SITR
Privacy PolicySITR W.L.L.

Privacy Policy

This Privacy Policy describes how SITR W.L.L.(“SITR”, “we”, “us”, or “our”) handles data in connection with the platform.

3.1Introduction

This Privacy Policy is intended to inform prospective and current client institutions, their technology teams, and relevant regulators about our data practices.

SITR is an enterprise infrastructure platform deployed within or connected to client environments. The scope, ownership, and handling of data differs significantly from consumer software and is addressed in detail below.

3.2Deployment Architecture and Data Residency

On-premise deployment

Where SITR is deployed on-premise within the client’s own infrastructure, all transaction data processed by the platform remains within the client’s environment at all times. SITR does not have access to, does not store, and does not transmit client transaction data to external systems in this configuration.

Hosted or hybrid configurations

Where a hosted or hybrid configuration is agreed upon in writing, data handling, storage locations, and access rights are defined in the applicable Data Processing Agreement (DPA) executed between SITR and the client institution prior to deployment.

No default data transmission

By default, SITR does not transmit any transaction data, customer data, or institution-specific configuration data to SITR systems or third-party services. This applies to all deployment configurations unless explicitly agreed otherwise in writing.

3.3Categories of Data

Client institution data

Transaction records, account identifiers, product configurations, and Shariah rule mappings provided by or generated on behalf of the client institution are treated as the exclusive property of the client institution. SITR claims no ownership or independent right to use this data.

Platform configuration data

System configuration parameters, integration specifications, and audit rule sets are held within the client deployment environment and are not retained by SITR beyond what is necessary to provide implementation and support services.

Website and inquiry data

Contact information and enquiry data submitted through this website (name, organisation, email, and any information voluntarily provided in enquiry messages) is collected solely for the purpose of responding to the enquiry. This data is not sold, shared with third parties, or used for marketing purposes without explicit consent.

3.4Personnel Access

Access to client environments by SITR personnel, including for implementation, configuration, or support purposes, is governed by the terms of the applicable service agreement and requires explicit authorisation from the client institution. Any such access is logged, time-limited, and conducted only for the purposes specified in the engagement documentation.

3.5Security Standards

SITR operates with security controls appropriate to a regulated financial services environment. Implementation-level security specifications are provided to client IT and security teams during the procurement and technical evaluation process. Clients are encouraged to conduct their own security assessments prior to deployment.

3.6Regulatory Compliance

SITR operates in accordance with applicable Bahraini law, including requirements applicable to technology service providers operating within the financial services sector. Client institutions are responsible for ensuring their use of SITR complies with their own regulatory obligations under CBB licensing conditions and applicable Shariah governance requirements.

3.7Data Retention

SITR does not retain client transaction data beyond the scope of an active engagement. Post-engagement data handling is defined in the applicable service agreement. Website enquiry data is retained only for the duration necessary to respond to the enquiry, unless ongoing correspondence requires otherwise.