PRIVACY POLICY
1. Introduction
SIQ PETRA respects the privacy of its users and processes personal data in accordance with the laws in force in the Hashemite Kingdom of Jordan, including Personal Data Protection Law No. 24 of 2023 and the regulations and instructions issued under it.
This Policy explains what personal data we collect, why we use it, with whom we may share it, how long we retain it, the rights available to data subjects, and how to contact us.
2. Data Controller
The controller responsible for processing personal data within the scope of SIQ PETRA services is Siq Petra for Marketing and E-Commerce LLC, National Establishment No. 200212988, Registration No. 82058, with its registered centre in Amman, Hashemite Kingdom of Jordan.
Privacy contact: info@siqpetra.com | +962 79 126 2026. If a Data Protection Officer or dedicated privacy channel is appointed in the future, this page will be updated with the relevant details.
3. Scope of This Policy
This Policy applies to website visitors, customers, account holders, persons submitting enquiries or complaints, marketing subscribers, supplier representatives, and any natural person whose personal data is processed through the Platform’s services.
4. Categories of Personal Data We May Collect
Identity and contact data: name, phone number, email address, delivery address, and billing address.
Account data: username, account settings, login history, and preferences.
Order and transaction data: products ordered, transaction values, order status, refunds, invoices, shipping details, and customer-service history.
Payment data: payment status, transaction identifiers, and information made available to us by the payment provider. Sensitive card information should never be sent to us by email or chat.
Technical data: IP address, device and browser type, security logs, and usage events necessary to operate and protect the website.
Marketing data: preferences, consents, subscription source, and campaign interactions, where applicable.
Supplier and representative data: contact details, job title or capacity, and documents needed for the commercial relationship, settlement, and compliance.
5. Sensitive Personal Data
SIQ PETRA does not ask customers to provide sensitive personal data unless it is necessary and legally permitted. Certain financial or other information may be considered sensitive under applicable law. Core payment information is processed through qualified payment service providers according to the design of the service.
6. Sources of Personal Data
We collect data directly from individuals when they create an account, place an order, or contact us; from their use of the website; from payment, shipping, and technical service providers to the extent required to perform a transaction; and from suppliers where such collection is necessary and lawful.
7. Purposes of Processing
We process personal data to create and manage accounts; process orders, payments, and shipping; issue invoices and documents; administer returns and complaints; provide operational communications; prevent fraud and secure systems; improve Platform performance; manage suppliers; comply with legal, accounting, and regulatory obligations; protect legal rights; and send marketing communications where the necessary consent or legal basis exists.
8. Legal Basis and Consent
Processing is carried out on the basis of prior consent where required by law, in circumstances where the law permits processing without consent, or where processing is necessary to perform a transaction or comply with a legal obligation, as applicable.
Where we rely on consent, it must be specific, clear, and capable of proof. Consent may be withdrawn in accordance with applicable law without affecting the lawfulness of processing carried out before withdrawal.
9. Direct Marketing
We do not make marketing consent a condition of completing a purchase where it is not necessary for that purchase. Users may unsubscribe from marketing messages through the unsubscribe link or by contacting us. Opting out of marketing does not affect operational messages that are necessary for orders, account administration, or security.
10. Disclosure and Sharing of Personal Data
We may share the minimum personal data necessary with shipping companies, payment providers and banks, hosting, infrastructure, email, customer-service, and analytics providers, the supplier that requires data to fulfil a specific order, professional advisers, and government or judicial authorities where there is a legal obligation or competent order.
We do not sell personal-data lists to third parties for their independent marketing purposes.
11. Suppliers and Customer Data
Where a supplier needs the customer’s name, phone number, or address to fulfil an order, only the necessary information will be shared. The supplier must not use that data for independent marketing or to build its own customer database unless it has a separate lawful basis and any required consent.
12. Processors and Service Providers
Where another party processes personal data on behalf of SIQ PETRA, we seek to regulate the relationship contractually so that data is used only for the specified purpose and period and is subject to confidentiality, security, deletion, or return obligations in accordance with applicable law.
13. Transfers Outside Jordan
The Platform may rely on hosting, cloud, email, payment, or other technical services whose providers or servers are located outside Jordan. When personal data is transferred outside the Kingdom, SIQ PETRA takes the necessary measures to verify the required level of protection and comply with the legal conditions applicable to international data transfers.
14. Retention Periods
SIQ PETRA retains personal data only for as long as necessary for the purpose for which it was collected, or for the period required by law or necessary to protect legal rights. As an operational standard:
Account data: for the duration of the active account and for up to two years after closure unless a valid deletion request, legal obligation, or ongoing dispute requires otherwise.
Orders, invoices, and financial records: for the legally required period. Applicable invoicing and financial-record obligations may require retention for at least four years for certain records.
Complaints and customer service records: for up to three years after closure of the complaint, unless a longer period is required because of a dispute or legal obligation.
Technical and security logs: generally for up to 12 months, with longer retention where required for a security incident or legitimate investigation.
Marketing data: until consent is withdrawn or the purpose expires, while a limited suppression record may be retained to prove the opt-out and prevent unintended re-subscription.
Cookie data: according to the periods shown in the Cookie Settings tool and the technologies actually used.
15. Data Subject Rights
Subject to applicable law and the circumstances of the request, an individual may have the right to be informed about and access personal data, obtain a copy of it, withdraw consent, correct, amend, or update data, restrict the scope of processing, object to processing, request deletion or concealment where legally available, and request data portability where provided by law.
Some requests may not be fulfilled where data must be retained due to a legal obligation or where a lawful exception applies.
16. Exercising Your Rights
Privacy requests should be sent to info@siqpetra.com with a clear description of the request. We may request reasonable information to verify identity before disclosing, changing, or deleting personal data in order to protect the data subject against unauthorised access.
17. Data Security
SIQ PETRA applies technical and organisational measures proportionate to the nature of the data and the risks involved, including access controls, account protection, backups, security updates, encryption where appropriate, event logging, incident-response procedures, and periodic security testing.
No electronic system can be guaranteed to be completely secure. Protection therefore depends on a combination of technical, administrative, and user-side measures, including the user’s responsibility to protect account credentials.
18. Personal Data Security Incidents
If a serious personal-data security incident occurs, SIQ PETRA will take containment and assessment measures and provide any legally required notifications to affected persons and competent authorities within the time limits and conditions prescribed by law.
19. Cookies and Similar Technologies
The Platform uses essential cookies for operation, security, shopping-cart functionality, and accounts. Non-essential analytics or marketing cookies that require consent will not be activated except in accordance with the user’s choices. See the Cookie Policy for further details.
20. Minors and Persons Without Legal Capacity
Purchases through the Platform are intended for persons with legal capacity or must be made under proper legal supervision or representation. If SIQ PETRA learns that personal data of a person without legal capacity has been collected in circumstances requiring a parent’s or guardian’s consent, appropriate steps will be taken in accordance with law.
21. External Links and Services
The Platform may contain links to or integrations with external services. Where those parties act as independent data controllers, their own privacy policies govern their processing activities.
22. Complaints
We encourage individuals to contact SIQ PETRA first at info@siqpetra.com to address any privacy concern. This does not affect the individual’s right to approach the competent authorities in accordance with law.
23. Updates to This Policy
We may update this Policy when services, technologies, or legal requirements change. The latest update date will appear at the top of the page. Fresh consent will be requested where legally required due to a material change in the nature or purpose of processing.
