Last reviewed: July 2026. This policy explains what personal data VertexPartners collects through this website, why, how long we keep it, and the rights you have over it.
1. Who we are
VertexPartners ("we", "us") is a business setup and compliance consultancy operating in the Kingdom of Saudi Arabia. For the purposes of the Saudi Personal Data Protection Law (PDPL) and the EU/UK General Data Protection Regulation (GDPR), we are the controller of the personal data described below.
Questions about this policy, or about your data, can be sent to the contact address published on this site. We aim to respond within 30 days.
2. What we collect, and why
2.1 When you submit an enquiry
Our contact and consultation forms collect: your name, email address, country, the service you are interested in, and your message. If you arrive from a pricing card we also record which plan you clicked, and we store the language you used and any campaign parameters (utm_source, utm_medium, utm_campaign) present in the link that brought you here.
Lawful basis: your consent (which you give with the tick box on the form), and our legitimate interest in responding to a business enquiry. Under PDPL, this is processing necessary to respond to a request you initiated.
We do not store your IP address. We store a salted one-way hash of it, used only for abuse prevention and rate limiting. The original address cannot be recovered from it.
2.2 When you subscribe to our newsletter
We collect your email address and the language you subscribed in. Subscription is double opt-in: we send a confirmation email and add you to the list only after you click the link in it. Every email we send carries a one-click unsubscribe link.
Lawful basis: consent, which you may withdraw at any time by unsubscribing.
2.3 When you browse the site
Analytics are off until you consent. Nothing in this subsection happens if you decline.
With your consent we record: pages viewed, the section of a page you reached, clicks on primary call-to-action buttons (including which pricing tier), when a form field is first focused, your approximate country (derived from your connection — we do not store the address itself), and a randomly generated visitor identifier stored in the vp_visitor cookie. This identifier is not linked to your name unless you separately submit a form.
Lawful basis: consent.
2.4 When you use the chat assistant
The assistant on this site is a scripted question-and-answer tool. It is not an AI system, it does not learn from your messages, and your messages are not used to train any model. What you type is processed to select a pre-written answer.
2.5 Security and abuse prevention
We use Cloudflare Turnstile on our forms to distinguish humans from automated submissions. Turnstile is a privacy-preserving alternative to traditional CAPTCHAs and does not track you across sites. Its use is governed by Cloudflare's own privacy notice.
We also apply rate limiting and record hashed identifiers of requests that trigger abuse protections.
3. What we do NOT do
- We do not sell, rent or trade your personal data. Ever.
- We do not use your data for automated decision-making or profiling that produces legal effects for you.
- We do not place advertising or cross-site tracking cookies.
- We do not store payment card details on this website.
- We do not store raw IP addresses.
4. How long we keep it
Data is deleted automatically once its retention period expires. Current periods:
| Data | Retention | Why |
|---|---|---|
| Enquiries and leads | 3 years from last activity | Commercial follow-up and our own record of the engagement |
| Newsletter subscribers | 3 years, or until you unsubscribe | Consent-based marketing |
| Analytics events | 90 days | Short-window traffic analysis only |
| Consent records | 395 days | Proving that consent was given, as PDPL and GDPR require |
| Email delivery logs | 365 days | Diagnosing non-delivery and disputes |
Where a longer period is required by Saudi commercial, tax or anti-money-laundering law, that legal requirement takes precedence over the periods above.
5. Who we share it with
We share personal data only with processors acting on our instructions, and only as far as needed:
- Our hosting provider, which stores the website and its database.
- Our email delivery provider, which transmits confirmation, notification and newsletter emails.
- Cloudflare (Turnstile), for bot protection on forms.
- Google Analytics, only where you have consented to analytics cookies.
We may also disclose data where we are legally required to do so by a competent Saudi authority or court, or to establish or defend a legal claim.
6. International transfers
Some of the processors above may store or process data outside the Kingdom of Saudi Arabia. Where that happens we rely on the transfer mechanisms permitted under PDPL and its implementing regulations, and — for personal data of individuals in the EU/UK — on an adequacy decision or on Standard Contractual Clauses. You may request details of the safeguards applied to a specific transfer.
7. Your rights
Under PDPL and, where applicable, GDPR, you have the right to:
- Be informed about how your data is used — that is what this document is for.
- Access the personal data we hold about you.
- Rectify data that is inaccurate or incomplete.
- Erase your data ("right to be forgotten"), where no overriding legal obligation requires us to keep it.
- Port your data — receive it in a structured, machine-readable format.
- Object to processing based on legitimate interests, and to withdraw consent at any time.
- Restrict processing while a dispute about accuracy or lawfulness is resolved.
You can exercise any of these using the data request form on this page. To protect you, we ask you to confirm the request from the email address it concerns — we send a verification link, and we do not act on the request until you click it. This prevents someone else asking us to disclose or delete your data.
We respond within 30 days. Exercising these rights is free; we may charge a reasonable fee only for manifestly unfounded or excessive repeat requests.
If you believe we have not handled your data properly, you may complain to the Saudi Data & Artificial Intelligence Authority (SDAIA), or — if you are in the EU/UK — to your local supervisory authority.
8. Children
This site offers business services and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact us and we will delete it.
9. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS), encryption at rest for sensitive fields, hashed rather than stored IP addresses, role-based access control with two-factor authentication for staff accounts, session binding, rate limiting, and automatic deletion at the end of each retention period.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the competent authority and, where required, you — within the timeframes set by PDPL and GDPR.
10. Changes to this policy
We version this document. Material changes will be announced on this page, and where the change affects a purpose you consented to, we will ask for consent again. The version number and date at the top of this page tell you which version you are reading.
11. Governing language
This policy is published in several languages for convenience. In the event of any discrepancy between versions, the English version governs.