Controller and data
Strategy to Knowledge Office for Communications and Information Technology is the controller of data collected by STK Lite. The privacy contact channel appears on the business details page. We collect names, email addresses, mobile numbers, organization names, scope details and policy consents.
Data is collected directly from customers to prepare orders, communicate, deliver services, bill, provide support and meet legal obligations. For payments, we store transaction identifiers, status, amount and environment for linking and reconciliation. We do not collect or store full card numbers or CVC codes.
When transactional messaging is active, we process recipient addresses and order confirmation or payment receipt content. An operational log stores message type, provider identifier, sending/delivery/bounce/complaint status and related times. This log contains no full card numbers or CVC codes.
Name, email, mobile number and requirements are required to process an order; without them, an order cannot be created. Organization name and marketing consent are optional.
To protect the service and enforce attempt limits, the application derives a one-way fingerprint from the IP address within a short time window. Rate-limit records do not store raw IP addresses. Fingerprints expire with the protection window and are removed in the next cleanup cycle.
Basis and purpose
We process order data for pre-contractual steps, contract performance, legal obligations and site protection. Acceptance of terms is not treated as marketing consent.
Order confirmations, payment receipts and operational notifications are sent to service the order and establish its status. They do not depend on marketing consent and contain no marketing offers, with one exception: if you consent to marketing updates, your order confirmation may include a short list of optional additions available for the ordered service. Payment receipts never include these suggestions.
Marketing consent is optional, separate and not preselected. It can be withdrawn without affecting an order.
Sharing and transfers
Moyasar Financial Company processes payment data directly as the payment provider. Hosting and support providers may process order data as needed to provide their services. Personal data is not sold.
When Tabby is shown at checkout and when selected, we send it your name, email, mobile number, order amount and line items as displayed in the amount summary (service, extra pages, Arabic/English version, selected add-ons and priority delivery where applicable, each line’s amount, and any discount and VAT), plus summaries of previous STK Lite orders (date, amount, status and service) to assess eligibility and complete installment payment. We also send a pseudonymous customer ID without contact details and a digital delivery address (Riyadh with the business postcode or a general city postcode) instead of a shipping address. Tabby processes this data independently under its privacy policy and may process it outside Saudi Arabia where applicable.
When Tamara is shown at checkout, we send it your email, mobile number and order amount for preliminary eligibility checks. When selected, we send your name, email, mobile number, order amount and reference, and line items as displayed in the amount summary (service, extra pages, Arabic/English version, selected add-ons and priority delivery where applicable, each line’s amount, and any discount and VAT) to complete the financing request. Tamara processes this data under its privacy policy.
When you use Saud, your messages are sent to STK’s assistant service, which uses an AI provider that may process messages outside Saudi Arabia solely to generate replies. STK Lite does not store conversations. A copy remains in your browser until the tab closes. No enquiry is sent to STK until you press the send button yourself, at which point it is treated as a contact enquiry.
When transactional email is enabled, we use Resend, provided by Plus Five Five, Inc., as a processor and sending provider. Resend receives recipient details, message content and delivery data needed to send order confirmations, payment receipts and company notifications. It may use subprocessors under its published list and terms.
Resend or some subprocessors may process data outside Saudi Arabia. Only the minimum required for the message is sent. Enabling transfers requires assessment of purpose, destination and protection level, and documentation of appropriate legal safeguards under the Personal Data Protection Law and cross-border transfer regulations. If transfer requirements are not met, sending through this service remains disabled.
Retention and rights
Each data category is retained according to its purpose. Order data and related financial records, including payment receipts, are kept for the statutory commercial-record retention period. Transactional email delivery logs and rate-limit fingerprints are kept for the shortest period needed to operate and protect the service. Data is destroyed or anonymized when its purpose ends unless a law or ongoing dispute requires longer retention.
The email provider may retain copies or technical logs for periods defined by its service terms and applicable data processing agreement. Deleting an STK Lite record may not immediately delete those copies; their deletion is subject to the provider’s terms and relevant legal obligations.
You may request information, access, a copy, correction or destruction of data where the right applies. Send privacy requests to support@stk.sa with the subject “Privacy request” and an order reference if available. We respond within the statutory period and explain any justified extension.
Data subjects may complain to the Saudi Data and Artificial Intelligence Authority (SDAIA) if they believe processing violates the Personal Data Protection Law.
This version does not automatically delete order records. Retention, destruction and anonymization are reviewed manually, with identity checks and review of any dispute or legal obligation before action.
Optional interaction analytics
With your optional analytics consent, Contentsquare (Hotjar) may provide click maps and interaction recordings on public pages. Assistant conversations are masked, and administration, order, tracking and payment pages are excluded. Interaction data is sent to Contentsquare (Hotjar) under its terms and account settings and may be processed outside Saudi Arabia. You can withdraw consent through cookie settings in the footer. The cookie policy explains the tools and choices.
Security and incidents
We use transport encryption, restricted access, input validation, audit logs and provider review. In a data incident, we activate assessment and notification procedures within statutory timeframes.