Skip to content

Privacy Policy

How Hetaf collects, uses, stores and transfers personal data, and how to use your rights under the Kingdom's Personal Data Protection Law.

Last updated:

Contents

This policy is designed to align with the Personal Data Protection Law issued by Royal Decree No. M/19 dated 9/2/1443H as amended, its Implementing Regulation, and the Regulation on Personal Data Transfer outside the Kingdom. It explains what we collect when you use hetaf.ai, the Hetaf platform and its APIs, why we collect it, how we protect it, and what your rights are.

1Who we are and how to reach us

The controller of the personal data described in this policy is Hetaf, which operates hetaf.ai and the Hetaf platform for voice and WhatsApp agents, the team workspace and developer APIs.

2Our role and the role of businesses using Hetaf

We are the controller for account and billing data, website visitor data, website demo calls, demo booking requests and support correspondence.

Data that a business manages about its own customers through Hetaf, such as callers, WhatsApp contacts, customer records and conversations, is processed by us as a processor on that business's behalf and on its instructions. The business is the controller of that data and is responsible for its lawful basis and for informing its customers. Our commitments in this role are set out in the data processing summary.

3Data we collect

  • Account data: name, email address, mobile number, business name, your team role and sign-in details. If you choose to sign in with an external account, we receive only your name and email address from it.
  • Billing data: top-up amounts, tax invoices, credit notes and your business's tax details. Card details are entered on the pages of a licensed payment provider; we never see or store the full card number. If you turn on automatic top-up we keep an encrypted payment token that allows charging without the card number.
  • Content you add: agent settings and instructions, knowledge documents, contacts, messages, call audio, transcripts and summaries, and recordings where you turn them on.
  • Website demo calls: the call audio and transcript. Before the call starts we say that it is recorded to improve the agent.
  • Demo booking requests: name, email address, company, mobile number if you add it, team size, interests and your message.
  • Support correspondence: what you send us and our replies.
  • Technical data: IP address, device and browser type, usage and security logs, and the result of the check that you are not an automated program.

We do not ask you for sensitive data. Please add it to the platform only when needed and with a lawful basis.

4Where the data comes from

  • From you directly, when you register, use the service or write to us.
  • From your business, when a team member invites you to its workspace.
  • From your device automatically, such as the technical data above.
  • From services you choose to connect, and from the payment provider that confirms the result of a payment.

5Purposes and legal bases

We process data only for a defined purpose and on a basis the law recognises:

PurposeLegal basis
Creating your account, providing the platform and running the features you turn onPerforming our agreement with you
Billing, tax invoices and credit notesPerforming the agreement, and our tax obligations
Protecting accounts and preventing fraud and abuseLegitimate interest, and legal obligations
Service messages such as sign-in codes, security and billing noticesPerforming the agreement
Recording a website demo call and using it to improve the agentYour consent: we state that the call is recorded before you start it
Answering demo booking and support requestsSteps at your request before a contract, and performing the agreement
Responding to competent authoritiesLegal obligation

Where we rely on legitimate interest we weigh it against your rights and document that assessment. Where we rely on your consent you can withdraw it at any time; this does not affect processing that took place before you withdrew it.

We do not sell personal data and we do not use it for advertising.

6AI processing

Hetaf is an AI platform. To deliver the features you turn on, automated systems process the content you add, such as audio, text and documents, using specialised speech recognition, text-to-speech and language model services, only to produce the output you ask for.

Call recording on your numbers is off by default, and so is contact memory for each agent. AI output can be inaccurate, so review it before you rely on it.

7Sharing

We share personal data only with:

  • Service providers that act on our instructions under contractual confidentiality and security duties, in these categories: hosting and databases, AI and speech processing, telephony and messaging delivery, email delivery, payments and e-invoicing, and bot protection.
  • Services you choose to connect to your account, such as WhatsApp, telephone carriers and webhooks, at your direction.
  • Competent authorities where the law requires it.

The list of service providers is available to enterprise customers under a data processing agreement, on request to karan@hetaf.ai.

8Where data is stored and transfers outside the Kingdom

Our primary systems and database run on Microsoft Azure in the United Arab Emirates (the UAE North region, in Dubai). This means personal data is transferred and stored outside the Kingdom of Saudi Arabia.

Some service providers may process data in other countries outside the Gulf region, depending on the feature in use.

We transfer personal data outside the Kingdom only as far as the service needs, on a basis that the Regulation on Personal Data Transfer outside the Kingdom permits, with contractual safeguards with the recipients and a risk assessment where the Regulation requires one.

9Retention and destruction

  • Call recordings, including website demo calls: deleted automatically after 30 days.
  • Account data and content: while your account is active. After it is closed, or when you ask, we destroy it or make it anonymous, except what the law requires us to keep.
  • Tax invoices and billing records: for the period that tax and commercial laws require.
  • Demo booking requests and support correspondence: until they are handled, and for a reasonable period afterwards for follow-up.
  • Security logs: for a limited period, long enough to protect the service and investigate incidents.

If data is needed for a matter before a judicial body, we keep it until the proceedings end and then destroy it.

10Your rights and how to use them

The Personal Data Protection Law gives you these rights:

  • To be informed of the legal basis and purpose of collecting your data and how it is processed.
  • To access the personal data we hold about you.
  • To obtain a copy of it in a readable and clear format.
  • To ask for it to be corrected, completed or updated.
  • To ask for it to be destroyed when it is no longer needed, unless the law requires us to keep it.
  • To withdraw your consent to processing that is based on consent.

To use any of these rights, email support@hetaf.ai, preferably from the address registered on your account. We may ask for enough information to verify your identity first. We reply within 30 days of receiving the request, and may extend this by a further 30 days in the cases the Implementing Regulation allows; if we do, we will tell you and explain why.

If your data is held by a business that uses Hetaf, such as a shop or clinic you called or messaged, that business is the controller. Contact it first, and we will help it handle your request.

11Security

We apply appropriate organisational, technical and administrative measures to protect data, including encryption in transit and at rest, separation of each business's data, permission-based access and monitoring. Details are on the security and trust page. No method is perfect, so tell us straight away if you notice unauthorised use of your account.

12Personal data breaches

If personal data we control is leaked, damaged or accessed unlawfully, we notify the Saudi Data and AI Authority (SDAIA) within 72 hours of becoming aware of it where the Implementing Regulation requires, and we notify affected people without undue delay where it may harm them, with steps they can take to protect themselves. If the incident affects data we process for a business, we notify that business without undue delay so it can meet its own obligations.

13Children

Hetaf is a service for businesses. It is not directed at anyone under 18 and we do not knowingly collect their data. If you learn that a minor has given us their data, email us and we will destroy it. A business that deals with minors through Hetaf is responsible for obtaining a guardian's consent where the law requires it.

14Cookies and browser storage

We use one cookie to remember your language, browser storage for your sign-in session and display preferences, and a security check on sign-in, registration and demo forms. We use no analytics, advertising or tracking tools. Details are in the cookie policy.

15Complaints

If you have a complaint about how your data is processed, email us first at support@hetaf.ai so we can address it. You also have the right to complain to the Saudi Data and AI Authority (SDAIA), the competent authority overseeing the Personal Data Protection Law.

16Changes to this policy

We may update this policy and will post the date of the update at the top of this page. If a change is significant, we will tell you by email or in the platform before it takes effect.

This document is published in Arabic and English. If the two versions differ, the Arabic version governs.

Contact: support@hetaf.ai · karan@hetaf.ai