Skip to contentSkip to navigationSkip to contact details

Legal

Privacy & data protection policy

We handle health data about people with disabilities — among the most sensitive categories there are. This policy sets out what we collect and why, and what we will not do with it.

Last updated:

1. Scope

This policy applies to personal data processed by Amad Association for Developing the Capabilities of People with Disabilities and Their Families through this website and through its services and programmes, and is applied under the Saudi Personal Data Protection Law and its implementing regulation.

The association is the controller of this data — the party that determines the purpose and means of processing and bears responsibility for it.

2. What we collect

We collect three categories of data:

  • Contact data: name, email, mobile number and city — from the contact, volunteering, partnership and newsletter forms.
  • Beneficiary data: the beneficiary’s name, age, type of disability or diagnosis and description of need, and later the assessment reports, individual plan and progress indicators. This is health data, classified in law as sensitive data.
  • Limited technical data: an IP address, held temporarily and solely to rate-limit form abuse (preventing automated repeat submissions).

This site uses no tracking or advertising cookies, and no analytics that build a behavioural profile of you. Your accessibility preferences are stored in your browser alone and never reach us.

3. Purpose and lawful basis

  • Service-request data is processed on the explicit consent you give when applying, for one purpose: assessing the request, delivering the service, and following it up.
  • Volunteering, membership and partnership data is processed to carry out the relationship requested and to verify statutory eligibility.
  • Some data is processed to meet a legal obligation — such as the records required by the regulator or the external auditor.

We do not repurpose your data for a use that arises later without coming back to you, and we do not sell it to anyone under any circumstances.

4. Who can see your data

Access is limited to those who need it for their work: the screening and assessment team sees beneficiary files, the finance function sees donation records, the volunteering coordinator sees volunteer files. No employee has access to data outside their role.

We share data outside the association in three cases only: with your consent (for instance a referral to a partner clinic), in response to a lawful request from a competent authority, or with a technology provider bound by contract to confidentiality and barred from using the data for its own purposes.

We publish no beneficiary’s image or story in any media, report or campaign without explicit written consent from them or their guardian — consent that may be withdrawn at any time.

5. Retention

We keep data for as long as the purpose it was collected for requires, or for the period the law imposes, whichever is longer — then dispose of it securely under the records retention and disposal policy. Beneficiary files are kept for the duration of the service and the statutory period thereafter; contact-form data is deleted once its purpose has ended.

6. Your rights

Under the Personal Data Protection Law, you have the right to:

  1. be informed of what we collect, and the basis and purpose of processing.
  2. access your data and obtain a copy of it.
  3. request correction of inaccurate data or completion of incomplete data.
  4. request destruction of your data when the purpose has lapsed or consent is withdrawn, unless the law requires it to be kept.
  5. withdraw consent at any time, without affecting the lawfulness of prior processing.

To exercise any of these rights, write to the data protection officer at privacy@amad.org.sa. We respond within thirty days, and where we decline a request we state a lawful reason for doing so.

You also have the right to complain to the competent personal data protection authority in the Kingdom if you are not satisfied with our response.

7. Security

Data is transmitted over an encrypted connection and stored in systems with role-restricted access. Permissions are reviewed periodically and access to beneficiary files is logged. In the event of a breach likely to harm a data subject, we notify the competent authority and those affected within the statutory timeframes.

8. Children’s data

Many of our beneficiaries are children. We collect a child’s data only through their guardian or legal representative, and never solicit data from a child directly through this site. Children’s data is additionally subject to the beneficiary safeguarding policy.

9. Changes to this policy

This policy may be updated as our services or the regulatory requirements change. The date of last revision appears at the top of this page, and where a change is material and affects existing processing, we notify those concerned before it takes effect.