Privacy & Data Governance Policy
aregcon ("we", "us", or "our") operates as a specialized engineering consultancy and construction technology provider across Canada, Saudi Arabia, and Pakistan. We are fundamentally committed to safeguarding the confidentiality, intellectual integrity, and privacy of all personal and enterprise telemetry data entrusted to us by mega-capital project owners, EPC contractors, and corporate stakeholders.
Information We Collect
When you interact with the aregcon portal, submit project briefings, schedule executive consultations, or submit client feedback, we may collect the following categories of data:
- Professional Identity: Full name, professional title, corporate organization, department, and contact email address.
- Project & Program Telemetry: Capital program scope, estimated project valuation bracket, timeline milestones, and engineering domain requirements (QMS, BIM, MIS, Custom R&D).
- Regional Desk Preference: Selected routing desk (Canada, Saudi Arabia, Pakistan, or Global Desk).
- Client Feedback & Review Metrics: Numerical ratings, qualitative observations, and endorsement permissions.
- Technical Metadata: Browser language preference, timestamp, and client session identifiers used solely for static site functionality.
Purpose & Lawful Basis of Processing
We process personal and project information under recognized lawful grounds, including:
- Contractual Pre-Execution & Advisory: To review submitted project parameters and prepare bilateral engineering proposals, NDAs, and executive briefings.
- Compliance with Legal & Regulatory Mandates: Adhering to government procurement, audit, and tax regulations in the Kingdom of Saudi Arabia, Canada, and Pakistan.
- Legitimate Professional Interests: Maintaining quality assurance standards, preventing unauthorized portal misuse, and continuous enhancement of our engineering software offerings.
In-Country Data Sovereignty & Security Standards
aregcon strictly adheres to the data localization and sovereign security standards prescribed by:
- Saudi Personal Data Protection Law (PDPL): Mandated by SDAIA and the National Cybersecurity Authority (NCA).
- Canadian PIPEDA: Personal Information Protection and Electronic Documents Act.
- ISO/IEC 27001 & ISO 9001: End-to-end cryptographic encryption for all technical drawings, BIM models, and audit logs.
Zero Sale or Commercial Monetization
aregcon maintains an absolute zero-monetization policy regarding user data. We do not sell, rent, lease, or trade personal information or client project parameters to third-party advertisers or data brokers under any circumstances.
Cookies & Client-Side Storage
Our web portal operates on a clean, modern static architecture. We use local browser storage (such as localStorage) strictly for:
- Remembering your selected language interface preference (English, Arabic, French, or Chinese).
- Retaining submitted consultation reference codes locally on your own device for easy reference.
- We do NOT deploy intrusive third-party cross-site advertising trackers or analytics cookies.
Your Data Subject Rights
Under applicable international data protection frameworks, you maintain the right to:
- Request confirmation of whether aregcon processes your personal or commercial consultation records.
- Request access to, rectification of, or permanent deletion of your contact records.
- Withdraw consent for technical communications or newsletter dispatches at any time.
Regional Desk & Data Protection Contacts
To exercise any data protection rights or discuss enterprise compliance frameworks, contact our regional offices: