Compliance & confidentiality

Trust begins with protecting information.

We handle sensitive financial and personal data every day. That's why we treat compliance and confidentiality as the foundation of the service, not an add-on.

Our position

Collection touches the rights of two parties

Debt collection touches the rights of two parties: a creditor awaiting what is due, and a debtor whose dignity and privacy are protected by law.

We are committed to carrying out this work in accordance with the laws and regulations in force in the Kingdom of Saudi Arabia, and to respecting the principles of the Personal Data Protection Law in how information is collected, used and stored. This page sets out what we commit to — towards our clients, towards debtors, and towards the information itself.

Saudi laws & regulations Personal Data Protection Law principles Dignity of every debtor
Data protection

Our data-protection commitments

Eight commitments that govern how we handle the data of the businesses we serve and of their debtors.

01

Access on operational need

Only staff whose duties require it can view file data. Permissions are reviewed regularly and revoked as soon as they are no longer needed.

02

Confidentiality of client and debtor data

We treat the data of the businesses we serve and of their debtors as a trust, disclosing it to no third party without written authorisation or a lawful request.

03

Use within the agreed scope

Data is used solely for the purpose it was provided for, never for marketing or any other commercial activity.

04

Adherence to procedures and controls

We operate under written data-protection policies and procedures, on which every employee is trained, updated in step with regulation.

05

Data minimisation

We request and retain only what is needed to deliver the service.

06

Secure retention and disposal

Data is kept for the period the contract and regulations require, then returned to the client or securely and verifiably destroyed.

07

Binding confidentiality undertakings

Every employee and contractor signs a confidentiality undertaking that applies during and after their engagement.

08

Respect for data-subject rights

Requests for access and correction are handled as guaranteed by the Personal Data Protection Law, in coordination with the creditor as data controller.

Ethical collection code

Eleven principles that shape every conversation

These principles bind everyone who communicates on behalf of Sedad Mawthooq. They are part of team training and performance evaluation.

  1. 01

    Respect first

    Every debtor is addressed courteously, whatever the amount, the age of the debt or the nature of their response.

  2. 02

    No threats, no intimidation

    We never threaten action we cannot take or that has not been taken, and never use scare tactics or undue pressure.

  3. 03

    No harassment

    Contact frequency stays reasonable; we never call repeatedly to the point of nuisance.

  4. 04

    Defined contact hours

    We contact debtors within an approved window on working days [e.g. 9:00 AM–9:00 PM], avoiding prayer times and public holidays unless the debtor requests otherwise.

  5. 05

    Privacy from third parties

    We never disclose a debt to a debtor's relatives, colleagues, neighbours or employer, nor leave messages revealing its details to others.

  6. 06

    Clear identification

    We identify ourselves and the creditor we represent at the start of every contact.

  7. 07

    Accurate information

    Amounts, their origin and supporting documents are stated exactly as they are, and any error is corrected as soon as it is verified.

  8. 08

    Every contact documented

    Calls are recorded and correspondence archived, and the debtor is informed that the call is being recorded.

  9. 09

    Official payment channels only

    We never ask for transfers to personal accounts, and never accept cash outside approved procedures.

  10. 10

    Disputes are heard

    If a debtor disputes the amount or the debt itself, we document the objection and refer it to the creditor, and do not pursue the disputed portion until it is resolved.

  11. 11

    Care in special circumstances

    Illness, bereavement and humanitarian situations are handled with flexibility and consideration, and referred to the creditor for review.

Complaints & feedback

Every concern is heard and reviewed

If you have a concern about how one of our team communicated — whether you are a client or a debtor — we want to hear it.

01

Tell us

Write to complaints@sadadmag.com or call +966 56 611 8820.

02

Independent review

Every complaint is referred to a function independent of the team concerned.

03

Acknowledgement

We acknowledge receipt within two business days.

04

Resolution

We aim to resolve it within ten business days at most.

Information-security practices

Controls proportionate to the data we hold

We apply technical and administrative controls proportionate to the sensitivity of the data we handle, and review them continuously.

Ask a security question
  • Secure data transferFiles are exchanged with clients through agreed encrypted channels, never via ordinary email or personal messaging apps.
  • Access controlIndividual user accounts, strong passwords, and multi-factor authentication on sensitive systems.
  • Audit logsLogins, file views and edits are logged so any unusual activity can be traced.
  • Device protectionCentrally managed, secured work devices, with restricted use of external storage media.
  • BackupsRegular, protected backups to ensure business continuity and record integrity.
  • Ongoing awarenessRegular team training on cybersecurity and on recognising fraud and phishing attempts.
  • Incident responseA written procedure for any security incident, covering containment, investigation, and notification of the client and competent authorities as the regulations require.

Have specific compliance requirements?

We review your internal policies and sector requirements with you, and build them into the service agreement.