Privacy Policy
Shaima Alattas Photography Studio ("the Studio," "we," "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what information we collect when you visit our website (shaimaalattas.com) or engage the Studio for a commission, how we use it, with whom we share it, and the rights you have under the Saudi Personal Data Protection Law (PDPL) and other applicable laws.
1. Who we are
The Studio is operated by Shaima Anwar Alattas, based in Jeddah, Kingdom of Saudi Arabia. For all data-protection enquiries, please contact us at Support@shaimaalattas.com.
2. What we collect
We collect the following categories of personal data:
- Contact details you provide voluntarily: full name, email address, WhatsApp/phone number, and any notes you include in our contact or booking flow.
- Booking details processed through our third-party scheduling provider (Calendly): the session type you select, your chosen date and time, and any information you submit on Calendly's intake form.
- Payment details processed by our payment gateway to collect the 25% booking deposit. We do not store or have direct access to your card number, expiry, or CVV — these remain with the gateway. We receive only a charge reference, the amount, and confirmation of success or failure.
- Photographs of you created during your commissioned session. Photographs are personal data under the PDPL when they identify you.
- Technical data: IP address, browser type and version, device type, pages visited, and timestamps. This is collected automatically when you visit the site.
- Cookies and similar technologies — see Section 9 below.
3. Why we collect it (legal basis)
- To respond to your enquiry and operate the booking process — legal basis: performance of a contract or pre-contractual steps requested by you.
- To deliver your session and final photographs — legal basis: performance of a contract.
- To send your invoice, session reminders, and after-session follow-up — legal basis: performance of a contract.
- To use your photographs in our portfolio, social channels, exhibitions, or marketing — legal basis: your explicit written consent recorded in a separate Photo Release. Photographs are never published without that consent.
- To improve the website through anonymous analytics — legal basis: your consent given via our cookie banner.
- To comply with Saudi law — including ZATCA tax record-keeping obligations.
4. Who we share it with
We share your data only with the third-party processors needed to operate the Studio. Each processor is contractually bound to protect your data and use it only for the purposes we instruct:
- Calendly — appointment scheduling.
- [Payment gateway — to be confirmed] — deposit collection. The gateway is PCI-DSS compliant.
- WhatsApp Business / email service provider — invoice and confirmation delivery.
- Analytics provider — anonymous traffic analysis (only with your consent).
- Hosting provider (Netlify) — website infrastructure.
- Tax authorities (ZATCA) and regulatory bodies — where required by Saudi law.
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.
5. International transfers
Some of our processors store data outside the Kingdom of Saudi Arabia. Where this is the case, we rely on the safeguards permitted under the PDPL — including service-provider contractual commitments to apply protections substantively equivalent to those required under Saudi law. If you would like further detail on any specific transfer, please write to us.
6. How long we keep it
- Enquiry and booking records: up to 24 months after your last contact with the Studio, then deleted or anonymised.
- Invoices and accounting records: retained for at least the period required by Saudi tax law (currently 10 years for VAT-registered businesses).
- Photographs: kept indefinitely as part of our professional archive, unless you exercise your rights under Section 7.
- Analytics data: anonymised at the point of collection where technically possible; otherwise retained for no longer than 14 months.
7. Your rights
Under the PDPL you have the right to:
- Be informed about how we use your personal data (this Policy).
- Access the personal data we hold about you.
- Have inaccurate or incomplete data corrected.
- Request that we destroy your personal data when it is no longer required for the purposes it was collected for.
- Withdraw any consent you previously gave, at any time, without affecting the lawfulness of processing before the withdrawal.
- Lodge a complaint with the Saudi Data & AI Authority (SDAIA) if you believe your rights have been infringed.
To exercise any of these rights, write to Support@shaimaalattas.com. We respond within 30 days.
8. Security
We apply administrative, technical, and physical safeguards proportionate to the sensitivity of the data — including HTTPS across the site, strong access controls on our booking and payment systems, and limiting staff access on a need-to-know basis. No method of transmission over the internet is 100% secure; if you believe your data has been compromised, please contact us immediately.
9. Cookies and analytics
We use two kinds of cookies on this site:
- Essential cookies: required for the site to function (for example, remembering your language choice and cookie preference). These are set without your consent because the site cannot operate without them.
- Analytics cookies: anonymous, used to understand which pages are visited and how the site performs. These are set only after you accept them via the cookie banner. You can decline at any time.
You can clear cookies at any time from your browser settings.
10. Children
The website is not directed at children under 18. We do not knowingly collect personal data from children. Sessions involving minors are arranged exclusively through the child's parent or legal guardian, and any photographs of minors used in our portfolio require explicit written parental consent on the Photo Release.
11. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date at the top of the page reflects the most recent revision. Material changes will be highlighted on the website and, where appropriate, notified to you directly.
12. Governing law
This Policy is governed by the laws of the Kingdom of Saudi Arabia. Any dispute relating to it shall be resolved before the competent courts of Jeddah.
13. Contact
Shaima Alattas Photography Studio
Jeddah, Kingdom of Saudi Arabia
Support@shaimaalattas.com