01
Who we are
In short: The Mining Association is the controller of your data on this platform.
The Mining Association (a non-profit professional body, Riyadh) operates the membership, credentials and CPD platform and is the “controller” as defined by the Personal Data Protection Law issued by Royal Decree M/19 and its implementing regulations.
We have appointed a data protection officer you can reach directly at dpo@sma.org.sa or through the contact form.
02
Data we collect
In short: Identity, contact, qualifications and payment data — only what the service needs.
| Category | Examples | Source |
|---|---|---|
| Identity | Name, national ID / Iqama, date of birth, nationality | You or Nafath |
| Contact | Mobile, email, national address | You |
| Professional | Qualifications, experience, employer, supporting documents | You and verifiers |
| CPD | Activities, certificates, approved hours | You and training providers |
| Financial | Invoices, receipts, last 4 card digits | Payment gateway |
| Technical | Sign-in logs, device type, approximate IP | Automatically |
We never store your full card details; they are processed by a SAMA-licensed, PCI DSS compliant gateway.
03
Why we use your data
In short: To deliver membership, credentials and CPD, and meet our legal duties.
| Purpose | Legal basis |
|---|---|
| Reviewing applications and issuing your card | Performance of our agreement |
| Public verification of memberships and certificates | Legitimate interest and your listing consent |
| Billing, receipts and refunds | Legal obligation (ZATCA) |
| Renewal and CPD reminders | Performance of our agreement |
| Newsletter and events | Your consent — withdraw any time |
| Platform security and fraud prevention | Legitimate interest |
05
Transfers outside the Kingdom
The platform and its databases are hosted in the Kingdom. Where limited data must leave it (such as international learning services you link yourself), it happens only under the controls approved by SDAIA and with appropriate safeguards.
06
How long we keep it
In short: Each data type has a set period, then it is deleted or anonymised automatically.
| Data type | Period |
|---|---|
| Unsubmitted drafts | 180 days after last edit |
| Interest registrations | 2 years or until you unsubscribe |
| Membership file and documents | Membership term + 5 years |
| Financial records | 10 years (legal requirement) |
| Audit and security logs | 5 years |
07
Your rights
In short: You can exercise most rights yourself from account settings in minutes.
- Right to be informed: what we collect and why (this document).
- Right of access: download a copy of your data, machine-readable and as PDF.
- Right to correction: edit your data or request correction of verified fields.
- Right to destruction: request account deletion, with what must legally be retained explained.
- Right to withdraw consent: stop marketing or directory listing at any time.
We handle requests within 30 days at most and confirm the outcome in writing. You may complain to SDAIA if you are not satisfied with our response.
08
How we protect it
- Encryption in transit (TLS 1.2+) and at rest.
- Mandatory MFA for staff, and step-up verification for sensitive actions.
- Role-based access and a tamper-evident audit log of every view and change.
- Alignment with the NCA Essential Cybersecurity Controls.
10
Changes to this policy
We will tell you about any material change by email and notification 30 days before it takes effect, and record your acceptance of each version (version, date, channel) in the consent ledger.
Questions about this document?
Our data protection officer replies within 5 working days.