MIS Connect Privacy Policy
Introduction
This Privacy Policy explains how Excellence Application Solutions Technology Company MIS Connect collects, uses, processes, protects, and discloses personal data relating to individuals and organizations in accordance with the applicable laws and regulations of the Kingdom of Saudi Arabia, including the Personal Data Protection Law issued by the Saudi Data & Artificial Intelligence Authority (SDAIA) and the relevant regulatory requirements issued by the Saudi Central Bank (SAMA) concerning Open Banking services.
MIS Connect operates as an Open Banking Service Provider, offering Account Information Services (AIS) through integration with licensed financial institutions within the Kingdom of Saudi Arabia.
We are committed to protecting your privacy and ensuring that your personal data is processed in accordance with the highest standards of security, confidentiality, and regulatory compliance. By using our services or website, you acknowledge and agree to the terms of this Privacy Policy.
1. Scope of the Policy
This Policy applies to all personal data collection and processing activities carried out by MIS Connect, including:
- • End users of AIS services
- • Financial institutions and partners
- • Website users
- • Job applicants and employees
- • Developer Portal users
2. Definitions
For the purposes of this Policy, the following terms shall have the meanings set out below:
2.1 Company
Excellence Application Solutions Technology Company MIS Connect.
2.2 Personal Data
Any information that identifies, or can reasonably be used to identify, an individual directly or indirectly.
2.3 Data Subject
Any individual whose personal data is processed by the Company.
2.4 Services
Account Information Services (AIS), the Developer Portal, and related technology services.
2.5 Data Provider
The data subject or any party providing data to the Company in accordance with applicable systems, regulations, and required consents.
2.6 Financial Institutions
Banks or financial institutions licensed by the Saudi Central Bank (SAMA).
3. Legal Basis for Processing Personal Data
Personal data is processed based on one or more of the following legal grounds:
- • The data subject's consent
- • Performance of contractual obligations
- • Compliance with legal and regulatory requirements
- • The Company's legitimate interests, provided such interests do not override the rights of data subjects
- • Compliance with regulatory requirements, including those issued by SAMA
4. Collection of Personal Data
We may collect personal data directly or indirectly from the following sources:
- • Licensed financial institutions as part of AIS services
- • Know Your Business (KYB) forms and official documentation
- • Website forms and communication channels
- • The Developer Portal
- • Recruitment and employment processes
- • Communications with clients or users
The data collected may include:
- • Identity information
- • Contact information
- • Bank account information obtained through AIS and subject to user consent
- • Technical and behavioral data related to service usage
- • Employment and professional information submitted during recruitment processes
5. Purposes of Data Processing
Personal data may be used for the following purposes:
- • Providing and operating Open Banking Account Information Services (AIS)
- • Identity verification and due diligence processes (KYC/KYB)
- • Compliance with legal and regulatory obligations
- • Managing relationships with clients and users
- • Improving and developing our services
- • Enhancing cybersecurity and fraud prevention measures
- • Operating the Developer Portal and providing technical support
- • Meeting the requirements of SAMA and other regulatory authorities
6. Data Sharing and Disclosure
Personal data will only be shared where necessary and in accordance with applicable laws and regulations. Data may be disclosed to:
- • Licensed financial institutions within the scope of AIS services
- • Regulatory and supervisory authorities in the Kingdom of Saudi Arabia, including SAMA
- • Third-party service providers (technical or operational) who are contractually bound to maintain appropriate data protection standards
- • Affiliates and operational partners
- • Judicial, governmental, or law enforcement authorities where required by law
7. Data Retention
The Company retains personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable laws and regulations in the Kingdom of Saudi Arabia. Personal data will generally be retained for a period of ten (10) years following the end of the business relationship.
The retention period is determined based on:
- • Legal and regulatory requirements
- • Contractual obligations
- • Risk management and fraud prevention requirements
- • Audit and compliance obligations
- • Resolution of potential legal disputes
8. Data Protection and Information Security
MIS Connect implements appropriate technical and organizational security measures, including but not limited to:
- • Encryption of data in transit and at rest
- • Access control and authorization management
- • Continuous security monitoring
- • Vulnerability management and incident response procedures
- • Periodic security assessments and testing
- • Requiring service providers to maintain equivalent information security standards
9. Data Subject Rights
In accordance with the Personal Data Protection Law of the Kingdom of Saudi Arabia, data subjects have the right to:
- • Be informed about the collection and processing of their personal data
- • Access their personal data
- • Request correction or updating of their personal data
- • Request deletion of personal data where permitted by law
- • Object to certain types of processing
- • Withdraw consent where legally permissible
Requests relating to these rights may be submitted via email to:
We will respond within a period not exceeding seven (7) business days from the date of receiving the request.
10. Personal Data Breaches
In the event of a personal data breach:
- • Incident response procedures will be activated immediately
- • The impact of the incident will be assessed and appropriate corrective actions will be taken
- • Relevant authorities and affected customers will be notified in accordance with applicable legal and regulatory requirements
11. Changes to this Privacy Policy
MIS Connect reserves the right to amend this Privacy Policy from time to time. Any updated version will be published on our website and will become effective from the date of publication.
12. Contact Information
For inquiries, data subject rights requests, or complaints:
- • Compliance, Data Protection, and Complaints: compliance@misconnect.sa
- • Human Resources: hr@misconnect.sa
13. Governing Law
This Privacy Policy shall be governed by and construed in accordance with the laws and regulations of the Kingdom of Saudi Arabia, including the Personal Data Protection Law and any related regulations issued by the competent regulatory authorities.
