Privacy policy
Last updated · 5 June 2026
This policy explains what personal data we collect, why, and how we protect it. It is written under the Saudi Personal Data Protection Law (PDPL) and the implementing regulations issued by the Saudi Data & AI Authority (SDAIA). If any clause here diverges from the law, the law controls.
Data controller
The entity responsible for processing your personal data under this policy is Kafu Technologies (Saudi limited liability company, Commercial Registration No. [CR-PENDING]), based at Riyadh, Kingdom of Saudi Arabia — [full street address pending legal review].
For privacy queries: privacy@kafuapp.com. For data subject requests (access, rectification, erasure, portability, objection): dsr@kafuapp.com.
Categories of personal data
We collect the following categories of personal data, depending on how you use the platform:
- Account data: name, email address, mobile number, profile photo, hashed password.
- Tenant data (business customers): legal name, Commercial Registration number, VAT number, billing address.
- Survey response data: your answers and any demographic fields the survey publisher elected to collect (age, gender, region, nationality, income, etc.).
- Verified panel data: for members of the Kafu verified panel, we retain identity-verified profile data to ensure sample quality and disburse rewards.
- Technical data: IP address, browser and OS type, device identifier, session timestamps, error logs.
- Payment data (subscribers): processed directly by SAMA-licensed payment providers; we retain only the last four digits of the card and the transaction reference.
- Communications data: support message content, in-product chat, tickets, and recorded calls (with consent).
We do not collect sensitive personal data (PDPL Art. 1) — health, religious, or ethnic data — except when professionally necessary and on an explicit legal basis. When a tenant collects sensitive data from respondents through a survey, the tenant is the controller and is responsible for obtaining explicit consent; we process such data as a "processor" under the terms of the Data Processing Addendum.
Purposes & lawful basis
We process your personal data for the following purposes, each with a stated lawful basis under PDPL Article 6:
- Operating the platform and delivering its services — Basis: performance of the contract with you (Art. 6/1/b).
- Issuing tax invoices and collecting payments — Basis: legal obligation under ZATCA regulations (Art. 6/1/c).
- Sending service notifications and security alerts — Basis: contract performance and our legitimate interest in securing your account (Art. 6/1/f).
- Aggregated, de-identified usage analytics to improve the product — Basis: legitimate interest (Art. 6/1/f).
- AI-assisted survey generation and analysis — Basis: contract performance (Art. 6/1/b). See the AI use disclosure for processing details.
- Optional marketing messages — Basis: your explicit consent, which you may withdraw at any time (Art. 6/1/a).
- Compliance with court orders and lawful investigations — Basis: legal obligation (Art. 6/1/c).
- Defending vital interests (e.g. cyber-incidents that threaten users) — Basis: vital interest (Art. 6/1/d).
Cross-border transfer
Your data is stored inside the Kingdom of Saudi Arabia by default, in data centers approved by the competent authorities. Cross-border transfer happens in only two specific cases:
- AI features: when you invoke a feature that uses an AI model, the prompted content is sent to our AI model provider in the United States over a secured API (TLS 1.2+). The transfer is protected by contractual safeguards equivalent to Standard Contractual Clauses (SCCs), under PDPL Article 29 and SDAIA controls.
- Engineering support: our team may access data necessary to resolve a specific support ticket from outside the Kingdom, under strict confidentiality agreements and full audit logging.
We do not transfer survey response data or verified panel data outside the Kingdom for storage or analytics. You may request a complete log of past transfers of your data via the DSR mailbox.
Your data subject rights
PDPL grants you the following rights over your personal data. Kafu commits to honoring them free of charge within 30 days of your request:
- Right to be informed: know who we are, what we collect, and why — this policy is our formal disclosure.
- Right of access: we provide a full copy of your personal data held by us, in a readable format.
- Right of rectification: correct inaccurate or incomplete data.
- Right of erasure: have your data deleted, subject to overriding legal obligations (e.g. ZATCA requires retention of tax invoices for 10 years).
- Right of restriction: pause processing while we review an objection or request.
- Right of portability: receive your data in a structured, machine-readable format and transfer it to another provider.
- Right to object: object to processing based on legitimate interest, including direct marketing.
- Right to withdraw consent: revoke any consent previously given (e.g. marketing opt-in or sensitive-data collection), without affecting prior lawful processing.
- Right to complain: lodge a complaint directly with the Saudi Data & AI Authority (SDAIA) at https://sdaia.gov.sa if you believe we have not handled your request properly.
To exercise any of these rights: email dsr@kafuapp.com from the address registered to your account, stating the type of request. We verify your identity before fulfilling access or erasure requests, to protect your data.
Retention periods
Different categories of data are retained for specific periods, after which they are deleted or de-identified:
- Active account data: for the life of the account + 90 days post-closure (to allow accidental-closure recovery).
- Survey response data: as configured by the publishing tenant, up to a maximum of 5 years from survey close.
- Tax invoices and transaction records: 10 years (ZATCA obligation).
- Support records: 24 months from ticket closure.
- Security logs: 18 months, with defined extensions for active investigations.
- Backups: 35-day rolling retention, then physically deleted.
Security
We apply technical and organizational controls proportionate to the risk, including:
- Encryption at rest (AES-256) and in transit (TLS 1.2+).
- Role-based access control (RBAC) and environment separation (prod/test).
- Mandatory two-factor authentication for any administrative access, with full audit logging.
- Periodic security reviews and annual penetration testing by an independent third party.
- Incident response plan; notification to SDAIA and affected data subjects within 72 hours of any material incident discovery.
To report a security vulnerability: security@kafuapp.com. We commit to acknowledging within 24 hours.
Data Protection Officer
We have appointed a Data Protection Officer per regulatory requirements. Contact: privacy@kafuapp.com. For data subject requests: dsr@kafuapp.com.
If we do not respond to your request satisfactorily, you have the right to file a complaint with the Saudi Data & AI Authority (SDAIA) at https://sdaia.gov.sa.
Changes to this policy
We may update this policy from time to time. For any material change, we notify you by email and via an in-product banner at least 30 days before the change takes effect. The last update date is shown at the top.