AZM Fintech (“AZM”, “we”, “us”, or “our”) is a Saudi company providing financial technology solutions and services through its Edaat system. Edaat supports the provision and management of services to its customers and users in accordance with applicable laws and regulatory requirements.
AZM Fintech is committed to protecting the Personal Data of its customers and users and processing it in accordance with the Saudi Personal Data Protection Law (PDPL) and its Implementing Regulations.
This Privacy Policy explains how AZM Fintech collects, uses, stores, protects, shares, retains, and deletes Personal Data in connection with Edaat, as well as the rights available to Data Subjects and the methods for exercising those rights.
This Privacy Policy applies to users, customers, visitors, and other individuals who access or use Edaat or its related services (hereinafter referred to as “you” or “your”).
The term “Edaat” refers to the Edaat system operated by AZM Fintech.
Version: V2
Last Updated: 28/9/2026
Company Information
Company Name: AZM Fintech
Website: azmfintech.sa
Telephone: 800 1111053
Postal Address: Building No. (23), Laysen Valley, King Khalid Rd, Riyadh, Kingdom of Saudi Arabia
PDPL Officer Contact: PDPL@AZM.COM
1. Personal Data We Collect
We collect only the Personal Data necessary for the relevant processing purpose and retain it only for the period permitted or required under applicable laws and regulations.
Personal Data may be collected through the following methods:
A. Data Collected Directly from the Data Subject
Personal Data may be collected directly from you through methods such as registration forms, electronic forms, required fields, drop-down lists, radio buttons, account creation, customer support requests, complaints, and other information that you voluntarily provide when using Edaat or its related services.
B. Data Collected Indirectly
Personal Data may also be collected indirectly through cookies and similar technologies, automatic collection of technical and usage information, website or system analytics, activity logs, and integrations or interconnections with other entities, where applicable and permitted by law.
The types of Personal Data may include:
• Registration data, such as name, address, email address, and mobile number.
• Identity verification data, including national ID or passport information where required.
• Information provided when reporting an issue, submitting a complaint, or contacting technical support or customer care.
• Transaction-related data, including payments, deposits, and relevant activity logs.
• Technical and usage information generated through your interaction with Edaat.
• Any other Personal Data voluntarily provided by you or collected lawfully for a specified purpose.
2. Cookies
Cookies are small text files stored on your device when you visit Edaat. We may use cookies and similar technologies to:
• Improve your experience and understand how you interact with Edaat.
• Identify errors and improve Edaat, its content, and services.
• Support the functionality and security of Edaat.
• Facilitate access to certain features and services.
Where required, consent will be obtained before using cookies that require consent.
You may manage or disable cookies through your browser or device settings. Disabling certain cookies may affect the functionality of some Edaat services.
Third-party cookies, where applicable, are subject to the privacy practices of the relevant third parties.
3. How We Use Personal Data
We may process Personal Data for the following purposes:
• Providing and managing access to our services.
• Creating and managing accounts and profiles.
• Verifying identity and account information.
• Activating and managing email or mobile verification.
• Processing and managing payments and transactions.
• Responding to inquiries, complaints, Data Subject Requests, and feedback.
• Providing customer support and technical support.
• Improving and developing our services and user experience.
• Managing surveys and interactive activities, where applicable.
• Detecting, preventing, and investigating fraud, security incidents, and malicious activities.
• Fulfilling legal, regulatory, and contractual obligations.
• Enforcing applicable Terms and Conditions.
• Communicating with you regarding services, security matters, and material changes to our services or this Privacy Policy.
• Any other purpose permitted under applicable laws and regulations.
Personal Data will not be processed for purposes incompatible with the purpose for which it was collected unless permitted by applicable law or based on a valid legal basis.
4. Legal Basis for Processing
We process Personal Data based on one or more applicable legal bases under the PDPL and its Implementing Regulations, including, where applicable:
• Your consent, where consent is required.
• Compliance with a legal or regulatory obligation.
• Performance of a contract or taking steps at your request prior to entering into a contract.
• Legitimate purposes permitted under applicable laws and regulations.
• Protection of your vital interests or those of another person, where applicable.
• Other legal bases permitted under the PDPL and its Implementing Regulations.
Where processing is based on consent, you have the right to withdraw your consent at any time, subject to applicable legal and regulatory requirements and any consequences resulting from such withdrawal.
5. Data Subject Rights
Subject to the provisions, conditions, and exceptions of the PDPL and its Implementing Regulations, Data Subjects may have the following rights in relation to their Personal Data:
• The right to be informed about the legal or practical justification for collecting their Personal Data and the purpose of processing it.
• The right to access their Personal Data held by us.
• The right to request a copy of their Personal Data in a clear and readable format.
• The right to request correction, completion, or updating of their Personal Data.
• The right to request the destruction of their Personal Data where the applicable legal conditions are met.
• The right to withdraw consent where consent is the applicable legal basis for processing.
• The right to know the legal basis for processing their Personal Data, where applicable.
• The right to request that processing of their Personal Data be restricted where the applicable legal conditions are met.
• The right to object to certain processing activities where permitted by applicable laws and regulations.
• Any other rights granted to Data Subjects under the PDPL, its Implementing Regulations, or other applicable laws and regulations.
Data Subjects may exercise their rights by submitting a request through the official Privacy / Data Subject Request Channel specified in Section 6 of this Privacy Policy.
The exercise of these rights is subject to the requirements, conditions, and exceptions established by the PDPL and its Implementing Regulations.
6. How to Exercise Your Rights
You may exercise your Data Subject Rights by submitting a request through the following official communication channel:
Privacy / Data Subject Request Channel: PDPL@AZM.COM
When submitting a request, you may be required to provide sufficient information to verify your identity and to enable us to identify and process the request.
We may request additional information or supporting documentation where reasonably necessary to verify your identity, assess the request, or comply with applicable legal and regulatory requirements.
Requests will be assessed and processed by the relevant responsible functions in accordance with applicable internal procedures and controls.
If you are dissatisfied with the outcome of your complaint or the manner in which your Data Subject Request has been handled, you may escalate the matter to the Saudi Data & AI Authority (SDAIA), as the competent authority, in accordance with the applicable laws and regulations.
7. Data Subject Request Processing and Response Timeline
We will process Data Subject Requests without undue delay and, subject to the applicable requirements of the PDPL and its Implementing Regulations, provide a response within a period not exceeding 30 days from receiving the request.
Where the implementation of the request requires disproportionate effort or where we receive multiple requests from the same Data Subject, the response period may be extended by an additional period not exceeding 30 days, where permitted by applicable law.
Where an extension is required, we will notify the Data Subject in advance of the extension and provide the reasons for the delay.
Where a request cannot be fulfilled, is restricted, or is rejected based on an applicable legal or regulatory exception, we will provide the Data Subject with the applicable explanation, subject to legal and regulatory requirements.
8. Consent and Withdrawal of Consent
Where consent is required as the legal basis for processing, we will obtain consent through a clear and appropriate method and, where applicable, maintain records demonstrating the consent provided.
Consent may relate to different processing purposes depending on the relevant service or business process, including, where applicable:
• Service-related consent.
• Optional consent.
• Marketing consent.
• Explicit consent where required by applicable law.
You may withdraw your consent at any time where consent is the applicable legal basis for processing by submitting a request through the following channel:
Consent Withdrawal Channel: PDPL@AZM.COM
A request to withdraw consent will be recorded and processed through the applicable internal procedures. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal.
Where Personal Data continues to be processed after withdrawal of consent, such processing will be based on another valid legal basis, where applicable.
9. Personal Data Protection and Security
We implement appropriate technical and organizational measures designed to protect Personal Data against unauthorized access, disclosure, alteration, loss, destruction, or other unlawful processing, taking into account the nature and sensitivity of the Personal Data and the associated risks.
Access to Personal Data is restricted to authorized personnel and service providers who require access for legitimate business or service purposes and are subject to applicable confidentiality and security requirements.
We do not sell or trade Personal Data.
Where a Personal Data Breach occurs that requires notification under applicable laws or regulations, the relevant notifications will be made to the competent authority and affected Data Subjects, where required.
10. Data Sharing and Disclosure
We may disclose or share Personal Data with other entities, whether inside or outside the Kingdom, where permitted or required by applicable laws and regulations.
Personal Data may be disclosed to the following categories of entities:
• Regulatory and Government Authorities: such as competent regulatory, supervisory, governmental, or law enforcement authorities, where required or permitted by applicable laws or regulations.
• Service Providers and Third Parties: authorized service providers that support the operation, maintenance, security, hosting, technical support, or delivery of Edaat and its related services.
• Professional and Advisory Parties: auditors, legal advisors, consultants, and other professional service providers where necessary for legitimate business, legal, regulatory, or compliance purposes.
• Other Authorized Entities: other entities where disclosure is necessary to provide the requested services, protect our rights or systems, prevent fraud or security incidents, or where you have provided valid consent, where consent is the applicable legal basis.
The main purposes of sharing or disclosing Personal Data include fulfilling legal and regulatory obligations, providing and operating Edaat services, maintaining security, preventing fraud, providing technical and operational support, and protecting the rights and interests of AZM Fintech, users, and other relevant parties.
Personal Data may be disclosed occasionally or regularly, depending on the nature of the service, legal or regulatory requirements, contractual arrangements, and the operational requirements of Edaat.
Where applicable, third parties receiving Personal Data will be subject to appropriate contractual, confidentiality, security, and data protection requirements.
Where Personal Data is disclosed or transferred outside the Kingdom, such disclosure or transfer will be carried out in accordance with the applicable requirements and conditions of the PDPL, its Implementing Regulations, and other applicable regulatory requirements.
11. Data Retention and Disposal
We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, or for the period required or permitted by applicable laws and regulations.
The retention period may vary depending on:
• The purpose for which the Personal Data was collected.
• Legal and regulatory requirements.
• Contractual obligations.
• Requirements relating to dispute resolution, audits, or regulatory investigations.
• Applicable data retention requirements.
When Personal Data is no longer required, and where there is no legal or regulatory requirement to retain it, we will take appropriate measures to securely delete, destroy, or anonymize the Personal Data in accordance with applicable internal procedures and legal requirements.
Where a Data Subject requests destruction of Personal Data, the request will be assessed in accordance with applicable legal and regulatory requirements and any applicable exceptions to the right of destruction.
12. International Data Transfer
We do not transfer Personal Data outside the Kingdom of Saudi Arabia except in accordance with the requirements and conditions of the PDPL, its Implementing Regulations, and other applicable regulatory requirements.
Where an international transfer is permitted, appropriate safeguards and controls will be implemented as required by applicable laws and regulations.
13. Obligations of the Parties
Where applicable, clients, billers, and other parties interacting with Edaat are expected to maintain the confidentiality and security of Personal Data and use such data only for authorized purposes.
Each party shall, as applicable:
• Maintain the confidentiality and privacy of Personal Data.
• Protect Personal Data from unauthorized use or disclosure.
• Use Personal Data only for lawful and authorized purposes.
• Protect transaction-related information.
• Not collect other users’ Personal Data without lawful authorization.
• Comply with applicable legal, regulatory, contractual, and data protection requirements.
14. Privacy Policy Review and Updates
This Privacy Policy is subject to periodic review to ensure that it remains accurate, effective, and aligned with applicable legal, regulatory, and operational requirements.
The Privacy Policy will be reviewed at least annually, or earlier where there are material changes to applicable laws, regulations, regulatory requirements, processing activities, services, systems, or organizational practices.
Changes to this Privacy Policy will be documented through appropriate version control and change history.
Where material changes affect the way Personal Data is processed or the rights of Data Subjects, appropriate notice will be provided through Edaat or other suitable communication channels, where required.
The effective date and “Last Updated” date will be reflected in the latest approved version of this Privacy Policy.
15. Contact Us
For questions, complaints, Data Subject Requests, consent withdrawal requests, or inquiries relating to the processing of Personal Data, you may contact us through:
• Company Name: AZM Fintech
• Website: azmfintech.sa
• Telephone: 800 1111053
• Postal Address: Building No. (23), Laysen Valley, King Khalid Rd, Riyadh, Kingdom of Saudi Arabia
• PDPL Contact: PDPL@AZM.COM
We will handle requests and inquiries in accordance with applicable legal and regulatory requirements and our internal procedures.