Legal
Privacy Policy
Last updated: May 27, 2026
At CyberMashrek, we take your privacy and data security seriously. This policy outlines how we collect, use, and protect your information in compliance with SAMA, NESA, GDPR, and ISO 27001 standards.
Our Privacy Principles
✓
TransparencyWe clearly disclose what data we collect and why.
✓
MinimizationWe collect only data necessary to operate and improve the platform.
✓
ProtectionIndustry-standard encryption and security controls protect all user data.
Information We Collect
- •Account Information: Email address, full name, and user role when you register.
- •Usage Data: Pages visited, time spent, and interactions with threat intelligence content (for analytics only).
- •Device Information: IP address, browser type, and device type for security and analytics purposes.
- •We do NOT collect sensitive personal data such as health information, financial records, or biometric data.
How We Use Your Data
- •Account Management: To authenticate users and provide access to the platform.
- •Service Improvement: To understand how users interact with the platform and improve our threat intelligence features.
- •Communications: To send security alerts, platform updates, and educational content (with your consent).
- •Compliance: To maintain audit logs and meet regulatory requirements under SAMA, NESA, GDPR, and ISO 27001.
Data Sharing and Third Parties
- •We do NOT sell your personal data to advertisers or third parties.
- •We share data only with essential service providers (cloud hosting, authentication services) under strict data processing agreements.
- •We may disclose data if required by law, court order, or to protect against fraud or security threats.
- •All third-party integrations comply with regional data protection laws (PDPL, GDPR, SAMA Framework).
Your Rights
- •Access: You have the right to access and download your personal data at any time.
- •Correction: You can update or correct your profile information directly.
- •Deletion: You can request account deletion and data removal (subject to legal retention requirements).
- •Opt-Out: You can unsubscribe from marketing communications through your account settings.
- •For GDPR and PDPL compliance requests, contact: privacy@cybermashrek.com
Data Security
- •End-to-End Encryption: All data transmitted to and from our servers is encrypted using industry-standard TLS 1.2+.
- •Access Controls: User data is restricted to authorized personnel only.
- •Regular Audits: We conduct security assessments and penetration testing annually.
- •Incident Response: We maintain a 24-hour incident response protocol and will notify affected users of any breach within regulatory timeframes.
- •Compliance Certifications: Our infrastructure meets ISO 27001 standards.
Contact and Data Rights Requests
- •Privacy Officer: privacy@cybermashrek.com
- •Data Deletion Requests: dpo@cybermashrek.com
- •Security Concerns: security@cybermashrek.com
- •Response Time: We aim to respond to all data rights requests within 30 days.
- •Regional Regulators: SAMA (Saudi Arabia), NESA (UAE), GDPR authorities (EU), relevant national regulators.
Regional Compliance
Saudi ArabiaCompliant with SAMA Cybersecurity Framework and PDPL (Personal Data Protection Law)
UAECompliant with NESA (National Electronic Security Authority) guidelines
EuropeFully compliant with GDPR (General Data Protection Regulation)
InternationalAdherent to ISO 27001 information security standards
Cookies and Tracking
We use cookies and similar technologies for:
- •Essential: Session management and security (required for login)
- •Analytics: Understanding user behavior to improve the platform (optional)
- •Preferences: Remembering your language and theme settings
You can manage cookie preferences via your browser settings or our cookie consent banner.
