1. Introduction and scope
This policy is issued by DATA, the service provider and platform owner, referred to here as "DATA".
It applies to personal data processed through DATA services, which include:
- Website
- DATA's public pages, including contact and access-request forms.
- Platform
- The authenticated application used by authorised users inside an organisation.
- Customer workspace
- Each organisation's isolated environment, its settings, departments, users and content.
- Qanoni
- The legal research and document drafting service inside the platform.
- Connectors and integrations
- Connections the customer enables to bring in data from its systems or providers.
- Support services
- Technical and operational assistance related to the service.
2. The roles of DATA and the customer
DATA acts as controller for personal data relating to website visitors, access requests, account administration, contact and subscription data, security logs, and service communications.
The customer organisation acts as controller for data about its employees, customers, finances, legal matters, operations and connected systems, and is responsible for the lawful basis, accuracy and access permissions of that data.
DATA acts as processor or service provider for customer workspace content, following the customer's instructions and the agreement in place.
Whether DATA or the customer is controller depends on the nature of the processing and the agreement signed with the customer.
3. Categories of data we may process
Not all categories below are processed by default; several are processed only when the customer uploads, connects or authorises them.
| Category | Examples | Source | Purpose | Mandatory? | Possibly sensitive? | Retention | Role |
|---|---|---|---|---|---|---|---|
| Requester data | Name, work email, job title, phone | Directly from the user | Assessing and responding to the request | Yes | No | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Controller |
| Requesting organisation | Company name, size, industry | Directly from the user | Assessing service fit | Yes | No | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Controller |
| Scope of use | Requested departments, existing systems, use case | Directly from the user | Workspace and technical scoping | Optional | No | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Controller |
| Category | Examples | Source | Purpose | Mandatory? | Possibly sensitive? | Retention | Role |
|---|---|---|---|---|---|---|---|
| User identity | Name, work email, job title | User or organisation admin | Account creation and authentication | Yes | No | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Controller / processor |
| Organisational placement | Employee ID if provided, department, role | Organisation admin | Permissions and access control | Per customer setup | Possibly | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Processor |
| Preferences | Language, time zone | User | Interface personalisation | No | No | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Controller |
| Access state | MFA status, invitation and access status | System | Security and membership management | Yes | No | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Controller |
| Category | Examples | Source | Purpose | Mandatory? | Possibly sensitive? | Retention | Role |
|---|---|---|---|---|---|---|---|
| Legal organisation data | Legal name, CR, VAT, national address (only if actually collected) | Organisation admin | Contracting and verification | Case by case | No | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Controller |
| Subscription and plan | Plan status, usage limits | System and agreement | Operating the service and its limits | Yes | No | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Controller |
| Department and domain setup | Enabled departments, domain verification data | Organisation admin | Access control and verification | Yes | No | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Processor |
| Billing contact | Billing contact name and email | Organisation admin | Billing, only when billing is activated | When billing is active | No | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Controller |
| Category | Examples | Source | Purpose | Mandatory? | Possibly sensitive? | Retention | Role |
|---|---|---|---|---|---|---|---|
| Sign-in activity | Sign-in times, session state | System | Security and prevention of unauthorised use | Yes | No | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Controller |
| Network and device data | IP address, browser and device metadata | System | Security and suspicious-use detection | Yes | No | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Controller |
| Audit logs and security events | Permission changes, access attempts | System | Audit and compliance | Yes | Possibly | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Controller / processor |
| Key and session metadata | API key and session metadata | System | Controlling programmatic access | Per usage | No | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Processor |
| Connector logs | Connection health, sync and error logs | Authorised connectors | Running integrations and troubleshooting | Per usage | Possibly | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Processor |
| Category | Examples | Source | Purpose | Mandatory? | Possibly sensitive? | Retention | Role |
|---|---|---|---|---|---|---|---|
| Uploaded files | CSV, Excel, JSON, XML and documents | Customer | Analysis and reporting per customer instruction | Per usage | Possibly | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Processor |
| HR data | Employee records, performance, attendance | Customer or its connectors | Workforce analysis | Per usage | Yes | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Processor |
| Finance and commercial data | Transactions, reports, customer and sales data | Customer or its connectors | Analysis and decision support | Per usage | Possibly | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Processor |
| IT and security data | Alerts, customer system logs | Customer or its connectors | Operational and security monitoring | Per usage | Possibly | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Processor |
| Legal documents and contracts | Contracts, documents, drafts | Customer | Review, drafting and research | Per usage | Yes | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Processor |
| AI conversations | Questions, answers, cited sources, connector metadata | User and system | Producing answers and tracing sources | Per usage | Possibly | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. | Processor |
F. Sensitive or high-risk data: DATA may process sensitive or high-risk data only when the customer uploads, connects or authorises it, for example:
- Payroll and benefits data.
- Compensation and job structure data.
- HR performance and appraisal data.
- Health or identity data if the customer uploads it.
- Financial transactions.
- Privileged or protected legal content.
- Security alerts and logs.
4. Sources of collection
- Directly from the user through forms and the platform.
- From the organisation administrator when creating accounts, invitations and permissions.
- From connectors the customer authorises.
- From files and documents the customer uploads.
- From browser, device and network logs.
- From support requests and related correspondence.
- From approved API integrations.
- From cookies where enabled.
5. Purposes of processing
- Authenticating users and managing access and permissions.
- Creating and administering the workspace.
- Providing dashboards, AI analysis, reports and workflows.
- Processing uploaded or connected data as authorised.
- Security, prevention of unauthorised use and audit trails.
- Customer support and handling technical requests.
- Service improvement, only in line with approved settings and agreements.
- Legal and contractual obligations.
- Communications about the service, the account and security.
6. Lawful basis for processing
- Performance of a contract or steps prior to contracting.
- Consent where required.
- Legal obligation.
- Legitimate interest within applicable regulatory controls.
- Protection of rights and legal claims.
The appropriate lawful basis is determined by the type of data, the purpose of processing and the nature of the relationship with the customer.
7. Artificial intelligence and Qanoni
- DATA AI processes only information the authorised user is permitted to submit or access.
- AI output may contain errors and must be reviewed before it is relied upon.
- AI output is not professional legal, financial, HR, tax, medical or security advice.
- Qanoni output is legal-information and research support only, not legal advice.
- Passwords, secrets, API keys and unnecessary sensitive data must not be submitted.
AI provider terms: AI processing runs through approved processing providers under appropriate contractual and technical controls.. Provider retention: Conversation content is retained for as long as needed to provide the service or for the period agreed with the customer.. Model-training position: DATA does not use customer content to train general AI models without the customer's explicit written consent and in line with the agreement with the customer..
8. Disclosure and subprocessors
DATA may engage vetted subprocessors for hosting, authentication, storage, messaging, monitoring, AI processing, support and security, subject to applicable agreements and safeguards.
Customer data is not disclosed except as authorised by the customer, required by law, necessary to provide the service, or under valid customer instruction.
The list of approved subprocessors is published on the subprocessors page.
9. Transfers outside the Kingdom
Some processing, hosting or support may take place outside the Kingdom of Saudi Arabia only where necessary and after the required regulatory, contractual and technical controls are applied, as applicable to the service and the customer.
Hosting and processing regions: Data may be processed or hosted inside or outside the Kingdom of Saudi Arabia depending on customer configuration, the nature of the service and approved service providers, in line with applicable regulations and contractual obligations.. Transfer mechanism: Appropriate contractual and technical safeguards apply to any processing or transfer of data outside the Kingdom..
10. Retention and destruction
We retain data for as long as needed to fulfil the stated purposes, for the period agreed with the customer, or for the period required by law, after which it is securely deleted, destroyed or anonymised.
| Data type | Retention period |
|---|---|
| Access requests | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. |
| User account records | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. |
| Audit and security logs | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. |
| Customer workspace data | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. |
| Uploaded files | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. |
| Connector and sync logs | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. |
| AI conversations | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. |
| Subscription and billing records | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. |
| Customer legal documents | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. |
| Backups | For as long as needed to provide the service, or the period agreed with the customer, or the period required by law. |
11. Security measures
We apply organisational and technical controls according to what is enabled in the service environment, including:
- Access control and authentication
- Role-based permissions
- Tenant isolation at the database layer
- Encryption in transit
- Encryption at rest
- Audit logging of sensitive events
- Secret and key management
- Data export restrictions
DATA does not claim absolute security, nor any certification it has not actually been issued.
12. Data subject rights
- The right to be informed.
- The right of access to personal data.
- The right to obtain a copy.
- The right to correction and updating.
- The right to destruction where applicable.
- The right to withdraw consent where consent is the basis.
- The right to complain to the competent authority.
- The right to request an explanation of the processing.
Request flow:
- Send the request to the privacy contact: info@data.sa.
- Identity verification where necessary.
- Issue of a reference number for tracking.
- Response within the applicable statutory period and approved operational policy.
14. Personal data incidents
If a personal data incident occurs, DATA takes containment, investigation and remediation steps and makes the required notifications to competent authorities and data subjects where the statutory conditions are met and within the applicable statutory periods.
15. Updates
Current version: 1.0. Effective date: 14 August 2025.
Changes are recorded in the version history at the bottom of this document, and customers are notified of material changes by registered work email or an in-platform notice.
16. Contact
- Privacy contact
- info@data.sa
- General contact
- info@data.sa
Version history
- 1.014 August 2025Approved for publication.
