Privacy Policy
This Privacy Policy describes how SITR W.L.L.(“SITR”, “we”, “us”, or “our”) handles data in connection with the platform.
3.1Introduction
This Privacy Policy is intended to inform prospective and current client institutions, their technology teams, and relevant regulators about our data practices.
SITR is an enterprise infrastructure platform deployed within or connected to client environments. The scope, ownership, and handling of data differs significantly from consumer software and is addressed in detail below.
3.2Deployment Architecture and Data Residency
On-premise deployment
Where SITR is deployed on-premise within the client’s own infrastructure, all transaction data processed by the platform remains within the client’s environment at all times. SITR does not have access to, does not store, and does not transmit client transaction data to external systems in this configuration.
Hosted or hybrid configurations
Where a hosted or hybrid configuration is agreed upon in writing, data handling, storage locations, and access rights are defined in the applicable Data Processing Agreement (DPA) executed between SITR and the client institution prior to deployment.
No default data transmission
By default, SITR does not transmit any transaction data, customer data, or institution-specific configuration data to SITR systems or third-party services. This applies to all deployment configurations unless explicitly agreed otherwise in writing.
3.3Categories of Data
Client institution data
Transaction records, account identifiers, product configurations, and Shariah rule mappings provided by or generated on behalf of the client institution are treated as the exclusive property of the client institution. SITR claims no ownership or independent right to use this data.
Platform configuration data
System configuration parameters, integration specifications, and audit rule sets are held within the client deployment environment and are not retained by SITR beyond what is necessary to provide implementation and support services.
Website and inquiry data
Contact information and enquiry data submitted through this website (name, organisation, email, and any information voluntarily provided in enquiry messages) is collected solely for the purpose of responding to the enquiry. This data is not sold, shared with third parties, or used for marketing purposes without explicit consent.
3.4Personnel Access
Access to client environments by SITR personnel, including for implementation, configuration, or support purposes, is governed by the terms of the applicable service agreement and requires explicit authorisation from the client institution. Any such access is logged, time-limited, and conducted only for the purposes specified in the engagement documentation.
3.5Security Standards
SITR operates with security controls appropriate to a regulated financial services environment. Implementation-level security specifications are provided to client IT and security teams during the procurement and technical evaluation process. Clients are encouraged to conduct their own security assessments prior to deployment.
3.6Regulatory Compliance
SITR operates in accordance with applicable Bahraini law, including requirements applicable to technology service providers operating within the financial services sector. Client institutions are responsible for ensuring their use of SITR complies with their own regulatory obligations under CBB licensing conditions and applicable Shariah governance requirements.
3.7Data Retention
SITR does not retain client transaction data beyond the scope of an active engagement. Post-engagement data handling is defined in the applicable service agreement. Website enquiry data is retained only for the duration necessary to respond to the enquiry, unless ongoing correspondence requires otherwise.