Personal Data Protection Law — Privacy Notice

Privacy Notice

This notice explains what personal data Joushen collects through this website and in the course of its business, why we collect it, who we share it with, how long we keep it, and the rights you have over it under the Personal Data Protection Law of the Kingdom of Saudi Arabia.

Version 1.0 · Effective 2 August 2026 · Ref NOTICE/SEC/001

01

Who we are

Joushen ("Joushen", "we", "us") is a company registered in the Kingdom of Saudi Arabia under commercial registration number [CR number], with its registered address at [national address].

For the personal data described in this notice, Joushen is the controller — we decide why and how it is processed.

Where we process personal data on behalf of a client under a services agreement, the client is the controller and its own privacy notice applies to that data. This notice does not cover it.

Questions about this notice, or about your personal data, go to info@joushen.com.

02

What this notice covers

This notice applies to personal data we collect:

  • when you visit or interact with this website;
  • when you contact us by form, email, telephone, or messaging;
  • when you apply for a role with us;
  • when you represent a client, supplier, or partner we deal with;
  • when you subscribe to updates or attend an event we run.

It does not apply to third-party websites we link to. Those sites publish their own notices.

03

Personal data we collect

Where it comes fromWhat we collect
Website visitIP address, approximate location derived from it, device and browser type, pages viewed, referring page, and the date and time. Recorded server-side by our hosting provider (Cloudflare) as standard request logs — not through analytics cookies. See section 5.
Contact formYour name, work email, organisation, phone number, area of interest, and the message you write. When you reach the form from a link elsewhere on the site, we also record the enquiry type (for example, a consultation or a quote) and the page you came from, so we can respond in context.
Job applicationName, contact details, CV, qualifications, employment history, references, and any information you provide during interview.
Client, supplier and partner contactsName, job title, business contact details, and records of our correspondence and meetings.
Subscriptions and eventsName, email address, organisation, and your subscription preferences.
Security and access recordsLog records generated when you interact with our systems, kept to protect those systems from misuse.

We do not seek sensitive personal data — such as data revealing racial or ethnic origin, religious, intellectual or political belief, security or criminal records, biometric or genetic data, health data, or data indicating unknown parentage — through this website. Please do not include it in messages to us. Where a role or an engagement genuinely requires it, we will ask for it separately and explain why.

Providing personal data is voluntary. If you choose not to provide what a form marks as required, we may be unable to respond to your enquiry or consider your application.

04

Why we process it, and on what basis

Under the Personal Data Protection Law we must have a lawful basis for every purpose. Ours are set out below.

PurposeLawful basis
Responding to your enquiry and providing information you asked forYour consent, given when you contact us; or performance of a contract you are party to
Assessing a job application and communicating with you about itYour consent; and steps taken at your request before entering an employment contract
Managing our relationship with clients, suppliers, and partnersPerformance of the contract, and our legitimate interest in running the relationship
Operating, securing, and improving this websiteOur legitimate interest in keeping the site available and protected from misuse
Sending updates, newsletters, or marketingYour consent, which you may withdraw at any time
Meeting legal, regulatory, tax, and record-keeping obligationsCompliance with a legal requirement
Establishing, exercising, or defending a legal claimOur legitimate interest, and compliance with a legal requirement

We do not use your personal data for automated decision-making that produces legal effects for you, and we do not sell it.

05

Cookies and analytics

This site uses very few cookies and runs no analytics or advertising technology.

  • Strictly necessary only. The only third-party component that runs in your browser is Cloudflare Turnstile, which protects the contact form from bots; it, and our host Cloudflare, may set short-lived tokens or cookies needed to serve the site securely. These do not require consent.
  • No analytics. We run no analytics of any kind — no Google Analytics, no third-party analytics, no page-view tracking.
  • No advertising or marketing cookies, and no cross-site tracking.

Your language preference is remembered only in your browser’s local storage — it is not a cookie and is never sent to us. Because we set no non-essential cookies, the site shows no cookie-consent banner and there is nothing to opt into or out of. You can clear site data in your browser at any time.

The standard server logs our host (Cloudflare) generates when the site is requested are described in section 3.

06

Who we share it with

We do not sell personal data and we do not share it for anyone else’s marketing. We disclose it only to:

  • Service providers that process data on our instructions — including Resend (transactional email for the contact form), Cloudflare (website hosting, the spam check, and the rate-limit store), and our email and file-storage providers. Each is bound by a written agreement requiring confidentiality, appropriate security, and deletion or return of the data.
  • Professional advisers — such as legal, audit, or accounting advisers — where they need it to advise us.
  • Competent authorities, where disclosure is required by law or by a valid order. We verify the legal basis of every such request, disclose only what is required, and keep a record of it.
  • A purchaser, if the business or part of it is transferred, subject to the same protections.
07

Transfer outside the Kingdom

Some of the service providers we rely on to run this website store or access personal data outside the Kingdom. In particular, Resend (which delivers contact-form email) and Cloudflare (which hosts the site and runs the spam check and rate-limit store) operate globally, including in the United States and other regions. [exact regions depend on Cloudflare edge routing and Resend infrastructure — to confirm with each provider during data-mapping]

Where personal data is transferred outside the Kingdom, we do so only in accordance with the Personal Data Protection Law and its regulations on data transfer, and we apply the safeguards those regulations require. You may ask us for details of these arrangements using the contact details in section 14.

For client confirmation: this states that personal data IS processed outside the Kingdom, which is factually the case for Cloudflare and Resend. The all-within-the-Kingdom alternative does not apply and has been removed. Confirm the region list after the data-mapping exercise.
08

How long we keep it

We keep personal data only for as long as we need it for the purpose it was collected for, or for as long as a law requires.

DataRetention
Contact-form enquiries and correspondence[e.g. 24 months from last contact — to confirm]
Unsuccessful job applications[e.g. 12 months — to confirm]
Client and supplier records[e.g. 10 years — check statutory period]
Subscription and marketing records[until consent is withdrawn]
Website server logs[period — to confirm with Cloudflare]
Rate-limit countersExpire automatically within about 10 minutes (Cloudflare KV).

At the end of the period the data is destroyed or irreversibly anonymised. Copies held in backups are overwritten in the normal backup cycle. Note that contact-form submissions are delivered to us as email and are not stored in any database of ours; they remain in our email inbox for the retention period above.

09

How we protect it

We apply organisational and technical measures to protect personal data, including classification of information by sensitivity, access on a least-privilege basis, multi-factor authentication, encryption in transit and where supported at rest, logging, backup, and staff training. The contact form is served over HTTPS and protected by a bot check and rate limiting, and every field is validated and sanitised before an email is generated.

If a personal data breach occurs that may cause harm to you or to your data, we assess it and notify the competent authority within 72 hours of becoming aware of it. Where the breach is likely to cause you serious harm, we notify you without undue delay.

10

Your rights

Under the Personal Data Protection Law you have the right to:

  • be informed — to know the legal basis and purpose for which we collect your personal data;
  • access your personal data held by us;
  • obtain a copy of it in a readable and clear format;
  • request correction, completion, or updating of it;
  • request destruction of it where it is no longer needed for the purpose it was collected for;
  • withdraw consent at any time, where our processing relies on consent.

Exercising these rights is free. Send your request to info@joushen.com. We may ask you for information to verify your identity before we act, and we ask only for what we need to be sure.

We respond within [30 days — confirm current statutory period] of receiving a complete request. If we cannot meet a request in full, we tell you why and on what legal ground.

11

Complaints

If you are not satisfied with how we have handled your personal data or your request, contact us first at info@joushen.com so we can put it right.

You also have the right to complain to the Saudi Data & Artificial Intelligence Authority (SDAIA), which supervises the Personal Data Protection Law. Contacting us first does not affect that right.

12

Children and legal capacity

This website is intended for business audiences and is not directed at children. Where we need personal data relating to a person who lacks legal capacity, we obtain the consent of their guardian or legal representative. If you believe we hold data about a child or a person lacking capacity without that consent, contact us and we will delete it.

13

Changes to this notice

We review this notice at least once a year, and whenever our processing changes. The version number and effective date at the top of the page tell you which version applies. Where a change materially affects how we use your personal data, we will bring it to your attention rather than rely on the updated page alone.

14

Contact us

For anything relating to this notice or to your personal data:

  • Email — info@joushen.com
  • Telephone — [telephone]
  • Address — [national address]

Our personal data protection contact is [role or name].