Data
Legal document

Privacy and Personal Data Protection Policy

This policy explains how DATA collects, processes and protects personal data when you use the website, the platform and related services, together with the rights of data subjects and how to contact us. This is a translation of the Arabic text; the Arabic version governs in case of conflict.

Last updated
14 August 2025
Version
1.0
Governing language
Arabic. The English version is a guidance translation unless a written agreement states otherwise.
Contact us about privacyinfo@data.sa
1. Introduction and scope

1. Introduction and scope

This policy is issued by DATA, the service provider and platform owner, referred to here as "DATA".

It applies to personal data processed through DATA services, which include:

Website
DATA's public pages, including contact and access-request forms.
Platform
The authenticated application used by authorised users inside an organisation.
Customer workspace
Each organisation's isolated environment, its settings, departments, users and content.
Qanoni
The legal research and document drafting service inside the platform.
Connectors and integrations
Connections the customer enables to bring in data from its systems or providers.
Support services
Technical and operational assistance related to the service.

2. The roles of DATA and the customer

DATA acts as controller for personal data relating to website visitors, access requests, account administration, contact and subscription data, security logs, and service communications.

The customer organisation acts as controller for data about its employees, customers, finances, legal matters, operations and connected systems, and is responsible for the lawful basis, accuracy and access permissions of that data.

DATA acts as processor or service provider for customer workspace content, following the customer's instructions and the agreement in place.

Whether DATA or the customer is controller depends on the nature of the processing and the agreement signed with the customer.

3. Categories of data we may process

Not all categories below are processed by default; several are processed only when the customer uploads, connects or authorises them.

A. Access request data
CategoryExamplesSourcePurposeMandatory?Possibly sensitive?RetentionRole
Requester dataName, work email, job title, phoneDirectly from the userAssessing and responding to the requestYesNoFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Controller
Requesting organisationCompany name, size, industryDirectly from the userAssessing service fitYesNoFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Controller
Scope of useRequested departments, existing systems, use caseDirectly from the userWorkspace and technical scopingOptionalNoFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Controller
B. Account and membership data
CategoryExamplesSourcePurposeMandatory?Possibly sensitive?RetentionRole
User identityName, work email, job titleUser or organisation adminAccount creation and authenticationYesNoFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Controller / processor
Organisational placementEmployee ID if provided, department, roleOrganisation adminPermissions and access controlPer customer setupPossiblyFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Processor
PreferencesLanguage, time zoneUserInterface personalisationNoNoFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Controller
Access stateMFA status, invitation and access statusSystemSecurity and membership managementYesNoFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Controller
C. Organisation and administration data
CategoryExamplesSourcePurposeMandatory?Possibly sensitive?RetentionRole
Legal organisation dataLegal name, CR, VAT, national address (only if actually collected)Organisation adminContracting and verificationCase by caseNoFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Controller
Subscription and planPlan status, usage limitsSystem and agreementOperating the service and its limitsYesNoFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Controller
Department and domain setupEnabled departments, domain verification dataOrganisation adminAccess control and verificationYesNoFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Processor
Billing contactBilling contact name and emailOrganisation adminBilling, only when billing is activatedWhen billing is activeNoFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Controller
D. Usage and security data
CategoryExamplesSourcePurposeMandatory?Possibly sensitive?RetentionRole
Sign-in activitySign-in times, session stateSystemSecurity and prevention of unauthorised useYesNoFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Controller
Network and device dataIP address, browser and device metadataSystemSecurity and suspicious-use detectionYesNoFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Controller
Audit logs and security eventsPermission changes, access attemptsSystemAudit and complianceYesPossiblyFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Controller / processor
Key and session metadataAPI key and session metadataSystemControlling programmatic accessPer usageNoFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Processor
Connector logsConnection health, sync and error logsAuthorised connectorsRunning integrations and troubleshootingPer usagePossiblyFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Processor
E. Customer content and department data
CategoryExamplesSourcePurposeMandatory?Possibly sensitive?RetentionRole
Uploaded filesCSV, Excel, JSON, XML and documentsCustomerAnalysis and reporting per customer instructionPer usagePossiblyFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Processor
HR dataEmployee records, performance, attendanceCustomer or its connectorsWorkforce analysisPer usageYesFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Processor
Finance and commercial dataTransactions, reports, customer and sales dataCustomer or its connectorsAnalysis and decision supportPer usagePossiblyFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Processor
IT and security dataAlerts, customer system logsCustomer or its connectorsOperational and security monitoringPer usagePossiblyFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Processor
Legal documents and contractsContracts, documents, draftsCustomerReview, drafting and researchPer usageYesFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Processor
AI conversationsQuestions, answers, cited sources, connector metadataUser and systemProducing answers and tracing sourcesPer usagePossiblyFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.Processor

F. Sensitive or high-risk data: DATA may process sensitive or high-risk data only when the customer uploads, connects or authorises it, for example:

  • Payroll and benefits data.
  • Compensation and job structure data.
  • HR performance and appraisal data.
  • Health or identity data if the customer uploads it.
  • Financial transactions.
  • Privileged or protected legal content.
  • Security alerts and logs.

4. Sources of collection

  • Directly from the user through forms and the platform.
  • From the organisation administrator when creating accounts, invitations and permissions.
  • From connectors the customer authorises.
  • From files and documents the customer uploads.
  • From browser, device and network logs.
  • From support requests and related correspondence.
  • From approved API integrations.
  • From cookies where enabled.

5. Purposes of processing

  • Authenticating users and managing access and permissions.
  • Creating and administering the workspace.
  • Providing dashboards, AI analysis, reports and workflows.
  • Processing uploaded or connected data as authorised.
  • Security, prevention of unauthorised use and audit trails.
  • Customer support and handling technical requests.
  • Service improvement, only in line with approved settings and agreements.
  • Legal and contractual obligations.
  • Communications about the service, the account and security.

7. Artificial intelligence and Qanoni

  • DATA AI processes only information the authorised user is permitted to submit or access.
  • AI output may contain errors and must be reviewed before it is relied upon.
  • AI output is not professional legal, financial, HR, tax, medical or security advice.
  • Qanoni output is legal-information and research support only, not legal advice.
  • Passwords, secrets, API keys and unnecessary sensitive data must not be submitted.

AI provider terms: AI processing runs through approved processing providers under appropriate contractual and technical controls.. Provider retention: Conversation content is retained for as long as needed to provide the service or for the period agreed with the customer.. Model-training position: DATA does not use customer content to train general AI models without the customer's explicit written consent and in line with the agreement with the customer..

8. Disclosure and subprocessors

DATA may engage vetted subprocessors for hosting, authentication, storage, messaging, monitoring, AI processing, support and security, subject to applicable agreements and safeguards.

Customer data is not disclosed except as authorised by the customer, required by law, necessary to provide the service, or under valid customer instruction.

The list of approved subprocessors is published on the subprocessors page.

9. Transfers outside the Kingdom

Some processing, hosting or support may take place outside the Kingdom of Saudi Arabia only where necessary and after the required regulatory, contractual and technical controls are applied, as applicable to the service and the customer.

Hosting and processing regions: Data may be processed or hosted inside or outside the Kingdom of Saudi Arabia depending on customer configuration, the nature of the service and approved service providers, in line with applicable regulations and contractual obligations.. Transfer mechanism: Appropriate contractual and technical safeguards apply to any processing or transfer of data outside the Kingdom..

10. Retention and destruction

We retain data for as long as needed to fulfil the stated purposes, for the period agreed with the customer, or for the period required by law, after which it is securely deleted, destroyed or anonymised.

Retention schedule
Data typeRetention period
Access requestsFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.
User account recordsFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.
Audit and security logsFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.
Customer workspace dataFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.
Uploaded filesFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.
Connector and sync logsFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.
AI conversationsFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.
Subscription and billing recordsFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.
Customer legal documentsFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.
BackupsFor as long as needed to provide the service, or the period agreed with the customer, or the period required by law.

11. Security measures

We apply organisational and technical controls according to what is enabled in the service environment, including:

  • Access control and authentication
  • Role-based permissions
  • Tenant isolation at the database layer
  • Encryption in transit
  • Encryption at rest
  • Audit logging of sensitive events
  • Secret and key management
  • Data export restrictions

DATA does not claim absolute security, nor any certification it has not actually been issued.

12. Data subject rights

  • The right to be informed.
  • The right of access to personal data.
  • The right to obtain a copy.
  • The right to correction and updating.
  • The right to destruction where applicable.
  • The right to withdraw consent where consent is the basis.
  • The right to complain to the competent authority.
  • The right to request an explanation of the processing.

Request flow:

  1. Send the request to the privacy contact: info@data.sa.
  2. Identity verification where necessary.
  3. Issue of a reference number for tracking.
  4. Response within the applicable statutory period and approved operational policy.

13. Cookies

  • Necessary cookies to run the website and platform and protect the session.
  • Functional cookies to remember preferences such as language.
  • Analytics cookies, used only if actually enabled and disclosed.
  • Preferences can be managed through browser settings or through in-site controls where enabled.

If analytics or marketing tools are added, a separate cookie notice will be published.

14. Personal data incidents

If a personal data incident occurs, DATA takes containment, investigation and remediation steps and makes the required notifications to competent authorities and data subjects where the statutory conditions are met and within the applicable statutory periods.

15. Updates

Current version: 1.0. Effective date: 14 August 2025.

Changes are recorded in the version history at the bottom of this document, and customers are notified of material changes by registered work email or an in-platform notice.

16. Contact

Privacy contact
info@data.sa
General contact
info@data.sa

Version history

  • 1.014 August 2025Approved for publication.