Policies
King Faisal University (KFU) is an integrated educational, research, and service-oriented institution established pursuant to Royal Decree No. (H/67) dated 28 Rajab 1395 AH. The University seeks to act as a development driver and a key knowledge partner
in supporting vital sectors locally and regionally by providing future-enabling education, research that stimulates development and change, community partnerships that achieve mutual enrichment, and sustainable business development. KFU is committed
to protecting beneficiaries' data when they access its electronic services and systems and to safeguarding their privacy through the application of the necessary administrative controls and technical measures, in accordance with the relevant laws,
regulations, decisions, and policies. This Privacy Policy has been developed to help beneficiaries understand the nature and types of data collected through the University's various channels, the purposes for which such data is collected and processed,
and how it is protected. Use of KFU's services constitutes acknowledgment by the data subject that they have reviewed and agreed to the provisions of this Privacy Policy and any subsequent amendments thereto. KFU therefore encourages beneficiaries of its
services to review the Privacy Policy periodically to stay informed of any updates through the Data Management and Decision Support Office page on the University's website. The University also seeks to improve the quality of its operations and to notify
beneficiaries by email of any updates made to its policies.
Contact Information - Data Management and Decision Support Office Address:
Al-Ahsa Governorate, Eastern Province - P.O. Box: 400, Postal Code: 31982 - Phone: 0135896729 - Email: dmo@kfu.edu.sa
What Personal Data Is Collected?
KFU collects only the minimum amount of beneficiaries' personal data necessary to fulfill the purposes for which it is collected. Personal data includes the following categories:
Basic Personal Data:
This includes information such as name, gender, national identification number, nationality, marital status, and other identifying information that the University may require.
Contact Data:
This includes information such as telephone numbers, email addresses, and postal addresses.
Account Data:
This includes login credentials for accounts on the University's platforms and applications, such as usernames and passwords.
Technical Data:
This includes, but is not limited to, Internet Protocol (IP) address information, login data, browser type and version, time zone and location settings, browser plug-in types and versions, and information collected through cookies.
Financial Data:
This includes information collected for payment processing purposes, such as account numbers and credit card details.
How Is Your Personal Data Collected and What Is the Purpose of Collection?
Some of the personal data processed by the University is obtained directly from beneficiaries through the following:
Services:
When registering through electronic platforms or various services.
Communication:
When communicating with the University through its communication channels.
Surveys.
Electronic registration forms.
We also obtain certain personal data indirectly from the following sources:
Data provided to us by other entities, such as government and private entities that provide or support services for beneficiary groups.
Technical data recorded automatically when you visit the University's website, including Internet Protocol (IP) address information, login data, browser type and version, time zone and location settings, browser plug-in types and versions, and information collected through cookies.
Circumstances stipulated in Article 10 of the Personal Data Protection Law and its Implementing Regulations.
How Do We Use Your Personal Data?
We use personal data collected directly or indirectly as follows:
- Completing the information required to provide services.
- Enabling beneficiaries to access services and conduct transactions.
- Resolving and addressing inquiries or complaints and improving the beneficiary experience across all communication channels.
- Collecting and processing personal data to meet legal and regulatory requirements.
- Providing analyses and statistics to decision-makers.
- Sending awareness messages or messages related to the services provided to you.
- Conducting studies that serve the University.
How Do We Disclose Your Personal Data?
In accordance with the University's Data Sharing Policy, we may share necessary personal data with government entities or non-government entities authorized to perform government services for specific purposes based on lawful grounds or a justified operational need
intended to serve the public interest, without causing any harm to national interests or individuals' privacy. When sharing personal data, the University ensures compliance with the relevant laws, regulations, and policies. Such data is shared through a secure and
trusted environment. The University also takes additional steps to protect personal data by entering into data-sharing agreements containing specific terms and conditions consistent with the principles governing data sharing and exchange.
Legal Bases for Collecting and Processing Your Personal Data
In accordance with the Personal Data Protection Law, the legal bases on which we rely to process such data are as follows:
- The explicit consent of the personal data subject, which the beneficiary may withdraw at any time.
- Data processing is a condition for providing a service or benefit and is directly related to a relationship connected with the processing of personal data.
- Compliance with legal obligations, such as compliance with applicable laws and regulations.
- Circumstances stipulated in Article 10 of the Personal Data Protection Law and its Implementing Regulations.
- Circumstances stipulated in Article 27 of the Personal Data Protection Law and its Implementing Regulations.
How Do We Store Your Data?
Personal data is stored within the Kingdom of Saudi Arabia on the University's servers at its main campus or in a cloud environment hosted at one of the data centers in the Kingdom owned by a cloud service provider approved by the Saudi Data and
Artificial Intelligence Authority. Relevant security standards and best practices are applied to ensure the security and protection of the data. Data is retained for the periods necessary to fulfill the University's regulatory obligations and until the purpose for which
it was processed has been fulfilled. Thereafter, it is securely destroyed in a manner that prevents the data from being accessed or recovered again, in accordance with the provisions of Article 18 of the Personal Data Protection Law.
Your Rights in Relation to the Processing of Your Personal Data
Under the Personal Data Protection Law, you have the following rights:
Right to Be Informed: To know how your data is collected, the legal basis for its processing, and the purpose of such processing.
Right of Access: To request access to your personal data held by the University.
Right to Obtain Your Personal Data: To obtain your personal data in a readable and clear format whenever technically feasible.
Right to Rectification: To have your personal data corrected if it is inaccurate or incomplete.
Right to Destruction of Personal Data: To have your personal data destroyed once the purpose for which it was collected has ended, unless a lawful basis exists for retaining it.
Right to Withdraw Consent: To withdraw consent to the processing of your personal data unless otherwise required by applicable laws.
How Can You Submit a Complaint or Objection?
If you have concerns or believe there has been non-compliance with the Personal Data Protection Law, you may submit a complaint to the Data Management and Decision Support Office at King Faisal University using the contact channels provided above. You may also submit a complaint to the National Data Management
Office if you are dissatisfied with how your personal data has been used or if your complaint has not been addressed within 30 days.
Data Management Office AddressKingdom of Saudi Arabia - Riyadh
https://sdaia.gov.sa/ndmo
Data Collection and Use
-
The application uses Apple Pay as a payment method for settling outstanding invoices.
-
The application does not collect, store, or process any payment card information, such as the card number, expiration date, or security code.
-
All Apple Pay transactions are processed securely through Apple's systems only.
Data Received by the Application
-
The application receives only a notification indicating whether the payment transaction was successful or unsuccessful, without access to any sensitive financial data.
Data Sharing
-
No payment data is shared with any third party.
Amendments
-
This Privacy Policy may be updated from time to time, and any updates will be published on this page.