Privacy notice
How Arabian Energy Company handles personal data. Effective 1 July 2026.
This notice covers arabiaen.com and AEC Nexus, the company’s internal platform. It is written to be read rather than to be defensible, and it describes what the systems actually do.
Who is responsible
Arabian Energy Company is the controller of the personal data described here. Enquiries about this notice, including requests to exercise the rights below, should go through the contact page marked for the attention of the data protection contact.
What we collect, and why
If you send us an enquiry
We store your name, email address, the organisation you gave, the category you chose and the message itself, along with the IP address and browser the message arrived from. We use this to reply to you and to keep a record that the enquiry was received and answered. The lawful basis is our legitimate interest in operating the business and responding to people who contact us.
If you hold an account on AEC Nexus
Accounts are created by an administrator; there is no self-registration. We hold your name, work email, username, role, and the profile details you or your administrator enter — position, department, office, telephone, disciplines, geographies, approval limit and biography.
For security we hold a hashed form of your password (never the password itself), your authenticator secret, hashed session tokens, sign-in timestamps, IP addresses and browser strings, and the record of failed attempts and lockouts. The lawful basis is performance of your contract of employment or engagement, and our legitimate interest in securing a system that holds commercially sensitive material.
Activity records
Every change made in the platform is written to a tamper-evident audit log, recording who made it, what changed, and when. These records exist so that decisions involving substantial capital can be reconstructed and audited. They cannot be edited or selectively deleted by design — the log is hash-chained, so removing an entry breaks verification of everything after it. This is a deliberate constraint, and it limits what we can do in response to an erasure request over audit data specifically.
Cookies
The public site sets no cookies and runs no analytics or advertising trackers. The platform sets exactly one cookie, aec_session, which holds an opaque session token. It is strictly necessary for signing in, is marked HttpOnly, Secure and SameSite, and carries no profiling information. There is no consent banner because there is nothing to consent to.
Who we share it with
We do not sell personal data and we do not share it for advertising. We share it only with:
- Infrastructure providers hosting the application and its database, under contract
- Our email delivery provider, for the messages we send you
- Professional advisers where necessary for a transaction, under confidentiality
- Regulators and auditors where we are legally required to
Where a feature sends text to an artificial intelligence provider for analysis, that is stated at the point of use and is limited to the material the feature is analysing. Personnel records are never sent.
How long we keep it
- Website enquiries
- Two years from the last contact, unless the enquiry becomes a business relationship.
- Account and profile records
- For the duration of the account, then seven years, to meet audit and corporate record obligations.
- Session records
- Sessions expire after twelve days, or twelve hours of inactivity; the records are pruned after ninety days.
- Audit records
- Retained for the statutory record-keeping period. They are not deleted selectively.
Your rights
Subject to the applicable law, you may ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to erase it, object to processing based on legitimate interests, or ask us to restrict processing while a dispute is resolved. We will respond within one month.
Where we cannot fully honour a request — most commonly erasure of audit records — we will tell you which data is affected and why, rather than declining in general terms.
Security
Passwords are hashed with a memory-hard function and a per-user salt. Multi-factor authentication is mandatory for every account. Sessions are opaque server-side tokens rather than self-describing ones, so a stolen cookie can be revoked immediately and centrally. Access is granted by role, and the interface hiding an action is never the only thing preventing it — every action is checked again on the server.
Changes
If this notice changes materially we will say so on this page and date the change. This version is effective 1 July 2026.
