Overview
Saudi Railway Company is committed to safeguarding your privacy and adhering to the highest standards of data protection, as prescribed by the Personal Data Protection Law of Saudi Arabia (‘KSA PDPL’, ‘Law’).
Personal Data encompasses any information relating to an identified or identifiable individual (‘Personal Data’), which may include but is not limited to, your name, address, photograph, and more. This Privacy Policy serves to inform you about how SAR collects, processes, and protects your Personal Data. The aim of this Privacy Policy is to ensure transparency in our data handling practices and empower you to make informed decisions about your privacy.
Purpose
The purpose of this Privacy Policy is to provide you, our valued (‘Customer’), with clarity on how SAR collects, uses, stores, shares, and processes your Personal Data. This is integral to our commitment of delivering personalized products and services tailored to your specific needs. SAR ensures transparent and lawful processing of your Personal Data and implements comprehensive security measures to safeguard against unauthorized access, disclosure, or destruction
Types of Data Collected
We collect various types of Personal Data, including but not limited to the following categories:
- Personal Identification Information: Full name, email address, phone number, postal address, National Identification, Passport Number, or similar documentation
- Service Usage Data: Details about your interactions with SAR services, such as travel history, preferences, and complaints.
- Payment Information: Payment methods, billing details, and transaction history. We do not store credit card information unless explicitly permitted for recurring payments.
- Cookies and Tracking Technologies: We use cookies, web beacons, and similar technologies to monitor website performance, improve user experience, and deliver targeted advertisements. You can manage your cookie preferences via your browser settings.
- Sensitive Personal Data: Any data related to health or biometric information (if applicable), and only collected with explicit consent.
How We Use Your Data:
We ensure the lawful and transparent processing of your Personal Data, using it for the following purposes:
- To provide and maintain our services (e.g., booking tickets, parcel shipments).
- To send notifications about service updates, promotions, or operational changes. To allow you to participate in interactive features of our service.
- To respond to inquiries, complaints, and offer relevant assistance.
- To gather analysis and insights that help improve our services and user experiences with your consent, we may use your Personal Data to provide personalized offers and promotions based on your preferences.
- To comply with applicable legal and regulatory requirements, including responding to lawful requests from public authorities.
Legal Basis for Processing Personal Data
We will only collect and use your Personal Data in accordance with the requirements under the KSA PDPL. In most cases, our legal justification will be:
- Your Consent, where Parents and legal guardian consent will be obtained for processing Personal Data related to children and incompetents’.
- Processing achieves a definite interest for you, and it is impossible or difficult to contact you.
- Processing is required by applicable law and is performed in accordance with them.
- Processing is performed in order to perform an agreement to which you are a party.
- Processing is necessary for the purpose of SAR’s legitimate interests.
Disclosure
As necessitated by the purposes listed (refer to section 4) above, we reserve the right to disclose your Personal Data, which is defined under the KSA PDPL as enabling any person other than us to access, collect, or use personal data by any means and for any purpose. Disclosure may occur in the following cases:
- Our contractors who provide us with professional or management services, such as IT companies, etc.
- Any applicable regulatory authorities (governmental and other public bodies, etc.) or other third parties as could be required by applicable law or in accordance with other regulatory obligations or policies applicable to SAR or to you.
- You consent to the disclosure.
- Your Personal Data has been collected from a publicly available source.
- The entity requesting disclosure is a public entity, and the collection or processing of your Personal Data is required for public interest or security purposes, or to implement another law, or to fulfil judicial requirements.
- The disclosure is necessary to protect public health, public safety, or to protect the lives or health of specific individuals.
- The disclosure will only involve subsequent processing in a form that makes it impossible to directly or indirectly identify you.
We may disclose your Personal Data in accordance with KSA PDPL in the following cases:
Transfer
We may share your Personal Data with internal parties and external parties (e.g. regulatory authority, service providers, partners, etc.) including those of children and incompetents for processing to the extent necessary to fulfil the purposes listed above (refer to section 5). In some circumstances where the law permits, this will involve SAR transferring your Personal Data outside KSA. Such transfers will adhere to the legal provisions concerning cross-border transfers of Personal Data, as stipulated by the KSA PDPL and the relevant laws and regulations.
Data Security
We have implemented appropriate security measures, administrative controls, and legal safeguards to:
- Safeguard your Personal Data and Sensitive Data, including data pertaining to children and incompetents from accidental loss, unauthorized access, misuse, alteration, or disclosure.
- Address any suspected Personal Data breaches promptly and thoroughly, in accordance with legal requirements. Should such a breach occur, we will notify you and the Competent Authority as mandated by the KSA PDPL.
Data Retention
We will retain your Personal Data (including Personal Data related to children and incompetents) for the period required by KSA PDPL or any other period necessary for us to meet our operational obligations such as maintaining accounts, facilitating client relationship management, responding to legal claims or regulatory requests, etc.
Your Rights
In accordance with the KSA PDPL, you are entitled to exercise the following rights:
- Right of access: You may obtain access to your Personal/Sensitive Data which we hold about you.
- Right to be informed: You have the right to be informed about the legal basis and the purpose of the collection and processing.
- Right to request obtaining Personal Data: You are entitled to request a copy of your Personal/Sensitive Data (held by us) in a readable and clear format.
- Right to request correction/completing or updating: You have the right to request correction, completion or updating your Personal Data/Sensitive Data if you believe that any of the collected Personal/Sensitive Data we are holding is incorrect or incomplete.
- Right to request the destruction of Personal Data: SAR is entitled to retain your Personal/Sensitive Data in accordance with applicable laws, regulations, or judicial requirements, and for any legitimate interest as permitted by law.
- Right to withdraw consent: While you have the right to withdraw consent for processing your personal data, please be aware that there are situations where this right may be limited:
- If the SAR is required to retain your Personal/Sensitive Data under applicable laws or regulations or by judicial requirement.
- If the processing of your Personal/Sensitive Data is essential to fulfil a contract or provide a service to you where your personal/sensitive data is necessary for the completion.
- You have the right to submit a complaint to the competent authority within (90) days from when incident occurred, or as soon as you are aware of it. You may submit a request to exercise your rights by filling out the Data Subject Request Form and share it with DPO@SAR.COM.SA .
Social media
SAR operates across multiple social media platforms to inform, assist, and engage with you, with the aim of enhancing our products and services. We kindly ask that you refrain from sharing Personal or Sensitive Data on our social media channels. It's important to note that SAR is not responsible for any information shared on these platforms, except for content posted by our authorized employees.
- Data Use: SAR may collect and use anonymized or aggregated data from your social media interactions to improve services. Personal Data shared through private messages will be processed in line with our Privacy Policy and the platform’s policies.
- Third-Party Platforms: Your activity on social media is governed by the privacy policies of the respective platforms. SAR advises reviewing them for details.
- Targeted Advertising: With your consent, SAR may use your Personal Data to deliver personalized promotions through social media. You can manage preferences via your social media account settings or by contacting SAR.
- Third-Party Platforms: Your activity on social media is governed by the privacy policies of the respective platforms. SAR advises reviewing them for details.
Marketing from SAR
We may use your Personal Data for marketing/advertising purposes to inform you about our products and services based on the consent provided. You may ask us to stop sending the marketing messages by contacting the SAR Customer Care department (8001262000 / customerservices@sar.com.sa ).
- SAR may send you promotional content via email, SMS, or social media based on your preferences. These messages aim to keep you informed about our latest services and offers.
- With your consent, SAR will tailor marketing communications based on your service usage and preferences to provide you with relevant offers.
- You can opt out of marketing communications at any time by following the “unsubscribe” link in our emails, updating your preferences through your SAR account, or contacting our customer care team.
SAR will not share your Personal Data with third parties for their own marketing purposes without your explicit consent.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on SAR’s website.
Disclaimer
This Privacy Policy is not intended to, nor does it, create any contractual rights or obligations whatsoever on SAR or you, nor does it create any legal rights or obligations on SAR in respect of any other party or on their behalf.
Contact Us
Maintaining the accuracy and currency of your Personal Data is very important for us. For inquiries about our Privacy Policy or further details, please contact: DPO@SAR.COM.SA