Effective date: [to be approved] | Last updated: 13 September 2026

Amarnex Data Privacy Policy

Purpose and Commitment

Amarnex treats customer and tenant data as confidential. Each tenant retains its rights and interests in the business data it submits to or manages through Amarnex. Amarnex does not acquire ownership of tenant data merely because it is stored or processed through the service.

We process tenant data only to provide, secure, maintain, support, and improve the contracted service; to follow documented tenant instructions; and to meet applicable legal obligations. We do not sell tenant data. We do not allow unrelated parties to access it. Access is limited to authorized people and service providers who need it for an approved purpose and are subject to confidentiality and security duties.

This policy describes the proposed public privacy framework. The signed customer agreement, data-processing terms, product configuration, and applicable law may provide additional or controlling requirements.

Who This Policy Covers

This policy covers personal data processed through Amarnex websites, enquiries, demonstrations, customer onboarding, support, and the Amarnex platform. It addresses tenant administrators and users, prospective customers, business contacts, property buyers or prospects whose information a tenant manages, and other individuals who contact us.

A tenant commonly decides why and how property-customer data is used and acts as controller under applicable law; Amarnex commonly processes that data on the tenant’s behalf as processor. Amarnex may act as controller for its own account, billing, security, support, recruitment, and website-contact information. Final roles depend on the specific activity and agreement.

Data We May Process

Depending on the selected services and tenant instructions, data may include names, business and personal contact details, account identifiers, user roles, property interests, enquiry and lead history, customer communications, bookings, contracts, invoices, payment-status records, project and unit references, support messages, device and security information, and activity records.

Tenants must configure their use lawfully and avoid collecting data that is unnecessary for the stated purpose. Payment-card credentials, government identifiers, biometric data, and other sensitive data should not be entered unless an approved feature, lawful basis, security design, and documented scope expressly require them.

Sources

We may receive data directly from an individual; from the tenant and its authorized users; from systems the tenant instructs us to connect; from communications providers; and from technical use of the service. Where a tenant imports data, it is responsible for having authority to provide it and for giving required notices.

Purposes and Legal Bases

Purposes may include creating and administering accounts; delivering configured platform services; managing leads and customer journeys on tenant instructions; supporting bookings, sales, collection follow-up, and communications; providing support and migration; securing and monitoring the service; preventing misuse; complying with law; and, where permitted, communicating about Amarnex.

The applicable legal basis may be performance of a contract, compliance with law, legitimate interests that do not override individual rights, or valid consent. The tenant is responsible for establishing the basis for its own processing. Consent for optional marketing must be separate and withdrawable.

Tenant Data Ownership and Control

Tenant data remains the tenant’s property as between Amarnex and the tenant, subject to the rights of individuals and applicable law. The tenant controls its authorized users, purposes, records, workflows, communications, and instructions. Amarnex receives only the limited rights needed to process the data for the agreed service.

No clause should be read as transferring an individual’s legal rights in personal data to a tenant or to Amarnex. Tenant ownership language concerns the business relationship and does not remove access, correction, deletion, or other rights provided by law.

Confidentiality and Access

Customer data is secret and confidential within the service relationship. It is not open to Amarnex personnel generally. Access may occur only where needed for service operation, authorized support, security investigation, migration or implementation requested by the tenant, legal compliance, or protection of rights and safety.

Access should follow least-privilege roles, authorization checks, confidentiality commitments, and appropriate logging. Tenant administrators are responsible for granting and removing user access. Support access should be approved through the agreed process, limited in purpose and time where practical, and ended when no longer needed.

Security

Amarnex will use reasonable administrative, technical, and organizational measures appropriate to the risk. Proposed policy areas include access control, authentication, encryption where appropriate, secure development and change management, backups, vulnerability management, incident handling, and supplier assessment.

No system is completely secure. Tenants must protect credentials, configure permissions carefully, keep user lists current, and report suspected misuse promptly. Specific certifications, hosting locations, recovery objectives, encryption standards, and security commitments must be stated only in approved contractual or security documentation.

Service Providers and Subprocessors

Amarnex may use carefully selected providers for hosting, communications, support, monitoring, analytics, or other necessary functions. They may process data only for contracted purposes, under confidentiality, security, and data-protection obligations. Amarnex does not authorize a provider to use tenant data for its own unrelated purposes.

A current subprocessor list, notification process, and objection procedure should be published or incorporated into customer data-processing terms before this policy becomes effective.

Integrations and Tenant-Directed Disclosures

If a tenant enables a connector or directs a communication, relevant data may be shared with the selected provider according to the configured direction and purpose. The tenant should review the provider’s terms and privacy practices. Amarnex does not control an independent provider’s processing outside the Amarnex service.

Data may also be disclosed where required by binding law or lawful authority, or to protect rights, safety, and service security. Where legally permitted, Amarnex should notify the affected tenant and limit disclosure to what is required.

International Transfers and Data Location

Hosting and transfer locations must be confirmed in the applicable service documentation. Where personal data is transferred across borders, Amarnex and the tenant will apply the safeguards required by applicable law and their roles, including Saudi transfer requirements where relevant. This policy does not promise that all data remains in one country unless a signed agreement states that commitment.

Retention, Return, and Deletion

Data should be retained only for the agreed service purposes, tenant instructions, legitimate security needs, and applicable legal requirements. Retention periods vary by record type and contractual obligation. The tenant should define operational retention and deletion rules for the data it controls.

At the end of service, Amarnex will return or delete tenant data according to the agreement, applicable law, backup cycles, and documented exceptions. Data required for legal claims, security evidence, or compliance may be isolated and retained only for the necessary period.

Individual Rights

Subject to applicable law, individuals may have the right to be informed; access their data; receive a clear copy; request correction, completion, or updating; request destruction when requirements are met; and withdraw consent. Other jurisdictions may provide additional rights.

When Amarnex processes data for a tenant, requests should usually be directed to that tenant, which controls the customer relationship. Amarnex will provide reasonable assistance as required by the agreement and law. We may verify identity and authority before acting and may apply lawful limitations.

Saudi Personal Data Protection

For processing within the scope of the Saudi Personal Data Protection Law, the parties should apply the PDPL and its Implementing Regulations, including purpose limitation, data minimization, transparency, security, individual rights, retention, disclosure, and transfer requirements. SDAIA is the competent authority identified in official guidance.

Official reference: SDAIA laws and regulations. This policy is not legal advice and should be reviewed by qualified Saudi counsel before publication.

Children and Sensitive Data

Amarnex is a business platform and is not intentionally directed to children. Tenants must not process children’s data or sensitive data without the authority, safeguards, notices, and consent or other lawful basis required by law. Contact us promptly if information appears to have been submitted improperly.

Cookies and Website Analytics

The public website may use necessary cookies for security and operation, and optional analytics or marketing technologies only as configured and permitted. A cookie notice should identify categories, providers, duration, choices, and consent requirements. Rejecting optional cookies should not prevent essential website functions.

Incidents

Amarnex will maintain a process to identify, contain, investigate, and document personal-data incidents. Where required, Amarnex will notify the tenant and/or competent authority within the applicable legal timeframe and provide information reasonably available. Tenants should report suspected incidents through the verified security or privacy contact without sending unnecessary affected data through an open form.

Requests, Complaints, and Contact

Privacy requests should include the requester’s name, relationship to the relevant tenant, the right being exercised, and enough detail to locate the data. Do not submit passwords, one-time codes, or unnecessary identity documents in the initial request.

Privacy contact: [privacy_email to be approved]

Postal address: Amarnex, RJ5C+V6Q, Anas Ibn Malik Rd, Al Malqa, Riyadh 13524, Saudi Arabia.

Tenant requests: contact your tenant administrator first where the tenant controls the data.

Individuals may also complain to the competent authority where applicable. In Saudi Arabia, official SDAIA channels should be used.

Changes to This Policy

We may update this policy to reflect service, legal, or operational changes. The current version should show an effective date and material changes should be communicated as required. A draft or editorial note is not an effective policy.