Privacy Policy

Last updated 19 July 2026

This policy explains what personal data MyDiyafa handles, why we hold it, who else sees it, and what you can ask us to do about it. We have written it in plain language and described the platform as it actually works today, including the parts we are still building.

MyDiyafa is operated by [LEGAL ENTITY NAME], commercial registration [CR NUMBER], of [REGISTERED ADDRESS], Kingdom of Saudi Arabia. The bracketed details are placeholders until the operating entity is registered, and this document has not yet completed legal review. It is published now so that hotels evaluating MyDiyafa can see exactly how the platform treats data.

What this policy covers

MyDiyafa is a guest request platform for hotels, serviced apartments and hospitality groups in Saudi Arabia. This policy covers the staff application, the guest request pages reached by QR code, and this website. It does not cover a hotel's own systems, its property management system, or anything a hotel does with your data outside MyDiyafa.

Who is responsible for your data

When a guest raises a request, the hotel decides what is collected and why. The hotel is the data controller and MyDiyafa is its processor, handling that data on the hotel's instructions and on its behalf. For staff accounts and for visitors to this website, MyDiyafa is the controller in its own right. If you are a guest and want to exercise a right over your data, start with the hotel you stayed at; we support them in answering you.

What a guest gives us

Guests do not have accounts on MyDiyafa. There is no sign-up, no password and no profile. A request carries only what is needed to resolve it:

  • What you asked for — the free-text description you write, in the language you write it in.
  • Where — the room your QR code belongs to, or nothing at all when you scan a property-wide code such as one in the lobby.
  • Your name and phone number, both optional. A request works without them; they exist so staff can reach you if resolving it needs a conversation. We never ask a guest for an email address.
  • Any photo you choose to attach, along with its file name, type and size.
  • Your rating and comment if you leave feedback, and your reason if you cancel or reopen a request.
  • The IP address the request was submitted from, recorded in the hotel's audit trail alongside the action.

What hotel staff accounts hold

Staff use MyDiyafa through a named account created by their employer. For these accounts we hold:

  • Name, work email address, optional phone number, role and preferred language.
  • A password hash, never the password itself.
  • Sign-in security records: failed sign-in counts, lockout times, and the IP address a session was created from.
  • An audit trail of significant actions — who did what, when, and the IP address it came from. Failed sign-in attempts also record the email address that was submitted, which is how we detect attacks against accounts that do not exist.

What this website collects

This website is deliberately quiet. It carries no advertising, no third-party analytics, no tracking pixels and no social media scripts. Fonts are served from our own domain, so loading a page makes no request to a third party.

  • The contact and demo form does not send anything to our servers. It opens a message in your own email application, addressed to us, and you decide whether to send it. What reaches us is the email you chose to send.
  • Our servers keep ordinary technical logs of incoming requests, which can include IP addresses, for security and troubleshooting.
  • We do not build advertising profiles, we do not sell personal data, and we do not share it with data brokers.

Cookies and browser storage

We use the minimum a working application needs, and nothing for advertising or measurement.

  • One cookie, named mydiyafa_refresh, keeps hotel staff signed in. It is HttpOnly, limited to the sign-in path, and expires after fourteen days. Staff access tokens are held in memory only and are never written to browser storage.
  • For guests, your browser stores the reference to your own open request so you can find it again after closing the tab. It stays on your device, identifies a request rather than a person, and you can clear it.
  • Staff browsers also remember the selected property and the light or dark theme. Because we set no advertising or analytics cookies, there is no consent banner to click through.

Why we handle this data

Under the Personal Data Protection Law we rely on the performance of our contract with the hotel, our legitimate interest in operating and securing the service, and consent where the law requires it. Every category above exists for a specific purpose:

  • To deliver the service — routing a request to the right department, giving it one owner and a deadline, and confirming resolution with the guest.
  • To keep accounts secure — authenticating staff, rate limiting the API, and locking out repeated failed sign-ins.
  • To give a hotel an accurate operational record — audit trails, response times, and analytics about that property's own performance.
  • To answer you — replying to a demo or contact enquiry you chose to send us.

Who else sees it

We do not sell personal data and we do not share it with advertisers or data brokers. Today the list is short:

  • The hotel whose property you are staying at. Staff at that property and supervisors above them see requests for that property, and a hotel group can see reporting across the properties it owns.
  • Our hosting provider, which runs the servers and database the platform lives on. [HOSTING PROVIDER — to be named before commercial launch.]
  • We currently use no third-party analytics, error tracking, advertising, payment or messaging providers. If that changes, this page will name them before the change takes effect.
  • Anyone the law requires us to disclose to, or where disclosure is needed to establish, exercise or defend a legal claim.

Where your data is stored

MyDiyafa is built for the Saudi market and intends to hold personal data within the Kingdom. [HOSTING REGION — to be confirmed before commercial launch.] Where a transfer outside the Kingdom becomes necessary, it will be made only on the terms the Personal Data Protection Law and its implementing regulations allow, and this page will name the destination before it happens.

How long we keep it

This is a part of the platform we are still building, and we would rather say so plainly than imply otherwise. As MyDiyafa stands today:

  • A guest request and everything attached to it — description, optional name and phone, photos, feedback and audit records — is kept for as long as the hotel's account is active. The platform does not yet delete or anonymise this data automatically.
  • Requests close automatically three days after resolution. Closing ends the ability to reopen a request; it does not delete anything.
  • Refresh tokens expire after fourteen days and staff access tokens after fifteen minutes. Password reset and invitation links are single use and expire on their own schedule.
  • [RETENTION SCHEDULE — to be defined before commercial launch.] Automatic deletion and anonymisation are planned. Until they ship, erasure requests are carried out manually by our team on the hotel's instruction.

How we protect it

Security is described in more detail in our engineering documentation, but in summary:

  • Passwords are stored only as hashes, and refresh tokens are stored hashed as well. Neither can be read back.
  • Guest request links use unguessable 256-bit tokens. The short code you can read aloud is display only and cannot be used to look a request up.
  • Staff access is scoped by role and by property and enforced at the database query level, so a user reaches only the properties they are assigned to.
  • Accounts lock after five failed sign-ins, and the API is rate limited.
  • No system is perfectly secure. If a breach affects personal data, we will notify the affected hotel and the competent authority as the Personal Data Protection Law requires.

Your rights

Under the Personal Data Protection Law of the Kingdom of Saudi Arabia you have the rights below, and we answer requests within 30 days. If you are a hotel guest, address your request to the hotel first, since it is the controller of your request data. Note that these requests are currently handled manually rather than through a self-service tool.

  • To be informed — to know what is collected, why, and who sees it. That is what this document is for.
  • To access — to obtain a copy of your personal data.
  • To request correction — of data that is incomplete, inaccurate or out of date.
  • To request destruction — of personal data we no longer have a lawful reason to keep.
  • To portability — to receive your data in a readable, structured format.
  • To object or withdraw consent where our handling rests on consent, and to complain to the Saudi Data and AI Authority (SDAIA).

Children

MyDiyafa is a tool for hotel operations and is not directed at children. We do not knowingly collect personal data from children, and a request raised on behalf of a family is treated as the booking guest's request. If you believe a child's personal data has reached us, contact us and we will remove it.

Changes to this policy

We will update this page whenever the platform changes what it collects or how that data is handled. The date at the top always reflects the most recent change, and material changes are communicated to hotels through their account contact before they take effect.

How to reach us

For privacy questions, data requests, or to reach whoever is responsible for data protection at MyDiyafa, use the address below. If you are a hotel guest, contacting the hotel directly is usually faster, because the hotel controls your request data.

Questions? Contact us at hello@mydiyafa.example.