Privacy policy
SAEI complies with the Saudi Personal Data Protection Law (PDPL), issued by Royal Decree No. M/19 and its amendments, and with its implementing regulations issued by the Saudi Data and AI Authority (SDAIA). This policy explains how we collect, use, retain and protect your personal data.
Data controller
SAEI is the Data Controller for your personal data in its relationship with you as a customer or a visitor. A designated Data Protection Officer (DPO) handles privacy enquiries — contact: privacy@automize.sa.
The data we collect
- Contact data (name, email, mobile, business name) — when you get in touch or register.
- Anonymised usage data (pages visited, browser type) — for analytics only.
- Operational data (conversations, campaigns, contacts) — data necessary to deliver the service under the contract.
- Billing data (legal name, tax number, billing address) — as required by the Zakat, Tax and Customs Authority.
Lawful basis for processing
- Performance of your subscription contract — for all operational data.
- Explicit consent — for optional marketing communications.
- A specified legitimate interest — for improving the service and detecting fraud.
- Legal obligation — for retaining tax records and invoices.
How we use data
We use data solely to deliver the service, improve it, issue invoices and communicate with our customers. We do not sell data to any third party. We do not share your data with external advertising or marketing parties under any circumstances.
Your rights under the PDPL
- The right to be informed: to know that your data is processed and for what purposes.
- The right of access: to obtain a copy of your data in a readable format.
- The right to rectification: to have inaccurate or incomplete data corrected.
- The right to erasure: to have your data deleted once it is no longer needed.
- The right to restrict or object to processing on legitimate grounds.
- The right to port your data to another provider in a machine-readable format.
- The right to withdraw consent at any time, without affecting the lawfulness of processing carried out before.
- The right to lodge a complaint with the Saudi Data and AI Authority (SDAIA) at sdaia.gov.sa.
How to exercise your rights
To exercise any of the rights above, send a request through the Data Subject Request (DSR) form on the "Contact us" page, or write to privacy@automize.sa. We will respond within 30 days as the PDPL requires, and we may ask you to verify your identity before we act on the request.
Retention periods
- Operational data (conversations, campaigns): for as long as you are an active customer, then deleted within 90 days of the subscription ending.
- Billing data and tax invoices: 10 years, as the Zakat authority requires.
- Sign-in and security audit logs: 18 months.
- Anonymised analytics data: not linked to an identity, and may be retained in fully anonymised form.
Transfers outside the Kingdom
Your operational data is held in data centres inside the Kingdom of Saudi Arabia. Some component services (Meta infrastructure, email, the Cloudflare CDN) may process data abroad under approved contractual safeguards (Standard Contractual Clauses) and security guarantees equivalent to the PDPL standard. Any transfer follows an impact assessment and observes SDAIA Resolution No. 102.
Data breach notification
If a breach affects your personal data, we will notify SDAIA within 72 hours of discovering the incident, and notify you directly if the breach poses a high risk to your rights or freedoms. Notifications cover: the nature of the breach, the data affected, the steps taken, and what you should do.
Children's data
The service is intended for businesses. We do not knowingly collect data from children under 18. If we discover that we have collected a minor’s data without parental consent, we delete it immediately.
Marketing consent
We do not send you marketing communications without your explicit consent. You can withdraw that consent at any time through the "unsubscribe" link in every message, from your account settings, or by writing to privacy@automize.sa.
Technical security
- Full encryption in transit over TLS 1.3 for every connection.
- Encryption at rest (AES-256) for stored data.
- Strict access controls with tiered permissions and two-factor authentication for staff.
- Regular security reviews and annual penetration testing.
- A complete audit trail for every access to sensitive data.