Green Tower Trading is committed to handling personal data lawfully, fairly, transparently, and only for defined purposes. This policy explains our practices when you visit this website, use its published contact details, or otherwise communicate with us in connection with the site.
1. Scope and interpretation
This policy applies to visitors to the Green Tower Trading website and individuals who contact our team through the telephone number, email address, postal address, map link, or social-media link published here. “Personal data” means information relating to an identified or identifiable individual under the Saudi Personal Data Protection Law and, where applicable, the EU General Data Protection Regulation or another mandatory data-protection law.
This policy does not replace a separate privacy notice that may apply to employees, suppliers, distributors, customers, or other established business relationships. Where a more specific notice is provided, that notice governs the processing it describes.
2. Data controller and contact details
Green Tower Trading determines the purposes and means of the processing described in this policy. Questions, objections, and privacy requests may be sent to info@makroyalfoods.com, made by telephone at 920007884, or delivered by post to 4503 Abi Al Qasim Al Harbi, Al-Masani, 6461, Riyadh 14714.
3. Personal data we may process
The categories processed depend on how you interact with us and may include:
- Website and device data: IP address, browser and device type, operating system, requested page, referrer, approximate location, timestamps, response status, and technical or security logs generated when the website is delivered;
- Basic cookieless measurement: page views and exits, page path, and limited technical context held in browser memory only for the current page request, without a stable visitor identifier;
- Consented analytics data: anonymous visitor and session identifiers, navigation, scroll milestones, catalogue filter use, high-level search usage, performance measurements, outbound destination domains, contact-channel selection, and browser errors;
- Communications data: your name, employer or organization, business contact details, message, enquiry history, and information you voluntarily provide when contacting us; and
- Preference and compliance data: your cookie selection, notice version, request history, and records reasonably required to demonstrate compliance with legal obligations.
The public website has no customer account, public upload facility, payment function, or contact-form database. We do not send product-search wording, email addresses, telephone numbers, or message content to our analytics provider.
4. Sources of personal data
We obtain data directly from you when you communicate with us, automatically from your browser and hosting infrastructure when a page is requested, and from optional persistent analytics only after acceptance. We may also receive business contact information from an organization you represent or from a lawful public business source where relevant to an enquiry.
5. Purposes and lawful grounds
We process personal data only where a lawful ground applies and only to the extent reasonably necessary to:
- provide, secure, maintain, troubleshoot, and improve the website and its content delivery;
- maintain aggregate page-traffic and availability statistics without browser persistence;
- respond to enquiries and take steps requested before a business contract;
- measure navigation and catalogue engagement after consent to optional analytics;
- prevent abuse, protect our rights and systems, and establish, exercise, or defend legal claims; and
- comply with applicable legal, regulatory, accounting, tax, and lawful authority requirements.
Optional persistent analytics relies on consent. Essential website delivery, security, and minimal aggregate page measurement rely on our legitimate interest in operating a secure and effective corporate website where that ground is permitted, balanced against visitor privacy through memory-only measurement, IP anonymization, and data minimization. Enquiry handling may be necessary to take pre-contractual steps at your request or to perform a contract. Where consent applies, it may be withdrawn without affecting earlier lawful processing.
6. Cookies and browser storage
Cookies are small text files stored by a browser. Basic aggregate page counting operates without cookies, local storage, or a stable cross-page identifier. The website uses one necessary preference cookie and, following acceptance, limited first-party cookie and local-storage identifiers for enhanced PostHog analytics. Rejecting optional analytics does not restrict access to any public page or feature.
| Type | Purpose | Category | Duration |
|---|---|---|---|
| Cookie preference | Remembers the selected analytics preference and notice version. | Necessary | 180 days |
| Anonymous analytics identifier | Connects consented activity into an anonymous visit and session for enhanced analytics. | Optional analytics | Up to 180 days |
Following acceptance, enhanced analytics measures navigation and contact-link use, catalogue filtering, scroll depth, performance, and browser errors. IP anonymization is enabled, person profiles are not created, full URLs are stripped of query strings, and session recording is disabled. Product-search wording is not collected.
You may change the choice at any time. Rejecting after acceptance stops enhanced analytics and removes its stored identifiers from that browser. Basic memory-only page counting continues without persistent storage. Browser controls may also delete cookies, although deleting the preference cookie may show the notice again.
7. Service providers and recipients
Netlify provides static hosting, content delivery, and technical security logging. PostHog provides analytics through its EU Cloud service and processes the limited technical and usage data sent by the website. Email, telephone, maps, and social-media services process information when you choose their links. Professional advisers, auditors, insurers, authorities, or courts may receive information where reasonably necessary and legally permitted.
We do not sell personal data, rent visitor lists, or permit analytics data to be used for independent direct marketing. We do not use website analytics to make decisions producing legal or similarly significant effects about visitors.
8. International processing
Internet and cloud services may process information in Saudi Arabia, the European Economic Area, the United States, and other provider locations. Where personal data is transferred across a national boundary, we use contractual, organizational, and technical safeguards required by applicable law, taking account of the information, destination, and provider involved.
9. Retention and destruction
We retain personal data only for the period necessary for its purpose and applicable legal, accounting, security, or dispute requirements. Analytics event data is normally retained for up to 12 months. The consent preference and optional analytics identifiers last up to 180 days. Hosting and security logs follow provider operational and security schedules.
Enquiry and business correspondence is kept as reasonably necessary to answer the enquiry, administer a relationship, and meet legal or evidentiary requirements. When retention is no longer justified, information is deleted, securely destroyed, or irreversibly anonymized, subject to backup cycles and lawful preservation.
10. Security and incident handling
Safeguards include encrypted transport, restricted administrative access, a static public architecture without visitor accounts or a public database, provider security controls, dependency maintenance, change tracking, and backup and rollback procedures. Access is limited to personnel and providers with a legitimate need. No internet transmission or storage system can be guaranteed absolutely secure.
Suspected personal-data incidents are assessed, contained, documented, and notified to affected individuals or competent authorities where notification is required by applicable law.
11. Your rights
Subject to applicable conditions and exceptions, you may have the right to:
- be informed about processing and request access to or a readable copy of your personal data;
- correct incomplete, inaccurate, or outdated information;
- request deletion or destruction when the legal conditions apply;
- restrict or object to certain processing and request data portability where applicable;
- withdraw consent as easily as it was given; and
- complain to the Saudi Data and Artificial Intelligence Authority or another competent authority.
Requests should be sent to info@makroyalfoods.com. We may request proportionate information to verify identity, authority, and scope. We will respond within the period required by applicable law and explain any lawful limitation or refusal.
12. Children and external websites
This corporate information website is not directed to children, and we do not knowingly solicit their data. External map, social-media, email, and other links are controlled by their respective operators; their privacy terms apply after you leave this website.
13. Complaints and policy changes
Please contact us first so we can investigate a concern. This does not limit any right to complain to the Saudi Data and Artificial Intelligence Authority or another competent supervisory authority. We may amend this policy for changes in law, providers, technology, or operations. The current version is identified by the date above, and a material change to consented processing will trigger a new choice where legally required.