Tell us about
your project.
Thank you!
Your inquiry has been received and is now under review by our team. We’ll contact you soon.
Back to website
Back to website
Oops! Something went wrong while submitting the form.

PRIVACY POLICY

Website Privacy & Personal Data Protection Notice

Field

Detail

Effective Date

15 August 2026

Version

2.0

Controller

Ashmont

Commercial Registration

7001716013

Privacy Contact

info@ashmont.com.sa

National Address

Building 4129, Prince Khalid Ibn Bandar Ibn Abdulaziz Street, Al Arid District, Riyadh, Kingdom of Saudi Arabia

Related Document

Ashmont Cookie Notice; Ashmont Website Terms of Use and Intellectual Property Notice

This policy describes how Ashmont collects, processes, stores, protects, shares and transfers personal data through its website and related digital services.

Contents

       1. About Ashmont and Data Controller
‍
       2. Scope of this Privacy Policy
‍
       3. Global Access to the Website
‍
       4. Personal Data We May Collect
‍
       5. Mandatory and Optional Information
‍
       6. Sensitive Personal Data
‍
       7. How Personal Data Is Collected
‍
       8. Webflow: Hosting, CMS and Form Processing
‍
       9. Cloudflare Turnstile: Security and Anti-Spam
‍
       10. Cookies, Analytics and Consent
‍
       11. Purposes of Processing
‍
       12. Legal Bases for Processing
‍
       13. Data Minimisation and Accuracy
‍
       14. Confidentiality and Ashmont Digital Systems
‍
       15. Disclosure and Third-Party Service Providers
‍
       16. International Processing and Data Transfers
‍
       17. Retention and Secure Destruction
‍
       18. Information Security
‍
       19. Your Rights Under Article 4 of the PDPL
‍
       20. How to Exercise Your Rights
‍
       21. Direct Marketing
‍
       22. Automated Decision-Making
‍
       23. Children and Persons Lacking Legal Capacity
‍
       24. Instagram, LinkedIn, Email and External Links
‍
       25. Website Content and Terms of Use
‍
       26. Changes to this Privacy Policy
‍
       27. Questions, Complaints and Contact
‍
       28. Governing Regulatory Framework

Ashmont (“Ashmont”, “we”, “us” or “our”) respects the privacy of individuals who visit, access or interact with our website and is committed to protecting personal data in accordance with the applicable laws and regulations of the Kingdom of Saudi Arabia.

This Privacy Policy explains how Ashmont collects, uses, processes, stores, protects, discloses, transfers and destroys personal data obtained through the Ashmont website, including information submitted through the Contact Us form and information generated through standard website functionality and security tools.
‍
This Privacy Policy has been prepared with reference to the Personal Data Protection Law of the Kingdom of Saudi Arabia (the “PDPL”), its Implementing Regulations, the Regulation on Personal Data Transfer Outside the Kingdom, and applicable requirements and guidance issued by the competent Saudi authority.

Two related documents form part of Ashmont’s website documentation and should be read alongside this Policy: the Ashmont Cookie Notice, which explains cookies, security technologies and analytics in detail; and the Ashmont Website Terms of Use and Intellectual Property Notice, which governs use of website content.

1.  About Ashmont and Data Controller

Ashmont is an engineering, architecture and design consultancy based in Riyadh, Kingdom of Saudi Arabia. Its professional services include architecture, interior design, mechanical, electrical and plumbing (MEP) engineering, project consultancy, project supervision, and related multidisciplinary design and engineering services.

For personal data collected through the Ashmont website, Ashmont acts as the Data Controller. This means Ashmont determines the purposes for which personal data is processed and the principal means by which that processing is carried out.

Data Controller

Ashmont

Commercial Registration

7001716013

Privacy Email

info@ashmont.com.sa

National Address

Building 4129, Prince Khalid Ibn Bandar Ibn Abdulaziz Street, Al Arid District, Riyadh, Kingdom of Saudi Arabia

Website Contact

Contact Us page and the email address above

Ashmont has assessed whether it is required to appoint a Personal Data Protection Officer under the PDPL and the applicable rules issued by the competent Saudi authority. Where such an appointment is required, the relevant contact details will be published in this Policy and registered with the competent authority. Until then, privacy enquiries should be directed to the contact above.

2.  Scope of this Privacy Policy

This Privacy Policy applies to personal data processed through Ashmont’s public website, including the Homepage, Services, Projects, Insights, Contact Us page, and any other website page or form that links to this Policy.

The website is primarily an informational and corporate website used to present Ashmont, its professional services, projects, design work, photographs, videos, articles and company information. It is not currently intended to operate as an e-commerce platform, payment platform, customer account portal or recruitment portal.

3.  Global Access to the Website

The Ashmont website may be accessed by visitors located both within and outside the Kingdom of Saudi Arabia. This Privacy Policy applies to personal data processed by Ashmont through the website regardless of the visitor’s physical location, subject to any additional mandatory rights or requirements that may apply under the law applicable to a particular visitor.

A visitor accessing the website from outside Saudi Arabia does not, by itself, constitute an international transfer of personal data by Ashmont. International transfers concern the movement, disclosure, storage or access of personal data across jurisdictions and are addressed in Section 16.

4.  Personal Data We May Collect

4.1  Information Submitted Through the Contact Us Form

The Contact Us form collects the categories of information set out in the table at Section 5, which also identifies which fields are mandatory and which are optional.

In addition to the form fields, the free-text message area may contain any information a visitor chooses to include, such as project details, requirements, timelines or other commercial information. Visitors should include only information relevant to their enquiry.

4.2  Technical Information Generated Through Website Use

Depending on the technical configuration of the website and the services described in Sections 8 to 10, technical information may include:

     — Internet Protocol (IP) address or network information used for routing, security or technical operation;

     — Browser type and version;

     — Device type and operating system;

     — Date and time of access;

     — Pages viewed and general interaction information;

     — Referring website or traffic source;

     — Technical, diagnostic and error information;

     — Security and anti-abuse signals;

     — Cookie or similar technology information, where applicable, as described in the Ashmont Cookie Notice.

5.  Mandatory and Optional Information

Ashmont identifies clearly on the Contact Us form which fields must be completed and which are optional. Mandatory fields are marked with an asterisk (*) on the form itself, and the table below reflects the current form configuration.

Field

Status

Why it is collected / consequence if not provided

Full name

Mandatory

Required to identify the enquirer and address a response appropriately. Without it, the form cannot be submitted.

Email address

Mandatory

Required as the primary channel for Ashmont to reply. Without it, Ashmont cannot respond to the enquiry.

Message / enquiry details

Mandatory

Required for Ashmont to understand and evaluate the enquiry. Without it, Ashmont cannot assess whether its services are relevant.

Telephone or mobile number

Optional

Allows Ashmont to respond by telephone where that is faster or more appropriate. Not providing it simply means Ashmont will respond by email.

Company or organisation name

Optional

Helps Ashmont understand the context of the enquiry. Not providing it does not prevent a response.

Job title or position

Optional

Helps Ashmont direct the enquiry to the appropriate team. Not providing it does not prevent a response.

Type of service or project of interest

Optional

Helps Ashmont route the enquiry internally. Not providing it may result in a more general response or a follow-up request for detail.

Consequences of not providing mandatory information. Fields marked as mandatory are the minimum Ashmont requires in order to receive, evaluate and respond to an enquiry. If a mandatory field is not completed, the form cannot be submitted and Ashmont will not receive the enquiry. If mandatory information is provided but is inaccurate or incomplete — for example, an incorrect email address — Ashmont may be unable to respond, and may be unable to evaluate the enquiry or progress any related discussion, proposal or professional engagement.

Providing optional information is entirely at the visitor’s discretion. Declining to provide optional information will not, by itself, prevent Ashmont from receiving or responding to an enquiry, although in some cases it may mean Ashmont needs to ask follow-up questions before it can respond substantively.

6.  Sensitive Personal Data

Ashmont does not intend to collect sensitive personal data through the general website or Contact Us form. Visitors should not submit sensitive personal data through a general website enquiry unless it is genuinely necessary and appropriate for the communication.

If Ashmont is required to process sensitive personal data in another professional, contractual or legal context, that processing will be handled separately and in accordance with applicable Saudi Arabian law.

7.  How Personal Data Is Collected

7.1  Directly From You

     — When you complete the Contact Us form;

     — When you send an email to Ashmont;

     — When you request information about Ashmont’s professional services;

     — When you contact Ashmont regarding a potential project, proposal or business opportunity;

     — When you otherwise voluntarily provide information to Ashmont;

7.2  Through Website Technology and Service Providers

Certain information is processed through the technology providers used to host, operate, secure and analyse the Ashmont website. The principal services currently used are described in Sections 8 to 10.

8. Webflow: Hosting, CMS and Form Processing

Ashmont uses Webflow as the website platform for hosting, content management system (CMS) functionality, forms and standard website operation. Webflow, Inc. is established in the United States of America.

When a visitor submits information through an Ashmont website form, the submission is transmitted to and processed through Webflow’s form infrastructure on Ashmont’s behalf. Under Ashmont’s current website configuration:

     — the submission is stored within Ashmont’s authorised Webflow site environment, where it remains accessible to authorised Ashmont personnel;

     — Webflow sends a form notification containing the submitted information to Ashmont at info@ashmont.com.sa; and

     — the submission is also processed through Webflow’s hosting, content delivery and security infrastructure in the ordinary course of delivering the website.

Webflow acts as an external technology service provider and processor in relation to personal data processed through the platform on Ashmont’s behalf. Webflow engages authorised infrastructure providers and subprocessors in delivering its services, including cloud hosting and content delivery network providers. Personal data processed through Webflow may therefore be stored on, transmitted through or accessed from infrastructure located outside the Kingdom of Saudi Arabia. This is addressed in detail at Section 16.

Ashmont remains the Data Controller and remains responsible for determining why information submitted to Ashmont is used and for handling that information in accordance with applicable Saudi data-protection requirements.

9.  Cloudflare Turnstile: Security and Anti-Spam

Ashmont uses Cloudflare Turnstile on the Contact Us form as a security and anti-spam measure. Turnstile is provided by Cloudflare, Inc., established in the United States of America, and helps distinguish legitimate human visitors from automated bots, abusive traffic and fraudulent form submissions.

Cloudflare’s role. Cloudflare acts as a processor on Ashmont’s behalf in providing the Turnstile service. Ashmont determines that Turnstile is deployed on the Contact Us form and for what purpose; Cloudflare performs the technical assessment and returns a result indicating whether a submission appears legitimate. Cloudflare does not receive the content of the enquiry itself through Turnstile.

In performing that assessment, Cloudflare may process technical and behavioural signals relating to the visitor’s browser and session, which may include:

     — IP address and network-level information;

     — Browser type, version and configuration, and information about installed browser features;

     — Device and operating system characteristics;

     — Interaction and timing signals relating to how the page and form are used;

     — A Turnstile-issued token or identifier used to record the outcome of the challenge for the duration of the session;

     — Other signals Cloudflare uses to detect automated or abusive traffic;

Turnstile generally operates in the background and usually does not require a visitor to complete a traditional CAPTCHA, although in some cases an interactive step may be presented. Turnstile is deployed as necessary security functionality rather than as advertising, profiling or behavioural marketing technology, and Ashmont does not use Turnstile signals for marketing purposes.

Cloudflare’s own privacy documentation describes in further detail how it processes data in providing Turnstile. Because Cloudflare operates a global network, the signals described above may be processed outside the Kingdom of Saudi Arabia; see Section 16.

10. Cookies, Analytics and Consent

Detailed information about the cookies and similar technologies used on the Ashmont website — including strictly necessary cookies, security technologies, any analytics technologies, the categories used, their purposes and duration, and how consent is obtained and withdrawn — is set out in the separate Ashmont Cookie Notice, which is available on the website and forms part of Ashmont’s website privacy documentation.

In summary, and as more fully described in the Cookie Notice:
‍
     — Strictly necessary cookies and security technologies are used to operate the website safely and correctly and do not require consent under applicable requirements;

     — No analytics technology is currently operated on the website. Any non-essential technology introduced in future will not be activated until the visitor provides consent through the cookie banner or preference mechanism;

     — Consent may be withdrawn at any time through the mechanism described in the Cookie Notice;

     — Visitors may reject non-essential technologies without losing access to the ordinary public content of the Ashmont website.

Ashmont does not use the website for advertising pixels, behavioural advertising or remarketing technologies. If that changes, Ashmont will update this Privacy Policy and the Cookie Notice, and will implement the applicable consent controls, before or when such processing is introduced.

11. Purposes of Processing

Ashmont may process personal data for the following purposes:

     — Receiving, reviewing and responding to enquiries and messages;
‍
     — Understanding potential project requirements and determining whether Ashmont’s services are relevant;

     — Communicating with prospective clients, consultants, contractors, suppliers or business partners;

     — Preparing for discussions, proposals, quotations or professional engagements;

     — Administering a professional or contractual relationship where an enquiry develops into a project or engagement;

     — Operating, maintaining, troubleshooting and improving the website;

     — Protecting the website, systems and networks against spam, bots, misuse, fraud, unauthorised access and cyber threats;

     — Understanding general website performance and usage through consent-controlled analytics, if such analytics is introduced in future;

     — Maintaining reasonable business and correspondence records;

     — Complying with applicable legal, regulatory, judicial or governmental obligations;

     — Establishing, exercising or defending Ashmont’s legal rights and protecting its legitimate business interests where permitted by law.

Ashmont will not intentionally process personal data for a new purpose that is incompatible with the purpose for which it was collected unless the processing is otherwise permitted by applicable law.

12.  Legal Bases for Processing

Depending on the processing activity and the circumstances, Ashmont may rely on one or more lawful bases permitted under the PDPL and its Implementing Regulations.

12.1  Consent

Where consent is required, Ashmont may process personal data on the basis of the individual’s consent. Consent may be withdrawn in accordance with applicable law, without affecting processing lawfully carried out before withdrawal.

12.2  Contractual or Pre-Contractual Purposes

Where an individual contacts Ashmont in connection with a potential or existing professional engagement, processing may be necessary to take steps requested by the individual or to establish, administer or perform the relevant contractual relationship.

12.3  Legal Obligations

Ashmont may process personal data where required to comply with applicable laws, regulations, judicial requirements or authorised governmental requests.

12.4  Legitimate Interests

Where permitted under Saudi law, Ashmont may process non-sensitive personal data where necessary to achieve a legitimate interest, provided that the applicable legal requirements and safeguards are satisfied and the rights and interests of the individual are not unfairly prejudiced. Examples may include reasonable business administration, website security, responding to professional enquiries and protecting Ashmont’s legal and commercial interests.

13. Data Minimisation and Accuracy

Ashmont seeks to collect only personal data that is reasonably necessary and relevant to the purpose for which it is collected. Visitors are encouraged not to provide information that is unrelated to their enquiry.

Ashmont also seeks to keep personal data accurate, complete and up to date where this is necessary for the relevant purpose. Individuals may request correction, completion or updating of their personal data as described in Sections 19 and 20.

14.  Confidentiality and Ashmont Digital Systems

Personal data received by Ashmont is treated as confidential information. Copies received and retained by Ashmont are maintained within Ashmont’s authorised digital environment, which may include its business email systems, approved cloud or business systems, authorised internal digital records and, where relevant, client or project records.

Website form submissions also remain stored within Ashmont’s authorised Webflow website environment. Access is restricted, where reasonably practicable, to authorised Ashmont personnel and approved service providers who require access for a legitimate business or technical purpose.

Ashmont does not make information submitted through the Contact Us form publicly available.

15. Disclosure and Third-Party Service Providers

Ashmont does not sell personal data. Personal data may be disclosed where there is an appropriate purpose and legal basis, including to:

     — Authorised Ashmont employees, management and representativesWebflow, for website hosting, CMS functionality and form processing;

     — Cloudflare, for Turnstile security and anti-spam functionality;

     — Approved IT, email, cloud, cybersecurity, website maintenance and technical support providers;

     — Professional advisers such as lawyers, accountants, auditors and insurers where reasonably necessary;

     — Consultants, subconsultants or professional service providers where a website enquiry develops into a project or professional engagement and disclosure is necessary for that purpose;

     — Government, regulatory, judicial or law-enforcement authorities where disclosure is required or permitted by law;

     — Other parties where the individual has authorised the disclosure or where another lawful basis applies.

Where a third party processes personal data on Ashmont’s behalf, Ashmont will put in place a written processing arrangement and take the other steps required by the PDPL and its Implementing Regulations in relation to the appointment, instructions, security and protection of the data.

16. International Processing and Data Transfers

Ashmont is established in the Kingdom of Saudi Arabia. However, the technology providers used to operate, secure and analyse the website are established outside the Kingdom and operate global infrastructure. Personal data processed through the website will therefore, in the ordinary course, be processed, stored, transmitted or accessed outside Saudi Arabia.

16.1  Which Transfers Occur

The principal transfers arising from the website are set out below.

Provider

Role

Data involved

Where processed

Webflow, Inc.

Processor — hosting, CMS and form processing

Contact Us form submissions, including name, email, telephone, company, position, service interest and message content; plus website technical and log data

United States and other locations used by Webflow’s authorised infrastructure providers, cloud hosting providers and content delivery network subprocessors

Cloudflare, Inc.

Processor — Turnstile security and anti-spam

Technical and behavioural signals described in Section 9; not the content of the enquiry

Cloudflare’s global network, which routes traffic through the point of presence nearest the visitor and may include locations outside the Kingdom

16.2  Safeguards Applied

Where personal data is transferred or disclosed outside the Kingdom, Ashmont handles the transfer in accordance with the PDPL, the Regulation on Personal Data Transfer Outside the Kingdom and other applicable requirements. Depending on the transfer and the provider, the measures applied include:

     — Purpose limitation — the transfer must serve a lawful and defined purpose, and the transferred data is limited to what is necessary for that purpose;

     — Contractual safeguards — entry into the data-processing terms made available by the relevant provider and, where required, an appropriate transfer mechanism such as standard contractual clauses approved by or consistent with the requirements of the competent Saudi authority;

     — Assessment of protection — an assessment of the level of protection available to the transferred data in the destination jurisdiction, taking into account the provider’s own security and legal commitments;

     — Transfer risk assessment — where required under the applicable Regulation, a risk assessment is carried out and documented before the transfer proceedsSubprocessor controls — reliance on the provider’s contractual commitments regarding the engagement, oversight and flow-down of obligations to its authorised subprocessors;

     — Technical and organisational measures — encryption in transit, access controls and the other measures described in Section 18;

     — Minimisation — configuring the website so that no more personal data than necessary is exposed to the relevant provider.

Ashmont keeps the transfer arrangements applicable to its website providers under review and will update this Policy if the providers, the destinations or the applicable safeguards change materially.

For the avoidance of doubt, the fact that a visitor is physically located outside Saudi Arabia when accessing the website does not, by itself, mean that Ashmont has transferred that visitor’s personal data outside the Kingdom.

17.  Retention and Secure Destruction

Ashmont retains personal data only for as long as reasonably necessary for the purpose for which it was collected, or for a longer period where retention is required or permitted by applicable law.

The retention period or criteria applied may depend on:

     — The nature and purpose of the enquiry;

     — Whether the enquiry develops into a client, project or contractual relationship;

     — The need to maintain reasonable business correspondence records;

     — Applicable legal, contractual, financial, audit, insurance or professional record-keeping requirements;

     — Potential disputes, claims or legal proceedings;

     — Website security and troubleshooting requirements;

     — The retention settings and deletion capabilities of authorised service providers.

General website enquiries that do not develop into an ongoing business or professional relationship are periodically reviewed and removed when they are no longer reasonably required for the purposes described above. This review covers both Ashmont’s internal systems and the form submissions stored within the Webflow environment.

Where an enquiry develops into a professional engagement, relevant information may become part of Ashmont’s client or project records and may be retained for the period reasonably necessary to satisfy the applicable professional, contractual and legal requirements.

When personal data is no longer required and there is no lawful basis for continued retention, Ashmont takes appropriate steps to delete, destroy, anonymise or otherwise render the data inaccessible. Where data is contained in technical backups, deletion may occur through the applicable backup replacement or secure deletion cycle.

18. Information Security

Ashmont takes reasonable administrative, organisational and technical measures designed to protect personal data from unauthorised access, disclosure, loss, misuse, alteration, destruction, damage and other unlawful processing.Measures may include, where appropriate:

     — Controlled access to business systems and website administration environments;

     — Authentication and account-security controls;

     — Appropriate cybersecurity and network protectionsRestricted access to business email and digital records;

     — Use of security tools such as Cloudflare Turnstile to reduce automated abuse;

     — Encryption of data in transit;

     — Confidentiality obligations for personnel and service providers;

     — Appropriate backup, recovery and administrative procedures;

     — Periodic review of access, systems and retention practices.

No method of internet transmission or electronic storage can be guaranteed to be completely secure. If a personal data breach occurs, Ashmont will assess and manage the incident and will notify the competent authority and, where required, affected individuals, within the periods required by applicable law.

19. Your Rights Under Article 4 of the PDPL

Article 4 of the PDPL confers the following five rights on data subjects, “pursuant to this Law and as set out in the Regulations”. Each right is therefore subject to the conditions, controls, procedures, limitations and exceptions established by the PDPL and its Implementing Regulations, and to any other applicable legal requirement.

Article 4 right

What it means

4(1) — Right to be informed

The right to be informed of the legal basis and the purpose for the collection of your personal data. This Privacy Policy, together with the Cookie Notice, is provided in satisfaction of that right.

4(2) — Right of access

The right to access your personal data held by Ashmont, in accordance with the rules and procedures set out in the Implementing Regulations and without prejudice to Article 9 of the PDPL.

4(3) — Right to obtain your personal data

The right to request to obtain your personal data held by Ashmont in a readable and clear format, in accordance with the controls and procedures specified by the Implementing Regulations.

4(4) — Right to correction, completion or updating

The right to request the correction, completion or updating of your personal data held by Ashmont.

4(5) — Right to request destruction

The right to request the destruction of your personal data held by Ashmont where it is no longer needed, without prejudice to Article 18 of the PDPL and to any legal, regulatory, contractual or judicial requirement obliging Ashmont to retain it.

19.1  Further Rights Under the PDPL and the Implementing Regulations

In addition to the rights conferred by Article 4, and subject in each case to the applicable conditions and exceptions:

     — Withdrawal of consent — where processing is based on consent, that consent may be withdrawn at any time in accordance with the PDPL and the Implementing Regulations. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and does not require Ashmont to cease processing carried out on a different lawful basis;

     — Right to complain — the right to submit a privacy complaint to Ashmont and, where applicable, to the competent Saudi authority, as described in Section 27;

     — Rights in relation to direct marketing — as described in Section 21.

Limitations and exceptions. The rights described in this Section are not absolute. Ashmont may decline or restrict a request, in whole or in part, where the PDPL, its Implementing Regulations or any other applicable law so permits or requires — including where the request would prejudice the rights of another person, where the data is required for the establishment, exercise or defence of legal claims, where a legal or regulatory retention obligation applies, or where an exception under Article 9 or Article 18 of the PDPL is engaged. Where Ashmont declines a request, it will explain the reason unless prevented from doing so by law.

20. How to Exercise Your Rights

To exercise a personal data right, request correction or destruction, withdraw consent, or make a privacy-related enquiry, contact Ashmont using:

     — Email: info@ashmont.com.sa

     — Address: Building 4129, Prince Khalid Ibn Bandar Ibn Abdulaziz Street, Al Arid District, Riyadh, Kingdom of Saudi Arabia

     — The Contact Us page on the Ashmont website

Ashmont may request information reasonably necessary to verify the identity of the person making the request before providing, changing or destroying personal data. This is a protective measure and is intended to prevent disclosure to an unauthorised person.

Valid requests are handled without undue delay and within the period required by applicable law. Under the Implementing Regulations, rights requests are generally addressed within 30 days of receipt, subject to any extension, limitation or exception permitted by law. Where an extension applies, Ashmont will inform the individual of the extension and the reason for it.

There is no charge for exercising these rights, save where the applicable law permits a reasonable fee in defined circumstances.

Where a valid request concerns information retained in Ashmont’s Webflow environment or other authorised service-provider systems, Ashmont will take reasonable steps to action the request within those systems, subject to applicable legal and technical requirements, and will instruct its processors accordingly.

21. Direct Marketing

The Ashmont website is not currently used as a behavioural advertising or remarketing platform. Ashmont will not use personal means of communication to send direct promotional or advertising material where prior consent is required under applicable law unless the necessary consent has been obtained.

Where Ashmont later offers newsletters, Insights subscriptions or other marketing communications, the relevant consent or opt-out mechanism will be provided separately, and each communication will include a means of unsubscribing. A request to stop marketing communications will not prevent Ashmont from sending necessary project, contractual, professional or administrative communications supported by another lawful basis.

22.  Automated Decision-Making

Ashmont does not use personal data collected through the general website or Contact Us form to make decisions based solely on automated processing that produce legal or similarly significant effects on visitors. The automated assessment performed by Cloudflare Turnstile is limited to distinguishing legitimate visitors from automated traffic for security purposes and does not produce such effects.

23.  Children and Persons Lacking Legal Capacity

The Ashmont website is intended for clients, professionals, consultants, businesses, organisations and individuals interested in Ashmont’s professional services and projects. It is not designed to solicit personal data from children or persons lacking full legal capacity. 

If Ashmont becomes aware that personal data has been collected in circumstances requiring additional consent, guardian involvement or legal protection, Ashmont will take appropriate steps in accordance with applicable law, which may include ceasing processing and destroying the data.

24.  Instagram, LinkedIn, Email and External Links

24.1  Instagram and LinkedIn

The Ashmont website may contain ordinary hyperlinks to Ashmont’s Instagram and LinkedIn pages and to other external platforms. Selecting an external link may take the visitor away from the Ashmont website.

Once a visitor accesses an external platform, that third party’s own privacy policy, cookie practices, terms and data-processing activities apply. Ashmont does not control the independent privacy practices or technical operation of Instagram, LinkedIn or other third-party websites.

24.2  Email Links

Where the website includes an email hyperlink, selecting it may open the visitor’s default email application or email service. Information is provided to Ashmont when the visitor chooses to compose and send an email. Once received, that communication is treated as confidential and processed in accordance with this Privacy Policy.

25.  Website Content and Terms of Use

Ashmont’s rights in the content published on the website — including architectural and interior designs, engineering work, drawings, renders, photographs, videos, written content and branding — together with the treatment of third-party material referenced in the Insights section, are addressed in the separate Ashmont Website Terms of Use and Intellectual Property Notice, which is available on the website.

Those provisions concern intellectual property and permitted use of the website rather than the processing of personal data, and have been separated from this Privacy Policy so that each document remains clear and focused on its subject matter.

26.  Changes to this Privacy Policy

Ashmont may update this Privacy Policy periodically to reflect changes in the website, website technology, service providers, personal-data processing practices, applicable laws or regulatory guidance.

The latest version is made available through the Ashmont website. The Effective Date and Version shown at the beginning of this Policy identify the date on which the current version took effect and the version in force. Where a change is material, Ashmont will take reasonable steps to bring it to the attention of affected individuals.

27. Questions, Complaints and Contact

If you have a question, concern or complaint regarding this Privacy Policy or Ashmont’s processing of personal data, please contact Ashmont first so that the matter can be reviewed.

Company

Ashmont

Commercial Registration

7001716013

Email

info@ashmont.com.sa

National Address

Building 4129, Prince Khalid Ibn Bandar Ibn Abdulaziz Street, Al Arid District, Riyadh, Kingdom of Saudi Arabia

If an individual believes that a privacy concern has not been adequately addressed, the individual may have the right to submit a complaint to the Saudi Data & AI Authority (SDAIA), as the competent authority for personal-data protection in the Kingdom of Saudi Arabia, through the channels made available by the National Data Governance Platform and in accordance with applicable procedures and time limits.

Where mandatory privacy law in another jurisdiction applies to a particular individual or processing activity, the individual may also have rights to contact another competent supervisory authority in accordance with that law.

28.  Governing Regulatory Framework

This Privacy Policy is governed by and interpreted in accordance with the applicable laws and regulations of the Kingdom of Saudi Arabia, including, where applicable:

     — The Personal Data Protection Law (PDPL)The Implementing Regulations of the Personal Data Protection Law;

     — The Regulation on Personal Data Transfer Outside the Kingdom;

     — The rules issued by the competent authority in relation to the appointment of Personal Data Protection Officers;

     — Applicable rules, decisions and guidance issued by the competent Saudi authority.

Nothing in this Privacy Policy is intended to limit any mandatory right granted to an individual under applicable law.

Contact
Contact
Thank you!
Your inquiry has been received and is now under review by our team. We’ll contact you soon.
Oops! Something went wrong while submitting the form.