Data disclosure

Last updated: 28 Aug 2026

This page answers one question without hedging: where your organization's data goes, when a call leaves the system to a third party, and who bears responsibility for it. If something you need is not here, ask us before you sign.

Where data is stored

Your organization's data — customers, deals, correspondence, attachments — is stored on our servers in the Kingdom of Saudi Arabia. Backups stay in the same geography, encrypted at rest and in transit.

Isolation between organizations

Each organization is a separate record. No query in the system reads a record without an explicit constraint on the organization identifier, and no path exposes one organization's data to another's users — not in search, not in reports, not through the API. We audit this isolation on a schedule, not once at build time.

External connections

The system contacts no third party on its own. Every connection below does not work until you enable it with your own account and keys, and stops the moment you disconnect it.

ServiceWhat leavesWhenWhose account
Microsoft 365 / OutlookMessage body, attachments, recipient addressesWhen you send mail or sync your mailboxYours
WhatsApp Business (Meta)Message text, media, recipient numberWhen you send a message or an automation you enabled repliesYours
AI assistant (Hibab)The text you ask it to analyze and the deal fields it needsWhen you request analysis or draftingOurs, unless you connect your own key
Tender radarYour search criteria only — no customer dataWhen the radar runs on your scheduleOurs
E-signatureThe document and signer detailsWhen you send a document for signatureYours
Payment gatewayInvoice details — we never store your card numberWhen you pay a subscriptionOurs
Your own mail server (SMTP)Message body and attachmentsWhen you send mailYours

Your responsibility for the calls you enable

When you connect an account on an external service, you issue the instruction and we carry it out. It follows that:

  • The third party's terms apply to you. Your use of WhatsApp, Microsoft or any other provider is governed by their terms and policies in addition to ours, and their suspension of your account is outside our control.
  • The lawful basis for contact is yours. Having a lawful basis to contact the people you contact — and their consent where the law requires it — is your obligation, not ours.
  • What leaves does not come back. A message delivered to a third party is not ours to recall; deleting it here does not delete it there.
  • Cost and limits are yours. Your quota consumption and your provider's fees are settled with them, not with us.

We log every external call for you — when it left, where it went, and at which user's instruction — and the log is visible inside the system whenever you want to review it.

What we do not do

  • We do not sell, rent, or share your data for marketing — not to a third party and not to another organization on the platform.
  • We do not train AI models on your organization's content, and we do not use it to improve service for another customer.
  • We do not look at your content except in two cases: a support request from you, or an operational necessity to fix a fault. Both are logged with the employee's name, time, and reason, and the log is yours on request.

Retention and deletion

  • What you delete moves to the restore bin for 30 days, then is erased.
  • When your subscription ends, your data stays available for export for 60 days, then is deleted.
  • You can export all your data at any time, without our permission and at no charge.
  • Security audit logs are kept 12 months — they record actions, not content.

Your rights

Under the Personal Data Protection Law of Saudi Arabia you may access, correct, delete, and port your personal data, and object to specific processing. Write to privacy@effistar.sa and we respond within thirty days.

If anything changes

We notify you inside the system and by email thirty days before any material change to this page takes effect. The last-updated date appears at the top.