Who is responsible for your data?
MASON is the controller of the personal data collected through this website and its related communication channels. You can reach us at info@masonksa.com or on +966 50 352 0030, or visit us at 3689 Imam Saud bin Abdulaziz Branch Road, Al Nuzha, Riyadh 12474.
The data we collect
We collect the minimum needed to provide the service, which may include:
- Name, phone number and email address.
- Details of the space, project type, city, approximate budget and suitable appointment times.
- Messages, files, photographs and drawings you choose to send us.
- Limited technical data such as IP address, device and browser type, security logs, and cookies where used.
- Contract, invoicing and correspondence records if you become a client.
MASON does not request sensitive data through website forms. Please avoid sending identity documents or financial information unless we have asked for them through a secure channel and for a clear purpose.
How we collect it
We collect data directly from you when you send an enquiry, request a consultation or a quotation, subscribe to our mailing list, or contact us. Limited technical data may be collected automatically when you visit the site. If your data reaches us from a third party, we verify that there is a lawful basis for using it.
Why we use it
- To answer your enquiry, understand the project requirements and prepare a consultation or quotation.
- To manage the contractual relationship, deliver the project and communicate about it.
- To send the messages you chose to subscribe to; you can unsubscribe at any time.
- To protect the site, prevent misuse, and improve performance and usability.
- To meet legal and accounting requirements and to defend legal rights.
Depending on the case, we rely on your consent, the performance of a contract or steps taken at your request before contracting, a legal obligation, or a legitimate interest that does not override your rights.
Who we share it with
We may share what is necessary with providers of hosting, email, client management and technical support, with the designers, suppliers and contractors involved in your project, or with competent authorities where the law requires it. We require service providers to protect the data and use it only for the agreed purpose. We do not sell your personal data.
Processing outside the Kingdom
Some technology providers may use cloud infrastructure outside the Kingdom. Where an international transfer or disclosure takes place, we apply the requirements of the Personal Data Protection Law and its regulations, and put appropriate safeguards in place before the transfer. You may request further information about where processing happens and which safeguards apply.
Retention and destruction
- Visitor enquiries: up to 24 months from the last contact.
- Mailing list subscriptions: until you unsubscribe, or after 24 months without interaction.
- Technical security logs: up to 12 months, unless they must be kept to investigate an incident.
- Contracts, invoices and project files: for as long as needed to perform the contract, meet legal requirements and protect rights.
Once the purpose ends, we delete the data or anonymise it so it can no longer be linked to you, unless the law requires us to keep it.
How we protect data
We use organisational and technical measures appropriate to the nature of the data, including restricted access, protection of accounts and systems, backups, and review of service providers. No electronic method is entirely free of risk, so we review these measures as needed.
Your rights
Under the Personal Data Protection Law, and depending on the purpose and lawful basis, you have the right to:
- Be informed how your data is collected and used.
- Access your data and receive a clear copy of it.
- Request correction, completion or updating of inaccurate data.
- Request destruction of data once its purpose has ended, unless there is a basis for keeping it.
- Withdraw consent where consent is the basis of processing.
Send your request to info@masonksa.com. We may ask for limited information to verify your identity before acting on it, and we will respond within the statutory period.
Complaints and updates
If you have an objection, contact us first by email and we will review the request. If you are not satisfied with how it was handled, you may complain to the competent personal data protection authority through the national data governance platform operated by SDAIA.
We may update this policy when our services or legal requirements change. The last updated date appears at the top of the page, and we will alert you to any material change where required.