Introduction
Third Financial District Hospitality Company for Hotel Operations ("Atheel KAFD") owns the Atheel KAFD Hotel, which is operated by Adeera Hospitality Company (“Adeera”, “we”, “us”, or “our”) pursuant to the terms of a hotel management agreement entered into between Atheel KAFD and Adeera. For the purposes of applicable data protection laws, Adeera acts as the Data Controller for personal data collected through the website, as further detailed below.
Welcome to Adeera’s privacy policy (the "Privacy Policy"). This Privacy Policy should be read together with our Website Terms and Conditions and Booking Terms and any other documents referred to in these documents.
This Privacy Policy sets out how we protect and use personal data about you that we collect through your use of this website (www.atheelkafd.com) or other websites managed by us ("Websites") or our mobile applications ("Apps"), and when you stay at or visit one of our properties in the Kingdom of Saudi Arabia or use the facilities, such as restaurants, spas or fitness centres, at one of our properties.
This Privacy Policy is designed to describe:
Introduction
Who we are and how to contact us
When this Policy was last updated
What personal data do we collect about you?
How is your personal data collected?
How we use your personal data and why?
When would we disclose your personal data?
Legal basis for collecting and processing your personal data
How do we store your personal data and how long do we keep your personal data?
Your rights and control of your personal data
How can you exercise your rights?
Complaints and Enquiries
SDAIA Address
Third party links
This Privacy Policy will apply whether you have provided the personal data directly to us or we have obtained it from a different source, such as third-party booking platforms.
Please read this Privacy Policy carefully.
Who we are and how to contact us
For the purposes of the Personal Data Protection Law and its Regulations issued by Royal Decree No. (M/19) dated 9/2/1443H and amended by Royal Decree No. (M/148) dated 5/9/1444 AH (the "PDPL"), the data controller is Adeera which is a company registered in the Kingdom of Saudi Arabia, under commercial registration number 1010661169, and having its office at 8596, Prince Turki Ibn Abdulaziz Al Awal, King Saud University, 12371 Riyadh, Kingdom of Saudi Arabia.
Adeera has been set up to run hotel operations in the Kingdom of Saudi Arabia and may collect personal data of guests, visitors, customers, users of our Websites and Apps, partners, suppliers and employees in running its operations, as further detailed in this Privacy Policy.
If you would like to contact us about this Privacy Policy or our privacy practices, please contact us at:
Involved department / team: Data privacy team
Address: 8596, Prince Turki Ibn Abdulaziz Al Awal, King Saud University, 12371 Riyadh, Kingdom of Saudi Arabia
Phone number: 00966114161731
Email: dataprivacy@adeera.com
Licence / commercial registration: 1010661169
When this Policy was last updated
This Privacy Policy was last updated on 12th April 2026.
We may occasionally update this Privacy Policy. We encourage you to periodically review this Privacy Policy to stay informed about how we are using and protecting personal data that we collect.
Depending on the circumstances, we will notify you of any significant change.
What personal data do we collect about you?
Personal data means any information about an individual from which that person can be identified. It does not include data where the identity has been removed, and it can no longer be associated with a natural person (anonymous data).
When you use the Websites or Apps or when you make a reservation to stay at one of our properties or visit one of our properties to use its facilities, we may collect and process the following personal data:
Identity Data includes first name, maiden name, last name, title and date of birth.
Contact Data includes postal address, email address, telephone numbers, messaging identifiers and social media handles.
Reservation and Profile Data includes dates of your stay, room selections, dietary information, special requests (including interests and preferences where provided), guest count, itinerary details (including third party bookings), reservation history, any feedback provided, survey responses and other communications with you about our services (including where you communicate with us through messaging apps).
Identity Verification Data includes passport, visa or other government-issued identification and the personal data contained within your identity document including name, national ID number and nationality.
Health Data includes any information relating to any medical conditions you make us aware of or any medical details relating to any accident or incident you have when staying at or visiting one of our properties.
Financial and Transaction Data includes tokenised payment details, billing address, invoice information, details about payments to and from you and other details of services you have purchased from us.
Loyalty Data includes third party loyalty programme membership details such as membership number, details of programme transactions and currency accrued or expended, available rewards and benefits where these are required in connection with any eligible third party loyalty programme applicable in connection with your booking.
Marketing and Communications Data includes your contact details, your preferences in receiving marketing from us, our affiliated companies and third parties, our historic marketing communications with you and any profiling we conduct to ensure our marketing communications are tailored and personalised to you.
Technical Data includes mobile device ID, internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our Websites and/or Apps.
Digital Profile and Usage Data includes your username and password, information about how you use our Websites and/or Apps, including browsing history.
Image Data includes CCTV footage of you in and around our properties including entrances, lobby, corridors, lifts, car parks, and perimeter (please note we do not operate CCTV in guest rooms and private areas such as changing facilities).
Employment/Qualifications Data (if you are applying for a job with us) includes employment history, nationality, date of birth, and other relevant information to enable us to conduct background checks.
So you are aware, we also use aggregated and anonymised data such as statistical or demographic data in managing our business such as assessing certain website features or analysis trends in our properties' occupancy rates. This aggregated and anonymised data will not identify you. Although we do not expect to, in the event the aggregated and anonymised data is connected with information that can identify you we treat the combined data as personal data which will be used in accordance with this Privacy Policy.
In addition to Health Data, we may collect Sensitive Categories of Personal Data about you (this may include for example details about your race or ethnicity, religious or philosophical beliefs, political opinions, genetic and biometric data (such as the results of psychometric tests), and criminal convictions and offences. We will obtain your explicit consent before processing any Sensitive Categories of Personal Data about you where required under the applicable data protection laws.
How is your personal data collected?
We use different methods to collect personal data about you including:
Direct interactions: We collect some of the personal data we hold about you directly from you through the following methods:
when you make a reservation to stay at one of our properties through our Websites or Apps, when you check-in and check-out at one of our properties, and when you book to use any of our services (such as restaurants, spas and fitness centres) either through the Websites or Apps or through the staff at one of our properties;
when you create an account on our Websites or Apps;
when you provide your third party loyalty programme details to us (for example, at booking or check‑in) so that we can apply eligible benefits and/or request points accrual / redemption with the relevant loyalty programme provider;
when you use WI-FI at any of our properties;
through CCTV when you stay at or visit any of our properties;
when you communicate with us including when you provide feedback, make a complaint, complete a survey or communicate with us through a messaging app; or
if you agree to receive marketing from us or sign up to our newsletter, including if you enter any competition we run.
Automated technologies or interactions: As you interact with our Websites and/or Apps, we will automatically collect Technical Data about your equipment, devices and browsing actions. We collect this personal data by using cookies, server logs and other similar technologies. We may also receive Technical Data about you if you visit other websites employing our cookies. Please see our Cookie Policy for further details.
Third parties or publicly available sources: We will collect some personal data about you from various third parties and public sources, which may be updated from time to time. These include:
third party loyalty programme operators;
third party online travel agencies, online booking platforms and reservation websites;
third party travel companies such as travel agencies, travel management companies and airlines; and
analytics providers such as Google.
When processing personal data from publicly available sources, we ensure that the collection is conducted in full compliance with legal requirements and aligns with the specified purposes under the law.
How and why we use your personal data collected through these methods is set out in Section 6 below.
How we use your personal data and why?
We may use personal data about you in the following ways:
Account registration to register you as a new customer on our Websites or Apps.
Reservations, guest registration, managing your stay at any of our properties, managing your special requests or preferences and otherwise managing our relationship with you.
Managing your bookings at our restaurants, spas, fitness centres and other facilities at any of our properties and otherwise providing our services to you.
Payment, billing and accounting.
Communications with you, including to provide information during your stay at one of our properties and handling complaints, feedback, surveys or market research.
Providing WI-FI within our properties.
Marketing and promotions including to make suggestions and recommendations to you about our services that may be of interest to you.
In connection with your membership of third party loyalty programmes including applying eligible benefits and discounts and for points accrual / redemption purposes.
Operation of the Websites and Apps including troubleshooting, data analysis and analytics to improve the Websites and Apps, testing, system maintenance, support, reporting and hosting of data.
To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you.
Managing lost and found items.
Managing any incidents or accidents that occur during your stay at or visit to one of our properties.
Change of purpose
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider through a specific assessment that we need to process it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us at dataprivacy@adeera.com. In any case, we will notify you as required by applicable law, and we will explain the legal basis which allows us to use it for such other purpose.
Tailoring your experience
We will use your personal data to tailor and personalise the marketing communications we send you and determine which marketing we send to you. Where required by applicable law, we will only use your personal data for direct marketing purposes where you have provided your consent.
Your personal data will not be processed in a way which means you could be subject to a decision based solely on automated processing, including profiling, which may have a significant impact on you.
What happens if you fail to provide us with the necessary personal data?
Where we need to collect your personal data by law, or under the terms of a contract we have with you, and you fail to provide that personal data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you our services). In this case, we may have to cancel a reservation or other booking you have with us but we will notify you if this is the case at the time.
If the processing relies on your consent, declining to provide it will not result in any consequences, except that we will be unable to perform the activity that relies on your consent.
If the processing is based on our legitimate interest and you exercise your right to object, we will conduct a balancing test to re-evaluate the interests involved and the potential impact and consequences of not proceeding with the processing activity. In any case, if you revoke your consent and/or object to processing for marketing or profiling purposes, we will promptly cease these processing activities.
Security and the processing of your personal data
We understand that security is an important concern for you when online. Information you give us will be stored securely with our third party cloud hosting provider and we use sophisticated technology to help make sure that all your personal data remain confidential.
Our security technologies and procedures are regularly reviewed to confirm that they are up to date and effective. For further verification, look for the padlock symbol in your browser window as you proceed through the order and payment process.
We take the security of your information seriously and use measures designed to protect it when you use our Websites or Apps. While we work to maintain a secure environment, no online service can guarantee absolute security. For your protection, please use a trusted device and secure internet connection when making payments, keep your passwords and security codes confidential, and follow any security guidance we may provide from time to time.
When would we disclose your personal data?
We may share your personal data with the following parties for the purposes set out in Section 6 above.
Other companies in our group. We regularly share data with our group so we can provide the best service across our group. We also share your personal data within our group for management forecasting and financial planning purposes - although this would generally be aggregated and anonymised Data where no individual is identifiable.
Other properties that Adeera manages within the Kingdom of Saudi Arabia. We regularly share data to provide the best guest services including identifying returning guests and providing services based on interests and preferences.
Sale or acquisition. We may occasionally share your personal data in the event of a sale, transfer, merger or acquisition.
Service providers. We will share your personal data with service providers in order to perform identity verification and anti-money laundering checks.
Third parties who are providing your booking. If we arrange a booking with a third party (such as a third-party transportation or excursion provider) we will share your personal data with that third party so they can arrange your booking.
Third party loyalty programme operators. We will share your personal data with the operators of third-party loyalty programmes in relation to eligible benefits and for points accrual / redemption purposes.
Professional advisers. This may include lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, insurance and accounting services to obtain advice from the relevant professional advisers.
Regulators and other authorities. We will disclose personal data where we are required to report processing activities in certain circumstances.
Third party providers. Third party providers assisting us in running our business, including our payment and delivery service providers, reservation channels (such as OTAs), software solutions used in the hospitality and travel industry, marketing agencies and website hosting providers.
Third parties that operate our restaurants, spas and fitness facilities. Where these facilities are operated by a third party, we will share your personal data to enable them to identify a particular guest and to charge transactions to a specific room.
The above parties may process your personal data as autonomous data controllers or on our behalf for specified purposes and in accordance with our instructions. In any case, we require all third parties to respect the security of your personal data and to process it in accordance with applicable law.
International transfers
Whenever we transfer your personal data to a recipient located in a third country outside of the Kingdom of Saudi Arabia, we will ensure an equivalent degree of protection is afforded to it by ensuring a suitable safeguard is implemented in compliance with applicable law. In particular, we will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data or, in the absence of an adequacy decision, use appropriate transfer solutions such as standard contractual clauses to the extent these are compliant with applicable data protection laws. For further information, please contact us at dataprivacy@adeera.com.
Legal basis for collecting and processing your personal data
We will only use your personal data when the law allows us to. In respect of each of the purposes for which we use your personal data, applicable law requires us to ensure that we have a "legal basis" for that use. Most commonly, we will use your personal data in the following circumstances (to the extent compliant with applicable data protection law):
where we need to perform a contract we are about to enter into or have entered into with you ("Contractual Necessity");
where it is necessary for our legitimate interests, and your interests and fundamental rights do not override those interests ("Legitimate Interests"). More detail about the specific legitimate interests pursued in respect of each purpose we use your personal data for is set out in the table below;
where we need to comply with a legal or regulatory obligation ("Compliance with Law");
where processing is necessary to protect your actual / vital interests but it is difficult / impossible to communicate with you ("Actual Interests"); and
where we have your specific consent to carry out the processing for the purpose in question ("Consent") in accordance with the applicable law and regulations. Where you have provided your consent to the processing of your personal data for a specific purpose, you have the right to withdraw your consent for that specific processing at any time – please see Sections 10 and 11 below for details of how to withdraw your consent.
We have set out below, in a table format, a description of all the ways we plan to use your personal data and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.
Note that we may process your personal data for more than one lawful basis depending on the specific purpose for which we are using your personal data. Please contact us if you need details about the specific legal basis we are relying on to process your personal data where more than one basis has been set out in the table below.
| Purpose / Activity | Type of personal data | Lawful basis for processing including basis of legitimate interest |
|---|---|---|
| Account registration to register you as a new customer | Identity Data Contact Data Reservation and Profile Data | Contractual Necessity Legitimate interest (to operate the account and related services) |
| Reservations, guest registration, managing your stay at any of our properties, managing your special requests or preferences | Identity Data Contact Data Reservation and Profile Data Identity Verification Data Health Data – if provided by you such as in relation to special requests. | Contractual Necessity Legitimate interest (to operate our properties, manage our relationship with you and to provide you with the best services that we can) Compliance with Law |
| Managing your bookings at our restaurants, spas, fitness centres and other facilities at any of our properties and otherwise providing our services to you | Identity Data Contact Data Reservation and Profile Data Health Data – if provided by you such as allergy information for restaurant bookings or medical information in connection with spa / fitness centre usage. | Contractual Necessity Legitimate interest (to operate our services and to provide you with the best services that we can) Consent |
| Payment, billing and accounting | Financial and Transaction Data | Contractual Necessity Legitimate interest (to recover any debts) |
| Customer communications including complaints, feedback, surveys and market research | Identity Data Contact Data Reservation and Profile Data | Legitimate interests (in managing our relationship with you and addressing any complaints or issues) |
| Providing WI-FI within our properties | Contact Data Technical Data Digital Profile and Usage Data | Contractual Necessity Legitimate interests (in protecting the security of our networks) |
| Marketing and promotions | Identity Data Contact Data Reservation and Profile Data Marketing and Communications Data | Consent |
| In connection with your membership of third party loyalty programmes including applying eligible benefits and discounts and for points accrual / redemption purposes. | Identity Data Contact Data Reservation and Profile Data Loyalty Data | Legitimate interests (in applying eligible benefits and discounts and for points accrual / redemption purposes) |
Operation of the Websites and Apps (including troubleshooting, data analysis and analytics to improve the Websites and Apps, testing, system maintenance, support, reporting and hosting of data) Also to deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you | Technical Data Digital Profile and Usage Data | Legitimate interests (to operate our Websites and Apps including to study how customers use our services, to develop them, to grow our business and to inform our marketing strategy) Consent |
| Lost and found | Identity Data Contact Data | Legitimate interest (operating lost and found services for our guests and visitors) |
| Managing any incidents or accidents that occur during your stay at or visit to one of our properties | Identity Data Contact Data Reservation and Profile Data Health Data | Contractual Necessity Actual Interests Compliance with Law Legitimate interests Protection of public health, public safety, or to protect the life or health of specific individuals |
| Operation of CCTV systems at our properties | Image Data | Legitimate interests (to ensure the security of our guests and properties) |
How do we store your personal data and how long do we keep your personal data?
We store your personal data securely with our cloud hosting provider.
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
In some circumstances, you can ask us to delete your data. Please see Section 10 below for further information.
In some circumstances, we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
Your rights and control of your personal data
You have the right, at any time, to:
Be informed. You are entitled to know the methods by which we collect your personal data, the legal basis for collecting it and processing it, how it will be processed, stored and destroyed, and with whom it will be shared. This information is set out in this Privacy Policy. If you require further details, please contact us using the details set out below.
Request access to your personal data (commonly known as a data subject access request). This enables you to receive both further information on the ongoing processing activities, and a copy of the personal data we hold about you and to check that we are lawfully processing it. This right is subject to specific exemptions set out in applicable law which allow us to withhold or redact information.
Obtain portability of your personal data. Under certain circumstances, this enables you to receive your personal data provided to us, in a structured, commonly used and machine-readable format, and obtain the transmission of such personal data to another organisation. This applies to personal data provided by you that is processed on the basis of consent or performance of contract, and that is processed by automated means.
Request correction of the personal data that we process about you. This enables you to have any incomplete or inaccurate personal data we hold about you corrected, completed or updated, though we may need to verify the accuracy of the new data you provide to us. It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us. Where you request it such personal data will be reviewed and updated within 30 days.
Request restriction or destruction of your personal data (commonly known as the right to be forgotten). This enables you to ask us to limit our processing activities (i.e., with the exception of storage, your personal data will only be processed with your consent, for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person), or to delete personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your personal data unlawfully or where we are required to erase your personal data to comply with local law. We may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
Object to the processing based on our legitimate interest or withdraw consent where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out prior to your objection to the processing or withdraw of your consent. In some cases, we may demonstrate that we have compelling legitimate grounds to process your personal data which override your rights and freedoms. If you object to the processing or withdraw your consent, we may not be able to provide certain services to you. We will advise you if this is the case at the time you object to the processing or withdraw your consent.
Right of complaint. You also have the right to file a complaint. If you have any concerns, or if we do not comply with the PDPL, you can file a complaint to Adeera using the contact details below. Please see Section 12 below.
How can you exercise your rights?
If you wish to exercise any of the rights set out above, please contact us at:
Email: dataprivacy@adeera.com
Address: Data Privacy Team, 8596, Prince Turki Ibn Abdulaziz Al Awal, King Saud University, 12371 Riyadh, Kingdom of Saudi Arabia To withdraw your consent to direct marketing or change your marketing preferences, please update your account profile on our Websites / Apps or click the unsubscribe link in any marketing communication.
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances. We will inform you if this is the case.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
We try to respond to all legitimate requests within 30 days unless the law provides otherwise. Occasionally it could take us longer than 30 days (and up to a further 30 days) if your request is particularly complex, requires unusual or unexpected additional effort, or you have made a number of requests. In this case, we will notify you within the first 30 days of receipt and keep you updated.
Complaints and Enquiries
We would welcome addressing any concerns you may have about our handling of your personal data. You can contact us to file a complaint by contacting the Data Privacy Team at dataprivacy@adeera.com.
However, under the PDPL, if you are not satisfied with how we process your complaint, or if we fail to respond within 30 days (or 60 days where we have notified you of an extension), you can file a complaint with the Saudi Data & AI Authority (SDAIA).
SDAIA Address
Kingdom of Saudi Arabia, Riyadh
Website: Saudi Data & AI Authority (sdaia.gov.sa)
National Data Governance Platform “DGP” (dgp.sdaia.gov.sa)
Third party links
Our Websites and Apps may include links to third party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our Websites or Apps, we encourage you to read the privacy policy of every website you visit.