Privacy Policy — the ARK47 Platform
Version 1.0 — 18 September 2026
This English text is a convenience translation. This Policy was drawn up in Arabic and the Arabic text is the authoritative one; any translation is for convenience only.
APEX Operations Company
A single-person limited liability company — Unified Commercial Registration Number: 7051961980 — Tax Registration Number: 314285795400003
Address: Riyadh, King Salman District, Ibn Zaydan Street, Postal Code 12443, Kingdom of Saudi Arabia
Data Protection Officer: [email protected]
Version: 1.0 — Effective date: 7/4/1448H corresponding to 18/9/2026
1. Scope of this Policy — read this section first
1.1 Purpose. This Policy sets out how APEX Operations Company (the "Company" or "we") collects, processes, retains and destroys personal data in its capacity as Controller, your rights in respect of it and how to exercise them, in implementation of what the Personal Data Protection Law issued by Royal Decree No. (M/19) dated 9/2/1443H and its Implementing Regulations require by way of publishing a privacy policy and making it available to data subjects before their data is collected. This Policy is made available before your data is collected, is displayed to you at registration before it is completed, and your review of it is documented in accordance with Clause 5.2 of the Terms and Conditions.
1.2 Who this Policy addresses. This Policy addresses:
- (a) visitors to the ark47.ai website and those who contact us through it;
- (b) representatives of Customers and their Authorised Users who create accounts on the Platform or use it;
- (c) those who contact our sales or support teams, subscribe to our mailing lists, or take part in our events;
- (d) applicants for employment with us, as regards application data.
1.3 Who this Policy does not address — an important notice. Our Customers are establishments that use the Platform to configure and operate their Applications. The personal data that our Customers enter into their Applications or collect through them — such as the data of their employees, their End Users, their contacts, their correspondence and their calls — is data of which the Customer is the Controller, and which we process on its behalf and in accordance with its instructions in our capacity as Processor. If you are a customer or an employee of one of our Customers, the privacy notice that governs your data is that Customer's notice, and you should approach it to exercise your rights; we refer to it without delay any request that reaches us from you. Section (16) of this Policy sets out how we process that data in our capacity as Processor.
1.4 Supplementary documents. This Policy is read together with: the General Terms and Conditions of Use of the ARK47 Platform and the Personal Data Processing Addendum contained in them, the Sub-processor List, which we provide to Customers on request, and the terms and conditions and the privacy policy of the customer relationship management system where applicable.
2. Who we are and how to contact us
2.1 The Controller. APEX Operations Company, a Saudi limited liability company registered under Unified Number 7051961980, whose head office is at Riyadh, King Salman District, Ibn Zaydan Street, Postal Code 12443.
2.2 Contact for data protection. The Company has designated a point of contact for personal data protection matters, who may be contacted at [email protected], or at the postal address above marked for the attention of the "Data Protection Officer".
2.3 Channels for exercising rights. You may exercise the rights set out in Section (10) by writing to [email protected].
3. The legal framework
We process personal data in accordance with the Personal Data Protection Law and its Implementing Regulations, the Regulation on Personal Data Transfer outside the Kingdom issued by the Saudi Data and Artificial Intelligence Authority, the E-Commerce Law issued by Royal Decree No. (M/126) dated 7/11/1440H and its Regulation as regards the data of those dealing electronically, the Anti-Cyber Crime Law, and all other laws in force in the Kingdom of Saudi Arabia. We are guided by the artificial intelligence ethics principles and the controls issued by the Saudi Data and Artificial Intelligence Authority as regards the use of artificial intelligence technologies.
4. The data we collect and how we collect it
4.1 Data you provide to us directly.
| Category | Examples | Mandatory or optional |
|---|---|---|
| Account and registration data | Name, e-mail address, mobile number, the name of the establishment and its commercial registration number, job title, password (encrypted) | Mandatory in order to create the account |
| Establishment verification data | Commercial registration or licence number, tax number, national address, the details of the authorised representative | Mandatory in order to activate a paid subscription |
| Billing and payment data | Invoice details and the payment method (processed by the licensed payment service provider; we do not store full card numbers) | Mandatory for a paid subscription |
| Correspondence and support | The content of support requests and of correspondence with us | Mandatory to the extent necessary to handle your request |
| Support call recordings | Recording of telephone calls with the support team — after notifying you before the recording begins — in order to document requests and assure quality; you may object and use a written channel instead | Optional |
| Marketing data | Communication preferences, subscription to newsletters | Optional |
| Recruitment data | Curriculum vitae and application data | Mandatory in order to consider your application; the only consequence of not providing it is that the application cannot be considered |
4.2 Data collected automatically when the website or the Platform is used. Internet Protocol address; device, browser and operating system type; the pages and features used and the times of use; event and error logs; the electronic acceptance data for the Terms (the date, the time, the Internet Protocol address, the version number and its digital fingerprint); cookies and similar technologies (Section 13); and the metering and consumption data necessary for billing.
4.3 Data we receive from third parties. Commercial registration and commercial identity verification data from the available government bodies and platforms, payment confirmations from payment service providers, and data from our partners where you have authorised them to share it with us.
4.4 Data we do not collect and do not request. We do not request, for our own purposes, any sensitive data (such as health, biometric, belief-related, ethnic-origin or criminal-record data), and we do not knowingly collect the data of minors. If data of this kind reaches us without being requested, we destroy it unless the law requires otherwise.
5. Why we process your data and on what legal basis
5.1 The rule. We do not process your personal data except for a specific and legitimate purpose, on one of the legal bases prescribed by the Personal Data Protection Law, and to the minimum extent necessary to achieve the purpose.
5.2 Table of purposes and bases.
| Purpose | Legal basis |
|---|---|
| Creating and administering your account and verifying your establishment and its representative | Where you are the contracting party: performance of the agreement to which you are a party; and where you act as a representative of your establishment or as a user within it: the Company's legitimate interest in managing its contractual relationship with your establishment and in securing the Platform, with a documented balancing assessment (Clause 5.3) |
| Providing the Services, operating the Platform and making technical support available | The same basis as that set out in the preceding row |
| Recording support calls in order to document requests and assure quality | Legitimate interest, with notification before the recording begins and the ability to object |
| Billing, collecting the Fees, issuing electronic invoices and keeping accounting records | Compliance with a legal obligation (the zakat, tax and customs laws and the laws on keeping commercial books and records), and performance of the agreement with your establishment |
| Documenting your acceptance of the Terms and exercising and defending our rights | The Company's legitimate interest, and compliance with the requirements of the Electronic Transactions Law |
| Protecting the security of the Platform, preventing fraud and misuse, and complying with the Anti-Cyber Crime Law | Legitimate interest and compliance with a legal obligation |
| Measuring usage, improving the Platform and analysing performance (in aggregated form where possible) | Legitimate interest |
| Sending operational and statutory notifications (such as amendment of the Terms, invoices and security alerts) | Performance of the agreement and compliance with a legal obligation |
| Direct marketing and newsletters | Your express and separate consent (Section 15) |
| Responding to the requests of the competent authorities | Compliance with a legal obligation |
| Considering applications for employment | Your express consent, and the Company's legitimate interest in evaluating candidates |
5.3 Legitimate interest. Where we rely on legitimate interest, we document an assessment balancing our interest against your rights and interests; we do not rely on it in any case for the processing of any sensitive data, nor where the effects of the processing on your rights outweigh it.
5.4 Consequences of not providing the data. If you do not provide the data marked as mandatory in Section (4), we will not be able to create your account, activate your subscription, issue your invoices or provide you with support. As for optional data, the only consequence of not providing it is that the feature associated with it will not be available.
5.5 Consent and its withdrawal. Where we rely on your consent, it is requested from you separately from acceptance of the Terms and for a specific purpose, and you may withdraw it at any time by writing to [email protected] without this affecting the lawfulness of the processing that preceded the withdrawal.
6. Artificial intelligence and automated decisions
6.1 The Platform relies on generative artificial intelligence technologies. As regards your data in your capacity as a representative of the Customer or an Authorised User, we do not take any automated decision producing a material legal or contractual effect on you without human intervention, save for automated security measures (such as stopping suspicious sign-in attempts), which you may object to and have reviewed by a natural person by contacting us.
6.2 We do not use the personal data of your account to train general artificial intelligence models. The use of Inputs and of structural metadata to improve the Platform is governed by what is set out in Clause 9.9 of the Terms and Conditions, and takes place after anonymisation such that the data cannot — by any reasonable means — be linked to any natural person.
6.3 Where you interact with automated systems of ours (such as the automated support assistant), we disclose that to you at the start of the interaction and make a natural person reachable to you.
7. With whom we share your data
7.1 The rule. We do not sell or rent your personal data, and we do not disclose it except to the categories set out below and to the extent necessary for the purpose.
7.2 Sub-processors. We engage service providers who process data on our behalf under written agreements binding them to confidentiality and to a level of protection no lower than our own obligations. We do not publish their names; the list — with each provider's name, the purpose of the engagement, its location and its country of processing — is provided to our Customers in writing on request. The categories are:
| Category | Country of processing |
|---|---|
| Infrastructure, hosting, the production database and backups | Kingdom of Saudi Arabia — Riyadh region |
| Content delivery, protection against attacks and domain names | A global edge network |
| Storage of uploaded files | United States of America |
| Databases of the Applications our Customers publish | United States of America |
| Artificial intelligence model providers | United States of America and the People's Republic of China |
| Outbound e-mail and sign-in with a Google account | United States of America |
| Collecting the Fees and processing payments | Kingdom of Saudi Arabia, and the United States and Ireland |
We do not currently use any third-party analytics or measurement tool, and we use no messaging channel other than e-mail. If we add any, this Policy and the Sub-processor List are updated.
7.3 Other parties. We may disclose your data: (a) to the competent governmental, judicial and regulatory authorities upon their request in accordance with the law; (b) to our legal advisers, accountants and auditors who are bound by confidentiality; (c) to our successor in the business in the event of a merger, an acquisition or a transfer of assets, with notification to you and with your data remaining subject to this Policy or to a policy no less protective than it; (d) to any other party with your consent.
7.4 Payment service providers. Payment method data are processed by the payment service provider in accordance with its own policy, and we do not retain full card numbers. What is collected inside the Kingdom is processed by a payment service provider licensed by the Saudi Central Bank; subscriptions collected by card outside the Kingdom are processed by an international payment service provider identified in the Sub-processor List, and that entails the transfer of payment data outside the Kingdom in accordance with Section (8).
8. Transfer of data outside the Kingdom
8.1 Disclosure. Providing the Services may require some of your personal data to be processed by Sub-processors whose premises or servers are outside the Kingdom of Saudi Arabia, as set out in Section (7.2) and in the Sub-processor List, which states the country of processing for each of them.
8.2 Controls. We do not transfer personal data outside the Kingdom except: (a) to the minimum extent necessary to achieve the purpose; (b) in a manner that does not prejudice the national security or the vital interests of the Kingdom; (c) under the mechanisms permitted by the Regulation on Personal Data Transfer outside the Kingdom, among them the standard contractual clauses and appropriate contractual safeguards, and after carrying out a risk assessment where the Regulation requires one and documenting it; (d) or to a country included by the competent authority in the list of countries with an adequate level of protection, once that list is issued. You may request information about the safeguards applied through the Data Protection Officer.
8.3 Subjection to foreign laws. We disclose that some of our Sub-processors are subject to the laws of other countries, which may affect the level of protection, and that we have contracted with them for appropriate contractual safeguards to address this.
9. Retention periods and the method of destruction
9.1 The principle. We retain personal data for the period necessary to achieve the purpose for which it was collected, and then destroy it without undue delay, unless the law requires it to be retained for a longer period.
9.2 Table of periods.
| Data category | Retention period | Basis |
|---|---|---|
| Account and registration data | The Subscription Term, then the Retrieval Window (60 days), then deletion within 30 days, and from the backups within a further 90 days | Contractual |
| Electronic acceptance records for the Terms | The Subscription Term, then throughout the limitation period prescribed by law for bringing claims (10 years) | Preserving evidence of contracting and defending rights |
| Metering and consumption data | The Subscription Term, then with the accounting records to the extent necessary for billing | Contractual / legal obligation |
| Support call recordings | 12 months from the date of the call | Legitimate interest |
| Invoices and accounting and tax records | For the period imposed by the zakat, tax and customs laws and the laws on keeping commercial books and records, and then destroyed | Legal obligation |
| Support correspondence | 3 years from the closure of the request | Legitimate interest / defence of rights |
| Security and access logs | 12 months, unless they relate to a security incident being handled | Legitimate interest / legal obligation |
| Marketing data | Until consent is withdrawn, or 24 months from the last interaction | Consent |
| Recruitment data | 12 months from the closure of the vacancy unless you agree to a longer period | Consent |
| Breach notification records and processing records | 5 years after the end of the processing | Legal obligation |
9.3 The method of destruction. We destroy data by methods that prevent its retrieval, among them: secure deletion from the operational databases, the expiry of backups according to their defined cycle, the destruction of encryption keys where they are used, and the physical destruction of media when taken out of service. Where destruction is not technically possible immediately (such as archived backups), we isolate the data from use until it is destroyed at its due time.
9.4 Anonymisation. We may retain anonymised data that cannot by any reasonable means be linked to you, for statistical and development purposes, without a time limit.
10. Your rights and how to exercise them
10.1 Your rights under the Personal Data Protection Law.
| Right | What it means |
|---|---|
| The right to be informed | To be informed of the legal basis for collecting your data and of the purpose of it, and that your data will not be processed for a purpose other than that for which it was collected except in accordance with the law |
| The right of access | To view your personal data held by us |
| The right to obtain the data | To obtain a copy of your data in a clear and legible format, and where possible in a machine-readable format |
| The right to correction | To request the correction, completion or updating of your data |
| The right to destruction | To request the destruction of your data once it is no longer needed, having regard to what the law requires to be retained |
| The right to withdraw consent | Where the processing is based on your consent (in accordance with the consent provisions of the Law and its Implementing Regulations) |
10.2 Exercise. Submit your request through the channels set out in Section (2), stating your identity and the nature of your request. We may ask you for what is necessary to verify your identity, in order to protect your data.
10.3 The period. We answer your request within thirty (30) days of receiving it, and the period may — in complex cases or where requests are numerous — be extended by a like period, with notification to you of that and of its reasons, unless the Regulations prescribe a shorter period, in which case we comply with it.
10.4 No fees and no adverse effect. Exercising your rights is free of charge, unless the request is manifestly repetitive or excessive, in which case a reasonable fee may be requested or the request refused with a statement of the reason. Exercising your rights has no adverse effect on your dealings with us.
10.5 Limits. We may decline to meet the request in whole or in part where the law so requires, such as protecting the rights of others or complying with a legal obligation to retain, or where the request relates to data we process in the capacity of Processor for a Customer (Section 16), in which case we refer the request to the Customer concerned.
10.6 Complaints. If you are not satisfied with our handling of your request, you may escalate to the Data Protection Officer, and you may lodge a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA) as the competent authority, through its official channels.
11. Data security
We apply appropriate organisational, administrative and technical measures to protect personal data, guided by recognised practices, among them the Essential Cybersecurity Controls issued by the National Cybersecurity Authority to the extent applicable, and comprising: encryption in transit and at rest, multi-factor authentication for access, permission control on a need-to-know basis, logical separation between Customers' workspaces, logging and monitoring, backup, vulnerability and update management, and our employees' obligation of confidentiality. Responsibility for protecting your sign-in credentials and for enabling multi-factor authentication rests with you.
12. Data breach incidents
In the event of an incident of leakage, destruction or unlawful access affecting your personal data that we process in the capacity of Controller, we notify the competent authority within seventy-two (72) hours of becoming aware of it, in accordance with what the Regulations prescribe, and we notify you without undue delay if the incident would harm your data, your rights or your interests, stating the nature of the incident, its likely effects, the measures taken and what is advised to be done.
13. Cookies and similar technologies
We use only the cookies that are necessary for operating the website and the Platform — session, security and preference cookies. These do not require your consent, because the Platform cannot be provided without them.
We do not currently use analytical or marketing cookies, and we do not use any third-party analytics or measurement tool. Should we introduce any, we will not activate it before obtaining your consent through a consent panel, and this Policy will be updated first.
You may manage cookies at any time through your browser settings, noting that disabling the necessary cookies may affect the operation of the Platform.
14. Minors
Our services are directed at establishments and are not aimed at minors, and we do not knowingly collect the data of minors. If we learn that the data of a minor has been collected without the necessary legal basis, we destroy it.
15. Direct marketing
15.1 We do not send you marketing messages or make promotional calls to you except with your express and separate consent, and your acceptance of this Policy or of the Terms and Conditions does not constitute consent to receive marketing, in compliance with the controls on unsolicited messages and calls issued by the Communications, Space and Technology Commission.
15.2 Every marketing message includes identification of the sender and an easy means of unsubscribing, and we stop sending within twenty-four (24) hours of your request and confirm that to you. We do not send promotional messages at the times prohibited by the controls.
15.3 We may send you — without marketing consent — the operational and statutory notifications necessary to perform the agreement or to comply with a legal obligation.
16. Data we process in the capacity of Processor on behalf of our Customers
16.1 The role. This Policy does not create any obligation on us towards you in the capacity of Controller in respect of what we process on behalf of our Customers; this Section is a transparency statement about what we do in the capacity of Processor, and the corresponding obligations fall on the Customer as Controller. When our Customer uses the Platform to configure and operate its Applications, the personal data that it enters or collects (the data of its employees, its End Users, its contacts, its correspondence and its calls) is data of which the Customer is the Controller, and which we process on its behalf and in accordance with its documented instructions, under the Personal Data Processing Addendum contained in the Terms and Conditions, which sets out the purpose, the categories, the duration, our security obligations, incident notification, Sub-processors, transfer outside the Kingdom, and deletion at the end of the subscription.
16.2 What we do not do. We do not use that data for our own purposes, we do not take decisions in respect of it, we do not disclose it to others except in accordance with the Customer's instructions or by order of a competent authority, and we do not use it to train artificial intelligence models.
16.3 If you are a data subject held by one of our Customers. Direct your request to that Customer, as it is the party that determines the purposes and means of the processing and that determines the privacy notice applicable to you. If your request reaches us directly, we refer it to the Customer within five (5) Business Days and inform you of that, and we do not answer it ourselves except to the extent that the law requires.
16.4 AI Agents. If you deal with an AI Agent operated by one of our Customers on the Platform, that agent acts in the Customer's name and on its behalf, and the Customer is responsible for disclosing its automated nature to you and for what issues from it.
17. Amendment of this Policy
We may amend this Policy to keep pace with legal or operational changes. We publish the amended version together with its version number, its effective date and a summary log of the changes, and we notify account holders of material amendments at their registered e-mail address and through the Platform at least thirty (30) days before they take effect. If an amendment requires your consent (such as the addition of a new purpose of processing), we request it from you separately before the processing begins.
18. Contact and complaints
| Channel | Details |
|---|---|
| Data Protection Officer | [email protected] |
| General support | [email protected] |
| Legal notices | [email protected] |
| Postal address | APEX Operations Company — Riyadh, King Salman District, Ibn Zaydan Street, 12443 |
| The competent authority | The Saudi Data and Artificial Intelligence Authority (SDAIA) — through its official channels |
The complaints route: (1) submit your complaint to the Data Protection Officer, and we respond to you within fifteen (15) Business Days; (2) if it is not resolved, you may escalate to the Company's senior management at [email protected]; (3) and you have, in all cases, the right to lodge a complaint with the competent authority.
Severability: If any provision of this Policy is adjudged void, the remaining provisions remain in force.
APEX Operations Company — Unified Number 7051961980 — Tax Number 314285795400003 — Riyadh, King Salman District, Ibn Zaydan 12443