This Privacy Policy explains how Marimo Hospitality Services Co. ("Marimo", "we", "us", "our") collects, uses, shares, and protects personal data when you visit marimo.sa, request a meeting with our CEO, or otherwise interact with us through this website. We are committed to handling your information responsibly and in line with the Saudi Personal Data Protection Law (PDPL) and, where applicable, the EU/UK General Data Protection Regulation (GDPR).
1.About Marimo
Marimo Hospitality Services Co. is a hospitality services company registered in the Kingdom of Saudi Arabia. For the purposes of this website, Marimo is the "data controller" of any personal data you provide. Marimo Hotels Ltd, an affiliated entity registered in the United Kingdom, may receive limited personal data in the course of group operations.
2.Information we collect
2.1 Information you provide directly
- Your name, email address, phone number, and any context you choose to share when requesting a meeting through our Calendly booking widget.
- Any message content if you contact us by email.
2.2 Information collected automatically
- Standard log data — IP address, browser type, device type, referring URL, pages viewed, and time spent on the site.
- Analytics data via Google Analytics (only if you accept analytics cookies).
3.Cookies and similar technologies
We use a small number of cookies and similar technologies on this site:
- Strictly necessary cookies — required for the site to function. These are always on.
- Analytics cookies (Google Analytics) — used to understand how visitors use our pages. These load only if you accept them via our cookie banner.
- Third-party cookies from Calendly may be set when you interact with the booking widget, in line with Calendly's own policies.
You can change your cookie preferences at any time by clearing your browser's storage for this site, which will cause the cookie banner to reappear.
4.How we use your information
We use the information we collect to:
- Schedule and confirm meeting requests with our CEO.
- Respond to your enquiries and communications.
- Operate, maintain, and improve the website.
- Understand aggregate visitor behaviour through analytics (consent-based only).
- Comply with our legal obligations.
5.Legal basis for processing
Where the GDPR or comparable laws apply, we rely on the following legal bases:
- Consent — for analytics cookies and for any optional information you choose to provide.
- Legitimate interests — to operate the site, respond to enquiries, and protect against fraud or misuse.
- Contract — to perform the meeting or service you have requested.
- Legal obligation — where we are required to retain or disclose information by law.
6.Sharing with third parties
We share limited personal data with the following service providers, each of whom processes data on our behalf or as an independent controller:
- Amazon Web Services (AWS) — website hosting (Amplify, Route 53).
- Google Analytics — visitor analytics (consent-based).
- Calendly — meeting scheduling and reminders.
- Microsoft 365 — business email and calendar.
We do not sell your personal data, and we do not share it with advertisers.
7.International data transfers
Some of our service providers store and process data outside the Kingdom of Saudi Arabia, including in the European Union, the United Kingdom, and the United States. Where personal data is transferred outside the KSA, we rely on the relevant providers' appropriate safeguards (such as Standard Contractual Clauses or equivalent mechanisms) and the requirements of the Saudi PDPL governing cross-border transfers.
8.Data retention
We retain personal data only for as long as needed for the purpose for which it was collected:
- Meeting booking records: up to 24 months from the date of the booking.
- Email correspondence: as long as needed to handle the matter, then archived in line with our internal retention schedule.
- Analytics data: as governed by Google Analytics retention settings (default 14 months).
9.Your rights
Depending on your location, you may have the following rights regarding your personal data:
- Right to access the personal data we hold about you.
- Right to correct inaccurate personal data.
- Right to request deletion of your personal data, subject to legal exceptions.
- Right to object to or restrict certain processing.
- Right to withdraw consent at any time, where processing is based on consent.
- Right to data portability, where applicable.
- Right to lodge a complaint with the Saudi Data & AI Authority (SDAIA) or another competent supervisory authority.
To exercise any of these rights, please contact us using the details in Section 14.
10.Security
We take reasonable technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, or alteration. This includes HTTPS encryption in transit, access controls on our administrative tools, and reliance on reputable cloud providers with established security practices. However, no method of transmission or storage over the internet is completely secure.
11.Children's privacy
This website is not directed at children under the age of 13, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
12.Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. The "Effective date" at the top of this page indicates when it was last updated. Material changes will be highlighted on the website.
13.Governing law
This Privacy Policy is governed by the laws of the Kingdom of Saudi Arabia, including the Personal Data Protection Law (PDPL) and its implementing regulations. Any dispute arising under or in connection with this Policy shall be subject to the exclusive jurisdiction of the competent courts in Riyadh, Saudi Arabia.
14.Contact us
For any questions about this Privacy Policy, or to exercise any of the rights above, please contact us: