Privacy Policy
Version 1.1 · Last updated: 3 September 2026
This policy explains how personal data is collected and processed in the Qimam SME Enablement Program portal ("the Portal"), operated for Soudah Development Company (SDC). It is published in line with Article 12 of the Saudi Personal Data Protection Law (PDPL), which requires a controller to make a privacy policy available before collecting personal data.
The data controller is Soudah Development Company (SDC), which determines the purposes and means of processing. The technical operator (processor) is Star, which builds and operates the Portal on SDC's behalf and under its instructions. SDC's formal contact details — and a Data Protection Officer, if one is required — will be published here once confirmed.
Personal data we collect
We collect the following directly from you through the Portal's forms. Each form marks whether a field is required or optional.
- Account data: your full name, email address and mobile number (email and mobile are stored encrypted), together with account verification flags and versioned consent records.
- Identity and eligibility data: national ID number and date of birth (both stored encrypted) and a scanned copy of your national ID (a PDF or photo, stored encrypted at rest) — these verify your identity and are required; region and city; an eligibility-area flag indicating your connection to the Soudah project area (Soudah or Rijal Almaa); gender; and a proof-of-residence document. A proof-of-eligibility document may be issued in your guardian's name; the guardian's name shown on it is used solely to verify your eligibility, by matching it against your full name. To verify your identity and your connection to the project area, the filtration committee (and SDC administrators) may view these identity and eligibility details — your national ID number is always shown to them masked, and each view of your national ID image or a proof document is logged. The evaluation (grading) committee that scores your idea does not see any of them. These details are entered manually by the applicant.
- Application data: your idea or project details (title, type, description, need or opportunity, connection to the Soudah destination, target customers, distinctiveness, current stage, whether you are applying individually or as part of a team, and requested support areas); for an existing business, its name, commercial registration (CR) number and certificate, activity, years of operation and website; and any pitch deck you upload.
- Support data: the messages you send through the Portal's support channel.
- Feedback data: any feedback or bug report you submit, including an optional contact email and an optional screenshot, plus the page path, language and a shortened browser identifier.
- Technical data needed to operate and secure the Portal, such as sign-in and security-event records.
How and why we use your data, and the legal basis
We use your data to: create and secure your account; verify your email; assess your eligibility; enable the program committee to evaluate applications; organise the hackathon phase, including team formation and capacity planning, under the published Terms & Conditions of Eligibility; provide support; issue in-portal notifications; and operate, secure and improve the Portal.
Our legal bases under the PDPL are: your consent (Article 5), captured as a versioned record at registration and again when you submit an application; the necessity of processing to act on the application and account you asked us to create (Article 6); and, for feedback and portal improvement, a legitimate interest that involves no sensitive data (Article 6). Where we rely on your consent, it is not a condition for any service beyond what that consent directly enables.
How your data is handled
- Committee members review applications under a pseudonymous reference (for example #001) that carries no name, contact detail or national ID, to reduce evaluation bias.
- A dedicated filtration committee reviews your identity and your connection to the Soudah project area. For that purpose only, it sees your region, city, eligibility-area flag and the connection details you provide, together with your date of birth, National Address, masked national ID number and — through logged, on-demand views — your national ID image and proof documents. The evaluation (grading) committee that scores your idea against the criteria sees none of this identity, location or connection information.
- Personal data is masked by default across the Portal's screens, its administrative console and its logs; revealing a full value is a restricted, audited action.
- Draft ideas you have not yet submitted are visible only to you and are not shared with the committee.
Sharing and disclosure
We do not sell your data and do not share it with third-party advertising or analytics services.
- Within the program: SDC administrators and Star operators (with personal data masked by default); the evaluation (grading) committee (a pseudonymous view only, without your identity, location or connection data); and the filtration committee (a pseudonymous view that additionally includes your region, city, eligibility-area flag, connection details, date of birth, National Address, masked national ID number and logged on-demand views of your national ID image and proof documents, used solely to verify your identity and connection to the Soudah project area).
- One-time verification codes and portal notifications are delivered by email through SDC's own in-Kingdom notification gateway, engaged with SDC's provision and approval; no separate third-party email provider is used, and delivery stays inside the Kingdom. Delivery of one-time codes by SMS is not yet enabled; this policy will be updated if an approved in-Kingdom SMS provider is engaged.
Storage, retention and destruction
- Your data is hosted inside the Kingdom of Saudi Arabia, on Saudi cloud infrastructure in the me-central2 region, operated by Star as processor on SDC's behalf.
- No personal data is transferred outside the Kingdom. Should any cross-border flow ever become necessary, it will be enabled only on the legal basis required by the PDPL and its Cross-Border Personal Data Transfer Regulation, and after SDC approval.
- We keep personal data only for as long as it is needed for the purposes above. Retention periods per data category are being finalised with SDC; unsubmitted draft ideas are deleted automatically after their cohort's window closes. When data is no longer needed it is destroyed so that it cannot be recovered (PDPL Article 18).
How we protect your data
We apply administrative, technical and organisational safeguards, including: encryption of direct identifiers at rest (AES-256-GCM) and encryption in transit (TLS); role-based access on the least-privilege principle; and a tamper-evident, hash-chained audit log of privileged actions.
Your rights
Under the PDPL you have the following rights over your personal data:
- To be informed of the legal basis and purpose of collecting your data (PDPL Articles 4 and 13).
- To access the personal data the controller holds about you.
- To obtain a copy of your personal data in a clear, readable format.
- To request correction, completion or updating of your data.
- To request destruction of your data when it is no longer needed for the purpose it was collected for.
- To withdraw your consent to processing at any time, unless another legal basis requires otherwise.
- To lodge a complaint with the competent authority, the Saudi Data & AI Authority (SDAIA).
- To claim compensation for material or moral damage resulting from a violation of the PDPL.
Exercising your rights, and complaints
To exercise any of these rights, or to raise a privacy complaint, contact us through the Portal's support channel; SDC's dedicated privacy contact details will be published here once confirmed. We will respond within the period set by the PDPL and its Implementing Regulation.
If you are not satisfied with how your request is handled, you may escalate to the Saudi Data & AI Authority (SDAIA) as the competent authority.
Updates to this policy
This policy is published by Star as technical operator on behalf of Soudah Development Company (SDC), the data controller, and describes the practices the Portal currently implements. The items noted above as still to be confirmed — SDC's contact details, the data protection officer, and retention periods for each category of data — will be published here once SDC provides them. Any amendment will be recorded here with its date.