Privacy Policy
Effective 2026-09-08 · Saudi Personal Data Protection Law (PDPL)
1. Who We Are and Effective Date
This policy takes effect on 8 September 2026 (2026-09-08) and replaces any earlier version.
Rewaq Pro is a cloud accounting and business-management system for small and medium businesses in the Kingdom of Saudi Arabia. It covers sales, purchases, inventory, general ledger, point of sale and fuel-station POS, and works in Arabic and English. The main site is https://rewaq.pro; every subscribing business gets its own address in the form https://<business-name>.rewaq.pro, and there is a Rewaq POS app for Android.
The company that runs the service and is responsible for this policy is: Rewaq Modern Business Co. (CR No. [commercial registration number]), located at: [operator's national address].
In this policy, "we" means the operating company, "customer" means a business that subscribes to Rewaq Pro, "user" means any person for whom a customer creates a login, and "you" means anyone this policy applies to.
This policy applies to: (a) customers and their users, (b) people whose data customers enter into the system (their own customers, suppliers and employees), to the extent described in the section "Who Is Responsible for the Data?", and (c) anyone who contacts us through our support channels. Browsing the website without creating an account involves no tracking tools, and no cookies other than the display-language cookie described in the "Cookies" section.
This policy is written in accordance with the Saudi Personal Data Protection Law issued by Royal Decree No. M/19 dated 9/2/1443H, as amended by Royal Decree No. M/148 dated 5/9/1444H (the PDPL), its Implementing Regulations, and the Regulation on Personal Data Transfer Outside the Kingdom. The Saudi Data and Artificial Intelligence Authority (SDAIA) supervises the PDPL. We make this policy available to you before collecting any data, as Article 12 of the PDPL requires.
This policy explains, in plain language, what data we collect, why, who we share it with, where it is stored, how we protect it, and what your rights are. If you use the system on behalf of a business, you confirm that you are authorised to read and accept this policy for it.
2. Who Is Responsible for the Data? (Controller and Processor)
Rewaq Pro holds two kinds of data, and our legal responsibility differs for each:
- The first kind: your account data with us (your name, email, subscription and login details, support correspondence). Here we are the "controller": we decide why this data is collected and how it is used, and we carry the controller's obligations under the PDPL.
- The second kind: the business data you enter into the system (your customers, suppliers, employees, invoices, journal entries). Here the customer is the "controller" and we are the "processor": we store and process it on the customer's behalf and only on its documented instructions.
The terms as the PDPL defines them: "personal data" is any data that identifies a specific person directly or indirectly. A "controller" decides the purpose and means of processing. A "processor" processes data on behalf of, and for, a controller.
Example: if you record an invoice for your customer "Al-Noor Trading Est.", that customer's data is your responsibility. We never use it for purposes of our own, and we only touch it as far as needed to run and secure the service, or when you ask for support.
As the processor of your business data, we commit to:
- Not using it for anything other than providing, maintaining and securing the service for you.
- Not sharing it with anyone except the providers listed in "Who We Share Data With", or where the law requires.
- Not adding a new provider that processes your data without notifying you first.
- Helping you answer requests from your customers and employees about their data, and notifying you of any incident affecting your data.
- Deleting your data, or returning it to you, when your subscription ends, as described in "How Long We Keep Data, and Deletion".
What this means in practice: you are responsible for collecting your customers', suppliers' and employees' data lawfully, for telling them it is kept in a cloud accounting system, and for answering their requests about it. We give you the technical tools to do that: export, edit and delete.
The relationship between us and you as controller is governed by the Terms of Service and the Data Processing Agreement: [link/reference to the Rewaq Pro–customer data processing agreement].
3. The Data We Collect
A. Account data you give us (we are the controller). Collected when you sign up at https://rewaq.pro or when a user is added inside a customer account:
- Full name.
- Company name.
- The subdomain you choose (for example: alnoor.rewaq.pro).
- Email address (verified through a link we send you when you self-register; a user added by the business's admin has the email the admin entered).
- Password. We never store it as typed; we keep only an Argon2id hash of it, and nobody at Rewaq Pro can see it.
- Phone number (optional).
- If you turn on two-factor authentication: the key needed to verify the codes from your authenticator app (TOTP).
- Your contact details and the content of your message when you write to us on WhatsApp or by email.
B. Security data and logs generated automatically (we are the controller):
- Your IP address, browser or device type at each login, and the time of your last login. These go into a security log that protects your account.
- The activity log inside the customer account: who did what and when. Support-staff access is recorded in our own system logs (see the security section).
C. Business data you enter into the system (the customer is the controller; we are the processor):
- Your company's registration data: commercial registration (CR) number, VAT number, national address.
- Your employees' data if you use the HR and payroll module: name, national ID or iqama number, salary and allowances, bank account details.
- Any attachments or files you upload to documents (supplier invoices, contracts, images).
- Customer-portal accounts if you enable the portal: your customer's email and a hashed password so they can view their statement.
- Your users and employees: name, email, phone, roles and permissions.
- Your customers and suppliers: names, VAT numbers, CR numbers, addresses, phone numbers, email addresses.
- Invoices, credit and debit notes, payments, journal entries, inventory, price lists.
- E-invoice XML files and QR codes the system generates for the Zakat, Tax and Customs Authority (ZATCA).
- Signer details (name, phone, email) when you enable electronic signing of delivery notes through Sadq.
The system does not require any sensitive data within the meaning of the PDPL (such as health, religious, genetic or biometric data), and we ask you not to enter such data into it. We collect no data about you from outside sources, and we use no advertising trackers or third-party analytics.
4. Why We Use Data, and On What Legal Basis
We process account data only for the purposes below, each with its legal basis under Articles 5 and 6 of the PDPL:
- Creating your account, running your business's address, delivering the service, and managing the subscription and billing. Basis: performance of our contract with you, or steps taken at your request before entering into it.
- Sending email verification, account notifications, and a few onboarding emails during the trial that explain how to get started (you can ask us to stop them). Basis: performance of the contract.
- Contacting you about your account by phone, if you provided a number. Basis: performance of the contract; providing the number is optional and you can ask us to remove it at any time.
- Protecting your account and the system against intrusion and fraud (login log, lock after 5 failed attempts, two-factor authentication). Basis: our legitimate interest, and that of our customers, in securing the service; this processing involves no sensitive data and does not prejudice your rights.
- Providing technical support when you ask for it, including time-limited, logged access to your account by a support staff member. Basis: performance of the contract at your request.
- Complying with Saudi law and responding to competent authorities where there is a legal obligation. Basis: legal obligation.
Your business data is processed by us as a processor for one purpose only: carrying out your instructions through the system's functions (issuing invoices, journal entries, reports, submitting invoices to ZATCA when the integration is enabled, and e-signature when enabled). The legal basis for collecting that data is yours to determine as controller.
What we never do:
- We do not sell or rent your data.
- We do not use it for advertising or share it with advertisers.
- We do not currently send marketing messages. If we ever wish to, we will only do so with your prior consent, and you will be able to stop them at any time.
- We do not make solely automated decisions with legal effects about you based on your data, and we do not build profiles of you.
- We do not use your business data (your customers, your invoices) for anything other than running the service for you.
We follow the principle of data minimisation: we collect only what the stated purpose needs, and we do not process data for a different purpose than the one it was collected for, except where the PDPL permits.
5. Who We Share Data With
We share your data only with the parties below, and only to the minimum needed for each purpose. The list contains no advertising or analytics providers.
A. Service providers (sub-processors):
- Hetzner Online GmbH
- Purpose: hosting of the application, database and backups.
- Data: all account data and customer business data, since it is the service's infrastructure.
- Location: Helsinki, Finland (EU) — outside Saudi Arabia.
- Resend (via Amazon SES)
- Purpose: transactional email only: signup verification, notifications, onboarding emails during the trial.
- Data: the recipient's email address, name and the message content. No accounting data and no marketing email passes through it.
- Location: Resend Inc. in the USA; messages are relayed through Amazon SES servers outside Saudi Arabia (the AWS ap-northeast-1 region in Japan).
- Cloudflare
- Purpose: domain-name lookup (DNS) only. None of your data or your traffic to the system passes through Cloudflare.
- Data: domain-name resolution queries only, containing no personal data.
- Location: USA.
- Sadq
- Purpose: electronic signing of delivery notes if you enable the feature. Nothing is sent to Sadq unless you enable it.
- Data: the signer's name, phone number, email and national ID number (if you enter it), plus the delivery-note document itself so it can be signed.
- Location: Saudi Arabia.
Each of these providers is bound by contract to protect the data and to use it only for the stated purpose and on our instructions. We will notify customers before adding a new provider or replacing one of those listed, and we will update this list before any sharing begins.
B. Government authorities, under a legal obligation:
- ZATCA (the Zakat, Tax and Customs Authority), Fatoora platform: see "E-Invoicing and ZATCA". ZATCA is a government authority; submission to it is a legal obligation, not a service we buy.
- Any competent Saudi judicial or regulatory authority, upon a binding lawful order or request, limited to what is strictly required. We notify the affected customer unless the law prohibits it.
Inside your business: you control which of your users can see your data through roles and permissions, and each customer's data is fully isolated from every other customer's.
If Rewaq Pro is sold or merged with another entity, data may pass to the successor provided it is bound by this policy or one at least as protective, and we will notify you in advance.
6. Transfers Outside Saudi Arabia
We want to be clear with you: our servers are in Helsinki, Finland (inside the European Union). This means your account data and your business data — including your customers, invoices, journal entries and backups — are stored outside the Kingdom of Saudi Arabia.
Transactional emails (verification, notifications, onboarding emails) also pass through Resend servers in the USA and Amazon SES servers outside the Kingdom, and they contain your name, email address and the message content. DNS lookups are served by Cloudflare in the USA and contain no personal data.
What is sent to ZATCA and to Sadq stays inside the Kingdom.
We make these transfers under Article 29 of the PDPL and the Regulation on Personal Data Transfer Outside the Kingdom, relying on: [transfer mechanism adopted for transfers outside the Kingdom: an adequacy decision for the destination country, SDAIA standard contractual clauses, or other appropriate safeguards]. We commit to:
- Limiting transfers to the minimum data needed to provide the service.
- Encrypting data in transit (TLS 1.2 or higher) and encrypting backups.
- Signing data processing agreements with providers outside the Kingdom that bind them to a level of protection no lower than the law requires.
- Carrying out a transfer risk assessment as the Regulation requires, and updating it when circumstances change.
- Not transferring data to any additional country or party without first updating this policy.
Important: if your business is regulated by an authority that requires your data to stay inside Saudi Arabia (some financial or healthcare sectors, for example), or if the Zakat and tax rules you are subject to set conditions on where your records are kept or accessed, check that using the system is compatible with those requirements before subscribing. You can export all of your data at any time.
We will update this section if we move hosting to a data centre inside the Kingdom or change any of our providers.
7. E-Invoicing and ZATCA
The system generates e-invoice XML files and QR codes for your invoices in the format ZATCA (the Zakat, Tax and Customs Authority) requires, and stores them in your business account.
When you enable Phase-2 e-invoicing integration, tax invoices, credit and debit notes and prepayment invoices are digitally signed and submitted to ZATCA's Fatoora platform for clearance or reporting. Nothing is sent to ZATCA unless you enable the integration.
The data submitted is the content of the invoice itself: seller and buyer details (name, VAT number, CR number, address), the invoice lines, amounts and tax.
Legal basis: a legal obligation that rests on you as the taxpayer under the VAT Law, its Implementing Regulations and the E-Invoicing Regulations, which we carry out as a processor on your behalf. ZATCA is a government authority, not our vendor, and processes what it receives under its own rules inside the Kingdom.
What has been submitted to ZATCA cannot be recalled or deleted by us, and is not affected by deletion of your data on our side. We therefore recommend keeping a copy of your invoice XML files with your statutory records (see the tax-record retention period in the next section).
8. How We Protect Your Data, and What Happens in an Incident
We apply the following technical and organisational measures in accordance with Article 19 of the PDPL:
- All traffic between your device and our servers is encrypted (TLS 1.2 or newer, with Let's Encrypt certificates).
- Passwords are stored as an Argon2id hash and cannot be recovered.
- Short sessions: the access token lasts 15 minutes and lives only in browser memory; the refresh token lasts 7 days in a protected (httpOnly, Secure) cookie that scripts cannot read.
- Two-factor authentication (TOTP) is available to every user, and we recommend turning it on.
- Accounts lock automatically after 5 failed login attempts.
- Each customer's data is isolated from every other customer's in every database query (tenant_id), enforced in the data-access layer. One business cannot see another's data.
- Roles and permissions inside your business: you decide who sees what and who can do what.
- Encrypted daily backups at 02:00 Riyadh time, keeping 30 daily and 12 monthly copies.
- An activity log of important operations inside each account.
Temporary support access to your account: our support team may occasionally need to enter your account to reproduce a technical problem or verify a security report. This access is subject to the following controls:
- It is used only for technical support, investigating a problem or security incident, or legal compliance.
- The session is short and expires automatically after at most one hour.
- Every session is recorded in our system logs with the identity of the staff member and the time.
- Support staff cannot see your password.
Data breach notification: no system is 100% secure. If personal data is leaked, destroyed or accessed unlawfully, we commit, under Article 20 of the PDPL and its Implementing Regulations, to:
- Notify the Saudi Data and Artificial Intelligence Authority (SDAIA) within no more than 72 hours of becoming aware of the incident, where it may harm the data or the people it concerns.
- Notify affected people without undue delay, describing the nature of the incident, the likely risks, the measures we have taken, and the steps they can take to protect themselves.
- As processor of your business data: notify you as soon as we become aware, and give you what you need to meet your own obligations towards SDAIA and towards your customers and employees.
- Record the incident, its causes and the corrective actions in an internal register.
Your part matters too: do not share your password, turn on two-factor authentication, remove access for employees who have left, and tell us immediately if you suspect unauthorised use of your account.
9. How Long We Keep Data, and Deletion on Cancellation
We keep data only as long as its purpose requires, then delete or anonymise it in accordance with Article 18 of the PDPL, unless another law requires a longer period:
- Account and subscription data: for as long as you subscribe, then deleted within 90 days of cancellation, unless the law requires us to keep it longer.
- Your business data (invoices, journal entries, inventory, etc.) and the in-account activity log: for as long as you subscribe, then deleted with the account within 90 days of cancellation.
- Tax invoices and accounting records: Saudi VAT and Zakat rules require businesses to keep them for at least 6 years. That duty rests with your business as the taxpayer; Rewaq Pro does not act as a records custodian for you after your subscription ends.
- Backups: a rolling cycle of 30 daily, 12 monthly and 7 yearly copies, overwritten automatically. A copy of deleted data may therefore remain inside encrypted backups for up to 12 months after deletion, and in the yearly copy for up to 7 years. Backups are used only to restore the system after a failure, never to restore data that was deleted on request.
- Login records (each user's last login IP and time) and the activity log: for as long as you subscribe, deleted with the account.
- Support correspondence: treated as part of your account data and kept for the same period.
What happens when you cancel:
- Before cancelling: export all of your data from inside the system (invoices, notes, journal entries, general ledger, customers, suppliers, items, e-invoice XML files). Export is available from each screen as Excel, and XML files from the e-invoicing report; once deleted, data cannot be recovered.
- Within 90 days of cancellation: your account data and business data are deleted from the live database. You may ask for deletion sooner by a documented request from an authorised user.
- After that: backups are overwritten on their cycle (12 months for monthly copies, 7 years for yearly ones), and only what the law requires us to keep remains (for example our own billing records).
- Deletion on our side does not affect what was lawfully submitted to ZATCA or signed through Sadq; those parties retain it under their own rules.
If you delete a customer, supplier or item inside the system, it disappears from your working screens immediately and moves to your Trash until you permanently delete or restore it. A user (employee) inside your business is deleted by your administrator from user settings.
At the end of the retention period, data is deleted in a way that prevents its recovery.
11. Your Rights, How to Exercise Them, and Complaints to SDAIA
The PDPL (Article 4) and its Implementing Regulations give you the following rights, which you can exercise free of charge:
- Right to be informed: to know the legal basis and purpose of collecting your data, which this policy provides.
- Right of access and to a copy: to see the data we hold about you and receive a copy in a clear, readable format.
- Right to correction: to have your data corrected, completed or updated.
- Right to deletion (destruction): to have your data deleted once the purpose of collection has ended, subject to legal exceptions such as tax retention periods.
- Right to withdraw consent: at any time for any processing based on your consent, without retroactive effect on earlier processing.
- Right to restrict processing: in the cases the PDPL allows.
- Right to object: to processing based on legitimate interest, subject to what the security of the service requires.
- Right to data portability: to export your business data (Excel from each screen, XML for e-invoices) in a format you can use in another system.
How to ask: write to [privacy email] or message us on WhatsApp at [support WhatsApp number]. We will verify your identity before acting, to protect your data, and reply within 30 days of receiving a complete request as the Implementing Regulations require. This period may be extended where the request is complex or where there are several requests, in which case we will tell you. We charge no fee except for repetitive or unfounded requests, within the limits the Regulations permit. We never treat anyone less favourably for exercising their rights.
If you are an employee, customer or supplier of a business that uses Rewaq Pro, your data in the system is that business's responsibility as controller. Send your request to it directly; if your request reaches us, we will forward it to that business and help it carry it out technically. We cannot alter or delete its data on our own initiative without its instructions, unless the law requires us to.
Complaints: if you are not satisfied with our answer or with how we handle your data, you have the right to lodge a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA), the authority responsible for enforcing the PDPL, through its official channels at https://sdaia.gov.sa or via the National Data Governance Platform. We would appreciate the chance to address your complaint first.
12. The Rewaq POS Android App
The Rewaq POS app for fuel stations is a shell that shows the same system on an Android device, and this policy applies to it in full. It collects no extra data about you.
- It stores on the device only: the server address, printer settings and the login session inside the app's browser view.
- It requests Bluetooth permission only to connect to a receipt printer.
- It does not access the camera, microphone or location.
- Everything you enter in it goes straight to your business account on our servers and is treated as customer business data under the same controls described in this policy.
If you hand the device to another employee, log out first.
13. Minors
Rewaq Pro is a service for businesses, business owners and accountants and is not intended for anyone under 18. We do not knowingly collect personal data from minors and do not allow accounts to be created for them.
If we learn that we have collected data from someone under that age without the consent of their legal guardian, we will close the account and delete the data without delay. If you believe this has happened, tell us at [privacy email].
14. Changes to This Policy and How to Contact Us
We may update this policy when our services, our providers or the law change. The updated version is published at https://rewaq.pro with a new effective date. For any material change (such as adding a provider outside the Kingdom, moving hosting, or changing the purposes of processing), we will notify customers by their registered email or an in-app notice a reasonable time before the change takes effect.
To contact us about privacy, your data, or to exercise your rights:
- Responsible entity: Rewaq Modern Business Co. (CR No. [commercial registration number])
- Address: [operator's national address]
- Privacy email: [privacy email]
- WhatsApp: [support WhatsApp number] (link available in the site footer). WhatsApp is a third-party service outside the Kingdom, so we recommend using email for requests that contain personal data.
- Data Protection Officer (if appointed): [DPO name/email]
Supervisory authority: Saudi Data and Artificial Intelligence Authority (SDAIA) — https://sdaia.gov.sa
This policy is governed by the laws of the Kingdom of Saudi Arabia. It is issued in Arabic and English; if the two texts conflict, the Arabic text prevails.