Allo Mazare'a← Back to home

Privacy Policy

Allo Mazare'a — Nuwas Co.

Terms & ConditionsPrivacy Policy

Chapter One: Introduction

Nawas Company (the “Company”) welcomes you to the Alo farmer application (the “Application”).

The Company is committed to protecting the privacy of all Users of the Application and maintaining the confidentiality of their Personal Data in accordance with the applicable laws and regulations of the Kingdom of Saudi Arabia, including the Personal Data Protection Law (“PDPL”) and its Implementing Regulations.

This Privacy Policy explains how Personal Data is collected, used, processed, disclosed, and protected. It also sets out the rights of Data Subjects and the procedures through which they may exercise those rights.

By using, registering with, or benefiting from the services of the Application, the User acknowledges that they have reviewed and agreed to this Privacy Policy.

Chapter Two: Definitions

Company

Nawas Company, the owner and operator of the Alo farmer Application.

Application

The Alo farmer electronic platform in all its versions, including mobile applications, the website, and any other digital channels approved by the Company.

Personal Data

Any information relating to an identified natural person or a natural person who may be identified directly or indirectly, including their name, identification number, mobile number, email address, address, geographical location data, and any other data protected under applicable law.

Data Subject

Any natural person to whom the Personal Data processed through the Application relates.

Processing

Any operation performed on Personal Data, whether manually or electronically, including collection, recording, organisation, storage, modification, use, disclosure, transfer, deletion, and destruction.

Service Provider

Any individual or establishment registered with the Application to provide agricultural services to Customers.

Chapter Three: Personal Data We Collect

First: Account Data

  • Full name.
  • Mobile number.
  • Email address.
  • Password, stored in encrypted form.
  • Profile photograph, where optionally provided.

Second: Identification Data, Where Required

  • National identity card or residence permit.
  • Commercial registration, in the case of establishments.
  • Licences or permits required to conduct the relevant activity.

Third: Location Data

Location Data may be collected and used for the following purposes:

  • Identifying the location where the Service is to be performed.
  • Recommending nearby Service Providers.
  • Improving response times for Service Requests.

Fourth: Request Data

  • Type of Service requested.
  • Date and time of the Request.
  • Service location address.
  • Photographs or notes added by the User.
  • Status of the Request and the User’s previous Service history.

Fifth: Payment Data

When electronic Payment Methods are used, certain data relating to the payment transaction may be processed.

Payment card information is generally managed by licensed payment service providers. The Company does not retain complete payment card details except to the extent permitted by applicable laws, regulations, and industry standards.

Sixth: Technical Data

  • Device type.
  • Operating system.
  • Internet Protocol address (“IP Address”).
  • Device identifier.
  • Usage logs.
  • Browser type.
  • Error reports and performance analytics.

Chapter Four: Purposes of Processing Personal Data

Personal Data may be processed for the following purposes:

  • Creating and managing the User’s Account.
  • Processing and fulfilling Service Requests.
  • Enabling communication between the Customer and the Service Provider where necessary.
  • Processing payments and issuing invoices.
  • Verifying identity and complying with legal and regulatory requirements.
  • Improving the quality of Services and the User experience.
  • Developing the Application and adding new features.
  • Responding to enquiries and complaints.
  • Sending notifications relating to Requests or the Account.
  • Sending offers or marketing communications after obtaining the necessary consent, where required by law.
  • Preventing fraud and misuse and enhancing Platform security.
  • Fulfilling legal and regulatory obligations.

Chapter Five: Lawful Basis for Processing Personal Data

The Company may process Personal Data on one or more of the following lawful bases:

  • The consent of the Data Subject, where such consent is required.
  • The performance of a contract to which the Data Subject is a party.
  • Compliance with a legal or regulatory obligation.
  • The pursuit of a legitimate interest of the Company or the Data Subject, provided that such interest does not conflict with the Data Subject’s lawful rights and interests.

Chapter Six: Disclosure and Sharing of Personal Data

Nawas Company does not sell, rent, or trade Users’ Personal Data.

Personal Data shall only be disclosed within the limits permitted by applicable law and for the purposes specified in this Privacy Policy.

Article (1): Sharing Data With Service Providers

The following information may be shared with a Service Provider where necessary:

  • The User’s first name or approved display name within the Application.
  • Contact number, where required.
  • Location where the Service is to be performed.
  • Details of the Request.
  • Scheduled appointment.

Such information may only be used for the purpose of performing the Service and must not be used for any other purpose.

Article (2): Government and Regulatory Authorities

Personal Data may be disclosed:

  • To comply with a court judgment or judicial order.
  • In response to a lawful request.
  • To comply with applicable laws and regulations.
  • To protect the lawful rights of the Company or Users.

Article (3): Third-Party Service Providers

Personal Data may be shared with third-party providers that support the operation of the Application, including:

  • Electronic payment service providers.
  • Text messaging service providers.
  • Email service providers.
  • Cloud hosting providers.
  • Mapping and location service providers.
  • Analytics service providers.
  • Technical support service providers.

Such parties are required to protect Personal Data in accordance with the agreements entered into with them and the applicable laws and regulations.

Chapter Seven: Data Protection and Information Security

The Company applies appropriate technical, organisational, and administrative measures to protect Personal Data, including:

  • Encrypting sensitive data during transmission and storage where appropriate.
  • Protecting servers and databases.
  • Using identity verification and access-control measures.
  • Monitoring systems and detecting attempted security breaches.
  • Performing periodic data backups.
  • Periodically reviewing access permissions.
  • Training employees on data protection and confidentiality requirements.

Despite these measures, no electronic system can be guaranteed to be entirely free from risks.

The Company therefore exercises reasonable care to reduce such risks and to respond to information security incidents in accordance with applicable laws and regulations.

Chapter Eight: Data Retention

The Company retains Personal Data only for as long as necessary to fulfil the purposes for which it was collected, comply with legal and regulatory obligations, or protect legal rights.

When Personal Data is no longer required, it shall be deleted, destroyed, or anonymised so that the Data Subject can no longer be identified, in accordance with applicable laws and approved policies, unless the Company is legally required to retain it for a longer period.

Chapter Nine: Rights of Data Subjects

First: Right to Be Informed

The Data Subject has the right to be informed of:

  • The lawful basis for collecting their Personal Data.
  • The purpose for which the Personal Data is processed.
  • The parties to whom the Personal Data may be disclosed.

Second: Right of Access

The Data Subject may request access to, or a copy of, the Personal Data held by the Company, subject to applicable legal requirements and restrictions.

Third: Right to Rectification

The Data Subject may request the correction of any inaccurate or incomplete Personal Data.

Fourth: Right to Destruction

The Data Subject may request the deletion or destruction of their Personal Data in cases permitted by law, subject to any legal or contractual obligations requiring the Company to retain certain data.

Fifth: Right to Withdraw Consent

Where Processing is based on the Data Subject’s consent, the Data Subject may withdraw that consent at any time.

Withdrawal of consent shall not affect the lawfulness of any Processing carried out before the withdrawal or any other lawful basis that permits the continued Processing of the Personal Data.

Chapter Ten: Cookies

The Application or website may use cookies and similar technologies for the following purposes:

  • Improving the performance of the Application.
  • Remembering User preferences.
  • Analysing usage.
  • Enhancing security.
  • Measuring the quality of Services.

The User may control cookie settings through their browser or device settings.

The User acknowledges that disabling certain cookies may affect the performance or availability of some Application functions.

Chapter Eleven: Transfer of Personal Data

Personal Data may be processed or stored within or outside the Kingdom of Saudi Arabia in accordance with the applicable legal requirements and regulatory controls and in a manner that ensures an appropriate level of protection.

Where Personal Data is transferred outside the Kingdom, the Company shall comply with the legal and regulatory requirements applicable to cross-border transfers of Personal Data.

Chapter Twelve: Contact and Complaints

Users may contact the Company to exercise their rights relating to their Personal Data or to submit any enquiry or complaint regarding this Privacy Policy through the official communication channels announced by the Company within the Application or on its website.

The Company shall review and respond to such requests within the timeframes and in accordance with the procedures prescribed by applicable laws and the Company’s internal policies.

Chapter Thirteen: Updates to the Privacy Policy

The Company may amend this Privacy Policy from time to time to reflect legal, regulatory, operational, or technical developments.

The updated version shall be published within the Application together with its effective date.

The User’s continued use of the Application after the amendments become effective shall constitute acceptance of the amended Privacy Policy, to the extent permitted by applicable law.

Chapter Fourteen: Effective Date

This Privacy Policy shall enter into force from the date of its publication within the Alo farmer Application and shall form an integral part of the Terms and Conditions governing the use of the Application.

© 2026 Allo Mazare'a. All rights reserved.Home