Fusion Harbor Academia

Privacy Policy

Applicable to our websites, learning management system (LMS), and mobile applications for iOS and Android.

We respect your privacy and are committed to protecting it through our compliance with this privacy policy (“Policy”). This Policy describes the types of information we may collect from you, or that you may provide (“Personal Information”), through the Fusion Harbor Academia website at fhacademia.com and the Fusion Harbor website at fusionharbor.sa (each a “Website”), our learning management system (“LMS”), and our mobile applications for iOS and Android (the “App”), together with any related products and services such as course delivery, consultation booking, blogs, and marketing pages (collectively, the “Services”). It also describes our practices for collecting, using, maintaining, protecting, and disclosing that Personal Information, the choices available to you, and how you can access and update it.

This Policy is a legally binding agreement between you (“User”, “you” or “your”) and Fusion Harbor Academia, a brand operated by Fusion Harbor [Company — confirm full legal name and CR] (“Fusion Harbor Academia”, “we”, “us” or “our”). If you are entering into this Policy on behalf of a business, school, or other legal entity, you represent that you have the authority to bind that entity to this Policy, in which case “User”, “you” or “your” shall refer to that entity. If you do not have such authority, or you do not agree with the terms of this Policy, you must not accept it and may not access or use the Services. By accessing and using the Services, you acknowledge that you have read, understood, and agree to be bound by this Policy. This Policy does not apply to the practices of companies we do not own or control, or to individuals we do not employ or manage.

Collection of personal information

You can browse much of our Website and marketing content without telling us who you are or revealing information by which someone could identify you. To create an account, enrol in a course, book a consultation, make a purchase, or use the LMS or App, you will be asked to provide certain Personal Information. When required, this may include:

Some information we collect directly from you. We may also receive Personal Information from other sources, such as social-login providers, our partners and resellers, and third-party data providers — which may include demographic information (for example, age and gender), device information (for example, IP address and device identifiers), approximate location (for example, city and region), and online activity related to your use of the Services.

You can choose not to provide certain Personal Information, but you may then be unable to use some features of the Services. If you are unsure what information is mandatory, please contact us.

Mobile application and device information

When you use the App, we and our service providers may collect additional information specific to your mobile device in order to operate and improve the App:

Permissions the App may request

Depending on the features you use, the App may ask for your permission to access certain device capabilities. You may grant or decline these, and change them later in your device settings; declining a permission may limit related functionality:

App stores

The App is distributed through the Apple App Store and Google Play. Your download and use of the App is also subject to those platforms’ own terms and privacy practices. You can review their privacy and data-safety information via Apple and Google.

Use and processing of collected information

We act as a data controller and a data processor when handling Personal Information, unless we have entered into a data processing agreement with you, in which case you would be the data controller and we would be the data processor. We act as a controller when we determine the purposes and means of processing — for example, when we ask you to submit information necessary to access and use the Services. We act as a processor when you submit Personal Information through the Services that we process only in accordance with your instructions.

To make the Services available to you, or to meet a legal obligation, we may need to collect and use Personal Information. If you do not provide requested information, we may be unable to provide the products or services concerned. Information we collect may be used to:

Processing your Personal Information depends on how you interact with the Services and where you are located, and may rely on one or more of the following: (a) your consent; (b) performance of a contract with you or pre-contractual steps; (c) compliance with a legal obligation; (d) a task carried out in the public interest or official authority vested in us; or (e) our or a third party’s legitimate interests. We may combine or aggregate Personal Information to better serve you and improve the Services.

We rely on the following legal bases to collect and process your Personal Information:

Under some laws we may process information until you object by opting out, without relying on consent or another basis above. We are happy to clarify the specific legal basis that applies, including whether the provision of Personal Information is a statutory or contractual requirement.

Children and minors

Fusion Harbor Academia provides educational services that may be used by learners under the age of 18 (“minors”). We are committed to protecting the privacy of minors and to processing their Personal Information lawfully, fairly, and with data minimisation in mind.

Parental and guardian consent

Where a learner is a minor, registration and use of the Services require the verifiable consent of a parent or legal guardian, except where a school or institution lawfully provides that consent on the minor’s behalf. By providing consent, the parent, guardian, or institution agrees to this Policy on behalf of the minor. We may take reasonable steps to verify that the person providing consent is the minor’s parent or guardian.

Information we collect from minors

When the Services are used by a minor, we limit the information we collect to what is necessary to provide the educational service — such as account details, learning records, progress, and assessment results. We do not require a minor to provide more Personal Information than is reasonably necessary, and we do not condition participation on the disclosure of unnecessary information.

How we use minors’ information

Parental rights

A parent, guardian, or authorised institution may review the Personal Information we hold about a minor in their care, request its correction or deletion, and withdraw consent to further processing. To exercise these rights, contact us using the details at the end of this Policy; we may ask for information to verify the requester’s relationship to the minor before acting.

Jurisdiction note: where minors use the Services, additional regimes may apply — for example, COPPA for U.S. children under 13, the GDPR/UK “child’s consent” rules (ages 13–16 depending on the member state), the UK Age Appropriate Design Code, and the Saudi PDPL and its Implementing Regulations. Because age thresholds and verification requirements differ, please have this section reviewed against the specific markets FH Academia operates in.

Payment processing

For Services that require payment, you may need to provide payment-account information, which is used solely to process payments. We use third-party payment processors (“Payment Processors”) [confirm provider(s) — e.g., a licensed Saudi gateway such as Moyasar, HyperPay, PayTabs, or Tap, and/or an international processor] to handle your payment information securely. We do not store full card numbers on our own servers.

Payment Processors adhere to the security standards managed by the PCI Security Standards Council, a joint effort of brands such as Visa, Mastercard, American Express, and Discover. Sensitive data is exchanged over an SSL-secured channel, encrypted, and protected with digital signatures. We share payment data with the Payment Processors only to the extent necessary to process your payments, issue refunds, and handle related complaints and queries.

Payment Processors may collect Personal Information from you (such as your email, billing address, card details, and bank account number) to process payments through their systems. Where necessary for recurring payments and subject to your consent, your financial information may be stored in encrypted form on the Payment Processors’ secure servers. Their use of your Personal Information is governed by their own privacy policies, which we encourage you to review.

Managing information

You can delete certain Personal Information we hold about you, and the categories you can delete may change as the Services change. When you delete Personal Information, we may retain a copy of the unrevised information in our records for the period necessary to comply with our legal and contractual obligations, and for the purposes described in this Policy.

Disclosure of information

Depending on the requested Services or as necessary to complete a transaction, we may share information with trusted subsidiaries and joint-venture partners, contracted companies, and service providers (collectively, “Service Providers”) who help us operate the Services — such as cloud and LMS hosting, payment processing, communications and email delivery, analytics, and customer support — and whose privacy practices are consistent with ours or who agree to abide by our policies. We do not share information with unaffiliated third parties for their own purposes.

Service Providers are given only the information they need to perform their functions and are not authorised to use or disclose it for their own marketing or other purposes.

We may also disclose Personal Information where required or permitted by law — for example, to comply with a subpoena or similar legal process, or where we believe in good faith that disclosure is necessary to protect our rights, protect the safety of you or others, investigate fraud, or respond to a lawful government request. If we undergo a business transition, such as a merger, acquisition, or sale of assets, your account and Personal Information may be among the assets transferred.

Retention of information

We retain and use your Personal Information for the period necessary to provide the Services, enforce this Policy, resolve disputes, and meet our legal obligations — and, unless a longer period is required or permitted by law, up to a maximum of 120 months. We may retain learning records and certificates for longer where required to verify qualifications or comply with educational record-keeping obligations.

We may use aggregated data derived from your Personal Information after you update or delete it, but not in a way that identifies you personally. Once the retention period expires, Personal Information is deleted; accordingly, the rights of access, erasure, rectification, and data portability cannot be enforced after that period.

Transfer of information

Depending on your location, data transfers may involve transferring and storing your Personal Information in a country other than your own, including the Kingdom of Saudi Arabia. Where required by applicable law — including the Saudi PDPL and its rules on transfers outside the Kingdom — we will ensure that such transfers rely on an appropriate legal ground, such as your explicit consent or appropriate safeguards designed to protect your Personal Information.

You are entitled to learn about the legal basis of such transfers and the measures we take to secure your Personal Information. If you would like more detail, please refer to the relevant sections of this Policy or contact us.

Region-specific notices

Out of respect for your privacy, we have implemented additional measures to comply with the obligations and rights associated with the collection of Personal Information under the laws governing the regions of our users.

Disclosures for residents of the Kingdom of Saudi Arabia

If you are located in the Kingdom of Saudi Arabia, you have certain rights in relation to your Personal Information under the Personal Data Protection Law (“PDPL”) and its Implementing Regulations, supervised by the Saudi Data and Artificial Intelligence Authority (“SDAIA”), which we comply with as part of our commitment to your privacy. Unless otherwise stated, terms in this section have the same meaning as defined in the PDPL.

(a) Right to be informed: You have the right to be informed of the legal basis and purposes for collecting your Personal Information, and we will not use it for purposes inconsistent with those, or for which you have not been notified.

(b) Right of access: You have the right to access your Personal Information held by us, in accordance with the controls defined by the regulations.

(c) Right to obtain a copy: You have the right to obtain a copy of your Personal Information in a readable and clear format.

(d) Right to correction: You have the right to request the correction, completion, or updating of your Personal Information held by us.

(e) Right to destruction: You have the right to request the destruction of your Personal Information that is no longer needed, subject to legal retention requirements.

(f) Right to withdraw consent: Where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.

We process Personal Information in accordance with the PDPL, apply appropriate safeguards to sensitive data, and will notify SDAIA and affected individuals of personal-data breaches where required by the PDPL and its Implementing Regulations. To exercise any of these rights, contact us using the details at the end of this Policy.

Disclosures for residents of Australia

If you are a resident of Australia, you have certain rights under the Australian Privacy Act 1988 (“Privacy Act 1988”). Unless otherwise stated, terms in this section have the same meaning as defined in the Privacy Act 1988.

(a) Right to access and correct: You have the right to access the Personal Information we hold about you and to request corrections if you think it is inaccurate, out of date, incomplete, irrelevant, or misleading.

(b) Right to restrict processing: You can request that we stop or restrict processing of your Personal Information in certain circumstances, such as when you contest its accuracy.

(c) Right to data portability: You have the right to request the transfer of your Personal Information to another service provider where technically possible, or directly to you.

(d) Right not to be subject to automated decision-making: You have the right to opt out of decisions based solely on automated processing where these have legal or similarly significant effects on you.

(e) Right to anonymity: You may generally use a pseudonym or remain anonymous when interacting with us, unless certain Personal Information is required — for example, to assess your eligibility for a program. We will tell you when anonymity is not possible.

Disclosures for residents of Brazil

If you are a resident of Brazil, you have certain rights under the Brazilian General Data Protection Law (“LGPD”). Unless otherwise stated, terms in this section have the same meaning as defined in the LGPD.

(a) Right to know and access: You have the right to confirm whether we process your Personal Information and, if so, to access it.

(b) Right to correct: You have the right to correct incomplete, inaccurate, or out-of-date Personal Information.

(c) Right to anonymise and block: You can request the anonymisation or blocking of Personal Information that is unnecessary, excessive, or not processed in compliance with the LGPD.

(d) Right to data portability: You have the right to transfer your data to another service provider or product supplier.

(e) Right to delete: Where we processed your data based on consent, you can request its deletion, except where the law requires or permits us to retain it.

(f) Right to information about third parties: You can ask about the third parties with whom we share your data.

(g) Right to information on consent denial: You have the right to be informed of the consequences of denying consent.

(h) Right to withdraw consent: You can withdraw your consent for data processing at any time.

(i) Right to review automated decisions: You can request a review of decisions made solely on automated processing that significantly affect you.

Disclosures for residents of Canada

If you are a resident of Canada, you have certain rights under the Personal Information Protection and Electronic Documents Act (“PIPEDA”). Unless otherwise stated, terms in this section have the same meaning as defined in PIPEDA.

(a) Right to access: You have the right to access the Personal Information we hold about you to review, verify, or correct it.

(b) Right to correct: We will promptly make necessary corrections when you identify inaccuracies in your data.

(c) Right to withdraw consent: You can withdraw your consent at any time, subject to legal or contractual limitations.

(d) Right to complain: You have the right to file a complaint with the Privacy Commissioner of Canada.

(e) Right to challenge compliance: You can challenge our compliance with PIPEDA, including how we handle access and correction requests.

(f) Right to know about breaches: You have the right to be notified of a security breach involving your Personal Information that poses a real risk of significant harm.

Disclosures for residents of the EU/EEA and the UK

If you are a resident of the European Union (“EU”), the European Economic Area (“EEA”), or the United Kingdom (“UK”), you have certain rights under the GDPR and the UK DPA. Unless otherwise stated, terms in this section have the same meaning as defined in the GDPR and the UK DPA.

(a) Right to withdraw consent: Where the legal basis is consent, you may withdraw it at any time, without affecting the lawfulness of processing before withdrawal.

(b) Right to access: You have the right to learn whether your Personal Information is being processed, obtain disclosure about the processing, and obtain a copy of the information undergoing processing.

(c) Right to rectification: You have the right to have inaccurate information updated or corrected and incomplete information completed.

(d) Right to object: You have the right to object to processing carried out on a legal basis other than consent; where processing is for direct marketing, you may object at any time without justification.

(e) Right to restrict processing: You have the right, in certain circumstances, to restrict the processing of your Personal Information — for example, while its accuracy is verified.

(f) Right to delete: You have the right, in certain circumstances, to obtain the erasure of your Personal Information, subject to legal exceptions such as compliance with a legal obligation or the establishment or defence of legal claims.

(g) Right to data portability: You have the right to receive your Personal Information in a structured, commonly used, machine-readable format and, where technically feasible, to have it transmitted to another controller.

(h) Right to complain: You have the right to lodge a complaint with your local data protection authority if you are not satisfied with our response.

Disclosures for residents of New Zealand

If you are a resident of New Zealand, you have certain rights under New Zealand’s Privacy Act 2020 (“Privacy Act 2020”). Unless otherwise stated, terms in this section have the same meaning as defined in the Privacy Act 2020.

(a) Right to access: You have the right to access the Personal Information we hold about you.

(b) Right to correction: You have the right to request correction of incorrect or out-of-date Personal Information.

(c) Right to make a complaint: You have the right to make a complaint to a data protection authority if you believe your privacy rights have been breached.

(d) Right to object to automated decision-making: You can object to decisions made solely on automated processing that significantly affect you.

(e) Right to data portability: Where applicable, you can request the transfer of your Personal Information to another service provider or directly to you.

(f) Right to anonymity and pseudonymity: Where possible, you may interact with us without revealing your identity or by using a pseudonym.

(g) Notification of data breaches: We will notify you promptly of a data breach that may harm your privacy and take steps to mitigate the impact.

Disclosures for residents of the USA

If you are a resident of California, Colorado, Connecticut, Delaware, Iowa, Maryland, Utah, or Virginia, you have certain rights and we take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Information under the applicable state laws, including the CCPA/CPRA, CPA, CDPA, DOPPA, ICDPA, Maryland PIPA, UCPA, and VCDPA, and any regulations arising from them. Unless otherwise stated, terms in this section have the same meaning as defined in the related state laws.

In addition to the rights explained in this Policy, if you provide Personal Information to obtain Services for personal, family, or household use, you have the right to submit requests related to your Personal Information once a calendar year. There are circumstances where we may be unable to comply — for example, where we cannot verify your request or where a full response conflicts with other legal obligations — and we will notify you if so.

(a) Right to know and access: You have the right to request the specific pieces of Personal Information we hold, the categories of sources, and the purposes for collecting, selling, or sharing it, and to receive it in a portable, usable format where technically possible.

(b) Right to correct: You have the right to request correction of inaccurate Personal Information.

(c) Right to delete: You have the right to request deletion of your Personal Information.

(d) Right to opt out of sale and sharing: You have the right to opt out of the sale or sharing of your Personal Information for monetary or other valuable consideration.

(e) Right to limit sensitive information: You have the right to direct us to limit the use and disclosure of your sensitive Personal Information to what is necessary to provide the Services.

(f) Right to non-discrimination: You have the right not to be discriminated against for exercising your rights.

(g) Shine the Light: California residents with an established business relationship may ask how their personal information is disclosed to third parties for direct-marketing purposes, or opt out of such practices.

To exercise any of your rights, contact us using the details below. After we receive and verify your request, we will process it to the extent possible.

Other countries and general privacy rights

If you reside in a country not specifically mentioned, we are committed to protecting your Personal Information in accordance with internationally recognised privacy principles. You may have rights similar to those above, including:

How to exercise your rights

Any request to exercise your rights can be directed to us using the contact details in this Policy. We may ask you to verify your identity before responding. Your request must include sufficient detail for us to verify that you are the person you claim to be, or the authorised representative of that person. If a request comes from an authorised representative, we may request evidence of a power of attorney or other valid written authority. We cannot respond or provide Personal Information unless we first verify your identity or authority and confirm that the information relates to you.

Cookies

Our Website and Services use “cookies” to help personalise your online experience. A cookie is a text file placed on your device by a web-page server. Cookies cannot run programs or deliver viruses, are uniquely assigned to you, and can only be read by a web server in the domain that issued them. If you decline cookies, you may not be able to fully experience the features of the Services.

We may use cookies for security and personalisation, to operate the Services, and for statistical purposes. Most browsers accept cookies by default, but you can modify your browser settings to decline them.

Data analytics

Our Website, LMS, and App may use third-party analytics tools that use cookies, web beacons, software development kits (SDKs), or similar technologies to collect standard activity and usage information — such as how often Users access the Services, which pages or screens they view, and for how long. We use this information to monitor performance and improve the Services. We use analytics to understand aggregate behaviour and do not use these tools to associate statistical reports with an individual User’s identity beyond what is necessary to operate the Services.

Advertising and marketing

We may promote our own courses, programs, and services through our Website, social media, email, and third-party advertising platforms. To measure and improve these campaigns, we may use marketing cookies and measurement tools (such as conversion pixels and remarketing tags provided by advertising and social-media platforms) that help us show relevant information about our Services to people who have visited our Website. These tools may set cookies or use identifiers to recognise your device across sites.

We do not sell your Personal Information, and we do not deliver behavioural or targeted advertising to minors. You can control marketing cookies through your browser or device settings and through the consent options we provide, and you can opt out of marketing emails at any time using the unsubscribe link they contain. Rejecting marketing cookies does not stop you from using the Services.

If FH Academia is actually enrolled with a specific third-party advertising network or runs display ads on its blog, name the provider(s) here so the disclosure is accurate.

Do not sell my personal information

You have the right to choose not to have your Personal Information sold or disclosed by contacting us. Once we receive and verify your request, we will cease such sale or disclosure. Opting out of data transfers to third parties may affect our ability to provide certain Services you have signed up for. We reserve the right to reject opt-out requests where permitted by law, such as where a transfer is required to fulfil a legal or contractual duty. We do not sell the Personal Information of minors.

Do Not Track signals

Some browsers include a Do Not Track feature signalling that you do not want your online activity tracked. Because there is no uniform standard for how browsers communicate this signal, the Services are not currently set up to respond to Do Not Track signals. As described throughout this Policy, we limit our use and collection of your Personal Information. To learn more about the choices available to you, visit internetcookies.com.

Information security

We secure the information you provide on computer servers in a controlled, secure environment, protected against unauthorised access, use, or disclosure, and maintain reasonable administrative, technical, and physical safeguards. However, no method of transmission over the Internet or wireless network can be guaranteed.

While we strive to protect your Personal Information, you acknowledge that (a) there are security and privacy limitations of the Internet beyond our control; (b) the security, integrity, and privacy of information exchanged between you and the Services cannot be guaranteed; and (c) such information may be viewed or tampered with in transit by a third party despite best efforts. Because security also depends on the device you use and how you protect your credentials, please take appropriate measures to safeguard them.

Data breach

If we become aware that the security of the Services has been compromised, or that Users’ Personal Information has been disclosed to unrelated third parties as a result of external activity — including security attacks or fraud — we reserve the right to take reasonably appropriate measures, including investigation, reporting, and cooperation with law-enforcement authorities.

In the event of a data breach, we will make reasonable efforts to notify affected individuals where we believe there is a reasonable risk of harm, or where notice is otherwise required by law, and we may post a notice on the Website. Where required, we will also report the breach to the relevant authorities — including SDAIA in the Kingdom of Saudi Arabia — in accordance with applicable data protection regulations.

Changes and amendments

We reserve the right to modify this Policy or its terms relating to the Services at any time at our discretion. When we do, we will revise the updated date at the bottom of this page, and may provide notice in other ways, such as through the contact information you have provided.

An updated version of this Policy will be effective immediately upon posting unless otherwise specified. Your continued use of the Services after the effective date constitutes your consent to the changes. However, we will not, without your consent, use your Personal Information in a manner materially different from what was stated when it was collected.

Acceptance of this policy

You acknowledge that you have read this Policy and agree to all its terms and conditions. By accessing and using the Services and submitting your information, you agree to be bound by this Policy. If you do not agree, you are not authorised to access or use the Services.

Contacting us

If you have questions about the information we hold about you, or wish to exercise your rights, you may submit a request using our data subject request form: data subject request form [confirm whether to keep this third-party form or use a dedicated FH Academia channel].

For any other questions, concerns, or complaints regarding this Policy, contact us at: info@fusionharbor.sa [add a dedicated privacy/DPO address if available, e.g., privacy@fhacademia.com].

We will make every reasonable effort to resolve complaints and honour your rights as quickly as possible and, in any event, within the timescales provided by applicable data protection laws. If you believe your concerns have not been adequately addressed, you may escalate the matter to the appropriate data protection authority in your region — including SDAIA in the Kingdom of Saudi Arabia.

This document was last updated on June 10, 2026.