Privacy Policy
Last updated: 2 September 2026 · This policy is the privacy notice required by the Personal Data Protection Law and its Implementing Regulations.
- We collect the minimum needed to organise your attendance: name, email, mobile, organisation (optional) and your session and workshop selections.
- We do not sell or rent your data, and we do not share it with sponsors or partners for marketing.
- We use no tracking, analytics or advertising tools; our cookies are strictly necessary ones.
- We ask for no payment details — attendance is free — and no sensitive data.
- You may access and correct your data, ask for it to be destroyed, and withdraw your consent at any time.
This summary is for guidance only; the full text below governs.
Who we are, and the scope of this policy
Madinah Chamber of Commerce and Industry is the data controller for personal data collected through the Governance of Vital Sectors Forum website. It determines the purposes and means of processing, and is based at Madinah, Kingdom of Saudi Arabia.
This policy explains what we collect when you visit the Website, create an account or register to attend; why we collect it; the lawful basis for processing it; who sees it; how long we keep it; and what rights you have and how to use them.
It does not apply to third-party sites or services you may reach from links on the Website; each of those has its own policy.
What we collect, why, and for how long
We collect no more than the purposes below require, and we do not use it for anything else:
| Data | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Full name, email address, mobile number, organisation (optional) | Confirming your registration, contacting you about the forum, and managing entry | Your explicit consent at registration | 24 months from the date of the forum |
| Your panel-session and workshop selections, and any waiting-list status | Allocating seats, organising rooms and managing waiting lists | Performing the service you asked for | 24 months from the date of the forum |
| Account data: your email as identifier, your password stored as a one-way hash, your language preference and account status | Letting you manage your own registration, and protecting the account from unauthorised access | Performing the service, and our legitimate interest in account security | For as long as the account exists; closed on your request |
| Outbound message log: recipient address, subject, and whether sending succeeded or why it failed | Proving that registration and confirmation notices were sent, and diagnosing mail failures | Our legitimate interest in evidencing delivery | 12 months |
| Audit log: the operation and its time, the email of the staff member who performed it, and a hash of the IP address — never the address itself | Showing who read or changed personal data, detecting misuse, and meeting accountability requirements | Legal obligation, and our legitimate interest in information security | 24 months |
| Strictly necessary cookies | Keeping you signed in, protecting against request-forgery attacks, and remembering your language | Necessary to provide the service you requested | Until the session ends; one year for the language cookie |
| Photographs and video of the forum | Documenting the event, media coverage, and publication on the chamber's official channels | Our legitimate interest in documenting a public event, with notice in advance and a right to object | In line with the chamber's archiving policy |
Mobile numbers are stored in a normalised form (9665XXXXXXXX) to avoid duplicate records and keep contact details valid.
What we do not collect
- We ask for no payment or card details: attendance is free and no fee is ever due.
- We do not ask for national ID or iqama numbers, or images of official documents, through the Website.
- We do not collect sensitive data — health, religious, ethnic, criminal, biometric or genetic — and never ask for it. Please do not send it; if it reaches us incidentally we destroy it.
- We use no analytics, advertising or behavioural-tracking tools, we build no behavioural profile of you, and we make no automated decisions about you without human involvement.
How we collect it
- Directly from you, through the registration form, your attendee area, or your correspondence with us.
- From what your use of the Website generates: the outbound message log, the audit log and the strictly necessary cookies.
- We buy no data lists, and we do not gather your data from data brokers or social networks.
Purposes of processing
- Organising your attendance: accepting registrations, allocating workshop seats, managing waiting lists and managing entry.
- Operational contact: receipt and confirmation notices, timing changes, arrival details and password resets.
- Aggregate, non-identifying statistics to evaluate the forum and improve future editions.
- Website security, preventing abuse and automated registration, and verifying the integrity of operations.
- Meeting legal requirements and requests from the competent authorities.
We will not process your data for a purpose materially different from these without telling you and obtaining fresh consent.
Lawful basis
Depending on the case, our processing rests on one of the following, as the table above shows:
- Your explicit consent — the basis for the registration data. You give it deliberately in the registration form, we record it with its date, and you may withdraw it at any time.
- Performing the service you requested — allocating your seats and running your account.
- Legitimate interest — information security, audit records and evidencing notices, without prejudice to your rights, never extending to sensitive data, and only as far as the PDPL and its Regulations permit.
- Legal obligation — where a law or a competent authority requires it.
Cookies and external services
The Website uses three cookies, all of them strictly necessary:
| Cookie | Purpose | Lifetime |
|---|---|---|
| gove.auth | Keeping you signed in. It cannot be read by browser scripts, is only sent over an encrypted connection, and is never sent with requests from other sites | Ends when you sign out or the session ends |
| .AspNetCore.Antiforgery | Protecting forms against cross-site request forgery (CSRF) | Ends with the session |
| .AspNetCore.Culture | Remembering your choice of display language (Arabic / English) | One year |
The Website sets no analytics, advertising or tracking cookies, and no third-party cookies. That is why it shows no cookie banner: strictly necessary cookies need no separate consent. You can still delete or block them in your browser settings, but blocking them will prevent signing in and submitting forms.
The Website's typeface is loaded from Google's font service (fonts.googleapis.com and fonts.gstatic.com), which may see your device's IP address and browser type when the font loads. It is the only external service the Website loads, and none of your name, email or registration data is sent to it.
Who sees your data
- Inside the chamber: only authorised staff, and only to the extent of each staff account's permissions. Not everyone with dashboard access can see registrant data, and not everyone who can see it can export it. Every read and every change is written to the audit log.
- Service providers: the Website and database host, and the email service. They process data on our behalf and on our instructions only, under confidentiality and data-protection obligations, and are not permitted to use it for their own purposes.
- Competent authorities: where a law, a lawful request or a judicial order requires it, and only to the extent required.
- We do not sell, rent or trade your data, and we do not share it with the forum's sponsors, partners or speakers for marketing purposes.
- When an announcement goes out to registrants it is sent as a separate message to each recipient, so no registrant's address is ever visible to another.
Where data is stored and cross-border transfer
The Website's database and files are held with a commercial hosting provider whose servers may be located outside the Kingdom of Saudi Arabia; email is sent through the chamber's own mail service.
Where any storage or processing takes place outside the Kingdom, we comply with the PDPL and the rules governing transfer of personal data abroad: the transfer is limited to what the service requires, follows a check that the recipient's level of protection is adequate and contractual safeguards are in place, and must not prejudice data security, the rights of data subjects, or national security.
If you would like details of the hosting provider or the contractual arrangements with it, write to us at the address at the end of this page.
How we protect your data
We take organisational and technical measures to protect your data, including:
- Encrypting the entire connection to the Website, and requiring the browser to use it.
- Storing passwords as one-way hashes from which the password cannot be recovered — nobody here knows it.
- Locking an account temporarily after a set number of failed sign-in attempts.
- Giving each staff member the least privilege their work needs, and separating permission to view from permission to export.
- Logging every read of and change to personal data in an audit trail that survives deletion of the underlying record.
- Storing a hash of the IP address rather than the address itself — enough to detect abuse, not enough to identify a person.
- Validating uploaded files by type, content and size before accepting them, and preventing the Website from loading any external scripts.
- Protecting every form against request forgery, and preventing the Website from being framed inside another site.
No electronic system can be absolutely secure. We work to reduce risk and to address issues as they appear — and you are part of that protection by choosing a strong password and not sharing it.
Retention and destruction
- We keep your data for the periods in the table above, or for as long as the purpose requires — whichever is shorter — and then destroy it or render it non-identifying.
- We may keep it longer where a law, obligation, claim or live investigation requires, and only to the extent needed.
- Withdrawing your registration marks it "cancelled" and the record is kept for audit until its retention period ends. You may ask for full erasure, and we comply so far as no legal obligation prevents it.
- Registrant data is destroyed securely, so that it cannot be recovered.
Your rights
The Personal Data Protection Law gives you the following rights:
- The right to be informed
- To know the lawful basis and the purpose of collecting your data — which is what this policy sets out.
- The right of access
- To ask to see the personal data we hold about you.
- The right to obtain a copy
- To receive a copy of your data in a clear, readable format.
- The right to correction
- To ask for your data to be corrected, completed or updated. Most of it you can change yourself in the attendee area.
- The right to destruction
- To ask for data that is no longer needed for the purpose it was collected for to be destroyed.
- The right to withdraw consent
- To withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal — noting that withdrawing it means your registration cannot proceed.
How to exercise your rights
- Most of what you need is available directly in your attendee area: changing your session and workshop selections, updating your details, and withdrawing.
- For anything beyond that — a copy of your data, erasure, or withdrawing consent — write to us at the address at the end of this page, setting out your request.
- We verify your identity before acting, to protect your data from being requested by someone else.
- We act on the request, or explain why we cannot, within thirty days of receiving it complete — free of charge.
- If a request is repetitive or manifestly excessive, or acting on it would conflict with a legal obligation, we will tell you and explain why.
Making a complaint
If you believe our processing breaches the law or this policy, write to us first: we will look into it and reply. If your complaint is not resolved satisfactorily, you may raise it with the Saudi Data and Artificial Intelligence Authority (SDAIA), the authority supervising the Personal Data Protection Law, through its official channels at sdaia.gov.sa.
Data breaches
If your personal data is leaked, damaged or unlawfully disclosed, we act immediately to contain the incident and address its effects, notify the competent authority within the period the law prescribes (72 hours of becoming aware), and notify you directly where the incident may harm your data or conflict with your rights and interests — telling you what happened and what you can do.
Children's data
The Website is intended for people aged 18 or over. We do not knowingly collect children's data; if we find that we hold a child's data without the consent of a parent or legal guardian, we destroy it.
Messages we send you
- Operational messages: registration received, attendance confirmed, password reset, and event reminders. These are part of the service you asked for and cannot be switched off while your registration stands.
- Forum announcements: changes of date, venue, entry details, or session materials.
- We do not use your email or number for third-party advertising, and we do not add you to mailing lists unrelated to the forum. Any new marketing use would need your separate consent.
- You can ask us to stop sending announcements; the messages necessary for your registration will continue.
Changes to this policy
We may update this policy when the law or our practice changes. Updates are published on this page and the "last updated" date above is revised. Where a change is material — to the purposes of processing or the categories of data collected — we notify registrants by email, and we seek fresh consent where consent is the lawful basis.
Contact us
Madinah Chamber of Commerce and Industry
Madinah, Kingdom of Saudi Arabia
For personal-data requests and questions about this policy: legal@mcci.org.sa
For the terms of use and registration: Terms and Conditions
This policy was drafted in Arabic and translated into English for convenience. In the event of any discrepancy, the Arabic text prevails.