Legal
Privacy policy
Last updated August 2026
Yasmina is trusted with sensitive data — by partners building on the platform and by their customers buying cover. This policy explains exactly what we collect, why, who sees it and the rights you have under the Saudi Personal Data Protection Law.
1. Who this covers
This policy explains how Yasmina handles personal data when you visit our website, register for the partner portal, or when insurance is purchased through a partner’s integration. It is written to comply with the Saudi Personal Data Protection Law (PDPL) and its regulations.
2. Data we collect
Partner data: name, work email, phone number, company details (commercial registration, IBAN) and portal activity — collected when you create and operate a partner account.
Policyholder data: identification details (such as National or Iqama ID), contact details and the information needed to quote and issue the specific insurance product — submitted through a partner’s integration when a customer buys cover.
Website data: the name, work email, company and message you send through our contact and sales forms, and — if you apply to a role — your name, email, phone, CV and any links or notes you add.
3. How we use it
We use personal data to operate the platform: verifying and onboarding partners, quoting and issuing policies with the underwriting insurer, paying revenue share, providing support, meeting regulatory obligations, preventing fraud, and improving the product. We do not sell personal data.
4. Legal bases
We process data where it is necessary to perform a contract (issuing a policy, operating your account), to comply with legal obligations (Insurance Authority and other regulatory requirements), for our legitimate interests (security, product improvement), or with consent where the PDPL requires it — which you can withdraw at any time.
5. Who we share it with
Policy data is shared with the licensed Saudi insurer underwriting the product, and with regulators where required. We use vetted service providers (hosting, communications) under contracts that restrict their use of the data. Partners see the policy data of their own customers only. We do not transfer personal data outside Saudi Arabia except as the PDPL permits.
6. Retention
We keep personal data only as long as needed for the purposes above — policy records for the periods insurance regulation requires, account data for the life of the account plus applicable statutory periods — and then delete or anonymise it.
7. Security
Data is encrypted in transit and at rest. Access is role-based and logged. API authentication uses scoped client secrets that partners are required to store securely. We review our controls regularly and notify affected parties and authorities of any breach as the PDPL requires.
8. Your rights
Under the PDPL you can request access to your personal data, correction of inaccurate data, deletion where the law allows, and a copy of data you provided. You can also withdraw consent and object to certain processing. Write to hello@yasmina.ai and we will respond within the statutory period.
9. Cookies
This website currently sets no analytics or advertising cookies — there is no Google Analytics, no Meta or LinkedIn pixel, and no session recording of any kind. The only cookies it can set are Cloudflare’s bot-check on the contact and application forms, and a sign-in cookie for staff using the internal admin — never for an ordinary visitor. The cookie banner still lets you record a preference, in case that ever changes.
10. Changes
We update this policy as the platform and regulation evolve. Material changes are announced on this page and, for partners, in the portal before they take effect.
11. Contact
Questions about this document? Write to hello@yasmina.ai or reach us via the contact page.