Privacy Policy
Last updated: 28 Aug 2026
We respect your privacy and follow the principles of Saudi Arabia's Personal Data Protection Law and its implementing regulations. This policy explains what we collect, why, and how we protect it.
1. Our role
We are a processor for data your organization enters about its customers (your organization is the controller), and a controller for platform account data and enquiries received through this website.
2. What we collect
- Account data: name, work email, mobile, role and organization.
- Operational data: sign-in and action logs (who did what and when) — for security and audit.
- Content you enter: customers, deals, conversations and attachments — belonging to your organization; we access it only at your explicit support request or for a documented operational necessity.
- Invite form data: what you write in the request form on this site.
3. Legal basis and purpose
We process data to perform our contract with you, for our legitimate interest in securing the service and preventing abuse, and with your consent where consent is required (such as marketing contact). We do not sell personal data, and we do not use your customers' content to train general AI models.
4. Artificial intelligence
When AI modules are enabled, only what the analysis requires is sent to the model provider your organization selects, and it is not used to train their general models under our agreements. You can switch these modules off entirely.
5. Sharing
We share data only with infrastructure and service providers necessary to operate (hosting, email, messaging), under contracts binding them to confidentiality and to processing for our purposes alone. We disclose to no one else except under legal order.
6. Retention and deletion
We retain data for your subscription term and a reasonable period after, to allow export. Deletion inside the platform passes through a 30-day recycle bin before becoming permanent. On termination your data is deleted or anonymised within an agreed period.
7. Security
- Full tenant isolation — each organization's data is its own, and we audit this regularly.
- Secrets (integration keys, mailbox passwords) encrypted per organization.
- Fine-grained permissions and a data scope per role, with a complete audit trail.
- All traffic encrypted in transit (TLS).
8. Your rights
You have the right to know what we process, access it, request correction, request destruction when no longer needed, and receive a readable copy. Contact hello@effistar.net and we respond within the statutory periods.
9. Cookies
We use only cookies necessary for the session and to remember your language preference. We place no advertising trackers on this site.
10. Transfers outside the Kingdom
Where operation requires a provider outside the Kingdom, this is done under the law's controls and with appropriate protection contracts, and is set out in the data-processing agreement with your organization.
Last updated: August 2026 · Data protection contact: hello@effistar.net