This privacy notice ("Notice") applies to current and former users of the KAUSTCentral application. The purpose of this Notice is to inform you of how we process your Personal Data. This Notice does not form part of any contract.
For the purpose of applicable data protection legislation, the entity which is responsible for your Personal Data is King Abdullah University of Science and Technology, Thuwal 23955-6900, Kingdom of Saudi Arabia ("KAUST", "we", "us", "our").
This Notice replaces and supersedes any previous notices addressing the same or similar issues, whether formal or informal. KAUST reserves the right to alter, amend, or replace this Notice in whole or in part. The latest version of this Notice can be found here. You should always check that you are referring to the latest version of this Notice if you have previously downloaded hard copies of this Notice.For a copy of a previous version of this privacy notice, please contact DPO@KAUST.edu.sa.
Depending on how you interact with the application, the following types of Personal Data may be collected by
the KAUSTCentral application
As new features are added, other similar types of Personal Data may be collected to enable you to use those features and capture your preferences.
Please note: No payment information is collected or otherwise processed by the KAUSTCentral
app.
Most Personal Data is collected from the information you enter into the application, i.e., your
preferences, your orders and/or requests for services, and your profile information. KAUSTCentral
captures your login information when you log in. Individuals may report phone numbers connected to
scam phone calls. KAUST maintains a database of phone numbers for individuals approved to access KAUST
IT systems, which is used as the “Verified” list in the VerifyCaller function. Names associated with
KAUST-issued phone numbers are obtained from you at the time of issuing the phone number. For any
questions about your Personal Data collected by the application, please contact us at
KAUSTCentral.support@kaust.edu.sa
or DPO@kaust.edu.sa. . In cases of a localized emergency, KAUSTCentral may access your office location from a KAUST IT system. KAUSTCentral also logs when you scan your QR Code in connection with a bus booking, event registration, and cinema booking.
No, the application is designed to be "opt-in" to optimize your data privacy. Logging into the application, creating a profile, requesting notifications, and setting preferences are completely optional.
Access to certain functionalities is restricted to authenticated users.
We collect and share the following data with third party service providers registered at KAUST:
- Food retailers: your order and contact details to prepare and deliver the food you request
- Taxi service providers: your pick-up location and destination, contact information and preferences (i.e., if a wheelchair is required, the type of vehicle requested, etc...)
- Bus service providers: your booking details, including destination, departure date, time, number of passengers with you, whether you are booking for another person, whether the trip is one-way or round trip
- Cinema service provider: your ticket details, including the date, time, and movie selected; the number of tickets you booked; and attendance at the event (check-in with QR code)
- Key and access management service providers: your KAUST ID and virtual office key.
- Communications, Space & Technology Commission: phone numbers you report in VerifyCaller that KAUST Information Security investigate and determine to be scammers are reported to the Communications, Space & Technology Commission.
We do not share any Personal Data with any third parties for advertising or marketing purposes, and we
never sell Personal Data to third parties. and
Personal Data will be stored in a variety of places – in the University's IT systems, including e-mail, and in the cloud on third-party servers that are located inside and outside the Kingdom of Saudi Arabia.
In some scenarios, the KAUSTCentral application acts as a hub of communication to access a set of services and/or applications provided by third-party systems. Sometimes content is embedded in third-party applications and/or sites that KAUST does not control or operate. When you interact with these sites, you are not interacting with KAUSTCentral but instead the embedded service, and KAUST cannot guarantee which Personal Data will be collected and stored. As such, the Personal Data sent to these applications is not transmitted via the KAUSTCentral backend, not stored, and KAUST is not responsible for the privacy practices of these third parties. You should review their respective privacy policies before interacting with such content.
Any Personal Data collected will be viewed and stored with all reasonable care, and we implement a variety of security measures to prevent your Personal Data from being accidentally lost, used, or accessed in an unauthorized way. For instance, all communication between the KAUSTCentral app, and the KAUSTCentral backend are encrypted using HTTPS. We limit access to your Personal Data to those who have a genuine business need to know it. Those processing your Personal Data will do so only in an authorized manner and are subject to a confidentiality agreement.
For more information about the technical measures KAUST applies to protect your Personal Data, please
see KAUST's
Minimum Security Standard,
Information Security Policy, and
Data Classification Procedure.