Data Retention and Breach Response Policy

INTRODUCTION

iRazzh is committed to handling every piece of personal and business data it holds with legal precision, proportionality, and purpose. We keep data for as long as we genuinely need it, whether to deliver our services, honor legal obligations, or protect legitimate interests, and no longer.

This policy has two connected parts.

Part A sets out how long iRazzh retains different categories of personal and business data, and how data is disposed of when that period ends.

Part B explains how iRazzh identifies, contains, and reports a personal data breach, and what affected individuals can expect if a breach occurs.

This policy governs how long iRazzh holds personal and business data, how it is disposed of when it is no longer needed, and what iRazzh does step-by-step when a data breach occurs. It operates alongside Section 9 and Section 10 of the Privacy Policy (POL-002), which should be read together with this document.

This policy is issued in compliance with the Personal Data Protection Law (PDPL, Royal Decree M/19 as amended by M/148), SDAIA breach notification requirements, ZATCA data retention mandates, Saudi AML law, and the E-Commerce Law.

PART A — DATA RETENTION

1. GUIDING PRINCIPLES

iRazzh retains personal and business data only for as long as is necessary for the purpose for which it was collected, consistent with contractual obligations and the applicable Saudi legal requirements for each data category. At the end of the applicable retention period, data is securely deleted or irreversibly anonymized using methods that prevent reconstruction of the original personal data.

Where a retention period in this policy exceeds the period published in the Privacy Policy's Section 9 table, the longer period governs, and the Privacy Policy will be updated at the next scheduled review to reflect any correction. Where a legal requirement establishes a minimum retention period that exceeds the period otherwise needed for operational purposes, the legal minimum governs.

2. RETENTION SCHEDULE

Data Category Retention Period Legal Basis or Reason
Account and identity data Duration of account plus 3 years post-closure PDPL; E-Commerce Law; general contractual obligations
Order and transaction records 10 years from the date of the transaction ZATCA mandatory minimum for tax and e-invoice records
VAT and e-invoice records 10 years from the date of issue ZATCA mandatory minimum
Payment data (tokenized card references) 3 years since the last transaction PCI-DSS alignment; SAMA payment processing guidelines
Customer support records years from case closure PDPL: potential dispute or litigation period
Marketing consent records Duration of consent plus 3 years PDPL; evidence of lawful processing basis
Cookie and tracking data Maximum 12 months Cookie Policy; PDPL proportionality principle
Vendor KYC documentation Duration of relationship plus 10 years Saudi AML Law — minimum ten-year retention for due-diligence records on business clients
Vendor transaction and commission records 10 years from the date of transaction ZATCA; Vendor Agreement obligations
Data breach records and investigation documentation Minimum 5 years from the date of the incident PDPL; SDAIA incident record-keeping guidelines

3. VENDOR KYC RETENTION — CORRECTION NOTE

The retention period for Vendor KYC documentation has been set at the duration of the relationship plus 10 years, consistent with Saudi AML requirements that mandate a minimum ten-year retention period for client due diligence records.

This supersedes any shorter period that may have been communicated to Vendors during earlier onboarding processes. All active Vendor KYC records are subject to this ten-year post-relationship minimum from the date the relationship ends.

4. RETENTION REVIEW AND DISPOSAL

Data holdings are reviewed at least annually to identify data that has reached the end of its applicable retention period. Data confirmed as past its retention period is:

  • Deleted: permanently removed from all active systems and backups within a reasonable operational cycle; or
  • Anonymized: processed in a manner that irreversibly removes all fields capable of identifying an individual or entity, such that the data can no longer reasonably be attributed to any specific person.

Where a retention period is extended beyond the standard schedule, for example, because data is relevant to an ongoing complaint, dispute, regulatory inquiry, or litigation, the extension is logged internally, and the data is flagged for review at the conclusion of the relevant proceeding.

5. CROSS-REFERENCE TO PRIVACY POLICY

The retention periods in Section 2 of this policy are the authoritative, complete version of iRazzh's data retention schedule. The Privacy Policy (Section 9) sets out a summary of the same retention periods for the purpose of consumer transparency. In the event of any discrepancy between the two documents, this policy's table governs, since it incorporates legal basis references and is reviewed at a more granular operational level.

PART B — DATA BREACH RESPONSE

6. WHAT CONSTITUTES A DATA BREACH

A personal data breach is any security incident resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data held or processed by iRazzh. This includes incidents affecting data processed by iRazzh's third-party service providers on iRazzh's behalf.

A breach does not need to involve malicious intent to meet this definition; accidental deletion, unintended disclosure, or misdirected communications containing personal data all qualify and must be treated in accordance with this policy.

7. REPORTING OBLIGATIONS — WHO MUST REPORT AND WHEN

Any iRazzh employee, contractor, or Vendor who becomes aware of, or reasonably suspects, a potential data breach must report it immediately and in all cases within 2 hours of becoming aware, to:

security@iRazzh.com

No external communication about a suspected or confirmed breach may be made by any individual employee, contractor, or Vendor before the Data Protection Officer (DPO) has been notified and has assessed the situation. This restriction applies regardless of the severity or apparent scope of the incident at the time of initial awareness.

8. STAGED BREACH RESPONSE

STAGE 1 — DETECTION AND INTERNAL ESCALATION (IMMEDIATE — WITHIN 2 HOURS)

Upon receiving a breach report, the DPO or nominated deputy initiates internal escalation, including:

  • Logging the incident in iRazzh's breach register with the time, date, and initial description.
  • Notifying the relevant technical, legal, and senior management contacts.
  • Confirming whether the breach is ongoing or contained.

STAGE 2 — INITIAL ASSESSMENT (WITHIN 2 HOURS OF INTERNAL ESCALATION)

The DPO and the relevant technical team conduct an initial assessment to determine:

  • The nature and apparent scope of the breach.
  • The categories and estimated volume of personal data affected.
  • The likely severity of impact on affected individuals.
  • Whether the breach is ongoing and, if so, what immediate action is required.

The outcome of this assessment determines the priority of containment action and the applicable notification timelines.

STAGE 3 — CONTAINMENT (WITHIN 4 HOURS OF INITIAL ASSESSMENT)

Containment measures are implemented promptly and proportionately to the nature of the breach, including as applicable:

  • Isolating affected systems or network segments.
  • Revoking or resetting compromised credentials and access tokens.
  • Blocking identified unauthorized access vectors.
  • Preserving all forensic evidence for investigation and regulatory reporting purposes.
  • Engaging iRazzh's cybersecurity partners where external technical support is required.

STAGE 4 — SDAIA NOTIFICATION (WITHIN 72 HOURS OF BECOMING AWARE OF THE BREACH)

In accordance with Article 24 of the PDPL Implementing Regulations, IRazzh notifies SDAIA of a personal data breach within 72 hours of becoming aware of the incident.

This obligation applies to all breaches — the 72-hour notification window to SDAIA is not conditional on a finding that the breach has caused, or is likely to cause, harm to data subjects. The harm threshold applies only to the obligation to notify affected individuals directly (Stage 5 below), not to the SDAIA notification itself.

The SDAIA notification is submitted through SDAIA's official Personal Data Breach Notification Service (accessible at sdaia.gov.sa) and includes, at a minimum:

  • A description of the nature of the breach and how it occurred.
  • The categories and approximate number of data subjects and personal data records affected.
  • An assessment of the likely consequences of the breach.
  • The measures iRazzh has taken or proposes to take to contain, remediate, and prevent recurrence.
  • The contact details of iRazzh's DPO.

Where it is not possible to provide all required information within 72 hours, iRazzh provides available information within that window and supplements it as soon as the additional information becomes available.

STAGE 5 — INDIVIDUAL NOTIFICATION (WITHOUT UNDUE DELAY WHERE HIGH RISK IS CONFIRMED)

Where the breach poses a high risk to the rights or interests of specific individuals, for example, where sensitive personal data, financial data, or identity credentials have been exposed, iRazzh notifies affected individuals directly, without undue delay, by:

  • Registered email to the address held on the individual's iRazzh account; and
  • In-app notification within the iRazzh platform.

The individual notification is written in plain, accessible language and includes:

  • A clear description of what occurred and what data was affected.
  • The likely consequences of the breach for the individual.
  • The steps iRazzh has taken to contain and remediate the breach.
  • Practical steps the individual can take to protect themselves.
  • The DPO's contact details for further enquiries.

STAGE 6—POST-BREACH REVIEW AND DOCUMENTATION

Following containment and notification, iRazzh conducts a full post-breach review to:

  • Identify the root cause of the breach.
  • Evaluate the effectiveness of the response at each stage.
  • Implement technical and organizational improvements to prevent recurrence.
  • Document the breach and all response actions in iRazzh's breach register, which is maintained for a minimum of 5 years and is available to SDAIA upon request.

9. PENALTIES FOR NON-COMPLIANCE

Non-compliance with PDPL data protection obligations carries significant consequences. iRazzh publishes this information transparently so that its operational teams understand the stakes of handling personal data correctly:

  • Fines of up to SAR 5,000,000 per violation.
  • Repeating violations involving the same breach or pattern of conduct may result in doubled fines.
  • Intentional or repeated violations involving sensitive personal data may result in criminal prosecution and imprisonment of up to two years.
  • SDAIA has the authority to suspend iRazzh's data processing activities in cases of serious or persistent non-compliance, which would create significant operational disruption to the platform.

These are the consequences of non-compliance with the PDPL as currently enforced by SDAIA and are published here for transparency and internal awareness. This Section does not create any new obligation or commitment on the part of iRazzh to affected individuals beyond those already set out in the PDPL itself.

10. DISCLAIMER & LIMITATION OF LIABILITY

iRazzh implements technical and organizational measures to protect personal data to the greatest reasonably practicable extent.

No system is entirely immune to sophisticated attacks or human error. In the event of a breach caused by a third-party processor, iRazzh will enforce that processor's contractual security obligations under the PDPL and the applicable processing agreement.

11. POLICY AMENDMENTS

iRazzh reviews this policy at least annually, and promptly following any material change in the PDPL, ZATCA requirements, AML retention rules, or SDAIA's published breach notification guidance. Material changes will be communicated via email and in-app notification at least 15 calendar days before taking effect. Continued use of the platform after the effective date constitutes acceptance of the revised policy.

12. CONTACT — DATA PROTECTION ENQUIRIES

For questions about data retention, or to report a suspected data breach:

For matters requiring direct regulatory escalation, you may contact SDAIA directly via their official channels at sdaia.gov.sa.

Last Updated: 25/06/2026 | Policy ID: POL-010