Download
Data Protection Specifications v3.0, English (PDF) مواصفات حماية البيانات، الإصدار 3.0، Arabic (PDF)
Status of this document
This specification stands on its own. It describes FTH's personal data protection practices across all its services, it applies to every client whose data FTH processes, and it is not an annex to any particular agreement.
The governing version is the one published on this page, carrying a version number and a date. Any other copy governs only if it matches it.
- Changes that add or alter a commitment are published with a new version number and take effect on the date stated in that version.
- New or replacement sub-processors are published on the sub-processor register. Publication is the notice, and FTH may engage the sub-processor from the date it is listed. A client may object on reasonable data protection grounds within thirty days of publication, and FTH works with the client to address the objection. Where the sub-processor is part of the platform's infrastructure and the objection cannot be resolved, the client may terminate the service that relies on it, and termination is limited to that service rather than the client's other services. An objection does not suspend the engagement.
- Clarifications that reduce no commitment take effect on publication.
- Every version is listed below with its date and a summary of what changed.
Where the two texts differ, the Arabic text prevails.
Version history
| Version | Date | What changed |
|---|---|---|
| 3.0 | 30 August 2026 | Rewrote the opening sections to cover FTH's Business Profile services and its FTH Maps platform product. Established this document as a standalone published specification with its own versioning and notice model. Corrected the sub-processor register: the hosting account is recorded on evidence and the hosting location is stated at the level the provider's panel evidences, the European Union; the Article 28 agreements concluded on 2026-08-24, 2026-08-29 and 2026-08-30 are recorded; and the operating sub-processor listed in earlier drafts is removed because FTH performs operation, development and support itself. Rewrote the AI section so each service is described on its own, and replaced the flat statement that the platform has no AI feature with the default-off position and the consent step governing any future feature. Recorded the transfer assessment as maintained. Added the retention period for review removal requests. Stated the erasure commitment as durable across synchronisation. Disclosed FTH personnel access to client accounts during the managed services, and the diagnostic data recorded when fault investigation is enabled. Stated FTH's responsibility for its declared sub-processors, to the same extent and within the same limits as for its own acts. Restated the sub-processor notice model: publication is the notice, FTH may engage from the date of listing, and a client objection within thirty days is answered by working with the client, by excluding an optional-feature sub-processor from that workspace, or where it is infrastructure and unresolved, by the client terminating the service that relies on it. |
| 2.4 | 30 July 2026 | Previous issued version. |
Contact
Privacy enquiries, data subject requests and audit requests: privacy@fth.sa for FTH's Business Profile services, privacy@fth.marketing for its products. Every clause in the document is demonstrable against the platform.