- Home
- Privacy Policy
Privacy Policy
What we collect, why, where it is stored, and what you can ask of us. Written to be read, not to hide behind.
Three sentences are enough for most readers
- Your customers’ conversations are not stored with us under the on-premise option — they are on your server.
- We do not sell your data, do not share it for marketing purposes, and do not use it to train a model serving anyone else.
- You can request your copy or its deletion whenever you like, and we respond within thirty days.
Who is the controller and who is the processor?
A distinction that determines all responsibility: you are the controller of your customers’ data, and we are the processor on your behalf. We process only what you instruct, and never decide a new purpose for your data ourselves.
Which is why we do not say “we grant you compliance” — no processor can grant it. We say: we remove the largest obstacle to it.
The data, its reason, and how long it stays
| Type | What it is | Why | Duration |
|---|---|---|---|
| Contact data | your name, email and number from the “contact us” form | Replying to you and scheduling the discovery session | Two years from last contact |
| Your customers’ conversations | The text of messages and images sent to your number | Generating the reply and keeping the customer context | By your setting — from 30 days to unlimited |
| Customer records | stage, quotes, contracts and payments | Running the system and avoiding repeated questions | For as long as the subscription lasts |
| Operations log | the time of each decision, its source, and which tool was called | Auditing, and explaining any reply after the fact | 12 months |
| Payment data | the transaction reference, its status and amount | Confirming and recording payment | As required by invoicing regulations |
We never store card data at all. Payment happens at a licensed gateway, and all that reaches us from it is the transaction reference and its status.
Two modes, and no transfer outside the Kingdom in either
On-premise
The system and the model sit on your own server. We hold no copy of your conversations, and their text never passes through us. And when you end the subscription there is nothing for us to “return” — it is already with you.
Managed
On servers in your country that we operate on your behalf. And if any operation requires a cross-border transfer, it happens only with your written consent and under the safeguards your country’s law requires.
The AI models we call may run locally on your server or at a cloud provider, depending on your setting. We tell you which provider is used for your business before go-live, and you may require local only.
What you can ask for, and how
Access and a copy
a copy of your data in a readable format.
Correction
amending any incorrect or incomplete data.
Erasure
deleting your data unless a law obliges us to keep it.
Send your request to privacy@naateq.com — we respond within thirty days. And if your request is not handled as it should be, you may complain to the Saudi Data and AI Authority.
What leaves, and what does not
Who we share with
- WhatsApp: the message text passes through it by virtue of being the delivery channel.
- The payment gateway you choose: the transaction amount and reference.
- The systems you connect yourself — and within the limits you set.
- The model provider in cloud mode only.
Cookies
This site uses no tracking cookies and no third-party analytics. What we keep in your browser is a single local item (naateq-theme) remembering your choice of light or dark theme; it never leaves your device and does not identify you.
The demo dashboard at /app/demo/ holds display data, and no data is collected from you there.
Security, and disclosure on a breach
We hold no international certifications yet, and we will not claim what we do not have.
- The connection is encrypted, and credentials are stored outside the repository and never appear in any log.
- Every incoming text is screened before it reaches the model, and attempts to impersonate the owner are blocked.
- On any breach affecting your data, we notify you within 72 hours of becoming aware of it, and notify the competent authority as the law requires.
We may update this policy. We notify you of any material change thirty days before it takes effect. Last updated: August 2026.
A question about your data?
Write to us directly — a person replies, not a model.