1. Introduction and Legal Framework
At Edlaabox, we are committed to protecting your privacy and personal data in accordance with the Saudi Personal Data Protection Law (PDPL) issued by Royal Decree No. (M/19) dated 9/2/1443H, effective September 14, 2024.
This policy explains how we collect, use, and protect your information when using our electronic voting platform.
Edlaabox - Electronic Voting Platform
Email: privacy@edlaabox.com
2. Personal Data We Collect
2.1 Basic Personal Data
- Identity Data: Full name, National ID/Iqama number, Membership number
- Contact Data: Email address, Mobile phone number
- Usage Data: Login records, Voting times, IP address, Browser type
2.2 Sensitive Data (as defined by PDPL)
We may collect the following data classified as sensitive:
- Voting Data: Votes and choices in meetings (encrypted and protected)
- Membership Data: Membership type and voting privileges
3. Legal Basis for Data Processing
We process your data based on the following legal grounds under PDPL:
| Purpose | Legal Basis |
|---|---|
| Identity and eligibility verification | Contract performance |
| Voting operations | Explicit consent + Legitimate interest |
| Sending invitations and notifications | Contract + Consent |
| Governance compliance | Legal obligation |
| Service improvement | Legitimate interest |
4. Data Protection and Security Measures
We implement strict security measures in accordance with NCA (National Cybersecurity Authority) requirements:
- Data encryption in transit (TLS 1.3) and at rest (AES-256)
- Two-factor authentication (OTP) for sensitive operations
- Comprehensive audit logs for all operations
- Encrypted and regular backups
- Limited access based on "least privilege" principle
- Regular penetration testing
- Servers located within Saudi Arabia
5. Data Sharing and Cross-Border Transfer
5.1 Data Sharing
We do not sell or rent your data. We may share data with:
- Your organization/association (for voting purposes only)
- Service providers (hosting, email, SMS) under data protection agreements
- Government authorities by court order
5.2 Cross-Border Data Transfer
6. Your Rights as a Data Subject
Under the Personal Data Protection Law, you have the following rights:
- Right to Know: Know the legal basis for collecting your data and its purpose
- Right of Access: Obtain a copy of your personal data
- Right to Rectification: Request correction or update of your data
- Right to Erasure: Request destruction of your data (subject to legal obligations)
- Right to Withdraw Consent: Withdraw your consent at any time
- Right to Object: Object to processing of your data
- Right to Data Portability: Request transfer of your data to another entity
To exercise any of these rights, contact us at: privacy@edlaabox.com
We will respond to your request within 30 days maximum.
7. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Voting records | 10 years | Governance and audit requirements |
| Meeting minutes | Permanent | Legal obligation |
| Login records | 12 months | Security and audit |
| Contact data | Until membership cancellation + 1 year | Service delivery |
8. Data Breach Notification
In case of a data breach affecting your personal data:
- We will notify SDAIA (Saudi Data & AI Authority) within 72 hours
- We will notify you directly if the breach poses a risk to your rights
- We will explain the nature of the breach and actions taken
9. Cookies
We use only necessary cookies:
- Session Cookies: To maintain your login (essential)
- Security Cookies: To prevent fraud and protect your account (essential)
- Preference Cookies: To save language and settings (functional)
We do not use tracking or advertising cookies.
10. Filing Complaints
If you are not satisfied with how we handle your data, you can:
- Contact us first at: privacy@edlaabox.com
- File a complaint with SDAIA (Saudi Data & AI Authority):
- Website: sdaia.gov.sa
11. Policy Updates
We may update this policy to comply with regulatory changes or our services. We will notify you of any material changes via:
- Notice on the platform
- Email (for material changes)
12. Contact Us
For any inquiries about this policy or to exercise your rights:
- Email: privacy@edlaabox.com
- Address: Kingdom of Saudi Arabia