Who we are and scope of this policy
BedBank Company (شركة بدبانك) is a Saudi company operating the BedBank.SA platform, its subdomains, the partner portal and the application programming interface (API) for wholesale distribution of hotel accommodation in the Kingdom and worldwide. We contract with travel and tourism agencies, tour operators, Umrah operators and corporate travel buyers ("Partners") and fulfil their accommodation bookings with hotels and accommodation suppliers.
This policy explains what personal data we collect and why, how we use, share, retain and destroy it, and what your rights are and how to exercise them, in accordance with the Personal Data Protection Law issued by Royal Decree No. (M/19) dated 9/2/1443H, as amended, and its Implementing Regulations.
This policy applies to:
- Partner users: anyone who creates an account or uses the platform or the API on behalf of a Partner.
- Guests and travellers: anyone whose details a Partner enters to complete an accommodation booking.
- Website visitors and anyone who contacts us: through our forms, email or telephone.
If you are a guest, the Partner that booked for you collected your details from you directly and is bound by its agreement with us to inform you of this policy and to obtain whatever is required before entering your details. We are the controller of the booking records we hold on our platform.
Contact details
Responsible team: Privacy and Data Protection Team — BedBank Company
Address: Office 12, Floor 1, Al Khayyat Tower, Abu Bakr As Siddiq Road, Al Sharafeyah District, Jeddah 23218, Kingdom of Saudi Arabia
Unified number: 920035522
Email: Info@BedBank.SA
Commercial registration: 7050680649
Personal Data Protection Officer: Reachable through the email address above with the subject line "Personal Data Protection"
This policy in one minute
| Who we are | A Saudi B2B platform for wholesale distribution of hotel accommodation to Partners. |
| What we collect | Partner account and user details, guest details needed for bookings, payment and settlement data, and technical logs. |
| Why | To fulfil, settle and support bookings, protect the platform, comply with the law, and market to you only with your consent. |
| Who we share it with | Hotels and suppliers according to the booking, the payment gateway, hosting and notification providers, and competent authorities on lawful request. We do not sell your data. |
| Where we keep it | On cloud servers inside the Kingdom (Riyadh region); booking details are transferred to the hotel in its country when the stay is outside the Kingdom. |
| How long | By data type (Section 7): from the end of a session up to 10 years for financial records. |
| Your rights | To be informed, access, obtain a copy, correct, destroy, withdraw consent, complain and claim compensation. |
| How to reach us | Info@BedBank.SA — we respond within 30 days. |
1. Personal data we collect
We collect the minimum needed for each service, and our forms distinguish mandatory fields from optional ones. The data falls into the following categories:
| Category | Examples | Mandatory or optional | Source |
|---|---|---|---|
| Partner account and users | Name, work email, mobile number, job title and permissions, preferred language and currency, credentials (the password is stored as a derived value, not readable text) and API keys | Mandatory to open the account; mobile number optional unless two-factor authentication is enabled | The Partner user directly |
| Partner business details | Company name, commercial registration or tourism licence, tax number, national address, authorised representative details, bank account for settlements | Mandatory for eligibility checks and invoicing | The Partner; verified against official registers |
| Guests and travellers | Names as shown on the travel document, title, nationality, country of residence, children's ages, lead-guest status, special requests, expected arrival time | Names, nationality and children's ages are mandatory to confirm a booking; the rest is optional | The Partner on behalf of the guest |
| Booking | Destination, hotel, stay dates, rooms and occupancy, price and cancellation terms, booking reference and voucher, status and amendments | Created automatically on booking | The platform and the hotel or supplier |
| Payment and settlement | Payment method, transaction amount and currency, payment reference and status, prepaid balance and credit-limit movements, statements and tax invoices, refund details. We never receive or store the full card number or security code; card details are entered only on the payment gateway page | Mandatory for payment and settlement | The Partner and the payment gateway |
| Support and correspondence | Ticket and message content, attachments and contact details | Whatever you choose to send | You |
| Technical use and security | IP address, browser, device and operating system, pages and requests and their timing, API logs and sign-in attempts | Collected automatically to operate and protect the platform | The platform |
| Marketing | Newsletter and offer subscription preferences | Optional, with your consent | You |
Sensitive data: We do not request sensitive data within the statutory meaning (such as health, religious, credit or biometric data). If a Partner includes in a special request something that reveals a guest's health need (such as an accessible room), it is processed solely to fulfil that request with the hotel, and the Partner is responsible for obtaining the guest's explicit consent before entering it.
Minors: Children's ages are collected only for occupancy and pricing. No account is created for anyone under 18; a child's details are entered by a parent, guardian or the authorised Partner.
2. How we collect your data
Directly from you: through registration forms, account settings, the booking interface, the API, and contact and support forms.
Indirectly:
- From the Partner: guest details entered to complete a booking, and details of anyone booking on a Partner's behalf.
- From hotels and suppliers: booking confirmations and amendments, and arrival or no-show status.
- From the payment gateway: the result and reference of a payment or refund.
- From official registers: to verify a Partner's commercial registration and tourism licence.
- Automatically: through cookies and technical logs when you use the platform (Section 8).
When booking for others, the person entering the data must ensure they are authorised to provide it and must inform its owners of this policy.
3. Purposes and legal bases
We tie every processing activity to its specific purpose and to a legal basis set out in Article 6 of the Law, and we do not later process your data in a way incompatible with the purpose for which it was collected.
| Purpose | Data used | Legal basis |
|---|---|---|
| Opening the Partner account and managing users and permissions | Partner account and users, business details | Performance of the Partner agreement, and legitimate interest in managing access |
| Verifying Partner eligibility and preventing commercial fraud | Business details | Legal requirement (tourism licensing and invoicing), and legitimate interest |
| Displaying availability, rates and booking conditions | Booking data, nationality and country of residence, children's ages | Performance of the Partner agreement |
| Fulfilling the booking, transmitting it to the hotel or supplier and issuing vouchers | Guests and booking | Performance of the Partner agreement; for guest data: the legitimate interest of BedBank and the Partner in fulfilling the booking, and the guest's actual interest in completing the stay where direct contact with the guest is impracticable |
| Collection, settlement and tax invoicing | Payment and settlement | Performance of the agreement, and legal requirement (VAT Law and E-Invoicing Regulation) |
| Support and handling amendments, cancellations, refunds and disputes | Support, booking, payment | Performance of the agreement, and legitimate interest |
| Platform security, preventing abuse and investigating errors | Technical use and security | Legitimate interest |
| Legal compliance and responding to competent authorities | What the authority lawfully requests within its remit | Legal and judicial requirement |
| Sending newsletters and offers | Contact and marketing data | Your consent, which you may withdraw at any time |
| Improving the platform and producing aggregate statistics | Anonymised data that does not identify you | Processing of anonymised data under Article 9 of the Implementing Regulations |
Legitimate interest: We rely on it only after a documented assessment of necessity, proportionality and your reasonable expectations, without overriding your rights, and never for sensitive data.
Consent: We do not make marketing consent a condition of any service, and neither reading this policy nor completing a booking constitutes marketing consent. You may withdraw consent from your account preferences or by email without affecting processing carried out before withdrawal or processing based on another legal basis.
Automated decisions: Automated rules may be used to detect fraud or abuse; any outcome affecting your account is reviewed by a person before final action is taken.
4. How we process your data
- Collection: through the interfaces and channels described in Section 2, limited to the minimum needed for the purpose.
- Storage: in the platform's databases and their backups inside the Kingdom (Section 6), with encryption and restricted access.
- Use: only for the stated purpose, by authorised staff and systems according to role and task.
- Sharing: with the recipients listed in Section 5, to the extent each recipient needs.
- Destruction: when the purpose and retention period end, by permanent deletion or anonymisation (Section 7).
5. Who we share your data with
We do not sell your data and do not disclose it to any party for direct-marketing purposes. Disclosure is limited to what is needed to deliver the service or meet a legal obligation, and to the data each recipient needs. No Partner can see another Partner's data or guests.
| Recipient | Data | Purpose | Location | Frequency |
|---|---|---|---|---|
| Hotels and accommodation suppliers, according to the booking | Guest names, nationality, children's ages, special requests and stay details | Checking availability and delivering the stay | Inside or outside the Kingdom, depending on the hotel and supplier location | Regular |
| Payment gateway | Transaction amount, currency and reference, and contact details the transaction requires | Processing payments and refunds | Inside the Kingdom; card data may pass through international payment networks | Regular |
| Hosting and cloud infrastructure providers | Stored data and its backups | Hosting, operation and backup | Inside the Kingdom (Riyadh region) | Regular |
| Email, SMS and notification providers | Contact details and notification content | Booking confirmations and notifications | Inside or outside the Kingdom depending on the provider, with the safeguards in Section 6 | Regular |
| Professional advisers (auditors, accountants and legal counsel) | What the engagement requires | Audit, compliance and disputes | Inside the Kingdom | Occasional |
| Competent government, judicial and regulatory authorities (such as the Ministry of Tourism, ZATCA, the Saudi Central Bank, SDAIA, and security and judicial authorities) | What the authority lawfully requests within its remit | Legal and judicial compliance | Inside the Kingdom | Occasional |
| A legal successor in a merger, acquisition or restructuring | Platform records | Business continuity, bound by this policy | — | Occasional |
Service providers that process data on our behalf are bound by processing contracts that limit them to the purpose, impose confidentiality and security measures, and prohibit use of the data for their own purposes.
6. Processing location and transfers outside the Kingdom
Your data and its backups are stored inside the Kingdom on cloud servers of a licensed provider, in the Riyadh region.
A transfer outside the Kingdom occurs in two cases: when the hotel or accommodation supplier is outside the Kingdom, the guest details needed for the booking are transferred to it in its country; and when a service provider (such as notifications or payment networks) uses infrastructure outside the Kingdom.
Transfers are limited to the minimum necessary and are made in accordance with Article 29 of the Law and the Regulation on Personal Data Transfer outside the Kingdom: on a recognised transfer basis, after verifying the level of protection in the receiving country or applying appropriate safeguards (such as standard contractual clauses), and with a risk assessment where required. You may request the recipient and country for a specific booking using the contact details above.
7. Storage, retention and destruction
| Data type | Retention period | What happens afterwards |
|---|---|---|
| Partner account and users | For the term of the agreement, then 12 months after account closure to settle any obligations | Deletion of the account, credentials and API keys |
| Guest details in the booking record | 24 months from the check-out date or from settlement of the last amendment, refund or dispute, whichever is later | Anonymisation of guests in the booking record; the financial record remains |
| Financial records, tax invoices and statements | 10 years from the end of the financial year under the Commercial Books Law and the VAT Law | Secure destruction |
| Support correspondence | 24 months from closure of the request | Deletion |
| Sign-in logs, security events and API logs | 12 months for security and incident-investigation purposes | Automatic deletion |
| Consent-based marketing data | Until consent is withdrawn | Removal from mailing lists, keeping a record of the withdrawal so we do not contact you again |
| Cookies and browser storage | As set out in Section 8 | Expire automatically |
Method of destruction: Permanent, unrecoverable deletion from our systems and, in line with the rotation cycle, from backups, or anonymisation so that you can no longer be identified. Destruction may be delayed where there is an ongoing dispute, a request from a competent authority or a legal retention obligation, in which case use is restricted to that purpose. A quote or hold expiry is not a record-destruction date. You may request the period and basis applying to a specific record.
Security measures: Encryption in transit and at rest, passwords stored as derived values, two-factor authentication, role-based access with isolation of each Partner's data, revocable API keys, audit logs, regular backups, periodic security testing, staff confidentiality undertakings, and processing contracts with service providers. Do not send passwords, verification codes or card details through a support ticket. These measures do not guarantee the absence of risk.
Data incidents: In the event of a leak, damage or unlawful access, we assess the incident, notify the Saudi Data and AI Authority within 72 hours of becoming aware of it where the notification conditions apply, and notify affected individuals without delay where the incident may cause them harm.
8. Cookies and browser storage
The platform uses storage needed for the functions you request; marketing consent is not a condition of using them:
- Session cookie: identifies your signed-in session and ends when you sign out, the session expires, or an account administrator revokes it.
- Security cookies: protect forms against forged requests and verify session integrity.
- Functional storage: keeps your language, currency, recent searches and selections on your device, and merges them into your account when you sign in.
The platform does not use advertising cookies or third-party tracking tools. If optional analytics tools are added in future, they will be activated only with your consent and this policy will be updated beforehand.
You can set your browser to block or clear storage; your sign-in session and saved selections may be affected. Clearing browser data does not destroy the records held in your account.
9. Your rights and how to exercise them
| Right | What it means | How to exercise it |
|---|---|---|
| To be informed | To know the legal basis and purpose for collecting your data, and how it is processed, shared, retained and destroyed | This policy; you may ask for any further clarification |
| Access | To view the personal data we hold about you | Directly from your account for account and booking data, or by request by email |
| Obtain a copy | A clear, readable copy matching our records | By request; delivered in a commonly used electronic format where technically feasible |
| Correction, completion and updating | To correct anything you consider inaccurate or incomplete | From your account for Partner data; by request for booking data, noting that a confirmed booking is amended through the hotel's amendment channels |
| Destruction | To have data that is no longer needed destroyed | By request, unless a legal basis for retention applies (Section 7) |
| Withdraw consent | To stop processing based on your consent | From account preferences or by request, without affecting earlier lawful processing |
| Complain | To lodge a complaint with the competent authority | Section 10 |
| Compensation | To claim compensation for material or moral harm caused by a breach of the Law | Before the competent court |
How to submit a request: Email Info@BedBank.SA with the subject line "Personal Data Rights Request", stating the type of request, a reply method and the booking reference if any. A guest may apply to us directly or through the Partner that booked for them.
Identity verification: We may require proportionate verification of your identity or your representative's authority before disclosing any data; do not send a full identity document image initially.
Timeframe: We respond within 30 days of receiving a complete request, extendable by a further 30 days in the cases set out in the Implementing Regulations, with notice of the reasons.
Fees: No fee is charged for exercising your rights, except as the Law permits for repetitive or disproportionate requests.
Limitations: A request may not be fulfilled in whole or in part where it conflicts with a legal obligation or the rights of others, such as confirmed-booking data tied to a financial record; in that case we will explain the reason and how to object.
10. Complaints and objections
If you object to the processing of your data, or we have not enabled you to exercise your rights within the stated period, submit your complaint to the Privacy and Data Protection Team at Info@BedBank.SA or on the unified number 920035522, describing the matter and quoting any earlier request reference. We acknowledge receipt and decide on the complaint within 30 days.
If you are not satisfied with the outcome, or we do not respond within that period, you may complain to the Saudi Data and AI Authority (SDAIA) through the National Data Governance Platform.
Competent authority: Saudi Data and AI Authority (SDAIA) — Riyadh, Kingdom of Saudi Arabia
Website: sdaia.gov.sa
Complaints platform: National Data Governance Platform — dgp.sdaia.gov.sa
11. Availability of this policy and updates
This policy is published on BedBank.SA and in the partner portal, and a short privacy notice is shown when an account is created and when guest details are entered. Partners are bound to make this policy available to the guests they book for.
We review the policy whenever services, processing purposes or recipients change, and at least annually. We notify you of any material change through the partner portal or by email before it takes effect, and obtain fresh consent where required before the related processing.
In the event of any conflict between the Arabic and English versions, the Arabic version prevails.
| Version | Date | Description |
|---|---|---|
| 1.0 | 10 September 2026 | First release of the BedBank platform privacy policy. |
📞 Questions About This Policy?
Contact our Privacy and Data Protection Team:
Email: Info@BedBank.SA
Address: Office 12, Floor 1, Al Khayyat Tower, Abu Bakr As Siddiq Road, Al Sharafeyah District, Jeddah 23218, Kingdom of Saudi Arabia
