Skip to main content

Seen CRM

Information Security Policy

Document numberSEEN-POL-01
Version1.0
Effective dateOn approval
Policy ownerSeen CRM Management
Approved bySeen CRM Management
ClassificationPublic
Next reviewWithin 12 months of the effective date

1. Purpose

This policy sets out how Seen CRM protects the information its customers entrust to it, and the principles that govern all of Seen CRM's security practices.

2. Scope

This policy applies to the Seen CRM platform, the information it processes, and all personnel and service providers who support it.

3. Policy

  1. Governance. Seen CRM maintains information security policies approved by management and reviews them at least once a year.
  2. Data separation. Each customer's data is kept logically separate. No customer can access another customer's data.
  3. Access. Access is granted on a least-privilege basis. Multi-factor authentication is required for all administrative access. Access is removed promptly when it is no longer needed.
  4. Encryption. Data is encrypted in transit and at rest. Sensitive personal data receives additional field-level encryption.
  5. Secure development. Every change to the platform is reviewed and automatically tested, including security testing, before release.
  6. Monitoring. The platform is monitored continuously. Personal data is removed from system error reports.
  7. Incidents. Security incidents are handled under the Incident Response Policy. Affected customers are notified without undue delay, in line with the Personal Data Protection Law.
  8. Continuity. Data is backed up and can be restored under the Backup and Recovery Policy.
  9. Service providers. Providers that process customer data are selected and reviewed under the Vendor Management Policy.

4. Responsibilities

Management approves this policy and any exception to it. All personnel and service providers must comply with it.

5. Exceptions

Any exception must be approved in writing by management, with a stated reason and an end date.

6. Review

This policy is reviewed at least once a year, and after any major security incident.

7. Contact

Questions about this policy: info@seencrm.com

This policy describes Seen CRM's security practices and does not form part of any contract. If it conflicts with the Terms of Service or a signed agreement, the Terms of Service or the signed agreement prevail. Seen CRM may update this policy at any time; the version in force is the one published at seencrm.com.

© 2026 Seen CRM. All rights reserved. This document and its contents are the intellectual property of Seen CRM and are protected by the Copyright Protection Law of the Kingdom of Saudi Arabia and applicable international treaties. It is published for the information of Seen CRM's customers and prospective customers. No part of it may be copied, reproduced, modified, distributed or used for any other purpose without the prior written consent of Seen CRM. “Seen” and “Seen CRM” are trade names of Seen CRM.