This Privacy Policy explains how Cybersee collects, uses and protects personal data in line with the Saudi Personal Data Protection Law. It is written to be clear: if anything is unclear, please ask us.
1. Who we are
This policy is issued by Smart Surveillance for Cybersecurity Company (شركة الرقابة الذكية للأمن السيبراني), trading as Cybersee, Commercial Registration No. 1009081639, Riyadh, Kingdom of Saudi Arabia ("Cybersee", "we", "us"). We are the controller of the personal data described here under the Personal Data Protection Law (PDPL) issued by Royal Decree No. M/19 and its Implementing Regulations.
Questions about this policy or your personal data can be sent to our privacy team at info@cybersee.sa, or by post to Riyadh, Kingdom of Saudi Arabia.
2. What this policy covers
This policy explains how we collect, use, store, share and protect personal data when you visit cybersee.io, use Cybersee Labs (our free Dark Web Report and Attack Surface Scan), contact us, or use the Cybersee platform and related services (together, the "Services").
We may provide additional notices for specific activities, such as support requests or events. Those notices work together with this policy.
3. Personal data we collect
- Account details: name, work email, company name, job title and, for paid subscriptions, billing details.
- Cybersee Labs scans: the domain you scan and the work email you provide to view the results.
- Enquiries and forms: contact details and the content of your message when you book a demo, request a datasheet, apply to partner or contact us.
- Platform activity: searches, alert settings, monitored assets and dashboard activity.
- Technical data: IP address, browser, device and operating system, and pages visited, collected through server logs and, where you consent, cookies.
- Threat intelligence: data from dark web, deep web and surface web sources, such as leaked credentials, stealer logs and card BIN data, which may include personal data exposed by third parties. We process it only to protect our customers and do not link it to individuals except where needed to deliver alerts for monitored assets.
We do not intentionally collect sensitive personal data such as health, genetic, religious or criminal data. Where sensitive data appears in threat intelligence we receive, we restrict access to it and process it only as necessary for security purposes.
4. How we collect it
- Directly from you, when you sign up, run a scan, submit a form or contact us.
- Automatically, through server logs and, with your consent where required, cookies. See our Cookie Policy.
- From third parties, such as payment processors, analytics providers and public sources like company registries, and from threat intelligence sources as described above.
5. Why we use it and our legal basis
| Purpose | Legal basis under the PDPL |
|---|---|
| Providing the Services, reports and scan results | Performance of a contract with you, or steps you request before entering one |
| Account, subscription and billing management | Performance of a contract; legal obligation for tax and accounting records |
| Responding to enquiries, demo and datasheet requests | Your consent, or steps you request before entering a contract |
| Security, fraud prevention and protecting the Services | Legitimate interest, where it does not override your rights and does not involve sensitive data |
| Improving the Services using aggregated statistics | Legitimate interest |
| Marketing emails about our services | Your consent, which you can withdraw at any time |
| Complying with laws and requests from competent authorities | Legal obligation |
We collect only the personal data needed for these purposes. If we want to use it for a new purpose, we will tell you first and, where required, ask for your consent.
6. Marketing
We send marketing messages only with your consent. You can withdraw consent at any time using the unsubscribe link in any email or by writing to info@cybersee.sa. Withdrawing consent does not affect service messages such as security notices or billing emails. We never share your personal data with third parties for their own marketing.
9. Where your data is stored
Personal data and customer data are hosted and processed on infrastructure located inside the Kingdom of Saudi Arabia.
We do not transfer personal data outside the Kingdom except where permitted under Article 29 of the PDPL and the Regulations on Personal Data Transfer outside the Kingdom, limited to the minimum necessary and with appropriate safeguards. If this changes, we will update this policy.
10. How long we keep it
| Data | Retention |
|---|---|
| Account and contract data | For the duration of the contract and afterwards for the period required by Saudi law |
| Enquiries, demo and datasheet requests | Up to 24 months after our last contact, unless you become a customer |
| Cybersee Labs scan requests | Up to 12 months |
| Server and security logs | Up to 12 months |
| Marketing preferences | Until you withdraw consent |
When data is no longer needed we securely destroy or anonymise it. We may keep data longer where required by law or to resolve a dispute.
11. How we protect it
We use technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls based on least privilege, logging and monitoring, and staff confidentiality obligations. No system is completely secure, so please keep your account credentials private and tell us immediately at info@cybersee.sa if you suspect unauthorised access.
If a personal data breach occurs, we will notify the Saudi Data and Artificial Intelligence Authority (SDAIA) within 72 hours of becoming aware of it where required, and inform affected individuals without undue delay where the breach may harm them.
12. Your rights
Under the PDPL you have the right to:
- be informed about how and why your personal data is processed;
- access your personal data and obtain a copy in a clear, readable format;
- request correction, completion or updating of your personal data;
- request destruction of your personal data when it is no longer needed, unless the law requires us to keep it;
- withdraw your consent at any time, where processing is based on consent.
To exercise a right, write to info@cybersee.sa. We may need to verify your identity. We respond within 30 days; if a request is complex we may extend this by up to 30 more days and will tell you why before the first period ends. Requests are free of charge.
13. Complaints
If you are not satisfied with how we handle your personal data, please contact us first at info@cybersee.sa so we can try to resolve it. You also have the right to file a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA) within 90 days of the incident or of becoming aware of it.
14. Children
Our Services are intended for businesses and are not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
15. Links to other websites
Our website may link to websites we do not control. Their privacy practices are their own, so please review their policies before sharing personal data with them.
16. Changes to this policy
We may update this policy to reflect changes in our Services or in the law. We will post the new version here with a new "Last updated" date and, for significant changes, notify you by email or through the Services.
17. Contact us
Smart Surveillance for Cybersecurity Company (شركة الرقابة الذكية للأمن السيبراني), trading as Cybersee, Commercial Registration No. 1009081639, Riyadh, Kingdom of Saudi Arabia.
Email: info@cybersee.sa
Address: Riyadh, Kingdom of Saudi Arabia