Privacy Policy
MyAdvisior.AI — operated by [COMPANY_LEGAL_NAME] (CR [CR_NUMBER]), [REGISTERED_ADDRESS].
Effective date: [EFFECTIVE_DATE]
Draft for legal review. This policy is written to align with Saudi Arabia's Personal Data Protection Law (PDPL) and, where EU/EEA/UK data subjects are served, the GDPR/UK GDPR. It is a template and must be finalized by qualified counsel before publication. See
legal/README.md.
1. Who we are and our roles
[COMPANY_LEGAL_NAME] operates MyAdvisior.AI. For the personal data of our account holders and billing contacts, we act as a Controller. For personal data contained in Customer Content that a Customer uploads or processes within its Workspace (e.g. data about the Customer's own clients and matters), we act as a Processor on the Customer's behalf, governed by the Data Processing Agreement.
Privacy contact: [PRIVACY_EMAIL] · Data Protection Officer / privacy contact: [DPO_NAME_AND_CONTACT].
2. Personal data we collect
You provide:
- Account & profile: name, email, password (hashed), display name, organization/Workspace name, tenant type (individual, law firm, company, etc.), data-residency selection, locale, MFA secrets (encrypted).
- Billing: plan, subscription status, and payment metadata processed by our payment provider (we do not store full card numbers).
- Customer Content: documents and records you upload or create (contracts, cases, matters, etc.), which may contain personal data you are responsible for.
- Support & communications: messages you send us.
Collected automatically:
- Usage & device data: log data, IP address, user-agent, request metadata, and feature/usage counters used for security, rate-limiting, quota enforcement, and service operation.
- Cookies/local storage: see the Cookie Policy. The mobile apps store authentication tokens in the device secure keystore.
We do not sell personal data.
3. How and why we use personal data (purposes & legal bases)
| Purpose | Examples | PDPL / GDPR basis (to confirm) |
|---|---|---|
| Provide the service | Authenticate, run AI queries, store/retrieve your content | Performance of a contract |
| Billing | Manage subscriptions, enforce quotas | Performance of a contract |
| Security & abuse prevention | MFA, rate-limiting, audit logging, fraud prevention | Legitimate interests / legal obligation |
| Support | Respond to requests | Performance of a contract / legitimate interests |
| Service improvement | Aggregate/operational metrics (not used to train third-party models on your content without a lawful basis) | Legitimate interests |
| Legal compliance | Respond to lawful requests, keep records | Legal obligation |
| Marketing (opt-in) | Product updates where you have consented | Consent |
We do not use Customer Content for purposes other than providing the service, except as instructed by the Customer or required by law.
4. AI processing
When you use AI features, your query and the retrieved legal-corpus context are processed to generate a cited answer. Where a third-party AI provider is used, the relevant input is transmitted to that provider under its data-processing terms. [Confirm the provider, its retention, and whether content is used for model training; state the truthful position here.] The Platform is designed so that answers are grounded in reviewed, published legal sources and presented with citations, a confidence score, and the provider used — never silently fabricated.
5. Sharing and sub-processors
We share personal data only with:
- Sub-processors that help us run the service (e.g. cloud hosting, object storage, email, payment
processing, error tracking, AI provider), under data-processing terms. A current list is at
[SUBPROCESSOR_LIST_URL]. - Authorities, where required by valid legal process.
- A successor in a merger/acquisition, subject to this policy.
We do not share Customer Content between tenants. The Platform enforces tenant isolation at the database level (row-level security) so one Customer cannot access another Customer's data.
6. International transfers & data residency
The Platform offers a data-residency selection (KSA, GCC, or Global). [State the actual hosting region(s).] Where personal data is transferred outside the Kingdom, we rely on a lawful transfer mechanism (e.g. an adequacy decision, appropriate safeguards, or your explicit consent) and, for EU/EEA data, Standard Contractual Clauses where required. (Confirm the actual transfer basis with counsel.)
7. Retention
We retain account and billing data for the life of the account and as required by law (e.g. tax/record retention). Customer Content is retained until you delete it or close the Workspace; on closure we delete or return it within a commercially reasonable period, subject to legal-retention requirements and backups, which expire on a rolling schedule. Audit and security logs are retained for a limited period for security and compliance.
8. Your rights
Subject to applicable law (PDPL and, where relevant, GDPR/UK GDPR), you may have rights to: access; obtain a copy/port your data; correct inaccurate data; delete data; restrict or object to certain processing; and withdraw consent. For Customer Content where we act as Processor, please direct requests to the relevant Customer (Controller); we will assist them as required by the DPA. To exercise rights regarding data we control, contact [PRIVACY_EMAIL]. You may also have the right to complain to a supervisory authority (in Saudi Arabia, the competent PDPL regulator; in the EU/UK, your local authority).
9. Security
We apply measures designed to protect personal data, including: encryption in transit; password hashing and encrypted MFA secrets; tenant isolation via database row-level security; role-based access control; rate-limiting; audit logging; private object storage for uploaded files; and operational monitoring. No system is perfectly secure; we do not claim any specific certification unless and until independently audited.
10. Children
The Platform is not directed to children and is intended for professional/business use by adults.
11. Changes
We may update this policy and will post the new effective date; material changes will be notified.
12. Contact
Privacy requests: [PRIVACY_EMAIL] · [COMPANY_LEGAL_NAME], [REGISTERED_ADDRESS]. EU/UK representative (if applicable): [EU_REPRESENTATIVE].