Star13/07/2026

MIS Connect Privacy Policy

Introduction

This Privacy Policy explains how Excellence Application Solutions Technology Company MIS Connect collects, uses, processes, protects, and discloses personal data relating to individuals and organizations in accordance with the applicable laws and regulations of the Kingdom of Saudi Arabia, including the Personal Data Protection Law issued by the Saudi Data & Artificial Intelligence Authority (SDAIA) and the relevant regulatory requirements issued by the Saudi Central Bank (SAMA) concerning Open Banking services.
MIS Connect operates as an Open Banking Service Provider, offering Account Information Services (AIS) through integration with licensed financial institutions within the Kingdom of Saudi Arabia.
We are committed to protecting your privacy and ensuring that your personal data is processed in accordance with the highest standards of security, confidentiality, and regulatory compliance. By using our services or website, you acknowledge and agree to the terms of this Privacy Policy.

1. Scope of the Policy

This Policy applies to all personal data collection and processing activities carried out by MIS Connect, including:
  • End users of AIS services
  • Financial institutions and partners
  • Website users
  • Job applicants and employees
  • Developer Portal users

2. Definitions

For the purposes of this Policy, the following terms shall have the meanings set out below:

2.1 Company

Excellence Application Solutions Technology Company MIS Connect.

2.2 Personal Data

Any information that identifies, or can reasonably be used to identify, an individual directly or indirectly.

2.3 Data Subject

Any individual whose personal data is processed by the Company.

2.4 Services

Account Information Services (AIS), the Developer Portal, and related technology services.

2.5 Data Provider

The data subject or any party providing data to the Company in accordance with applicable systems, regulations, and required consents.

2.6 Financial Institutions

Banks or financial institutions licensed by the Saudi Central Bank (SAMA).

3. Legal Basis for Processing Personal Data

Personal data is processed based on one or more of the following legal grounds:
  • The data subject's consent
  • Performance of contractual obligations
  • Compliance with legal and regulatory requirements
  • The Company's legitimate interests, provided such interests do not override the rights of data subjects
  • Compliance with regulatory requirements, including those issued by SAMA

4. Collection of Personal Data

We may collect personal data directly or indirectly from the following sources:
  • Licensed financial institutions as part of AIS services
  • Know Your Business (KYB) forms and official documentation
  • Website forms and communication channels
  • The Developer Portal
  • Recruitment and employment processes
  • Communications with clients or users
The data collected may include:
  • Identity information
  • Contact information
  • Bank account information obtained through AIS and subject to user consent
  • Technical and behavioral data related to service usage
  • Employment and professional information submitted during recruitment processes

5. Purposes of Data Processing

Personal data may be used for the following purposes:
  • Providing and operating Open Banking Account Information Services (AIS)
  • Identity verification and due diligence processes (KYC/KYB)
  • Compliance with legal and regulatory obligations
  • Managing relationships with clients and users
  • Improving and developing our services
  • Enhancing cybersecurity and fraud prevention measures
  • Operating the Developer Portal and providing technical support
  • Meeting the requirements of SAMA and other regulatory authorities

6. Data Sharing and Disclosure

Personal data will only be shared where necessary and in accordance with applicable laws and regulations. Data may be disclosed to:
  • Licensed financial institutions within the scope of AIS services
  • Regulatory and supervisory authorities in the Kingdom of Saudi Arabia, including SAMA
  • Third-party service providers (technical or operational) who are contractually bound to maintain appropriate data protection standards
  • Affiliates and operational partners
  • Judicial, governmental, or law enforcement authorities where required by law

7. Data Retention

The Company retains personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable laws and regulations in the Kingdom of Saudi Arabia. Personal data will generally be retained for a period of ten (10) years following the end of the business relationship.
The retention period is determined based on:
  • Legal and regulatory requirements
  • Contractual obligations
  • Risk management and fraud prevention requirements
  • Audit and compliance obligations
  • Resolution of potential legal disputes

8. Data Protection and Information Security

MIS Connect implements appropriate technical and organizational security measures, including but not limited to:
  • Encryption of data in transit and at rest
  • Access control and authorization management
  • Continuous security monitoring
  • Vulnerability management and incident response procedures
  • Periodic security assessments and testing
  • Requiring service providers to maintain equivalent information security standards

9. Data Subject Rights

In accordance with the Personal Data Protection Law of the Kingdom of Saudi Arabia, data subjects have the right to:
  • Be informed about the collection and processing of their personal data
  • Access their personal data
  • Request correction or updating of their personal data
  • Request deletion of personal data where permitted by law
  • Object to certain types of processing
  • Withdraw consent where legally permissible
Requests relating to these rights may be submitted via email to:
We will respond within a period not exceeding seven (7) business days from the date of receiving the request.

10. Personal Data Breaches

In the event of a personal data breach:
  • Incident response procedures will be activated immediately
  • The impact of the incident will be assessed and appropriate corrective actions will be taken
  • Relevant authorities and affected customers will be notified in accordance with applicable legal and regulatory requirements

11. Changes to this Privacy Policy

MIS Connect reserves the right to amend this Privacy Policy from time to time. Any updated version will be published on our website and will become effective from the date of publication.

12. Contact Information

For inquiries, data subject rights requests, or complaints:

13. Governing Law

This Privacy Policy shall be governed by and construed in accordance with the laws and regulations of the Kingdom of Saudi Arabia, including the Personal Data Protection Law and any related regulations issued by the competent regulatory authorities.
Star IconLet's Talk!

Ready to Transform Your Financial Services? Let's Discuss Your Needs

Banner Logo