This policy is an integral part of the framework governing the use of the TAC Flow platform. It explains how data is collected, processed, and protected in line with leading technical practices and the regulations in force in the Kingdom of Saudi Arabia.
TAC Flow is operated by the equipment e-marketing platform owned by TAC Group, under commercial registration number 7038510140, with its registered address at Riyadh — King Abdulaziz District.
We collect the data necessary to deliver the service efficiently, including account information, asset and equipment data, maintenance records, incident reports, and operational data associated with use of the platform.
Data may also include technical information related to platform usage — such as login times, device type, and operational event logs — for the purpose of improving performance, security, and the user experience.
Data may further include content uploaded by the customer, such as photos, reports, and operational attachments, which are processed exclusively in the context of delivering the service.
The “TAC Flow Field” app provides field representatives with visit logging and route tracking. When a representative starts their work shift, the app collects their geographic location — including while running in the background or with the screen off — to trace their visit route and verify arrival at customer sites.
Location collection is limited to the active shift only. Tracking stops automatically the moment the representative ends their shift and never runs outside working hours. The app requests the representative’s explicit consent before enabling tracking and shows a visible notification for the entire duration of the shift.
Location data is used exclusively for the company’s field supervision and operations, and is never sold or shared with third parties for marketing purposes.
Data is used to improve service quality, operate platform features, generate reports, support users, and strengthen the security and stability of the system. Customer data is not used outside the scope of delivering and improving the service.
Data is also used to enhance the accuracy of alerts, develop preventive and predictive maintenance capabilities, and support customer teams with technical and operational follow-up.
We apply appropriate technical and organizational measures to protect data against unauthorized access, loss, alteration, or disclosure. Security controls are reviewed regularly to ensure ongoing protection.
These measures include access-control policies, periodic backup procedures, and technical monitoring practices intended to safeguard the operating environment and the continuity of the service.
The customer is likewise responsible for managing the permissions of its internal users in a disciplined manner, since data security is a shared responsibility between provider and customer.
Customer data is not shared with any third party except where necessary to deliver the service, or where required by a legal or judicial obligation, and only to the minimum extent required.
When supporting technology service providers are engaged, processing is carried out under contractual safeguards that ensure data confidentiality and limit use to the defined operational purpose.
Customer data is never sold or licensed to any third party for marketing purposes independent of the scope of the service.
Customers may request to update or correct their data and to inquire about how it is processed, through the official communication channels approved by TAC Flow.
Customers may also request clarifications regarding data-retention controls associated with their account, and may request support in managing permissions and access within their operating environment.
Data is retained for the period required to deliver the service and to fulfill compliance and operational-documentation purposes, or as required by applicable regulations.
Upon termination of the contractual relationship, data is handled in accordance with the retention, archiving, and deletion policies adopted by TAC Flow, in line with regulatory requirements.
Should the customer request a copy of its data after termination, it will be provided in a mutually agreed format within a reasonable period and in accordance with approved operational procedures.
The platform may use cookies or similar technologies to improve performance, analyze usage, and provide a more stable user experience.
Users may manage their browser settings related to these technologies, noting that disabling some of them may affect the functionality of certain platform features.
We treat asset data, maintenance records, and incident reports as sensitive operational data, with access restricted under clearly defined roles and permissions.
This approach aims to protect the confidentiality of operational information, limit unauthorized access, and strengthen the reliability of data-driven decisions.
This policy may be updated as needed to reflect the continuous development of the platform and applicable regulatory requirements. Continued use of the platform after an update constitutes implicit acceptance of the most recent version of the policy.
TAC Flow is committed to processing data in accordance with the laws and regulations in force in the Kingdom of Saudi Arabia, including relevant requirements for the protection of personal data.
For any inquiry related to privacy or data processing, you may reach us through the official channels approved by TAC Flow. Requests will be handled seriously, professionally, and within a reasonable timeframe.