Privacy Policy
Fintilty Home | Effective Date: 27/09/2026 | Fintilty Technologies Company
This privacy policy applies to the Fintilty Home application (hereby referred to as the “Application”) for mobile devices, created by Fintilty Technologies Company (hereby referred to as the “Service Provider”) as a Commercial service. This service is intended for use “AS IS”.
Introduction
This privacy policy applies to the Fintilty Home application (hereby referred to as the “Application”) for mobile devices, created by Fintilty Technologies Company (hereby referred to as the “Service Provider”) as a Commercial service. This service is intended for use “AS IS”.
Fintilty Home is a household management application that allows home owners and household staff members to sign in securely, access a household dashboard, and manage tasks, requests, records, and documents in one place. This policy explains what information the Application collects, how it is used, and the rights available to you.
Account Types and Roles
The Application supports two categories of users, and the information processed differs by role:
Home Owner: creates and administers the household account, adds and manages staff members, and has visibility over household tasks, requests, and records.
Staff Member: is added to an existing household account by the home owner, and accesses the tasks, requests, and documents assigned to them.
Where a home owner enters or uploads information relating to a staff member, the home owner is responsible for ensuring that they have a lawful basis to do so and that the staff member has been informed of this policy. The Service Provider processes such data on behalf of the household account.
Information Collection and Use
The Application collects information when you download, register for, and use it. This information may include:
Registration and Identity Data: your full name, email address, mobile number, Iqama or national identity number where used for sign-in, and account password (stored only in hashed form).
Household Data: household or home name, address or location details you choose to enter, and household member records.
Operational Data: tasks, requests, assignments, statuses, notes, schedules, and household records created within the Application.
Attachments: images and PDF documents that you choose to upload from your device as supporting files.
Profile Data: profile photo, contact details, and account preferences that you add or edit.
Verification Data: one-time passwords (OTP) and password reset requests sent to your email or mobile number.
Technical Data: your device’s Internet Protocol (IP) address, device and operating system information, the screens of the Application you visit, the time and date of your visit, and the time spent on those screens.
Attachments and Device File Access
The Application allows you to attach images and PDF documents when adding photos, records, or supporting files. These files are selected by you from your device’s existing media library or document storage.
The Application does not request or require camera permission and does not capture photographs or video directly.
The Application accesses only the specific files you select through your device’s file or media picker. It does not scan, index, or browse your wider media library or file system.
Uploaded attachments are stored securely and are visible only to authorized members of the household account to which they were uploaded.
You should not upload documents containing information you do not wish to share with the other authorized members of your household account. You may delete attachments you have uploaded at any time, subject to the retention periods described below.
Secure Access and Authentication
Sign-in is performed using your email address, mobile number, or Iqama number together with a password. Home owners may create a household account and add staff members to it. Passwords are stored in hashed form and are not accessible to the Service Provider in plain text. You are responsible for maintaining the confidentiality of your credentials and for all activity that occurs under your account.
Communication
The Service Provider may use the information you provided to contact you from time to time to provide you with important information, required notices, service and security alerts, invitation and verification messages, and marketing promotions. You may opt out of marketing communications at any time; service, security, and transactional messages are necessary to operate your account and cannot be opted out of while the account remains active.
For a better experience, while using the Application, the Service Provider may require you to provide certain personally identifiable information. The information the Service Provider requests will be retained by them and used as described in this privacy policy.
Legitimate Interests and Processing Bases
Personal data processing is undertaken on the following legal bases:
Contractual Necessity: processing necessary to create your account, operate the household dashboard, and deliver the service you have requested.
Legal Obligation: processing required by applicable laws, regulations, court orders, or government requests, including the Saudi Personal Data Protection Law.
Legitimate Interests: processing pursued for legitimate business interests including fraud prevention, security, product improvement, analytics, and business operations, where such interests are not overridden by your privacy rights.
Consent: processing based on your explicit, informed, and freely given consent, which you may withdraw at any time.
Vital Interests: processing necessary to protect the vital interests of you or another natural person.
Third Party Access
Only aggregated, anonymized data is periodically transmitted to external services to aid the Service Provider in improving the Application and their service. The Service Provider may also share your information with third parties in the ways described in this privacy statement, including with cloud hosting and storage providers, email and SMS delivery providers, analytics providers, and customer support platforms, each acting under written instructions and confidentiality obligations.
Within a household account, information is shared between the home owner and the staff members of that household in line with their assigned roles and permissions. The Service Provider does not sell personal data.
Data Processors and Vendor Management
The Service Provider may engage third-party data processors and service providers to process personal information on its behalf. These processors are bound by written Data Processing Agreements (DPA) that ensure they: (a) process personal data only on documented instructions from the Service Provider; (b) maintain appropriate technical and organizational security measures; (c) implement data protection by design principles; (d) maintain detailed records of processing; (e) notify the Service Provider of data breaches; and (f) cooperate with supervisory authorities.
All processors are subject to strict confidentiality obligations and are prohibited from processing personal data for their own purposes. The Service Provider remains responsible and liable for any processor failure to comply with data protection obligations.
Data Retention and Deletion
The Service Provider retains user data for as long as necessary to provide services and fulfill the purposes outlined in this privacy policy. Once you delete your account or request data deletion, the Service Provider will remove your personal information from active databases within 30 days, except where retention is required by law or for legitimate business purposes. Backup copies may be retained for up to 90 days following deletion to ensure recovery capabilities.
Different categories of data are retained according to the following schedules:
Account profile data: retained for the duration of the active account plus 1 year.
Household records, tasks, and requests: retained for the duration of the household account plus 1 year, or until deleted by the home owner.
Uploaded attachments: retained until deleted by an authorized household member, or until deletion of the household account.
Support communications: retained for 3 years, or until issue resolution plus 6 months.
System and security logs: retained for 90 days.
Analytics data: aggregated data retained indefinitely; individual-level data deleted after 24 months.
Marketing data: retained until opt-out or 2 years of inactivity, whichever is sooner.
Where a household account is deleted, staff members linked to that household lose access to its records. Data subject to legal holds or litigation remains exempt from automatic deletion until the hold is lifted or proceedings conclude.
Security Measures
The Service Provider is committed to protecting your personal information through industry-standard security measures, including but not limited to:
Encryption of data in transit using HTTPS and TLS protocols.
Encryption of sensitive data and uploaded attachments at rest.
Hashed password storage and secure one-time password (OTP) verification.
Role-based access control separating home owner and staff member permissions.
Regular security audits, vulnerability assessments, and penetration testing.
Restricted access to personal data by authorized personnel only.
Regular backup procedures to prevent data loss.
However, no system is 100% secure. While the Service Provider implements comprehensive security measures, they cannot guarantee absolute security of your information. Any transmission of data is at your own risk.
Your Privacy Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Right to be Informed: you may request information on how and why your personal data is processed.
Right to Access: you can request a copy of the personal data the Service Provider holds about you.
Right to Correction: you can request correction of inaccurate or incomplete personal data.
Right to Deletion: you can request deletion of your personal data under certain circumstances.
Right to Data Portability: you can request your data in a machine-readable format suitable for transfer to another service provider.
Right to Opt-Out: you can opt out of marketing communications and certain non-essential data processing.
Staff members may exercise these rights in respect of their own personal data. Requests concerning household records created by a home owner may need to be directed to that home owner, who controls the content of the household account. To exercise these rights, please contact the Service Provider using the information in the Contact Information section below.
Procedures for Exercising User Privacy Rights
To exercise any privacy rights, users must submit a written request to support@fintilty.com including: (a) your full legal name; (b) current email address and mobile number; (c) a specific description of your request and the affected data categories; (d) proof of identity; and (e) any relevant account information.
The Service Provider will verify your identity before processing your request. Following verification, the Service Provider will respond within the timeframe specified by applicable law (typically 30 calendar days). Requests may be refused if they are manifestly unfounded, excessive, duplicative of recent requests, or technically unfeasible; in such cases the Service Provider will provide a detailed explanation and information about available remedies.
Cookies and Tracking Technologies
The Application and any associated web portal may use cookies and similar tracking technologies to maintain sessions, remember preferences, and measure usage. These include session cookies, persistent cookies, and analytics cookies. You can control cookie settings through your browser preferences; however, disabling cookies may affect the functionality of the Application.
Children’s Privacy
The Application is intended for use by adults managing a household and is not directed at children. The Service Provider does not knowingly collect personal information from individuals under the age of 18, or the minimum age of digital consent in your jurisdiction, whichever is higher. If the Service Provider becomes aware that personal information of a child has been collected, it will take immediate steps to delete such information and terminate the associated account.
Parents or guardians who believe their child has provided information to the Service Provider should contact them immediately using the contact information below.
Third-Party Links and Services
The Application may contain links to third-party websites, applications, and services that are not operated by the Service Provider. This privacy policy applies only to the Application. The Service Provider is not responsible for the privacy practices of third-party services, and we encourage you to review their privacy policies before providing any personal information.
International Data Transfer
Your personal information may be processed and stored in countries other than your country of residence, which may have data protection laws that differ from your home country. Where the Service Provider transfers personal data internationally, it implements appropriate legal mechanisms including Standard Contractual Clauses, adequacy decisions by competent authorities, or your explicit consent, in accordance with the Saudi Personal Data Protection Law and its Implementing Regulations. By using the Application, you consent to such transfers for the purposes described in this privacy policy.
Data Breach Notification and Incident Response
In the event of a data breach or security incident that compromises the confidentiality, integrity, or availability of personal information, the Service Provider will undertake immediate investigation and remediation efforts in accordance with applicable data protection regulations.
Users and affected individuals will be notified of any data breach without unreasonable delay, typically within 72 hours of discovery when required by law. The notification will include: (a) the nature of the breach and the categories of personal data affected; (b) the likely consequences; (c) measures taken or proposed to address the breach and mitigate harm; (d) a contact point for further information; and (e) recommendations for protective measures individuals can take. For significant breaches, the Service Provider will also notify the relevant supervisory authorities and maintain detailed records of all security incidents.
Privacy by Design and Impact Assessment
The Service Provider is committed to implementing privacy by design and by default throughout all processing activities, meaning data protection considerations are integrated into every stage of system development and operations. For processing activities that pose high risks to individuals’ rights and freedoms, the Service Provider conducts Data Protection Impact Assessments (DPIA) covering systematic evaluation of the processing operation, assessment of necessity and proportionality, risk analysis and mitigation strategies, and consultation with relevant stakeholders when appropriate.
Automated Decision-Making and Profiling
The Service Provider may use automated processing to detect security threats, prevent fraud, and personalize the user experience. You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects concerning you, except where such processing is necessary for contract performance, required by law, or based on your explicit consent. Where automated decision-making is used, you have the right to request information about the logic involved, request meaningful human review, and contest the decision.
Regulatory Compliance Framework
The Service Provider complies with the Saudi Personal Data Protection Law issued under Royal Decree No. M/19 and its Implementing Regulations, together with other applicable data protection regulations in the jurisdictions in which the Application is offered, which may include GDPR (EU/UK), CCPA (California), PIPEDA (Canada), and PDPA (Singapore). Users in regulated jurisdictions may have additional rights specific to those regulations, and the Service Provider will provide jurisdiction-specific privacy notices where required by law.
Changes to This Privacy Policy
The Service Provider may update this privacy policy from time to time to reflect changes in its practices, technology, legal requirements, and other factors. The updated version will be posted on the Application with the “Effective Date” updated accordingly. Continued use of the Application following any changes constitutes your acceptance of the modified privacy policy. For significant changes that affect your rights, the Service Provider will provide additional notice, such as through email or a prominent notice within the Application.
Contact Information and Data Subject Requests
For any privacy inquiries, data subject access requests, complaints, or other matters related to this Privacy Policy, please contact:
Fintilty Technologies Company — Email: support@fintilty.com
Please allow up to 30 days for a response to data subject access requests.