Privacy Policy
Last updated: 7 September 2026
This Policy explains how personal data is handled on Rushd: what we collect, why, where it is stored, who else touches it, how long we keep it, and what you can do about it. It is written under the Saudi Personal Data Protection Law ("PDPL") and its Implementing Regulations.
1. Who We Are and What This Policy Covers
Rushd is operated by O A I Company For Artificial Intelligence (commercial registration no. 7053520024), registered in Al Khobar, Kingdom of Saudi Arabia, trading as "O AI" ("we", "us"). The "Platform" means the Rushd web application at rushd.oai.sa, the client portal we host for law firms' own clients, and the Rushd mobile app (currently for iOS; any later version for other systems falls under this Policy from its release).
Read this Policy together with our PDPL & Data Protection page, which sets out the commitments we make to law firms as their data processor, and with the Rushd Terms and Conditions.
2. Controller or Processor: Which One We Are
The PDPL separates the party that decides why and how data is processed (the controller) from the party that processes it on another's instructions (the processor). We act in both roles, and the difference determines where you send a request.
O AI is the controller for the account and billing data of each subscribing law firm (the "Firm") and its individual users, and for data you send us directly — for example by emailing info@oai.sa.
The Firm is the controller for the client and case data it enters into Rushd: its clients' identities, matters, documents, and correspondence. For that data we are the Firm's processor and act only on its instructions. If a Firm holds data about you and you want it accessed, corrected, or deleted, ask that Firm; we will help it respond. Our PDPL & Data Protection page describes this arrangement in detail.
3. What We Collect
How we get it: account data is entered by your Firm's administrator when it invites you, then by you when you complete your profile; usage, device, and location data is collected automatically as described below. Your name, email address, and role are required to hold an account; phone number, profile photo, notifications, and location are optional and can be declined or withdrawn without losing access to the rest of the Platform.
Account data: name, email address, phone number, role, and Firm affiliation for each user, including staff users of the iOS app. Portal accounts that a Firm creates for its own clients are part of that Firm's client data: the Firm is their controller, we process them as its processor, and a client who wants a portal account changed or deleted asks the Firm (the app's "Request account deletion" screen explains this).
Billing data: subscription plan, invoices, and payment status. Card details are entered on our Saudi-based payment processor's hosted payment form and never reach our servers.
Client and case data: whatever a Firm submits about its own clients and matters, which can include national ID numbers, national addresses, dates of birth, and case files. We process this for the Firm as described in section 2.
AI content: text and documents submitted to the drafting assistant and the output it produces.
Mobile data: device model, operating-system version, and — if a user turns notifications on — a push token that lets us deliver alerts to that device.
Location data: when someone records attendance (check-in or check-out) or sets an office location, the iOS app reads the device's position at that moment and sends the coordinates so the check-in can be matched to a workplace. It happens only while the app is open and only when the user takes one of those actions. Rushd never follows a device in the background, and a user who declines the permission can still use everything else. The permission can be withdrawn at any time in iOS Settings; check-in then simply asks again the next time it is needed.
Photos: when a user attaches an image to a case — an evidence photo, a scanned document, a profile picture — the app reads that one image from the device's photo library. Nothing else in the library is read.
Face ID: the iOS app can use Face ID or Touch ID to unlock the app. The check is performed by iOS on the device itself; we never receive, collect, or store any biometric data, and the feature can be switched off in the app's settings or in iOS Settings.
Files: when a user uploads a document from the Files app or another storage provider, the app reads only the file the user picks and sends it to the Firm's case storage. It has no other access to the device's files.
Every device permission — location, photos and files, notifications, and Face ID — can be withdrawn at any time in iOS Settings, and the app keeps working without it.
Technical data: login history, IP addresses, browser and device information, and error logs.
4. Why We Process It, and on What Legal Basis
For the Firm's own data, processing is necessary to perform our contract with the Firm: running the Platform, managing accounts, providing support, and billing. For the personal data of individual users, whom the Firm invites and authorises, we process on the Firm's documented instructions and — for our own purposes as controller, such as creating the account, authenticating logins, and sending service notices — in our legitimate interest in administering accounts the Firm has authorised. We never rely on legitimate interest for sensitive data.
Some is required by law, such as keeping billing records for as long as Saudi commercial and tax rules demand.
We also process technical data in our legitimate interest of keeping the Platform secure: detecting attacks, enforcing rate limits, and investigating abuse. Where the PDPL requires consent — above all before any customer content could be used to train AI models — we obtain it explicitly first, or we do not proceed.
5. AI Features
The drafting assistant uses large language models from a third-party AI provider. Requests sent to the assistant may be processed by that provider in regions outside the Kingdom. The provider does not use these requests to train its models, and we do not use customer content to train any model without the Firm's explicit consent.
Case content can include sensitive data in the PDPL sense — criminal, security, or health information. Whatever a user types or attaches in the assistant is sent to the AI provider under this section, so a Firm should submit only what the drafting task needs and, as controller, remains responsible for having a lawful basis for that content.
We keep assistant conversation logs for 90 days, then delete them. Output from the assistant is a draft for a qualified lawyer to review, not legal advice.
6. Who Else Touches the Data
We do not sell personal data. We share it with the following service providers, each under a contract restricting what it may do: a cloud hosting provider (compute, database, and file storage, in Saudi Arabia), an AI model provider (AI processing, section 5), a Saudi-based payment processor (payment processing, in Saudi Arabia), a third-party transactional email service (processing in the United States), and Expo together with Apple's and Google's push services (delivery of mobile notifications, outside the Kingdom).
Before we add a sub-processor that will handle Firm data, we notify Firms by email in advance. We may also disclose data where a competent Saudi authority lawfully requires it.
7. Where the Data Lives
Production compute, the database, and file storage all run on Saudi-based cloud infrastructure, inside the Kingdom of Saudi Arabia. Three flows leave the Kingdom: assistant requests processed by our AI provider (section 5); transactional email sent through a third-party email service that processes data in the United States; and mobile push notifications, relayed by Expo and delivered by Apple's and Google's push services outside the Kingdom, which receive only the device token and the short notification text. Each carries only the minimum data the task needs and is covered by contractual data-protection commitments consistent with the PDPL's rules on transfers outside the Kingdom.
8. Security
Data is encrypted in transit over TLS and at rest on our cloud infrastructure. Access inside a Firm is governed by role-based permissions; multi-factor authentication and per-firm IP allowlisting are available; every login is recorded in a history the Firm can see. Our staff's access to customer data is limited and logged. The Rushd Security page describes these measures, and our responsible-disclosure terms, in full.
9. How Long We Keep It
Assistant conversation logs are kept for 90 days, then deleted.
Data of a suspended account — cases, clients, documents, and audit history — is permanently deleted 30 days after suspension if the Firm has not settled or appealed. Before that deletion, the Firm can ask in writing for an export of its data in a common machine-readable format.
Automated database backups are short-lived and expire on a rolling basis.
Account and billing records stay for as long as Saudi commercial and tax law requires, even after a subscription ends.
Attendance coordinates are stored as part of the Firm's attendance records and follow the Firm's own retention decisions inside Rushd. A device's push token is deleted when the user signs out of that device or the account is removed.
Everything else is held while the subscription is active; within Rushd, the Firm decides what client and case data to keep or erase.
10. Your Rights
Under the PDPL you may ask to be informed about how your data is processed, to access it, to receive a copy in a readable format, to have it corrected or deleted, and to withdraw any consent you gave. Send requests to info@oai.sa; we verify identity before acting and respond within 30 days, or, for an unusually complex or voluminous request, within a further 30 days after telling you why.
Deleting an account: Rushd has no self-service sign-up — Firms are onboarded by O AI, staff accounts are created by the Firm's administrator, and client-portal accounts are issued by the Firm — and deletion follows the same route. A staff member asks the Firm's administrator to remove the account; a client of a Firm can submit the request from the "Request account deletion" screen in the client portal, including in the iOS app, or ask the Firm directly, and the Firm actions it; a Firm that wants its own account and data deleted writes to info@oai.sa. When an account is removed we delete the user's profile, device details, and push token; entries the user made in the Firm's case records remain part of the Firm's data, which the Firm controls, and billing records stay only as long as Saudi commercial and tax law requires.
If your data was entered by a Firm — you are a Firm's client, for instance — that Firm is the controller and your request should go to it (section 2); we will assist the Firm in responding. If you are not satisfied with our answer, you may complain to the Saudi Data & AI Authority (SDAIA).
11. If a Breach Happens
When a personal data breach occurs, we notify SDAIA within 72 hours where the PDPL requires it, and we inform affected Firms without undue delay, together with the individuals whose data we control ourselves (Firm account holders, staff users, and people who wrote to us) — stating what happened, which data was involved, and what we are doing about it. For client and case data, the Firm, as controller, decides on and sends any notice to its clients, and we give it what it needs to do so.
12. Children
Rushd is a professional tool. Neither the Platform nor oai.sa is directed at anyone under 18, and we do not knowingly open accounts for minors. A Firm's case files may lawfully contain information about minors — a custody matter, for example — and for that data the Firm is the controller.
13. Changes and Language
If we change this Policy in a material way, we give notice by email or inside the Platform, normally 30 days before the change takes effect. Continued use of the Platform after the effective date is acceptance of the change. This Policy is published in Arabic and English; if the two versions differ, the Arabic text prevails.
14. Contact
Questions, requests, and complaints about privacy all go to info@oai.sa. You can also use the contact form on oai.sa.