كتبنا هذه السياسة لتُقرأ وتُفهم، لا لتُخفي شيئًا خلف عبارات قانونية معقدة. نشرح فيها بوضوح ما نجمعه من بيانات شخصية، ولماذا نجمعها، وكيف نحميها، وما حقوقك بموجب نظام حماية البيانات الشخصية في المملكة العربية السعودية ولوائحه التنفيذية.
بند اللغة: تصدر هذه السياسة باللغتين العربية والإنجليزية. النص العربي هو النص الأصلي المعتمد، وهو الملزم عند أي اختلاف بين النسختين.
1. من نحن
«مي» مساعدة مبيعات تعمل بالذكاء الاصطناعي، تطوّرها وتشغّلها شركة C-01، وهي شركة مقرها المملكة العربية السعودية (السجل التجاري: TODO: CR number — العنوان المسجل: TODO: registered address). فيما يخص زوار موقعنا الإلكتروني وبيانات حسابات عملائنا، تُعد C-01 «جهة التحكم» بمفهوم نظام حماية البيانات الشخصية، أي الجهة التي تحدد غرض المعالجة وكيفيتها.
2. ثلاث فئات نتعامل معها بشكل مختلف
لا يتعامل الجميع مع «مي» من الموقع نفسه، ولذلك نفرّق بوضوح بين ثلاث فئات:
زوار الموقع: كل من يتصفح موقعنا أو يعبّئ أحد نماذجه.
العملاء: المنشآت التي تشترك في الخدمة، وأصحاب الحسابات والمستخدمون التابعون لها.
العملاء المحتملون (Leads): الأشخاص الذين تتواصل معهم «مي» نيابة عن عملائنا. بياناتهم ملك لعملائنا لا لنا، ونعالجها بصفتنا «جهة معالجة» فقط (انظر البند 5).
3. البيانات التي نجمعها
لا نجمع إلا ما نحتاجه فعلًا لتقديم الخدمة، ونذكره هنا كما هو:
من زوار الموقع: عند حجز عرض توضيحي أو طلب استشارة نجمع: الاسم، والبريد الإلكتروني، ورقم الواتساب أو الجوال، واسم الشركة، وحجم الشركة، ووصفًا حرًا للتحدي البيعي الذي تواجهه منشأتك.
من العملاء: بيانات الحساب وبيانات التواصل الخاصة بممثلي المنشأة، وبيانات الاشتراك والفوترة، وسجلات استخدام المنصة، وإعدادات ربط حساب واتساب للأعمال والبريد الإلكتروني الخاصين بالعميل. الحسابات المربوطة تبقى ملكًا للعميل ولا تنتقل إلينا.
من العملاء المحتملين (نيابة عن العميل): بيانات التواصل التي يزودنا بها العميل (كالاسم ورقم الواتساب والبريد الإلكتروني)، ومحتوى المحادثات مع «مي»، وحالة التأهيل والمتابعة، والاجتماعات المحجوزة.
4. أغراض المعالجة وأسسها النظامية
لكل معالجة نقوم بها غرض محدد وأساس نظامي واضح وفق نظام حماية البيانات الشخصية:
تنفيذ العقد أو التمهيد لإبرامه: تشغيل الخدمة، وإدارة الحساب والاشتراك والفوترة، وتقديم الدعم، والرد على طلبات العرض التوضيحي والاستشارة التي تقدمها بنفسك.
الموافقة: التواصل التسويقي معك بعد تعبئتك أحد نماذج الموقع. يمكنك سحب موافقتك في أي وقت من دون أن يؤثر ذلك على مشروعية المعالجة السابقة للسحب.
المصلحة المشروعة (كما يؤطرها النظام): تحسين الخدمة وتأمينها ومنع إساءة استخدامها، وذلك في حدود البيانات غير الحساسة، وبعد موازنة لا تُخل بحقوقك ومصالحك وتوقعاتك المعقولة.
5. بيانات العملاء المحتملين: دورنا جهة معالجة
عندما تتحدث «مي» مع عملائك المحتملين، فالبيانات بياناتك أنت، لا بياناتنا. العميل هو «جهة التحكم» في بيانات عملائه المحتملين، وC-01 «جهة معالجة» تعمل وفق تعليمات العميل الموثقة وبموجب اتفاقية معالجة البيانات المبرمة معه. مسؤولية الحصول على الموافقات النظامية للتواصل (opt-in) تقع على العميل بصفته مالك الحساب وقوائم التواصل. جميع المحادثات مسجَّلة ومرئية للعميل في لوحة التحكم الخاصة به، ولا نستخدمها لأغراضنا الخاصة خارج نطاق تقديم الخدمة.
6. الإفصاح عن الذكاء الاصطناعي وحق إيقاف التواصل
لا نخفي أن «مي» ذكاء اصطناعي، ولا نجادل من يطلب التوقف. تفصح «مي» عن كونها مساعدة ذكاء اصطناعي عند أول تواصل مع أي عميل محتمل. وإذا طلب أي شخص إيقاف التواصل («إيقاف» أو أي عبارة في معناها) نفّذنا طلبه فورًا وبشكل دائم. وفي المرحلة الحالية، يراجع شخص من فريق العميل كل رسالة صادرة ويعتمدها قبل إرسالها.
7. ملفات تعريف الارتباط والتحليلات
موقعنا لا يستخدم حاليًا سوى ملفات تعريف الارتباط الضرورية تقنيًا لعمل الموقع، ولا نستخدم أدوات تتبع إعلانية ولا نبني ملفات تعريف سلوكية للزوار. TODO: analytics — إذا أُضيفت لاحقًا أداة تحليلات أساسية تحترم الخصوصية، سيُحدَّث هذا البند ويُذكر اسم الأداة قبل تفعيلها.
8. مع من نشارك البيانات
لا نبيع بياناتك الشخصية ولا نتاجر بها، أبدًا. نشاركها فقط في الحالات التالية:
مزودو الخدمات (جهات معالجة من الباطن): مثل الاستضافة السحابية والبنية التقنية للمراسلة ومعالجة المدفوعات، وجميعهم ملزمون تعاقديًا بحماية البيانات ومعالجتها وفق تعليماتنا وبما لا يقل عن متطلبات النظام.
الجهات المختصة: عندما يوجب النظام الإفصاح بموجب طلب نظامي صحيح.
9. نقل البيانات خارج المملكة
تُستضاف البيانات بشكل أساسي في TODO: hosting region. وإذا اقتضى تشغيل الخدمة نقل بيانات شخصية خارج المملكة أو الإفصاح عنها لجهة خارجها، فلا يتم ذلك إلا وفق شروط وضوابط النقل المنصوص عليها في نظام حماية البيانات الشخصية (المادة التاسعة والعشرون) ولوائحه التنفيذية، وبما يضمن مستوى حماية للبيانات لا يقل عما يوفره النظام.
10. مدة الاحتفاظ بالبيانات
لا نحتفظ بالبيانات أطول من حاجتنا الفعلية إليها:
سجلات المحادثات وبيانات العملاء المحتملين: طوال مدة اشتراك العميل. بعد انتهاء الاشتراك تتاح للعميل نافذة 30 يومًا لتصدير بياناته، ثم تُحذف البيانات نهائيًا خلال مدة لا تتجاوز 90 يومًا من انتهاء الاشتراك.
بيانات نماذج الموقع: حتى انتهاء الغرض الذي جُمعت له أو طلبك حذفها، أيهما أسبق.
بيانات الفوترة والسجلات المالية: وفق مدد الحفظ التي توجبها الأنظمة المالية والضريبية المعمول بها.
11. أمن البيانات
نحمي البيانات بتشفيرها أثناء النقل وفي حالة التخزين، ونطبّق ضوابط وصول صارمة على مبدأ الحد الأدنى من الصلاحيات، فلا يطّلع على بيانات العملاء المحتملين إلا من يحتاج ذلك لتشغيل الخدمة. ونراجع إجراءاتنا الأمنية دوريًا، وفي حال وقوع حادث تسرب يمس بياناتك نلتزم بالإشعار وفق ما يوجبه النظام ولوائحه.
12. حقوقك بموجب النظام
يكفل لك نظام حماية البيانات الشخصية حقوقًا واضحة، ونحن نلتزم بتمكينك منها: حقك في العلم بكيفية معالجة بياناتك، وفي الوصول إليها، وفي الحصول على نسخة منها بصيغة واضحة، وفي طلب تصحيحها أو تحديثها، وفي طلب إتلافها (حذفها)، وفي سحب موافقتك في أي وقت.
كيف تمارس حقوقك؟ راسلنا على privacy@[الدومين] (TODO: domain) وسنستجيب لطلبك خلال مدة لا تتجاوز 30 يومًا من استلامه. وإذا كنت «عميلًا محتملًا» تواصلت معك «مي» نيابة عن إحدى المنشآت، فجهة التحكم في بياناتك هي تلك المنشأة؛ يمكنك التوجه إليها مباشرة، أو مراسلتنا وسنحيل طلبك إليها فورًا ونساعدها على تنفيذه.
13. الشكاوى والتصعيد
إذا لم يرضك تعاملنا مع طلبك أو رأيت أننا أخللنا بالتزاماتنا، نرجو أن تمنحنا فرصة المعالجة أولًا عبر privacy@[الدومين] (TODO: domain). ويحق لك في جميع الأحوال تقديم شكوى إلى الجهة المختصة بالرقابة على تطبيق النظام: الهيئة السعودية للبيانات والذكاء الاصطناعي (سدايا).
14. بيانات القاصرين
خدمتنا موجهة للمنشآت والأعمال، وليست موجهة لمن هم دون الثامنة عشرة، ولا نجمع بياناتهم عن قصد. وإذا علمنا أننا جمعنا بيانات قاصر عن غير قصد، حذفناها دون تأخير.
15. التغييرات على هذه السياسة
قد نحدّث هذه السياسة من وقت لآخر لتواكب تطور الخدمة أو الأنظمة. عند أي تغيير جوهري سنشعرك مسبقًا عبر البريد الإلكتروني أو عبر إشعار واضح في المنصة قبل سريانه، مع تحديث تاريخ السريان أعلى هذه الصفحة. استمرارك في استخدام الخدمة بعد السريان يعني اطلاعك على النسخة المحدثة.
We wrote this policy to be read and understood — not to hide anything behind walls of legalese. It explains plainly what personal data we collect, why we collect it, how we protect it, and what your rights are under the Saudi Personal Data Protection Law (PDPL) and its Implementing Regulations.
Language clause: This policy is published in Arabic and English. The Arabic version is the original, authoritative text and prevails if the two versions ever differ.
1. Who we are
Mai is an AI sales assistant built and operated by C-01, a company based in the Kingdom of Saudi Arabia (Commercial Registration: TODO: CR number — registered address: TODO: registered address). For visitors to our website and for our customers' account data, C-01 is the "controller" within the meaning of the PDPL — the party that decides why and how personal data is processed.
2. Three groups of people, three different relationships
Not everyone interacts with Mai from the same position, so we distinguish clearly between three groups:
Site visitors: anyone browsing our website or filling out one of its forms.
Customers: the businesses that subscribe to the service, along with their account holders and users.
Leads: the people Mai talks to on behalf of our customers. Their data belongs to our customers, not to us — we process it strictly as a "processor" (see Section 5).
3. What we collect
We only collect what we actually need to run the service, and we list it here as it is:
From site visitors: when you book a demo or request a consultation, we collect your name, email, WhatsApp or phone number, company name, company size, and a free-text description of the sales challenge your business is facing.
From customers: account and contact details of the company's representatives, subscription and billing data, platform usage logs, and the connection settings for the customer's own WhatsApp Business account and email. The connected accounts remain the customer's property — they never become ours.
From leads (on behalf of the customer): the contact details the customer provides (such as name, WhatsApp number, and email), the content of conversations with Mai, qualification and follow-up status, and booked meetings.
4. Why we process data, and on what legal basis
Every processing activity has a defined purpose and a clear legal basis under the PDPL:
Contract performance (or steps to enter one): operating the service, managing your account, subscription, and billing, providing support, and responding to demo and consultation requests you submit yourself.
Consent: marketing communication with you after you fill out a form on our site. You can withdraw consent at any time, without affecting the lawfulness of processing done before withdrawal.
Legitimate interest (as the PDPL frames it): improving and securing the service and preventing abuse — limited to non-sensitive data, and always balanced so it does not prejudice your rights, interests, or reasonable expectations.
5. Leads' data: our role is processor
When Mai talks to your leads, the data is yours — not ours. The customer is the "controller" of its leads' data; C-01 is a "processor" acting on the customer's documented instructions under a data processing agreement. Obtaining lawful opt-in consent for outreach is the customer's responsibility as the owner of the account and the contact lists. All conversations are logged and visible to the customer in their dashboard, and we do not use them for our own purposes outside delivering the service.
6. AI disclosure and the right to stop
We don't hide that Mai is an AI, and we don't argue with anyone who asks her to stop. Mai discloses that she is an AI assistant on first contact with every lead. If anyone asks to stop receiving messages ("stop" or anything to that effect), we honor it immediately and permanently. And at this stage, a person on the customer's team reviews and approves every outgoing message before it is sent.
7. Cookies and analytics
Our website currently uses only the cookies that are technically necessary for it to function. We use no advertising trackers and build no behavioral profiles of visitors. TODO: analytics — if a basic, privacy-respecting analytics tool is added later, this section will be updated to name it before it goes live.
8. Who we share data with
We never sell your personal data, and we never trade in it. We share it only in these cases:
Service providers (subprocessors): such as cloud hosting, messaging infrastructure, and payment processing — all contractually bound to protect the data, process it only on our instructions, and meet at least the PDPL's requirements.
Competent authorities: where the law requires disclosure under a valid legal request.
9. Data leaving Saudi Arabia
Data is hosted primarily in TODO: hosting region. If operating the service requires transferring personal data outside the Kingdom or disclosing it to a party outside it, we do so only under the transfer conditions and controls set out in the PDPL (Article 29) and its Implementing Regulations, ensuring a level of protection no lower than the law provides.
10. How long we keep data
We keep data no longer than we actually need it:
Conversation logs and lead data: for the duration of the customer's subscription. After the subscription ends, the customer has a 30-day window to export their data, and the data is then permanently deleted no later than 90 days after the subscription ends.
Website form data: until the purpose it was collected for is fulfilled, or you ask us to delete it — whichever comes first.
Billing and financial records: for the retention periods required by applicable financial and tax regulations.
11. Security
We protect data with encryption in transit and at rest, and we enforce strict, least-privilege access controls — only people who need lead data to run the service can see it. We review our security practices regularly, and if a breach ever affects your data, we will notify as the PDPL and its regulations require.
12. Your rights under the PDPL
The PDPL gives you clear rights, and we are committed to honoring them: the right to be informed about how your data is processed, to access it, to obtain a copy of it in a clear format, to request correction or updating, to request destruction (deletion), and to withdraw your consent at any time.
How to exercise them: email us at privacy@[domain] (TODO: domain) and we will respond to your request within no more than 30 days of receiving it. If you are a lead whom Mai contacted on behalf of one of our customers, the controller of your data is that customer — you can go to them directly, or write to us and we will forward your request to them right away and help them fulfill it.
13. Complaints and escalation
If you are not satisfied with how we handled your request, or you believe we have fallen short of our obligations, we ask you to give us a chance to fix it first via privacy@[domain] (TODO: domain). In all cases, you have the right to lodge a complaint with the competent supervisory authority: the Saudi Data & Artificial Intelligence Authority (SDAIA).
14. Children's data
Our service is built for businesses. It is not directed at anyone under 18, and we do not knowingly collect their data. If we learn we have collected a minor's data unintentionally, we delete it without delay.
15. Changes to this policy
We may update this policy from time to time as the service or the law evolves. For any material change, we will notify you in advance by email or a clear notice in the platform before it takes effect, and update the effective date at the top of this page. Continuing to use the service after the change takes effect means you have seen the updated version.
16. Contact us
For any question or request about privacy and personal data: