Tadawul Market Cap: $2.9T ▲ +8.2% YoY | CMA Licensed Entities: 127 ▲ +14 in 2025 | SAMA Sandbox Participants: 43 ▲ +9 YTD | Saudi Fintech Investment: $1.2B ▲ +34% YoY | Sukuk Issuance Volume: $78.4B ▲ +12% YoY | Vision 2030 Financial Target: 24.5% GDP ▲ On Track | Digital Payment Adoption: 62% ▲ +7pp YoY | Fintech Licenses Issued: 82 ▲ +18 in 2025 | Tadawul Market Cap: $2.9T ▲ +8.2% YoY | CMA Licensed Entities: 127 ▲ +14 in 2025 | SAMA Sandbox Participants: 43 ▲ +9 YTD | Saudi Fintech Investment: $1.2B ▲ +34% YoY | Sukuk Issuance Volume: $78.4B ▲ +12% YoY | Vision 2030 Financial Target: 24.5% GDP ▲ On Track | Digital Payment Adoption: 62% ▲ +7pp YoY | Fintech Licenses Issued: 82 ▲ +18 in 2025 |

Privacy Policy


Privacy Policy

Effective date: March 20, 2026 | Last updated: March 20, 2026

Saudi Tokenisation (“we,” “us,” “the Platform”), published and operated by The Vanderbilt Portfolio AG, Zurich, Switzerland, is committed to safeguarding the privacy and personal data of every visitor to sauditokenisation.com. This Privacy Policy sets forth in comprehensive detail the types of information we collect, the purposes for which we process that information, the legal bases under which processing occurs, how we store and protect your data, and the rights available to you as a data subject. By accessing or using this Platform, you acknowledge that you have read and understood this Privacy Policy in its entirety.

Scope and Applicability

This Privacy Policy applies to all data processing activities that occur through sauditokenisation.com, encompassing our CMA framework analysis, SAMA fintech coverage, capital markets intelligence, ecosystem research, entity profiles, comparison tools, glossary definitions, contact form submissions, and newsletter subscriptions. This policy does not govern data processing by external websites linked from this Platform, including Saudi government portals such as the Capital Market Authority, SAMA, or the Saudi Data and Artificial Intelligence Authority.

Data Controller Information

The data controller responsible for processing your personal data is:

The Vanderbilt Portfolio AG Zurich, Switzerland Email: info@sauditokenisation.com

For matters specifically related to data protection, you may direct inquiries to our Data Protection Officer at the address above. Our DPO oversees compliance with the Swiss Federal Act on Data Protection (FADP), the EU General Data Protection Regulation (GDPR), and all other applicable data protection legislation.

Information We Collect

Automatically Collected Data

When you visit sauditokenisation.com, our web servers and integrated analytics tools automatically collect the following categories of technical data:

  • Device and browser information — Browser type and version (e.g., Chrome 124, Safari 17.4), operating system and version, screen resolution, device category (desktop, mobile, tablet), and preferred language settings.
  • Network information — IP address (anonymized before storage in analytics systems), internet service provider, and approximate geographic location (country and city level) derived from your IP address.
  • Browsing behavior — Pages visited, timestamps of page views, session duration, scroll depth, click interactions with navigation elements, referring URL (the page that directed you to our Platform), and exit pages. This data helps us understand how visitors navigate between our CMA framework analysis and SAMA fintech coverage, enabling editorial improvements.
  • Performance data — Page load times, error rates, and server response metrics collected to maintain Platform availability and performance.

Data Collected Through Cookies

We use cookies and related tracking technologies as described in our Cookie Policy. In summary, cookies set on this Platform include essential cookies required for site functionality, analytics cookies operated through Google Analytics 4, and advertising cookies deployed through Google AdSense. Detailed information about each cookie category, retention period, and opt-out mechanism is provided in our Cookie Policy.

Voluntarily Provided Data

We collect personal information that you choose to submit through the following channels:

  • Contact form and email — When you contact us at info@sauditokenisation.com, we collect your email address, name (if provided), and the content of your message.
  • Newsletter subscription — If you subscribe to our newsletter, we collect your email address and subscription preferences.
  • Data licensing inquiries — Institutional users who inquire about data licensing provide their name, organizational affiliation, email address, and details about their intended use.

Data We Do Not Collect

This Platform is an informational resource focused on Saudi Arabia’s broader tokenisation ecosystem — spanning CMA digital asset regulations, SAMA payment token frameworks, capital markets infrastructure, and ecosystem development. We do not facilitate investment transactions, process payments, or handle financial instruments. Accordingly, we do not collect cryptocurrency wallet addresses, financial account numbers, investment portfolio information, government-issued identification numbers, biometric data, health information, or any categories of data classified as sensitive personal data under GDPR Article 9 or the Swiss FADP.

We process your personal data under the following legal bases as defined by the GDPR and Swiss FADP:

  • Legitimate interest (Article 6(1)(f) GDPR) — Processing of automatically collected data and analytics data is necessary for our legitimate interests in maintaining Platform security, understanding audience engagement patterns, improving content quality, and optimizing the user experience. We have conducted a balancing test and determined that these interests do not override your fundamental rights and freedoms, particularly because we anonymize IP addresses and aggregate analytical data.
  • Consent (Article 6(1)(a) GDPR) — Processing of data through non-essential cookies (analytics and advertising cookies) occurs only with your prior consent, obtained through our Consent Mode v2-compliant consent banner. You may withdraw consent at any time.
  • Contractual necessity (Article 6(1)(b) GDPR) — Processing of data provided through contact forms and newsletter subscriptions is necessary to fulfill your request or to take steps at your request prior to entering into a service arrangement.
  • Legal obligation (Article 6(1)(c) GDPR) — We may process and retain certain data to comply with legal obligations, including Swiss tax law record-keeping requirements and responses to lawful government requests.

How We Use Your Information

We use the information collected for the following purposes:

  1. Platform operation and improvement — Ensuring sauditokenisation.com loads correctly, displays content properly, and functions across browsers and devices.
  2. Content development — Analyzing aggregate traffic patterns to identify which topics — whether digital riyal CBDC coverage, tokenized sukuk analysis, or GCC cooperation research — generate the most reader interest, enabling data-driven editorial decisions.
  3. Communication — Responding to inquiries submitted through info@sauditokenisation.com and delivering newsletter content to subscribers.
  4. Advertising — Displaying relevant advertisements through Google AdSense to support the free availability of our research and analysis. Google AdSense processes advertising data according to Google’s privacy policies.
  5. Security and fraud prevention — Monitoring for suspicious activity, preventing abuse, and protecting against unauthorized access.
  6. Legal compliance — Maintaining records as required by Swiss law and responding to lawful requests from authorities.

Google AdSense and Google Analytics Disclosure

This Platform uses Google AdSense to display advertisements and Google Analytics 4 (GA4) to collect website usage statistics. Both services are provided by Google LLC and its affiliates.

Google AdSense uses cookies (including the DoubleClick IDE cookie) to serve advertisements based on your browsing history across the internet. Google and its advertising partners may collect and use data about your visits to this Platform and other websites for the purpose of displaying targeted advertisements. You may opt out of personalized advertising at https://adssettings.google.com.

Google Analytics 4 collects data about page views, session behavior, user demographics (age range and interests, in aggregate only), and traffic sources. We have configured GA4 with the following privacy-protective settings: IP anonymization is enabled, data sharing with Google products is limited to analytics purposes, and data retention is set to 14 months. Google Analytics data is processed on Google servers, which may be located in the United States. Google is certified under the EU-U.S. Data Privacy Framework.

This Platform implements Google Consent Mode v2 in compliance with requirements for serving users in the European Economic Area and the United Kingdom. Consent Mode communicates your cookie consent choices to Google services through consent signals including ad_storage, analytics_storage, ad_user_data, and ad_personalization. All consent signals default to “denied” until you provide affirmative consent. When consent is denied, Google services operate in a privacy-preserving mode that does not set cookies and does not collect personally identifiable information. For full details on cookie categories and consent management, see our Cookie Policy.

Data Sharing and Third-Party Services

We do not sell your personal data to any third party. We share data with the following categories of service providers, each of which processes data under contractual data processing agreements:

  • Google LLC — Google Analytics and Google AdSense, as described above.
  • Hosting provider — Our web hosting infrastructure provider processes server logs containing IP addresses and request metadata to ensure Platform availability and performance.
  • Email service provider — Our email delivery service processes subscriber email addresses to deliver newsletter communications.

We may also disclose personal data if required to do so by law, in response to valid legal process (such as a court order or government investigation), or to protect our rights, property, or the safety of our users.

International Data Transfers

The Vanderbilt Portfolio AG is based in Zurich, Switzerland. Switzerland is recognized by the European Commission as providing an adequate level of data protection under GDPR Article 45. Where data is transferred to service providers located outside Switzerland and the EEA — including Google LLC in the United States — such transfers are protected by appropriate safeguards, including the EU-U.S. Data Privacy Framework, Standard Contractual Clauses (SCCs) approved by the European Commission, or the data importer’s binding corporate rules.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy:

  • Server logs — Retained for 90 days, then automatically deleted.
  • Google Analytics data — Retained for 14 months in accordance with our GA4 configuration settings.
  • Contact form submissions — Retained for 2 years from the date of the most recent correspondence, then deleted unless a longer retention period is required for legal or contractual purposes.
  • Newsletter subscriber data — Retained for as long as your subscription is active. Upon unsubscription, your email address is removed from our active mailing list within 30 days.
  • Advertising data — Retention periods for Google AdSense cookies are determined by Google and vary by cookie type (see our Cookie Policy for details).

Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encrypted data transmission (TLS/SSL) across the entire Platform, access controls limiting data access to authorized personnel, regular security assessments and vulnerability monitoring, and secure configuration of all third-party analytics and advertising integrations.

While we take reasonable steps to secure your data, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security but are committed to promptly addressing any data breach in accordance with GDPR Article 33 notification requirements and Swiss FADP obligations.

Your Rights Under GDPR and Swiss FADP

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under the GDPR and the Swiss Federal Act on Data Protection:

  • Right of access (Article 15 GDPR) — You may request a copy of the personal data we hold about you.
  • Right to rectification (Article 16 GDPR) — You may request correction of inaccurate personal data.
  • Right to erasure (Article 17 GDPR) — You may request deletion of your personal data, subject to legal retention obligations.
  • Right to restrict processing (Article 18 GDPR) — You may request that we limit how we process your data under certain circumstances.
  • Right to data portability (Article 20 GDPR) — You may request your personal data in a structured, commonly used, machine-readable format.
  • Right to object (Article 21 GDPR) — You may object to processing based on legitimate interests, including profiling for advertising purposes.
  • Right to withdraw consent — Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
  • Right to lodge a complaint — You may file a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or with the data protection authority in your country of residence.

To exercise any of these rights, please contact us at info@sauditokenisation.com. We will respond to your request within 30 days, or within the timeframe required by applicable law.

Your Rights Under CCPA

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with the following rights:

  • Right to know — You may request disclosure of the categories and specific pieces of personal information we have collected about you.
  • Right to delete — You may request deletion of personal information we have collected from you.
  • Right to opt out — You may opt out of the sale or sharing of personal information. Google advertising cookies may constitute “sharing” under CCPA definitions; you may opt out by declining advertising cookies or by enabling the Global Privacy Control (GPC) signal in your browser.
  • Right to non-discrimination — We will not discriminate against you for exercising your CCPA rights.

To exercise your CCPA rights, contact us at info@sauditokenisation.com or use the cookie consent mechanisms described in our Cookie Policy.

Children’s Privacy

This Platform is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have inadvertently collected personal data from a child under 16, we will take immediate steps to delete that information. If you believe a child under 16 has provided us with personal data, please contact us at info@sauditokenisation.com.

Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our data processing practices, applicable laws, or regulatory guidance. Material changes will be communicated through a prominent notice on the Platform. We encourage you to review this policy each time you visit sauditokenisation.com. The “Last updated” date at the top of this policy indicates when it was most recently revised.

Contact Us

If you have questions or concerns about this Privacy Policy, our data processing practices, or your data protection rights, please contact:

The Vanderbilt Portfolio AG Zurich, Switzerland Email: info@sauditokenisation.com

You may also review our Cookie Policy for specific information about cookie usage and our Terms of Service for the conditions governing Platform use.

Institutional Access

Coming Soon