PRIVACY POLICY
Last Updated: 17 August 2026
Introduction
Abdulaziz bin Hamad Al-Subait Limited Liability Company (the “Company,” “we,” “us,” or “our”) welcomes you and is committed to protecting the privacy of all users of the “Fosshati” application, website, and related digital services (collectively, the “Services”).
This Privacy Policy explains how Personal Data is collected, Processed, used, disclosed, and protected when you use the Services. It also sets out the rights of Data Subjects and the mechanisms through which such rights may be exercised, in accordance with the Personal Data Protection Law, issued pursuant to Royal Decree No. (M/19) dated 09/02/1443 AH, as amended, its Implementing Regulations, and all other applicable laws, regulations, rules, and instructions in force in the Kingdom of Saudi Arabia. The official Saudi materials use Personal Data Protection Law and recognize the legislation as issued under Royal Decree No. (M/19), as subsequently amended.
Please read this Privacy Policy carefully before using the Services. Your use of the Services after reviewing this Privacy Policy constitutes an acknowledgment that you have read and understood its contents, without prejudice to any explicit consent that may be required under applicable laws and regulations in respect of specific Personal Data Processing activities.
Definitions
For the purposes of this Privacy Policy, the following terms and expressions shall have the meanings assigned to them below, unless the context otherwise requires:
Company: Abdulaziz bin Hamad Al-Subait Limited Liability Company, in its capacity as the owner and operator of the Fosshati Platform and the related Services.
Platform or Application: The Fosshati platform, including its mobile applications, website, dashboards, and any related electronic systems.
Services: The digital services provided by the Company through the Fosshati Platform to enable schools, their students, and parents or legal guardians to use the electronic school canteen services, including managing balances allocated for purchases, making purchases and payments, and monitoring transactions associated with the school canteen.
Personal Data: Any data, regardless of its source or form, that may lead to the specific identification of an individual or make it possible to identify an individual directly or indirectly, in accordance with the Personal Data Protection Law.
Data Subject: The individual to whom the Personal Data being Processed relates.
Processing: Any operation performed on Personal Data by any means, whether manual or automated, including, without limitation, the collection, recording, saving, organization, storage, modification, updating, use, sharing, disclosure, transfer, anonymization, or destruction of Personal Data.
Student: The beneficiary of the Services whose account is linked to the Parent or Legal Guardian’s account and who uses the available balance or the applicable school payment method.
Parent or Legal Guardian: The person who creates or manages the relevant account, funds the balance, determines the Student’s spending limits, or otherwise lawfully represents the student.
School: The educational institution at which the Platform’s Services are activated pursuant to an agreement entered into between the School and the Company.
Service Providers: Any persons or entities that provide services to the Company in connection with the operation, support, development, or provision of the Application or related Services, including, for example, hosting service providers, SMS service providers, payment gateway providers, technical support providers, and other similar service providers.
Scope of This Policy
This Privacy Policy applies to all Personal Data collection and Processing activities carried out through the “Fosshati” Platform, including Personal Data collected or Processed when:
- creating or activating an account;
- using the electronic school canteen services;
- making purchases or payments through the Application;
- contacting customer service or technical support; or
- using the website or any electronic platforms associated with the Services.
This Privacy Policy does not apply to websites, applications, or services operated by third parties, even where they may be accessed through links made available within the Application or website. Such websites, applications, and services are subject to their respective privacy policies, and the Company recommends reviewing those policies before using them.
Who We Are
Abdulaziz bin Hamad Al-Subait Limited Liability Company is a Saudi company that owns and operates the “Fosshati” Platform, which provides digital technology services relating to the electronic operation of school canteens, enabling Students, Parents or Legal Guardians, and Schools to manage and carry out purchases and payments associated with school canteen services.
The Company is committed to Processing Personal Data in accordance with the Personal Data Protection Law and other applicable laws and regulations, and in a manner that upholds high standards of privacy and information security.
Personal Data We Collect
The Services are designed for use by Students through their School and under the supervision of a Parent or Legal Guardian, as applicable. The Parent or Legal Guardian is responsible for creating, or approving the creation of, the account associated with the Student, managing and funding the wallet, and determining the permissions and controls applicable to the Student’s use of the Services.
The Company does not collect or Process Students’ Personal Data except to the extent necessary to provide and operate the Services and on the basis of an appropriate legal basis for Processing, including the consent of the Parent or Legal Guardian where such consent is required.
A Parent or Legal Guardian may contact the Company to request access to or correction of the Student’s Personal Data associated with the relevant account, or to exercise the applicable statutory rights in relation to such Personal Data, subject to verification of the Parent’s or Legal Guardian’s identity, status, and legal authority.
The Company seeks to collect and Process only the minimum amount of Personal Data necessary to provide and operate the Services and to achieve the purposes described in this Privacy Policy. Depending on the nature of your use of the Services, the Personal Data we collect may include the following:
Account and Identity Data
Personal Data collected for the creation or management of an account may include:
- Full name.
- Username.
- National ID number or Iqama number, where applicable.
- Date of birth.
- Mobile number.
- Email address.
- Address.
- Profile photograph, where uploaded by the user.
- Identity verification and account activation data, such as One-Time Passwords (OTPs).
- Login credentials and other authentication data required to access the account.
Student and Parent or Legal Guardian Data
When the Application is used as part of the Services provided to Schools, we may Process Personal Data necessary to operate the Services, which may include:
- Student’s name.
- Parent or Legal Guardian information associated with the Student’s account.
- National ID number or Iqama number, where applicable.
- Date of birth.
- Contact details.
- Address.
- The School or store associated with the account.
- Profile photograph, where uploaded by the user.
- Information relating to the Student’s food allergies, where such information is entered into the Platform by the Parent, Legal Guardian, or another authorized user, as applicable.
The Company shall Process Students’ Personal Data only to the extent necessary to provide and operate the Services and in accordance with the applicable laws and regulations of the Kingdom of Saudi Arabia.
Financial Transaction Data
Data relating to the use of the Digital Wallet and the completion of purchase transactions may include:
- Digital Wallet top-up transactions, where applicable.
- Payment transactions.
- Purchases made through the school canteen.
- Refund transactions, where available.
- Transaction amount, date, and time.
- Transaction number or reference number.
- Transaction status.
- The available balance in the Digital Wallet, together with records of credits, debits, and any adjustments made to the balance.
The Company does not retain or Process payment instrument data except to the extent necessary to provide the Services or as required under applicable laws and regulations, depending on the manner in which payment transactions are carried out and the approved payment service providers involved.
Usage Data
We may collect data relating to the manner in which you use the Application, including:
- Order and purchase history.
- History of your use of the Services.
- Preferences and settings within the Application.
- Data relating to your interactions with the Application, where such data assists in improving the user experience.
Technical Data
When you use the Application or website, we may automatically collect certain technical data, including:
- Internet Protocol (IP) address.
- Device type and operating system.
- Browser type and version.
- Device identifiers, where applicable.
- Login data and system logs.
- Crash reports and technical error data.
- Data collected through cookies and similar technologies when using the website.
Customer Service Data
When you contact the Company, we may Process Personal Data necessary to respond to your inquiries, requests, or complaints, which may include:
- Name.
- Contact details.
- The content of correspondence, inquiries, reports, or complaints.
- Any other information you voluntarily provide to us when communicating with the Company.
Geolocation Data
Subject to obtaining the necessary permission from the user, the Application may collect approximate or precise geolocation data to the extent necessary to provide location-based Services, verify the geographical area in which the Services are available, enhance account security, and prevent unauthorized or unlawful use.
Users may control the Application’s access to their location through their device settings.
How We Collect Personal Data
The Company collects Personal Data provided directly by users through the Application or website, together with certain technical data that is automatically collected when the Services are used, to the extent necessary to achieve the purposes described in this Privacy Policy.
Personal Data Provided by the Data Subject
We may collect Personal Data provided directly by the Data Subject when:
- creating or activating an account;
- using the Application or website;
- making purchases or payments through the Application;
- contacting customer service or technical support;
- submitting inquiries, complaints, or feedback; or
- providing the Company directly with any data or documents.
Personal Data Collected Automatically
Certain technical data may be collected automatically when the Application or website is used, including device data, Internet Protocol (IP) address, system logs, Usage Data, cookies, and other technical data necessary to operate, improve, and protect the Services.
Personal Data Obtained from Service Providers
Where applicable, we may obtain limited Personal Data from Service Providers engaged by the Company in connection with the provision of the Services, such as electronic payment service providers, identity verification or One-Time Password (OTP) service providers, technical support providers, and hosting service providers.
Such Personal Data will be obtained only to the extent necessary to provide the Services or comply with applicable legal and regulatory requirements.
Purposes of Processing Personal Data
The Company Processes Personal Data for specific and lawful purposes that are appropriate to the nature of the Services it provides. Depending on the circumstances, such purposes may include the following:
Account Creation and User Management
- Creating and activating user accounts.
- Verifying users’ identities.
- Managing accounts and updating account information.
- Enabling users to log in to the Application and use the Services.
Provision of the Services and Operation of the Application
- Operating the electronic school canteen services.
- Enabling users to make purchases and payments.
- Managing Digital Wallets and related services, where available.
- Carrying out transactions and other operations associated with the use of the Application.
Processing Financial Transactions
- Processing payment and purchase transactions.
- Generating operational records and reports relating to transactions.
- Verifying financial transactions and handling refunds or transaction disputes, where applicable.
Communications with Users
- Sending account activation messages and verification codes.
- Sending notifications relating to the use of the Application or transactions.
- Responding to inquiries, complaints, and requests.
- Providing technical support services.
Protecting the Application and Enhancing Security
- Protecting the Application against unauthorized, unlawful, or fraudulent use.
- Detecting and investigating security incidents.
- Managing information security risks.
- Monitoring system performance and improving information security.
Service Development and Improvement of User Experience
- Analyzing the use of the Application on an aggregated or anonymized basis, where possible.
- Developing existing Services and introducing new features.
- Measuring the performance of the Application and improving the user experience.
- Conducting technical testing and ensuring the quality and reliability of the Services.
Compliance with Legal and Regulatory Obligations
- Complying with applicable laws, regulations, rules, and instructions in force in the Kingdom of Saudi Arabia.
- Responding to requests from competent authorities where legally required.
- Protecting the rights of the Company, users of the Application, or third parties, where applicable.
Other Lawful Purposes
The Company may Process Personal Data for any other lawful purpose permitted under applicable laws and regulations, provided that such Processing is compatible with the purpose for which the Personal Data was originally collected, or that the necessary consent is obtained where such consent is required by applicable law.
Location-Based Services
- Verifying the geographical scope within which the Services are provided or the user’s association with a School or service location, where applicable.
- Enabling or personalizing certain location-based features of the Application.
- Enhancing account security and detecting unusual, unauthorized, or unlawful use.
Legal Basis for Processing Personal Data
The Company Processes Personal Data on the basis of one or more of the legal bases provided for under the Personal Data Protection Law and other applicable laws and regulations, depending on the nature and circumstances of the relevant Processing activity. Such legal bases may include:
- Performing contractual obligations or taking steps necessary at the request of the Data Subject prior to providing the Services.
- Complying with the legal and regulatory obligations to which the Company is subject.
- Pursuing the Company’s Legitimate Interests, provided that such interests do not prejudice or conflict with the rights and interests of the Data Subject, in accordance with applicable laws and regulations.
- Obtaining the Data Subject’s consent where consent is required under applicable laws and regulations.
The Company will not use or Process Personal Data in a manner that extends beyond the purposes for which it was collected, unless such Processing is permitted under applicable laws and regulations or the necessary consent has been obtained where required.
Sharing and Disclosure of Personal Data
The Company seeks to ensure that Personal Data is not shared or Disclosed except to the extent necessary to achieve the purposes described in this Privacy Policy, or where there is a lawful basis permitting such sharing or Disclosure, and in accordance with the Personal Data Protection Law and other applicable laws and regulations.
Where appropriate, the Company may share or Disclose Personal Data with the following categories of recipients:
Schools and Educational Institutions
Personal Data may be made available to the School with which the Student is associated, to the extent necessary to operate the electronic school canteen Services and manage the transactions and activities associated therewith.
Each School’s access shall be restricted to Personal Data relating solely to its own Students and their Parents or Legal Guardians. The Company does not permit any School to access Personal Data relating to Students or Parents or Legal Guardians associated with another School.
Payment Service Providers
Data necessary for payment transactions may be shared with electronic payment service providers or relevant financial institutions for the purposes of processing, verifying, and completing payments and handling any refunds or transaction disputes, where applicable.
Technical Service Providers
The Company may engage technical Service Providers to operate, host, maintain, or support the Application, or to provide SMS and One-Time Password (OTP) services, infrastructure services, information security services, or other technical services necessary for the operation of the Application.
In all cases, the Company shall, to the extent required under applicable laws and regulations, ensure that such Service Providers implement appropriate measures to protect Personal Data.
Competent Authorities
The Company may Disclose Personal Data to judicial, security, regulatory, or other competent governmental authorities where such Disclosure is required to comply with a legal obligation or in response to a request or order issued in accordance with the applicable laws and regulations of the Kingdom of Saudi Arabia.
Professional Advisers
Where necessary, the Company may share Personal Data with its professional advisers, including legal advisers, financial advisers, and auditors, to the extent necessary for the provision of their professional services, subject to their applicable contractual or statutory confidentiality obligations.
The Company does not sell, rent, or trade Personal Data to any third party.
Transfer of Personal Data Outside the Kingdom of Saudi Arabia
Personal Data is stored and hosted within the Kingdom of Saudi Arabia using hosting and cloud computing services provided by Amazon Web Services (AWS), in accordance with the technical infrastructure adopted by the Company.
Where the nature of the Services requires Personal Data to be transferred to or Processed outside the Kingdom of Saudi Arabia, the Company will only carry out such Transfer or Processing in accordance with the Personal Data Protection Law and other applicable laws and regulations, after satisfying the applicable legal and regulatory requirements and safeguards, and in a manner that ensures an appropriate level of protection for Personal Data.
Retention and Destruction of Personal Data
The Company retains account-related Personal Data for as long as the user’s account remains active and the user continues to use the Services.
Where a user requests the cancellation or deletion of their account, the Company will delete or Destroy the Personal Data associated with that account, unless the retention of certain Personal Data is required under applicable laws and regulations, is necessary for the completion or resolution of an existing transaction, claim, or dispute, or is otherwise permitted by applicable law.
The applicable retention period may vary depending on the type of Personal Data and the purposes for which it is used. This may include, without limitation:
- Account Data: for as long as the account remains active or the Services continue to be provided, unless a longer retention period is required under applicable laws and regulations.
- Financial Transaction Records: for the periods required under applicable laws, regulations, and regulatory instructions.
- Operational and Security Logs: for the period necessary to maintain system security, investigate security incidents, and improve the performance of the Services.
- Technical Support Requests and Complaint Data: for the period necessary to resolve the relevant request or complaint, or for such longer period as may be required under applicable laws and regulations.
Once the purpose for Processing the Personal Data has been fulfilled, or the applicable statutory retention period has expired, the Company will securely delete, Destroy, or anonymize the Personal Data in accordance with its approved data destruction policies and procedures, unless a legal obligation requires the Personal Data to be retained for a longer period.
Information Security
The Company is committed to implementing appropriate organizational, administrative, and technical measures to protect Personal Data against unauthorized access, unlawful use, alteration, Disclosure, Destruction, loss, or any other form of unlawful Processing.
Depending on the nature of the Services and the associated risks, such measures may include access management controls, security event logging, backup procedures, encryption of data where appropriate, system monitoring, vulnerability management, and other measures consistent with applicable laws, regulations, and controls, including the Essential Cybersecurity Controls (ECC) issued by the National Cybersecurity Authority (NCA), to the extent applicable to the Company.
Such measures may also include the use of secure communication protocols, including TLS/SSL protocols, and the performance of periodic security testing and assessments, taking into account the nature of the systems, Services, and associated risks.
Notwithstanding the Company’s implementation of appropriate security measures, absolute security cannot be guaranteed for any system or method of data transmission.
Security Incident Management
In the event of a Security Incident that may affect the confidentiality, integrity, or availability of Personal Data, the Company will take appropriate measures to contain the incident, investigate its causes, mitigate its effects, and remediate it.
Where the applicable legal and regulatory requirements are triggered, the Company will also provide the required notifications to the Competent Authority and affected Data Subjects in accordance with the applicable laws and regulations of the Kingdom of Saudi Arabia.
Data Subject Rights
The Company is committed to respecting the rights of Data Subjects in accordance with the Personal Data Protection Law and other applicable laws and regulations, to the extent that such rights apply in each case. These rights include the following:
Right to Be Informed
The Data Subject has the right to be informed of the legal basis for the Collection of their Personal Data, the purpose for which it is collected, the manner in which it is Processed, the parties to whom it may be Disclosed, and the applicable retention period, through this Privacy Policy or by any other means adopted by the Company.
Right of Access to Personal Data
The Data Subject has the right to request access to their Personal Data Processed by the Company, in accordance with the procedures and controls prescribed under applicable laws and regulations.
Right to Obtain a Copy of Personal Data
The Data Subject may request a copy of their Personal Data in a clear and readable format or, where applicable and technically feasible, in a commonly used electronic format, in accordance with applicable laws, regulations, and controls.
Right to Correction of Personal Data
If the Data Subject becomes aware that any of their Personal Data is inaccurate, incomplete, or outdated, they have the right to request that such Personal Data be corrected, completed, or updated.
The Company will review the request and take the appropriate action within the period prescribed by applicable laws and regulations.
Right to Request Destruction of Personal Data
The Data Subject may request the Destruction of their Personal Data where permitted under applicable laws and regulations, provided that such request does not conflict with any legal obligation requiring the Company to retain the Personal Data for a specified period, or with any other lawful basis permitting the continued Processing of such Personal Data under applicable laws and regulations.
Right to Withdraw Consent
Where the Processing of Personal Data is based on the Data Subject’s consent, the Data Subject has the right to withdraw such consent at any time.
Withdrawal of consent will not affect the lawfulness of any Processing carried out on the basis of consent prior to its withdrawal, nor will it affect any Processing that may continue on the basis of another lawful basis under applicable laws and regulations.
Exercising Data Subject Rights
The Data Subject may exercise any of the rights set out above by contacting the Company through the contact details provided in this Privacy Policy.
The Company may request additional information or documentation to verify the identity of the person submitting the request before responding to it, in order to protect Personal Data and prevent unauthorized access.
The Company will review and respond to requests within the period prescribed by applicable laws and regulations. A request may be refused, in whole or in part, where such refusal is based on a lawful or legitimate ground, and the Company will notify the requester of the reason for the refusal where required by applicable laws and regulations.
Cookies and Similar Technologies
The website uses cookies and similar technologies to improve website performance, facilitate its use, analyze usage patterns, and enhance the user experience.
Users may manage their cookie preferences through their browser settings. However, disabling certain cookies may affect the functionality or performance of certain features of the website or the Services.
Messages and Notifications
The Company may send users operational messages or notifications relating to the provision of the Services, including account activation messages, One-Time Passwords (OTPs), payment or purchase transaction notifications, and alerts relating to the user’s account or the Services.
Where the Company sends messages of a marketing nature, such messages will be sent in accordance with applicable laws and regulations, and users will be provided with the ability to unsubscribe from such messages where required or available.
Third-Party Links and Websites
The Application or website may contain links to websites, applications, or services operated by third parties. Such third-party websites, applications, and services are not managed or controlled by the Company.
The Company is not responsible for the privacy policies or Personal Data Processing practices of such third parties. Users are encouraged to review the applicable privacy policies of those third parties before using their services or providing them with any Personal Data.
Changes to This Privacy Policy
The Company may amend or update this Privacy Policy from time to time to reflect legal, regulatory, technical, or operational developments, or other changes relating to the Services provided by the Company.
The updated version of this Privacy Policy will be published through the Application or website and will become effective as of the date of its publication, unless otherwise specified.
Users are encouraged to review this Privacy Policy periodically to remain informed of any updates.
Contact Us
If you have any questions regarding this Privacy Policy or the manner in which your Personal Data is Processed, or if you wish to exercise any of your rights under this Privacy Policy or applicable laws and regulations, you may contact the Company using the following contact details:
Company Name: Abdulaziz bin Hamad Al-Subait Limited Liability Company Address: Riyadh, Al Hassan Al Khallal, Building No. 2401 Email: support@fosshati.com.sa Telephone: +966505899699
The Company is committed to reviewing and handling requests, complaints, and objections relating to Personal Data in accordance with the applicable laws and regulations of the Kingdom of Saudi Arabia.