1. معلومات عن الهيئة
أنشئت هيئة تطوير محمية الملك عبد العزيز الملكية بموجب قرار مجلس الوزراء ذي الرقم 437 والمؤرخ في 1/7/1441هـ الموافق 24/2/2020م. وتُعنى الهيئة بتطوير محمية الملك عبد العزيز الملكية، والمحافظة على ثرواتها الطبيعية، وتمتلك السلطة التشريعية والتنظيمية للمحمية، وتعمل على تنفيذ إستراتيجية تطويرها، بالتعاون مع مختلف الجهات العاملة في المنظومة البيئية المحلية والعالمية، للمحافظة على بيئة المحمية وضمان استدامتها لأجيال اليوم والمستقبل، وحرصاً من هيئة تطوير محمية الملك عبدالعزيز الملكية على بيانات ومعلومات المستخدم تم إعداد سياسة الخصوصية التي توضح كيفية جمع واستخدام وتخزين وإتلاف وحماية البيانات الشخصية التي يتم تقديمها من قبل المستخدم أثناء استخدام موقع الهيئة، علماً بأن استخدام موقع الهيئة يعد قبولاً ضمنياً من المستخدم على سياسة الخصوصية.
2. البيانات التي سيتم جمعها والغرض من جمعها
البيانات الشخصية التي تُفصِح لنا عنها: نجمع البيانات الشخصية التي تقدمها لنا طواعيةً عند تسجيلك للحصول على خدماتنا والإعراب عن اهتمامك بمعرفة معلومات عن الهيئة أو عن المنتجات والخدمات التي تقدمها، أو عندما تتواصل معنا بطريقة أخرى.
البيانات الشخصية التي تقدمها: تعتمد البيانات الشخصية التي نجمعها على تفاعلاتك معنا ومع الخدمات، والخيارات التي تتخذها، والمنتجات أو الميزات التي تستخدمها. يجب أن تكون جميع البيانات الشخصية التي تقدمها لنا صحيحةً وكاملةً ودقيقة، ولديك مطلق الحرية في إشعارنا بأي تغييرات تطرأ على تلك البيانات.
البيانات التي تُجمَع تلقائيًّا: تُجمع بعض البيانات -مثل عنوان بروتوكول الإنترنت الخاص بك و/أو خصائص المتصفح والجهاز- تلقائيًّا عند استخدام خدماتنا ولا تُستخدم لأي أغراض أخرى.
3. الغرض من جمعها
يتم جمع البيانات الشخصية من أجل تقديم الخدمات الحكومية المطلوبة وتحسين جودة الخدمات وتجربة المستفيد.
4. طرق جمع البيانات
- يتم جمع البيانات التي يقوم صاحب البيانات الشخصية بتزويد الموقع بها عن طريق التسجيل، ولا يتم جمع بيانات شخصية من أي جهات أخرى.
- يتم جمع بياناتك الشخصية بطريقة غير مباشرة عن طريق ملفات الارتباط التي يتم جمعها عند زيارة الموقع (Cookies).
5. تخزين البيانات الشخصية وإتلافها
يتم تخزين البيانات الشخصية في خوادم محمية بأفضل التقنيات، كما تتخذ الهيئة جميع التدابير اللازمة لحماية البيانات الشخصية بما يتوافق مع سياسات وضوابط الهيئة الوطنية للأمن السيبراني وذلك لضمان عدم الوصول غير المصرح به والحد من المخاطر السيبرانية، وسيتم بعد ذلك إتلاف البيانات بطريقة آمنة لا يمكن من خلالها الاطلاع عليها أو استعادتها مرة أخرى.
6. الأساس النظامي لجمع ومعالجة البيانات الشخصية
يتم جمع ومعالجة البيانات الشخصية وفق الأنظمة السعودية ذات العلاقة لنظام حماية البيانات الشخصية بناء على موافقة صاحب البيانات الشخصية، ويمكنه الرجوع عن موافقته على جمع ومعالجة بياناته الشخصية في أي وقت ما لم يكن هناك أساس نظامي آخر، وللقيام بذلك يمكن التواصل مع مكتب إدارة البيانات في الهيئة عن طريق البريد الإلكتروني dmo@karnr.gov.sa.
7. حقوق صاحب البيانات الشخصية
- الحق في العلم: يحق لصاحب البيانات الشخصية معرفة طرق جمعنا لبياناته والأساس النظامي لجمعها ومعالجتها، وكيفية معالجتها وحفظها وإتلافها ومع من ستتم مشاركتها ويمكنك الاطلاع على كافة التفاصيل من خلال سياسة الخصوصية -هذه السياسة- أو يمكن التواصل معنا من خلال نماذج "اتصل بنا".
- الحق في تصحيح البيانات الشخصية: يحق لصاحب البيانات الشخصية أن يطلب تصحيح بياناته الشخصية التي يرى أنها غير دقيقة أو غير صحيحة أو غير مكتملة، وذلك عن طريق البريد الإلكتروني الموضح في البند السادس خلال مدة 7 أيام عمل من تاريخ الطلب.
- الحق في إتلاف البيانات الشخصية: يحق لصاحب البيانات الشخصية أن يطلب إتلاف بياناته الشخصية في ظروف معينة ما لم يكن هناك نص نظامي أو متطلبات تعاقدية تحدد مدة معينة للاحتفاظ بالبيانات.
- الحق في الرجوع عن الموافقة على معالجة البيانات الشخصية: يمكن لصاحب البيانات الشخصية الرجوع عن الموافقة على معالجة بياناته الشخصية في أي وقت ما لم تكن هناك أغراض مشروعة تتطلب عكس ذلك.
- الحق في الوصول: الحق في وصوله إلى بياناته الشخصية المتوفرة لدى الهيئة، ويشمل ذلك الاطلاع عليها، بناءً على طلب يقدمه، أو من خلال وسيلة توفرها جهة التحكم تمكّنه من الوصول إلى بياناته الشخصية بشكل تلقائي دون الحاجة إلى تقديم طلب.
8. مشاركة/ تبادل البيانات الشخصية
لا توجد مشاركة أو تبادل للبيانات الشخصية التي يتم جمعها من خلال موقع الهيئة مع جهات أخرى.
9. ممارسة حقوق صاحب البيانات الشخصية
يحق لصاحب البيانات الشخصية طلب الوصول/ التصحيح/ إتلاف بياناته عن طريق التواصل عبر البريد التالي:
10. حماية البيانات الشخصية
- تشفير البيانات أثناء النقل باستخدام بروتوكول (HTTPS).
- المراقبة الدورية للأنظمة المستخدمة للتحقق من عدم وجود التهديدات السيبرانية.
- استخدام الأنظمة التقنية الملاءمة لمنع الوصول غير المصرح به للبيانات.
1. About the Authority
The King Abdulaziz Royal Reserve Development Authority was established pursuant to Council of Ministers Resolution No. 437, dated 01/07/1441 AH (corresponding to 24/02/2020 AD). The Authority is tasked with developing the King Abdulaziz Royal Reserve, preserving its natural resources, and holding legislative and regulatory authority over the Reserve. It implements development strategies in collaboration with various local and global entities operating across the environmental ecosystem to safeguard the Reserve's environment and ensure its sustainability for current and future generations. In line with the Authority’s dedication to protecting user data and information, this Privacy Policy has been formulated to detail how personal data provided by users while utilizing the Authority’s website is collected, used, stored, destroyed, and protected. Using the Authority’s website constitutes implicit acceptance of this Privacy Policy.
2. Data to be Collected and the Purpose of Collection
Personal Data You Disclose to Us: We collect personal data that you voluntarily provide when registering for our services, expressing interest in obtaining information about the Authority or its products and services, participating in activities related to the services, or when you contact us through other means.
Personal Data You Provide: The personal data collected depends on your interactions with us and the services, the choices you make, and the products or features you utilize. All personal data provided to us must be accurate, complete, and true. You remain free to notify us of any changes to such data.
Automatically Collected Data: Certain data—such as your Internet Protocol (IP) address and/or browser and device characteristics—is collected automatically when utilizing our services and is not used for any other purposes.
3. Purpose of Collection
Personal data is collected to deliver requested government services, enhance service quality, and improve beneficiary experience.
4. Data Collection Methods
- Data provided directly by the personal data owner during website registration is collected; no personal data is collected from external parties.
- Personal data is collected indirectly through cookies gathered upon visiting the website.
5. Storage and Destruction of Personal Data
Personal data is stored on servers protected by advanced technical standards. The Authority takes all necessary measures to protect personal data in compliance with National Cybersecurity Authority (NCA) policies and controls, ensuring prevention of unauthorized access and mitigating cyber risks. Data is subsequently destroyed securely, preventing any unauthorized viewing or recovery.
6. Legal Basis for Collecting and Processing Personal Data
Personal data is collected and processed in accordance with relevant Saudi laws under the Personal Data Protection Law based on the consent of the data owner. The data owner may withdraw consent for data collection and processing at any time unless another legal basis exists. To do so, the Data Management Office at the Authority may be contacted via email: dmo@karnr.gov.sa.
7. Rights of the Personal Data Owner
- Right to Knowledge: The data owner has the right to know our collection methods, legal basis for collection and processing, handling, retention, destruction procedures, and parties with whom data will be shared. Complete details can be reviewed via this Privacy Policy or by contacting us through the "Contact Us" forms.
- Right to Rectification: The data owner has the right to request correction of personal data deemed inaccurate, incorrect, or incomplete via the email specified in Clause 6 within 7 business days from the request date.
- Right to Destruction: The data owner has the right to request the destruction of personal data under certain circumstances, unless statutory requirements or contractual obligations dictate specific retention periods.
- Right to Withdraw Consent: The personal data owner may withdraw consent to the processing of personal data at any time, unless legitimate interests require otherwise.
- Right of Access: The data owner has the right to access personal data available with the Authority, including reviewing it upon request, or via automated tools provided by the controller enabling direct access without requiring a formal request.
8. Personal Data Sharing / Exchange
Personal data collected through the Authority's website is neither shared nor exchanged with third parties.
9. Exercising Data Owner Rights
The personal data owner has the right to request access, rectification, or destruction of personal data by contacting:
10. Personal Data Protection
- Data encryption in transit using Secure Hypertext Transfer Protocol (HTTPS).
- Continuous monitoring of systems to detect and prevent cyber threats.
- Implementation of appropriate technical controls to prevent unauthorized access.