Protecting personal data is part of what we do for our clients, and we hold ourselves to the same standard. This policy explains, in plain terms, what we collect, why, who we share it with, how long we keep it and how you exercise your rights under the Personal Data Protection Law.
1Who we are and what this policy covers
CISO Consulting Company for Cybersecurity, a limited liability company registered in the Kingdom of Saudi Arabia under Commercial Registration No. 7053022526, with its head office in Riyadh (“CISO Consulting”, “we”, “us”), is the controller of the personal data described in this policy.
This policy explains how we collect, use, share, protect and keep personal data when you visit ciso.com.sa, use our client, partner, expert or candidate portals, contact us, apply for a role, or deal with us in connection with our services. It is issued under the Personal Data Protection Law (PDPL) and its Implementing Regulations.
Where we process personal data on behalf of a client while delivering services — for example, data contained in a client’s systems or evidence — we act as the client’s processor under the data processing annex to our services agreement, and the client’s own privacy notice applies to that data.
2The personal data we collect
What we collect depends on how you deal with us:
- Website visitors: device and browser information, pages visited, approximate location derived from the network address, and cookie choices.
- Enquiries and prospective clients: name, job title, organization, business e-mail, telephone, the content of your enquiry, and records of meetings and non-disclosure agreements.
- Clients and client users: name, job title, department, business contact details, portal account details, permissions, sign-in and security records, approvals and electronic acceptances, messages, and the records of the services we provide.
- Partners and experts: name, contact details, company and tax details, qualifications, certifications, availability, rates, bank details needed for payment, vetting results, agreements, timesheets and invoices.
- Candidates: name, contact details, nationality, city, CV and the information in it, experience, qualifications, notice period, interview notes, assessments, offers, and the identity, right-to-work and onboarding information described in section 7.
- Identity verification: when you sign or approve something that requires it, the result of verification through Nafath or an approved alternative. We store only the last four digits and a fingerprint of identity numbers, never the full number, except where a law requires otherwise.
- Security records: sign-in times, network addresses, device identifiers, one-time-code events and audit records of actions taken in the portals.
We do not seek to collect sensitive personal data (such as health, religious belief or criminal records) except where it is necessary and permitted by law — for example, background screening of a candidate for a role that requires it, with the candidate’s knowledge.
3Where the data comes from
Mostly from you. Some comes from your organization (for example, when a client account owner adds you as a user), from referees and previous employers you name, from identity-verification and screening providers, from partners who introduce an opportunity, and from public professional sources such as a business website or professional profile you point us to.
4Why we use personal data and on what basis
We process personal data only for specified, clear and legitimate purposes, and only as much as each purpose needs:
- To provide and manage our services and the portals, and to perform the contracts we have with clients, partners, experts and candidates — on the basis of contract.
- To verify identity, secure accounts, prevent fraud and misuse, and keep audit trails — on the basis of our legitimate interest in security and of legal obligations.
- To issue tax invoices, keep accounting records and comply with ZATCA, labour, GOSI and other legal requirements — on the basis of legal obligation.
- To recruit, assess and onboard candidates and to staff engagements — on the basis of the steps you ask us to take before a contract, contract, and your consent where required (for example, to share your profile with a client).
- To answer enquiries and, where you agree, to send you insights and event invitations — on the basis of consent, which you can withdraw at any time.
- To improve the Site and our services using aggregated or de-identified information — on the basis of legitimate interest.
Where we rely on consent, we ask for it clearly and record it, and withdrawing it does not affect processing done before withdrawal.
5Automated processing and artificial intelligence
We use software, including artificial intelligence, to help read CVs and documents, summarize information and suggest matches. These tools assist our people; they do not make decisions that have legal or similarly significant effects on you. Every hiring, vetting and engagement decision is made by a person, and you can ask for a human review of any assessment that concerns you.
6Sharing personal data
We do not sell personal data. We share it only where necessary, under contract and with appropriate safeguards:
- Service providers acting on our instructions: hosting and backup, e-mail and SMS delivery, identity verification, payment processing, electronic invoicing, and professional tools.
- Clients, partners and experts working on the same engagement, limited to what the work requires.
- A client considering a candidate: a candidate’s details are shared only with the candidate’s consent, and we do not name the client to the candidate until the process allows.
- Government and regulatory authorities, courts and other bodies where the law requires it, including the Zakat, Tax and Customs Authority, the General Organization for Social Insurance and the Ministry of Human Resources and Social Development (Qiwa).
- Professional advisers such as lawyers, auditors and insurers, under duties of confidentiality.
- A buyer or successor of our business, under equivalent protections, if our business is reorganized.
7Candidates
If you apply for a role or are put forward for one, we use your CV and the information you give us to assess your suitability, contact you, arrange interviews and, with your consent, present you to a client. You can sign in to the candidate portal at ciso.com.sa/careers/me with a code sent to your e-mail to see your applications, update your details, replace your CV and withdraw.
Before a client sees your details we ask you to sign a confidentiality agreement and record your consent. If you accept an offer, we collect what is needed to employ or second you lawfully — identity and right-to-work documents, a conflict-of-interest declaration, the employment contract, GOSI and Qiwa registration and background screening where the role requires it — and only once these steps are complete do we open project access.
If you are not hired, we keep your application for the period shown in section 10 so that we can consider you for future roles, unless you ask us to delete it sooner.
8Transfers outside the Kingdom
We aim to store and process personal data inside the Kingdom of Saudi Arabia. Where a service provider processes data outside the Kingdom, we transfer it only as permitted by the PDPL and the Regulation on Personal Data Transfer outside the Kingdom — for example, to a country with an adequate level of protection or under appropriate safeguards — and only to the extent necessary.
9How we protect personal data
We protect personal data with measures appropriate to the risk, aligned with recognized cybersecurity controls, including: encryption of data in transit and of sensitive files at rest; multi-factor authentication and session controls; role-based access limited to what each person needs, with periodic access reviews; separation of each client’s, partner’s and expert’s information; malware scanning of uploaded files; audit logging of access and actions; secure backups; and staff confidentiality obligations and training.
10How long we keep personal data
We keep personal data only as long as the purpose requires or the law obliges, and then destroy or de-identify it securely:
- Website analytics and security logs: up to 12 months, longer where needed to investigate an incident.
- Enquiries that do not become engagements: up to 24 months after the last contact.
- Client, partner and expert engagement records, agreements and correspondence: for the duration of the relationship and up to 10 years afterwards, in line with commercial record-keeping requirements.
- Tax invoices and accounting records: for the period required by ZATCA and accounting regulations.
- Candidates not hired: up to 24 months after the last activity, unless you ask for earlier deletion; employees and seconded staff: as required by labour and social insurance law.
- Electronic acceptance, signature and audit records: for as long as the related contract may be relied on, and in any case as required by law.
Data under a legal hold or needed to establish, exercise or defend a legal claim is kept until the matter is closed.
11Your rights
Under the PDPL you have the right to:
- be informed of how and why your personal data is processed — which this policy does;
- access your personal data and obtain a copy of it in a readable format;
- ask us to correct, complete or update inaccurate or incomplete data;
- ask us to destroy personal data we no longer need, subject to legal retention obligations;
- withdraw consent where processing relies on consent;
- complain to us, and to the competent authority.
You can exercise these rights through the “Your data” or privacy section of your portal, through the privacy choices page on the Site, or by writing to info@ciso.com.sa with the subject “Personal data request”. We will verify your identity and respond within the period the law sets, which is generally thirty days. Requests are free of charge unless manifestly unfounded or excessive.
12Cookies and similar technologies
We use cookies that are strictly necessary to run the Site and keep you signed in securely, and — only with your consent — cookies that help us understand how the Site is used. You can accept, refuse or change your choice at any time through the cookie banner or the privacy choices page. Refusing non-essential cookies does not affect your use of the portals.
13Marketing communications
We send insights, newsletters and event invitations only to people who have agreed to receive them or, for business contacts, where the law allows. Every message includes a way to unsubscribe, and you can change your preferences in your portal at any time. Service messages about your account, security, invoices and engagements are not marketing and continue while the relationship lasts.
14Children
The Site and our services are intended for organizations and adults. We do not knowingly collect personal data from anyone under eighteen. If you believe a child has given us personal data, contact us and we will delete it.
15Personal data breaches
If a personal data breach occurs that is likely to harm you, we will notify the competent authority within the period the law requires — within seventy-two hours of becoming aware of it — and inform you without undue delay where the law requires, with what happened, its likely effect, and what we and you can do to limit it.
16Changes to this policy
We review this policy regularly. The current version and its effective date are always shown on this page, and material changes are announced on the Site or in the portals before they take effect.
17Contact and complaints
For any question, request or complaint about personal data, contact our data protection officer:
CISO Consulting Company for Cybersecurity · Commercial Registration No. 7053022526 · Riyadh, Kingdom of Saudi Arabia · info@ciso.com.sa (subject: “Personal data”) · +966 55 093 9344
If you are not satisfied with our response, you may complain to the Saudi Data and Artificial Intelligence Authority (SDAIA), the competent authority for personal data protection in the Kingdom.