This privacy policy (the "Privacy Policy") tells you how EFG Hermes KSA (the "Company," "we," "our," or "us") process personal data we collect about you in accordance with the Saudi Personal Data Protection Law (PDPL) and its implementing regulations (collectively, the "PDPL"). The PDPL establishes protections for your personal data and grants you certain rights. This Privacy Policy applies when you use our websites, and interact with us (collectively, the "Services"). The policy also describes the manner by which we use cookies and employ similar tracking technologies. Additionally, this Privacy Policy sets out your personal data protection rights, including your right to object to some of the data processing which we carry out.
The controllers of your personal data are listed under Annex 1 of this Privacy Policy.
We are committed to protecting your privacy and personal data, and we take our responsibility to hold your personal data securely and in strict confidence seriously.
+
What personal data do we process about you ?
We collect the following personal data you provide during your use of the Services:
- Your name
- Your date of birth
- Your gender
- Data which appears on your government or state issued identification documents (e.g. passport and national ID)
- Your phone number
- Your fax number
- Your residential address
- Your postal address
- Your e-mail address
- Your demographic information
- Your bank account
- Information about your income
- Information about your account balances
- Your account details (including your username and your password) in respect of the accounts used to access our website
- Your IP address
- Your browser or your device information
- Information about how you access and/or use our Services
- Information collected via the employment of cookies, pixel tags, google tags, tracking URLs, and other similar tracking technologies
- Telephonic or electronic recordings
- Survey responses and similar information which reveal your views and preferences
+
How do we collect your personal data?
We and our third-party service providers collect the above information in a variety of ways. This includes from you directly and:
- Through your browser and/or your device:
Certain information/personal data is collected by most browsers or automatically through devices, including, but not limited to, your Media Access Control (MAC) address, your computer type (Windows or Mac), your screen resolution, your operating system name and version, your device manufacturer and model, the language selected on your browser or device, your internet browser type, the version and the name of the services/applications you use. We also collect your IP address, which is automatically assigned to a computer by an Internet Service Provider. An IP address will be identified and logged automatically in our server log files whenever you access any of our Services, along with the time of the visit and the page(s) that were visited. We use IP addresses for the purposes of, among other purposes, calculating usage levels, diagnosing server problems, and for administrative purposes. We also derive approximate location from IP addresses for the foregoing purposes, and in order to analyze the location from which you are using our Services;
- Via e-mail: If you correspond with us via e-mail, we retain a copy of such correspondence for internal purposes. Information collected via e-mail is also used to provide a record of communications between you and us, in order to comply with any applicable legal and/or regulatory requirements;
- By way of using cookies and similar tracking technologies: Please refer to the ‘Cookies and Similar Technologies’ section;
- From third parties: Please refer to the Do We Collect Personal Data About You From Third Parties?’ section.
+
How do we use your personal data?
We collect and use your personal data for the following purposes:
a) to execute a contractual arrangement with you or to take steps linked to executing a contractual arrangement with you;
b) subject to the execution of a contractual arrangement with you, and subject to the terms and conditions of that contractual arrangement, to establish an account for you on our Services;
c) to pursue our legitimate interests which do not override your interests or fundamental rights and freedom, such as:
- Operating and administering our Services;
- Providing our products and services to you and/or our clients and to communicate with you and/or our clients about such products and services;
- Improving and developing products and services we provide;
- Providing information to you about our and/or our group companies’ services and products and/or any additional products and services that we think may be of interest to you and/or our clients. This information may be provided to you in the form of a digital advertisement and campaigns or via e-mail or via Short Message Service (SMS);
- Identifying which products or services we think you are interested in by using cookies or similar tracking technologies on our Services which track and analyse how you use our Services;
- Keeping a record of your communication with us;
- Administrative, assessment, and analysis purposes;
- Verifying your identity;
- Monitoring and analyzing the use of our products, services, and Services for system administration, operation, testing and support purposes;
- Managing our information technology and ensuring the security of our Services and systems;
- Establishing, exercising, and/or defending legal claims or rights, and/or assisting our clients or others with the foregoing;
- Investigating and responding to complaints or incidents relating to us or our business, maintaining the Services’ quality, and training our staff to deal with complaints and disputes;
- Verifying compliance with and enforcing our terms and conditions or other contractual terms; and
- In relation to any proposed merger or acquisition of any part of our business;
d) to comply with applicable laws prevailing the Kingdom of Saudi Arabia or in any other jurisdiction where we (or any of our affiliates) may operate;
e) to serve the purposes which are set out under the ‘Cookies and Similar Technologies’ section.
f) For the avoidance of doubt, we obtain your consent, and you have the right to withdraw your consent at any time. By not providing your consent or withdrawing your consent, certain aspects or features of our Services may not be available to you. The withdrawal of your consent does not affect the lawfulness of processing your personal data which was collected based on your original consent prior to the withdrawal thereof.
In order for us to provide you with certain services, including but not limited to the Services, securities brokerage services, and research services, which require us to process your personal data due to regulatory and legal requirements (for example KYC and AML), the provision of personal data is mandatory.
If the relevant personal data is not provided to us, then we will not be able to provide you with the full range of our services, meaning that our services may only be offered with a limited scope or not at all. All other provision of your personal data is optional.
+
Cookies and similar technologies
Cookies are small pieces of information sent by a web server to a web browser which allows the server to uniquely identify the browser on each page. Other tracking technologies, which are similar to cookies, are also employed and used by us. Other similar technologies can include pixel tags, google tags, and tracking URLs. All these tracking technologies shall be collectively referred to as the "Cookies".
The types of Cookies that we use on our Services, and the purposes for which they are used, are set out below:
- Strictly necessary cookies: These Cookies are essential in order to enable you to move around our Services and use their respective features, such as accessing secure areas of our Services. Without these Cookies, any services on our Services that you wish to access cannot be provided (the "Strictly Necessary Cookies");
- Analytical/performance cookies: These Cookies collect information about how you and other visitors use our Services, including, for instance, which pages you go to most often, and if you get error messages from certain pages. We use data from these Cookies to help test designs and to ensure a consistent look and feel is maintained on your visit to the Services. All information these Cookies collect is aggregated. It is only used to improve how the Services work. We use Google Analytics, for example, to anonymously track Services usage and activity;
- Functionality cookies: : These Cookies allow our Services to remember choices you make (such as your username, language, or the region you are in) and provide enhanced, more personal features. These Cookies can also be used to remember changes you have made to text size, fonts, and other parts of the pages that you can customize. These Cookies are also used to provide services you have asked for, such as watching a video or commenting. Additionally, these Cookies can be used to allow an optional service to function. The information these Cookies collect may be anonymised and they cannot track your browsing activity on other websites;
- Targeting cookies: These Cookies are used to deliver adverts which are more relevant to you and your interests. These Cookies are also used to limit the number of times you see an advertisement, as well as help measure the effectiveness of the advertising campaign. These Cookies are usually placed by advertising networks with the Service operator’s permission; These Cookies remember that you have visited a Service and this information is shared with other organisations such as advertisers. Quite often, targeting or advertising Cookies will be linked to site functionality provided by the other organization;
- Social media cookies: These cookies allow you to share what you’ve been doing on our Services on social media such as Facebook, Instagram and X (previously Twitter). These Cookies are not within our control. Please refer to the respective privacy policies for how their cookies work;
- Pixel tags: Also known as a clear GIF or web beacon. These Cookies are invisible tags placed on certain pages of our Services but not on your computer. When you access these pages, pixel tags generate a generic notice of that visit. They usually work in conjunction with cookies, registering when a particular device visits a particular page. They are used to, among other things, track the actions of users of our Services (including email recipients), measure the success of our marketing campaigns, and compile statistics about usage of our Services and response rates. If you turn off Cookies, the pixel tag will simply detect an anonymous visit.
If you wish to disable Cookies (save for Strictly Necessary Cookies), you can opt to disable the same by choosing "No, I Disagree" when given the option, via the Cookies consent management tool on our Services or you may rely on your browser’s settings to disable all Cookies. You can choose "Yes, I Agree" to accepting all Cookies. You can also accept or decline certain Cookie categories (save for Strictly Necessary Cookies) via the Cookies consent management tool on our Services. Where you delete or disable Cookies, certain features of our Services may not be able to function.
To find out more about Cookies please visit: www.allaboutcookies.org or see www.youronlinechoices.eu which contains further information about behavioral advertising and online privacy.
We are committed to protecting personal data from loss, misuse, disclosure, alteration, unavailability, unauthorized access, and destruction and takes all reasonable precautions to safeguard the confidentiality of personal information, including through use of appropriate security measures. These measures include the following:
- Preventative Measures: We use these measures to proactively prevent threats from reaching your personal data. This includes using advanced security software, firewalls, data encryption, and regular security assessments;
- Detective Measures: We use these measures to focus on identifying and responding to security incidents if they occur. This includes continuous system monitoring, brand protection measures, and incident response plans;
- Functionality cookies: : These Cookies allow our Services to remember choices you make (such as your username, language, or the region you are in) and provide enhanced, more personal features. These Cookies can also be used to remember changes you have made to text size, fonts, and other parts of the pages that you can customize. These Cookies are also used to provide services you have asked for, such as watching a video or commenting. Additionally, these Cookies can be used to allow an optional service to function. The information these Cookies collect may be anonymised and they cannot track your browsing activity on other websites;
- Physical Security Measures: We use these measures to protect the physical infrastructure that houses your personal data. This includes restricted access, environmental controls, and security cameras.
We regularly review and update our security measures to ensure that they are effective in protecting your personal data. If we know or have reason to believe that your personal data has been compromised, we will immediately notify you and take steps to mitigate the impact of the breach.
However, while providing your personal data to us, your personal data may be transferred over the internet. Although we make every effort to protect the personal data which you provide to us, we cannot guarantee the security of your personal data transmitted to us over the internet.
+
For how long do we keep your personal data?
We keep your personal data for no longer than necessary for the purposes for which the personal data is used or otherwise processed. The length of time we retain personal data depends on the purposes for which we collect and use it and / or as required to comply with applicable laws. In all cases we will only retain data as required to support legitimate business purposes.
Where we process data for: (i) registration purposes, (ii) support purposes, or (iii) in order to customize your experience on our Services, we keep this personal data for the duration of the period where you are a user and for an additional Ten-year period from when you cease to be a user, in compliance with regulatory rules and regulations, unless a longer retention period is required by applicable laws.
Where we process personal data for marketing purposes we will do so unless we receive a request from you to cease such action. We will hold a record of such personal data for Ten years from when you request us to cease such action.
Where we process personal data for the security of the Services, we hold this personal data for a maximum period of ten years.
+
Who do we share your personal data with?
Where we send direct marketing materials to you, we send your personal data to third parties with whom we have contracted to provide these materials to you on our behalf and in our name. These third parties may be located inside or outside of Saudi Arabia.
We also share your personal data with:
- service providers, who provide a service to us or you the List of Service Providers
- their service providers, delegates and agents;
- the Parent company ("EFG Holding")-located in Egypt-, to enable you to receive the services provided by EFG Holding which may cover different financial services;
- to enable you to receive the services provided by our affiliate entities which may cover different financial services or be in different jurisdictions to those that we cover;
- to allow us to improve the services that we provide across the EFG group; and
- to allow us to produce analytical reports reflecting the services provided throughout the EFG Hermes group.
We also disclose your personal data to:
- regulators, exchanges, auditors, courts, the police, or other law enforcement agencies where we are legally obliged to do so;
- to other persons where disclosure is required by law or to enable products and services to be provided to you or our clients;
- our professional service providers (e.g., legal advisors, accountants, auditors, insurers, and tax advisors) where relevant. If it becomes relevant, we will share your personal data with a potential buyer and their advisers in connection with any proposed merger or acquisition of any part of our business.
For the avoidance of doubt, please note that Service Providers do not use/disclose your personal data for marketing purposes or for any other purposes. Personal data received by Service Providers are used for the purposes of performing their designated functions.
+
Where is your personal data transferred?
When we share your personal data with the parties listed above, it may involves transferring your personal data outside of kingdom of Saudi Arabia to countries where the level of protection of personal data has not been deemed adequate by Saudi Arabia.
Our third party service providers are located in the List of Service Providers
Where information is transferred outside Saudi Arabia to a country that is not subject to an adequacy decision by Saudi Arabia, personal data is adequately protected by NCA ECC, NCA DCC, SAMA CSF & Regulation on Personal Data Transfer outside the geographical boundaries of the Kingdom.
+
What are your rights in relation to the personal data we process about you?
You have the following rights in relation to your personal data:
- Right of access: You have the right to access your personal data and to be informed of how it is being processed;
- Right to rectification: You have the right to have your personal data rectified if it is inaccurate or incomplete;
- Right to erasure: You have the right to have your personal data erased in certain circumstances, such as if it is no longer necessary for the purpose for which it was collected or if you withdraw your consent to processing;
- Right to restriction of processing: You have the right to restrict the processing of your personal data in certain circumstances, such as if you contest the accuracy of the personal data or if you object to processing;
- Right to data portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to have it transmitted to another controller.
- Right to object to processing: You have the right to object to the processing of your personal data for certain purposes, such as direct marketing;
To exercise any of these rights, please contact us at EFGHermes_DataProtection@efg-hermes.com
We are entitled to decline your request to exercise your data subject rights if it is not permitted by applicable laws, or if it is unreasonably repetitive, or if it would violate the rights of others.
These rights may be limited, for example if fulfilling your request would reveal personal data about another person, where they would infringe the rights of a third party (including our rights) or if you ask us to delete information which we are required by applicable laws to keep or have compelling legitimate interests in keeping. KSA PDPL outlines these limitations in detail. We will inform you of relevant exemptions we rely upon when responding to any request you make.
Your request will be answered promptly and within 30 business days unless we are legally entitled to an extension of time. If we are unable to grant your request, we will provide you with an explanation.
If you have any concerns about how we handle your personal data, we encourage you to contact us at EFGHermes_DataProtection@efg-hermes.com. We're committed to resolving your concerns. However, you also have the right to lodge a complaint with your local data protection authority if you believe we haven't addressed your concerns adequately.
+
Amendments to this privacy policy
This Privacy Policy was last updated in May 2024 . We reserve the right to revise this Privacy Policy at any time by posting a revised version and, if we consider it necessary, we will notify you of changes.
+
How can you contact us?
#
|
Data Controller
|
Address
|
Jurisdiction
|
Group Representative/ Contact Details
|
1
|
EFG Hermes KSA
|
PO Box 300189 Third Floor, Sky Towers Northern Tower , Riyadh Kingdom of Saudi Arabia
|
KSA
|
Email: EFGHermes_DataProtection@efg-hermes.com
|
EFG Hermes KSA is regulated by the Capital Market Authority.
© 2024 EFG-Hermes Holding S.A.E.
All rights reserved.