Let's Tie logo Let's Tie
Home About Services Why Us The Group Contact
Contact Us

\ Legal

Privacy Policy

This policy explains what personal data Let's Tie collects, why we collect it, how we protect it, who we share it with, and the rights you have over it.

Last updated: 19 August 2026

On this page

  1. 1. Introduction
  2. 2. Who we are
  3. 3. What we collect
  4. 4. How we use it
  5. 5. Our legal basis
  6. 6. Cookies & third parties
  7. 7. Sharing your data
  8. 8. International transfers
  9. 9. Security
  10. 10. How long we keep it
  11. 11. Your rights
  12. 12. Children's privacy
  13. 13. Changes
  14. 14. Contact us

Draft pending legal review. Every item highlighted in red below is a placeholder that must be replaced with real details, and this document should be reviewed by a Saudi-qualified lawyer against the Personal Data Protection Law (PDPL) before it is published.

1. Introduction

Let's Tie ("Let's Tie", "we", "us" or "our") is committed to protecting the privacy of everyone who visits our website, contacts us, or works with us. This Privacy Policy describes how we handle personal data in connection with this website and the consultancy services we provide.

We handle personal data in accordance with the Personal Data Protection Law of the Kingdom of Saudi Arabia and its Implementing Regulations (the "PDPL"), together with any other laws that apply to us.

By using this website or contacting us, you confirm that you have read and understood this policy. If you do not agree with it, please do not use this website or submit information to us.

2. Who we are

Let's Tie is a technology consultancy and the technology arm of Tie Together Group, operating in the Kingdom of Saudi Arabia. For the purposes of the PDPL, the data controller responsible for your personal data is:

  • Legal entity name: [full registered company name]
  • Commercial Registration (CR) number: [CR number]
  • Registered address: [street, city, postal code, Saudi Arabia]
  • Privacy contact: lets@tiesaudi.com [confirm whether a dedicated privacy address or Data Protection Officer should be named here]

3. What we collect

Information you give us

When you complete the enquiry form on our website or email us, we collect the details you choose to provide. This ordinarily includes your name, email address, telephone number (if you supply one) and the content of your message.

Information we receive through a client engagement

Where you engage us to deliver services, we may receive personal data belonging to you, your staff or your own customers as part of that work — for example contact details for project stakeholders, or data contained within systems we are asked to build, migrate, integrate or secure. Where we process such data on your behalf and under your instructions, we act as a processor rather than a controller, and our handling of that data is governed by the written agreement between us.

Information collected automatically

Our hosting provider may automatically record standard technical information when you visit this website, such as your IP address, browser type, device type, the pages you viewed and the date and time of your visit. This is generated as part of the ordinary operation and security of a web server. [Confirm what your host actually logs and for how long.]

We do not ask for, and request that you do not send us, sensitive personal data — such as health, biometric, genetic, credit, religious or criminal-record information — through the website enquiry form or by unencrypted email.

4. How we use it

We use personal data only for purposes connected to our business, namely to:

  • respond to your enquiry and correspond with you about it;
  • prepare and provide proposals, quotations and scopes of work;
  • deliver, manage and support the services we have been engaged to provide;
  • carry out client onboarding, contracting, invoicing and payment collection;
  • operate, maintain and secure this website and our own systems;
  • keep records required for accounting, tax, audit and regulatory purposes; and
  • comply with applicable law and respond to lawful requests from authorities.

We do not sell your personal data, and we do not use it for automated decision-making that produces legal or similarly significant effects on you.

[If you intend to send marketing emails, newsletters or event invitations, that purpose must be added here together with a description of how consent is obtained and withdrawn.]

5. Our legal basis

Under the PDPL we rely on one or more of the following grounds for processing:

  • Your consent — for example, when you voluntarily submit an enquiry form.
  • Performance of a contract — where processing is necessary to enter into or carry out an agreement with you or your organisation.
  • Compliance with a legal obligation — where a law, regulator or court requires us to process or retain data.
  • Our legitimate interests — where processing is necessary for a legitimate interest of ours and does not prejudice your rights, such as securing our systems and preventing fraud.

Where we rely on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal, and it may mean we can no longer respond to your enquiry.

6. Cookies & third parties

This website does not set cookies of its own, and does not use advertising or analytics trackers.

The site does load its typefaces from Google Fonts. When your browser requests those font files, your IP address and basic request information are sent to Google's servers, and that transfer is governed by Google's own privacy policy. If you would prefer to avoid this, the fonts can be self-hosted instead.

Our enquiry form does not transmit your message to a server. Submitting it opens your own email application with the message pre-filled, so the message reaches us only if you choose to send it, and it travels through your own email provider.

[This section must be updated the moment analytics, a chat widget, embedded video, a marketing pixel, a CAPTCHA or a server-side form handler is added to the site.]

7. Sharing your data

We do not sell or rent personal data. We may share it in the following limited circumstances:

  • Within Tie Together Group — with our parent and affiliated companies where necessary to respond to your enquiry or deliver a service.
  • Service providers — with suppliers who support our business under contract, such as hosting, cloud infrastructure, email, and professional advisers. They may use the data only on our instructions.
  • Professional advisers — with our lawyers, auditors and insurers where reasonably required.
  • Legal and regulatory — where disclosure is required by law, court order, or a competent authority, or to establish, exercise or defend legal claims.
  • Business transfers — with a counterparty in connection with a merger, acquisition or restructuring, subject to appropriate confidentiality protections.

[List the actual key processors used — hosting provider, email provider, CRM — as the PDPL Implementing Regulations expect transparency about who receives personal data.]

8. International transfers

Some of the service providers we rely on may store or process data outside the Kingdom of Saudi Arabia. Where personal data is transferred outside the Kingdom, we will do so only in the circumstances permitted by the PDPL and its Implementing Regulations, and we will take appropriate steps to ensure the data remains protected to an equivalent standard.

[Confirm which providers store data abroad and in which countries, and record the transfer mechanism relied upon. This is a specific PDPL compliance point and should be verified with counsel.]

9. Security

Security is core to what we do. We maintain organisational and technical measures designed to protect personal data against loss, misuse, unauthorised access, disclosure, alteration and destruction. These include access controls, encryption in transit, network and endpoint protections, and restricting access to personnel who need it.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach, we will handle it in accordance with the notification requirements of the PDPL. [Confirm your internal breach-response and notification procedure, including timelines, with counsel.]

10. How long we keep it

We keep personal data only for as long as necessary for the purpose it was collected for, and for as long as we are required to keep it by law — for example, commercial, tax and accounting record-keeping obligations. When data is no longer needed, we delete it or anonymise it securely.

  • Enquiries that do not become engagements: [retention period]
  • Client and project records: [retention period]
  • Financial and accounting records: [statutory retention period]
  • Website and server logs: [retention period]

11. Your rights

Subject to the conditions and exceptions in the PDPL, you have the right to:

  • Be informed — to know the legal basis and purpose for which we collect your data.
  • Access — to request access to the personal data we hold about you.
  • Obtain a copy — to receive your personal data in a readable, commonly used format.
  • Rectification — to have inaccurate, incomplete or outdated data corrected or updated.
  • Erasure — to request deletion of personal data we no longer need for the purpose it was collected for.
  • Withdraw consent — to withdraw consent at any time where our processing relies on it.

To exercise any of these rights, contact us at lets@tiesaudi.com. We may need to verify your identity before acting on a request. We will respond within the period required by the PDPL.

If you are not satisfied with our response, you have the right to lodge a complaint with the competent supervisory authority in the Kingdom of Saudi Arabia. [Confirm the current competent authority and add its contact details.]

Where we process personal data on behalf of a client as a processor, requests relating to that data should be directed to the client, and we will support them in responding.

12. Children's privacy

This website and our services are intended for businesses and professional audiences. They are not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.

13. Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, our services, or the law. The current version will always be published on this page with the "Last updated" date shown above. Where a change is significant, we will take reasonable steps to bring it to your attention.

14. Contact us

If you have questions about this policy, about how we handle personal data, or if you wish to exercise any of your rights, please contact us:

  • Email: lets@tiesaudi.com
  • Address: [registered address]
  • Telephone: [telephone number]

See also our Terms & Conditions.

A technology consultancy driving digital transformation across industries — AI, automation, data, FinTech and cybersecurity. Part of Tie Together Group.

Navigate
Home About Services Why Us The Group Contact
The Group
Tie Togther — Real Estate Land of the Braves — Brokerage Dar Al Malfa — Hospitality Ready Right Resolve — Community Tawazon — Environmental
Contact
lets@tiesaudi.com Saudi Arabia
© 2026 Let's Tie. Part of Tie Together Group. All rights reserved.
Privacy Policy Terms & Conditions
Together is not only our name — it is our philosophy.