f. We may use your personal data to investigate fraudulent claims or applications made by insurance policyholders, including cases of large-scale or
organized fraud, medical malpractice, and to conduct Anti-Money Laundering (AML) checks.
g. We may also share the information we collect where we are legally obliged to do so, e.g., to comply with a court order.
h. Any social media posts or comments you send to us: (on Gulf Union Alahlia’s Facebook page, for instance) will be shared under the terms of the relevant
social media platform (e.g., Facebook, Twitter, LinkedIn, or other) on which they are written, and could be made public. Other people, not Gulf Union Alahlia,
control these platforms. Gulf Union Alahlia is not responsible for this kind of sharing. Before you make any remarks or observations about anything, you should
review the terms and conditions and privacy policies of the social media platforms you use. That way, you will understand how they will use your information,
what information relating to you they will place in the public domain, and how you can stop them from doing so if you are unsatisfied about it. It is worth
remembering that any blog, review, or other posts or comments you make about us and/or our products and services on any of our blogs, reviews, or user
community services will be shared with all other members of that service and the public at large. You should take extra care to ensure that any comments you
make on these services, and on social media in general are fit to be read by the public, and are not offensive, insulting, or defamatory. Ultimately, you are
responsible for ensuring that any comments you make comply with any relevant policy on acceptable use of those services.
i. Third parties/ Data Processors: To whom we may choose to sell, transfer, or merge parts of our business or our assets. Alternatively, we may seek to
acquire other businesses or merge with them. If a change occurs in our business, we will notify you, and the new owners may use your personal data in
accordance with the terms outlined in this privacy notice. We require all third parties to respect the security of your personal data and to treat it in accordance
with the law. We do not allow our third-party service providers/ data processors to use your personal data for their own purposes and only permit them to
process your personal data for specified purposes and in accordance with our instructions/third-party agreements.
How do we protect your personal data?
Gulf Union Alahlia uses appropriate technical and organizational measures to protect the personal data that we collect and process. The measures Gulf Union
Alahlia uses are designed to provide a level of security appropriate to the risk of processing your personal data.
A lot of the information we receive reaches us electronically, originating from your devices, and is then transmitted by your relevant telecoms network provider.
Where it’s within our control, we put measures in place to ensure this ‘in flight’ data is as secure as it possibly can be.
Sensitive data like, passwords are protected for data in transit by data encryption. In addition to encryption, we have implemented robust network security
controls to help protect data in transit. Network security solutions like firewalls and/or network access control to secure the networks used to transmit data
against malware attacks or intrusions.
We do not permit the copying of official documents that identify Data Subjects, except where required by law or if a competent public authority requests such
copying in accordance with applicable regulations.
Gulf Union Alahlia uses secure means to communicate with you where appropriate, such as ‘https’ and other security and encryption protocols.
How long will we keep your personal data?
We will retain your personal data only for as long as necessary to fulfill the purposes for which it was collected. Once these purposes are met, we will securely
destroy the data without undue delay, unless there is a legal requirement to retain it for a specific period. In such cases, we will retain the data until the legal
retention period expires or the original purpose is fulfilled, whichever is longer. Additionally, if the data is needed for an ongoing judicial matter, we will retain it
until the legal process is concluded.
Your personal data will also be retained in accordance with the period authorized by regulatory authorities and for the purposes specified in this Privacy Notice.
We will use and retain information as necessary to comply with legal obligations, resolve disputes, and enforce our legal agreements and policies, following
instructions from regulatory authorities such as the Council of Health Insurance (CHI), the Insurance Authority, the Saudi Data and Artificial Intelligence Authority
(SDAIA), and other applicable regulations within the Kingdom of Saudi Arabia. During the retention period, we will implement all necessary organizational,
administrative, and technical measures to ensure the security and protection of your personal data.
Automated Decision Making
Automated decisions are decisions concerning you which are made automatically on the basis of a computer determination (using software algorithms), without
human intervention. We do not use automated decision-making.
What are your data protection rights?
Your duty to inform us of changes:
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes by keeping your details
up to date on our website and by sharing your updated details with our DPO at <insert email ID>.
Your rights in connection with personal data:
Under certain circumstances, by law, you have the right to:
a. Be informed: We must inform you what is being collected, from whom it is collected, what it is being used for, how long it will be kept, and if and with
whom it will be shared.
b. Be provided with sufficient information on the automated decision-making mechanism, if any, in plain and clear language.
c. Access personal data: We must provide a method in which you can access your personal data, when requested.
d. Correct, update, complete personal data: We must enable you to correct/ update/ complete your personal data in case your data is incomplete, outdated
or is inaccurate.
e. Destruct personal data: We must destruct your personal data upon your request and when it is considered lawful under the PDPL.