1. Controller and contact
Sadin Real Estate Office (مكتب سدين للعقار) is the controller for this website. Commercial registration 4650200249; unified national entity number 7003908675; FAL brokerage and marketing licence 1200042362. Its activity is licensed real-estate brokerage, marketing, property advertising, customer requests and related digital account services. Public office address: Prince Mohammed bin Salman Road (formerly Airport Road), Abu Ouf Plaza, seventh floor, Madinah, Saudi Arabia. Privacy and rights requests: info@sadin.com.sa. Telephone: 0530084666.
The privacy contact is assigned to this channel; it is not described as a formally appointed data protection officer.
2. Data, sources, and whether it is required
- Accounts: name, email, mobile number, city, password verifier, language, account state and security events supplied by you. Required fields are identified on the form; without them we cannot create or secure the account.
- Optional sign-in: a provider identifier and the limited profile fields actually returned by an enabled Google, Facebook, Microsoft, Telegram or X sign-in flow. External sign-in is optional; disabled providers are not used.
- Property enquiries and requests: name, contact method, request details, property reference, preferences and consent/notice evidence supplied by you. Without required contact and request data we cannot follow up.
- Property and brokerage records: listing, manager, licensing, media and location information supplied by property owners, managers, authorized staff or official/public sources. Exact location is restricted according to the approved publication setting.
- Account activity: favorites, sessions, verification and relevant account actions. Favorites are optional.
- Newsletter: email, language, consent version/source and confirmation, withdrawal and suppression evidence. Subscription is optional and separate from service delivery.
- Communications and administration: direct-message and campaign evidence, recipient snapshots, provider acceptance, attempts and audit events required for authorization, accountability and dispute handling.
- Technical and security data: network address or a protected derivative, timestamps, browser/request metadata, security events, application/access logs and aggregate counters where generated by the application, web server or security controls. We do not claim that raw network information is never present in bounded operational logs.
- Uploads: property images, documents and their metadata submitted by authorized users. Do not upload unnecessary personal data.
3. Purposes and lawful bases
| Purpose | Lawful basis |
|---|---|
| Create and secure accounts; authenticate users; maintain sessions. | Taking steps at the data subject’s request, performing the service agreement, legal obligations and legitimate security interests that do not override the individual’s rights. |
| Answer enquiries, property requests and arrange brokerage follow-up. | Taking steps at your request, performance of an agreement, and applicable brokerage/legal obligations. |
| Publish and administer lawful property advertising and licensing evidence. | Agreement, legal and regulatory obligations, and legitimate interests in accurate licensed brokerage. |
| Security, fraud prevention, audit, monitoring, backup and incident response. | Legal obligations and legitimate interests in protecting users, records and the service. |
| Send account, request or direct office communications. | Service necessity, agreement, legal obligation, or the authorized sender’s legitimate operational purpose as applicable. |
| Send newsletters or marketing. | Your separate, explicit consent. Withdrawal is available at any time and is as easy as subscribing. |
| Aggregate service measurement where enabled. | Legitimate interest in operating and improving the service with data minimization; the current production analytics setting is disabled. |
| Respond to privacy rights, complaints and lawful authority requests. | Legal obligation and establishment, exercise or defense of legal claims. |
4. Processing and recipients
We collect, validate, organize, store, retrieve, use, disclose where authorized, secure, back up, restrict, anonymize and destroy data only for the stated purposes. Access is limited by role and operational need. Routine recipients may include authorized Sadin personnel and property managers within their scope, hosting/infrastructure providers, email delivery providers, enabled identity providers, mapping or embedded-content providers selected by the user, and security/monitoring providers. Exceptional disclosure may occur to competent Saudi authorities, courts, regulators, professional advisers or emergency recipients when legally required or permitted. We do not sell personal data.
5. Location and transfers outside Saudi Arabia
The primary service is operated for Sadin in Saudi Arabia, while selected authentication, email, maps, embedded-content or infrastructure providers may process limited personal data outside Saudi Arabia. Such processing is limited to providing the requested service and must follow applicable Saudi transfer requirements, data minimization, risk assessment where required, and suitable contractual or regulatory safeguards such as an adequate level of protection, approved standard contractual clauses, binding common rules or accreditation where applicable. Choosing third-party sign-in or opening an external map is optional.
6. Retention and destruction
- Account/profile data remains while the account is active and through a bounded closure process, then unnecessary data is destroyed or anonymized, while legal, fraud, dispute and audit evidence is preserved only as required.
- Enquiries and customer requests remain until closure and for a reasonable follow-up, brokerage, legal-claims and regulatory-evidence period, then unnecessary personal fields are securely destroyed or anonymized.
- Property, brokerage and advertising records remain for applicable contractual, real-estate, regulatory and dispute periods. Publication stops when it is no longer lawful; immutable regulatory evidence is not destroyed prematurely.
- Sessions use the configured seven-day maximum and two-hour idle timeout and are revoked on logout, password change/reset or a security action.
- Security, access and application logs are retained for no more than 12 months by default, unless a documented incident, investigation or legal obligation requires a longer hold.
- Newsletter consent remains while subscribed. After withdrawal, only minimum suppression and compliance evidence remains.
- Direct-message and campaign delivery, consent, suppression and audit evidence remains for accountability; message content is minimized or removed when no longer necessary without breaking canonical evidence or legal holds.
- OAuth linkage and minimum security evidence remain only as needed for the account; provider access tokens are not retained longer than operationally necessary.
- Protected backups remain until the bounded backup rotation expires or overwrites them. Data approved for destruction is not restored for ordinary use, except where recovery or law requires it.
- Rights requests and complaints retain minimized verification, decision and completion evidence for accountability.
Secure destruction makes data irretrievable; anonymization permanently removes direct and indirect identifiers. Backup copies expire through protected rotation rather than ad-hoc editing.
7. Protection measures
We use proportionate technical, administrative and organizational safeguards, including access control, least privilege, authentication and reauthentication, encrypted transport, protected credentials and message content, input validation, audit trails, durable delivery evidence, backups, monitoring, security updates and incident handling. No Internet service can promise absolute security.
8. Your rights and complaints
You may request information, access, a readable copy, correction, completion, update, destruction where legally applicable, withdrawal of consent, and make a complaint or seek compensation where provided by law. Use the privacy rights form, your authenticated account tools where available, or email info@sadin.com.sa. We verify identity proportionately and do not request excessive identity documents.
We respond within 30 days. One justified extension of no more than 30 additional days may be used after advance notice and reasons. You may contact Sadin at any time. An unresolved complaint may be submitted through the official channels of the competent Saudi personal-data authority, generally within 90 days of the incident or knowledge of it, subject to the authority’s rules.
9. Consent, minors, cookies and external services
Consent can be withdrawn through the same newsletter unsubscribe mechanism or our privacy channel without affecting prior lawful processing. Marketing consent is optional and never bundled with brokerage or account service. A lawful guardian acts for a minor or legally incapacitated person where applicable; users should not submit a child’s data without lawful authority.
Essential first-party session and security storage supports login, CSRF protection, language, preferences and service continuity. We do not add advertising cookies, fingerprinting or tracking pixels through this policy. Enabled external sign-in providers and external maps/embeds receive data only when their feature is used and apply their own notices. Aggregate first-party analytics is currently disabled; any future material change requires an updated notice and lawful basis.
Users of Facebook sign-in can review the dedicated Facebook user-data deletion instructions.
10. Breaches and policy updates
When the statutory harm threshold is met, Sadin will notify the competent authority within 72 hours of becoming aware of a personal-data breach and notify affected individuals without unjustified delay when legally required. Public wording does not disclose sensitive incident-response controls.
Material changes will be communicated through an appropriate website, account or direct notice before they take effect where required. Update history: 29 July 2026 — complete bilingual production policy; 29 July 2026 v2 — verified commercial registration, unified entity and FAL controller identifiers.