ServicesScorecardResourcesAboutContact
AR

Legal

Privacy Notice

Last updated: 18 May 2026

01

Who We Are

Profectus (profectus.sa) is a KSA AI governance advisory operating under Saudi law. We provide structured AI governance engagements to Saudi private sector organisations.

02

What We Collect

Contact name, company name, role, email address, and questionnaire responses submitted via the scorecard or contact form. We do not collect any other personal data.

03

How We Use It

To respond to enquiries, generate your scorecard report, and — only with your explicit consent — to contact you about our services. We do not sell, licence, or share personal data with third parties for their own purposes.

04

Legal Basis

Processing is based on Article 6(4) of the Executive Regulations of the Personal Data Protection Law (PDPL): data collected directly from the individual for a purpose they have initiated. Marketing communications require explicit consent, which you may withdraw at any time by emailing privacy@profectus.sa.

05

Sub-Processors

We use the following third-party processors. All personal data transferred outside Saudi Arabia is governed by Standard Contractual Clauses in the form approved by SDAIA.

ProcessorPurposeLocation
Vercel Inc.Hosting & serverless computeUSA
Make.com (Celonis SE)Workflow automation & notificationsCzech Republic
HubSpot Inc.CRM & contact managementUSA
Cloudflare Inc.CDN, DNS, bot protection, CAPTCHAUSA

Where AI-assisted portal features are active, additional processors apply:

ProcessorPurposeLocation
Anthropic PBCAI model inferenceUSA
Supabase Inc.Database & authenticationUSA
Clerk Inc.User identity managementUSA
06

Retention

Data CategoryPeriodBasis
Contact enquiries12 monthsLegitimate interest
Scorecard responses30 daysPurpose fulfilment
Engagement records5 yearsZATCA — statutory minimum
Invoice data5 yearsZATCA Article 66
Security logs30 daysOperational necessity
Marketing consent records3 years or until withdrawnPDPL consent accountability
07

Your Rights

Under PDPL Articles 4–8 and the Executive Regulations, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion
  • Object to processing
  • Data portability — receive your data in a machine-readable format

We will respond within 30 days. To exercise any right, contact privacy@profectus.sa. If you are dissatisfied with our response, you may lodge a complaint with SDAIA via the National Data Governance Platform at ndgp.sdaia.gov.sa.

08

No Cookies

This website does not use cookies or tracking scripts of any kind. No analytics platform is installed. No consent banner is required.

09

Changes to This Notice

We may update this notice periodically. The “Last updated” date at the top of this page reflects the most recent revision. Material changes will be communicated by email where we hold your address.

Privacy Contact

For any privacy-related request, enquiry, or complaint, please contact: privacy@profectus.sa