Last updated: July 2026
Saudi Arabia PDPL Notice: This policy is designed in alignment with the Kingdom of Saudi Arabia's Personal Data Protection Law (PDPL) and its Implementing Regulations, overseen by the Saudi Data & AI Authority (SDAIA). If you are a resident of the Kingdom, you have specific rights regarding your personal data as detailed in Section 12 of this policy.
This AI Assistant Privacy Policy ('AI Policy') governs the collection, processing, storage, and use of data generated when you interact with Elbetron's AI Assistant features and services ('AI Services'). This AI Policy supplements — and should be read alongside — our main Privacy Policy. By using our AI Services, you acknowledge that you have read, understood, and agreed to the practices described in this document. If you do not agree with any part of this AI Policy, please refrain from using the AI Services.
1. Scope of This Policy
This AI Policy applies specifically to all interactions you have with Elbetron's AI Assistant, including but not limited to: text-based chat conversations, voice queries and audio input, file uploads submitted for analysis, document processing requests, and any automated AI-generated responses you receive. This policy does not apply to third-party websites, products, or services that may be linked from our AI interface. We encourage you to review the privacy policies of any third-party services you access through our platform.
2. Data We Collect When You Use the AI Assistant
When you interact with the AI Assistant, we may collect and process the following categories of data:
- Conversation Content: All text messages, prompts, questions, and instructions you submit to the AI Assistant during a session.
- AI-Generated Responses: The outputs, answers, recommendations, and content generated by the AI in response to your queries.
- Session Metadata: Technical information such as session start/end timestamps, session duration, number of messages exchanged, and session identifiers.
- Device & Browser Information: IP address, browser type and version, operating system, screen resolution, and device identifiers, collected automatically for security and performance purposes.
- User Account Data (if authenticated): Your registered name, email address, organization name, and user role, used to personalize your AI experience and maintain usage history.
- Feedback & Ratings: Any explicit feedback, thumbs up/down ratings, correction requests, or comments you provide on AI responses.
- Error & Diagnostic Logs: Automatically generated logs that capture errors, failed queries, system warnings, and debugging information to ensure service stability.
- Usage Patterns: Aggregate, anonymized data about how features are used, which tools are accessed, and what types of queries are most common, used to improve the AI product.
- File & Document Metadata (if files are uploaded): File names, file types, sizes, and processing status — separate from the file content itself.
We do not sell, rent, or trade any of the data collected through your AI interactions to third parties for marketing or advertising purposes.
3. Data We Do NOT Collect or Store
To protect your privacy and minimize data exposure, our AI Assistant is designed with the following explicit exclusions:
- We do not retain the full content of your conversations long-term — it is encrypted at rest and permanently destroyed within 24 hours of your session, leaving only anonymised analytics.
- We do not use your conversations to train any AI model. Our models are pre-trained and run on our own servers, so your chats are never used for training — by us or anyone else.
- We do not collect biometric data such as facial recognition data, fingerprints, or retinal scans through our AI services.
- We do not intentionally collect special-category data such as racial or ethnic origin, political opinions, religious beliefs, health data, or sexual orientation. The assistant is instructed not to solicit such information, and we ask you not to share it.
- We do not record or store raw audio after it has been transcribed to text; the audio is discarded immediately.
- We do not share conversation content with third-party advertisers, data brokers, or analytics platforms in personally identifiable form.
4. How We Use Your Data
The data collected through your AI interactions is used strictly for the following purposes:
- Service Delivery: To generate accurate, relevant, and helpful responses to your queries in real time.
- Session Continuity: To maintain context within a single conversation session, enabling the AI to provide coherent and contextually appropriate follow-up answers.
- Service Improvement: To analyze anonymized and aggregated interaction patterns, identify gaps in AI knowledge or accuracy, and improve response quality over time.
- Safety & Content Moderation: To detect and prevent the generation of harmful, misleading, illegal, or policy-violating content, ensuring the AI behaves responsibly.
- Security Monitoring: To detect unauthorized access attempts, abuse of the AI system, prompt injection attacks, and other security threats.
- Legal Compliance: To fulfill obligations under applicable Saudi Arabian law, including the PDPL, as well as regulatory requests from competent authorities.
- Customer Support: To assist our support team in diagnosing and resolving issues you report regarding AI responses or service functionality.
- Analytics & Reporting: To generate internal performance reports about AI accuracy, user satisfaction, and service reliability — always in aggregated, non-identifiable form.
5. Voice & Audio Input Processing
If you use voice input features with our AI Assistant, the following practices apply:
- Your voice input is converted to text (speech-to-text transcription) in real time before being processed by the AI model.
- The resulting transcribed text is processed in exactly the same way as typed text input — subject to all the same protections described in this policy.
- Transcription is performed entirely on our own servers using a locally-hosted, open-source speech-recognition model (OpenAI Whisper). Your audio is never sent to any third-party provider.
- The temporary audio file is deleted immediately after transcription — whether it succeeds or fails. No audio is kept for review.
- You may disable voice input at any time, at which point no audio is captured or transmitted.
6. File & Document Uploads
When you upload files or documents to the AI Assistant for analysis, summarization, translation, or other processing tasks:
- Uploaded files are transmitted over encrypted HTTPS and processed entirely in memory. The file content is never written to our servers' storage.
- File content is used by the AI model solely to fulfil your specific request (e.g., summarizing, answering questions, translating).
- Because uploaded files are never stored on disk, there is no retention period — the content exists only for the moment it takes to answer your request, then is discarded.
- We do not use the content of your uploaded documents to train any AI model.
- Please do not upload files containing highly sensitive personal information of third parties (such as national ID numbers, medical records, or financial account details) unless you are authorized to share such data.
- Basic technical logs (not your file's content) may be kept for a limited period for security and audit purposes.
- We support standard document formats including PDF, DOCX, XLSX, PPTX, TXT, CSV, and common image formats. Files exceeding the maximum size limit are rejected and not stored.
7. Data Retention
We retain different categories of AI-related data for varying periods based on their purpose and our legal obligations:
- Conversation content: kept transiently and encrypted (AES-256-GCM) only long enough to produce anonymised analytics, then permanently destroyed within 24 hours of your session.
- Session Metadata & Logs: Retained for up to 12 months for security, analytics, and audit purposes, then securely deleted.
- User Account & Profile Data (dashboard users): Retained for as long as the account is active, plus a short period after deletion to allow for dispute resolution or legal holds.
- Anonymized & Aggregated Analytics Data: Retained in anonymized form for product improvement, as this data cannot be used to identify any individual.
- Legal Hold Data: Where data must be preserved due to a legal dispute, regulatory investigation, or court order, it may be retained solely for those legal purposes.
- Uploaded File Content: Never stored on disk — processed in memory and discarded immediately.
- Voice Audio: Not retained — the temporary file is deleted immediately after transcription.
- Security Incident Data: Data related to detected security threats, abuse patterns, or breaches may be retained for up to 3 years for forensic and legal purposes.
8. Data Storage & Geographic Residency
Elbetron's AI Assistant is fully self-hosted on infrastructure we control inside the Kingdom of Saudi Arabia:
- All customer conversation data is stored and processed on our own infrastructure located in the Kingdom of Saudi Arabia.
- No customer conversation data is processed by any external cloud or third-party AI service, and none is transferred outside the Kingdom for AI processing. All language, speech, and file processing happens locally on our own hardware.
- All data in transit is protected using TLS 1.2/1.3. Data at rest is protected with full-disk encryption plus application-level AES-256 encryption of message content.
- The only outbound data flow is transactional email (such as sign-in codes and invitations for dashboard users), sent via our email relay.
- If you are an enterprise customer with specific data-residency requirements, please contact us to discuss dedicated arrangements.
9. Personal Data Detection & Handling in AI Conversations
Because users may inadvertently include personal information in their AI queries, we have implemented the following protections:
- Automatic redaction: structured personal identifiers — email addresses, phone numbers, national ID / Iqama numbers, bank card numbers, and IBANs — are automatically detected and redacted from your messages before they are stored and before they are sent to the AI model.
- Redaction before storage: where a personal identifier is detected, it is redacted (e.g. replaced with [EMAIL] or [IBAN]) before the message is stored.
- User guidance: the assistant is instructed not to request sensitive personal data, and we encourage you not to share it.
- No Third-Party PII Sharing: personal data that appears in your conversations is never shared with third parties in identifiable form, except where required by law.
- Minimization Principle: we store and process only the personal data strictly necessary to fulfil your request.
- We do not intentionally process special-category data (such as health, religious, or political information).
10. Fully Self-Hosted AI — No Third-Party Providers
Elbetron's AI Assistant runs entirely on self-hosted, open-source models on hardware we control: a locally-run large language model (Qwen3, via llama.cpp) for text, a local speech-recognition model (Whisper) for voice, and local models for embeddings and document text-extraction. Your data is never sent to OpenAI, Google, Anthropic, or any other external AI provider — there is no third-party inference and no external model API in the pipeline. This is a deliberate design choice for data protection and offline capability.
11. Security Measures
We employ multiple layers of technical and organizational security measures to protect your AI interaction data:
- Encryption in transit: all traffic to the service is protected with TLS 1.2/1.3.
- Encryption at rest: full-disk encryption plus AES-256-GCM encryption of stored message content.
- Access controls: access to the analytics dashboard is restricted by role-based access control (RBAC) and requires multi-factor authentication (an email one-time code or an authenticator app).
- Abuse & prompt-injection protections: per-client request rate-limiting and a single-in-flight guard, plus grounding controls that keep the assistant on-topic.
- Fully local processing: because all AI processing happens on our own hardware, your data is never exposed to an external inference provider.
- DDoS protection: the service sits behind network-level DDoS mitigation.
12. Your Rights (Including PDPL Rights)
Depending on your location and applicable law, you have the following rights regarding your personal data processed through our AI services. Saudi Arabian residents have these rights under the PDPL:
- Right to Access: You have the right to request a copy of the personal data we hold about your AI interactions. You can also download it yourself at any time using 'Download my data' in the assistant's privacy settings.
- Right to Correction (Rectification): You have the right to request correction of any inaccurate or incomplete personal data we hold about you.
- Right to Deletion (Erasure): You have the right to permanent deletion of your data. You can delete your current conversation or all your data instantly using the assistant's privacy settings, or request deletion by email; we fulfil verified requests within 30 days.
- Right to Restrict Processing: You have the right to request that we restrict processing of your personal data while a dispute about its accuracy or legality is being resolved.
- Right to Data Portability: You have the right to receive your personal data in a structured, machine-readable format (JSON) — available instantly via 'Download my data'.
- Right to Object: You have the right to object to processing of your personal data for direct marketing or profiling.
- Right to Withdraw Consent: Where our processing is based on your consent, you have the right to withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
- Right Not to Be Subject to Solely Automated Decisions: If a decision that significantly affects you were based solely on automated processing, you have the right to request human review.
- Right to Lodge a Complaint: If you are a Saudi resident and believe your PDPL rights have been violated, you have the right to lodge a complaint with the Saudi Data & AI Authority (SDAIA).
To exercise any of the above rights, you can use the privacy controls built into the AI Assistant (Download my data / Delete this conversation / Delete all my data), or email [email protected] with the subject line 'AI Data Rights Request'. We verify your identity before processing and respond within 30 days.
13. Consent & Withdrawal
Before you start using the AI Assistant, we show you a data-processing notice and ask for your explicit, affirmative consent (a required checkbox). This consent is recorded with a timestamp and the version of the notice you agreed to, and processing does not begin until it is given. You can withdraw your consent at any time using 'Delete my data' in the assistant's privacy settings, which also deletes your conversation content. If you do not consent, please do not use the AI Services, as some processing is technically necessary to operate them.
14. Data Breach Notification
In the event of a personal-data breach affecting your AI interaction data, Elbetron will: (a) contain the breach and begin investigation immediately upon discovery; (b) notify the Saudi Data & AI Authority (SDAIA) in accordance with PDPL Article 20 and its Regulations where the breach is likely to cause harm; (c) notify affected users without undue delay where the breach is likely to result in a high risk to their rights or interests; (d) include in that notice a description of the breach, the data affected, the likely consequences, and the measures taken; and (e) keep an internal record of breaches. For any breach concern, contact [email protected].
15. AI Services & Minors
Our AI Assistant services are intended for use by individuals who are 18 years of age or older. We do not knowingly collect personal data from children under 18 years of age through our AI Services. If you are a parent or guardian and believe your child has interacted with our AI Assistant and provided personal data without your consent, please contact us immediately at [email protected] with the subject line 'Minor Data Removal Request'. We will promptly investigate and delete any data related to minors upon verified notification. We have implemented technical age-verification prompts during account registration; however, we acknowledge that determined users may misrepresent their age, and we rely on parents and guardians to supervise minors' internet use.
16. Changes to This AI Privacy Policy
We may update this AI Privacy Policy from time to time to reflect changes in our AI services, applicable laws, or industry best practices. When we make material changes, we will: (a) Post the updated policy on this page with a revised 'Last Updated' date. (b) Send an in-app notification or email to registered users at least 15 days before material changes take effect. (c) Where required by law (such as changes affecting how we process sensitive data or how we share data with third parties), we will seek your renewed consent before the new practices take effect. Your continued use of the AI Services after the effective date of any changes constitutes your acceptance of the updated policy. If you do not agree with the updated policy, you should discontinue use of the AI Services and request deletion of your data before the effective date.
17. Contact Us & Data Protection Officer
For any questions, concerns, or requests related to this AI Privacy Policy or to exercise your data rights, please contact us through any of the following channels:
- Email (General Privacy): [email protected]
- Subject Line for AI Policy Queries: 'AI Privacy Policy Inquiry'
- Data Rights Requests (Access, Deletion, Correction): [email protected] with subject 'AI Data Rights Request'
- Data Breach Reports (urgent): [email protected] with subject 'URGENT: Data Breach Report'
- Postal Address: Elbetron, Monsha'at Innovation Center, 2nd Floor, Alkurnaish, Al Khobar 34413, Saudi Arabia
- Website Contact Form: Available on the Contact page of our website
- Saudi Data & AI Authority (SDAIA) – for escalated complaints: sdaia.gov.sa