Privacy Policy

Your privacy matters to us. This policy explains how Livo Bank collects, uses, protects, and shares your personal data.

Last updated: May 2025 KSA PDPL Compliant Version 3.1
Home/ Legal/ Privacy Policy
Your Data, Your Rights: Livo Bank is committed to protecting your personal data in accordance with the Kingdom of Saudi Arabia's Personal Data Protection Law (PDPL) and applicable regulations.

1. Data Controller

The data controller responsible for your personal data is:

Entity Name
Livo Bank - Livo Bank
Headquarters
King Fahd Road, Al Olaya District, Riyadh, Kingdom of Saudi Arabia
Regulatory Authority
Regulator: pending, License No. PENDING
Data Protection Contact
privacy@livobank.online

2. Types of Personal Data We Collect

We collect and process the following categories of personal data:

2.1 Identity Data

  • Full name (as appearing on official ID)
  • National Identity Number / Iqama Number / Passport Number
  • Date of birth and place of birth
  • Nationality
  • Photograph (as required for identification)
  • Gender

2.2 Contact Data

  • Residential address and national address
  • Email address
  • Mobile phone number
  • Work phone number

2.3 Financial Data

  • Account balances and transaction history
  • Income and employment information
  • Credit history and credit score
  • Assets and liabilities
  • Tax identification numbers

2.4 Transaction Data

  • Details of transactions carried out through your accounts
  • Payment instructions and beneficiary details
  • Credit and debit card transaction records
  • Loan and finance repayment records

2.5 Technical Data

  • Device type, operating system, and browser information
  • IP address and geolocation data
  • Login timestamps and session data
  • Cookie identifiers and online activity data
  • Mobile device identifiers for app-based services

3. Purposes of Processing

We process your personal data for the following purposes:

  • Account Management: Opening, maintaining, and administering your accounts and providing banking services
  • Regulatory Compliance: Fulfilling our obligations under applicable regulations, AML/CFT laws, tax regulations, and other applicable legislation
  • Credit Assessment: Evaluating your creditworthiness for loan and credit card applications
  • Fraud Prevention: Detecting, preventing, and investigating fraudulent activities and unauthorized transactions
  • Marketing: Sending you promotional materials and product recommendations (with your consent, where required)
  • Service Improvement: Analyzing usage patterns to improve our products, services, and digital channels
  • Communication: Responding to your inquiries, complaints, and service requests
  • Risk Management: Managing credit risk, market risk, and operational risk as required by SAMA

We process your personal data on the following legal bases:

Consent
Where you have given explicit consent for specific processing activities, such as marketing communications. You may withdraw consent at any time.
Contractual Necessity
Where processing is necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract (e.g., account opening, processing transactions).
Legal Obligation
Where processing is required to comply with legal or regulatory obligations, including SAMA reporting requirements, AML/CFT regulations, and court orders.
Legitimate Interest
Where processing is necessary for our legitimate interests (or those of a third party), provided your fundamental rights do not override those interests. This includes fraud prevention, service improvement, and risk management.

5. Data Sharing

We may share your personal data with the following categories of recipients:

  • Regulator: pending: As required for regulatory oversight, supervision, and reporting
  • Credit Bureaus: Saudi Credit Bureau (SIMAH) for credit reporting and scoring purposes
  • Regulatory Authorities: Saudi Financial Intelligence Unit (SFIU), Zakat, Tax and Customs Authority (ZATCA), and other competent authorities as required by law
  • Service Providers: Third-party processors who provide services on our behalf (e.g., IT infrastructure, payment processing, courier services), subject to strict data protection obligations
  • Group Companies: Livo Bank subsidiaries and affiliates where necessary for internal administrative purposes, subject to appropriate safeguards
  • Correspondent Banks: For international wire transfers and trade finance transactions
  • Insurance Partners: For Takaful (Islamic insurance) products, with your consent
We do not sell your personal data to third parties. All data sharing is conducted in accordance with the KSA PDPL and applicable regulations.

6. Data Retention

We retain your personal data for the following periods:

  • Account Data: For the duration of the account relationship plus 5 years after account closure (as required by SAMA)
  • Transaction Records: Minimum 5 years from the date of the transaction
  • KYC Documents: Minimum 5 years from the end of the business relationship
  • Marketing Consent: Until consent is withdrawn
  • Complaints Records: Minimum 5 years from resolution of the complaint
  • Technical/Log Data: Maximum 12 months from collection, unless required for security investigations

After the applicable retention period expires, personal data is securely deleted or anonymized.

7. Your Rights

Under the KSA PDPL, you have the following rights regarding your personal data:

Right of Access

Request a copy of the personal data we hold about you.

Right of Rectification

Request correction of inaccurate or incomplete personal data.

Right of Erasure

Request deletion of your personal data, subject to legal retention obligations.

Right of Portability

Request your data in a structured, commonly used, machine-readable format.

Right to Object

Object to processing based on legitimate interest, including for marketing purposes.

Right to Restrict

Request restriction of processing in certain circumstances.

To exercise any of these rights, please contact our Data Protection team at privacy@livobank.online or call +966 92000 1000. We will respond to your request within the timeframes prescribed by the PDPL.

8. Data Security Measures

Livo Bank implements robust technical and organizational measures to protect your personal data, including:

  • 256-bit AES Encryption: All data is encrypted in transit and at rest using industry-standard encryption protocols
  • ISO 27001 Certification: Our Information Security Management System is certified to ISO 27001 standards
  • PCI DSS Compliance: Payment card data is handled in compliance with PCI DSS requirements
  • Multi-Factor Authentication: Biometric login, OTP verification, and two-factor authentication for high-risk transactions
  • Continuous Monitoring: 24/7 security operations center (SOC) monitoring for suspicious activities
  • Regular Audits: Periodic security assessments and penetration testing by independent third parties
  • Employee Training: Mandatory data protection and security awareness training for all employees

9. Cookies Policy

Livo Bank uses cookies and similar technologies on our website and digital channels. Cookies are small text files placed on your device to:

  • Essential Cookies: Required for the website to function properly (e.g., session management, security)
  • Analytics Cookies: Help us understand how visitors interact with our website (e.g., Google Analytics)
  • Preference Cookies: Remember your settings and preferences (e.g., language, region)
  • Marketing Cookies: Used to deliver relevant advertisements and measure campaign effectiveness

You can manage your cookie preferences through your browser settings. Disabling essential cookies may affect website functionality.

10. Children's Data

The Bank does not knowingly collect personal data from children under the age of 18 without the consent of a parent or legal guardian. Accounts for minors are opened by and managed under the supervision of a parent or guardian in accordance with applicable regulations. If we become aware that we have collected a child's data without proper consent, we will take steps to delete it promptly.

11. Cross-Border Data Transfers

Your personal data may be transferred to and processed in countries outside the Kingdom of Saudi Arabia for the purposes described in this policy (e.g., international wire transfers, cloud hosting). Such transfers are subject to appropriate safeguards as required by the PDPL, including:

  • Standard contractual clauses with the receiving entity
  • Adequacy assessments of the destination country's data protection regime
  • Your explicit consent where required

12. Contact Us

Data Subject Requests

privacy@livobank.online

Privacy Hotline

+966 92000 1000

Postal Address

King Fahd Road, Al Olaya District, Riyadh, KSA

13. Complaints to SAMA

If you are not satisfied with our handling of your data protection concerns, you have the right to lodge a complaint with the Regulator: pending through the SAMA Care channel within 90 days of receiving Livo Bank's final response. SAMA will review your complaint and coordinate with the Bank to achieve a resolution.

Commitment: The Bank is committed to maintaining the highest standards of data protection and privacy. We regularly review and update this policy to ensure compliance with evolving regulations and best practices.