Privacy Policy
How we collect, use, store and host data, including WhatsApp, Messenger and Instagram data, and your rights over it.
Draft — subject to legal review before publicationمسوّدة — تُراجع قانونيًّا قبل النشر
This English version is provided for convenience. If it differs from the Arabic version, the Arabic version prevails.
Who we are and our role
Ghaith is a customer relationship management platform provided by [to be added: legal entity name] to businesses so they can serve their customers. For customer data that a business enters into Ghaith or receives through it, the business is the data controller and we act as a data processor, processing that data on the business's behalf and according to its instructions. For the business account and its users' account data, we are the controller.
Data we collect
- Account data: the business name and activity, and the names, email addresses and mobile numbers of its users.
- Data entered by the business: its customers' details, conversations, appointments and orders, depending on the features it uses.
- Usage data: technical logs needed to operate and secure the service.
- This website: we use analytics on this website only after you consent, and those tools are self-hosted and do not track you across other websites.
How we use data
We use data to provide and operate the service, support users, protect the platform from abuse, and meet our legal obligations. We do not sell personal data.
Meta platform data
Ghaith connects to Meta platforms through an app registered with Meta under the name "Ghaith 360". The app lets a business connect its accounts in one click and manage its messages in a single inbox. We receive no data from a channel until an administrator of the business connects it and grants the requested permissions in Meta's own dialog.
Channels
- WhatsApp Business (WhatsApp Business Platform): when the business connects a WhatsApp number.
- Messenger: when the business connects a Facebook Page, for that Page's messages.
- Instagram: when the business connects an Instagram professional account, for direct messages.
We do not currently receive comments or posts from these platforms.
What we receive
When a channel is connected, we receive from Meta only what is needed to operate it:
- IDs and names of the connected Pages, accounts and WhatsApp numbers.
- Messages sent to or by the business through the channel, and their attachments (images, files and voice notes).
- The sender's name and username, and profile picture where available.
- Delivery and read statuses, reactions, and edits or deletions made by the sender.
- WhatsApp message templates created by the business, with their approval and quality status.
- Access tokens that Meta issues to the app, which we store encrypted and never display.
How we use it
- To show messages in the business's unified inbox, to its authorised users only.
- To let the business reply to its customers and send the messages and templates it chooses.
- For the business's own internal reports, such as conversation volume and response times.
What we do not do
- We do not sell this data.
- We do not use it for advertising or to build marketing profiles of individuals.
- We do not share it with anyone except the service providers needed to run the platform, such as our hosting provider, and Meta itself to deliver messages.
- We do not access the content of a business's messages except at its request for technical support, or where the law requires it.
Retention
- Messages and related data remain in the business's account for as long as the account exists, or until the business deletes them.
- If a sender deletes a message on the platform, we keep its text in the business's record marked "deleted by the customer", and the business administrator decides who can see it.
- We keep the raw copy of notifications received from Meta for 14 days to verify reliable delivery, and then erase their content.
- When a business account is deleted, we delete its data within 30 days of confirming the request, and it is automatically removed from our encrypted backups within a further 30 days.
- The general retention periods in the "Retention periods" section below also apply.
Disconnecting
- From Ghaith: a business administrator can disconnect any channel at any time from the connections page in Ghaith ("Channels" for Messenger and Instagram, and "WhatsApp → Numbers and settings" for WhatsApp numbers). When a channel is disconnected, we stop receiving and sending, revoke the stored access tokens, and unsubscribe the app from the Page or account at Meta. Earlier conversations stay in the business's account as its record until it deletes them or asks us to delete its account.
- From Facebook: Settings → Security → Apps and websites (or "Business integrations" for business accounts) → "Ghaith 360" → Remove.
- From Instagram: Settings → Apps and websites → "Ghaith 360" → Remove.
How to ask us to delete data after disconnecting is explained on the Data Deletion page.
Other channels
When connecting other channels, such as Telegram and TikTok, becomes available, the same terms in this section will apply to their data, and the details of what we receive from each platform will be added here in the same format.
Where we host data
We host data with an internationally certified (ISO 27001) cloud service provider in data centres located in the European Union (Germany), which are subject to the General Data Protection Regulation (GDPR). Data is encrypted in transit and at rest, and backups are encrypted. Data is transferred outside the Kingdom of Saudi Arabia in accordance with the Personal Data Protection Law and its implementing regulations.
Sharing with third parties
We share data only as needed with service providers we rely on to operate the platform, including Meta when a business connects a WhatsApp number, a Facebook Page or an Instagram account, and our hosting provider. These parties are bound by their contracts with us to protect the data.
Retention periods
- We keep a business's data for as long as its account exists.
- If a free trial ends without a subscription, we keep the data for sixty days and then delete it after giving notice.
- If payment fails, we keep the data for ninety days and then delete it after giving notice.
- We keep invoices for the period required by law.
Your rights
You have the right to access your personal data, to ask for it to be corrected, and to ask for it to be destroyed, in accordance with the Personal Data Protection Law and its regulations. Customers of a business may contact that business directly, as it is the controller of their data. How to request deletion is explained on the Data Deletion page.
Contact
- Operating entity: [to be added: legal entity name], Commercial Registration No. [to be added: commercial registration number].
- Address: [to be added: registered address]
- Data protection contact: [to be added: data protection contact]
- Privacy email: [to be added: privacy email]
For questions about this policy or to exercise your rights, email us at the privacy address above, or use the channels listed on our Contact page.
