Privacy Policy

In brief

We collect only what we need to deliver our services. We never sell your personal information. We comply with Saudi laws and international best practices, and we give you meaningful control over your data.

Effective
11 November 2025
Last updated
11 November 2025
Jurisdiction
Saudi Arabia / SAMA
Standards
PCI DSS / GDPR principles
Section 01

Introduction

Welcome to Sellzr (“we,” “us,” “our”). We are committed to protecting your privacy and ensuring the security of your personal information across every interaction with our platform.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit sellzr.com and use our services. Sellzr is registered under the laws of Saudi Arabia, with its registered office at Ras Al Ain St, Al Rahmaniyah, Riyadh.

By accessing or using our website or services, you agree to the terms of this Privacy Policy. If you do not agree with the terms, please do not use our services.

Section 02

Compliance and regulatory framework

We operate under a dual framework — local Saudi regulations alongside international best practices — to ensure your information is handled with the highest standards regardless of where you engage with us.

SA

Saudi compliance

  • SAMA regulations for payment processing and financial data
  • Saudi e-commerce and consumer protection laws
  • Saudi data protection and privacy requirements
  • AML and Counter-Terrorism Financing regulations
INT

International standards

  • Payment Card Industry Data Security Standard (PCI DSS)
  • GDPR principles where applicable
  • Industry-standard SSL/TLS encryption protocols
  • Continuous monitoring and audit practices
Section 03

Information we collect

We collect information that is reasonably necessary to deliver our services, fulfill contracts, and meet regulatory obligations. The information falls into three broad categories.

Information you provide

Collected when you register, submit forms, purchase services, communicate with our team, or apply for company formation services.

A

Personal identification

Name, email, phone, postal address, date of birth, national ID or passport (when required for legal entity formation).

B

Business information

Company name, business type, industry, registration details, tax identification numbers.

C

Financial information

Billing address and payment method details, processed exclusively through secure, licensed payment gateways.

D

Professional & documentation

Job title, project details, business plans, licenses, identification documents, and contracts required for service delivery.

Automatically collected

When you access our platform, certain technical information is collected to ensure functionality, security, and to improve our services.

  • Device data — IP address, browser type, OS, device identifiers
  • Usage data — pages visited, time on pages, click patterns, features used
  • Technical data — cookies, log files, web beacons, session data
  • Location — general geographic location based on IP address

From third parties

We may receive information about you from payment processors (Stripe, HyperPay, PayTabs), business partners assisting with formation and legal services, government and regulatory databases for verification, publicly available sources for due diligence, and KYC/AML verification services.

Section 04

How we use your information

Information is processed strictly for defined operational, compliance, and improvement purposes. Each use is grounded in a lawful basis explained in Section 05.

  • Service delivery — Managing accounts, processing transactions, establishing legal entities, delivering consulting and training, and providing platform access Contract
  • Payment & security — Processing payments through licensed gateways, conducting KYC/AML checks, fraud prevention, and SAMA compliance Legal obligation
  • Communication — Responding to inquiries, sending service notifications, order confirmations, and important legal notices Contract
  • Operations & compliance — Improving services, ensuring platform security, maintaining records, internal audits, and quality assurance Legitimate interest
  • Marketing & development — Sharing relevant program announcements, market research, surveys, anonymized statistics — only where you have explicitly opted in Consent
Section 05

Legal basis for processing

Every act of processing your data has a defined lawful basis. We rely on the following grounds, each applied to specific contexts as described below.

Consent
When you have given explicit consent for specific purposes, including marketing communications, surveys, and certain optional features.
Contract
To fulfill our contractual obligations, including providing the services you requested, processing payments, and managing your account.
Obligation
To comply with applicable laws, including SAMA regulations, Saudi commercial laws, KYC/AML requirements, tax obligations, and regulatory requests.
Interest
For our legitimate operational interests, including fraud prevention, service optimization, internal analytics, and protecting our legal rights.
Section 06

How we share your information

We do not sell your personal information to third parties. Disclosure is limited to defined operational, regulatory, and consent-based circumstances.

Payment
Necessary information shared with licensed payment gateways (Stripe, HyperPay, PayTabs) using SSL/TLS encryption and PCI DSS standards.
Partners
Trusted service providers — lawyers, accountants, formation specialists, cloud hosting, KYC/AML services — all bound by confidentiality agreements.
Authority
Regulatory and government bodies for business registrations, licenses, compliance filings, court orders, and lawful enforcement requests.
Transfer
In the event of a merger, acquisition, or sale of assets, with prior notification to you of any such change in privacy practices.
Consent
With third parties when you provide explicit consent for specific purposes outside the scopes above.
Section 07

Data security

We implement comprehensive technical and organizational safeguards to protect your information, layered across infrastructure, processes, and people.

TECH

Technical safeguards

  • SSL/TLS encryption for all data in transit
  • PCI DSS compliance for payment processing
  • Encrypted databases and secure cloud infrastructure
  • Multi-factor authentication and role-based access
  • Firewalls and intrusion detection systems
  • Regular vulnerability assessments and penetration testing
ORG

Organizational safeguards

  • Employee training on data protection and confidentiality
  • Confidentiality agreements with staff and contractors
  • Data minimization and privacy-by-design principles
  • Incident response and breach notification procedures
  • Regular policy reviews and security audits
  • Continuous fraud detection and AML/KYC screening

A note on limitations: While we apply industry-standard security measures, no method of transmission or storage is 100% secure. We continuously work to protect your information and respond promptly to any incident.

Section 08

Data retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this policy, unless a longer period is required or permitted by law.

Data category
Retention period
Basis
Account information
Active + reasonable period
Service continuity
Transaction records
5 – 10 years
SAMA & commercial law
Business formation documents
Permanent / per jurisdiction
Legal requirement
Marketing communications
Until you unsubscribe
Consent
Technical logs
12 – 24 months
Security & analytics

When information is no longer needed, we securely delete or anonymize it in accordance with our data retention policies and applicable legal obligations.

Section 09

Your rights and choices

You retain meaningful control over your personal information. The following rights are available to you, free of charge, with responses typically within 30 days.

i.
Access & portability
Request access to your data and obtain a copy in a portable, commonly used format.
ii.
Correction
Update or correct inaccurate or incomplete personal information.
iii.
Deletion
Request deletion of your data, subject to SAMA, tax, or other legal retention requirements.
iv.
Restriction
Limit the ways in which we process your information in certain circumstances.
v.
Objection
Object to processing based on legitimate interests or for direct marketing.
vi.
Withdraw consent
Withdraw consent for any consent-based processing at any time.

To exercise any of these rights, please contact us at info@sellzr.com. For security purposes, we may need to verify your identity before fulfilling your request. If you are not satisfied with our response, you have the right to file a complaint with the relevant Saudi regulatory authority or your local data protection supervisory authority.

Section 10

Cookies and tracking

Cookies are small text files stored on your device that help us deliver and improve our services. We use four categories, each with a different purpose and consent requirement.

You can manage cookie preferences through your browser settings, our consent banner, or your account preferences. Disabling certain cookies may affect website functionality.

Section 11

International data transfers

As a business that establishes legal entities across multiple jurisdictions, we may transfer information internationally to deliver our services. All transfers are protected by appropriate safeguards.

Your information may be processed in countries other than Saudi Arabia, including jurisdictions where our service providers operate, where we establish legal entities on your behalf, and where our cloud infrastructure is hosted.

When transferring data internationally, we ensure protection through Standard Contractual Clauses (SCCs) approved by relevant authorities, adequacy decisions recognizing equivalent data protection standards, your explicit consent where required, and full compliance with SAMA regulations for cross-border data transfers.

Section 12

Children’s privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children.

If we become aware that we have collected information from a child without proper parental consent, we will take steps to delete that information promptly. If you believe we may have inadvertently collected information from a child, please contact us immediately at info@sellzr.com.

Section 13

Changes to this policy

We may update this Privacy Policy to reflect changes in our practices, services, legal requirements, or business operations.

Material changes will be communicated through prominent notices on our website, an updated “Last Updated” date at the top of this document, and email notifications to registered users for significant updates. For changes that significantly affect your rights, we may require your explicit consent before they take effect.

Your continued use of our services after changes are posted constitutes acceptance of the updated policy. We encourage you to review it periodically.

Section 14

Contact us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach our team through any of the channels below.

Data Protection Officer
Phone — Saudi Arabia
+966 51 171 7230
Phone — United States
+1 (564) 224-7776
Saudi Arabia office
Ras Al Ain St, Al Rahmaniyah
Riyadh, Saudi Arabia
US office
100 24th Street West #1-2468
Billings, MT 59102
United States
Response time
Within 30 days, or as required by applicable law