Privacy Policy — Wateer
1. Who we are
The Wateer platform is operated by Masarat Wateer for Information Technology Company (LLC), registered in the Kingdom of Saudi Arabia under Commercial Registration No. 1010795924, with its head office in Riyadh.
Wateer is a software platform for issuing, delivering, and managing digital invoices and receipts, serving merchants and their customers.
This policy explains how we collect, use, and protect your personal data, what your rights are, and how to exercise them. It complies with the Personal Data Protection Law issued by Royal Decree M/148 dated 05/09/1444 AH and its Implementing Regulation.
It covers our website, applications, interfaces, and every channel through which we collect your data.
2. Our legal role
Our role changes with your relationship to us:
| Situation | Wateer's role | Controller |
|---|---|---|
| You registered an account with Wateer directly | Controller | Wateer |
| You received an invoice from a merchant using Wateer, with no account | Processor on the merchant's behalf | The merchant |
| You are a subscribed merchant | Controller for your own data; processor for your customers' data | Depends on the data |
Where we act as a processor, we act on the merchant's documented instructions and within what the law permits. Requests about that data go to the merchant, and we will help you reach them.
3. Data Protection Officer
| Name | Yazeed Hassan Mohammed Zaidan |
| Role | Data Protection Officer |
| [email protected] | |
| Address | Masarat Wateer for Information Technology Company, Riyadh, Kingdom of Saudi Arabia |
You may write to the DPO directly about anything concerning your personal data, this policy, or the exercise of your rights.
4. Data we collect
Personal data is any information, whatever its source or form, that identifies you or makes you identifiable, directly or indirectly.
4.1 Data you give us
| Category | Contents | Mandatory / optional |
|---|---|---|
| Account data | Name, mobile number, email address | Mandatory to create an account |
| Credentials | Username and password | Mandatory to use the account |
| Merchant data | Commercial registration, VAT number, activity, address | Mandatory for merchants only |
| Identity verification | National ID, residency permit, or passport | Mandatory where the law requires it, or when you exercise a right that requires verification |
| Correspondence | What you provide when contacting support | Optional |
If you do not provide it: the items marked mandatory are necessary to deliver the service; without them we cannot create the account or provide the service. Withholding optional data does not affect your core service.
4.2 Data collected automatically
- Transaction and receipt data: the goods or services purchased, date and time, amount and payment method, merchant name and location, and the associated e-invoice data.
- Usage data: pages viewed, searches, time spent, navigation paths.
- Device data: operating system and version, manufacturer, browser type, device identifiers, IP address.
- Approximate location: the city or country inferred from your IP address. We do not collect your device's precise location without your explicit permission from your device settings, which you can withdraw at any time.
- Cookies: see section 9.
4.3 Data from external sources
If you choose to sign in through a third-party service (such as Google or Apple), we receive the registration data you authorise it to share. Those services are governed by their own privacy policies.
4.4 What we do not collect
- We do not collect or store credit card or bank account numbers. Payment data is processed directly by the payment service provider and never passes through our systems. We receive only the outcome of the transaction and its reference.
- We do not request access to your contacts, photos, videos, or files.
- We do not collect sensitive, health, or biometric data.
5. Purposes and legal bases
We process your data only where a valid legal basis exists:
| Purpose | Description | Legal basis |
|---|---|---|
| Delivering digital invoices and receipts | Getting your invoice to you, storing it, keeping it retrievable | Contract |
| Account creation and management | Creating your account and running its features | Contract |
| Customer support | Answering your questions and resolving issues | Contract |
| Tax and e-invoicing compliance | Meeting Zakat, Tax and Customs Authority requirements | Legal obligation |
| Responding to lawful requests | Complying with judicial and regulatory orders | Legal obligation |
| Platform security and fraud prevention | Protecting accounts, detecting abuse, keeping systems sound | Legitimate interest |
| Loyalty programme | Enrolling you and running the programme | Consent |
| Email marketing | Sending offers and news | Consent |
| SMS marketing | Sending offers by SMS | Consent |
| WhatsApp marketing | Sending offers via WhatsApp | Consent |
| Usage analytics | Measuring and improving platform performance | Consent |
What this means in practice:
- Contract: necessary to deliver the service. No separate consent is asked, and it cannot be refused while continuing to use the service.
- Legal obligation: required of us by law; neither we nor you have a choice.
- Legitimate interest: relied on for platform security only, after a documented balancing of our interest against your rights. You may object.
- Consent: entirely optional, never pre-ticked, and withdrawable at any time. Withdrawal does not affect the lawfulness of processing before it, and does not affect your core service.
6. Who we share your data with
We do not sell your personal data, rent it, or trade in it.
We may disclose it, to the extent necessary, to:
| Category | Purpose |
|---|---|
| The merchant you purchased from | Issuing your invoice and after-sales service |
| Hosting and cloud storage providers | Running the platform and storing data |
| Payment service providers | Settling payments (your card data never passes through our systems) |
| Messaging providers | Sending SMS, email, and WhatsApp messages |
| Analytics providers | Measuring performance, with your consent |
| Consent management provider | Recording your consents and issuing verifiable receipts |
| Competent authorities | Courts, government and tax authorities, and law enforcement, where legally required |
Every processor operates under a contract binding it to the limits of processing, to confidentiality, and to protective measures. An up-to-date list of processors is available at privacy.wateer.sa.
7. Transfers outside the Kingdom
We are committed to processing your data inside the Kingdom. It is not transferred abroad except in the cases permitted by the Personal Data Protection Law, its Implementing Regulation, and the Regulation on Personal Data Transfer outside the Kingdom — and then only after the required technical and organisational safeguards are in place, and only to the minimum extent necessary.
8. Retention periods
We keep your data for as long as the purpose requires, or for as long as the law requires, whichever is longer:
| Category | Period | Basis |
|---|---|---|
| Invoices and transaction records | 10 years | Commercial Books Law |
| Accounting and tax records | 6 years after the end of the tax period | VAT Implementing Regulation |
| Account, profile, and identity data | Subscription term + 90 days | Operational window for recovery and dispute resolution |
| Login and security audit logs | 12 months | Platform security and incident investigation |
| Call recordings | 180 days | Service quality and complaint resolution |
| Consent evidence records and receipts | Processing period + 5 years | Proof of compliance and the claim window |
| Analytics data | 14 months | Seasonal trend analysis |
When a period ends, we securely delete the data or convert it into a form that does not identify you. Withdrawing consent or deleting your account does not override statutory retention periods; in that case we keep only the minimum required.
9. Cookies
What follows describes what we actually use, not what we might:
| Category | What it is | Needs your consent? |
|---|---|---|
| Strictly necessary | Session and sign-in cookies, and protection of forms against forgery | No — the platform cannot run without them, and they cannot be refused while continuing to use it |
| Usage analytics | Measuring and improving site performance using an analytics tool we host on our own servers, which sets no cookies on your device and does not track you across other sites | Yes |
We do not currently use functional or marketing cookies, advertising pixels, or third-party tracking tools. If that changes, we will update this policy and ask for your consent before activating any of them.
On your first visit we present a clear choice: nothing beyond the strictly necessary is activated before you consent, no box is pre-ticked, and refusing is as easy as accepting. You can change your choice at any time at privacy.wateer.sa or in your browser settings.
10. Your rights
Under the Personal Data Protection Law, you have the right to:
| Right | What it means |
|---|---|
| Be informed | Know the legal basis for collecting your data and the purpose of it |
| Access | See the data we hold about you |
| Obtain a copy | Receive your data in a clear, machine-readable format |
| Rectification | Correct what is inaccurate, incomplete, or out of date |
| Destruction | Have your data deleted once it is no longer needed, subject to statutory retention |
| Withdraw consent | Stop any consent-based processing, at any time |
| Object | Object to processing based on legitimate interest |
How to exercise them: at privacy.wateer.sa after verifying your identity with your mobile number, or by writing to [email protected].
When we respond: within thirty (30) days of receiving the request. We may ask you to prove your identity first, to protect your data.
If we refuse: we will tell you why, on what legal basis, and how to appeal.
Complaints: if you believe your rights have been breached, write to [email protected] first. In all cases you may lodge a complaint with the Saudi Data & AI Authority (SDAIA) as the competent supervisory authority — you are not required to come to us first.
11. Information security
We apply appropriate technical, organisational, and physical measures, including:
- Encryption of data in transit and at rest
- Role-based access controls on a least-privilege basis
- Audit logs for sensitive operations
- Regular backups and a recovery plan
- Periodic security review and incident response procedures
Even so, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Your part: keep your credentials confidential and never share them. No member of our staff will ever ask you for your password or a verification code — any such request is an attempted fraud. Report it to us immediately.
12. Data breaches
If your personal data is leaked, damaged, or accessed without authorisation:
- We notify the Saudi Data & AI Authority within seventy-two (72) hours of becoming aware of the incident.
- We notify you without undue delay where the breach would cause damage to your data or conflict with your rights or interests.
- The notification states the nature of the incident, the data affected, the steps taken, and what you can do to limit the impact.
13. Minors and persons lacking capacity
Our services are not directed at anyone under eighteen or at persons lacking legal capacity. In those cases a parent or legal guardian consents on their behalf.
We do not knowingly collect minors' data. If you learn that we have collected a minor's data without their guardian's consent, write to [email protected] immediately and we will take the steps needed to delete it.
14. Call and correspondence monitoring
We may record support calls and electronic correspondence for quality, training, compliance, and fraud prevention. We tell you when recording begins, and you may object and continue through another channel. Recordings are kept for the period stated in section 8.
15. Automated decisions
We do not make decisions producing legal effects for you based solely on automated processing, and we do not profile you for evaluation purposes. If that changes, we will amend this policy, notify you in advance, and explain your right to human review.
16. Social media
We may communicate with you through social media platforms. What you post on our public pages may be visible to the public, so take care when sharing your data there. Those platforms are governed by their own policies, not this one.
17. Updates to this policy
We may update this policy. We notify you of material changes in advance by email or through an in-platform notice. The current version is always published with its version number and effective date, and previous versions remain available for reference.
18. Language
This policy is issued in Arabic and English. In the event of any discrepancy, the Arabic text prevails.
19. Contact us
| Purpose | Channel |
|---|---|
| Privacy, data protection, exercising rights | [email protected] |
| Privacy centre | privacy.wateer.sa |
| Support and general complaints | [email protected] |
| Marketing opt-out | [email protected] or the unsubscribe link in every message |
| Supervisory authority | Saudi Data & AI Authority (SDAIA) |