Sanam — Data Processing Terms
Version: v1.0
Last updated: 24 July 2026
Applies to: the personal data that reaches the Sanam platform — operator and reseller business data, the people who use the accounts, and the traveller details that pass through so a booking can be delivered.
These Data Processing Terms explain how Sanam handles personal data at the platform level: the roles each party plays, the lawful basis we rely on, the categories of data involved, when data leaves the Kingdom, how we secure it, who helps us process it, the rights a person has, how long we keep data, and what happens if something goes wrong. They sit alongside our Privacy & Personal Data Notice, which is written for the individual whose data we hold; these Terms are the operational and contractual layer, written for the businesses on the platform and the people responsible for data inside them. Where the two describe the same thing, they are meant to say the same thing. This document is governed by the Saudi Personal Data Protection Law (PDPL) and its implementing regulations, overseen by the Saudi Data & AI Authority (SDAIA).
The party to these Terms is Sanam Experiences (شركة سانام إكسبيريانس), a single-person limited liability company registered in the Kingdom of Saudi Arabia with the Ministry of Commerce under Commercial Registration / Unified National Number 7054775262 ("Sanam", "we", "us").
#1. What these terms are, and how they fit with our other documents
1.1 These Terms describe our data-processing practices and set the data-protection obligations between Sanam and the operators and resellers who use the platform. Our Privacy & Personal Data Notice explains the same handling to the individual; our Terms of Service and Operator or reseller agreement carry the wider commercial relationship.
1.2 If a specific engagement needs a separately signed data processing agreement, that signed agreement governs its own subject matter. These Terms cover everything else, and where the two genuinely conflict on the same point, the signed agreement wins.
1.3 Nothing in these Terms reduces a right a person has under the PDPL, or a duty either of us owes under it.
#2. The roles each of us plays
2.1 Sanam is the controller of its own platform data. We decide the purposes and the means of how account, booking, compliance, payment and security data is processed on the platform, so for that data Sanam is the responsible party — the "controller" under the PDPL.
2.2 Operators and resellers are controllers in their own right. When we pass a traveller's details to the operator who will deliver the experience, or to a reseller who sold it, that party decides for itself how it uses those details to run its own business. For that use, it is a separate, independent controller and answers for its own compliance. Sanam does not decide those uses and does not control them.
2.3 In the ordinary operation of the platform, we are independent controllers, not processor and controller. Each party answers for the data it controls. Sanam does not act as an operator's or reseller's processor by default, and they do not act as ours.
2.4 The one exception, and only in writing. Where the parties agree in writing — for example a managed service in which Sanam processes a defined set of personal data solely on an operator's documented instructions and for no purpose of its own — Sanam acts as that operator's processor for that data, and section 12 applies to it. Absent such a written instruction, section 2.3 governs. Which role applies is a matter of who actually decides the purpose of the processing, not of what a document is called.
#3. The lawful basis we rely on
3.1 Under the PDPL we process personal data only where we have a valid basis. Depending on the activity, ours are: performance of our agreement with the operator or reseller; the delivery of a booking a traveller has bought, from us or from the reseller or OTA that sold it; a legal obligation (tax, accounting and record-keeping); our legitimate interests in operating, securing and improving the platform, where those interests do not override the individual's rights; and consent, which we rely on only where the law requires it and which a person can withdraw at any time.
3.2 We do not rely on legitimate interests for sensitive data, and we do not rely on it to justify anything a person would not reasonably expect. Our Privacy Notice sets out, activity by activity, which basis applies.
3.3 We never use traveller data for our own marketing.
#4. The categories of personal data we process
4.1 Business and account data — legal or business name, registration and VAT numbers and status, addresses and contact details, the names, emails, phone numbers and roles of account users, payout details, log-in credentials, and the record of terms and consents accepted.
4.2 Compliance documents — commercial registration certificates, Ministry of Tourism licences, insurance certificates, and the identity documents of the people authorised to act for a business.
4.3 Traveller booking data — the lead traveller's name and contact details, party size and, where an activity requires it, participant details such as an age band, together with the experience booked, the date and time, meeting or pick-up details, special requests, and the booking reference.
4.4 Payment and invoicing data — amounts, currency, payment status, references, invoices, vouchers and settlement records. Full card and payment-instrument numbers are handled by our payment provider and are not stored on our systems.
4.5 Channel, usage, technical and support data — the account and message data needed to run a distribution connection, log-in and session data, IP address, device and browser information, server-side usage records, audit and security logs, and the correspondence between us.
4.6 We collect only what a stated purpose actually needs, and no more.
#5. Sending personal data outside Saudi Arabia
5.1 Platform data is held in the Kingdom by default. Data leaves the Kingdom in three situations: when an experience is sold through an international reseller or OTA and the traveller's booking details go to that recipient; when an AI feature runs and the content of that task goes to our AI provider in the United States; and where some technical services we use process data abroad.
5.2 When personal data leaves the Kingdom we rely on a transfer condition permitted by the PDPL and the Kingdom's rules on transferring personal data abroad, and we check that a condition applies before we rely on it. We send only what the recipient needs for its role, not the whole record.
5.3 Where we hold the direct relationship with a recipient, we put written terms in place covering confidentiality, security, purpose limits and onward sharing. If we learn a recipient is not protecting the data properly, we change what we send or stop sending it.
5.4 An honest limit. When an operator enables an OTA or reseller channel, it is instructing us to send that channel the booking data it needs, and operators hold their own accounts with those channels — so once the data arrives, that channel's own agreement and notice govern what it does with it. We control what we send, to whom, and on what terms; we do not control what an independent channel does on its own systems.
#6. How we secure personal data
6.1 We apply, and keep under review, measures appropriate to the risk, including: encryption at rest for personal and financial fields; encrypted connections for data in transit; access by role on a need-to-know basis, with each organisation's data separated from every other's; audit trails for money movements and significant account actions; payment details handled by our payment provider, so full card numbers do not sit on our systems; and internal discipline that decrypts only at the point of use and keeps personal data out of ordinary logs.
6.2 Security is a continuing practice, not a state that is ever finished. No system can be made perfectly secure, and we do not represent that it can be. We improve these measures as the platform grows and as risks change.
#7. The people and services who help us process data
7.1 We use a limited set of service providers to run the platform — hosting and storage, communications (email, SMS, WhatsApp), payment processing, and our AI provider. Each processes personal data only to provide its service to us, under a written agreement that binds it to confidentiality, security and purpose limits.
7.2 Our AI provider is Anthropic, in the United States. Where an AI feature processes reservation documents or support messages, the content of that specific task is sent to it for that task only. Our agreement with it does not permit it to train its models on what we send, and we do not use personal data to train AI models.
7.3 We remain answerable for the data we entrust to a service provider. If we change providers or add a material one for a core function, we do so under the same discipline. A current description of the kinds of provider we use is kept in our Privacy Notice.
7.4 Recipients that are controllers in their own right — the operators, resellers and OTAs who receive traveller data to deliver, sell or support a booking — are not our processors. They receive the data to do their own job and answer for their own compliance, as section 2 sets out.
#8. The rights of the individual, and how we handle a request
8.1 Subject to the conditions and exceptions in the PDPL, an individual has the right to be informed, to access the data we hold about them, to obtain a copy in a readable format, to correct data that is wrong or out of date, to ask us to destroy data we no longer have a reason to keep, to withdraw consent where consent was our basis, and to object to processing based on our legitimate interests where the law allows.
8.2 A request goes to privacy@sanam.travel. We verify who is asking, then respond within 30 days, and tell the person if the law allows us more time. There is normally no charge. Where we cannot do what is asked — for example because a record must be kept for tax — we explain why.
8.3 Where a request touches data another party controls, we help the individual reach the right party and cooperate with a reasonable request from an operator, reseller or OTA that needs our help to answer its own data subject. Each controller answers for its own copy.
8.4 An individual also has the right to complain to the supervisory authority (SDAIA). We would like the chance to resolve a concern first, so please raise it with us; that does not remove the right to go to the authority.
#9. How long we keep personal data
9.1 We keep personal data only for as long as its purpose needs, then delete it or make it anonymous. We hold booking, invoice, payout and settlement records for the period Saudi tax and accounting rules require, counted from the end of the financial year the record belongs to. We hold account and business data while an account is open plus a limited period after it closes. We hold compliance and identity documents only while we rely on them. We hold security and audit logs for a short standard period, longer where an investigation or the law requires.
9.2 Where a record must be kept for a legal reason, we keep only that record and restrict access to it. We will tell a business the current period for any category on request.
#10. When something goes wrong — personal data breaches
10.1 If a personal data breach happens on our side, we contain and assess it, notify SDAIA within the time the law requires — our standard is within 72 hours of becoming aware — and inform the people affected where the breach is likely to cause them serious harm. We keep a record of every breach and what we did about it.
10.2 We each tell the other quickly. If an operator or reseller becomes aware of an incident affecting personal data it received through the platform, it will tell us within 24 hours and help us respond — we need that speed because a notifiable incident must reach the authority within 72 hours. We will do the same for a party whose data is affected by an incident on our side.
10.3 Neither of us will make a public statement that identifies the other in connection with an incident without first consulting the other, unless the law or an authority requires it.
#11. Cooperation, audit and assurance
11.1 We will give an operator or reseller the information it reasonably needs to satisfy itself that we handle the personal data it is responsible for in line with these Terms and the PDPL — normally through this document, our Privacy Notice, and a written answer to a specific, proportionate question.
11.2 We are an operating platform, not a data room. A request for assurance should be specific and proportionate to the data at stake; we are not obliged to disclose another customer's data, our security detail where disclosing it would weaken it, or commercially confidential information. Where a formal audit right is genuinely required, it is agreed in a signed data processing agreement under section 1.2.
#12. Processor terms — only where section 2.4 applies
12.1 This section takes effect only where the parties have agreed in writing that Sanam processes a defined set of personal data as an operator's processor. It does not apply to the ordinary independent-controller operation of the platform described in section 2.3.
12.2 Where it applies, Sanam will: process that data only on the operator's documented instructions and for the agreed purpose; keep it confidential and limit access to those who need it; apply the security measures in section 6; not appoint a sub-processor for that data without the operator's general or specific authorisation and equivalent written terms; assist the operator, so far as it reasonably can, with data subject requests, security, breach notification and any impact assessment; tell the operator without undue delay of a breach affecting that data; and, at the end of the engagement, delete or return that data except where the law requires it to be kept.
12.3 If Sanam considers an instruction to breach the PDPL, it will tell the operator and may pause that processing until the point is resolved.
#13. Changes to these terms
13.1 We may update these Terms as the platform, our partners and the law develop. When we do, we change the version and the "Last updated" date, and for a change that materially affects a business's obligations we tell account holders before it takes effect. The current version is the one that applies.
#14. Contact
Questions and requests about how we process personal data:
- Personal data and data subject requests: privacy@sanam.travel
- General and contractual: operations@sanam.travel
Sanam Experiences · Commercial Registration 7054775262 · Kingdom of Saudi Arabia
These Terms are governed by the laws of the Kingdom of Saudi Arabia, and any dispute about them will be dealt with by the competent courts of Riyadh unless the law requires otherwise.
*Data Processing Terms v1.0 — last updated 24 July 2026.*