BBCAP

Privacy Policy

Last updated: 2026-08-01

Template notice: This document is a template provided with Bassir Corporate Academy Platform (BCAP). It should be reviewed and adapted by the operating company's legal counsel before commercial use. It does not constitute legal advice.

This Policy explains how personal data is handled within Bassir Corporate Academy Platform (BCAP), consistent with the Personal Data Protection Law (PDPL) of the Kingdom of Saudi Arabia. In most cases the Customer organisation is the data controller and Bassir Technology acts as a data processor on its behalf.

1. Data we process

Account and profile data (name, work email, job title, department, branch), authentication data (hashed passwords, session records), and development data (training, competencies, certifications, succession and performance ratings).

Technical logs (audit events, sign-in timestamps) needed for security and support. Passwords are stored only as salted hashes and are never readable.

2. Purpose and lawful basis

Data is processed to provide the Service: authentication, delivering development modules, analytics for the employer, billing, and security.

The lawful basis is typically the performance of the employment or service relationship and the legitimate interests of the employer in developing its workforce, consistent with the PDPL. Data is not sold.

3. Data subject rights

Under the PDPL, data subjects have the right to be informed, to access their data, to request correction, to request deletion, and to withdraw consent where processing relies on it.

Because the employer is usually the controller, requests should first be directed to the employer's administrator; they may also be sent to privacy@bassir-academy.com and will be routed appropriately.

4. Data retention

Personal data is retained for as long as the Customer's account is active and for the period necessary to meet legal, accounting, and security obligations.

On account termination, Customer data is available for export for a limited window and is then deleted or irreversibly anonymised.

5. Security

Tenant data is isolated at the database level using row-level security. Access is role-based, passwords are hashed, sessions are signed, and administrative actions are audit-logged.

Data is encrypted in transit. Operators should also ensure encryption at rest, backups, and monitoring in their deployment environment.

6. Sub-processors

The Service may rely on sub-processors for hosting, email delivery, and payment processing. These are engaged under agreements requiring appropriate safeguards, and a current list is available on request.

7. Cross-border transfers

Where data is transferred outside the Kingdom, such transfers are made only in accordance with the PDPL and its implementing regulations, including appropriate safeguards or the data subject's rights being preserved.

8. Breach notification

In the event of a personal-data breach that poses a risk, the operator will notify the affected Customer without undue delay so the controller can meet its notification obligations to the competent authority and data subjects.

9. Contact

For privacy questions or to exercise your rights, contact privacy@bassir-academy.com. If your employer operates this workspace, you may also contact your administrator.