Table of Content
1. Introduction
1.1 Policy Purpose
1.2 Policy Scope
1.3 Abbreviation
1.4 Definition
2. Policy Body
2.1 Roles and Responsibilities
2.2 Personal Information We Collect and How to Use It
2.2.1 Data Security, Storage, Retention, and Cookies
2.3 Your Choices and Rights as a Data Subject
2.3.1 Legal Compliance, Disclosure, Contact and Updates
3. References & Attachments
3.1 Reference & Attachment 1
3.2 Reference & Attachment 2
1. Introduction
1.1 Policy Purpose
This Policy sets out top management's commitment to protecting the privacy and Personal Information of customers and other data subjects Who use Neoleap's (The Global Digital Financial Solutions Company) services, including the Unified Merchant Portal.
The objective of this Policy is to describe how Neoleap collects, uses, discloses, stores and protects Personal Information in compliance with the Personal Data Protection Law (PDPL) and other applicable laws and regulations within the Kingdom of Saudi Arabia, and to define the need for a formal, board-endorsed Privacy/Data Protection Policy governing these activities.
1.2 Policy Scope
This Policy applies to all Personal Information collected, processed and stored by Neoleap (The Global Digital Financial Solutions Company), whether collected online or offline, including through Neoleap ls we b5ite, mobile applications, social media, customer service interactions and the Unified Merchant Portal.
It covers Neoleap's operations with in the Kingdom of Saudi Arabia and applies to all customers, merchants and other individuals who interact with Neoleapls services.
1.3 Abbreviation
PDPL| Personal Data Protection Law
SDAIA| Saudi Data and Artificial Intelligence Authority (Competent Authority for the PDPL)
SAMA| Saudi Central Bank
KSA| Kingdom of Saudi Arabia
UMP| Unified Merchant Portal
DPO| Data Protection Officer
1.4 Definition
Personal Information| Any information that can be used to identify an individual, including but not limited to name, email address, contact information, and location data.
Data Subject| An individual who can be identified, directly or indirectly, by reference to Personal Information.
Data Controller| The entity that determines the purposes and means of processing Personal Information.
Data Processor| The entity that processes Personal Information on behalf of the Data Controller.
Consent| The freely given, specific, informed, and unambiguous indication of the data subjects wishes by which they, by a statement or a clear affirmative action, signify agreement to the processing of Personal Information relating to them.
Processing| Any operation or set Of operations performed on Personal Information, whether or not by automated means such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, or erasure.
Lawful Basis| The legal grounds on which Personal Information can be processed under applicable data protection laws.
Data Retention| The period during which Personal Information is stored or held by the Data Controller or Data Processor.
Third Party| Any individual or entity other than the data subject, Data Controller, Data Processor, or persons authorized under the direct authority of the Data Controll er or Data Processor to process Personal Information.
1.5 Impact Polices
Specify the other policy names that connected to the policy under review
2. Policy Body
This section sets out the substantive requirements of Neoleap's Privacy Notice governing the collection, use, sharing, storage, retention and protection of Personal information, and cross-references the Personal Data Protection Law (PDPL) and related Neoleap policies and procedures.
2.1 Roles and Responsibilities
Implementation: Business units and functions handling Personal Information within Neoleap (including the Unified Merchant Portal team, IT, and Customer Service) are responsible for implementing this Policy and its associated procedures in their respective work areas.
Monitoring: The Governance, Risk and Compliance function (including the Data Protection Officer) is responsible for monitoring implementation of, and compliance with, this Policy and its associated procedures.
Key Stakeholders: Customers, merchants, and other data subjects who use Neoleap's services are directly affected by this Policy. Business units responsible for implementation and compliance monitoring must be consulted during development or revision of this Policy and its associated procedures.
2.2 Personal Information We Collect and How to Use It
Data collected: Device information (hardware model, operating system, unique device identifiers, mobile network information); transaction information (account activity and product usage); usage information (features used, pages visited, actions taken); location information; information you provide directly (name, email address and other contact information); and data collected from partner schemes.
How it is used: To provide and improve our services; respond to inquiries and requests; communicate about our services and related offers; personalize your experience; analyze and improve our business operations and Unified Merchant Portal services; enforce our Terms of Service and other regulatory policies; protect you against fraud through identity, credit and conflict checks; and promote new products and services that may be of interest to you.
How it is shared: With your consent; with service providers performing services on our behalf (e.g. hosting, data analysis, custom er service); to comply with applicable laws, regulations or legal processes; to protect our rights, property or safety, or those of others; and in connection with a merger acquisition, or sale of assets.
2.2.1 Data Security, Storage, Retention, and Cookies
Storage: Personal Data is stored on secure servers located within the Kingdom of Saudi Arabia, on Neoleap it's own premises as well as on cloud infrastructure within the Kingdom,
Security: Reasonable technical, administrative and procedural measures are implemented to protect Personal Data from unauthorized access, use or disclosure, and security practices are reviewed and updated regularly. No method of transmission or storage can guarantee absolute security.
Cookies: Our websites use cookies to collect information about how our websites are used, which may include your data; the use of cookies is essential to the operation of our services.
Retention: Personal Data is retained only for as long as necessary to fulfil the purposes outlined in this Policy or as required by applicable law. When no longer needed, data is deleted or anonymized, You have the right to request deletion of your information, unless retention is required by law or for legitimate business purposes.
2.3 Your Choices and Rights as a Data Subject
Your choices: You may choose not to provide certain information, which may limit your ability to use our services or certain features. You may also opt out of our services by following the instructions provided by our customer support channels.
Your rights under the PDPL: Right to Access the Personal Data we hold about you; Right to Erasure of your Personal Data in certain circumstances; Right to Correction of Personal Data we hold about you; Right to Withdraw Consent at any time where consent is the lawful basis for processing; Right to Request a copy of your Personal Data; Right to Lodge a Complaint with SDAIA if you believe your rights under the PDPL have been violated (gene rally within 90 days of the incident or of becoming aware of it); and Right to Compensation before the competent court for material or moral damage resulting from any violation of the PDPL or its Implementing Regulation.
Exercising your rights: Please contact our customer support team. Requests are addressed within 30 days of correct receipt, with a possible extension of up to 30 additional days in case of multiple requests or requests needing unexpected additional time or effort.
2.3.1 Legal Compliance, Disclosure, Contact and Updates
Regulatory compliance: Neoleap is regulated and supervised by the Saudi Central Bank (SAMA) and complies with the Personal Data Protection Law (PDPL) issued pursuant to Royal Decree No. (M/19) dated 09/02/1443 AH (16/09/2021 G), as amended by Royal Decree No. (M/148) dated 05/09/1444 AH (27/03/2023 G), and its Implementing Regulation, supervised and enforced by SDAIA.
Lawful basis for processing: Consent; contractual necessity; legal obligation; and legitimate interests, provided such processing does not override the data subject's rights and freedoms.
Disclosure of Personal Data: Personal Data may be shared primarily with recipients within Saudi Arabia within the scope of the PDPL Where necessary (eg. international payment card networks or cloud hosting providers), Personal Data may be disclosed to recipients outside the Kingdom in accordance with Article 29 of the PDPL and the Regulation on Personal Data Transfer outside the Kingdom, subject to appropriate safeguards.
Contact and updates: Inquiries can be directed to dpo@neoleap.com.sa, customer care (8001000085), or www.neoleap.com.sa, This Policy may be updated from time to time; material changes will be notified by email or via a notice in the App.
3. Reference & Attachment
3.1 Reference & Attachment 1
Personal Data Protection Law (PDPL), issued pursuant to Royal Decree No. (M/19) dated 09/02/1443 AH, and its Implementing Regulation.
3.2 Reference & Attachment 2
Neoleap Unified Merchant Portal Privacy Notice (Version 2.0).
