Guardian Industries Company Limited (“Guardian”, “Company”, “we”, “us” or “our”) respects the privacy of individuals whose Personal Data we process. This Privacy Policy explains how Guardian collects, uses, stores, discloses, transfers, protects and destroys Personal Data through its corporate website, digital inquiry channels and related business communications.
Regulatory framework. This Policy is intended to operate in accordance with the Personal Data Protection Law of the Kingdom of Saudi Arabia (PDPL), its Implementing Regulations, applicable regulations governing transfers of Personal Data outside the Kingdom, and other applicable Saudi laws and regulatory requirements. If any provision of this Policy conflicts with mandatory law, the mandatory law shall prevail.
1. Controller and Contact Details
Guardian Industries Company Limited, headquartered in Dammam, Kingdom of Saudi Arabia, acts as Controller where it determines the purposes and means of Processing Personal Data covered by this Policy.
Privacy and Personal Data inquiries may be directed to: info@guardianind.com. Guardian may request reasonable information to verify the identity and authority of a person making a rights request.
2. Scope of this Policy
This Policy applies to Personal Data collected through Guardian’s corporate website, inquiry or contact forms, email communications generated through the website, tender/RFQ communications initiated through digital channels, and technical or security logs generated in connection with website use.
This Policy does not replace privacy notices or contractual data-protection provisions that may apply to employees, job applicants, suppliers, subcontractors, customers, project personnel or other categories of Data Subjects where Guardian provides a separate notice or enters into specific contractual arrangements.
3. Definitions
“Personal Data” means data that identifies, or may directly or indirectly identify, an individual, as defined under applicable Saudi law.
“Data Subject” means the individual to whom Personal Data relates.
“Processing” includes collection, recording, organization, storage, modification, retrieval, use, disclosure, transfer, sharing, blocking, erasure and destruction of Personal Data.
“Controller” and “Processor” have the meanings assigned to them under the PDPL and its Implementing Regulations.
4. Personal Data We May Collect
Depending on the manner in which you interact with Guardian, we may collect the following categories of Personal Data:
- Identity and professional information: name, job title, employer, department, professional role and authority.
- Business contact information: business email address, telephone number, office address and other contact details.
- Inquiry and commercial information: RFQs, tender references, project names, requirements, correspondence, quotations requested and information you voluntarily provide.
- Technical and project information: specifications, BOQs, drawings, schedules, site or infrastructure requirements and related attachments submitted to Guardian. Such materials may contain Personal Data even when primarily technical or corporate in nature.
- Website and technical information, where generated by Guardian’s website or service providers: IP address, browser/device information, date and time of access, pages requested, referring information, security logs, error logs and similar technical identifiers.
- Records of communications: correspondence, requests, complaints, rights requests and records reasonably necessary to administer business relationships and protect Guardian’s legal interests.
5. Information You Should Not Submit Through Ordinary Website Channels
Unless Guardian has expressly authorized an appropriate transmission method, users should not submit through ordinary website forms or general email channels:
- passwords, access credentials, encryption keys or privileged account information;
- classified, restricted or national-security-sensitive information;
- detailed vulnerability information, security weaknesses or information that could facilitate unauthorized access to critical infrastructure;
- Sensitive Data that is not necessary for the stated business purpose; or
- third-party confidential, proprietary, export-controlled or otherwise restricted material that the sender is not authorized to disclose.
Guardian may take reasonable steps to isolate, restrict access to, return, delete or otherwise handle unsolicited sensitive or restricted material in accordance with applicable law, contractual obligations and legitimate security requirements.
6. Sources of Personal Data
Guardian may obtain Personal Data directly from you; from the organization you represent; from authorized representatives, customers, EPC contractors, consultants, suppliers or project partners; from publicly available or lawfully accessible professional sources; and automatically through website/security infrastructure where applicable. Collection from sources other than the Data Subject will be undertaken only where permitted by applicable law.
7. Purposes of Processing
Guardian may Process Personal Data for purposes including:
- receiving, assessing and responding to commercial inquiries, RFQs, tenders and requests for quotations;
- preparing technical and commercial estimates, proposals and clarifications;
- performing, administering and supporting engineering, procurement, construction, installation, testing, commissioning, maintenance and related contracts;
- communicating with customers, consultants, EPC contractors, suppliers, subcontractors and project stakeholders;
- managing vendor, supplier and business-partner relationships;
- maintaining website functionality, availability, integrity, cybersecurity, fraud prevention and abuse detection;
- maintaining business, project, compliance, audit and transaction records;
- establishing, exercising or defending legal claims and protecting Guardian’s rights, property, personnel, systems and legitimate business interests;
- complying with applicable laws, regulations, court orders, governmental requirements and lawful requests of competent authorities; and
- other compatible or legally permitted purposes communicated to the Data Subject where required.
8. Legal Bases for Processing
Guardian will Process Personal Data only where a lawful basis exists under applicable Saudi law. Depending on the circumstances, this may include consent, performance or implementation of an agreement, compliance with a legal obligation, or Guardian’s legitimate interests where permitted and where the rights and interests of the Data Subject are appropriately considered. Where consent is the applicable basis, withdrawal of consent will be handled in accordance with applicable law and will not affect Processing lawfully carried out before withdrawal.
9. Data Minimization and Accuracy
Guardian seeks to collect Personal Data that is adequate, relevant and limited to what is necessary for the stated purpose. Guardian may take reasonable steps to verify that Personal Data is accurate, complete, current and relevant to the purpose for which it is Processed. Data Subjects are encouraged to notify Guardian when their professional contact information changes.
10. Disclosure and Categories of Recipients
Guardian does not sell Personal Data. Subject to applicable law and the purpose for which the information was collected, Guardian may disclose or make Personal Data available to:
- authorized Guardian personnel and, where applicable, affiliated or group entities that require the information for legitimate business purposes;
- customers, consultants, EPC contractors, project companies, suppliers, subcontractors, system integrators and engineering partners where necessary for project or commercial activities;
- website hosting, IT, cybersecurity, communications, cloud, backup, professional and other service providers acting under appropriate contractual or legal obligations;
- banks, insurers, auditors, accountants, legal advisers and other professional advisers where reasonably necessary;
- competent Saudi governmental, regulatory, judicial, law-enforcement or national-security authorities where disclosure is required or permitted by law; and
- parties involved in a corporate restructuring, merger, acquisition, financing, asset transfer or similar transaction, subject to applicable legal safeguards.
Guardian will not disclose Personal Data where such disclosure is prohibited by applicable law. Recipients are expected to process Personal Data only for authorized purposes and subject to applicable confidentiality, security and data-protection obligations.
11. International Transfers
Guardian does not represent that every Processing activity necessarily occurs only within the Kingdom. Where Personal Data is transferred, disclosed or otherwise Processed outside the Kingdom of Saudi Arabia, Guardian will seek to do so only where permitted by the PDPL, its Implementing Regulations and applicable transfer regulations, and subject to the required conditions, safeguards, assessments, contractual measures or exemptions, as applicable. Transfers will be limited to what is reasonably necessary for the relevant purpose.
12. Retention and Destruction
Guardian retains Personal Data only for as long as reasonably necessary to fulfil the purpose for which it was collected and to satisfy applicable contractual, legal, regulatory, accounting, audit, project-record, dispute-resolution and legal-claims requirements. Where the purpose has ended and no lawful basis requires continued retention, Personal Data will be destroyed, erased or anonymized in accordance with applicable law and Guardian’s applicable retention and destruction procedures. Specific retention periods may vary by record type and legal or contractual requirement.
13. Information Security
Guardian applies organizational, administrative and technical measures intended to protect Personal Data against unauthorized access, disclosure, alteration, loss, misuse or destruction, taking into account the nature of the information and relevant risks. No website, network, email system or method of electronic transmission can be guaranteed to be completely secure. Users are responsible for using appropriate security measures when transmitting information to Guardian.
14. Personal Data Breaches
Where Guardian becomes aware of a Personal Data breach, damage or unlawful access, Guardian will assess and handle the incident in accordance with applicable Saudi law, including notifications to the competent authority and affected Data Subjects where legally required.
15. Data Subject Rights
Subject to the PDPL, its Implementing Regulations, applicable exceptions and verification requirements, a Data Subject may have rights including:
- the right to be informed of the legal basis and purpose of collection;
- the right to access Personal Data held by Guardian;
- the right to request a copy of Personal Data in a readable and clear format, where applicable;
- the right to request correction, completion or updating of Personal Data;
- the right to request destruction of Personal Data when the applicable legal conditions are satisfied; and
- where Processing is based on consent, the right to withdraw consent in accordance with applicable law.
Requests may be submitted to info@guardianind.com. Guardian may request proof of identity, authority or additional information reasonably necessary to process the request and may restrict or refuse a request where permitted or required by law.
16. Cookies and Similar Technologies
Guardian’s website may use cookies, server logs or similar technologies that are necessary for website functionality, security, performance or analytics. The exact technologies used may change as the website is maintained. Where applicable law requires notice or consent for a particular technology, Guardian will implement appropriate notice or consent mechanisms. Users may also control certain cookies through browser settings, although disabling necessary technologies may affect website functionality.
17. Third-Party Websites and Services
The website may contain links to third-party websites or services. Guardian does not control and is not responsible for the privacy, security, availability, accuracy or practices of third-party websites. Users should review the applicable third party’s privacy notice before providing Personal Data.
18. Children
Guardian’s corporate website and services are directed to business and professional users and are not intended to solicit Personal Data from children. If Guardian becomes aware that Personal Data of a child has been submitted through the website without an appropriate legal basis or authorization, Guardian may take steps to delete or otherwise lawfully handle that information.
19. Changes to this Privacy Policy
Guardian may amend this Privacy Policy from time to time to reflect changes in law, regulation, technology, business practices or website functionality. The revised version will be published on the website with an updated ‘Last Updated’ date. Material changes will be communicated where required by applicable law.
20. Complaints and Contact
Questions, complaints and requests relating to this Policy or Guardian’s Processing of Personal Data may be submitted to:
| Controller | Guardian Industries Company Limited |
| Location | Dammam, Kingdom of Saudi Arabia |
| info@guardianind.com |
Data Subjects may also have the right to submit a complaint to the competent Saudi authority in accordance with applicable law.
21. Legal Interpretation
This Policy is intended to provide transparency regarding Guardian’s Processing of Personal Data and does not create contractual rights beyond those provided by applicable law or an executed agreement. Nothing in this Policy limits any right that cannot lawfully be limited or excludes any obligation imposed on Guardian by mandatory law.