Privacy Policy
Sarj Digital Information Technology Company
1. Introduction
Sarj Digital Information Technology Company (“Sarj,” “we,” “us,” or “our”) provides an Arabic-first enterprise AI platform for voice and chat agents. This Privacy Policy explains how we collect, use, disclose, and protect personal data when you visit sarj.ai, use our platform, or otherwise interact with us.
This Policy is designed to comply with the Kingdom of Saudi Arabia’s Personal Data Protection Law (PDPL) and its Implementing Regulations, and applies alongside any sector-specific obligations (including SAMA and NCA requirements) that govern our regulated clients.
2. Scope
This Policy applies to personal data we process through the sarj.ai website, our voice and chat agent platform, sales and proposal communications, and related services. Where Sarj processes personal data on behalf of a client (for example, end-customer conversation data flowing through a deployed agent), that client is the data controller and its own privacy policy governs; Sarj acts as a data processor under the terms of the applicable service agreement and Data Processing Addendum.
3. Information We Collect
3.1 Information you provide
- Contact details: name, job title, company, email, phone number
- Account and billing information for platform customers
- Content submitted through contact forms, demo requests, or support channels
- Information included in proposals, RFP responses, or contractual documents
3.2 Information collected automatically
- Network and security data needed to deliver and protect our public sites, such as IP address, browser type, requested URL, and Cloudflare security signals
- On partners.sarj.ai and blog.sarj.ai only, and only after you opt in: page route, referral origin, permitted campaign tags, interactions, and sanitized client errors
- Consent preferences and strictly necessary security cookies described in Section 11
3.3 Information processed on behalf of clients
When a client deploys a Sarj voice or chat agent, end-user conversation data (voice recordings, transcripts, chat messages) is processed strictly as instructed by that client under our Data Processing Addendum. We do not use this data for our own purposes beyond providing, securing, and improving the service.
4. How We Use Your Information
- Operate, maintain, and improve the sarj.ai website and platform
- Respond to inquiries, demo requests, and support tickets
- Prepare and manage proposals, contracts, and client onboarding
- Meet legal, regulatory, and contractual obligations, including sector compliance (SAMA, NCA ECC, PDPL)
- Detect, prevent, and investigate security incidents or fraud
- Send service updates and, where you have consented, marketing communications
5. Legal Basis for Processing
We process personal data on one or more of the following bases under the PDPL: your consent; performance of a contract with you or your organization; compliance with a legal obligation; or our legitimate interest in operating and securing our business, provided this does not override your rights and interests.
6. Data Sharing and Disclosure
We do not sell personal data. We may share it with:
- Service providers and sub-processors who support hosting, infrastructure, and platform operations, under contractual confidentiality and data protection obligations
- Regulators and government authorities where required by law (including SAMA, NCA, or SDAIA)
- Professional advisors (legal, audit) under confidentiality obligations
- A successor entity in the event of a merger, acquisition, or restructuring
7. International Data Transfers
Where personal data is transferred outside Saudi Arabia, we ensure appropriate safeguards are in place consistent with PDPL cross-border transfer requirements, including adequacy assessments, contractual clauses, or other mechanisms approved by SDAIA.
8. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy, to meet contractual and regulatory retention requirements (including sector-specific recordkeeping rules applicable to banking, healthcare, government, and insurance clients), or to resolve disputes and enforce agreements. Retention periods for client end-user data are governed by the applicable service agreement.
9. Data Security
We apply administrative, technical, and physical safeguards appropriate to the sensitivity of the data we process, including access controls, encryption in transit and at rest, and regular security reviews. No system is completely secure, and we cannot guarantee absolute security.
10. Your Rights
Subject to PDPL requirements, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data, subject to legal and contractual retention obligations
- Withdraw consent where processing is based on consent
- Object to certain processing, including direct marketing
- Lodge a complaint with the Saudi Data & AI Authority (SDAIA)
To exercise these rights, contact us at support@sarj.ai.
11. Cookies and Tracking Technologies
The main sarj.ai website does not run optional analytics or advertising trackers. partners.sarj.ai and blog.sarj.ai use PostHog anonymous analytics only after you select “Accept analytics.” “Reject analytics” is equally available there, analytics remains off by default, and Global Privacy Control or Do Not Track signals keep it off. You can change or withdraw your choice at any time through the Cookie settings control on those sites.
11.1 Tracker and storage inventory
- sarj.analytics-consent.v1 (browser local storage): records the analytics choice, scope, consent version, and timestamps for 180 days. It stays in your browser and is read by Sarj's public site.
- sarj.posthog-analytics-consent.v1 (browser local storage): after analytics has been enabled, tells the analytics library to stop or resume capture when you change your choice. It contains only consent state, remains until you change the choice or clear browser storage, and is read by Sarj's PostHog library.
- PostHog anonymous analytics (optional): after opt-in on partners.sarj.ai or blog.sarj.ai, measures page routes, referral origin, permitted campaign tags, interactions, and sanitized client errors. Sarj and PostHog receive the events. No account profile, session replay, advertising pixel, cross-site identifier, cookie, or persistent analytics storage is used; client state lasts only for the current page session, while server-side event retention follows Sarj's PostHog retention controls.
- __cf_bm (strictly necessary security cookie, when Cloudflare bot protection issues it): distinguishes automated traffic and is not tied to a Sarj user ID. Cloudflare receives it and it expires after 30 minutes of inactivity.
- cf_clearance (strictly necessary security cookie, only after a Cloudflare challenge): stores proof that a security challenge was passed. Cloudflare receives it and its default duration is 30 minutes, subject to Sarj's Cloudflare challenge configuration.
We do not sell analytics data. Strictly necessary security cookies may be set without opt-in because they protect and deliver the sites. Browser controls can delete stored choices, and the Cookie settings control on a site using optional analytics withdraws consent immediately.
12. Changes to This Policy
We may update this Policy from time to time. The “Effective date” above reflects the latest revision. Material changes will be notified through the website or, where appropriate, directly to affected clients.