iRazzh is committed to handling every piece of personal and business data it holds with legal precision, proportionality, and purpose. We keep data for as long as we genuinely need it, whether to deliver our services, honor legal obligations, or protect legitimate interests, and no longer.
This policy has two connected parts.
Part A sets out how long iRazzh retains different categories of personal and business data, and how data is disposed of when that period ends.
Part B explains how iRazzh identifies, contains, and reports a personal data breach, and what affected individuals can expect if a breach occurs.
This policy governs how long iRazzh holds personal and business data, how it is disposed of when it is no longer needed, and what iRazzh does step-by-step when a data breach occurs. It operates alongside Section 9 and Section 10 of the Privacy Policy (POL-002), which should be read together with this document.
This policy is issued in compliance with the Personal Data Protection Law (PDPL, Royal Decree M/19 as amended by M/148), SDAIA breach notification requirements, ZATCA data retention mandates, Saudi AML law, and the E-Commerce Law.
iRazzh retains personal and business data only for as long as is necessary for the purpose for which it was collected, consistent with contractual obligations and the applicable Saudi legal requirements for each data category. At the end of the applicable retention period, data is securely deleted or irreversibly anonymized using methods that prevent reconstruction of the original personal data.
Where a retention period in this policy exceeds the period published in the Privacy Policy's Section 9 table, the longer period governs, and the Privacy Policy will be updated at the next scheduled review to reflect any correction. Where a legal requirement establishes a minimum retention period that exceeds the period otherwise needed for operational purposes, the legal minimum governs.
| Data Category | Retention Period | Legal Basis or Reason |
| Account and identity data | Duration of account plus 3 years post-closure | PDPL; E-Commerce Law; general contractual obligations |
| Order and transaction records | 10 years from the date of the transaction | ZATCA mandatory minimum for tax and e-invoice records |
| VAT and e-invoice records | 10 years from the date of issue | ZATCA mandatory minimum |
| Payment data (tokenized card references) | 3 years since the last transaction | PCI-DSS alignment; SAMA payment processing guidelines |
| Customer support records | years from case closure | PDPL: potential dispute or litigation period |
| Marketing consent records | Duration of consent plus 3 years | PDPL; evidence of lawful processing basis |
| Cookie and tracking data | Maximum 12 months | Cookie Policy; PDPL proportionality principle |
| Vendor KYC documentation | Duration of relationship plus 10 years | Saudi AML Law — minimum ten-year retention for due-diligence records on business clients |
| Vendor transaction and commission records | 10 years from the date of transaction | ZATCA; Vendor Agreement obligations |
| Data breach records and investigation documentation | Minimum 5 years from the date of the incident | PDPL; SDAIA incident record-keeping guidelines |
The retention period for Vendor KYC documentation has been set at the duration of the relationship plus 10 years, consistent with Saudi AML requirements that mandate a minimum ten-year retention period for client due diligence records.
This supersedes any shorter period that may have been communicated to Vendors during earlier onboarding processes. All active Vendor KYC records are subject to this ten-year post-relationship minimum from the date the relationship ends.
Data holdings are reviewed at least annually to identify data that has reached the end of its applicable retention period. Data confirmed as past its retention period is:
Where a retention period is extended beyond the standard schedule, for example, because data is relevant to an ongoing complaint, dispute, regulatory inquiry, or litigation, the extension is logged internally, and the data is flagged for review at the conclusion of the relevant proceeding.
The retention periods in Section 2 of this policy are the authoritative, complete version of iRazzh's data retention schedule. The Privacy Policy (Section 9) sets out a summary of the same retention periods for the purpose of consumer transparency. In the event of any discrepancy between the two documents, this policy's table governs, since it incorporates legal basis references and is reviewed at a more granular operational level.
A personal data breach is any security incident resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data held or processed by iRazzh. This includes incidents affecting data processed by iRazzh's third-party service providers on iRazzh's behalf.
A breach does not need to involve malicious intent to meet this definition; accidental deletion, unintended disclosure, or misdirected communications containing personal data all qualify and must be treated in accordance with this policy.
Any iRazzh employee, contractor, or Vendor who becomes aware of, or reasonably suspects, a potential data breach must report it immediately and in all cases within 2 hours of becoming aware, to:
No external communication about a suspected or confirmed breach may be made by any individual employee, contractor, or Vendor before the Data Protection Officer (DPO) has been notified and has assessed the situation. This restriction applies regardless of the severity or apparent scope of the incident at the time of initial awareness.
Upon receiving a breach report, the DPO or nominated deputy initiates internal escalation, including:
The DPO and the relevant technical team conduct an initial assessment to determine:
The outcome of this assessment determines the priority of containment action and the applicable notification timelines.
Containment measures are implemented promptly and proportionately to the nature of the breach, including as applicable:
In accordance with Article 24 of the PDPL Implementing Regulations, IRazzh notifies SDAIA of a personal data breach within 72 hours of becoming aware of the incident.
This obligation applies to all breaches — the 72-hour notification window to SDAIA is not conditional on a finding that the breach has caused, or is likely to cause, harm to data subjects. The harm threshold applies only to the obligation to notify affected individuals directly (Stage 5 below), not to the SDAIA notification itself.
The SDAIA notification is submitted through SDAIA's official Personal Data Breach Notification Service (accessible at sdaia.gov.sa) and includes, at a minimum:
Where it is not possible to provide all required information within 72 hours, iRazzh provides available information within that window and supplements it as soon as the additional information becomes available.
Where the breach poses a high risk to the rights or interests of specific individuals, for example, where sensitive personal data, financial data, or identity credentials have been exposed, iRazzh notifies affected individuals directly, without undue delay, by:
The individual notification is written in plain, accessible language and includes:
Following containment and notification, iRazzh conducts a full post-breach review to:
Non-compliance with PDPL data protection obligations carries significant consequences. iRazzh publishes this information transparently so that its operational teams understand the stakes of handling personal data correctly:
These are the consequences of non-compliance with the PDPL as currently enforced by SDAIA and are published here for transparency and internal awareness. This Section does not create any new obligation or commitment on the part of iRazzh to affected individuals beyond those already set out in the PDPL itself.
iRazzh implements technical and organizational measures to protect personal data to the greatest reasonably practicable extent.
No system is entirely immune to sophisticated attacks or human error. In the event of a breach caused by a third-party processor, iRazzh will enforce that processor's contractual security obligations under the PDPL and the applicable processing agreement.
iRazzh reviews this policy at least annually, and promptly following any material change in the PDPL, ZATCA requirements, AML retention rules, or SDAIA's published breach notification guidance. Material changes will be communicated via email and in-app notification at least
For questions about data retention, or to report a suspected data breach:
For matters requiring direct regulatory escalation, you may contact SDAIA directly via their official channels at sdaia.gov.sa.