1. Scope
This policy applies to your use of the Musaid app, provided by Sharikni Solutions Trading Co. (CR No. 1010948282). By using the app or creating an account, you agree to the practices described here.
2. Data we collect
We collect: (a) account data — your mobile number, name, and optional profile details; (b) request data — details of what you're asking for, documents and files you share, and messages exchanged with the team; (c) technical usage data — device type, sign-in logs, and performance data needed to run and secure the app; (d) limited payment data — handled through the payment method enabled in the app; the app and its team never store full payment card details. We never collect or ask for bank or government login credentials, verification codes (OTPs), PINs, or passwords for external accounts.
3. How we use your data
We use your data to: carry out your requests and communicate with you about them, verify your identity via the code sent to your phone, improve service quality, meet legal obligations, and prevent fraud and misuse. We do not use your data for third-party marketing, and we do not sell it to anyone.
4. Legal basis for processing (PDPL)
We process your data based on: (a) your explicit consent when you create an account and accept this policy and the terms of use; (b) necessity to perform our contract with you (delivering the requested service); (c) a legal obligation in some cases (such as retaining certain records). When you create your account, your acceptance of five consent types necessary to deliver the service is recorded: terms of use, privacy policy, data processing, AI-assisted processing, and cross-border data transfer when applicable. Marketing consent is entirely separate and never granted automatically — no marketing data is collected about you without your explicit, separate opt-in.
5. AI-assisted processing
The app may use AI tools — the company's own or third-party providers' — to help understand and organise your request (for example, turning a voice message into text, or summarising a written request). No processing by a third-party AI provider happens unless your consent to "AI-assisted processing" and "cross-border data transfer" has been recorded, and this processing is controlled to prevent sensitive data (such as banking or government credentials or card data) from ever reaching an AI provider. You can withdraw consent to this kind of processing at any time by contacting the team; withdrawing consent does not affect processing that already took place under it.
6. Who we share your data with
We share your data only with: (a) the parties required to complete your specific request (such as a government body or bank, only to the extent necessary); (b) service providers who help us operate the app, such as SMS providers for sending verification codes, cloud hosting providers, and AI-tool providers when enabled; (c) regulators, where there is a legal obligation to do so. We never share your data with anyone for their own marketing purposes, and we never sell it to anyone.
7. Cross-border data transfer
Some of your data may be processed outside the Kingdom of Saudi Arabia, including within the European Union, through service providers whose handling of your data is subject to approved contractual safeguards consistent with Saudi PDPL's requirements for transferring data outside the Kingdom. No such transfer tied to AI-assisted processing happens without your explicit recorded consent, as described in clause p5.
8. Data retention
We retain your data for as long as your account is active, and for a further period after that where needed for legal, accounting, or dispute-resolution purposes. When you request account deletion, your account is suspended immediately, and identifying personal data (name, phone number, email, staff notes) is permanently and irreversibly erased within 30 days, while order and transaction records are kept in de-identified form solely for accounting and legal purposes.
9. Security
We apply reasonable technical and organisational measures to protect your data, including: encrypting the connection between your device and our servers, storing documents in access-restricted storage that is never publicly accessible, and using signed, time-limited access links for any document that is shared. Verification codes (OTPs) are never stored in plain text. No electronic transmission or storage method is completely secure, and we protect your data according to industry best practice.
10. Your rights under the Personal Data Protection Law (PDPL)
You have the right to: (a) access the personal data we hold about you; (b) correct inaccurate data; (c) request deletion of your data; (d) receive a copy of your data in a portable format. To exercise any of these rights, contact us at [email protected]. We respond to your request within 30 days of receiving it, and this period may be extended once by a further 30 days if needed, with notice of the reason for the extension.
11. Consent and withdrawal
You can withdraw consent to any processing that is not necessary for delivering the core service (such as AI-assisted processing) at any time by contacting the team at [email protected]. Withdrawing consent to processing that is necessary for the service (such as phone-number verification) may mean you can no longer use the app.
12. Children's privacy
The app is not directed at children below the legal age of majority, and we do not knowingly collect their data without a guardian's permission. If we learn we have collected a minor's data without permission, we delete it as soon as we become aware.
13. No sale of data, no third-party marketing use
The company does not sell customer data to anyone, and does not use it for third-party marketing purposes.
14. Changes to this policy
This policy may be updated from time to time. Customers are notified of material updates inside the app.
15. Contact us about privacy
For any question or request about your data, contact us at [email protected].
A question about your data? The team can answer it.
Contact us