Scope of Application
Rixa Solutions Company respects the privacy of users of the Rixa application and website and is committed to protecting personal data and processing it in accordance with the Personal Data Protection Law, its Implementing Regulations, the Regulation on Personal Data Transfer Outside the Kingdom, and the related laws applicable in the Kingdom of Saudi Arabia.
This Policy explains the personal data collected by Rixa, its sources, the purposes of its processing, how it is retained, shared and destroyed, the rights of data subjects, and the methods for exercising those rights.
Mere use of the Rixa Platform does not constitute consent to all data-processing activities. Rixa will request separate consent whenever consent is the required legal basis for processing.
Controller and Contact Details
Rixa Solutions Company is the controller of the personal data for which it determines the purposes and means of processing through the Rixa Platform, in accordance with the following details:
- Legal name: Rixa Solutions Company
- Commercial registration: 7053871518
- Address: Building 3598, Abdulaziz Ibn Muhammad Ibn Saud St, Al Faisaliyah Dist
- Website: rixa.app
- Phone: +966554867052
- Email: care@rixa.app
Scope of the Policy
This Policy applies to personal data collected or processed through:
- The Rixa application and website intended for customers.
- The application or dashboard intended for salons and Service Providers.
- Booking, payment, notification, marketing and technical-support services.
- Rixa communication channels, including email, messages and WhatsApp.
- Rixa's automated assistant and artificial intelligence features.
This Policy does not apply to websites or applications operated by independent entities, even if they can be accessed through the Rixa Platform.
Personal Data We Collect
The data collected by Rixa varies according to the nature of the service used and may include:
Name, mobile number, email address, date of birth or gender where necessary, profile picture, account identifier, login details, and encrypted password.
The selected Service Provider, type of service, appointment, branch or location, requested specialist, booking and cancellation history, attendance status, preferences and notes, reviews, ratings and attachments provided by the User.
Content that the User chooses to publish publicly, such as ratings and reviews, may be displayed to other Platform users according to the nature of the feature used.
The transaction amount, payment method, payment or refund status, reference number, invoice information, and limited information relating to the payment method, such as the last four digits of the card where provided by the payment provider.
As a general rule, Rixa does not retain the full card number or security verification code, as sensitive payment data is processed through independent payment service providers.
Approximate or precise location and address when a location-based service is requested or for displaying nearby branches and Service Providers, after obtaining the device's permission where necessary.
The User may disable location access through the device settings, which may result in certain service features becoming unavailable.
Internet Protocol address, device type and operating system, device and application identifiers, browser type, usage times, pages and features used, performance and crash logs, and cookies.
Correspondence, conversations, complaints, requests, attachments, and recorded calls where the caller has been notified of the recording.
Establishment details, commercial registration, licences, authorised representative, address, contact details, bank account, settlements, services, prices, appointments, names of specialists, their work schedules, and booking and performance data relating to the Platform.
When collecting data, Rixa explains whether its provision is mandatory or optional. Failure to provide necessary data may make it impossible to create an account, complete a booking or payment, or provide the requested service.
Sensitive Data
Rixa does not request health or sensitive data unless it is directly related to the requested service and necessary for the safe provision thereof.
Notes provided by the User may include information concerning allergies, skin conditions, pregnancy or a health condition affecting a beauty or care service. In such cases:
- Processing is limited to the minimum necessary.
- Providing the data is optional unless it is necessary for the safety of the service.
- Explicit consent is obtained whenever legally required.
- Sensitive data is not used for marketing or targeted advertising.
- It may be shared with the selected Service Provider to the extent necessary to fulfil the booking.
Methods and Sources of Data Collection
Rixa may collect data:
- Directly from the data subject: when creating an account, making a booking or payment, updating information, contacting support, or submitting a review or complaint.
- Automatically: when using the application or website, and through device and location data, cookies, and usage and crash logs.
- From other entities: such as salons and Service Providers, payment providers, login services such as Apple or Google, messaging and analytics providers, loyalty programmes, partners and competent authorities where a legal basis exists.
When data is obtained from a person other than the data subject, Rixa takes the necessary measures to inform the data subject in accordance with the legal requirements, unless a statutory exception applies.
Purposes of Data Processing
Rixa processes data for the following purposes:
- Creating and managing the account and verifying the User.
- Displaying available services, branches and Service Providers.
- Completing, confirming, amending and cancelling bookings.
- Sharing booking details with the selected Service Provider.
- Processing payments, refunds and settlements.
- Sending booking confirmations, reminders and operational notifications.
- Providing technical support and customer service and managing complaints and disputes.
- Improving Platform performance and the user experience and developing services.
- Analysing usage and preparing statistics and reports.
- Personalising search results and recommendations according to the User's preferences.
- Detecting fraud and misuse and protecting accounts and the Platform.
- Managing the relationship with Service Providers and partners.
- Operating the automated assistant and artificial intelligence features.
- Managing loyalty, rewards and promotional programmes.
- Sending marketing communications after obtaining the required consent.
- Complying with legal, accounting and tax obligations.
- Protecting the rights of Rixa or Users and bringing or defending claims.
Legal Bases for Processing
Rixa relies on the appropriate legal basis for each processing activity, including:
- Performance of a contract or taking steps at the User's request before entering into it.
- The data subject's consent, such as for marketing and certain cookies.
- Explicit consent when processing sensitive data or in circumstances where it is legally required.
- Compliance with a legal obligation.
- Protection of the vital interests of the data subject.
- Pursuit of a legitimate interest of Rixa, such as fraud prevention, network security and service improvement, after balancing that interest against the rights of the data subject, provided that the processing does not include sensitive data.
The data subject may withdraw consent at any time. Such withdrawal does not affect the lawfulness of processing carried out before the withdrawal or processing based on another legal basis.
Service Providers and Other Entities
Rixa operates as a technology platform connecting Users with participating beauty and care Service Providers.
The Service Provider may be an independent controller in relation to data it processes to provide the booked service, manage its direct relationship with the customer, or fulfil its professional and legal obligations.
The Service Provider may not use customer data obtained from Rixa for independent marketing purposes unless the required legal basis and consent are available.
Data Sharing and Disclosure
Rixa may share data, to the extent necessary to achieve the relevant purpose, with:
- The Service Provider or branch selected by the User.
- Payment, hosting and cloud-computing service providers.
- Messaging, email, WhatsApp, analytics and technical-support providers.
- Cybersecurity and fraud-prevention service providers.
- Loyalty programme, offers and instalment-service providers, after notifying the User where necessary.
- Legal advisers, accountants and auditors.
- Governmental, judicial and regulatory authorities where a legal obligation or legal basis exists.
- The entity to which Rixa's business is transferred as a result of a merger, acquisition or restructuring, subject to the adoption of appropriate legal safeguards.
Rixa requires its contracted processors to maintain the confidentiality and security of data and not to use it outside the specified purposes. Rixa does not sell personal data to third parties.
Electronic Payment
Payment transactions are processed through independent payment service providers. The User may enter card details directly into the payment provider's systems, and such processing is also subject to that provider's privacy policy and terms.
As necessary, Rixa receives limited transaction data, such as the transaction amount and status, reference number, type of payment method, refund data, and the last four digits of the card.
Data Collection and Use
Rixa may use artificial intelligence technologies and an automated assistant to respond to enquiries, verify appointments, create or amend bookings, send reminders, analyse requests, and suggest appropriate services or offers.
Rixa endeavours to make it clear that an interaction is taking place with an automated system where appropriate. The User may request human assistance through the support channels.
Conversations are not used to train general-purpose artificial intelligence models, and Rixa does not permit an external provider to use them for its independent purposes unless a legal basis is available and the User is notified or consent is obtained where necessary.
If Rixa makes a decision based entirely on automated processing and that decision has a material effect on the User, Rixa will provide the disclosures, consents and means required in accordance with the legal requirements.
Exchange of Information
Rixa does not send marketing communications by email, text message, WhatsApp or notification unless the required consent has been obtained.
The User may unsubscribe at any time through the unsubscribe link, account settings, the method stated in the message, or by contacting Rixa. Refusal of marketing does not affect the use of the core services.
Rixa uses cookies and similar technologies to operate the website, retain settings, secure accounts, analyse performance and usage, measure campaigns, and personalise content after obtaining consent where required.
The User may control non-essential cookies through browser settings or the cookie-preference panel. Disabling essential cookies may prevent certain Platform features from operating.
Transfer of Data Outside the Kingdom
Rixa may engage technology, cloud, messaging or analytics service providers whose systems are located inside or outside the Kingdom.
When personal data is transferred outside the Kingdom or made available to an entity outside it, Rixa complies with the legal requirements, including limiting the transfer to the minimum necessary, verifying the legitimate purpose, assessing the level of protection and risks where necessary, and applying the appropriate legal and contractual safeguards.
Retention and Destruction Period
Rixa retains data for the period necessary to achieve the purposes for which it was collected, taking into account the duration of the account and contractual relationship, booking and payment requirements, complaint and claim periods, accounting, tax and legal obligations, fraud-prevention requirements, and the protection of rights.
When the purpose or statutory retention period ends, the data is securely destroyed in a manner that prevents its recovery, or is anonymised so as to prevent re-identification, unless there is a legal basis requiring continued retention.
Data Protection and Data Breach Incidents
Rixa applies appropriate administrative, organisational and technical measures to protect data against loss, damage, alteration, disclosure or unauthorised access. These measures may include encryption of data in transit, access controls, authentication, backups, system monitoring, security testing, staff training, and the assessment of Service Providers.
Nevertheless, no electronic system can be guaranteed to be free from all risks. This does not affect Rixa’s obligation to adopt the appropriate statutory measures.
When a personal-data incident occurs, Rixa takes the necessary measures to contain it, assess its effects and address it, and notifies the competent authority and affected data subjects whenever the circumstances and statutory conditions requiring notification are met.
Rights of the Data Subject
Subject to the statutory exceptions, the data subject has the right to:
- Be informed of the legal basis and purpose for collecting and processing their data.
- Access their personal data.
- Obtain a copy of it in a readable, clear and commonly used format.
- Request its correction, completion or updating.
- Request its destruction where the statutory conditions apply.
- Withdraw consent where consent is the legal basis for processing.
- Submit a complaint concerning the processing of their data.
- Claim compensation for damage in accordance with the applicable legal provisions.
Exercising Rights and Submitting Complaints
Requests to exercise rights or complaints may be submitted through:
- Privacy email: care@rixa.app
- The website or application: rixa.app
- Phone: +966554867052
Rixa may request appropriate information to verify the identity of the person making the request and protect the data against disclosure to anyone other than its data subject.
Rixa will process the request within a period not exceeding thirty days from the date of receipt. The period may be extended for one additional period not exceeding thirty days in the statutory cases, after notifying the person making the request.
If the complaint is not handled satisfactorily, the data subject has the right to submit a complaint to the Saudi Data and Artificial Intelligence Authority through the available official channels.
Legal Capacity
Rixa's services are not intended for persons under eighteen years of age to create an independent account or complete a payment transaction.
If a person with limited or no legal capacity uses the service, this must be done through or with the consent of their legal guardian in accordance with the legal requirements.
If Rixa becomes aware that it has collected data relating to a person with limited or no legal capacity without appropriate consent or legal basis, it will take the necessary measures to stop the processing and destroy the data, unless a legal basis exists for retaining it.
Intellectual Property
The Rixa Platform may contain links or features belonging to independent entities. Data provided directly by the User to those entities is subject to their policies and terms.
The inclusion of a link does not mean that Rixa endorses the practices of the external entity. The User is advised to review its privacy policy before providing data.
Updating the Policy
Rixa may update this Policy when its services, processing practices or legal requirements change. The date of the latest update will appear at the top of the page.
Rixa will notify Users of material amendments through an appropriate means before they take effect. If an amendment introduces a new purpose requiring consent, the new processing will not begin before the required consent is obtained.
Applicable Law and Jurisdiction
This Policy is governed by the laws applicable in the Kingdom of Saudi Arabia, in particular the Personal Data Protection Law and its Implementing Regulations.