1. Introduction & Scope
This Privacy Policy explains how CISO Consulting ("we", "us", the "Company") collects, uses, discloses, transfers and protects personal data when you use the ciso.sa platform, our websites, applications, APIs and related services (the "Services"). It applies to visitors, registered users, enterprise clients and their authorised personnel, and to individuals whose data is provided to us.
We are committed to processing personal data lawfully, fairly and transparently in accordance with the Saudi Personal Data Protection Law (PDPL) and its Implementing Regulations. This policy should be read together with our Terms & Conditions.
2. Our Role (Controller / Processor)
We act as a data controller where we determine the purposes and means of processing (for example, account administration, security and billing). We act as a data processor where we process personal data on behalf of an enterprise client under a services agreement, following that client's documented instructions. For controller processing, our contact for privacy matters is privacy@ciso.sa.
3. Key Definitions
Personal data means any data that identifies or can identify a natural person. Processing means any operation performed on personal data. Data subject means the individual to whom the data relates. Sensitive data has the meaning given under the PDPL and receives additional protection.
4. Personal Data We Collect
We collect only what we need to deliver and secure the Services:
- Identity & contact — name, work email, phone, job title, organisation and country.
- Account & profile — credentials (stored hashed), preferences, language and settings.
- Content you provide — assessments, evidence, documents and messages you upload to the GRC modules and support.
- Usage & device — pages viewed, actions taken, IP address, browser and device attributes, approximate location derived from IP, and session activity used for security and analytics.
- Communications — support tickets, survey responses and correspondence.
- Billing — plan, invoices and transaction references. Card data is handled by our licensed payment provider; we do not store full card numbers.
5. How We Obtain Data
We obtain personal data directly from you (when you register, subscribe, upload content or contact us), automatically through your use of the Services (cookies and logs), and from your organisation where it provisions your access. Where you provide data about others, you confirm you have a lawful basis and authority to do so.
6. Purposes & Legal Bases
We process personal data to: provide, operate and maintain the Services; create and administer accounts; authenticate users and secure the platform; deliver support; process payments and prevent fraud; personalise and improve the Services; send transactional and (where permitted) marketing communications; and comply with legal, tax and regulatory obligations. Our lawful bases include performance of a contract with you, your consent (which you may withdraw at any time), our legitimate interests in operating and securing the platform, and compliance with applicable law.
7. Cookies & Similar Technologies
We use strictly-necessary cookies for authentication, session management and security; and optional analytics cookies to understand and improve usage. You can control non-essential cookies through your browser or, where offered, our cookie settings; disabling essential cookies may impair the Services. We honour applicable consent requirements for non-essential cookies.
8. Disclosure & Sub-Processors
We do not sell personal data. We disclose it only to: vetted sub-processors who support the Services (such as cloud hosting, email delivery and payment processing), each bound by contractual confidentiality and security obligations; your organisation's administrators where you use an enterprise account; professional advisors; and competent authorities where required by law or to protect rights and safety. Enterprise client data is logically segregated and processed strictly per the client's instructions.
9. Cross-Border Transfers
We prioritise data residency inside the Kingdom of Saudi Arabia. Where a transfer of personal data outside the Kingdom is necessary, we carry it out only on the legal bases and safeguards permitted by the PDPL and any applicable requirements of the Saudi Data & AI Authority (SDAIA) and the National Data Management Office (NDMO), ensuring an adequate level of protection for the data.
10. Your Rights under the PDPL
Subject to the PDPL, you have the right to: be informed of the legal basis and purposes of processing; access your personal data; request correction of inaccurate or incomplete data; request destruction of data no longer needed; and withdraw consent where processing is based on consent. Exercising a right will not disadvantage the Services you are entitled to, and we will not discriminate against you for doing so.
11. Exercising Your Rights
To exercise any right, contact us at privacy@ciso.sa with enough detail to locate your data. We may need to verify your identity before responding. We respond within the periods prescribed by the PDPL and its Regulations, and will explain if an exemption applies. If we process your data as a processor for an enterprise client, we will refer your request to that client where appropriate.
12. Data Retention
We retain personal data only for as long as necessary for the purposes described, to meet legal, tax and regulatory obligations, and to establish, exercise or defend legal claims. Retention periods vary by data type and context; when data is no longer required it is securely deleted or anonymised in line with our retention schedule. Backups are cycled and purged on a rolling basis.
13. Security Measures
We apply layered technical and organisational controls appropriate to the risk, including encryption in transit, hashed credentials, access controls and least-privilege, network and application-layer defences, monitoring and logging, and staff confidentiality obligations. No system is perfectly secure; we continuously test and improve our controls.
14. Personal Data Breach
We maintain procedures to detect, assess and respond to personal-data breaches. Where a breach is likely to cause harm, we will notify the competent authority and affected data subjects within the timeframes and in the manner required by the PDPL and its Regulations.
15. Automated Processing & AI
Some features use automated and AI systems (for example, to generate reports or assist analysis). We do not use such processing to make decisions producing legal or similarly significant effects about you without an appropriate legal basis and safeguards. You should independently review AI-generated output before relying on it, and must not submit others' personal data to AI features without a lawful basis.
16. Marketing & Communications
We may send you service-related (transactional) messages that are necessary to operate your account. We send marketing communications only where permitted and, where required, with your consent. You can opt out of marketing at any time using the unsubscribe link or by contacting us; opting out does not affect transactional messages.
17. Children
The Services are intended for professionals and are not directed at children under 18. We do not knowingly collect their personal data; if we become aware that we have, we will delete it.
18. Third-Party Websites
The Services may link to websites and services we do not control. This policy does not apply to them; please review their own privacy notices. We are not responsible for their content or practices.
19. Changes to this Policy
We may update this policy from time to time. We will post the updated version with a new effective date and, for material changes, provide reasonable notice. Continued use of the Services after changes take effect indicates acceptance of the updated policy.
20. Complaints & Supervisory Authority
If you have a concern about how we handle your personal data, please contact us first at privacy@ciso.sa so we can address it. You also have the right to lodge a complaint with the competent Saudi supervisory authority, the Saudi Data & AI Authority (SDAIA).
21. Contact
For any privacy question or to exercise your rights, contact our privacy team at privacy@ciso.sa. CISO Consulting, Riyadh, Kingdom of Saudi Arabia.