Privacy & data protection

Privacy policy

In plain words: what we collect about you, why, who we share it with, and how to exercise your rights under the Saudi Personal Data Protection Law (PDPL).

Version 3.2Effective 1 September 2026Last updated 18 August 2026

We never sell your data

Your data is never used for third-party advertising.

Hosted in the Kingdom

Data is stored in data centres inside Saudi Arabia.

You're in control

Download, correct or request deletion from your settings.

Kept only as needed

A defined retention period for every data type.

01

Who we are

In short: The Mining Association is the controller of your data on this platform.

The Mining Association (a non-profit professional body, Riyadh) operates the membership, credentials and CPD platform and is the “controller” as defined by the Personal Data Protection Law issued by Royal Decree M/19 and its implementing regulations.

We have appointed a data protection officer you can reach directly at dpo@sma.org.sa or through the contact form.

02

Data we collect

In short: Identity, contact, qualifications and payment data — only what the service needs.

CategoryExamplesSource
IdentityName, national ID / Iqama, date of birth, nationalityYou or Nafath
ContactMobile, email, national addressYou
ProfessionalQualifications, experience, employer, supporting documentsYou and verifiers
CPDActivities, certificates, approved hoursYou and training providers
FinancialInvoices, receipts, last 4 card digitsPayment gateway
TechnicalSign-in logs, device type, approximate IPAutomatically

We never store your full card details; they are processed by a SAMA-licensed, PCI DSS compliant gateway.

03

Why we use your data

In short: To deliver membership, credentials and CPD, and meet our legal duties.

PurposeLegal basis
Reviewing applications and issuing your cardPerformance of our agreement
Public verification of memberships and certificatesLegitimate interest and your listing consent
Billing, receipts and refundsLegal obligation (ZATCA)
Renewal and CPD remindersPerformance of our agreement
Newsletter and eventsYour consent — withdraw any time
Platform security and fraud preventionLegitimate interest

04

Who we share it with

In short: Only with contracted processors, and only as much as needed.

  • Nafath national SSO — to verify your identity when you choose to sign in with it.
  • Licensed payment gateway — to process payments and refunds.
  • SMS, email and WhatsApp providers — to send verification codes and notifications.
  • Partner learning platforms (e.g. Coursera, Udemy) — when you link your account to import CPD hours.
  • Government authorities — only under a binding legal request.

05

Transfers outside the Kingdom

The platform and its databases are hosted in the Kingdom. Where limited data must leave it (such as international learning services you link yourself), it happens only under the controls approved by SDAIA and with appropriate safeguards.

06

How long we keep it

In short: Each data type has a set period, then it is deleted or anonymised automatically.

Data typePeriod
Unsubmitted drafts180 days after last edit
Interest registrations2 years or until you unsubscribe
Membership file and documentsMembership term + 5 years
Financial records10 years (legal requirement)
Audit and security logs5 years

07

Your rights

In short: You can exercise most rights yourself from account settings in minutes.

  • Right to be informed: what we collect and why (this document).
  • Right of access: download a copy of your data, machine-readable and as PDF.
  • Right to correction: edit your data or request correction of verified fields.
  • Right to destruction: request account deletion, with what must legally be retained explained.
  • Right to withdraw consent: stop marketing or directory listing at any time.

We handle requests within 30 days at most and confirm the outcome in writing. You may complain to SDAIA if you are not satisfied with our response.

08

How we protect it

  • Encryption in transit (TLS 1.2+) and at rest.
  • Mandatory MFA for staff, and step-up verification for sensitive actions.
  • Role-based access and a tamper-evident audit log of every view and change.
  • Alignment with the NCA Essential Cybersecurity Controls.

09

Cookies

We use strictly necessary cookies for your session and language/theme preferences, plus anonymised analytics that only run with your consent.

10

Changes to this policy

We will tell you about any material change by email and notification 30 days before it takes effect, and record your acceptance of each version (version, date, channel) in the consent ledger.

Questions about this document?

Our data protection officer replies within 5 working days.