This page displays the approved English version. An Arabic legal version will be published after company approval.
1 Purpose of This Privacy Policy
This Privacy Policy explains how Tadeed Strategic Services Company collects, uses, discloses, stores, and protects personal data in connection with Tadeed eInvoicing.
It applies to personal data processed through:
- the Tadeed eInvoicing website and applications;
- customer and user accounts;
- sales, onboarding, billing, support, and training;
- integrations, APIs, and security logs;
- marketing and business communications; and
- other interactions with Tadeed relating to the Service.
This Policy should be read together with the Terms of Service and any applicable Data Processing Addendum.
2 Data Controller and Contact Details
The responsible entity is:
Tadeed Strategic Services Company
Commercial Registration No.: 7051732423
VAT Registration No.: 314244812800003
7447 9th Street, Al Amamrah District
Dammam 32415, Eastern Province
Kingdom of Saudi Arabia
Email: info@tadeed.com
For certain Customer Data, the business Customer determines why and how personal data is processed and therefore acts as the controller. In those circumstances, Tadeed generally processes the data as a processor on the Customer's instructions. Individuals should first direct requests relating to such Customer Data to the relevant Customer.
3 Personal Data We Collect
Depending on your relationship with Tadeed and how the Service is used, we may collect:
3.1 Account and identity data
- name, job title, employer, user ID, and profile details;
- business email address, telephone number, and contact details;
- authentication information, password hash, multi-factor authentication details, and access status; and
- authority, role, permission, branch, and organisation assignments.
3.2 Business and regulatory data
- company name, address, Commercial Registration information, VAT number, and branch details;
- taxpayer and electronic invoicing configuration information;
- onboarding, certificate, integration, and compliance status; and
- authorised representative and administrator details.
3.3 Invoice and transaction data
- customer and supplier contact details;
- invoice recipient or buyer information;
- products, services, quantities, prices, taxes, discounts, payment status, and transaction references;
- quotations, invoices, credit notes, debit notes, expenses, purchase records, and reports; and
- XML, QR code, UUID, hash, cryptographic, clearance, reporting, and response data associated with electronic invoices.
Invoice data may relate to companies, establishments, sole traders, contacts, employees, customers, or other individuals, depending on the Customer's business.
3.4 Subscription and payment data
- plan, billing address, invoice history, payment status, and transaction identifiers;
- limited payment information received from payment providers; and
- bank transfer details or remittance records where provided.
Tadeed should avoid storing full payment-card data where payment processing is handled by an authorised payment provider.
3.5 Technical and usage data
- IP address, device type, browser, operating system, language, and time zone;
- login time, session identifiers, feature usage, page activity, and error information;
- audit logs, API calls, integration events, and security alerts; and
- cookie and similar technology data.
3.6 Communications and support data
- emails, support tickets, chats, call details, feedback, survey responses, and training records;
- attachments and screenshots submitted for support; and
- records of consent and communication preferences.
3.7 Data from third parties
We may receive data from:
- the Customer or its account administrators;
- ZATCA and other government systems where the Customer enables or authorises integration;
- payment, identity, communication, analytics, hosting, and support providers;
- authorised partners or resellers; and
- public business registers and lawful public sources.
4 Purposes and Legal Bases for Processing
Subject to applicable law, Tadeed may process personal data for the following purposes and legal bases:
| Purpose | Typical legal basis |
|---|---|
| Create and administer accounts | Perform a contract, take requested pre-contract steps, and pursue legitimate operational interests where permitted |
| Provide invoicing, reporting, storage, integrations, and support | Perform the Customer contract and process data on the Customer's instructions |
| Verify organisations, users, authority, tax settings, and transactions | Perform the contract, comply with legal obligations, and prevent fraud |
| Process subscriptions, payments, collections, and business records | Perform the contract and comply with legal and accounting obligations |
| Secure the Service, maintain audit logs, prevent misuse, and investigate incidents | Comply with legal obligations and pursue legitimate security interests where permitted |
| Communicate service notices, updates, and support information | Perform the contract and pursue legitimate service-management interests where permitted |
| Improve functionality, reliability, accessibility, and user experience | Legitimate interests where permitted, or consent where required |
| Send marketing communications | Consent or another lawful basis permitted by applicable law |
| Respond to lawful authority requests and exercise or defend legal claims | Comply with legal obligations and protect legal rights |
Where consent is the applicable legal basis, consent may be withdrawn at any time. Withdrawal does not affect processing already lawfully carried out before withdrawal.
Where Tadeed relies on legitimate interests, it will consider the nature of the data, reasonable expectations, necessity, and impact on individuals, and will not use this basis where the individual's rights and interests override those interests.
5 How We Use Personal Data
We may use personal data to:
- register, authenticate, and manage users;
- configure organisations, branches, roles, permissions, and subscriptions;
- generate, transmit, report, clear, validate, store, and retrieve invoice-related information as instructed;
- provide dashboards, reports, notifications, integrations, and API functions;
- process payments and maintain tax, financial, and contractual records;
- respond to enquiries, provide support, troubleshoot issues, and deliver training;
- monitor availability, performance, security, fraud, and compliance;
- maintain audit trails and investigate suspected misuse;
- back up, restore, test, update, and improve the Service;
- communicate material Service and policy changes;
- measure engagement and, where lawful, personalise user experience;
- send marketing communications in accordance with preferences and applicable law; and
- comply with legal obligations and enforce agreements.
Tadeed will not process personal data in a manner incompatible with the stated purpose unless permitted by applicable law and, where required, after providing notice or obtaining consent.
6 ZATCA and Government Integrations
When a Customer enables electronic invoicing integration, Tadeed may process and transmit invoice, taxpayer, device, certificate, cryptographic, reporting, clearance, and response data to or from ZATCA systems as required to perform the Customer's instructions.
ZATCA and other government bodies process data under their own legal authority and privacy practices. Tadeed does not control how a government authority processes information after lawful submission.
Customers are responsible for ensuring that information submitted through the Service is accurate, lawful, and appropriate for the relevant regulatory process.
7 Sharing and Disclosure
Tadeed may disclose personal data to:
- authorised Customer administrators and users;
- hosting, infrastructure, backup, security, monitoring, customer support, communication, analytics, implementation, and professional service providers;
- payment providers, banks, and collection service providers;
- ZATCA and other government authorities where directed, authorised, or legally required;
- auditors, insurers, legal advisers, accountants, and other professional advisers;
- authorised partners, resellers, or integration providers involved in delivering requested services;
- a purchaser, investor, affiliate, or successor in connection with a proposed or completed corporate transaction, subject to confidentiality and legal safeguards; and
- law enforcement, courts, regulators, or other parties where disclosure is required by law or necessary to establish, exercise, or defend legal claims.
Service providers are permitted to process personal data only for agreed purposes and must provide appropriate protection as required by applicable law.
Tadeed does not sell personal data.
8 International and Cross-Border Transfers
Tadeed aims to host and process data in locations appropriate for Saudi customers and regulatory requirements. Some service providers or support operations may process personal data outside the Kingdom of Saudi Arabia.
Before transferring personal data outside Saudi Arabia, Tadeed will assess and implement the requirements of the Saudi Personal Data Protection Law and the regulation governing personal data transfers outside the Kingdom. Depending on the circumstances, safeguards may include:
- confirming that a recognised legal condition for transfer applies;
- ensuring an adequate level of protection;
- using approved contractual safeguards or other recognised protections;
- carrying out a transfer risk assessment;
- limiting the data to what is necessary; and
- obtaining regulatory approval or an exemption where required.
Enterprise Customers may request available information about relevant hosting locations and subprocessors.
9 Data Retention
Tadeed retains personal data only for as long as necessary for the purpose for which it was collected and as required by law, contract, legitimate business needs, dispute handling, security, backup, and regulatory obligations.
Retention periods may differ by category:
- account data is generally retained while the account or subscription remains active and for a reasonable period afterwards;
- financial, tax, invoice, and contractual records may be retained for the period required by Saudi law;
- security, access, and audit logs are retained for a period proportionate to security, investigation, and compliance needs;
- support records are retained while needed to resolve issues, establish service history, and protect legal rights;
- marketing data is retained until consent is withdrawn, an objection is accepted, or it is no longer required; and
- backup copies may remain temporarily until overwritten under normal backup cycles.
When retention is no longer required, data will be securely deleted, destroyed, or anonymised, unless continued retention is legally permitted or required.
Customers are responsible for defining and applying lawful retention periods to Customer Data and for preserving independent statutory records.
10 Data Security
Tadeed applies reasonable technical and organisational safeguards appropriate to the nature of the personal data and associated risks. These may include:
- role-based access and least-privilege controls;
- secure authentication and password hashing;
- encryption in transit and, where appropriate, at rest;
- tenant separation and access validation;
- audit logging and activity monitoring;
- secure development, code review, testing, and vulnerability management;
- backups, recovery processes, and availability monitoring;
- incident response procedures;
- confidentiality obligations and personnel access controls; and
- vendor security and data protection assessments.
No method of electronic storage or transmission is completely secure. Users must protect their credentials, devices, sessions, exported files, and local copies and immediately report suspected unauthorised access.
11 Personal Data Breaches
Tadeed maintains procedures to assess and respond to suspected personal data breaches. Where notification is required, Tadeed will notify the competent authority and affected individuals in accordance with applicable Saudi law.
Where Tadeed acts as a processor for a Customer, it will notify the Customer of a relevant breach without undue delay after becoming aware and will provide reasonably available information to help the Customer meet its obligations.
12 Your Data Protection Rights
Subject to the Saudi Personal Data Protection Law, its Implementing Regulations, and applicable exceptions, individuals may have the right to:
- be informed about the legal basis and purpose of collecting their personal data;
- access their personal data;
- obtain their personal data in a clear and readable format;
- request correction, completion, or updating of inaccurate data;
- request destruction of personal data when the legal requirements are met;
- withdraw consent where processing is based on consent; and
- submit a complaint to the competent authority.
To exercise a right concerning data controlled directly by Tadeed, contact info@tadeed.com. We may request information necessary to verify identity and authority before responding.
If the request concerns data controlled by a Tadeed Customer—for example, information contained in that Customer's invoices or business records—the request should be directed to that Customer. Tadeed will reasonably assist the Customer where required.
Rights may be limited where retention or processing is required by law, necessary to protect another person's rights, or subject to another lawful exception.
13 Marketing Communications
Tadeed may send information about products, features, events, and offers where permitted by law. You may opt out using the unsubscribe method in the communication or by contacting Tadeed.
Opting out of marketing does not stop essential operational, billing, security, legal, or account communications.
14 Cookies and Similar Technologies
The website and Service may use:
- strictly necessary cookies for login, security, session management, language, and core functionality;
- preference cookies to remember settings;
- analytics cookies to understand usage and improve performance; and
- marketing cookies where used and permitted.
Where required, non-essential cookies will be used only after obtaining appropriate consent. Users can manage cookies through the available consent tool or browser settings. Disabling necessary cookies may prevent parts of the Service from functioning.
A separate Cookie Notice should identify the actual cookies and providers used before website publication.
15 Children's Data
The Service is intended for businesses and authorised professional users and is not directed to children. Tadeed does not knowingly collect children's personal data through independent account registration.
Customers must not submit children's personal data unless it is lawful, necessary for a legitimate business purpose, and supported by all required notices, permissions, safeguards, and guardian consent.
16 Automated Decision-Making and Artificial Intelligence
Tadeed may introduce automation or AI-assisted functions to help with classification, extraction, recommendations, anomaly detection, support, or workflow efficiency.
Tadeed will provide appropriate information and controls where such processing has a legal or similarly significant effect on individuals. Unless expressly stated, AI-assisted outputs are recommendations and should be reviewed by an authorised user before being relied upon for tax, accounting, legal, employment, credit, or other significant decisions.
Customer Data will not be used to train a general-purpose third-party AI model unless Tadeed has a lawful basis, implements appropriate safeguards, and provides any notice or obtains any consent required by law or contract.
17 Customer Responsibilities
Customers using Tadeed eInvoicing must:
- provide their own privacy notices to employees, customers, suppliers, and other individuals where required;
- establish a lawful basis for personal data entered into the Service;
- collect only data relevant and necessary for legitimate purposes;
- configure roles and access appropriately;
- respond to data-subject requests for Customer-controlled data;
- notify Tadeed promptly of inaccurate, unlawful, or compromised data;
- comply with retention, tax, employment, consumer, and sector-specific requirements; and
- avoid placing sensitive or unnecessary personal data in free-text fields or attachments.
18 Links and Third-Party Services
The Service may contain links to or integrations with third-party websites and services. Their privacy practices are governed by their own notices. Tadeed is not responsible for third-party privacy practices, but will assess service providers where required for Tadeed's own compliance.
19 Complaints
Questions or complaints about Tadeed's processing may be sent to info@tadeed.com. Please include sufficient details to identify the issue without sending unnecessary sensitive information.
Individuals may also have the right to complain to the competent data protection authority in the Kingdom of Saudi Arabia in accordance with the procedures and time limits prescribed by applicable law.
20 Changes to This Privacy Policy
Tadeed may update this Privacy Policy to reflect changes in law, technology, Service functionality, subprocessors, or data practices. The revised Policy will show the updated effective date.
Where a change materially affects how personal data is processed, Tadeed will provide notice through the Service, email, website, or another appropriate method and will obtain consent where required.
21 Contact Us
For privacy questions, requests, or complaints:
Tadeed Strategic Services Company
7447 9th Street, Al Amamrah District
Dammam 32415, Eastern Province
Kingdom of Saudi Arabia
Email: info@tadeed.com

