1. Who is responsible
The business whose page you visit decides why your booking and customer information is used to provide its services. It is normally the data controller. Its identity and contact details appear on its storefront, booking confirmation, and customer document.
Seaa supplies the booking infrastructure and normally processes that information for the business. Seaa separately decides how it uses business-account contacts, security records, service administration, and pilot communications. Before production, this paragraph must identify Seaa’s legal operator and registered address.
2. Information we handle
- Booking data: name, email, verified mobile number required to confirm a booking, locale, service, resource or specialist, date and time, participants, price, accepted terms, cancellation or amendment history.
- Payment records: amount due, amount recorded as paid or refunded, method, currency, references, and reconciliation state. During the offline pilot, the business receives cash or transfer directly; Seaa does not collect bank credentials or verify the transfer automatically.
- Business-account data: staff name, business email, role, language, login and session security events, configuration changes, and audit history.
- Customer documents and feedback: invoice or receipt data, document identifiers, eligible review, private feedback, consent or withdrawal, and the business response.
- Technical data: request time, bounded route, device/browser information, IP-derived security signals, error and performance measurements. Logs are designed not to contain booking codes, access tokens, full payment payloads, email addresses, or phone numbers.
3. Why information is used
The exact legal basis depends on the responsible business and market. It may include steps requested before a contract, performance of a contract, legal obligations, legitimate interests assessed by the controller, or consent where the law requires it. The business must document and disclose the applicable basis.
- Create, protect, fulfil, amend, cancel, and support bookings and waitlist offers.
- Show availability, calculate the authoritative price, prevent double booking, and maintain a reliable booking and payment ledger.
- Send essential confirmations, reminders, amendments, cancellations, documents, payment notices, waitlist offers, and feedback invitations.
- Secure staff accounts, prevent abuse, investigate incidents, maintain backups, and demonstrate changes through audit records.
- Operate and improve the pilot using aggregated operational measures. Seaa does not use customer booking data for unrelated advertising.
5. Retention
Seaa keeps information only for the booking, security, support, contractual, and legal-record purposes that require it. The proposed pilot schedule uses short retention for expired holds, completed queue events, notification diagnostics, logs, support exports, and raw provider payloads; encrypted backups expire after 35 days. Businesses may need to retain booking, invoice, payment, refund, and tax records for longer periods required by local law. Final market-specific periods must be published before production.
6. Your choices and rights
- Ask the relevant business for access, correction, a copy, restriction, objection, or deletion where applicable.
- Withdraw consent for a public review; the review and rating are removed from public output while necessary audit evidence is retained without the review text.
- Use the secure booking-management path to cancel or amend where the business policy allows it.
- Contact Seaa about platform-account, security, or processor-assistance requests. We may need to coordinate booking-record requests with the responsible business.
- Complain to the competent privacy authority, including SDAIA in Saudi Arabia or the competent supervisory authority in the EEA, where applicable.
7. Security and incidents
Seaa uses HTTPS, tenant isolation, role-based access, short-lived booking holds, high-entropy access tokens, audit records, least-privilege service accounts, encrypted off-site backups, private databases and monitoring endpoints, dependency checks, and restoration drills. No internet service can guarantee absolute security. Suspected misuse or loss should be reported immediately to the contact below.
8. Cookies, storage, children, and automated decisions
Seaa stores a functional language preference and uses secure session cookies for signed-in users. Optional browser analytics stay off until you accept. Your choice and an optional analytics-provider preference cookie are stored for 180 days and can be changed using Privacy controls on public pages. Public-page traffic measurement uses a random browser cookie that expires at the next Riyadh midnight. The counter stores daily keyed hashes, not the raw identifier, contact details, or full page URLs. Daily cleanup removes identifier records older than the current and previous Riyadh dates; aggregate counts are retained for up to 401 calendar dates. Do Not Track and Global Privacy Control disable browser analytics. Non-essential advertising cookies are not part of the pilot. Seaa does not make legal or similarly significant decisions about customers through automated profiling. The service is intended for businesses and customers able to form or use a booking under the business’s rules; a child-specific service requires a separate age and guardian assessment.
9. Contact and updates
Send privacy and security questions through our contact form. The final notice must add the legal operator identity, postal address, privacy contact or DPO where required, subprocessor register, and market complaint details. Material changes will be dated and communicated where the law or contract requires it.
Contact form