Privacy policy
General Privacy Notice
Securitas Saudi Arabia
1. About this Privacy Notice
We at Securitas (“Securitas”, “we” or “us”), together with affiliated companies worldwide (“Securitas Group”), are a multinational global security firm focused on delivering protective and digital services for our clients. We respect your privacy and integrity, and this General Privacy Notice describes how we collect and process personal data about you.
This General Privacy Notice applies to personal data processing relating to:
- clients or prospective clients
- visitors of our premises
- suppliers, prospective suppliers and other third parties providing services to us
- visitors of our websites and social media channels
- business event attendees
- other third parties whose data is obtained from publicly available sources or shared by other third parties, including employees, representatives or other staff of legal persons whose personal data we process
This country version is intended to supplement the Securitas Group privacy approach and reflect local requirements in Saudi Arabia, including Kingdom of Saudi Arabia Personal Data Protection Law (PDPL), its Implementing Regulations and SDAIA/National Data Governance requirements. Where a separate “just in time” privacy notice is provided before specific processing takes place, that specific notice should be read together with this General Privacy Notice.
1.1 Data controller
Where we determine the purpose and means of processing personal data, Securitas will be the data controller or equivalent local role. Where we act as a processor in our capacity of providing protective and digital services to our clients, we process personal data only in accordance with our clients’ instructions and the relevant agreement, for example data included in guards’ reports.
For Saudi Arabia, the local controller/personal information handler details should be: Company SICORETAS AL-ARABIA Saudi Arabia, National Unified No 7001603732, Al Amir Faisal Ibn Turki Ibn Abdul Aziz, Al Murabba Dist, Riyadh, Building No 2920, Zip Code 12626, and local DPO/privacy contact: berhan.hawariat@securitas.com.sa. Global privacy contact: privacy@securitas.com.
You may also contact the global privacy team at privacy@securitas.com.
2. How do we get information about you
In general, we collect personal data directly from you, for example when you contact us, request information, provide feedback, complete a form, register for an event, respond to a survey, use our chatbot or perform an agreement with us. We may also receive business contact details from the organisation for which you work or from a client, supplier or other third party with which we interact.
We may collect personal data through use of our premises, such as CCTV systems, visitor logbooks and access-control logs; through our infrastructure, such as when access is provided to Securitas systems; and automatically when you visit our websites, for example through cookies, log files, analytics tools and chatbot interactions. For further information about cookies, please refer to our Cookie Policy.
We may collect limited personal data from third parties or publicly available sources such as news, public announcements, public company registers and other accessible sources, for example to prepare newsletters, security reports, customer insights or business development materials. We apply data minimisation and anonymise or delete copies before sharing research outputs where appropriate.
Our website and services are intended for business visitors and adults. We do not knowingly collect children’s data through the website. Users should not provide sensitive or special-category data through the chatbot or website forms unless specifically requested by Securitas in a separate process supported by an appropriate local legal basis under Kingdom of Saudi Arabia Personal Data Protection Law (PDPL), its Implementing Regulations and SDAIA/National Data Governance requirements.
3. Categories of personal data
The exact scope of data processed depends on your relationship with us. In general, we may process the following categories of personal data:
|
Category |
Examples |
|
Identity data |
Name, business title, organisation, photographs and similar identification details. |
|
Contact information |
Business address, email address, telephone number, country or location. |
|
Financial information |
Payment, billing and account information required to process payments for services. |
|
Client service data |
Client matter numbers, company announcements and policies, service enquiries, forms submitted to us, survey responses and feedback. |
|
Marketing and communications data |
Newsletter requests, marketing preferences, email open/click data, event registration and attendance, campaign interaction data. |
|
Additional marketing information |
Information about interactions with our marketing communications and related Securitas content, where permitted by local law. |
|
Chatbot conversation |
Information voluntarily submitted into the chatbot to help navigate website visitors to requested content or respond to enquiries. |
|
Usage, technical and browsing data |
Website usage, language preference, IP address, log data, device data, unique identifiers, cookies and similar technologies. |
|
Conversation logs |
Chatbot logs retained for up to 13 months for performance measurement, quality improvement, troubleshooting and security, then deleted or anonymised unless local law requires a shorter period. |
|
Limited publicly available information |
Information from public announcements, news, public registers or other public sources used for newsletters, security reports or business development outputs. |
|
Information from guards’ reports and third parties |
Information contained in guards’ reports created under client instructions and other data received from clients, processed in accordance with the relevant agreement and, where used for analytics, only after anonymisation where required. |
|
CCTV and physical security data |
CCTV footage, visitor logs, access-card records and similar physical security records connected with our premises or services. |
Local legal review point: Sensitive personal data, including health, genetic, biometric, credit, criminal, religious, political or similar categories under the PDPL, must not be collected through the website or chatbot unless strictly necessary, lawful, proportionate and approved by Legal.
4. Processing your personal data
4.1 Purpose and legal basis of processing
Securitas only processes personal data for specific purposes and only processes the minimum personal data reasonably required for those purposes. We will use personal data only for the purpose for which it was collected, for a compatible purpose, or as otherwise permitted by applicable law.
Under the Saudi PDPL, personal data should be collected and processed on a lawful basis recognised by the PDPL and its Implementing Regulations. Consent is a key basis and should be capable of withdrawal, unless another lawful basis applies under Saudi law, such as compliance with legal obligations or other statutory exceptions confirmed by Legal.
|
Purpose of processing |
Legal basis / local requirement for legal review |
|
Deliver protective, digital and related security services to clients |
Use the lawful basis applicable to the scenario, which may include consent, contract necessity, legal obligation, legitimate/recognised interests, public interest, vital interests or another local basis where permitted. Legal must confirm final wording for this country. |
|
Manage client and prospective client relationships |
Use the lawful basis applicable to the scenario, which may include consent, contract necessity, legal obligation, legitimate/recognised interests, public interest, vital interests or another local basis where permitted. Legal must confirm final wording for this country. |
|
Manage supplier and third-party relationships |
Use the lawful basis applicable to the scenario, which may include consent, contract necessity, legal obligation, legitimate/recognised interests, public interest, vital interests or another local basis where permitted. Legal must confirm final wording for this country. |
|
Manage payments, invoicing, accounting and tax records |
Use the lawful basis applicable to the scenario, which may include consent, contract necessity, legal obligation, legitimate/recognised interests, public interest, vital interests or another local basis where permitted. Legal must confirm final wording for this country. |
|
Undertake marketing activities, newsletters, events and business development |
Use anonymised or aggregated information where possible. Where personal data is used for marketing or reports, rely on consent or another valid local lawful basis confirmed by Legal. |
|
Purpose of processing |
Legal basis / local requirement for legal review |
|
Build limited marketing profiles and engagement scoring where permitted |
Direct marketing and related profiling should not be carried out without the consent required by the Saudi PDPL. Individuals must be able to opt out or withdraw consent for marketing communications. Profiling must be limited, transparent and not used to make decisions producing legal or similarly significant effects unless expressly permitted by law. |
|
Interact with website visitors through forms, chatbot and digital channels |
Use the lawful basis applicable to the scenario, which may include consent, contract necessity, legal obligation, legitimate/recognised interests, public interest, vital interests or another local basis where permitted. Legal must confirm final wording for this country. |
|
Request feedback, conduct surveys and market research |
Use the lawful basis applicable to the scenario, which may include consent, contract necessity, legal obligation, legitimate/recognised interests, public interest, vital interests or another local basis where permitted. Legal must confirm final wording for this country. |
|
Manage and protect our business, systems, premises and data security |
Use the lawful basis applicable to the scenario, which may include consent, contract necessity, legal obligation, legitimate/recognised interests, public interest, vital interests or another local basis where permitted. Legal must confirm final wording for this country. |
|
Perform legal, compliance, ethics, conflict, fraud, beneficial owner, AML or sanctions checks where applicable |
Use the lawful basis applicable to the scenario, which may include consent, contract necessity, legal obligation, legitimate/recognised interests, public interest, vital interests or another local basis where permitted. Legal must confirm final wording for this country. |
|
Prepare newsletters, security reports and other related content using anonymised or public information where possible |
Use anonymised or aggregated information where possible. Where personal data is used for marketing or reports, rely on consent or another valid local lawful basis confirmed by Legal. |
4.2 Marketing profiling and building client profiles
Securitas uses profiling in limited circumstances relating to marketing and business development. We may combine limited engagement and interaction data, such as newsletter opens, website visits, event participation or form submissions, to understand business interests and provide more relevant content.
Direct marketing and related profiling should not be carried out without the consent required by the Saudi PDPL. Individuals must be able to opt out or withdraw consent for marketing communications.
We do not carry out fully automated decision-making that produces legal or similarly significant effects on individuals through the website. Any analytics tools are limited to marketing insights, and human review is maintained where meaningful decisions are made.
For this purpose, we may use cookies or similar technologies that collect limited information for marketing and optimisation. Non-essential cookies should be disabled by default unless activated through the cookie banner or another legally valid consent/choice mechanism required by local law.
You may object to direct marketing and related profiling or withdraw consent where processing is based on consent. We will respect your decision and adjust our records accordingly.
4.3 Transparency about GenAI
When using the chatbot on our website, you may be interacting with generative artificial intelligence or automated response technology. This technology helps us provide automatically generated responses to enquiries and assist visitors in finding relevant information. Responses may occasionally be incomplete or imprecise; our marketing and sales personnel can assist further on request. AI-generated replies should be labelled clearly, for example “AI answer”.
Do not submit confidential, sensitive or special-category personal data into the chatbot unless we specifically request that information through a secure process and provide a separate privacy notice where required.
4.4 How long we keep your data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected and no longer than permitted by applicable law. For client or supplier relationships, we usually retain personal data for as long as needed to perform the contract and then for the period required for legal, tax, accounting, audit, dispute or regulatory purposes.
Where processing is based on consent, we process personal data until consent is withdrawn or until the relevant purpose ends, unless we are permitted or required to retain the data for another legal reason. All personal data is held in accordance with local retention schedules. Chat logs used for performance measurement, quality improvement and troubleshooting are retained for up to 13 months and then deleted or anonymised, unless a shorter period is required locally.
5. Who do we share your personal data with?
Securitas will only share personal data where there is a lawful basis or other valid legal justification, and only in a manner consistent with this General Privacy Notice and applicable local law.
Service providers and subcontractors: Personal data may be processed by service providers, subcontractors and business partners, including website hosting providers, cloud service providers, IT support, maintenance providers, analytics providers, marketing service providers and customer support providers. These parties may process personal data only on documented instructions from Securitas and only for the purposes described in this notice, unless they are independent controllers under local law.
Securitas Group: Personal data may be processed by companies within the Securitas Group that provide services in relation to common internal services, including IT support, management, administration, reporting, security, marketing and customer service. Group companies may act as processors, joint controllers or separate controllers depending on the processing activity and local law.
Public authorities: We may share personal data with public authorities such as police, tax authorities, regulators, courts, law enforcement authorities or national security organisations where required by law, in response to lawful requests, or to manage and defend legal claims. Authorities receiving personal data may be independent controllers for their own processing.
Other third parties: We may share personal data with legal advisers, auditors, insurers, professional advisers, event partners, advertising or marketing platforms, cookie providers such as embedded media providers, or other third parties where permitted by law and, where required, with your consent. Our websites may contain links to non-Securitas websites. Securitas is not responsible for the privacy practices of those external websites.
Chatbot providers: In relation to our chatbot, we may use Leadoo Marketing Technologies Ltd, Clearbit Inc. or equivalent/updated technical service providers acting on our instructions. They should be contractually bound to maintain confidentiality and not use Securitas data for AI model training or independent purposes unless separately approved by Legal.
6. Where we process your personal data
Personal data may be processed in Saudi Arabia, in the EU/EEA, and in other countries where Securitas Group companies, service providers or business partners operate. This may include hosting, technical support, marketing systems, security systems, analytics platforms and Group administrative systems.
Personal data should not be transferred outside the Kingdom of Saudi Arabia unless the transfer is permitted under the PDPL, the Transfer Regulations and any applicable adequacy, safeguard, exemption or approval requirements. Legal must approve regular transfers to Securitas Group companies or service providers outside Saudi Arabia.
Legal review requirement: confirm the actual hosting locations, chatbot data flows, cookie/analytics vendors, Group support locations and contractual transfer mechanism before publication.
7. How we protect your data
Securitas takes appropriate technical, physical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access. These measures may include access controls, network security, encryption where appropriate, confidentiality obligations, vendor due diligence, secure storage, incident response processes, data minimisation and retention controls.
Where a personal data breach occurs, Securitas will assess notification obligations under the Saudi PDPL and notify SDAIA and affected data subjects where required and within applicable timeframes.
8. Your rights
Securitas respects your privacy rights under applicable data protection law in Saudi Arabia. We may request additional information to confirm your identity and ensure the request originates from you before fulfilling your request.
Subject to applicable law, your rights may include:
- right to be informed of the legal basis and purpose of processing
- right to access personal data
- right to request correction, completion or updating of personal data
- right to request destruction or deletion where permitted
- right to withdraw consent where processing is based on consent
- right to object to or refuse direct marketing where recognised by Saudi law
- right to complain to SDAIA or another competent authority
To exercise your rights, please contact the local Securitas entity/privacy contact listed in section 1.1 or the global privacy team at privacy@securitas.com. You may also lodge a complaint with Saudi Data and Artificial Intelligence Authority
(SDAIA), or any other competent authority designated under Saudi law, subject to the procedure and conditions under local law.
9. Cookies, chatbot and digital channels
Our website may use cookies and similar technologies to provide core website functions, measure performance, improve user experience, support security, enable chatbot functionality and provide marketing content where permitted.
Non-essential cookies should be controlled through a cookie banner or preference centre that reflects local consent and opt-out requirements.
The chatbot may collect information that you type into the chat window. Please do not submit sensitive personal data, confidential client information, payment card data, passwords or information about third parties unless we specifically request it through a secure process.
Where chatbot data is used for quality improvement, performance measurement, troubleshooting or security, we retain the data only for the period described in this notice and then delete or anonymise it, subject to legal review for local retention limits.
10. Local legal review points before publication
- Confirm Arabic version requirement and exact statutory
- Confirm local controller, DPO/privacy contact and complaint
- Confirm cross-border transfer mechanism for AWS/EU/EEA and any Group
- Confirm exact local Securitas entity and registered
- Confirm DPO/privacy contact and regulator complaint
- Confirm cookie banner wording and consent/opt-out
- Confirm whether any local language version is legally or commercially
- Confirm whether the website uses Leadoo, Clearbit, AWS Ireland, YouTube, Spotify, GA/GTM or other vendors in this
- Confirm whether cross-border transfer notices, consents, impact assessments or filings are
11. Changes to this General Privacy Notice
We reserve the right to update this General Privacy Notice. If we make significant changes, we will notify you by displaying a notice on the Securitas website or by communicating with you directly where appropriate. Minor editorial changes may not prompt a separate notice.
This draft General Privacy Notice was last updated on 31 August 2026 for legal review.