Governance
Privacy Policy
Version 1.0 · Effective October 2026
Neopillar (the “Company”, “we”) treats data sovereignty as a first principle. This Policy explains how we collect, use, protect and share personal data, and the rights available to you.
It applies to personal data processed through this website and through our institutional communications, and is issued in accordance with the Personal Data Protection Law and its Implementing Regulations. The Company is the controller of the personal data described in it.
Legal basis
- 01The Personal Data Protection Law issued by Royal Decree No. M/19 dated 9/2/1443H, as amended by Royal Decree No. M/148 dated 5/9/1444H
- 02The Implementing Regulation of the Personal Data Protection Law and the Regulation on Personal Data Transfer outside the Kingdom
- 03The controls issued by the National Cybersecurity Authority
Article I
Personal Data We Collect
- 1.1
Contact and correspondence data
Name, title, organisation, email address, telephone number and the content of correspondence, when you contact us.
- 1.2
Engagement data
Information about the representatives of clients, partners, suppliers and government entities with whom we engage.
- 1.3
Technical data
Limited information processed automatically when you visit this website — your language preference and the standard server records needed to deliver and secure it.
- 1.4
Sensitive data
We do not seek sensitive personal data through this website. Please do not send it unless we have requested it.
- 1.5
Cookies
This website uses one strictly necessary cookie to remember your language, your browser's session storage to avoid repeating the opening animation within a visit, and its local storage to keep a record of your data-preference choice so the notice is not shown again. It uses no advertising cookies, cross-site tracking or third-party analytics. Your choice can be reviewed at any time through "Data Preferences" at the foot of every page.
Article II
Purposes & Legal Basis
- 2.1
Purposes
We process personal data only to respond to enquiries and arrange institutional briefings; to evaluate, conclude and perform agreements; to meet our legal obligations; and to secure our systems.
- 2.2
Lawful basis
Processing takes place only where the Personal Data Protection Law permits it: with your consent where consent is required, or where processing is necessary to perform an agreement, to comply with law, or for our legitimate interests where these do not override your rights.
- 2.3
Minimisation
We collect the minimum data necessary for each purpose and use it for no incompatible purpose.
- 2.4
No sale
We do not sell personal data, and we do not use it for advertising or profiling.
Article III
Data Sovereignty & Transfers
- 3.1
Residency
We prioritise the storage and processing of personal data within the Kingdom of Saudi Arabia.
- 3.2
Transfers outside the Kingdom
Where personal data is transferred outside the Kingdom — for example through internationally provided technology services — the transfer takes place only in the cases, and with the safeguards, permitted by the Personal Data Protection Law and the Regulation on Personal Data Transfer outside the Kingdom.
- 3.3
Client data
Data belonging to clients and partners remains their property and is held under the custody, access and residency terms agreed for each engagement.
Article IV
Security of IT & OT Environments
- 4.1
Safeguards
Personal data is protected by organisational, administrative and technical measures proportionate to its sensitivity and aligned with the controls of the National Cybersecurity Authority.
- 4.2
Segregation
Operational-technology environments in industrial engagements are kept separate from corporate information systems, and access between them is controlled and recorded.
- 4.3
Least privilege
Access to personal data is limited to authorised personnel on a need-to-know basis, and every access is attributable.
- 4.4
Processors
Service providers that process data on our behalf do so under written agreements requiring confidentiality, security and compliance with the Personal Data Protection Law.
- 4.5
Breach notification
Where a personal-data breach occurs, we notify the competent authority and affected individuals within the periods required by law.
Article V
Your Rights
- 5.1
To be informed
You have the right to know how and why your personal data is processed.
- 5.2
Access
You may access your personal data and obtain a copy of it in a readable format.
- 5.3
Correction
You may request the correction, completion or updating of your personal data.
- 5.4
Destruction
You may request the destruction of personal data that is no longer required.
- 5.5
Withdrawal of consent
Where processing rests on consent, you may withdraw it at any time.
- 5.6
Exercising your rights
Requests may be sent to info@neopillar.sa and are answered within the periods set by law. You may also lodge a complaint with the Saudi Data and Artificial Intelligence Authority.
Final provisions
- Retention
- Personal data is retained only as long as its purpose requires or as the law demands, and is then securely destroyed or anonymised.
- Changes
- We may update this Policy. The current version is always published on this page with its date.
- Language
- In the event of any inconsistency between the Arabic and English texts, the Arabic text shall prevail.
Questions about this Policy may be addressed to the Company at info@neopillar.sa