudi tax and commercial law (currently a minimum of ten years).
- Deliverable documents — kept available in the portal per your contract; you may request earlier deletion.
When data is no longer needed, we securely delete or irreversibly anonymise it.
09How we protect data
Satmz operates a security-first approach aligned with ISO/IEC 27001 and SOC 2, the NCA controls, and the SAMA Cyber Security Framework. Measures include:
- encryption of data in transit (TLS) and at rest;
- the just-in-time, no-standing-access model described in section 3;
- role-based access control, multi-factor authentication, and least-privilege internally;
- password hashing and secure session handling in the portal;
- logging, monitoring, and regular review of our systems;
- vendor due diligence and contractual security obligations on all processors.
If a personal data breach occurs that is likely to cause harm, we will notify SDAIA and affected individuals within the timeframes required by the PDPL.
10Your rights under the PDPL
Subject to the conditions in the PDPL, you have the right to:
- be informed of the legal basis and purpose for collecting your personal data;
- access your personal data and request a copy;
- request correction of data that is inaccurate, incomplete, or out of date;
- request destruction of your personal data where it is no longer needed;
- withdraw consent at any time for processing based on consent.
To exercise any of these rights, contact us using the details in section 14. We will respond within the period required by the PDPL. You will not be charged unless a request is manifestly excessive.
12Children's data
Our services are intended for businesses and are not directed at children. We do not knowingly collect personal data from anyone under the age of 18. If you believe a minor has provided us with personal data, please contact us and we will delete it.
13Changes to this policy
We may update this policy from time to time to reflect changes in our services, the law, or regulatory guidance. The “last updated” date at the top shows when it last changed. For material changes we will take reasonable steps to notify you — for example, by email or a notice on the site.
14Contact & complaints
Questions about this document can be sent to privacy@satmz.com, or by post to Satmz (SAT Microsystems), Al Aqsa Business Park, Prince Mitab Street, Jeddah 21572, Kingdom of Saudi Arabia. You can also reach us through our contact page.
If you have a concern about how we handle your personal data, we encourage you to contact us first so we can resolve it. You also have the right to lodge a complaint with the supervisory authority, the Saudi Data & Artificial Intelligence Authority (SDAIA).
