Last updated: 1 September 2026
At Rooya, protecting personal data is an important part of how we design and operate our AI video telematics platform.
This notice explains how the Saudi Personal Data Protection Law (PDPL) applies to drivers whose vehicles use Rooya technology, what personal data may be processed, why it is processed, and the rights available to drivers.
This notice should be read together with any privacy notice or monitoring policy provided by your employer or fleet operator.
The Personal Data Protection Law (PDPL) is Saudi Arabia’s national law governing the collection, use, storage, disclosure and protection of personal data.
Personal data is information that identifies you directly or indirectly. This can include your name and contact information, as well as images, video footage and information connected to your driving activity.
The PDPL is overseen by the Saudi Data and Artificial Intelligence Authority (SDAIA).
Under the PDPL, organisations handling personal data must follow requirements including:
If you drive a vehicle equipped with Rooya technology, certain information generated through the system may constitute personal data when it identifies you or can reasonably be linked to you.
Depending on the configuration selected by your employer or fleet operator, this may include:
Driver personal data may be collected automatically through Rooya technology installed in or connected to the vehicle, including cameras, GPS functionality, vehicle sensors, telematics devices and system-generated safety events.
Certain driver identification or account information may also be provided by your employer or fleet operator, depending on the configuration of the service.
The specific categories and methods of collection depend on the features enabled by your employer or fleet operator.
Your employer or fleet operator should inform you about the monitoring deployed in your vehicle and the purposes for which your personal data is processed.
Driver data processed through the Rooya platform is used for the purposes below. Each purpose is processed on the legal basis indicated, in accordance with the PDPL.
| Purpose | Legal Basis |
|---|---|
| Improving road and driver safety | Legitimate interest of the employer/fleet operator (Controller), where applicable, or consent |
| Identifying and reviewing safety-related driving events | Legitimate interest of the Controller, or consent |
| Supporting driver coaching and safety programmes | Legitimate interest of the Controller, or consent |
| Understanding driving behaviour and safety trends | Legitimate interest of the Controller, or consent |
| Reviewing incidents and providing supporting evidence | Legitimate interest of the Controller, and/or performance of a legal obligation |
| Supporting fleet safety and operational management | Legitimate interest of the Controller |
| Meeting applicable legal, regulatory or contractual requirements | Compliance with a legal obligation |
Where your employer or fleet operator relies on consent as the legal basis for any of the above, you have the right to withdraw that consent at any time — see Section 7. Where a different legal basis applies, withdrawal of consent will not affect processing carried out under that other basis.
Your employer or fleet operator, as Data Controller, is responsible for determining and documenting the specific legal basis relied upon for each purpose in your jurisdiction and employment context. This notice describes the bases typically relied upon but does not itself constitute your employer’s basis determination.
Where the Controller relies on legitimate interests as a lawful basis, the Controller is responsible for ensuring that the requirements of the PDPL are satisfied, including assessing and documenting the legitimacy, necessity and proportionality of the processing and considering the rights and interests of the data subject.
For driver and fleet data, your employer or fleet operator will generally determine the purposes and means of processing and may therefore act as the Data Controller under the PDPL.
Rooya generally processes this information on behalf of the relevant customer in providing its technology and services and may therefore act as a Data Processor.
The exact roles may depend on the specific service and circumstances.
For personal data collected directly by Rooya for its own purposes, such as information submitted through the Rooya website or certain business enquiries, Rooya may act as the Data Controller.
Personal data is retained according to applicable retention requirements and the arrangements between Rooya and the relevant customer.
Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected and processed, in accordance with the Personal Data Protection Law (PDPL), applicable legal and regulatory requirements, the instructions of the relevant Data Controller, and Rooya’s approved retention policies and procedures.
Retention periods may vary depending on the type of data, the purpose of processing, the applicable legal or contractual requirements, and the configuration of the Rooya service.
The current retention periods include:
The above retention periods are subject to review and may be adjusted where required by applicable law, regulatory requirements, contractual obligations, or the instructions of the relevant Data Controller.
Where personal data is no longer required, it will be securely deleted or destroyed using appropriate technical and organisational measures designed to prevent its recovery, reconstruction, or unauthorised use. Where appropriate and legally permitted, data may instead be anonymised in a manner that prevents individuals from being identified or re-identified.
Certain information may be retained for longer where required by law, regulatory obligations, audit or investigation requirements, an active insurance claim, legal dispute, or other applicable legal or contractual requirement.
Personal data relating to Rooya’s Saudi customers is hosted within the Kingdom of Saudi Arabia.
Rooya uses authorised infrastructure and service providers to support the delivery of its services.
Where personal data is disclosed to or processed by third parties, appropriate contractual, technical and organisational safeguards are applied in accordance with applicable requirements.
Subject to the conditions, limitations and exceptions provided under the PDPL and its Implementing Regulations, you have the following rights in relation to your personal data:
These rights are subject to the conditions, limitations and exceptions provided under applicable law.
If your personal data is processed through Rooya because you drive a vehicle operated by one of our customers, we recommend first contacting your employer or fleet administrator.
As the organisation responsible for the fleet programme, they can identify your records and coordinate with Rooya where required.
You may also contact Rooya regarding privacy questions or requests using the contact details below:
To protect personal data and prevent unauthorised disclosure, Rooya or the relevant Data Controller may request information reasonably necessary to verify the identity of the individual submitting a request before processing the request.
Requests relating to rights under the PDPL will be handled within the applicable legal timeframe. Requests will generally be handled within 30 days, and this period may be extended where permitted under the PDPL and its Implementing Regulations.
Rooya applies technical, organisational and administrative measures designed to protect personal data against unauthorised access, disclosure, alteration, loss or misuse.
Access to personal data is restricted according to operational requirements and authorised access controls.
Rooya also maintains internal processes for privacy management, security and incident response.
Rooya may use authorised service providers and sub-processors to support the operation, security and delivery of its services.
Where these parties process personal data, they are required to do so only for authorised purposes and in accordance with applicable contractual, technical and organisational safeguards under the PDPL.
Personal data may also be disclosed to competent regulatory, judicial or law-enforcement authorities where required or permitted by applicable law.
If you have questions about how your personal data is processed through the Rooya platform, you can contact your employer or fleet administrator or contact Rooya at info@rooya.ai.
If you believe that your rights under the PDPL have not been respected or your complaint has not been appropriately addressed, you may submit a complaint to the Saudi Data and Artificial Intelligence Authority (SDAIA) through the National Data Governance Platform, subject to the applicable legal requirements and complaint procedures.
Rooya may update this notice from time to time to reflect changes to its services, processing activities, or applicable legal and regulatory requirements.
The latest version will be published on this page together with the date it was last updated.
Talk to the Rooya team about your fleet, your risk profile and the insight you need to make safer, smarter decisions.
No commitment. We’ll be in touch within one business day.