Wetan

Your privacy matters

Privacy Policy

At Wetan we treat your data with the same care we put into our villas. This policy explains, in plain language, what we collect, why, and how you stay in control.

Last updated 16 May 2026

1.Who controls your data

The controller of personal data collected through this website (wetan.sa) is Wetan Investment & Real Estate Development, headquartered in Dammam, Eastern Province, Kingdom of Saudi Arabia.

We comply with the Saudi Personal Data Protection Law (PDPL) issued by the Saudi Data & AI Authority (SDAIA), and align with international best practice including the EU GDPR for visitors outside the Kingdom.

Privacy contact: email sales@wetan.sa · WhatsApp +966 55 742 4242

2.Data we collect

a. Data you provide directly

When you fill the reservation form or otherwise contact us, we collect:

  • Full name
  • Mobile number
  • Email address (optional)
  • City (optional)
  • Preferred villa type
  • Budget range (optional)
  • Preferred payment method (optional)
  • Additional notes or enquiries (optional)

b. Data collected automatically

  • IP address — truncated and hashed on receipt; never linked to your direct identity
  • Browser type, operating system, screen resolution
  • Preferred language (Arabic/English) and timezone
  • Pages visited, time on page, scroll depth
  • Source you arrived from (search engine, direct link, ad)
  • Ad identifiers (gclid · fbclid · ttclid) when arriving from a paid ad

c. Cookies

We use exactly two cookie categories:

  • Essential: remember your preferences (language, cookie decision). Always on; cannot be disabled because they’re required for the site to work.
  • Marketing: activated only after your explicit consent via the cookie banner. You can withdraw consent any time from your browser settings.
We implement Google Consent Mode v2: before consent, only anonymous signals are sent (never tied to your identity). After consent, the marketing platforms are activated in full.

3.How we use your data (legal basis)

We use your data only for the purposes below, each backed by a clear legal basis:

  • Pre-contractual / contractual: respond to your enquiry, schedule a viewing, issue a quote. This basis lets us process your data when you request our service.
  • Legitimate interest: site analytics to improve the experience and measure campaign effectiveness — without identifying you individually.
  • Explicit consent: marketing cookies and newsletter sign-up — you can withdraw at any time.
  • Legal obligation: retain transaction records for the period mandated by Saudi regulations.

4.Who we share data with

We do not sell your data. We work with trusted service providers, each under a binding Data Processing Agreement (DPA):

ProviderPurposeLocation
SupabaseSecure database for reservation requestsFrankfurt (EU)
VercelSite hosting + CDNGlobal edge network
ResendTransactional email notificationsUnited States
Meta · TikTok · Snap · GoogleAdvertising platforms + campaign measurement (only after consent)United States & Europe
Microsoft ClarityUX analytics with automatic PII maskingUnited States
Extra protection on ad platforms: when we share your email or phone with ad platforms to measure campaign performance, we hash the data with SHA-256 first — the hashed form cannot be reversed back to your identity, and the raw email/phone never reaches any third party.

5.International data transfers

Some providers (Vercel, Resend, Microsoft Clarity, ad platforms) host data outside the Kingdom. We ensure that:

  • Every transfer rests on recognized contractual safeguards (Standard Contractual Clauses) or internationally recognized certifications.
  • Our primary database (Supabase) sits in the EU, where GDPR-grade protections apply.
  • You may request the specifics of any transfer safeguard at any time.

6.Retention periods

  • Reservation data: for the duration of your engagement, plus 24 months after last interaction (Saudi commercial-record requirements).
  • Marketing cookies: 90 days maximum from your last visit.
  • Analytics data: 14 months in anonymized form (cannot be linked to a specific individual).
  • Encrypted backups: 30 days for daily snapshots, per disaster-recovery policy.

7.Your rights under Saudi law

As the data subject, you have the right to:

  • Access the data we hold about you.
  • Correct or update your data.
  • Request erasure (subject to mandatory retention periods).
  • Portability — receive a structured copy of your data.
  • Withdraw consent to processing at any time.
  • Object to specific processing.
  • File a complaint with the Saudi Data & AI Authority (SDAIA) at sdaia.gov.sa.

To exercise any of these rights, contact us at sales@wetan.sa. We respond within 30 business days at most.

8.Security

  • All site traffic is encrypted via HTTPS with modern TLS 1.3 certificates.
  • Stored data is encrypted at rest.
  • Customer-data access is restricted to authorized sales staff under a least-privilege policy.
  • We never store payment details or credit-card data on the site — any financial transaction occurs through separate, secure channels.
  • Daily encrypted backups, periodic security audits.
  • In the unlikely event of a data breach, we will notify you and the relevant authority within 72 hours, per regulation.

9.Children

This site targets adults (18+). We do not knowingly collect personal data from anyone under 18. If we discover such data has been provided, we delete it immediately.

10.Updates to this policy

We may update this policy from time to time to reflect regulatory or service changes. We will update the “Last updated” date at the top. For material changes, we’ll post a clear notice on the homepage and email registered customers.

11.Privacy contact

For any privacy-related enquiry or rights request: