Privacy Policy
Last updated: April 4, 2026
At A³ Audit, your privacy and data security are our top priorities. This policy explains how we collect, use, and protect your information, and our obligations to you under the Personal Data Protection Law (PDPL) issued by Royal Decree No. M/19 dated 1443 AH and its implementing regulations.
Our Commitment to Protecting Your Data
We commit to not accessing your work data (risk registers, reports, analyses) except in limited cases: explicit technical support requests from you, or compliance with a valid legal order from a competent authority. Your professional data is never shared, sold, or used for marketing purposes.
Data Isolation
Your data is logically isolated from other users through strict security rules that prevent any user from accessing another user's data.
End-to-End Encryption
All your data is encrypted in transit (TLS 1.3) and at rest (AES-256) on internationally certified cloud infrastructure.
Secure by Design
The infrastructure is built with the principle of least privilege, with security rules enforced at the database level for every read and write operation.
Data Hosting Location
All platform data is hosted in Saudi Arabia on Google Cloud Platform infrastructure in the me-central2 region (Dammam). Your data does not leave the Kingdom.
1. Data Storage & Processing
We are fully transparent about how your data is stored and processed:
- Cloud Infrastructure: Your operational data (risk registers, plans, reports, checklists) is stored on secure, internationally certified cloud infrastructure (ISO 27001, SOC 2). Data is protected by strict security rules ensuring each user is isolated from others.
- Browser Storage: Your browser's storage is used for temporary preferences (language, settings) to improve performance. This data never leaves your device.
- AI Processing: When using AI tools, the data you input (text and information you provide) is sent to advanced AI services for processing and returning results. This data is not stored by the AI provider and is not used for model training (on the paid plan).
- Email Services: We use an email service provider to send platform notifications (account verification, task alerts, verification codes). Only your email address is shared with this provider for delivery purposes only.
2. Information We Collect
We collect the minimum information necessary to operate your account and deliver the service:
- Registration Information: Full name, email address, and phone number — to create your account and communicate with you.
- Subscription Data: Plan type, subscription and renewal dates, payment records — to manage your subscription.
- Usage Data: AI credits consumed, pages visited, and activity logs — to improve the platform and manage your quota.
- Work Data: Risk registers, reports, checklists, and any content you enter — remains your property entirely and is not used for any other purpose.
3. Data Security & Protection
We apply multi-layered security measures to protect your data:
- Data encryption in transit and at rest using advanced industry standards.
- Database-level security rules enforced for every operation, preventing unauthorized access.
- Application identity verification (App Check) to block untrusted requests.
- Continuous monitoring for suspicious activities and brute-force attack protection.
- Strict internal access policy — administrative database access is restricted and logged in an admin audit trail.
4. AI Usage & Data Transfer
The platform leverages the most advanced AI models currently available to provide analysis and assessment services:
- When using AI tools (Cortex), the data you input is sent to a secured API for processing. This may involve processing outside the Kingdom of Saudi Arabia via global cloud infrastructure, with adequate protection guaranteed under Article 29 of the Personal Data Protection Law.
- Input data is processed in real-time and is not stored by the service provider, nor used for AI model training (per the paid usage policy).
- Analysis results are saved in your account only and are not shared with any party.
- You can choose not to use AI tools and rely entirely on manual tools.
- You have the right to request human review of any AI-generated assessment or result (Article 19 of the Personal Data Protection Law).
5. Your Rights
Under applicable data protection regulations, you have the following rights:
- Right of Access: View your personal data stored with us at any time.
- Right of Correction: Update or modify your personal data through your account settings.
- Right of Deletion: Request permanent deletion of your account and all your data.
- Right of Portability: Obtain a copy of your data in a readable format.
- Right of Objection: Object to the processing of your data for specific purposes.
- Right to Withdraw Consent: You may withdraw your consent to data processing at any time without affecting the lawfulness of processing carried out prior to withdrawal (Article 7).
- Right to Complain: You have the right to file a complaint with the Saudi Data & Artificial Intelligence Authority (SDAIA) if you believe your data has been processed in violation of the law (Article 20).
- We commit to responding to your requests within 30 days of receipt.
- To exercise any of these rights, contact us at: a3audit@a3audit.ai
6. Data Retention
We retain your data throughout your active subscription period. Upon account cancellation:
- Work data (reports, registers): Deleted within 30 days of cancellation confirmation.
- Account data (name, email): Retained for a maximum of 24 months after cancellation for compliance purposes, then automatically deleted unless there is a legal obligation to retain it.
- Activity logs: Deleted within 180 days (for regulatory compliance).
- You may request to export your data before deletion.
7. Data Breach Notification
In the event of a security breach affecting your personal data:
- We will notify you within 72 hours of discovering the breach.
- We will explain the nature of the breach, affected data, and actions taken.
- We will notify the Saudi Data & Artificial Intelligence Authority (SDAIA) in accordance with Article 21 of the Personal Data Protection Law.
- We will take all necessary measures to contain the breach and prevent recurrence.
8. Third Parties
We work with a limited number of service providers to operate the platform, all of whom are committed to strict security standards:
- Google Cloud Platform (GCP) — cloud infrastructure for data storage and platform hosting — Dammam region (me-central2), Kingdom of Saudi Arabia (ISO 27001, SOC 2 certified).
- Advanced AI API — processing analysis and assessment requests using state-of-the-art large language models. Processing may occur outside the Kingdom via secured global cloud infrastructure.
- Brevo (formerly Sendinblue) — sending notifications and verification messages via email.
- We do not sell or share your data with any marketing or advertising parties.
9. Changes to This Policy
We may update this policy to reflect changes in our services or regulatory requirements. We will notify you of any material changes at least 30 days before they take effect via email or an in-platform notification.
12. Contact
For any inquiries about this policy, our privacy practices, or to exercise your rights: Email: a3audit@a3audit.ai Website: a3audit.ai/contact