Privacy Policy
Last updated: 2026-08-01
This Policy explains how personal data is handled within Bassir Corporate Academy Platform (BCAP), consistent with the Personal Data Protection Law (PDPL) of the Kingdom of Saudi Arabia. In most cases the Customer organisation is the data controller and Bassir Technology acts as a data processor on its behalf.
1. Data we process
Account and profile data (name, work email, job title, department, branch), authentication data (hashed passwords, session records), and development data (training, competencies, certifications, succession and performance ratings).
Technical logs (audit events, sign-in timestamps) needed for security and support. Passwords are stored only as salted hashes and are never readable.
2. Purpose and lawful basis
Data is processed to provide the Service: authentication, delivering development modules, analytics for the employer, billing, and security.
The lawful basis is typically the performance of the employment or service relationship and the legitimate interests of the employer in developing its workforce, consistent with the PDPL. Data is not sold.
3. Data subject rights
Under the PDPL, data subjects have the right to be informed, to access their data, to request correction, to request deletion, and to withdraw consent where processing relies on it.
Because the employer is usually the controller, requests should first be directed to the employer's administrator; they may also be sent to privacy@bassir-academy.com and will be routed appropriately.
4. Data retention
Personal data is retained for as long as the Customer's account is active and for the period necessary to meet legal, accounting, and security obligations.
On account termination, Customer data is available for export for a limited window and is then deleted or irreversibly anonymised.
5. Security
Tenant data is isolated at the database level using row-level security. Access is role-based, passwords are hashed, sessions are signed, and administrative actions are audit-logged.
Data is encrypted in transit. Operators should also ensure encryption at rest, backups, and monitoring in their deployment environment.
6. Sub-processors
The Service may rely on sub-processors for hosting, email delivery, and payment processing. These are engaged under agreements requiring appropriate safeguards, and a current list is available on request.
7. Cross-border transfers
Where data is transferred outside the Kingdom, such transfers are made only in accordance with the PDPL and its implementing regulations, including appropriate safeguards or the data subject's rights being preserved.
8. Breach notification
In the event of a personal-data breach that poses a risk, the operator will notify the affected Customer without undue delay so the controller can meet its notification obligations to the competent authority and data subjects.
9. Contact
For privacy questions or to exercise your rights, contact privacy@bassir-academy.com. If your employer operates this workspace, you may also contact your administrator.