Data Protection Policy
1. Purpose of This Policy
The purpose of this policy is to:
- Protect personal and business data
- Ensure responsible data handling practices
- Reduce risks related to unauthorized access or misuse
- Support operational security and confidentiality
- Define responsibilities regarding data management
2. Scope
This policy applies to:
- Website visitors
- Clients and customers
- Employees and contractors
- Vendors and service providers
- Users of software, applications, and digital platforms managed by SolveTech
It covers both electronic and physical records where applicable.
3. Types of Data We May Collect
Depending on the nature of services provided, SolveTech may collect:
Personal Information
- Name
- Phone number
- Email address
- Company details
- Billing information
- Communication records
Technical Information
- IP address
- Browser type
- Device information
- Server logs
- Usage analytics
- Login activity
Business & Project Data
- Project documentation
- Software requirements
- Databases and records
- Credentials and access permissions
- Infrastructure configurations
4. Purpose of Data Collection
Data may be collected and processed for purposes including:
- Delivering IT and software services
- Client communication and support
- Billing and payment processing
- Technical troubleshooting
- System security and monitoring
- Service improvements and analytics
- Legal, contractual, or compliance obligations
- Preventing fraud or unauthorized access
5. Data Security Measures
SolveTech implements commercially reasonable safeguards to protect data, including:
- Access controls and authentication measures
- Password protection procedures
- Encrypted communication where applicable
- Security monitoring systems
- Firewall and infrastructure protection
- Limited administrative access
- Secure backup practices where included
Despite reasonable efforts, no digital environment can guarantee absolute security.
6. Data Access & Confidentiality
Access to sensitive information is restricted to authorized personnel, contractors, or service providers who require access for legitimate operational purposes.
Individuals handling data are expected to maintain confidentiality and follow internal security procedures.
7. Third-Party Services
SolveTech may use third-party providers for:
- Cloud hosting
- Payment processing
- Communication tools
- Analytics services
- Domain and infrastructure management
- API integrations
Third-party providers may process data according to their own privacy and security policies.
SolveTech is not responsible for security practices beyond its reasonable operational control.
8. Data Retention
Data may be retained:
- For the duration of the business relationship
- To fulfill contractual obligations
- For backup, operational, accounting, or legal purposes
- As required under applicable regulations
Data no longer required may be deleted, archived, or anonymized where reasonably possible.
9. Client Responsibilities
Clients are responsible for:
- Maintaining secure passwords and credentials
- Limiting unauthorized access to systems
- Providing lawful data for processing
- Maintaining backups where backup services are not included
- Informing SolveTech of suspected security incidents
10. International Data Transfers
Where services involve international cloud platforms or infrastructure providers, data may be processed or stored outside Kuwait subject to applicable operational and technical requirements.
11. Data Breach & Security Incidents
In the event of a suspected security incident or data breach:
- SolveTech may investigate and take reasonable containment measures.
- Affected clients may be notified where appropriate and reasonably practicable.
- Response timelines may depend on the nature and severity of the incident.
12. User Rights
Subject to applicable laws and operational limitations, individuals may request:
- Access to personal information
- Correction of inaccurate data
- Deletion requests where legally permissible
- Withdrawal of certain permissions where applicable
Certain data may still be retained where required for legal, contractual, or operational purposes.
13. Limitation of Liability
SolveTech shall not be liable for data loss, disclosure, or security incidents resulting from:
- Cyberattacks beyond reasonable protection measures
- User negligence or weak password practices
- Third-party provider failures
- Force majeure events
- Unauthorized external access
14. Employee & Internal Data Protection
Employees, contractors, and personnel handling sensitive information are expected to:
- Follow internal security procedures
- Use company systems responsibly
- Avoid unauthorized disclosure of confidential data
- Report suspected security incidents promptly
15. Governing Law
This Data Protection Policy shall be governed by the laws of the State of Kuwait.
Any disputes shall be subject to the jurisdiction of the competent courts in Kuwait.
16. Policy Updates
SolveTech reserves the right to modify or update this policy at any time. Updated versions become effective upon publication on official communication channels or websites.
17. Contact Information
For data protection or privacy-related inquiries, contact:
SolveTech
Kuwait
Email: privacy@solvetech.com
Phone: +965 XXXXXXXX