Last updated: 30 August 2026

Privacy policy

This policy explains how majal.sa handles visitor, contact, proposal-request, partner-network and optional attachment data. The Arabic version remains the governing text.

A connected trust ecosystem for identity, encryption, audit, data protection and governance
Trust that can be verifiedSecurity, identity, audit and clear accountability

Controller and contact

Majal Business Establishment for Communications & IT, unified national number 7004290479 and commercial registration number 1010451438, operates this website from Riyadh, Saudi Arabia. Privacy requests may be sent to info@majal.sa with “Privacy request” in the subject line.

Scope

This policy covers public pages, contact and proposal forms, optional attachments, partner-network applications and portal activity, correspondence begun through the site, and technical data needed to operate, protect and measure the service.

Data we may process

Contact and organisation details, project context, selected products or services, partner-application details and chosen files, basic visit, device and network information, first-party random identifiers, interface events and security logs. When a form is submitted, the internal notice includes its name and URL, the submitted fields and limited technical context such as browser, operating system, device, language, timezone, referrer and approximate country or city when available. It excludes raw network addresses, precise location, credentials, session values and secrets.

Data you should not send

Do not submit passwords, one-time codes, access tokens, API keys, payment or banking details, official identity documents, patient or health records, customer lists containing personal data, or confidential material not required for the request. The proposal and partner-application forms do not request official identity documents.

Purposes and lawful basis

We use data to operate and protect the site, respond to requests, prepare a scope or proposal, evaluate partner applications, manage authorised partner activity, measure aggregate performance and meet applicable obligations. The lawful basis depends on purpose and may be steps requested before contracting, contract, legal obligation, legitimate interest or consent where required.

Providers, disclosure and transfers

We do not sell personal data. Limited data may be shared with hosting, email, security, analytics or professional providers for a defined purpose under appropriate access, confidentiality and security controls, or when required by a competent authority. Any required cross-border processing is assessed under the applicable Saudi requirements before transfer.

Automatic first-party measurement

From 10 September 2026, limited measurement starts without a consent popup. This operating mode is not recorded as your consent. It records public page paths without queries, visible browsing time, scroll depth, device class, browser family and major version, language, source and approximate country/city. It does not collect browser fingerprints, replay, pointer movements, field values or precise location. IP is used in memory for an offline approximate lookup, not persisted in the new measurement records; separate security logs may still exist. IP Geolocation by DB-IP.

Browser identifiers and choices

The random first-party mj_vid identifier lasts up to 90 days after refresh; mj_sid expires after 30 minutes of inactivity. These identify a browser, not a confirmed person; device changes or clearing storage can create a different identifier. Settings below this policy let you stop measurement or offers. Saved refusals, Do Not Track and Global Privacy Control are respected. Preferences remain until changed or removed; an expired legacy policy does not cancel a refusal.

Relevant product offers

Product interest is inferred from page visits, not certain intent. Eligible browsers with at least three Flow sessions in 30 days and 30 seconds of previous active viewing are assigned equally to a comparison group or a Flow-offer group. After 20 seconds of visible browsing, the offer may appear once and can be dismissed. No name is inferred; contact details are linked only when voluntarily submitted. Offer delivery and actual saved Flow inquiry comparison use a 14-day window; clicks are not inquiries. Measurement update: 10 September 2026, version 2026-09-10-first-party-v1.

Optional partner draft

Local draft saving is off by default. If the applicant enables it, only non-sensitive selections such as portfolio, path, country and capabilities are stored in the browser for seven days. Names, registration and tax numbers, contact details, URLs, free text, opportunity details and files are excluded, and the draft can be disabled or deleted at any time.

Retention and destruction

Detailed analytics events are kept for up to 395 days after aggregation; network-address data is removed or de-linked after 90 days; rejected, cancelled or spam proposal requests may be retained for up to two years after the last update; rejected or withdrawn partner applications and attachments for up to one year; and privacy-request records for up to five years. Active contracts, disputes or legal obligations may require a documented extension. Destruction uses deletion from active systems followed by backup expiry, or de-identification where aggregate data remains useful.

Security

Controls proportionate to risk include role-based access, protected transfer, file validation, logging of sensitive operations, backup and review. No electronic service can promise absolute security.

Your rights and response time

Where applicable, you may ask to be informed, access, correct, complete, receive a copy of or request destruction of your data, and withdraw consent where processing relies on it. We may verify identity and will respond without undue delay and within 30 days of a complete request unless a documented extension is permitted and communicated.

Complaints, links and updates

Questions or complaints may be sent to info@majal.sa. If unresolved, a complaint may be submitted through SDAIA’s National Data Governance Platform. External services have their own policies. Effective and updated 2 September 2026, version 2026-09-02-form-context-v1. Material changes update the version and date on this page.