Version 1.0 — Last updated: 10 September 2026

Who we are and scope of this policy

BedBank Company (شركة بدبانك) is a Saudi company operating the BedBank.SA platform, its subdomains, the partner portal and the application programming interface (API) for wholesale distribution of hotel accommodation in the Kingdom and worldwide. We contract with travel and tourism agencies, tour operators, Umrah operators and corporate travel buyers ("Partners") and fulfil their accommodation bookings with hotels and accommodation suppliers.

This policy explains what personal data we collect and why, how we use, share, retain and destroy it, and what your rights are and how to exercise them, in accordance with the Personal Data Protection Law issued by Royal Decree No. (M/19) dated 9/2/1443H, as amended, and its Implementing Regulations.

This policy applies to:

If you are a guest, the Partner that booked for you collected your details from you directly and is bound by its agreement with us to inform you of this policy and to obtain whatever is required before entering your details. We are the controller of the booking records we hold on our platform.

Contact details

Responsible team: Privacy and Data Protection Team — BedBank Company

Address: Office 12, Floor 1, Al Khayyat Tower, Abu Bakr As Siddiq Road, Al Sharafeyah District, Jeddah 23218, Kingdom of Saudi Arabia

Unified number: 920035522

Email: Info@BedBank.SA

Commercial registration: 7050680649

Personal Data Protection Officer: Reachable through the email address above with the subject line "Personal Data Protection"

This policy in one minute

Who we areA Saudi B2B platform for wholesale distribution of hotel accommodation to Partners.
What we collectPartner account and user details, guest details needed for bookings, payment and settlement data, and technical logs.
WhyTo fulfil, settle and support bookings, protect the platform, comply with the law, and market to you only with your consent.
Who we share it withHotels and suppliers according to the booking, the payment gateway, hosting and notification providers, and competent authorities on lawful request. We do not sell your data.
Where we keep itOn cloud servers inside the Kingdom (Riyadh region); booking details are transferred to the hotel in its country when the stay is outside the Kingdom.
How longBy data type (Section 7): from the end of a session up to 10 years for financial records.
Your rightsTo be informed, access, obtain a copy, correct, destroy, withdraw consent, complain and claim compensation.
How to reach usInfo@BedBank.SA — we respond within 30 days.

1. Personal data we collect

We collect the minimum needed for each service, and our forms distinguish mandatory fields from optional ones. The data falls into the following categories:

CategoryExamplesMandatory or optionalSource
Partner account and usersName, work email, mobile number, job title and permissions, preferred language and currency, credentials (the password is stored as a derived value, not readable text) and API keysMandatory to open the account; mobile number optional unless two-factor authentication is enabledThe Partner user directly
Partner business detailsCompany name, commercial registration or tourism licence, tax number, national address, authorised representative details, bank account for settlementsMandatory for eligibility checks and invoicingThe Partner; verified against official registers
Guests and travellersNames as shown on the travel document, title, nationality, country of residence, children's ages, lead-guest status, special requests, expected arrival timeNames, nationality and children's ages are mandatory to confirm a booking; the rest is optionalThe Partner on behalf of the guest
BookingDestination, hotel, stay dates, rooms and occupancy, price and cancellation terms, booking reference and voucher, status and amendmentsCreated automatically on bookingThe platform and the hotel or supplier
Payment and settlementPayment method, transaction amount and currency, payment reference and status, prepaid balance and credit-limit movements, statements and tax invoices, refund details. We never receive or store the full card number or security code; card details are entered only on the payment gateway pageMandatory for payment and settlementThe Partner and the payment gateway
Support and correspondenceTicket and message content, attachments and contact detailsWhatever you choose to sendYou
Technical use and securityIP address, browser, device and operating system, pages and requests and their timing, API logs and sign-in attemptsCollected automatically to operate and protect the platformThe platform
MarketingNewsletter and offer subscription preferencesOptional, with your consentYou

Sensitive data: We do not request sensitive data within the statutory meaning (such as health, religious, credit or biometric data). If a Partner includes in a special request something that reveals a guest's health need (such as an accessible room), it is processed solely to fulfil that request with the hotel, and the Partner is responsible for obtaining the guest's explicit consent before entering it.

Minors: Children's ages are collected only for occupancy and pricing. No account is created for anyone under 18; a child's details are entered by a parent, guardian or the authorised Partner.

2. How we collect your data

Directly from you: through registration forms, account settings, the booking interface, the API, and contact and support forms.

Indirectly:

  • From the Partner: guest details entered to complete a booking, and details of anyone booking on a Partner's behalf.
  • From hotels and suppliers: booking confirmations and amendments, and arrival or no-show status.
  • From the payment gateway: the result and reference of a payment or refund.
  • From official registers: to verify a Partner's commercial registration and tourism licence.
  • Automatically: through cookies and technical logs when you use the platform (Section 8).

When booking for others, the person entering the data must ensure they are authorised to provide it and must inform its owners of this policy.

3. Purposes and legal bases

We tie every processing activity to its specific purpose and to a legal basis set out in Article 6 of the Law, and we do not later process your data in a way incompatible with the purpose for which it was collected.

PurposeData usedLegal basis
Opening the Partner account and managing users and permissionsPartner account and users, business detailsPerformance of the Partner agreement, and legitimate interest in managing access
Verifying Partner eligibility and preventing commercial fraudBusiness detailsLegal requirement (tourism licensing and invoicing), and legitimate interest
Displaying availability, rates and booking conditionsBooking data, nationality and country of residence, children's agesPerformance of the Partner agreement
Fulfilling the booking, transmitting it to the hotel or supplier and issuing vouchersGuests and bookingPerformance of the Partner agreement; for guest data: the legitimate interest of BedBank and the Partner in fulfilling the booking, and the guest's actual interest in completing the stay where direct contact with the guest is impracticable
Collection, settlement and tax invoicingPayment and settlementPerformance of the agreement, and legal requirement (VAT Law and E-Invoicing Regulation)
Support and handling amendments, cancellations, refunds and disputesSupport, booking, paymentPerformance of the agreement, and legitimate interest
Platform security, preventing abuse and investigating errorsTechnical use and securityLegitimate interest
Legal compliance and responding to competent authoritiesWhat the authority lawfully requests within its remitLegal and judicial requirement
Sending newsletters and offersContact and marketing dataYour consent, which you may withdraw at any time
Improving the platform and producing aggregate statisticsAnonymised data that does not identify youProcessing of anonymised data under Article 9 of the Implementing Regulations

Legitimate interest: We rely on it only after a documented assessment of necessity, proportionality and your reasonable expectations, without overriding your rights, and never for sensitive data.

Consent: We do not make marketing consent a condition of any service, and neither reading this policy nor completing a booking constitutes marketing consent. You may withdraw consent from your account preferences or by email without affecting processing carried out before withdrawal or processing based on another legal basis.

Automated decisions: Automated rules may be used to detect fraud or abuse; any outcome affecting your account is reviewed by a person before final action is taken.

4. How we process your data

  • Collection: through the interfaces and channels described in Section 2, limited to the minimum needed for the purpose.
  • Storage: in the platform's databases and their backups inside the Kingdom (Section 6), with encryption and restricted access.
  • Use: only for the stated purpose, by authorised staff and systems according to role and task.
  • Sharing: with the recipients listed in Section 5, to the extent each recipient needs.
  • Destruction: when the purpose and retention period end, by permanent deletion or anonymisation (Section 7).

5. Who we share your data with

We do not sell your data and do not disclose it to any party for direct-marketing purposes. Disclosure is limited to what is needed to deliver the service or meet a legal obligation, and to the data each recipient needs. No Partner can see another Partner's data or guests.

RecipientDataPurposeLocationFrequency
Hotels and accommodation suppliers, according to the bookingGuest names, nationality, children's ages, special requests and stay detailsChecking availability and delivering the stayInside or outside the Kingdom, depending on the hotel and supplier locationRegular
Payment gatewayTransaction amount, currency and reference, and contact details the transaction requiresProcessing payments and refundsInside the Kingdom; card data may pass through international payment networksRegular
Hosting and cloud infrastructure providersStored data and its backupsHosting, operation and backupInside the Kingdom (Riyadh region)Regular
Email, SMS and notification providersContact details and notification contentBooking confirmations and notificationsInside or outside the Kingdom depending on the provider, with the safeguards in Section 6Regular
Professional advisers (auditors, accountants and legal counsel)What the engagement requiresAudit, compliance and disputesInside the KingdomOccasional
Competent government, judicial and regulatory authorities (such as the Ministry of Tourism, ZATCA, the Saudi Central Bank, SDAIA, and security and judicial authorities)What the authority lawfully requests within its remitLegal and judicial complianceInside the KingdomOccasional
A legal successor in a merger, acquisition or restructuringPlatform recordsBusiness continuity, bound by this policyOccasional

Service providers that process data on our behalf are bound by processing contracts that limit them to the purpose, impose confidentiality and security measures, and prohibit use of the data for their own purposes.

6. Processing location and transfers outside the Kingdom

Your data and its backups are stored inside the Kingdom on cloud servers of a licensed provider, in the Riyadh region.

A transfer outside the Kingdom occurs in two cases: when the hotel or accommodation supplier is outside the Kingdom, the guest details needed for the booking are transferred to it in its country; and when a service provider (such as notifications or payment networks) uses infrastructure outside the Kingdom.

Transfers are limited to the minimum necessary and are made in accordance with Article 29 of the Law and the Regulation on Personal Data Transfer outside the Kingdom: on a recognised transfer basis, after verifying the level of protection in the receiving country or applying appropriate safeguards (such as standard contractual clauses), and with a risk assessment where required. You may request the recipient and country for a specific booking using the contact details above.

7. Storage, retention and destruction

Data typeRetention periodWhat happens afterwards
Partner account and usersFor the term of the agreement, then 12 months after account closure to settle any obligationsDeletion of the account, credentials and API keys
Guest details in the booking record24 months from the check-out date or from settlement of the last amendment, refund or dispute, whichever is laterAnonymisation of guests in the booking record; the financial record remains
Financial records, tax invoices and statements10 years from the end of the financial year under the Commercial Books Law and the VAT LawSecure destruction
Support correspondence24 months from closure of the requestDeletion
Sign-in logs, security events and API logs12 months for security and incident-investigation purposesAutomatic deletion
Consent-based marketing dataUntil consent is withdrawnRemoval from mailing lists, keeping a record of the withdrawal so we do not contact you again
Cookies and browser storageAs set out in Section 8Expire automatically

Method of destruction: Permanent, unrecoverable deletion from our systems and, in line with the rotation cycle, from backups, or anonymisation so that you can no longer be identified. Destruction may be delayed where there is an ongoing dispute, a request from a competent authority or a legal retention obligation, in which case use is restricted to that purpose. A quote or hold expiry is not a record-destruction date. You may request the period and basis applying to a specific record.

Security measures: Encryption in transit and at rest, passwords stored as derived values, two-factor authentication, role-based access with isolation of each Partner's data, revocable API keys, audit logs, regular backups, periodic security testing, staff confidentiality undertakings, and processing contracts with service providers. Do not send passwords, verification codes or card details through a support ticket. These measures do not guarantee the absence of risk.

Data incidents: In the event of a leak, damage or unlawful access, we assess the incident, notify the Saudi Data and AI Authority within 72 hours of becoming aware of it where the notification conditions apply, and notify affected individuals without delay where the incident may cause them harm.

8. Cookies and browser storage

The platform uses storage needed for the functions you request; marketing consent is not a condition of using them:

  • Session cookie: identifies your signed-in session and ends when you sign out, the session expires, or an account administrator revokes it.
  • Security cookies: protect forms against forged requests and verify session integrity.
  • Functional storage: keeps your language, currency, recent searches and selections on your device, and merges them into your account when you sign in.

The platform does not use advertising cookies or third-party tracking tools. If optional analytics tools are added in future, they will be activated only with your consent and this policy will be updated beforehand.

You can set your browser to block or clear storage; your sign-in session and saved selections may be affected. Clearing browser data does not destroy the records held in your account.

9. Your rights and how to exercise them

RightWhat it meansHow to exercise it
To be informedTo know the legal basis and purpose for collecting your data, and how it is processed, shared, retained and destroyedThis policy; you may ask for any further clarification
AccessTo view the personal data we hold about youDirectly from your account for account and booking data, or by request by email
Obtain a copyA clear, readable copy matching our recordsBy request; delivered in a commonly used electronic format where technically feasible
Correction, completion and updatingTo correct anything you consider inaccurate or incompleteFrom your account for Partner data; by request for booking data, noting that a confirmed booking is amended through the hotel's amendment channels
DestructionTo have data that is no longer needed destroyedBy request, unless a legal basis for retention applies (Section 7)
Withdraw consentTo stop processing based on your consentFrom account preferences or by request, without affecting earlier lawful processing
ComplainTo lodge a complaint with the competent authoritySection 10
CompensationTo claim compensation for material or moral harm caused by a breach of the LawBefore the competent court

How to submit a request: Email Info@BedBank.SA with the subject line "Personal Data Rights Request", stating the type of request, a reply method and the booking reference if any. A guest may apply to us directly or through the Partner that booked for them.

Identity verification: We may require proportionate verification of your identity or your representative's authority before disclosing any data; do not send a full identity document image initially.

Timeframe: We respond within 30 days of receiving a complete request, extendable by a further 30 days in the cases set out in the Implementing Regulations, with notice of the reasons.

Fees: No fee is charged for exercising your rights, except as the Law permits for repetitive or disproportionate requests.

Limitations: A request may not be fulfilled in whole or in part where it conflicts with a legal obligation or the rights of others, such as confirmed-booking data tied to a financial record; in that case we will explain the reason and how to object.

10. Complaints and objections

If you object to the processing of your data, or we have not enabled you to exercise your rights within the stated period, submit your complaint to the Privacy and Data Protection Team at Info@BedBank.SA or on the unified number 920035522, describing the matter and quoting any earlier request reference. We acknowledge receipt and decide on the complaint within 30 days.

If you are not satisfied with the outcome, or we do not respond within that period, you may complain to the Saudi Data and AI Authority (SDAIA) through the National Data Governance Platform.

Competent authority: Saudi Data and AI Authority (SDAIA) — Riyadh, Kingdom of Saudi Arabia

Website: sdaia.gov.sa

Complaints platform: National Data Governance Platform — dgp.sdaia.gov.sa

11. Availability of this policy and updates

This policy is published on BedBank.SA and in the partner portal, and a short privacy notice is shown when an account is created and when guest details are entered. Partners are bound to make this policy available to the guests they book for.

We review the policy whenever services, processing purposes or recipients change, and at least annually. We notify you of any material change through the partner portal or by email before it takes effect, and obtain fresh consent where required before the related processing.

In the event of any conflict between the Arabic and English versions, the Arabic version prevails.

VersionDateDescription
1.010 September 2026First release of the BedBank platform privacy policy.

📞 Questions About This Policy?

Contact our Privacy and Data Protection Team:

Email: Info@BedBank.SA

Address: Office 12, Floor 1, Al Khayyat Tower, Abu Bakr As Siddiq Road, Al Sharafeyah District, Jeddah 23218, Kingdom of Saudi Arabia