Naateq
  1. Home
  2. Privacy Policy

Privacy Policy

What we collect, why, where it is stored, and what you can ask of us. Written to be read, not to hide behind.

The short version first

Three sentences are enough for most readers

  • Your customers’ conversations are not stored with us under the on-premise option — they are on your server.
  • We do not sell your data, do not share it for marketing purposes, and do not use it to train a model serving anyone else.
  • You can request your copy or its deletion whenever you like, and we respond within thirty days.

Who is the controller and who is the processor?

A distinction that determines all responsibility: you are the controller of your customers’ data, and we are the processor on your behalf. We process only what you instruct, and never decide a new purpose for your data ourselves.

Which is why we do not say “we grant you compliance” — no processor can grant it. We say: we remove the largest obstacle to it.

What we collect

The data, its reason, and how long it stays

The types of data we process, their basis, and their retention period
TypeWhat it isWhyDuration
Contact datayour name, email and number from the “contact us” formReplying to you and scheduling the discovery sessionTwo years from last contact
Your customers’ conversationsThe text of messages and images sent to your numberGenerating the reply and keeping the customer contextBy your setting — from 30 days to unlimited
Customer recordsstage, quotes, contracts and paymentsRunning the system and avoiding repeated questionsFor as long as the subscription lasts
Operations logthe time of each decision, its source, and which tool was calledAuditing, and explaining any reply after the fact12 months
Payment datathe transaction reference, its status and amountConfirming and recording paymentAs required by invoicing regulations

We never store card data at all. Payment happens at a licensed gateway, and all that reaches us from it is the transaction reference and its status.

Where it is stored

Two modes, and no transfer outside the Kingdom in either

On-premise

The system and the model sit on your own server. We hold no copy of your conversations, and their text never passes through us. And when you end the subscription there is nothing for us to “return” — it is already with you.

Managed

On servers in your country that we operate on your behalf. And if any operation requires a cross-border transfer, it happens only with your written consent and under the safeguards your country’s law requires.

The AI models we call may run locally on your server or at a cloud provider, depending on your setting. We tell you which provider is used for your business before go-live, and you may require local only.

Your rights

What you can ask for, and how

Access and a copy

a copy of your data in a readable format.

Correction

amending any incorrect or incomplete data.

Erasure

deleting your data unless a law obliges us to keep it.

Send your request to privacy@naateq.com — we respond within thirty days. And if your request is not handled as it should be, you may complain to the Saudi Data and AI Authority.

Third parties and cookies

What leaves, and what does not

Who we share with

  • WhatsApp: the message text passes through it by virtue of being the delivery channel.
  • The payment gateway you choose: the transaction amount and reference.
  • The systems you connect yourself — and within the limits you set.
  • The model provider in cloud mode only.

Cookies

This site uses no tracking cookies and no third-party analytics. What we keep in your browser is a single local item (naateq-theme) remembering your choice of light or dark theme; it never leaves your device and does not identify you.

The demo dashboard at ‎/app/demo/‎ holds display data, and no data is collected from you there.

Security, and disclosure on a breach

We hold no international certifications yet, and we will not claim what we do not have.

  • The connection is encrypted, and credentials are stored outside the repository and never appear in any log.
  • Every incoming text is screened before it reaches the model, and attempts to impersonate the owner are blocked.
  • On any breach affecting your data, we notify you within 72 hours of becoming aware of it, and notify the competent authority as the law requires.

We may update this policy. We notify you of any material change thirty days before it takes effect. Last updated: August 2026.

A question about your data?

Write to us directly — a person replies, not a model.