HILIGHT ERP

Privacy Policy — HILIGHT ERP (Mobile App)

Effective date: July 24, 2026 · Applies to the HILIGHT ERP app (net.hilightsgroup.erp) · Controller: HIGHLIGHT SAUDI ARABIA EVENTS & TOURISM FESTIVALS COMPANY (Corporation, Saudi Arabia; operating the HILIGHT brand).

HILIGHT ERP is an internal, employee-only business application. It is not intended for the general public. Access requires a HILIGHT-issued account.

1. Who this app is for

HILIGHT ERP is provided and controlled by HIGHLIGHT SAUDI ARABIA EVENTS & TOURISM FESTIVALS COMPANY. It is provided to authorized HILIGHT employees to perform work tasks (projects, warehouse, attendance, custody, tasks and approvals). A valid HILIGHT account is required. Accounts are created and managed by HILIGHT HR/IT and cannot be self-registered in the app; there is no in-app account-deletion flow because there is no in-app account creation (see Section 7).

2. Data we collect and why

We collect only what is needed to operate work functions. We do not use the app for advertising and do not sell personal data.

DataPurposeNotes
Account & authentication (email or username depending on account configuration, password at sign-in, session tokens)Sign in / keep signed inThe sign-in identifier is your email or username depending on account configuration. Passwords sent to the HILIGHT ERP backend to authenticate; session tokens stored only in OS secure storage (Android Keystore / iOS Keychain).
Employee & work profile (name, HR data, documents, requests)Show profile, process requestsManaged by your employer's HILIGHT ERP system.
Precise location (foreground only)Attendance clock in/out & operational verificationCaptured only when you tap clock in/out. No background location.
Camera / imagesScan equipment QR/barcodes; capture profile photo & custody/expense documents you uploadCamera used only on scan/capture screens.
Custody & expense amounts (work-related financial information)Internal operational & accounting workflowsMonetary values of custody/expense records only. No payment-card data, no bank-account credentials, no consumer payment processing.
Push notification token & related device identifiersDeliver work notificationsVia Firebase Cloud Messaging; token sent to the HILIGHT ERP backend.
Operational data (projects, warehouse, custody, attendance, tasks, tickets, leaves, requests, notifications)Core app functionsStored in your employer's HILIGHT ERP system.

The app does not read contacts, does not access broad device storage beyond images you explicitly pick, and does not collect advertising identifiers.

3. Third-party services, analytics and logs

Firebase Cloud Messaging (Google) — used solely to deliver push notifications. No analytics or advertising: the app does not include Firebase Analytics or Crashlytics and does not use advertising analytics or IDs. Audit & security logs: for security, fraud-prevention and compliance, the backend records audit logs of user actions (create, update, delete, sign-in/out, export, send, approve) including the acting user, the affected record, an IP address and a timestamp; diagnostic/error logs may also be generated. Used for operational, security and compliance purposes only — not advertising or profiling. A device notification token (FCM / Firebase Installation ID) is collected to deliver notifications (Section 2).

4. Transmission & storage

All communication with the HILIGHT ERP backend uses HTTPS (encrypted in transit). Authentication tokens are stored only in OS secure storage. Work data is stored in your employer's HILIGHT ERP backend.

5. Retention

Data is retained only for as long as necessary for employment, operational, legal, audit, security and contractual purposes, according to HILIGHT's approved retention requirements. Device session tokens are removed on sign-out or uninstall.

6. Data sharing

We do not sell personal data and do not share it for third-party marketing. Data is processed by HILIGHT and by the provider strictly necessary to run the app (Google FCM, notifications only), and may be disclosed where required by law.

7. Your rights — access, correction, deletion (employees)

Subject to your employment relationship and Saudi law, you may request access, correction, or deletion of your data through either the designated privacy email (Section 9) or the company's authorized HR/IT administration channel. Requests are not actioned immediately; they are handled subject to legal, employment, audit, security and operational retention requirements, and only data no longer required is deleted. You may withdraw device permissions anytime in device settings.

8. Saudi PDPL

HILIGHT processes personal data under the Kingdom of Saudi Arabia's Personal Data Protection Law (PDPL) and its regulations, including a lawful basis (employment and legitimate operations), data minimization and honoring data-subject rights. Data-residency arrangements are managed by HILIGHT in line with the PDPL.

9. Contact

HIGHLIGHT SAUDI ARABIA EVENTS & TOURISM FESTIVALS COMPANY (Corporation) · Privacy email info@hilightsgroup.net · Support email info@hilightsgroup.net · Website https://hilightsgroup.net · Registered address King Fahad Road, Building 8522, Al Muhammadiyah District, Riyadh 12363, Saudi Arabia.

10. Changes

We may update this policy; the effective date reflects the latest version.