Skip to content
Provatto
Partnersالعربية

Privacy Policy

Effective date: 14 July 2026 · Last updated: 14 July 2026

Contents

  1. 1) Who We Are
  2. 2) Scope of This Policy
  3. 3) Data We Collect
  4. 4) How We Collect Data
  5. 5) Purposes of Processing
  6. 6) Legal Basis for Processing
  7. 7) Data Minimization
  8. 8) Data Accuracy
  9. 9) Disclosure of Personal Data
  10. 10) Transfer of Data Outside the Kingdom
  11. 11) Processors and Technical Service Providers
  12. 12) Data Retention
  13. 13) How Data Is Destroyed
  14. 14) Data Protection and Security
  15. 15) Notification of Security Incidents
  16. 16) Rights of the Data Subject
  17. 17) How to Exercise Rights
  18. 18) Marketing and Messages
  19. 19) Minors
  20. 20) Official Documents and Sensitive Data
  21. 21) Third-Party Data Provided by the User
  22. 22) Log Files and Technical Data
  23. 23) Amendments to This Policy
  24. 24) Governing Language
  25. 25) Contact Us

This policy explains how Ziad Nasser Alwashmi Trading Est. (Commercial Registration No. 7053851809), as the operator of the Provatto app, collects, processes, stores, discloses, and protects personal data when you use the app or its related services, in accordance with the Personal Data Protection Law of the Kingdom of Saudi Arabia and related regulations.

1) Who We Are

Provatto is an app that lets users create a digital record for watches and related collectibles, manage the associated data, and document certain facts and events within the app — including recording the transfer of a digital record between accounts at a user's request and with the other party's consent.

Business name: Ziad Nasser Alwashmi Trading Est.

Commercial Registration: 7053851809

Contact email: support@provatto.app

Address: Kingdom of Saudi Arabia, Riyadh, Al-Ghadeer district, postal code 13311

2) Scope of This Policy

This policy applies to the personal data we collect from users when creating an account, using the app, contacting us, or using the app's various functions. It also applies to data we collect from third parties within the limits permitted by law and where a legal basis exists.

3) Data We Collect

  • Account and contact data: name, email, mobile number, city, username, and account verification data.
  • Collectible digital record data: brand, model, reference number, serial number, purchase price, purchase date, photos, notes, and the event log associated with the item.
  • In-app transaction data: digital-record transfer request data, acceptance or rejection status, time and date, and the identity of the accounts involved.
  • Technical data: IP address, device or app identifier, device type, operating system, access logs, access times, crash data, and technical usage logs necessary to operate and secure the app.
  • Communication and support data: any information the user provides when contacting us for inquiries, support, complaints, or to exercise their statutory rights.

4) How We Collect Data

  • Directly from the user when creating an account, filling in fields, uploading photos, updating a digital record, or contacting us.
  • Automatically through the app and its related technical systems during use, such as technical logs and crash data.
  • From another user, in a limited scope, when using the digital-record transfer function, within the limits necessary to carry out the function and per the appropriate legal basis.

5) Purposes of Processing

  • Creating an account, signing in, and managing user identity.
  • Operating the app and enabling users to create and manage a digital record of their collectibles.
  • Carrying out functions requested by the user, including logging events and digital-record transfer requests.
  • Verifying account security and preventing misuse, fraud, or unauthorized access.
  • Providing technical support and customer service and handling complaints and requests.
  • Developing the app and improving performance and user experience.
  • Complying with legal obligations and requests from competent authorities.
  • Sending operational notifications related to the account, service, security, or material updates.
  • Sending marketing materials only where permitted by law and after obtaining consent where legally required.

6) Legal Basis for Processing

  • The consent of the data subject, where required under the Personal Data Protection Law.
  • Performance of an agreement to which the data subject is a party, or pre-contractual steps at their request, pursuant to Article 6 of the Law.
  • The legitimate interest of the controller, provided it does not prejudice the data subject's rights and the data is not sensitive, pursuant to Articles 10 and 15 of the Law.
  • Compliance with a legal obligation or a request from a competent authority.

7) Data Minimization

We ensure that personal data is adequate and limited to the minimum necessary to achieve the purpose of its collection and processing, pursuant to Article 11 of the Personal Data Protection Law.

8) Data Accuracy

The user must provide correct, accurate, and up-to-date data. We take reasonable steps to verify data accuracy, pursuant to Article 14 of the Law.

9) Disclosure of Personal Data

  • To technical service providers who process data on our behalf to operate, host, or technically support the app, per Article 8 of the Law.
  • To the other party in a digital-record transfer process, to the extent necessary to carry out the function.
  • If you request or consent to it in accordance with the law.
  • Where necessary to comply with a legal obligation or a request from a competent authority.
  • Where necessary to protect our legal rights, the security of the app or users, or to prevent fraud, within legal limits.

We do not sell personal data to third parties, nor disclose it for unauthorized or legally impermissible purposes.

10) Transfer of Data Outside the Kingdom

Some personal data may be hosted or processed inside or outside the Kingdom through technical service providers. If data is transferred outside the Kingdom, this is done in accordance with Article 29 of the Law, including: the transfer being for a legitimate, specific purpose; not prejudicing national security or the Kingdom's vital interests; an adequate level of protection being available; the transfer being limited to the minimum necessary; and appropriate contractual, organizational, and technical measures being taken.

11) Processors and Technical Service Providers

We may engage processors or service providers for cloud hosting, database, or infrastructure support. We select entities that provide the necessary guarantees, pursuant to Article 8 of the Law, without prejudice to our responsibility toward data subjects.

12) Data Retention

We retain personal data for as long as necessary to achieve the stated purposes, and when the purpose ends we destroy it without undue delay pursuant to Article 18 of the Law, unless there is a legal basis for retention. Upon an account deletion request, we generally seek to carry out deletion within 30 days, unless retention is legally or technically necessary or due to an existing dispute.

13) How Data Is Destroyed

When data is no longer needed, we take appropriate measures to destroy it or remove what would specifically identify its owner, in a way that prevents unlawful access or recovery.

14) Data Protection and Security

We take appropriate organizational, administrative, and technical measures to protect data from loss, misuse, unauthorized access, alteration, or unlawful disclosure, pursuant to Article 19 of the Law, including access controls, account protection, encryption, access monitoring, and security incident management.

15) Notification of Security Incidents

If we become aware of a leak, damage, or unlawful access to data that may cause harm, we will handle it in accordance with Article 20 of the Law, including the necessary notification to the competent authority or the data subject where legally required.

16) Rights of the Data Subject

  • The right to be informed of the legal basis and purpose for collecting their data.
  • The right to access their personal data held by us.
  • The right to request their data in a readable, clear format where legally possible.
  • The right to request correction, completion, or updating of the data.
  • The right to request destruction of data no longer needed, without prejudice to statutory retention cases.
  • The right to withdraw consent, without affecting the lawfulness of prior processing.
  • The right to file a complaint with the competent authority if their request is not handled per the law.

17) How to Exercise Rights

Email: support@provatto.app

We will exercise due care to respond within the statutory period, pursuant to Article 21 of the Law, taking into account any legal restrictions or exceptions.

18) Marketing and Messages

We do not use your contact data to send marketing materials except after obtaining consent where legally required, pursuant to Articles 25 and 26 of the Law. We also provide a clear means to stop these messages at any time.

19) Minors

The app is intended for those who are eighteen (Hijri) years or older. We do not knowingly allow accounts for those under this age, and if it becomes clear otherwise we may suspend or close the account and take necessary action per the law.

20) Official Documents and Sensitive Data

We do not normally request the uploading of official identity documents, and the user may not upload them unless we explicitly request so for a legitimate legal reason. The app is not intended to collect sensitive data, and the user must refrain from entering any sensitive data, official documents, or third-party data without a legal basis.

21) Third-Party Data Provided by the User

If the user provides data relating to another person, they must be legally authorized to enter it, and its use must be necessary for a legitimate, specific purpose. The user remains responsible for the correctness of this action and for not misusing third-party data.

22) Log Files and Technical Data

We may use technical logs and limited usage data for operation, protection, crash analysis, performance measurement, and service improvement, and it is not used for any unrelated purpose except under the appropriate legal basis.

23) Amendments to This Policy

We may amend this policy from time to time. When making material amendments, we will notify users by an appropriate means. Continued use of the app after updates take effect constitutes acceptance within the limits permitted by law.

24) Governing Language

This policy was drafted in Arabic, which is the reference in case of any difference in interpretation, unless we publish another approved version and stipulate otherwise.

25) Contact Us

Email: support@provatto.app

Address: Kingdom of Saudi Arabia, Riyadh, Al-Ghadeer district, postal code 13311

Back to the home page

PartnersPrivacyTermsContact usالعربية

Commercial register 7053851809© 2026 Provatto