Privacy Notice
Effective date: 01/08/2026 · Last updated: 01/08/2026
1. Who we are
The Hayatiq (حياتيق) service is provided by HAYATIQ AI SOLUTIONS F.Z.E (official Arabic legal name «حياتيك إيه آي سوليوشنز م.م.ح»), a Free Zone Establishment registered in Ajman Free Zone, United Arab Emirates, Licence/Registration No. 56374, registered address B.C. 1306744, Ajman Free Zone C1 Building, Ajman Free Zone, Ajman, United Arab Emirates ("we", "us").
"Hayatiq" is the name of the software; HAYATIQ AI SOLUTIONS F.Z.E is the name of the company that provides it — two different names, deliberately so. In this notice "we" always means the company, never the software.
Contact for privacy matters: privacy@hayatiq.ai, or by post to the registered address above.
2. What this notice covers — and what it does not
Covered (we are the controller): your account and profile data, your organisation's subscription and billing data, your support communications, and technical usage data — the data we decide how and why to process.
Not covered (we are the processor): the bookkeeping content your organisation keeps in Hayatiq — journal entries, invoices, uploaded documents and their contents. Your organisation is the controller of that data; we process it only on its instructions under the data processing agreement in place with your organisation, and your organisation's own privacy notice governs it. If you are named in a document uploaded by one of our customers (for example, a supplier invoice), the customer — not us — decides the purposes; please direct requests to them, and we will assist them as that agreement requires.
That distinction decides which obligations attach, which is why we state it explicitly.
3. Personal data we collect (as controller)
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email, phone, preferred language, role in your organisation | You |
| Organisation and billing data | Organisation name, address, CR and VAT identifiers, plan, subscription status. When paid subscriptions start, payment details are provided directly to our payment provider, Paddle, and are processed under Paddle's own privacy policy | You / your organisation |
| Usage and technical data | Log-ins, device/browser type, IP address, actions taken in the app (our audit trail records who did what, when) | Generated by your use |
| Support communications | Messages you send us, and our replies | You |
We do not ask for, and you should not send us, sensitive personal data (health, creed, biometric data and the like).
4. Purposes and legal basis
We process the data in section 3 to: (a) create and administer accounts and provide the service under our contract with your organisation; (b) bill and collect, once paid subscriptions start; (c) secure the service, including the audit trail and fraud/abuse prevention; (d) comply with legal obligations that apply to us; (e) communicate service and support matters; and (f) improve the service using aggregated or de-identified usage data.
Under the Saudi Personal Data Protection Law and its Implementing Regulations, we rely on: your consent where the law requires it; processing necessary for a contract to which you or your organisation is party; and the other lawful grounds the law provides for the purposes above. Where we rely on consent you may withdraw it at any time, without affecting prior processing.
We do not sell your personal data, and we do not use your data or your organisation's ledger content to train general-purpose AI models.
5. Who receives your data — sub-processors and other recipients
We use service providers ("sub-processors") to run Hayatiq, under contracts restricting them to our instructions, listed by category:
| Category | Provider | Location | Role |
|---|---|---|---|
| Database, authentication, storage | Supabase, Inc. | Frankfurt, Germany (eu-central-1) | Hosts our database, sign-in and uploaded files |
| Hosting / compute | Vercel, Inc. | Frankfurt, Germany (fra1) | Runs the application |
| OCR / document extraction | Google LLC (Document AI) | Outside Saudi Arabia; the specific region is being confirmed and this page will be updated | Reads uploaded documents to extract fields |
| AI processing | Anthropic, PBC | Outside Saudi Arabia; the specific region is being confirmed and this page will be updated | Drafts suggested entries; nothing posts without human approval |
| Workflow automation | n8n | Deployment model and location being confirmed; this page will be updated | Automation pipelines (e.g. document intake) |
| Error monitoring | Sentry | Region being confirmed; this page will be updated | Technical diagnostic events about the running application, scrubbed before transmission so they carry no ledger content, no document data and no request bodies, with organisation context as an opaque identifier only |
| Payments (once billing starts) | Paddle | Details will be stated when paid subscriptions start | Merchant of record; payment details are provided to it directly |
The current list is maintained on this page, and additions or replacements will be posted here. We may also disclose personal data where a law or a competent authority validly requires it, and in a corporate transaction subject to this notice's protections.
6. International transfer
We are a UAE free-zone company (Ajman Free Zone) and our infrastructure is currently located in Frankfurt, Germany, with the OCR/AI providers in the locations listed above. Your personal data is therefore processed outside the Kingdom of Saudi Arabia.
The Saudi Personal Data Protection Law permits transfers out of the Kingdom only on defined grounds and conditions. The specific transfer mechanism we rely on is being settled with qualified counsel, and we will state it plainly in this section once settled — we say so here rather than publish a general phrase that implies the question is closed. Where UAE data-protection law also applies to us, we will comply with its transfer rules as well.
7. How long we keep it (retention)
- Account data: for the life of the account and a limited period after closure, then deleted or anonymised.
- Billing and tax records: retained for the periods required by the laws applicable to us as a company registered in the United Arab Emirates.
- Audit trail: our audit log of actions in the app is append-only, for the integrity of your organisation's books; its retention period is under legal review and will be stated here once settled.
- Support communications: for a limited period after the ticket closes.
Where a statutory retention duty prevents earlier deletion, we restrict the data to that purpose until the period ends. The specific periods in this section will be completed once confirmed by our counsel; we do not publish unconfirmed numbers.
8. Your rights and how to exercise them
Subject to the conditions and exceptions of the Saudi Personal Data Protection Law, you have the right to: be informed; access your personal data and obtain a copy; request correction; request deletion/destruction; and withdraw consent where processing rests on it.
To exercise a right, contact privacy@hayatiq.ai. We will verify your identity and respond within the period the Implementing Regulations require.
Two honest caveats, so the promise matches the product: (a) where the law requires us to keep billing or tax records, deletion may be deferred until the statutory period ends — we will tell you when that applies; (b) requests about ledger content (e.g. your name on an invoice inside a customer's books) go to that customer as controller — see section 2.
If you are unsatisfied with our response, you may complain to the competent authority — in the Kingdom, the Saudi Data & AI Authority (SDAIA).
9. Data retention and erasure — how sections 7 and 8 meet
When you ask us to erase your personal data, we honour the request — except where a statutory accounting- or tax-record retention obligation requires the record to be kept (for example, the billing and tax records section 7 describes). Where a record must be kept but the evidentiary and audit chain permits, we anonymise profile and identity fields on request rather than destroying the underlying accounting record.
This is why a filed accounting record — and its immutable, append-only audit trail — may outlive an erasure request: the record and its evidential chain survive; your identifiers, where they can lawfully and technically be separated from the record, do not. Where the record is ledger content inside a customer's books, that customer is the controller — see section 2.
10. Security
Encryption in transit and at rest, tenant isolation enforced at the database layer, role-based access, least-privilege access for our personnel, and an append-only audit trail. No system is perfectly secure; if a breach affects you in a way the law requires us to notify, we will notify as the law requires.
11. Children
The Hayatiq service is a business tool and is not directed at minors.
12. Changes to this notice
We will post changes here with a new effective date, and notify account contacts of material changes a reasonable period before they take effect.