Privacy and Cookie Policy
This Privacy and Cookie Policy explains how Tadeed Strategic Services LLC collects, uses, stores, shares, transfers, and protects personal data when you use Connect.
Introduction
This Privacy and Cookie Policy explains how Tadeed Strategic Services LLC collects, uses, stores, shares, transfers, and protects personal data when individuals and organizations access or use Connect.
Connect is a software-as-a-service platform that enables businesses and teams to create and manage digital business cards, QR codes, documents, links, profiles, and related digital content.
In this Policy:
- “Connect,” “Platform,” “Service,” “we,” “us,” and “our” refer to Tadeed Strategic Services LLC and the Connect platform.
- “User,” “you,” and “your” refer to any person or organization accessing or using the Platform.
- “Customer” refers to an organization or person that creates or pays for a Connect account.
- “Team Member” refers to an individual invited to use an account managed by a Customer.
- “Visitor” refers to a person who visits the Platform without registering.
- “Personal Data” means information that identifies, relates to, describes, or may reasonably be linked to an identifiable individual.
- By using Connect, you acknowledge that your Personal Data will be handled as described in this Policy.
Data Controller
Unless stated otherwise, the controller responsible for Personal Data processed through Connect is:
Tadeed Strategic Services LLC, Operator of Connect
Al Lolwa Commercial Center, Building No. 7447, Unit B13, First Floor, 9th Street, Al Amamrah District, Dammam 32415, Kingdom of Saudi Arabia
Email: info@tadeed.com. Telephone: +966 541 766 969. Platform: connect.tadeed.com. Corporate website: tadeed.com. MISA Licence No.: 24925234377
For some business accounts, the Customer may act as the controller of Personal Data entered or uploaded by its authorized users, while Tadeed Strategic Services LLC acts as a processor or service provider on the Customer’s instructions.
Scope
This Policy applies to Personal Data collected through:
- The Connect website and web application.
- Connect account registration.
- Digital business cards and public profiles.
- QR codes generated or managed through Connect.
- Documents and files uploaded to the Platform.
- Subscription and billing processes.
- Customer service and support communications.
- Emails, forms, surveys, and business communications.
- Cookies, analytics technologies, and server logs.
- This Policy does not govern third-party websites, services, payment gateways, applications, or links that Connect does not control.
Personal Data We Collect
Depending on how you use Connect, we may collect the following categories of Personal Data.
4.1 Account and identity information
We may collect:
- Full name.
- Username.
- Email address.
- Telephone number.
- Password or authentication credentials in protected form.
- Preferred language.
- Country or region.
- Account role and permissions.
- Company or organization name.
- Job title, department, and professional information.
4.2 Digital business card and profile information
You may choose to provide:
- Profile photograph.
- Company logo.
- Professional biography.
- Business address.
- Website address.
- Email addresses and telephone numbers.
- Social media and messaging links.
- Professional qualifications.
- Products, services, portfolios, or business descriptions.
- Customized buttons, links, branding, and contact details.
- Some of this information may become publicly accessible when you publish or share a digital business card, profile, link, or QR code.
4.3 Team and organization information
For business and team accounts, we may collect:
- Organization name and business details.
- Administrator information.
- Team-member names and contact details.
- Organizational roles.
- Account permissions.
- Invitation and acceptance records.
- Team activity and account-management logs.
4.4 QR-code information
We may process:
- QR-code content.
- Destination links.
- QR-code names and identifiers.
- Creation and modification dates.
- Scan counts.
- Scan date and time.
- General device, browser, and operating-system information.
- Approximate geographic information derived from an IP address.
- Referring source or campaign information.
- Unless explicitly stated within the Platform, scan analytics should not be treated as identifying the individual who scanned a QR code.
4.5 Documents and user content
When you upload or share files, we may process:
You must not upload sensitive, confidential, regulated, or third-party Personal Data unless you have a lawful basis, appropriate authorization, and adequate safeguards.
- File names.
- File types.
- File sizes.
- File contents.
- File metadata.
- Upload and modification dates.
- Sharing settings.
- Access permissions.
- Download or viewing activity, where available.
4.6 Subscription and transaction information
For paid plans, we may collect:
Payment-card information may be collected and processed directly by an authorized payment provider. Connect may receive only limited payment information, such as payment status, card type, and the final digits of a payment card.
- Selected subscription plan.
- Billing name and address.
- Company billing information.
- Invoice details.
- Tax information.
- Payment status.
- Payment date.
- Transaction reference.
- Renewal, cancellation, and refund records.
4.7 Support and communication information
We may collect information contained in:
- Support requests.
- Emails.
- Complaints.
- Feedback.
- Survey responses.
- Telephone or online communications.
- Service-related correspondence.
4.8 Technical and usage information
We may automatically collect:
- IP address.
- Browser type and version.
- Device type.
- Operating system.
- Language and time-zone settings.
- Login and session information.
- Pages and features accessed.
- Dates and times of activity.
- Clickstream and interaction data.
- Error reports.
- Security logs.
- Referral information.
- Cookie and similar-technology identifiers.
Sources of Personal Data
We may obtain Personal Data:
Where a Customer provides Personal Data relating to another person, the Customer confirms that it is authorized to do so and has provided any legally required privacy notices.
- Directly from you.
- From your employer or organization.
- From a team administrator.
- When another user invites you to Connect.
- From payment and technical service providers.
- Through cookies and automated technologies.
- From publicly available professional or business sources.
- From authorized partners or resellers.
- When you scan, open, or interact with Connect content.
Purposes of Processing
We may process Personal Data to:
We will not process Personal Data in a manner incompatible with the purpose for which it was collected unless permitted by applicable law or supported by a valid legal basis.
- Create, authenticate, and manage accounts.
- Provide digital business cards, QR codes, profiles, documents, and links.
- Enable team administration and collaboration.
- Publish or share content according to user instructions.
- Process subscriptions, invoices, payments, renewals, and refunds.
- Provide customer support.
- Respond to requests, complaints, and inquiries.
- Personalize Platform settings and user experience.
- Monitor performance, reliability, and availability.
- Develop, test, maintain, and improve Platform functionality.
- Generate aggregated analytics and business insights.
- Detect fraud, misuse, spam, malware, and security threats.
- Enforce our Terms and other policies.
- Protect users, third parties, and Tadeed Strategic Services LLC.
- Maintain business, security, and audit records.
- Meet legal, regulatory, tax, accounting, and compliance obligations.
- Establish, exercise, or defend legal claims.
- Send operational and security notices.
- Send marketing communications where permitted by law.
- Obtain feedback and evaluate customer satisfaction.
Legal Bases for Processing
Depending on the circumstances and applicable law, we may process Personal Data based on:
Where processing is based on consent, you may withdraw that consent. Withdrawal will not affect processing lawfully completed before withdrawal.
Certain information is required to create an account, provide the Service, process payment, or meet legal obligations. If it is not provided, we may be unable to deliver all or part of the Service.
- Your consent.
- Performance of a contract with you.
- Steps taken at your request before entering into a contract.
- Compliance with a legal or regulatory obligation.
- Protection of your vital interests or those of another person.
- A legitimate interest permitted by applicable law.
- Another lawful basis recognized under the Saudi Personal Data Protection Law.
Publicly Shared Information
Digital business cards, public profiles, QR-code destinations, documents, links, and other content may be visible to anyone with access to the relevant link or QR code.
Before publishing or sharing content, you should:
Search engines or third-party websites may cache publicly accessible content. Removal from Connect may not immediately remove copies held by third parties.
- Review the information included.
- Remove information you do not want publicly available.
- Use access controls where available.
- Confirm that you have authority to publish third-party information.
- Avoid uploading confidential or sensitive content to public links.
- We are not responsible for third parties copying, saving, indexing, forwarding, or otherwise using information that you intentionally make public.
Customer-Controlled Data
Business Customers determine what data their authorized users enter, upload, publish, and share through their accounts.
Where we process Personal Data solely for a Customer:
- The Customer is responsible for providing lawful instructions.
- The Customer is responsible for notices, permissions, and legal bases.
- We process the data to provide and secure the Service.
- Requests relating to Customer-controlled data may be referred to the relevant Customer.
- The Customer controls user access, permissions, and account administration.
- Customers must not use Connect to collect or process Personal Data unlawfully.
Sharing and Disclosure
We do not sell Personal Data.
We may disclose Personal Data to the following recipients where necessary and lawful:
10.1 Service providers
These may include providers of:
- Cloud hosting and storage.
- Content delivery.
- Authentication.
- Cybersecurity and monitoring.
- Payment processing.
- Billing and invoicing.
- Email and messaging.
- Customer support.
- Analytics.
- Error tracking.
- Backup and disaster recovery.
- Professional consulting.
- Service providers are permitted to process Personal Data only for authorized purposes and subject to contractual or legal safeguards.
10.2 Customers and account administrators
Where you use a business or team account, administrators may access:
- Your profile information.
- Team activity.
- Account permissions.
- Content created under the account.
- Usage information.
- Account status.
- Your organization may manage, suspend, export, modify, or delete your account and associated content.
10.3 Legal and regulatory authorities
We may disclose information where reasonably necessary to:
- Comply with law, regulation, court order, or lawful government request.
- Protect rights, safety, security, or property.
- Investigate fraud or unlawful activity.
- Enforce contractual rights.
- Respond to emergencies.
- Establish, exercise, or defend legal claims.
10.4 Business transactions
Personal Data may be disclosed in connection with a proposed or completed merger, acquisition, financing, reorganization, sale of assets, or transfer of business, subject to appropriate safeguards.
10.5 With your instructions or consent
We may share information when you instruct us to do so or provide valid consent.
International Data Transfers
Some service providers may process or store Personal Data outside the Kingdom of Saudi Arabia.
Where Personal Data is transferred outside the Kingdom, we will take measures required by applicable law, which may include:
- Confirming an applicable legal basis.
- Assessing transfer risks.
- Using approved contractual safeguards.
- Limiting the data transferred.
- Applying technical and organizational protections.
- Obtaining approvals where legally required.
- The specific locations and transfer safeguards may depend on the hosting, payment, communication, analytics, and support providers used by Connect.
Data Retention
We retain Personal Data only for as long as reasonably necessary for the purposes described in this Policy, including to:
- Maintain active accounts.
- Provide the Service.
- Complete transactions.
- Meet legal, tax, accounting, and regulatory duties.
- Resolve disputes.
- Prevent fraud and abuse.
- Enforce agreements.
- Maintain security and audit records.
- Defend legal claims.
- Retention periods may vary according to the type of data, legal requirements, account status, risk, and business need.
- When data is no longer required, we may securely delete, anonymize, or isolate it, subject to backup cycles and legal retention obligations.
- Account deletion may not immediately remove:
- Information stored in routine backups.
- Transaction and invoice records.
- Security and fraud-prevention records.
- Records required by law.
- Content copied or retained by other users.
- Public content cached by search engines or third parties.
Data Security
We use reasonable technical and organizational measures designed to protect Personal Data, which may include:
No website, cloud service, database, or transmission method is completely secure. You are responsible for maintaining strong credentials, controlling account access, and immediately notifying us of suspected unauthorized use.
- Encryption during transmission.
- Access controls and authentication.
- Role-based permissions.
- Secure hosting practices.
- Logging and monitoring.
- Vulnerability management.
- Backup procedures.
- Employee and contractor confidentiality obligations.
- Incident-management procedures.
- Service-provider assessments.
Personal Data Breaches
If a Personal Data breach occurs, we will investigate and take reasonable measures to contain, assess, and remediate the incident.
Where required by applicable law, we will notify the relevant authority and affected individuals within the applicable legal period.
Users and Customers must promptly inform us of suspected security incidents involving Connect accounts or data.
Your Privacy Rights
Subject to applicable law, you may have the right to:
We may refuse or limit a request where permitted or required by law, including where the request would adversely affect another person’s rights, conflict with legal retention duties, compromise security, or reveal protected information.
For Customer-controlled data, we may direct your request to the Customer responsible for the relevant account.
Privacy requests may be sent to info@tadeed.com.
- Be informed about the collection and processing of your Personal Data.
- Access your Personal Data.
- Obtain a copy of your Personal Data in a clear and readable format.
- Correct, complete, or update inaccurate Personal Data.
- Request destruction or deletion of Personal Data where legally permitted.
- Withdraw consent where processing is based on consent.
- Object to or request restriction of certain processing where applicable.
- Submit a complaint to the competent authority.
- Exercise other rights provided by applicable law.
- We may need to verify your identity before processing a request.
Marketing Communications
We may send marketing messages where permitted by law.
You may opt out by:
- Using the unsubscribe option in the message.
- Adjusting available communication preferences.
- Contacting us at info@tadeed.com.
- Even after opting out of marketing, you may continue to receive essential account, security, billing, legal, and service communications.
Cookies and Similar Technologies
Connect may use cookies, local storage, pixels, scripts, software-development kits, and similar technologies.
17.1 Essential cookies
These technologies support:
- Account login.
- Session continuity.
- Security.
- Fraud prevention.
- Load balancing.
- Language preferences.
- Core Platform functions.
- Disabling essential cookies may prevent the Platform from operating correctly.
17.2 Preference cookies
These technologies remember settings such as:
- Language.
- Display preferences.
- Saved selections.
- Account settings.
17.3 Analytics cookies
These technologies help us understand:
- Visitor numbers.
- Feature usage.
- Page performance.
- Navigation patterns.
- Technical errors.
- Service reliability.
- Where required by law, non-essential analytics technologies will be used only after obtaining appropriate consent.
17.4 Marketing cookies
Where used, marketing technologies may help:
- Measure campaign performance.
- Limit repetitive advertisements.
- Understand referrals.
- Present relevant promotional content.
- Marketing cookies will be subject to consent where required.
17.5 Managing cookies
You may manage cookies through:
- The Platform’s cookie-consent tool, where available.
- Browser settings.
- Device settings.
- Third-party opt-out tools.
- Blocking certain cookies may affect Platform performance and functionality.
17.6 Cookie register
Before publication, Connect should maintain an up-to-date internal and public cookie register stating:
- Cookie name.
- Provider.
- Purpose.
- Category.
- Duration.
- Whether the cookie is first-party or third-party.
- The register should reflect the actual technologies deployed on the Platform.
Children’s Privacy
Connect is designed for professional, organizational, and business use. It is not directed to children.
Users must be at least 18 years old or the age of legal capacity applicable to them, whichever is higher.
We do not knowingly collect Personal Data from children without legally valid authorization. If we become aware that such information was collected improperly, we may delete it and terminate the relevant account.
Sensitive Personal Data
Connect is not intended for storing highly sensitive or specially regulated information unless we expressly agree otherwise in writing.
Users should not upload:
- Health or medical records.
- Biometric or genetic data.
- Government identification documents.
- Criminal records.
- Financial account credentials.
- Payment-card security codes.
- Passwords belonging to other services.
- Confidential legal, employment, or disciplinary records.
- Information requiring sector-specific authorization.
- If such data is processed, the Customer remains responsible for confirming that its use is lawful and appropriately protected.
Automated Processing and Analytics
We may use automated tools to:
We do not intend to make decisions producing legal or similarly significant effects solely through automated processing unless we provide a separate notice and comply with applicable law.
- Detect spam.
- Identify suspicious activity.
- Protect account security.
- Analyze Platform performance.
- Categorize support requests.
- Generate aggregated usage insights.
Third-Party Services and Links
Connect may contain integrations, links, embedded content, payment services, or tools operated by third parties.
Those third parties process Personal Data under their own terms and privacy policies. We are not responsible for third-party privacy, security, content, or availability.
You should review third-party policies before providing information or enabling integrations.
Changes to This Policy
We may update this Policy to reflect:
- Changes to the Platform.
- New legal requirements.
- New service providers.
- Security or operational changes.
- Changes to our business practices.
- We will publish the revised Policy and update the “Last updated” date.
- Where a change materially affects your rights or how we use Personal Data, we may provide additional notice where required by law.
Complaints
You may first contact us so that we can investigate and address your concern.
You may also have the right to submit a complaint to the competent personal-data-protection authority in the Kingdom of Saudi Arabia.
Contact Us
For privacy questions, rights requests, or complaints, contact:
Tadeed Strategic Services LLC, Operator of Connect
Al Lolwa Commercial Center, Building No. 7447, Unit B13, First Floor, 9th Street, Al Amamrah District, Dammam 32415, Kingdom of Saudi Arabia
Email: info@tadeed.com. Telephone: +966 541 766 969. Platform: connect.tadeed.com. Corporate website: tadeed.com. MISA Licence No.: 24925234377
