Version 1.0 — 15/07/2026

Privacy and Personal Data Protection Policy

Global-Check Platform

Home

01Introduction

The Company is committed to protecting the privacy of individuals and organizations and maintaining the confidentiality of personal data collected, processed, or stored while providing its services, operating its electronic systems, or managing its business. Data protection is an essential part of the Company's corporate governance, risk management, and information security framework.

This Policy explains the principles, controls, and procedures followed by the Company to ensure that personal data is processed lawfully, securely, fairly, and transparently in a manner that protects the rights of data subjects and strengthens trust in the electronic services provided by the Company.

The Company is also committed to implementing appropriate organizational, administrative, and technical measures to protect data against unauthorized access, unlawful use, loss, destruction, alteration, or unauthorized disclosure, while taking into account applicable Palestinian legislation and internationally recognized best practices and standards in data protection and information security.

02Purpose of the Policy

This Policy aims to achieve the following objectives:

  1. Protect the privacy of all personal data subjects.
  2. Regulate the collection, use, processing, disclosure, retention, and destruction of personal data.
  3. Ensure compliance with applicable Palestinian legislation concerning electronic transactions, cybercrime, and information confidentiality.
  4. Reduce the risks of security breaches and information leakage.
  5. Support the principles of transparency, accountability, and sound governance.
  6. Protect personal data against unlawful or unauthorized processing.

03Scope of Application

This Policy applies to:

  • All personal data collected, processed, or stored by the Company by any means.
  • All electronic systems, websites, applications, and digital platforms owned or operated by the Company.
  • All employees, workers, trainees, consultants, and contractors.
  • All current and prospective customers.
  • Suppliers, partners, and service providers.
  • Website visitors.
  • Users of electronic applications.

This Policy applies to all data-processing activities, whether conducted inside or outside Palestine, whenever the Company determines the purposes and means of processing or is otherwise responsible for such processing.

04Definitions

For the purposes of this Policy, the following terms shall have the meanings set out below:

Company: The legal entity issuing this Policy and collecting or processing personal data.

Personal Data: Any information relating to an identified or identifiable natural person, directly or indirectly, including a name, identification number, address, email address, telephone number, geographic location, Internet Protocol address (IP), or any other information that may identify the person.

Sensitive Data: Data whose disclosure may cause harm to its owner, including, depending on the nature of the Company's activities, financial, biometric, or other data requiring a higher level of protection.

Data Subject: The natural or legal person to whom the personal data relates.

Processing: Any operation performed on personal data, whether electronically or on paper, including collection, recording, organization, classification, storage, alteration, retrieval, use, transfer, sharing, linking, deletion, or destruction.

Consent: A freely given, explicit, and informed agreement issued by the data subject allowing the Company to process their data for specified purposes through use of the Platform.

Disclosure: Enabling another party to access or obtain data by any means.

Service Provider: Any external party that performs a service or operation on behalf of the Company and consequently processes personal data.

Data Breach: Any incident resulting in unauthorized access to, loss, alteration, destruction, or disclosure of personal data.

Cookies: Small technical files stored on or associated with a user's device or browser to manage secure sessions, protect requests, remember preferences, and enable essential Platform functionality.

Website: All websites, applications, or electronic platforms owned or operated by the Company.

05Purposes of Data Collection and Use

T & S Textiles collects and processes personal data and user data only to the extent necessary to provide the services of the Global-Check Platform for the following purposes:

A. Providing Platform Services

  • Performing name-screening and verifying persons and entities in accordance with customer requests.
  • Screening against international and local sanctions lists, politically exposed persons (PEP) lists, adverse media databases, and other databases used by the Platform.
  • Creating and managing user accounts and assigning permissions.
  • Saving screening results and search records and making them available to authorized users.
  • Creating reports and statistics relating to screening, risk management, and compliance.
  • Providing integration services with other systems through application programming interfaces (APIs) or other approved technical methods.

B. Identity Verification and Account Protection

  • Verifying user identities and permissions before granting access to the Platform.
  • Protecting accounts against unauthorized access or misuse.
  • Recording logins, logouts, and activities within the system for audit and security purposes.
  • Detecting and preventing intrusion attempts, system misuse, or other unlawful activity.

C. Communication and Technical Support

  • Sending notifications about system status, Platform updates, or technical reports.
  • Communicating with users regarding technical-support requests, inquiries, or complaints.
  • Informing customers of material updates, scheduled maintenance, or changes to services or terms of use.
  • Sending cybersecurity alerts or notices concerning risks that may affect user accounts or data.

D. Compliance and Legal Obligations

  • Complying with laws, regulations, and regulatory instructions concerning Anti-Money Laundering (AML), Counter-Terrorist Financing (CTF), international sanctions, Know Your Customer (KYC), and other related requirements.
  • Responding to requests from competent judicial, regulatory, or governmental authorities when required by law.
  • Documenting screening operations and usage records in accordance with regulatory or contractual requirements.
  • Retaining records and data for the periods required by law, regulation, or the Company's internal policies.

06Prohibited Uses

T & S Textiles confirms that it:

  • Does not use personal data for marketing, advertising, or promotional purposes without obtaining the customer's explicit consent where required by law.
  • Does not sell, lease, or trade personal data or customer data to any third party.
  • Uses data only to the extent necessary to provide services or fulfill legal or contractual obligations.

07Data Collected by the Company

The Company collects personal data only to the extent necessary to achieve legitimate purposes related to providing its services or fulfilling legal or contractual obligations. Depending on the nature of the relationship with the data subject, the data collected may include the following:

Identity Data

  • Full name.
  • Identification number, passport number, or another official identification document.
  • Date and place of birth, when required.
  • Nationality.
  • Personal photograph, where necessary to provide the service.
  • Handwritten or electronic signature.

Contact Data

  • Telephone number.
  • Email address.
  • Home or work address.
  • Correspondence address.
  • Other communication methods selected by the data subject.

Usage and Device Data

  • Internet Protocol address (IP Address).
  • Device type and operating system.
  • Browser type and version.
  • Language and time zone.
  • Device identifiers.
  • Login and usage records.
  • Date and time of service use.
  • Pages visited and duration of use.
  • Technical error information.
  • Search and screening records.
  • Referring URL, where applicable.
  • Cookie or similar technology information, where used.

Data Voluntarily Provided by the User

  • Registration forms.
  • Contact requests and inquiries.
  • Complaints and comments.
  • Survey responses.
  • Electronic correspondence.

08Data Subject Obligations

  1. Provide accurate and correct data.
  2. Update data whenever a change occurs.
  3. Maintain the confidentiality of electronic account login credentials.
  4. Do not share passwords with others.
  5. Use electronic services lawfully.
  6. Do not misuse, attempt to breach, or disrupt the Company's systems.
  7. Notify the Company immediately of any suspected unauthorized account use.

09 Cookies

The Global-Check Platform uses essential cookies and similar technical technologies that are necessary for the secure and proper operation of the Platform.

These technologies may be used for the following purposes:

  • Managing authenticated user sessions and maintaining access after login.
  • Protecting the Platform and user requests against Cross-Site Request Forgery (CSRF) and other security threats.
  • Remembering language and interface preferences.
  • Supporting account security, access control, and prevention of unauthorized use.
  • Maintaining Platform stability and enabling essential technical functionality.
  • Diagnosing technical errors and protecting the integrity of electronic services.

Essential cookies are required for the Platform to function correctly. Disabling or blocking them may prevent users from signing in, maintaining a secure session, changing language preferences, or using certain Platform features.

The Platform does not currently use cookies for behavioral advertising, cross-site tracking, or the sale of user information.

10Information Security and Data Protection

General Commitment

The Company protects personal data through administrative, technical, and organizational controls appropriate to the nature of the data and the associated level of risk.

Information Protection

T & S Textiles protects personal data and customer data using appropriate security, administrative, and technical measures, including but not limited to:

  • Encrypting data in transit and at rest using appropriate encryption technologies.
  • Using secure servers and infrastructure inside or outside the country in accordance with legal and contractual requirements.
  • Applying strict access-control policies in accordance with the principle of least privilege.
  • Using firewalls, intrusion detection and prevention systems, and other appropriate security measures.
  • Recording and monitoring access operations and system activity for audit and security purposes.
  • Conducting periodic security reviews and tests and applying necessary security updates to address known vulnerabilities.
  • Training authorized employees on information security, data protection, and confidentiality requirements.

The Company incorporates privacy and information-security requirements into the design, development, and updating of electronic systems and digital services so that data protection forms an essential part of the system life cycle from the earliest design stages through decommissioning or destruction.

If a data breach is likely to result in serious harm to data subjects, the Company will notify the competent authorities and affected persons whenever required by law.

11Personal Data Sharing and Disclosure

General Principle

The Company does not sell, lease, trade, or disclose personal data to any third party except to the extent permitted by law, in accordance with this Policy, or based on the explicit consent of the data subject where such consent is required.

Permitted Disclosure Cases

  1. Fulfilling contractual obligations to the data subject.
  2. Complying with a court order or a decision issued by a competent authority.
  3. Implementing binding legal or regulatory requirements.
  4. Protecting the rights of the Company, its employees, or its customers.
  5. Preventing or investigating fraud, cybercrime, or other unlawful activity.
  6. Protecting cybersecurity and system integrity.
  7. Protecting life or property where permitted by law.
  8. Conducting legal, financial, or compliance audits and reviews.
  9. Completing a merger, acquisition, restructuring, or sale of part of the Company's business while ensuring continued data protection.

Transfer of Ownership or Merger

The Company may in the future enter into a merger, acquisition, or partnership with local or international companies, or sell some or all of its assets. If such a transaction occurs, user data may be transferred to the new entity, whether Palestinian or foreign, provided that the same or equivalent protection and confidentiality standards set out in this Policy continue to apply.

The Company will make reasonable efforts to inform users of any material change in data ownership or management and provide them with appropriate options concerning continued use of the Platform, amendment of their data, or deletion of their data.

13Transfer of Data Outside the State of Palestine

The nature of the Company's services or technical infrastructure may require personal data to be transferred, stored, or processed outside the State of Palestine.

In such cases, the Company will implement the measures necessary to ensure an appropriate level of protection for transferred data in a manner that does not conflict with applicable Palestinian legislation.

14Amendments to the Privacy Policy

The Company may amend this Policy whenever necessary, including as a result of:

  • New legislation.
  • Service updates.
  • Development of technical systems.
  • Changes in business requirements.
  • Emergence of new risks.

The updated version of this Policy will be published on the website or through other methods adopted by the Company. Continued use of the services after an amendment takes effect constitutes acceptance of the amendment unless the law requires new consent.

15Contact and Complaints

Data subjects and users may contact the Company regarding:

  • Privacy-related inquiries.
  • Exercising rights provided under this Policy.
  • Requests to correct or update data.
  • Requests to delete data.
  • Reporting privacy violations.
  • Submitting complaints or comments.

16Data Retention

The Company retains personal data for as long as necessary to provide the service or for the period required by applicable Palestinian legislation, including, for example, legally required retention periods for insurance, tax, or judicial records.