BEDVIA PRIVACY
Privacy Notice
This notice explains, at a general level, how BEDVIA handles personal data while the website, test accounts, and controlled pre-launch environment are operating. Publication does not mean that company registration, licensing, or commercial launch is complete. Legal-entity and official contact details will be added before live commercial operations begin.
1. Scope and current status
BEDVIA is a pre-launch B2B platform intended to connect corporate accommodation demand with qualified Hotels. This notice applies to website visitors, Company and Hotel account users, organizational representatives, and travellers or guests whose data may later be handled through approved booking operations.
The website is currently in trial mode and does not accept live commercial transactions or real-money movement. The final operator name, registration details, registered address, and official privacy contact will be added after incorporation and required government steps are completed and before commercial launch.
2. Data we may process
- Professional account and contact data such as name, email, phone, role, organization, account status, and permissions.
- Company and Hotel profile, representative, verification, qualification, and compliance information submitted through dedicated workflows.
- Request and booking data such as city, dates, room counts, occupancy, requirements, pricing parameters, and operational references.
- Guest data required for accommodation, such as names and room allocation, and gender only where there is a legitimate operational need.
- Invoice, credit, settlement, and Hotel bank-verification information where relevant to approved operations; the trial website does not currently process live card transactions.
- Support, complaint, privacy-request, and evidence content submitted through platform workflows.
- Technical and security data such as session information, IP address where available, login and event logs, errors, and device or browser information needed for security and operation.
3. Why we use data
- To create and manage accounts and verify permissions and organizations.
- To operate accommodation requests, matching, bookings, and rooming-list workflows when those functions are used.
- To provide support, receive privacy requests, and investigate incidents, misuse, or operational disputes.
- To secure the platform, prevent fraud or unauthorized access, and maintain audit records.
- To develop, test, and measure the reliability and performance of the service in a compliant manner.
- To meet applicable legal, regulatory, and record-keeping obligations.
4. Legal basis
Processing will rely on an appropriate lawful basis for the relevant purpose under applicable Saudi requirements, which may include consent where required, carrying out a legitimate requested relationship or service, compliance with a legal obligation, or another basis permitted by law. BEDVIA will not rely on a generic statement of legitimate interest without the assessment required when that basis is used.
5. Sharing and Company-identity protection
Under BEDVIA's operating model, Company identity is not disclosed to a Hotel while the Hotel evaluates an opportunity. Hotels receive only the commercial and operational information needed to decide, and after booking only the guest and room data needed to provide accommodation, subject to operational necessity.
- Data may be shared with Hotels only to the minimum extent needed to provide accommodation.
- Technology, hosting, database, authentication, and security providers may process data as needed to operate the service.
- Professional advisers and public, regulatory, or judicial authorities may receive data where disclosure is legally required or permitted.
- No live payment-provider sharing for commercial transactions will be activated until the payment and compliance architecture is approved.
6. International transfers
Some technology services may involve providers operating in more than one country. Before commercial launch, BEDVIA will complete its processor map and transfer assessment and apply any safeguards required by applicable Saudi requirements. This statement does not itself approve any specific cross-border transfer.
7. Retention and deletion
We retain data only for as long as needed for the relevant operational, security, or legal purpose, and then delete or de-identify it unless a legitimate retention obligation applies. A detailed retention schedule will be finalized before commercial launch, including treatment of financial, contractual, and security records where applicable.
8. Security
BEDVIA uses technical and organizational controls including role-based permissions, database policies, role separation, audit logging, session protections, and minimization of Company-identity disclosure to Hotels. No system can eliminate all risk, so controls continue to be reviewed and tested before launch.
9. Data-subject rights
Subject to applicable Saudi requirements, rights may include being informed, access, obtaining a copy, correction or completion, destruction where applicable, withdrawal of consent where consent is the legal basis, and making a privacy complaint or request.
Any person may use the dedicated public channel at /privacy/request to submit a personal-data request. Each successful submission receives a reference, and request contents are restricted to authorized BEDVIA roles. Registered users may also use their in-portal support workflows.
10. Cookies and similar technologies
The site uses necessary or functional technologies for authentication, sessions, security, and language preference. BEDVIA does not currently use behavioural advertising or marketing cookies as part of V1. See the Cookie Notice for the current baseline; it will be updated if non-essential technologies are introduced.
11. Children
BEDVIA is a business service for Companies and Hotels and is not directed to children. Data relating to a minor guest may appear only where an authorized organization provides it for a legitimate booking and only to the extent required to provide accommodation, subject to applicable requirements.
12. Updates and contact
We may update this notice as the service, legal requirements, entity details, or providers change. The latest-update date will appear on this page. During pre-launch, the approved public privacy-request channel is /privacy/request; final legal-entity and official contact details will be added before live commercial operations.
