HAY Website Privacy Policy

Effective Date: April 30, 2025

1. Introduction

Welcome to the HAY website (the “Website”). At HAY (“we,” “us,” or “our”), we are pioneering the concept of “soft development,” creating premium, human-centric spaces where places truly come to life. Just as we prioritize experiences, community, and emotional connection in our physical developments, we are deeply committed to protecting the privacy and security of your personal information when you interact with us online.

This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you visit or use our Website. It also outlines your rights regarding your personal data and how you can exercise them. We are committed to processing your data transparently, responsibly, and in compliance with applicable data protection laws, including the Saudi Arabia Personal Data Protection Law (PDPL).

By using our Website, you acknowledge that you have read and understood this Privacy Policy. We encourage you to review this policy carefully to understand our practices regarding your personal data.

2. Information We Collect

We collect personal data to provide and improve our services, respond to your inquiries, and personalize your experience on our Website. The types of personal data we collect depend on how you interact with us:

a) Information You Provide Directly:

  • Contact Information: When you fill out contact forms, subscribe to our newsletter, or create a user account, we may collect your name, email address, and phone number.
  • Form Submissions: We collect the information you voluntarily provide when submitting forms on our Website, which may include inquiries, feedback, or requests for information.

b) Information Collected Automatically:

  • Usage Data: When you browse our Website, we automatically collect certain information about your device and how you interact with our site. This may include your IP address, browser type, operating system, pages visited, time spent on pages, and referring website addresses.
  • Cookies and Similar Technologies: We use cookies and similar tracking technologies (like web beacons or tags) to collect and track information about your browsing behavior, enhance your user experience, and analyze website traffic. Cookies are small data files stored on your device. We use:
    • Essential Cookies: Necessary for the Website to function properly.
    • Performance/Analytics Cookies: Help us understand how visitors use our Website, allowing us to improve its performance. We use tools like Google Analytics for this purpose. Google Analytics collects information such as how often users visit the site, what pages they visit, and what other sites they used prior to coming to our site. Google’s ability to use and share information collected by Google Analytics about your visits to this site is restricted by the Google Analytics Terms of Use and the Google Privacy Policy.
    • Functionality Cookies: Allow the Website to remember choices you make (such as language preference) and provide enhanced features.
    • Marketing Cookies: Used to track visitors across websites to display relevant advertisements (if applicable).

You can control the use of cookies through your browser settings. However, disabling certain cookies may affect the functionality of the Website.

3. How We Use Your Information

We use the personal data we collect for the following purposes, based on appropriate legal grounds as required by the PDPL:

  • To Provide and Manage Services: To operate our Website, manage user accounts, and provide you with the information or services you request.
  • To Respond to Inquiries: To communicate with you and respond to your questions, comments, or requests submitted through contact forms or other channels. (Legal Basis: Legitimate Interest / Performance of Contract)
  • To Send Marketing Communications: With your explicit consent, to send you newsletters, promotional materials, updates about HAY projects, and other marketing communications we believe may interest you. You can opt-out of these communications at any time. (Legal Basis: Consent)
  • To Improve Website Performance: To analyze how users interact with our Website using tools like Google Analytics, monitor performance, gather demographic information, identify trends, and improve the Website’s functionality, content, and user experience. (Legal Basis: Legitimate Interest / Consent for non-essential cookies)
  • To Personalize User Experience: To remember your preferences and settings, and tailor the content and features you see on our Website. (Legal Basis: Consent for functionality cookies / Legitimate Interest)
  • For Security and Compliance: To protect the security and integrity of our Website, prevent fraud, enforce our terms, and comply with legal obligations and regulatory requirements.

We will only process your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason compatible with the original purpose and permitted by law. We will obtain your explicit consent before using your personal data for any unrelated purpose.

4. How We Share Your Information

We respect your privacy and limit the sharing of your personal data. We do not sell your personal data. However, we may share your information in the following circumstances:

  • With Service Providers: We may share your data with trusted third-party vendors, consultants, and other service providers who perform services on our behalf. This includes website hosting, data analysis (like Google Analytics), marketing assistance, customer service, and IT support. These providers are contractually obligated to protect your data, use it only for the purposes we specify, and comply with applicable data protection laws.
  • For Legal Reasons: We may disclose your information if required to do so by law, regulation, or legal process (such as a court order or subpoena), or in response to valid requests by public authorities (e.g., a government or regulatory agency) to meet national security or law enforcement requirements.
  • To Protect Rights and Property: We may share information if we believe it necessary to investigate, prevent, or take action regarding potential violations of our policies, suspected fraud, situations involving potential threats to the safety of any person, or as evidence in litigation in which we are involved.
  • Business Transfers: In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Website of any change in ownership or uses of your personal data, as well as any choices you may have regarding your data.
  • With Your Consent: We may share your information with other third parties when we have your explicit consent to do so.

International Data Transfers: Some of the third parties we share data with (e.g., Google Analytics) may be located outside of the Kingdom of Saudi Arabia. When we transfer your personal data outside KSA, we will ensure that appropriate safeguards are in place to protect your data in accordance with the requirements of the PDPL and its implementing regulations. This may include relying on adequacy decisions, implementing standard contractual clauses approved by the relevant authorities, or obtaining your explicit consent for the transfer after informing you of the potential risks.

5. Your Rights and Choices

Under the Saudi Arabia Personal Data Protection Law (PDPL) and other applicable regulations, you have certain rights regarding your personal data. We are committed to facilitating the exercise of these rights. Subject to legal limitations and requirements, your rights include:

  • The Right to be Informed: You have the right to be informed about the collection and use of your personal data, including the legal basis and purpose for processing, as outlined in this Privacy Policy.
  • The Right of Access: You have the right to request access to the personal data we hold about you and receive a copy of it, typically in a readable and clear format (e.g., electronic format).
  • The Right to Request Correction: You have the right to request the correction of any inaccurate or incomplete personal data we hold about you.
  • The Right to Request Destruction (Deletion): You have the right to request the deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or if you withdraw consent (where applicable), or if the data has been processed unlawfully, subject to certain exceptions.
  • The Right to Withdraw Consent: Where we rely on your consent to process your personal data (e.g., for marketing communications), you have the right to withdraw that consent at any time. Withdrawing consent will not affect the lawfulness of processing based on consent before its withdrawal.
  • The Right to Restrict Processing: You may have the right to request the restriction of processing your personal data under certain circumstances, such as when you contest the accuracy of the data or object to the processing.

Exercising Your Rights:

To exercise any of these rights, please contact us using the details provided below. You can submit your request via email to:

it@hayliving.com

Please clearly state the right you wish to exercise and provide sufficient information to allow us to verify your identity. We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.

We will respond to your request within thirty (30) days of receipt. In certain complex cases or if we receive multiple requests, this period may be extended by an additional thirty (30) days, in which case we will inform you of the extension and the reasons for the delay.

Your Choices:

  • Marketing Communications: You can opt-out of receiving marketing emails from us at any time by clicking the “unsubscribe” link provided in those emails or by contacting us directly at it@hayliving.com.
  • Cookies: You can manage your cookie preferences through your browser settings or potentially through a cookie consent tool on our Website. Please refer to Section 2(b) for more details on cookies.

6. Data Security

We take the security of your personal data seriously and implement reasonable and appropriate technical, administrative, and organizational measures designed to protect your information from unauthorized access, use, disclosure, alteration, or destruction. These measures are consistent with the requirements of the PDPL and industry best practices.

Examples of security measures we may employ include:

  • Encryption: Using encryption technologies for data transmission and storage where appropriate.
  • Access Controls: Limiting access to personal data to authorized personnel who need it for their job functions.
  • Secure Storage: Utilizing secure servers and data centers.
  • Regular Assessments: Conducting regular security assessments and vulnerability testing.
  • Data Minimization: Collecting only the personal data necessary for the specified purposes.
  • Staff Training: Providing data protection training to our employees.

While we strive to use commercially acceptable means to protect your personal data, please remember that no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee its absolute security.

7. Data Retention

We will retain your personal data only for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements, or as otherwise required or permitted by applicable law, including the PDPL. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process it, and applicable legal requirements.

When your personal data is no longer needed for these purposes, we will securely destroy or anonymize it in accordance with our data retention policies and applicable laws.

8. Children’s Privacy

Our Website is not intended for use by children under the age of 18 (or the relevant age of majority). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child without appropriate consent, we will take steps to delete that information as soon as possible.

9. Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes, we will update the “Effective Date” at the top of this policy.

We will notify you of any material changes by posting the updated policy prominently on our Website and, where feasible, by sending a notification to the email address associated with your account (if applicable). We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.

10. Contact Us

If you have any questions, comments, or concerns about this Privacy Policy or our data practices, or if you wish to exercise your rights regarding your personal data, please contact us at:

Email: it@hayliving.com

We will address your concerns and attempt to resolve any privacy issues in a timely manner.