Privacy Policy

Last updated: [to be confirmed on legal approval]

Introduction

Rooya is committed to protecting individuals’ privacy and personal data when using its website, mobile applications, and digital services. We ensure that personal data is handled in accordance with applicable data protection laws and regulations.

This Privacy Policy explains how personal data is collected, used, processed, stored, shared, retained, and protected. It also outlines the rights of Data Subjects and how they can exercise those rights.

Rooya is committed to complying with the Saudi Personal Data Protection Law (PDPL), its Implementing Regulations, and other applicable laws and regulations governing personal data processing activities.

1. Scope of the Privacy Policy

This Privacy Policy applies to personal data collected or processed through:

  • Rooya’s website and its available contact forms.
  • Customer inquiries, requests for information, and demonstration requests.
  • Business correspondence and communications with existing and prospective customers.
  • The PolyDrive, PolyFit, and Rooya Drive mobile applications, depending on the functionality and services available within each application.

The legal entity responsible for the website or application acts as a Data Controller when it determines the purposes and means of processing personal data.

Where personal data is processed on behalf of a customer, the relevant entity processes such data in accordance with the Data Controller’s instructions and applicable legal and contractual obligations.

This Privacy Policy does not replace any separate privacy notices or data processing agreements that may apply to fleet management services or vehicle camera systems.

2. Personal Data We Collect

Depending on how you interact with our website or associated applications, we may collect or process certain personal data, including:

2.1 Identification and Contact Information

  • Full name and company or organization name.
  • Industry or business sector.
  • Email address and phone number.
  • City or business location.
  • Information provided through contact forms, inquiries, and demonstration requests.

2.2 Business and Optional Information

  • Fleet size or number of vehicles, where provided.
  • Types of equipment, devices, or software used.
  • Business requirements and preferences related to services and products.
  • Any additional information voluntarily provided by users when communicating with us.

We may also collect certain information related to the use of our website or applications when necessary to operate, improve, and protect our services, in accordance with applicable legal requirements.

We are committed to collecting and processing only the personal data necessary to achieve specific and lawful purposes.

3. Mobile Applications and Digital Services

Rooya provides a range of mobile applications and digital services related to vehicle management, activity tracking, and performance analysis, including:

  • PolyDrive
  • PolyFit
  • Rooya Drive

These applications may collect and process certain personal data necessary to provide their features and services, depending on the nature of each application and the features used by individuals.

Such data may include, where applicable:

  • Account details and user information.
  • Information provided by users during registration or while using the application.
  • Location data associated with activities or routes.
  • Application usage information and interactions with its features.
  • Data necessary to operate the application and improve its performance and security.

This data is processed for purposes related to providing, operating, and improving application functionality, in accordance with the appropriate legal bases and applicable personal data protection requirements.

The scope of personal data processing varies depending on each application’s functionality and the permissions granted to it.

4. Location Data

The PolyDrive and PolyFit applications may collect location data, such as Global Positioning System (GPS) data or information derived from Wi-Fi or cellular networks, depending on the application’s functionality and the device’s settings.

Location data may be used to provide application features, including:

  • Tracking activities and routes.
  • Analyzing trips and distances traveled.
  • Providing performance information and statistics.
  • Improving the accuracy of location-based features and analytics.

Location data is accessed through the permissions and settings provided by the device’s operating system, while taking into account the appropriate legal basis for processing personal data.

Users may manage or revoke location permissions through their device settings. Disabling these permissions may affect certain application features.

5. Mobile Application Permissions (PolyDrive, PolyFit, and Rooya Drive)

When using Rooya’s mobile applications, users may be asked to grant certain permissions to access device features, such as Location Services, depending on the nature of the application and the services available.

These permissions are used to enable application features such as activity tracking, route analysis, and displaying performance-related information, where applicable.

Access to device data is governed by the permissions granted by the user and the settings of the device’s operating system, subject to any additional legal requirements that may apply to the processing.

Users may manage, modify, or revoke application permissions at any time through their device settings. Disabling certain permissions may result in some features becoming unavailable or functioning differently.

Rooya is committed to using data accessed through application permissions only for specified and disclosed purposes, in accordance with applicable personal data protection requirements.

6. Purposes of Personal Data Processing

We may process personal data for the following purposes, depending on the nature of the interaction and the services provided:

  • Responding to inquiries and requests for information.
  • Arranging product demonstrations and discussing services.
  • Communicating with existing and prospective customers.
  • Understanding business requirements and providing relevant service information.
  • Operating the website and applications and maintaining their availability and security.
  • Enabling activity and route tracking features, where applicable.
  • Improving website and application performance and user experience.
  • Protecting systems against unauthorized access and cybersecurity threats.
  • Complying with applicable legal and regulatory obligations.
  • Sending marketing communications where permitted by law and after obtaining consent where required.

Personal data will not be used for purposes incompatible with those for which it was originally collected, except where permitted by applicable laws and regulations.

7. Legal Basis for Processing Personal Data

Personal data is processed based on the appropriate legal grounds under the Saudi Personal Data Protection Law (PDPL), depending on the nature and purpose of the processing activity.

These legal bases may include:

  • Consent: Where the Data Subject’s consent is required by law.
  • Performance of Contractual Obligations: Where processing is necessary to perform a contract to which the Data Subject is a party, subject to applicable legal conditions.
  • Compliance with Legal Obligations: Where processing is necessary to fulfill applicable legal and regulatory requirements.
  • Legitimate Interests: Where permitted by law, subject to the relevant conditions and restrictions.
  • Other Applicable Legal Bases: Any other legal grounds permitted under applicable laws and regulations.

The appropriate legal basis is determined according to the specific purpose and circumstances of each processing activity.

Where consent is required, it will be obtained through an appropriate mechanism, and Data Subjects will be able to withdraw their consent in accordance with applicable legal requirements.

8. Sharing and Disclosure of Personal Data

We may disclose personal data, where necessary and legally permitted, to the following parties:

  • Authorized employees and personnel responsible for providing services or responding to inquiries.
  • Website and application hosting providers and technical infrastructure service providers.
  • Technical support and maintenance service providers.
  • Communication and Customer Relationship Management (CRM) service providers, where applicable.
  • Authorized marketing or analytics service providers, where legally permitted.
  • Professional advisers subject to confidentiality obligations.
  • Competent governmental, regulatory, or judicial authorities where disclosure is required by law.

Rooya does not sell personal data to third parties.

We also implement appropriate contractual, organizational, and security measures to ensure the protection of personal data when it is shared or disclosed.

9. Data Storage and International Transfers

Personal data is stored and processed in accordance with applicable personal data protection requirements.

Where personal data is stored, transferred, disclosed, or made accessible from outside the Kingdom of Saudi Arabia, the relevant processing activities are reviewed in accordance with the Personal Data Protection Law and its Implementing Regulations, including the provisions governing international transfers of personal data.

Appropriate technical, organizational, and contractual safeguards are implemented where required by law.

Hosting locations and service providers are determined based on the actual technical and contractual arrangements.

10. Personal Data Security

Rooya implements appropriate technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction.

These measures may include:

  • The use of secure communication protocols.
  • Encryption of data where necessary, depending on its nature.
  • Restricting data access to authorized personnel.
  • Implementing authentication and account protection controls.
  • Security activity logging and monitoring.
  • Compliance with confidentiality and data protection requirements.

Security measures are reviewed in accordance with applicable operational and regulatory requirements.

11. Personal Data Retention

Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected or processed, subject to applicable legal, regulatory, and contractual obligations.

Retention periods may vary depending on the nature of the data and the purpose of its use, including:

  • Contact and inquiry information.
  • Business correspondence.
  • Application account information.
  • Location data associated with application features.
  • Technical and usage logs.
  • Marketing communication preferences.

When there is no longer a lawful basis for retaining personal data, it will be securely deleted, destroyed, or anonymized, as appropriate.

12. Data Subject Rights

In accordance with the requirements and exceptions provided under the Saudi Personal Data Protection Law (PDPL), individuals have the following rights:

12.1 Right to Be Informed

Data Subjects have the right to be informed about how their personal data is collected and processed and the purposes for which it is used.

12.2 Right of Access

Data Subjects have the right to request access to their personal data in accordance with applicable legal requirements.

12.3 Right to Obtain Personal Data

Data Subjects have the right to request a copy of their personal data in a clear and readable format.

12.4 Right to Rectification

Data Subjects have the right to request the correction, completion, or updating of their personal data.

12.5 Right to Destruction

Data Subjects have the right to request the destruction of their personal data where the relevant legal conditions are satisfied.

12.6 Right to Withdraw Consent

Data Subjects have the right to withdraw their consent to the processing of personal data where consent is the legal basis for processing, in accordance with applicable legal requirements.

12.7 How to Exercise Your Rights

Requests to exercise personal data rights may be submitted through the contact channels specified in this Privacy Policy.

We may request information necessary to verify the identity of the requester before taking the required action.

Requests will be handled within the timeframes prescribed by applicable laws and regulations.

Data Subjects also have the right to lodge a complaint with the competent personal data protection authority in accordance with applicable legal procedures.

13. Cookies and Tracking Technologies

Rooya’s website may use cookies or similar technologies to support website functionality, improve performance, and enhance user experience.

The use of these technologies depends on the features and services actually implemented on the website.

Where user consent is legally required for the use of cookies or tracking technologies, such consent will be obtained in accordance with applicable legal requirements.

Users may manage or disable cookies through their browser settings. However, disabling certain cookies may affect website functionality.

14. Marketing Communications

Rooya may use contact information to send communications regarding products, services, events, and relevant updates, to the extent permitted by applicable laws and regulations.

Where consent is required for marketing communications, it will be obtained before such communications are sent.

Users may withdraw their consent or unsubscribe from marketing communications through the available options or by contacting us.

15. Third-Party Websites and Services

Rooya’s website or applications may contain links to websites or services provided by third parties.

These websites and services may be subject to their own privacy policies and personal data protection practices.

We encourage users to review the privacy policies of these third parties before providing them with any personal data.

16. Changes to This Privacy Policy

Rooya may periodically review and update this Privacy Policy to reflect changes to its website, applications, personal data processing activities, or applicable legal and regulatory requirements.

Updated versions will be published through the relevant official channels, with the new effective date clearly indicated.

Where additional notification or consent is required by law, the necessary measures will be taken.

17. Contact Us

For privacy-related inquiries, complaints, or requests to exercise personal data rights, please contact us through the following channels:

Privacy Email: speakup@rooya.ai

General Inquiries: info@rooya.ai

Address: Al Olaya District, Al Olaya Street, Building No. 7087, Secondary No. 2427, Postal Code 12244, Riyadh, Kingdom of Saudi Arabia.

All privacy-related inquiries, complaints, and requests will be handled in accordance with applicable legal and regulatory requirements.

Clearer fleet visibility. Safer decisions.

Talk to the Rooya team to explore how we can help you improve fleet safety and make clearer operational decisions.

No commitment. We’ll be in touch within one business day.