PRIVACY POLICY
Last Updated: Aug 2026
INVENTO (“INVENTO”, “we”, “us”) respects your privacy. This policy explains what personal data we collect through this website, why we collect it, who we share it with, and the rights you have under the Saudi Personal Data Protection Law (PDPL) and the regulations issued by the Saudi Data & Artificial Intelligence Authority (SDAIA).
This policy covers invento.sa only. It does not cover any separate product, platform or application operated by INVENTO, each of which carries its own terms.
- Who is responsible for your data
INVENTO is the Data Controller for the personal data described below.
- Address: 8646 King Abdulaziz Road, Al Ghadeer District, Riyadh 13311, Kingdom of Saudi Arabia
- Email: info@invento.sa
- Phone: +966 92 001 2387
- What we collect
We do not require you to create an account, and we do not sell personal data. We collect only what our forms and our security controls actually capture:
- When you send us a message (contact page or footer form): your name, email address, country dialling code and phone number, subject, and the content of your message.
- When you apply for a job (careers form): your name, email address, dialling code and phone number, your stated field of interest, and your CV, which must be a PDF of up to 10 MB.
- When you book a meeting (demo booking): your name, email address, dialling code and phone number, any notes you add, the time slot you select, and your time zone.
- Automatically, with every form submission: your IP address, browser user-agent, the browser’s preferred language, the referring page, and a short “journey” record — the site that referred you plus up to the last twelve pages you viewed on invento.sa in that browser tab. The journey record is held in your browser’s session storage and is discarded when you close the tab; it is sent to us only if you submit a form.
- Anti-spam technical fields: a page-load timestamp and a hidden field that must stay empty, both used to distinguish people from automated submissions. We also keep a short-lived counter to rate-limit submissions, keyed to a one-way cryptographic hash of your IP address rather than the address itself.
We do not ask for, and ask that you do not send us, national ID numbers, payment card details, health information, or any other sensitive personal data through this website.
- Why we use it, and our legal basis under the PDPL
- To answer your enquiry and to arrange and hold meetings — necessary to take steps at your request before entering into a contract, and to perform one where we have.
- To assess job applications — necessary to take steps at your request before entering into an employment relationship. We keep applications on file so we can consider you for later openings; tell us if you would rather we did not.
- To keep the site and our inboxes secure — our legitimate interest in preventing spam, fraud and abuse. This is the basis for the IP address, user-agent, referrer, journey record and rate-limiting described above.
- To measure our advertising and understand how the site is used — your consent, where consent is required for the cookies and similar technologies involved. See section 5.
- To meet legal and regulatory obligations — where a law that applies to us requires us to retain or disclose information.
- Who we share it with
We do not sell personal data and we do not share it for anyone else’s independent marketing. We use a small number of service providers who process data on our behalf:
- Microsoft — our email and our meeting-booking system run on Microsoft 365. When you book a meeting, your name, email address, phone number and notes are written to our Microsoft Bookings calendar and a Microsoft Teams link is created for the meeting.
- Google — we use Google Ads conversion measurement. A single conversion event is recorded when a meeting booking is confirmed. See section 5.
- Microsoft Clarity — a product analytics service that records how pages are used, so we can find and fix usability problems.
- Our hosting and email providers — who necessarily process the data in transit and at rest in order to serve the site and deliver our mail.
We may also disclose personal data where we are legally required to do so, or to establish, exercise or defend a legal claim.
Transfers outside the Kingdom. Some of the providers above are international and may process personal data outside Saudi Arabia. Where that happens, we rely on the transfer conditions permitted by the PDPL and its implementing regulations, and we share only what the provider needs to deliver its service.
- Cookies, analytics and advertising
The site sets no cookies of its own for advertising or profiling. The following third-party technologies are loaded:
- Google Ads (tag AW-18367506093) — measures the effectiveness of our advertising. It records a conversion only when a meeting booking is confirmed; it does not fire on ordinary page views.
- Microsoft Clarity (project v3esusz3c0) — records page interactions to help us improve the site.
You can block or delete cookies in your browser settings, and you can opt out of Google’s advertising personalisation through Google’s own ad settings. Blocking them does not stop you using the site or its forms.
- How long we keep it
- Enquiries and their replies — kept in our business inboxes for as long as needed to deal with the enquiry and the relationship that follows from it.
- Job applications and CVs — kept so we can consider you for future roles, unless you ask us to delete them.
- Meeting bookings — kept in our calendar system as a record of the meeting.
- Security and anti-spam records — the submission log is kept for a limited period for troubleshooting and abuse investigation. Rate-limiting counters expire within minutes.
Where we no longer have a purpose or a legal reason to keep personal data, we delete it.
- How we protect it
Our forms are served over HTTPS. Mail credentials and booking credentials are stored outside the public web root and are never published in our website’s source code. Form submissions are protected by same-origin checks, an automated-submission trap and per-address rate limiting. Access to the inboxes and the booking calendar is restricted to the INVENTO staff who need it.
No method of transmission or storage is completely secure, and we do not claim otherwise. If a personal data breach occurs, we will notify SDAIA and affected individuals as the PDPL requires.
- Your rights under the PDPL
Subject to the conditions and exceptions in the law, you have the right to:
- Be informed of the legal basis and purpose for collecting your personal data.
- Access your personal data held by us, and to obtain a copy of it.
- Request correction of personal data that is inaccurate, incomplete or out of date.
- Request destruction of your personal data where we no longer need it for the purpose it was collected for.
- Withdraw consent at any time, where our processing is based on your consent. Withdrawal does not affect processing already carried out.
To exercise any of these rights, email info@invento.sa. We may need to verify your identity before we act. If you are not satisfied with our response, you may lodge a complaint with the Saudi Data & Artificial Intelligence Authority (SDAIA).
- Children
This website is aimed at businesses and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
- Links to other sites
Our pages link to other websites, including our own product sites and our social media profiles. This policy does not apply to them; please read the privacy policy of any site you visit.
- Changes to this policy
If we change this policy we will update the “Last Updated” date above. Material changes will be made clear on this page.
- Contact
Questions about this policy, or about how we handle personal data:
- Email: info@invento.sa
- Phone: +966 92 001 2387
- Address: 8646 King Abdulaziz Road, Al Ghadeer District, Riyadh 13311, Kingdom of Saudi Arabia
