Wafra Logo

WAFRA — PRIVACY POLICY

Version 1.2 · Effective August 1, 2026

App: Wafra Wealth

Developer: شركة منجم الآعمال للتطوير والاستثمار التجاري

About This Policy

Wafrat Alnamae Company, a company registered in the Kingdom of Saudi Arabia under Unified Number 7051717721, with its registered address in Al Malqa District, Imam Saud ibn Faisal Road, Riyadh, Kingdom of Saudi Arabia ("Wafra", "we", "us" or "our"), is the controller of the personal data described in this Policy unless a separate notice states otherwise.

Wafra operates a digital wealth platform that enables users to aggregate and view assets and liabilities, monitor net worth, and use financial tools and related services. In this Policy, the platform, websites, mobile applications, and related services are together called the "Services".

This Policy should be read with any product-specific or just-in-time privacy notice shown when personal data is collected. Where a bank, broker, custodian, open-banking provider, government service, or other third party determines its own purposes and means of processing, that party acts under its own privacy notice.

We process personal data in accordance with the Saudi Personal Data Protection Law (PDPL), its Implementing Regulation, the Regulation on Personal Data Transfer Outside the Kingdom, and other laws and binding regulatory requirements that apply to our activities. The Saudi Data & AI Authority (SDAIA) is the competent data-protection authority. References to sector regulators, including the Saudi Central Bank or the Capital Market Authority, apply only where the relevant regulator has jurisdiction over a particular service or activity.

Scope

This Policy applies to personal data relating to users, prospective users, website and application visitors, authorized representatives, and individuals who communicate with us. It does not apply to anonymized data that cannot reasonably identify an individual.

Personal Data We Collect

The personal data we collect depends on the Services you request, the accounts you connect, and the permissions you give. We limit collection to data that is relevant and reasonably necessary for the stated purpose.

Categories of personal data

  1. Identity data: name, nationality, date and place of birth, gender, national identity or residence permit number, passport information, and copies of official documents where copying is permitted or required by law.
  2. Contact data: residential or mailing address, email address, mobile number, and other contact details.
  3. Onboarding and compliance data: occupation, employer, source of funds or wealth, income range, tax residency, risk profile, investment objectives, sanctions or watchlist results, and information needed for identity verification, know-your-customer, anti-money-laundering, suitability, or appropriateness checks.
  4. Financial and transaction data: bank or investment account identifiers, balances, holdings, transaction history, payment information, and assets or liabilities you record or authorize us to receive, such as real estate, vehicles, credit cards, and loans.
  5. Account and profile data: user identifier, authentication information, preferences, connected accounts, notification settings, and saved configurations.
  6. Device, technical, and usage data: IP address, device and browser details, operating system, application version, session and login information, security logs, diagnostics, crash data, pages or features used, and interactions with the Services.
  7. Communications data: emails, support requests, complaints, in-application messages, call records where lawful and disclosed, survey responses, and feedback that is not anonymous.
  8. Consent and compliance records: records of notices presented, consents given or withdrawn, rights requests, identity checks, and related correspondence.

Sensitive personal data and credit data

Under the PDPL, sensitive personal data includes data revealing racial or ethnic origin; religious, intellectual, or political belief; criminal and security data; biometric data used to identify an individual; genetic data; health data; and data indicating that an individual has one unknown parent or unknown parents. We do not ordinarily seek this data. If a Service requires it, we will apply enhanced safeguards and rely on explicit consent or another exception specifically permitted by law.

Credit data includes personal data relating to an individual’s application for, or receipt of, financing for a personal or family purpose from an entity that practices financing, including data about credit eligibility, repayment capacity, or credit history. We process credit data only with the explicit consent, notices, security measures, and other controls required by the PDPL, the Credit Information Law, and applicable regulatory requirements.

Sources of personal data

  1. Directly from you when you register, complete onboarding, connect an account, enter information, upload a document, use a feature, or contact us.
  2. From banks, brokers, custodians, fund platforms, licensed open-banking or account-information providers, and other financial institutions that you authorize or direct us to connect with.
  3. From identity, authentication, and verification services and official sources, such as national digital identity services, government platforms, sanctions lists, and other databases, where you authorize access or the law permits collection from that source.
  4. Automatically through cookies, software development kits, logs, security tools, and analytics technologies used in connection with the Services.
  5. From service providers, professional advisers, business partners, and public sources where collection is lawful, relevant, and limited to the stated purpose.

Required and optional data

When data is mandatory, we will identify it at or before collection and explain the consequence of not providing it. If you do not provide data needed to verify your identity, meet a legal requirement, or perform an agreed Service, we may be unable to open or maintain your account or provide that Service. Optional data and permissions can be declined without affecting unrelated Services.

Children

The Services are intended for individuals aged 18 or older. We do not knowingly offer accounts to, or collect personal data directly from, anyone under 18. If we learn that such data was collected without lawful authorization, we will take appropriate steps to restrict processing and destroy it unless retention is required by law.

Why and on What Basis We Process Personal Data

We use personal data for specific, explicit, and legitimate purposes. Under the PDPL, consent is required unless a statutory exception applies. The basis used depends on the purpose, the data involved, and the circumstances.

Purpose What this includes Saudi legal basis
Provide and manage the Services Create and administer accounts; aggregate authorized financial information; display assets, liabilities, and net worth; provide dashboards, tools, and requested support. Performance of a prior agreement with you and, where required, your consent.
Identity and regulatory compliance Verify identity; perform KYC, AML, sanctions, fraud, suitability, or appropriateness checks; keep required records; respond to competent authorities. Processing required by applicable law or to perform the prior agreement; explicit consent where required, including for credit data.
Security and fraud prevention Authenticate users; secure accounts and systems; detect, investigate, and prevent fraud, misuse, and security incidents. Applicable legal obligations; or legitimate interests where the statutory conditions are met and no sensitive data is involved.
Service operation and improvement Troubleshoot; measure performance; improve accessibility, reliability, and user experience; conduct internal research using minimized or anonymized data where possible. Performance of the prior agreement; consent for non-essential technologies; or legitimate interests where the statutory conditions are met.
Communications Send service, security, account, legal, and support communications; respond to questions and complaints. Performance of the prior agreement; applicable legal obligations; or legitimate interests where the statutory conditions are met.
Marketing Send promotional communications and measure campaign effectiveness. Consent, with a simple and free method to opt out.
Corporate and legal matters Establish, exercise, or defend legal claims; obtain professional advice; manage audits, restructuring, financing, or a business transfer. Applicable law; performance of a prior agreement; or legitimate interests where the statutory conditions are met.

Legitimate interests

Where we rely on legitimate interests, we do so only where the processing is within your reasonable expectations, is necessary for a clear and lawful interest, does not involve sensitive personal data, and does not prejudice your rights or conflict with your interests. We document the assessment and apply proportionate safeguards.

Automated processing

We may use automated tools to support fraud detection, security monitoring, data classification, or service personalization. If Wafra proposes to make a decision based entirely on automated processing, we will provide the information required by law and obtain your explicit consent before doing so. We do not use optional AI-assisted import features to make a decision that produces legal or similarly significant effects without explicit consent, appropriate safeguards, and a separate notice.

Your Rights

Subject to the conditions and exceptions in applicable law, you have the following rights under the PDPL:

  1. Right to be informed: to know the legal basis and specific purpose for collecting and processing your personal data and the information required by law.
  2. Right of access: to access personal data available to us about you, subject to lawful limitations that protect you, other individuals, legal duties, and protected rights.
  3. Right to obtain a copy: to receive your personal data in a readable and clear form, including a commonly used electronic format and, where feasible, a printed copy.
  4. Right to correction: to correct inaccurate data and complete or update incomplete or outdated data. If accuracy is disputed, you may request that processing be restricted while we verify it, subject to applicable law.
  5. Right to destruction: to request destruction of personal data that is no longer needed, subject to mandatory retention, legal claims, judicial proceedings, and other lawful exceptions.
  6. Right to withdraw consent: to withdraw consent at any time. Withdrawal does not affect processing completed before withdrawal and may prevent us from providing a feature that depends on that consent.

How to make a request

Send your request to [email protected] or use an available privacy setting in the Services. Describe the right you wish to exercise and the data or account concerned. We may verify your identity and authority before acting, and we will not disclose another person’s data or information protected by law.

We will respond without delay and within 30 days. We may extend that period once, by no more than 30 additional days, if fulfilling the request requires unexpected or unusual effort or if we receive multiple requests from you. We will notify you in advance of the extension and explain why it is needed.

We may decline to process a request that is unreasonably repetitive or requires unusual effort. If we do, we will explain the reason and tell you about available complaint channels. We do not charge a fee for exercising rights under this Policy.

Consent and Choices

Where consent is required, we ask for it through a clear affirmative action. Consent requests will identify the purpose and will be separate from unrelated matters where appropriate. Explicit consent will be used where required, including for sensitive personal data, credit data, decisions based entirely on automated processing, and certain optional features.

We keep records of what you consented to, when and how consent was obtained, and any withdrawal. You may withdraw consent through the relevant Service setting where available or by contacting [email protected]. We will stop the consent-based processing without undue delay unless another legal basis requires or permits continued processing.

Service or security messages are not marketing and may be necessary to operate your account. Marketing messages will identify Wafra and include a simple, free method to stop receiving them.

Sharing and Disclosure

We do not sell personal data or disclose it to third parties for their independent direct marketing. We disclose only the minimum data reasonably necessary for the relevant purpose and only where the disclosure is permitted by law.

  1. Processors and technology providers: hosting, cloud infrastructure, cybersecurity, identity verification, communications, customer support, document processing, analytics, and other suppliers acting on our documented instructions.
  2. Financial institutions and connected partners: banks, brokers, custodians, fund platforms, payment providers, and licensed open-banking or account-information providers you ask us to connect with or use to carry out your request.
  3. Professional advisers and assurance providers: lawyers, accountants, auditors, insurers, and consultants who need the data for professional services and are subject to confidentiality duties.
  4. Authorities and other lawful recipients: SDAIA, competent sector regulators, courts, law-enforcement bodies, tax or government authorities, and other parties where disclosure is required or permitted by law.
  5. Corporate transaction parties: prospective buyers, investors, financiers, and advisers in connection with a merger, acquisition, financing, restructuring, or transfer, subject to confidentiality and lawful processing safeguards.

Processor safeguards

We select processors that provide sufficient privacy and security assurances. Our agreements define the purpose, categories of data, duration, confidentiality, security, incident notification, deletion or return, audit or verification, and subprocessor controls. We periodically verify compliance in proportion to the risk and remain responsible for our obligations as controller.

Optional AI-Assisted Import Features

Wafra may offer optional, user-initiated tools that help extract or organize information from documents, spreadsheets, voice input, or—if separately enabled—credit reports. These tools are intended to assist data entry or summarization. They do not provide financial, legal, investment, or credit advice, and you must review and confirm information before it is saved or used.

Controls before use

  1. A just-in-time notice will identify the feature, the data requested, the purpose, whether use is optional, the relevant processor, the processing country or countries, the retention approach, whether provider training or independent use is permitted, and the available alternative.
  2. Wafra will obtain explicit consent whenever required, including for credit data, sensitive personal data, decisions based entirely on automated processing, or a material change in purpose. Declining an optional AI feature will not prevent use of a reasonable manual alternative where that alternative is offered.
  3. Before launch, Wafra will complete the privacy impact and transfer-risk assessments required by law, validate data flows and deletion behavior, and put appropriate controller–processor and cross-border safeguards in place.
  4. We will minimize the data sent to the feature, limit extraction to relevant fields, and use masking, tokenization, or other protective techniques where appropriate and technically supported.
  5. AI providers may process data only under Wafra’s documented instructions. They may not use it for their own purposes, including model training, unless that use is specifically disclosed and lawfully authorized before you use the feature.
  6. Input files, audio, extracted content, prompts, and outputs will be retained only for the period stated in the launch notice and no longer than necessary for the feature, security, or a mandatory legal requirement.

Credit-report imports

If Wafra offers a credit-report import, it will be subject to a separate explicit-consent flow and additional controls for credit data. The launch notice will explain the source, fields processed, processing location, provider involvement, retention, and how to withdraw consent or use a non-AI alternative. No such transfer or processing will begin until required safeguards and notices are in place.

Security and Personal Data Breaches

We maintain risk-based technical, organizational, and administrative measures intended to protect personal data against unauthorized or unlawful access, use, alteration, disclosure, loss, destruction, or damage. Measures may include, as appropriate:

  1. Encryption in transit and at rest where appropriate; secure key and secrets management.
  2. Role-based access, least-privilege controls, multi-factor authentication, and periodic access reviews.
  3. Secure development, vulnerability management, logging, monitoring, backup, recovery, and incident-response procedures.
  4. Employee confidentiality obligations, privacy and security training, supplier due diligence, and periodic testing or audits.
  5. Data minimization, environment separation, retention controls, and secure destruction or anonymization.

No service can be guaranteed to be completely secure. You should protect your device and credentials, use available security features, and notify us promptly if you suspect unauthorized access to your account.

Breach notification

If Wafra becomes aware of a personal data breach that may harm personal data or a data subject, or may conflict with the data subject’s rights or interests, we will notify the competent authority within 72 hours of awareness in accordance with the Implementing Regulation.

If the breach may damage your personal data or conflict with your rights or interests, we will also notify you without undue delay in clear language. The notice will describe the incident, the potential risks, measures taken to prevent or mitigate harm, our contact details, and practical recommendations. We will document, investigate, contain, and remediate incidents as required.

Retention and Destruction

We retain personal data only for as long as necessary for the stated purpose and any longer period required by applicable law, regulation, a legal claim, or judicial proceeding. The period depends on the data, purpose, sensitivity, relationship, and mandatory recordkeeping rules.

Data category Retention approach
Account and profile data While the account or Service is active, then only for the period needed to close the relationship, handle requests, and meet legal obligations.
KYC, AML, transaction, and credit records For the period prescribed by applicable financial-services, anti-money-laundering, credit-information, tax, or other laws. The applicable period may continue after the relationship ends.
Communications, support, and complaints Until the matter is resolved, then for the period reasonably needed for audit, dispute, and legal-claim purposes.
Consent and rights-request records For as long as the related processing continues and afterward for the period needed to demonstrate compliance.
Security and technical logs For a limited operational security period, with longer retention only where necessary to investigate an incident or comply with law.
Optional AI inputs and outputs For the period stated in the feature’s launch notice and no longer than necessary for the stated purpose, security, or a mandatory legal requirement.
Cookies and similar identifiers For the session or the duration shown in the cookie preference tool or cookie details, subject to consent where required.

When retention ends, we destroy personal data so that it cannot reasonably be recovered or identify you, or we irreversibly anonymize it. Data in protected backups is isolated from ordinary use and deleted or overwritten through the backup lifecycle, unless a legal hold requires longer retention.

An account-deletion request does not require us to erase data that must be retained by law or for an active legal or judicial matter. During a mandatory retention period, access and use are limited to the lawful retention purpose.

International Transfers

We primarily process and store personal data in the Kingdom of Saudi Arabia. We transfer or disclose personal data outside the Kingdom only for a purpose and under conditions permitted by Article 29 of the PDPL and the Regulation on Personal Data Transfer Outside the Kingdom.

  1. We confirm that the transfer does not prejudice national security or the Kingdom’s vital interests and limit the transfer to the minimum personal data needed.
  2. We rely on an adequacy determination or, where a permitted exemption applies, an appropriate safeguard such as approved standard contractual clauses, binding common rules, or a recognized accreditation certificate.
  3. We conduct a transfer-risk assessment where required, including for transfers relying on an exemption and for continuous or large-scale transfers of sensitive personal data.
  4. We apply processor, security, confidentiality, deletion, audit, and onward-transfer controls so that the PDPL’s protections continue to apply.
  5. Where a separate notice or consent is required, we provide or obtain it before the transfer. Consent does not replace any safeguard or assessment required by the transfer rules.

You may contact us for information about the categories of overseas recipients and applicable safeguards, subject to legal, confidentiality, and security limitations.

Cookies and Similar Technologies

The Services may use cookies, software development kits, pixels, local storage, and similar technologies. Some are necessary for the Services to work; others are used only with consent where required.

Category Purpose Choice
Strictly necessary Authentication, security, fraud prevention, session management, and core functionality. Used where necessary to provide the requested Service; cannot be disabled through the consent tool.
Functional Remember language, display, accessibility, or other preferences. Used with consent where required.
Analytics and performance Understand usage, diagnose faults, measure performance, and improve the Services. Used with consent where required; data is minimized or aggregated where practicable.
Advertising or social media Measure or personalize advertising or enable social features. Not used unless introduced with an updated notice and consent controls where required.

Where non-essential technologies are used, a preference tool will allow you to accept, reject, or manage categories. You may also use browser or device settings, although disabling some technologies may affect functionality. Third-party technologies are subject to the relevant third party’s notice as well as the controls Wafra applies to that provider.

Contact, Requests, and Complaints

Contact point Details
Privacy requests and questions [email protected]
Data protection contact [email protected]
Controller Wafrat Alnamae Company, Al Malqa District, Imam Saud ibn Faisal Road, Riyadh, Kingdom of Saudi Arabia

Please include enough information to identify your account and understand your request, but do not send passwords, one-time codes, or unnecessary copies of identity documents by ordinary email.

Complaints

If you believe we have not handled your personal data in accordance with applicable law, you may complain to us using the contacts above. You also have the right to submit a complaint to SDAIA through the National Data Governance Platform. Contacting Wafra first is encouraged but is not a condition of your right to complain to the competent authority.

Changes, Governing Law, and Language

Changes to this Policy

We may update this Policy to reflect changes in law, regulatory guidance, the Services, technology, or our practices. The effective date and version will be updated. For material changes, we will provide reasonable advance notice where practicable through the Services, email, or another appropriate channel. We will obtain renewed consent before new processing where required by law.

Governing law and jurisdiction

This Policy is governed by the laws of the Kingdom of Saudi Arabia. Any dispute relating to it will be submitted to the competent courts or committees in Riyadh, Kingdom of Saudi Arabia, unless applicable law requires otherwise.

Language

This Policy is published in Arabic and English. If the two versions are inconsistent, the Arabic version prevails to the extent permitted by applicable law.

© 2026 Wafrat Alnamae Company. All rights reserved.