Privacy Notice
Last updated: 22 June 2026
Introduction
webook.com (“webook”, “Halayalla”, “we”, “us”, or “our”, referred to as “webook”) operates a digital super app designed for sports, entertainment, culture, communities, and related experiences. Through one integrated platform, webook enables users to discover activities around them, connect with others, and access a wide range of entertainment and lifestyle services.
We respect your privacy and maintaining your trust is our priority. We are committed to protecting your personal data in line with applicable data protection laws, including (as relevant):
- European Union General Data Protection Regulation (EU) 2016/679 (GDPR)
- UK GDPR and Data Protection Act 2018
- Kingdom of Saudi Arabia’s Personal Data Protection Law (PDPL)
- UAE’s Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL)
- Law No. 09-08 of Morocco on the Protection of Individuals with Regard to the Processing of Personal Data
- Personal Data Protection Law No. 24 of 2023 of Jordan
- Bahrain’s Personal Data Protection Law (PDPL)
- Law No. 13 of 2016 concerning Personal Data Privacy and Protection of Qatar
This Privacy Notice explains how we collect, use, disclose, store, and safeguard your personal data when you visit our website, create an account, purchase tickets, book events, or otherwise interact with our services.
Where local data protection laws impose additional or different requirements, the Jurisdiction-Specific Addendum applicable to your location supplements this Notice and prevails in the event of conflict.
Identity of Controller
Hala Yalla for Information Technology Co. (Saudi Arabia), a company incorporated in the Kingdom of Saudi Arabia with its registered address at “Floor 1, Building No. 4162, Abi Alasbat Street, Al Olaya District, Riyadh, Kingdom of Saudi Arabia, 12311”, is the parent company of the group (“Group”, “we”, “us”, “our”), and includes webook and other affiliated entities.
Depending on your location and the services you use, the relevant Group entity that provides services to you and determines the purposes and means of processing your personal data acts as the data controller.
The controller is typically the entity with which you contract, create an account, or purchase services.
Where two or more Group entities jointly determine the purposes and means of processing, they act as joint controllers in accordance with applicable law.
Further information about the relevant Group entities and their roles may be made available to you at the point of data collection or upon request.
When We Act as a Processor
In certain circumstances, such as when we provide ticketing, technology, or event management services to event organizers, corporate customers, or business partners, we may process personal data strictly on their behalf.
In such cases, we act as a data processor and the relevant customer or partner acts as the data controller. The privacy notice of that controller governs the processing of your personal data. We encourage you to review their privacy notice for further information.
Information We Collect
We may collect and process the following categories of personal data, depending on how you interact with us:
- Personal Identification Information
- Name, email address, phone number, billing address, and other contact details. In limited cases and where strictly necessary, we may collect additional details such as date of birth, gender, nationality, or identification information (e.g., passport or ID details).
- Payment Information
- Payment method, billing address, and transaction history. Payments are processed securely by third-party payment service providers. We do not store full credit or debit card numbers.
- Account and Booking Information
- Account credentials, booking history, ticket details, preferences, and special requests.
- Technical Data
- IP address, browser type and version, time zone setting, operating system, device identifiers, and related technical data.
- Usage Data
- Information about how you use our website and services, including pages viewed and interaction data. Information collected through cookies is governed by our Cookie Notice.
- Marketing and Communications Data
- Preferences in receiving marketing communications, responses to surveys, and engagement with promotional activities.
- Location Data
- Approximate geographic location derived from your device or IP address.
- Social Media Data
- Information you choose to share when interacting with us via social media platforms, subject to those platforms’ privacy settings.
- Interaction Data
- Records of communications with us, including customer support interactions.
- User Generated Data
- Reviews, feedback, ratings, comments, and other content voluntarily submitted.
- Legal and Compliance Data
- Information required to comply with legal obligations, detect fraud, resolve disputes, or enforce our terms.
Certain data may qualify as sensitive or special category data under applicable laws, such as government issued identification information (e.g., passport or national ID details) or other data required for regulatory or legal compliance purposes.
We process such data only where strictly necessary and where permitted under applicable laws. This includes, where required, obtaining your explicit consent or relying on other lawful bases permitted under applicable regulations. For example, under the Saudi Personal Data Protection Law (PDPL), processing of sensitive data is carried out on your explicit consent in accordance with Article 6 and other applicable provisions.
Such data is subject to enhanced safeguards, including restricted role-based access controls, encryption in transit and at rest, data minimization, segregation of sensitive datasets, enhanced monitoring and logging of access, and restricted retention periods.
Children’s Data
Our services may be accessed by individuals of different age groups, including children, subject to applicable legal requirements. The age at which a child may provide valid consent for the processing of their personal data varies by jurisdiction.
In the European Economic Area and the United Kingdom, parental or guardian consent is required for children below the applicable digital age of consent (which is 16 years, or lower where permitted by Member State law, but not below 13).
In jurisdictions such as the Kingdom of Saudi Arabia, United Arab Emirates, Qatar, Bahrain, Jordan, and Morocco, parental or guardian consent is typically required for the collection and processing of personal data relating to minors, typically individuals under the age of 18 years, subject to applicable laws.
Where required under applicable law, we rely on parental or guardian consent for the collection and processing of personal data relating to children.
If we become aware that personal data has been collected from a child without the required consent, we will take necessary steps to delete such data as soon as reasonably practicable.
If you believe that a child has provided personal data without appropriate authorization, please contact us so that we can take appropriate action.
How We Collect Your Information
We collect data through various methods, depending on how you interact with our website and services:
- Direct Interactions
- When you provide your personal data directly to us, such as creating an account, filling in forms, booking services, submitting reviews or feedback, participating in surveys or promotions, or communicating with us through customer support or other channels.
- Automated Technologies
- When you access and use our website, we may automatically collect certain technical and usage data through server logs and similar technologies. Information collected through cookies, or similar technologies is subject to your preferences and applicable consent requirements and is detailed in our Cookie Notice.
- Third Parties or Publicly Available Data Sources
- We may receive personal data from third parties, where permitted by applicable law, such as analytics providers, advertising or marketing partners, payment service providers, search information providers, social media platforms (including when you choose to log in or interact with us through such platforms), and publicly available sources.
- Third-Party Links and Embedded Content
- Our website may contain links to third-party websites or embedded content (such as videos, images or social media features). These third-parties may collect personal data independently of us and in accordance with their own privacy notices. We are not responsible for the privacy practices or content of such third-party websites or services.
How We Use Your Information and Legal Basis for Processing
We use your personal data only for specified, explicit and legitimate purposes for which it was originally collected, and in a manner compatible with applicable data protection laws. Where required by law, we rely on your consent or other legal basis. If we intend to use your personal data for a new purpose that is incompatible with the original purpose, we will notify you and, where required, obtain your consent or identify an appropriate legal basis that authorizes such use.
Where required, we rely on:
Performance of a Contract
- Account creation and management
- Booking processing and ticket issuance
- Payment processing and refunds
- Transactional communications
Legal Obligations
- Financial and tax compliance
- Regulatory reporting
- Responding to lawful authority requests
Legitimate Interests (Where Permitted)
- Customer support and service improvement
- Fraud prevention and system security
- Business analytics and operational improvement
- Non-intrusive personalization
- Establishing or defending legal claims
Where legitimate interests apply, we conduct appropriate assessments to ensure our interests do not override your rights.
In jurisdictions where legitimate interests are not recognized as an independent lawful basis (such as the Kingdom of Saudi Arabia), processing is carried out based on consent or another lawful ground permitted under applicable law.
Consent (Where Required)
- Marketing communications
- Optional surveys
- Analytics or marketing cookies
You may withdraw consent at any time.
We do not carry out automated decision-making that produces legal or similarly significant effects.
How We Share Your Information
We may share your personal data with the following categories of recipients, where necessary and in accordance with applicable data protection laws. All sharing is subject to contractual safeguards and confidentiality obligations.
- Service Providers (Processors)
- Third-party service providers who perform services on our behalf, such as but not limited to IT, payment processing, analytics, marketing, security services and customer service support. These providers are authorized to process personal data only in accordance with our instructions and are subject to appropriate contractual and confidentiality obligations.
- Business Partners
- Partners involved in delivery of our services, such as event organizers, cinema operators, and fulfillment agencies or logistics providers. Depending on the context, these partners may act as independent data controllers, as they determine how and why your personal data is processed for the purpose of delivering their services and complying with their legal obligations. For example, event organizers or venue operators may use attendee information to manage access, safety, and compliance at their venues and therefore act as independent controllers.
- Law Enforcement, Legal and Regulatory Authorities
- Government bodies, regulatory authorities, courts or law enforcement agencies where disclosure is required by applicable law, regulation, legal process, or to protect our legal interests, or to establish, exercise or defend legal claims.
- Corporate Transactions
- In the event of a merger, acquisition, reorganization, or sale of assets, or similar corporate transaction, your personal data may be shared with prospective or actual counterparties and their advisors, subject to appropriate confidentiality and data protection safeguards.
- Third-Party Links and Embedded Content
- Our website may include links to third-party websites or embedded content (such as videos or social media features). These third parties may collect personal data independently of us and in accordance with their own privacy notices. We are not responsible for their privacy practices.
International Data Transfer
Your personal data may be transferred to, stored, and processed in countries outside your country of residence, including jurisdictions that may not provide the same level of data protection as your home country. Where such transfers occur, we ensure that they are carried out in accordance with applicable data protection laws and are subject to appropriate safeguards.
These safeguards include:
- Adequacy decisions, i.e. transfers to countries that are recognized as providing an adequate level of data protection under applicable laws;
- Standard Contractual Clauses or contractual safeguards designed to protect personal data;
- Intra-group data transfer agreements;
- Regulatory approvals where required or notifications, where required under applicable law; and
- Other lawful transfer mechanisms permitted under applicable data protection regulations.
For transfers originating from the Kingdom of Saudi Arabia, personal data is transferred only in accordance with Article 29 of the PDPL and its Implementing Regulations.
You may request further details regarding safeguards.
How We Protect Your Information
We implement appropriate technical and organizational measures designed to protect your personal data against unauthorized access, alteration, disclosure, loss, or destruction. These measures are implemented taking into account the nature of personal data, the purposes of processing, and the risks involved. These may include, as appropriate, encryption, secure servers, firewall protections, access controls, and regular security monitoring and reviews. We also limit access to personal data to authorized personnel and service providers who require such access for legitimate business purposes and who are subject to confidentiality obligations. Where sensitive or special category data is processed, we apply additional safeguards such as enhanced access restrictions, stronger encryption standards, data segregation, increased monitoring of access and processing activities, and stricter retention and deletion controls, in line with applicable legal and regulatory requirements.
While we are committed to protecting your personal data and take reasonable and appropriate measures to do so, no method of transmission over the internet or electronic storage is completely secure.
Data Retention
We retain your personal data only for as long as is necessary to fulfill the purposes for which it was collected, including to meet legal, regulatory, accounting, reporting, or business requirements. The retention period may vary depending on the nature of data, purpose of processing and the applicable legal obligations.
Where possible, we apply the following standard retention periods:
| Category of Personal Data | Purpose of Processing | Retention Period |
|---|---|---|
| User account data (e.g., first name, last name, email) | Account management and authentication | Duration of the account; deleted after 24 months of inactivity or upon account deletion (based on last login) |
| Ticket orders and booking records | Legal, accounting and transactional management | Up to 10 years from the end of the relevant fiscal year; thereafter anonymized |
| Payment transaction metadata | Payment reconciliation, audits and financial compliance | Up to 10 years from the end of the relevant fiscal year; thereafter anonymized |
| Marketing contact details (email, phone number, preferences) | Marketing communications and preference management | Until you unsubscribe or withdraw consent; thereafter retained on a suppression list |
| Analytics data | Product analytics and service improvement | Up to 24 months from the date of collection |
| Security logs | Security monitoring and incident response | Up to 12 months from log creation |
| Marketing consent records | Demonstrate compliance with consent management | Up to 5 years after withdrawal of consent |
| Customer support communications | Handling enquiries, disputes, and service quality improvement | Up to 3 years from closure of the request |
| Event operations data (e.g., attendance, ticket scans) | For event management and operations | Up to 90 days after the relevant event |
We retain personal data for these periods for legitimate business purposes, including responding to enquiries or complaints, maintaining appropriate records, and verifying your identity when you contact us.
In certain circumstances, personal data may need to be retained for longer periods where required or permitted by applicable law. This may include, for example, retaining contact details, correspondence, complaints, or related records to comply with regulatory requirements, demonstrate compliance with data protection laws (such as handling data subject rights requests), or to establish, exercise, or defend legal claims within applicable statutory limitation periods.
When personal data is no longer required for the purposes for which it was collected, and there is no legal or regulatory requirement to retain it, we will securely delete, anonymize, or otherwise dispose of it in accordance with our data retention policies.
Data Storage
Your personal data may be stored and processed in secure data centers located in one or more jurisdictions where we or our service providers operate.
Where personal data is transferred or accessed across borders, we ensure that appropriate safeguards are implemented in accordance with applicable data protection laws and regulatory requirements.
Your Rights
Applicable data protection laws across jurisdictions of our operations, including but not limited to the EU GDPR, UK GDPR, KSA PDPL, UAE Federal PDPL, Jordan PDPL No. 24/2023, Morocco Law 09-08 and Bahrain PDPL, grant individuals (“Data Subjects”) certain rights in relation to their personal data.
Requests to exercise these rights are commonly referred to as Data Subject Requests (DSRs).
Not all rights are absolute. Their applicability depends on factors such as the legal basis for processing, statutory obligations, public interest considerations, or exemptions under applicable local laws.
The rights available to you may include the following, subject to jurisdictional applicability as set out in the Jurisdiction-Specific Addendum:
- Right of Access
- You have the right to request confirmation as to whether we process your personal data and, where applicable, to obtain access to such personal data together with supplementary information regarding its processing.
- Right to Be Informed
- You have the right to be informed about how your personal data is collected and used, including the purposes of processing, retention periods, and categories of recipients. This Privacy Notice is intended to satisfy that obligation.
- Right to Rectification
- You have the right to request correction of inaccurate personal data and completion of incomplete personal data.
- Right to Erasure or Deletion
- You have the right to request deletion of your personal data in certain circumstances, for example where the data is no longer necessary for the purposes for which it was collected. This right is subject to statutory exceptions, including legal retention obligations and legitimate legal claims.
- Right to Restriction of Processing
- In certain jurisdictions, you may have the right to request restriction or suspension of processing of your personal data under specific conditions, such as where you contest its accuracy or the lawfulness of processing.
- Right to Data Portability
- Where provided under applicable law and where processing is based on consent or contract and carried out by automated means, you may have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format and to request transmission to another controller, where technically feasible.
- Right to Object
- You may have the right to object to certain types of processing, including processing based on legitimate interests. You have an absolute right to object to the processing of your personal data for direct marketing purposes.
- Rights Related to Automated Decision-Making
- Where applicable law provides, you may have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal or similarly significant effects, and to request human intervention.
- Marketing & Profiling Controls
- You may opt out of marketing communications at any time by using the unsubscribe mechanism included in communications or by contacting us directly.
- Right to Lodge a Complaint
- You have the right to raise concerns regarding our data handling practices.
You may:
- Visit our Help Center;
- Contact our Data Protection Officer (DPO) at [email protected];
- Lodge a complaint with the competent data protection supervisory authority in your jurisdiction, as identified in the Jurisdiction-Specific Addendum.
Where provided by applicable law, you may also pursue legal remedies in respect of violations of your data protection rights.
To exercise your rights, please visit our Help Center.
We aim to respond to all valid requests within one month, in line with widely applicable data protection standards.
In certain jurisdictions, shorter response timeframes may apply (for example, 30 days under the laws of the Kingdom of Saudi Arabia). Where such requirements apply, we will comply with the applicable timeframe.
Where permitted by law, this period may be extended in complex cases, in which case we will notify you accordingly.
Personal Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within the timeframes required by applicable law (typically within 72 hours).
Where the breach is likely to result in a high risk to you, we will also notify you directly, unless an exemption applies under applicable law.
We maintain internal incident response procedures to ensure timely detection, investigation, and remediation of such incidents.
Data Protection Officer (DPO)
We have appointed a Data Protection Officer (DPO) responsible for overseeing compliance with applicable data protection laws and this Privacy Notice across the jurisdictions in which we operate.
The DPO is responsible for informing and advising the organization on its data protection obligations, monitoring compliance with applicable data protection laws and internal policies, and providing guidance on data protection impact assessments where required. The DPO also cooperates with relevant supervisory or regulatory authorities and acts as a point of contact for data subjects and regulators on matters relating to the processing of personal data.
The DPO operates independently and is supported by appropriate resources to carry out these responsibilities.
You may contact our DPO for any questions, concerns, or requests relating to this Privacy Notice or the processing of your personal data at: [email protected].
Cookies
We use cookies and similar technologies. Please refer to our Cookie Notice for further information.
Changes to this Notice
We may update this Notice periodically. Updates will be published on our website with a revised “Last Updated” date.
Contact Us
For any queries, complaints or information regarding this Notice, you may contact us at [email protected].
Jurisdiction-Specific Annexure
| Jurisdiction | Applicable Law | Additional / Specific Rights and Clarifications | Supervisory Authority |
|---|---|---|---|
| European Economic Area (EEA) | General Data Protection Regulation (EU) 2016/679 | Right to lodge a complaint in the EU Member State of habitual residence, place of work, or place of alleged infringement. | Relevant Supervisory Authority in your EU Member State |
| United Kingdom (UK) | UK GDPR & Data Protection Act 2018 | Right to lodge a complaint with the UK supervisory authority. | Information Commissioner’s Office (ICO) |
| Kingdom of Saudi Arabia (KSA) | Personal Data Protection Law (PDPL) | Rights include access, correction, and deletion, subject to regulatory exemptions. | Saudi Data & Artificial Intelligence Authority (SDAIA) |
| United Arab Emirates (UAE) | Federal Decree-Law No. 45 of 2021 | Rights include access, rectification, erasure, restriction, portability, and objection. | UAE Data Office |
| Qatar | Law No. 13 of 2016 | Rights include access, correction, objection, and deletion, subject to legal limitations. | National Cyber Security Agency (NCSA) |
| Bahrain | Personal Data Protection Law | Rights include access, rectification, erasure, objection, and portability. | Personal Data Protection Authority (PDPA) |
| Morocco | Law No. 09-08 | Rights include access, rectification, and objection. | Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP) |
| Jordan | Personal Data Protection Law No. 24 of 2023 | Rights include access, rectification, erasure, withdrawal of consent, and objection in specified circumstances. | Ministry of Digital Economy and Entrepreneurship |