1. Introduction
This Privacy Policy explains how Sahlix ("we", "us", "our") collects, uses, stores, and shares personal data when you use our booking platform, mobile and web applications, and related services (the Services).
Sahlix is a company operating in the Kingdom of Saudi Arabia. All data processing is conducted in accordance with the Personal Data Protection Law (PDPL) issued by Royal Decree No. M/19 and its implementing regulations.
By using the Services, you acknowledge that you have read and understood this Policy.
2. Definitions
- Sahlix Platform — the booking and business management system operated by Sahlix, accessible via web and mobile applications.
- Service Provider / Business — any company or individual that subscribes to Sahlix to manage their bookings and operations.
- End Customer — a person who books a service through a Service Provider's booking interface powered by Sahlix.
- Employee / Practitioner — a staff member whose data is entered into the platform by a Service Provider.
- User — any person interacting with the Sahlix platform in any capacity.
- Personal data — any information relating to an identified or identifiable natural person.
- Processing — any operation performed on personal data, whether automated or not.
- PDPL — the Personal Data Protection Law of the Kingdom of Saudi Arabia.
3. Our role in data processing
Sahlix acts in two distinct roles depending on the type of data:
- Data Controller — for data related to Service Provider accounts, billing, and platform usage. We determine the purposes and means of processing this data.
- Data Processor — for End Customer data collected through a Service Provider's booking interface. In this case, the Service Provider is the Data Controller and Sahlix processes the data on their behalf.
Service Providers are responsible for ensuring they have the appropriate legal basis to collect and share their customers' data with Sahlix.
4. Data we collect
Service Provider data
- Identity and contact information: name, phone number, email address, national ID or commercial registration number.
- Business information: branch details, service listings, pricing, working hours.
- Financial data: bank account details and billing records for subscription payments.
- Employee records: names, roles, and working hours of staff entered by the Service Provider.
End Customer data
- Name and contact details: phone number, and optionally email address.
- Booking information: services selected, specialist chosen, date, time, and price.
- Payment records: transaction references. Sensitive card data is processed directly by the payment provider, not by Sahlix.
- Loyalty and subscription data where applicable.
Technical data (all users)
- IP address, device type, browser, and operating system.
- Session logs and access timestamps.
- Cookies and similar identifiers (see Section 10).
5. How we use your data
- Service delivery — to operate the platform, process bookings, and provide customer support.
- Account management — to create and manage Service Provider accounts and subscriptions.
- Communications — to send booking confirmations, reminders, and service updates.
- Platform improvement — to analyse usage patterns and improve features.
- Legal compliance — to meet obligations under Saudi law, including tax and accounting requirements.
- Fraud prevention and security — to protect the platform and its users.
We obtain explicit consent where required by the PDPL before processing data for purposes beyond service delivery.
6. Data sharing
We do not sell or lease personal data. We share data only in the following limited circumstances:
- Within Sahlix — limited to employees who require access to perform their work.
- Payment providers — to process subscription and booking payments securely.
- Cloud infrastructure providers — to host and operate the platform, under data processing agreements.
- Messaging and notification services — such as SMS and WhatsApp gateways, to deliver booking confirmations and reminders.
- Legal authorities — when required by Saudi law or a valid legal order.
All third-party service providers are bound by confidentiality obligations and may only use the data for the purpose for which it was shared.
7. Data retention
| Category | Retention period |
|---|---|
| Service Provider account data | For the lifetime of the account, then 12 months after closure. |
| End Customer booking records | 3 years from the booking date. |
| Billing & invoicing data | 10 years (statutory accounting requirement under Saudi law). |
| Technical and access logs | 90 days. |
| Marketing consents | Until consent is withdrawn, plus 2 years for evidentiary purposes. |
After these periods, data is securely deleted or anonymised.
8. Your rights under the PDPL
Under the Personal Data Protection Law of the Kingdom of Saudi Arabia, you have the following rights:
- Right to be informed — to know the legal basis and purpose for which your data is processed.
- Right of access — to request access to your personal data and obtain a copy.
- Right to correction — to request correction or completion of inaccurate or incomplete data.
- Right to erasure — to request deletion of your data when processing is no longer necessary or lawful.
- Right to withdraw consent — to withdraw your consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at contact@sahlix.io with the subject line "PDPL Request". We will respond within 30 calendar days.
If you believe your rights have not been respected, you may file a complaint with the National Data Management Office (NDMO) in Saudi Arabia.
9. Cross-border data transfers
Where data is transferred outside the Kingdom of Saudi Arabia — for example, to cloud infrastructure or service providers — we apply the following safeguards in accordance with Article 29 of the PDPL:
- Transfers are made only to countries or recipients that provide an adequate level of protection, or
- Under contractual safeguards including KSA Standard Contractual Clauses, or
- With the explicit consent of the data subject.
We do not transfer personal data outside the Kingdom for commercial purposes beyond those necessary for service delivery.
10. Cookies
We use cookies and similar technologies for the following purposes:
- Strictly necessary cookies — for authentication, session continuity, and security. These cannot be disabled.
- Functional cookies — to remember language preferences and interface settings.
- Analytics cookies — to measure aggregate usage and improve the platform. These are only set with your consent.
You can manage your cookie preferences through your browser settings or via the banner displayed on your first visit.
11. Security
We apply technical and organisational security measures to protect personal data, including:
- Encryption of data in transit (TLS 1.3) and at rest.
- Role-based access control — only authorised personnel can access data.
- Audit logging and regular vulnerability assessments.
- A documented incident response procedure.
While we take all reasonable precautions, no system can be guaranteed 100% secure. We encourage users to use strong passwords and keep their credentials confidential. In the event of a data breach affecting your rights, we will notify the relevant authority and affected users as required by the PDPL.
12. Contact
For any questions about this Policy or to exercise your rights:
This Policy may be updated from time to time. Material changes will be communicated through the Services or by email.
