Data disclosure
Last updated: 28 Aug 2026
This page answers one question without hedging: where your organization's data goes, when a call leaves the system to a third party, and who bears responsibility for it. If something you need is not here, ask us before you sign.
Where data is stored
Your organization's data — customers, deals, correspondence, attachments — is stored on our servers in the Kingdom of Saudi Arabia. Backups stay in the same geography, encrypted at rest and in transit.
Isolation between organizations
Each organization is a separate record. No query in the system reads a record without an explicit constraint on the organization identifier, and no path exposes one organization's data to another's users — not in search, not in reports, not through the API. We audit this isolation on a schedule, not once at build time.
External connections
The system contacts no third party on its own. Every connection below does not work until you enable it with your own account and keys, and stops the moment you disconnect it.
| Service | What leaves | When | Whose account |
|---|---|---|---|
| Microsoft 365 / Outlook | Message body, attachments, recipient addresses | When you send mail or sync your mailbox | Yours |
| WhatsApp Business (Meta) | Message text, media, recipient number | When you send a message or an automation you enabled replies | Yours |
| AI assistant (Hibab) | The text you ask it to analyze and the deal fields it needs | When you request analysis or drafting | Ours, unless you connect your own key |
| Tender radar | Your search criteria only — no customer data | When the radar runs on your schedule | Ours |
| E-signature | The document and signer details | When you send a document for signature | Yours |
| Payment gateway | Invoice details — we never store your card number | When you pay a subscription | Ours |
| Your own mail server (SMTP) | Message body and attachments | When you send mail | Yours |
Your responsibility for the calls you enable
When you connect an account on an external service, you issue the instruction and we carry it out. It follows that:
- The third party's terms apply to you. Your use of WhatsApp, Microsoft or any other provider is governed by their terms and policies in addition to ours, and their suspension of your account is outside our control.
- The lawful basis for contact is yours. Having a lawful basis to contact the people you contact — and their consent where the law requires it — is your obligation, not ours.
- What leaves does not come back. A message delivered to a third party is not ours to recall; deleting it here does not delete it there.
- Cost and limits are yours. Your quota consumption and your provider's fees are settled with them, not with us.
We log every external call for you — when it left, where it went, and at which user's instruction — and the log is visible inside the system whenever you want to review it.
What we do not do
- We do not sell, rent, or share your data for marketing — not to a third party and not to another organization on the platform.
- We do not train AI models on your organization's content, and we do not use it to improve service for another customer.
- We do not look at your content except in two cases: a support request from you, or an operational necessity to fix a fault. Both are logged with the employee's name, time, and reason, and the log is yours on request.
Retention and deletion
- What you delete moves to the restore bin for 30 days, then is erased.
- When your subscription ends, your data stays available for export for 60 days, then is deleted.
- You can export all your data at any time, without our permission and at no charge.
- Security audit logs are kept 12 months — they record actions, not content.
Your rights
Under the Personal Data Protection Law of Saudi Arabia you may access, correct, delete, and port your personal data, and object to specific processing. Write to privacy@effistar.sa and we respond within thirty days.
If anything changes
We notify you inside the system and by email thirty days before any material change to this page takes effect. The last-updated date appears at the top.