Privacy Policy

CyberAgora — OSS Platform

Last updated: June 9, 2025

Who We Are

CyberAgora (شركة التجمع الرقمي) is a technology company incorporated in Jeddah, Kingdom of Saudi Arabia. We develop and operate OSS (Operations Success System), an AI-powered operating system for multi-location businesses, accessible via web platform and mobile applications.

This Privacy Policy explains how CyberAgora collects, uses, stores, and protects personal data when you use the OSS platform.

Data Controller:
  • CyberAgora (شركة التجمع الرقمي)
  • Jeddah, Kingdom of Saudi Arabia
  • Email: [email protected]
  • Phone: 920013624

1. Data We Collect

1.1 Account & Identity Data

  • Full name, job title, and role
  • Business email address and phone number
  • Organization name and contact details

1.2 Operational Data

Data generated through your use of the platform:

  • Order records, inventory entries, and transaction logs
  • Product catalog content, pricing, and specifications
  • Customer and delivery records entered by your team
  • Support tickets and communications

1.3 Location Data

We collect location data in the following contexts:

a. Delivery addresses Delivery addresses entered during order creation (street, city, district) are stored to route and fulfill orders.

b. Real-time GPS — delivery personnel If your organization uses OSS's Logistics & Delivery module, the mobile app collects real-time GPS coordinates from delivery drivers continuously for the duration of their shift, from clock-in to clock-out. This includes background location collection while the app is not in the foreground. This data is used to:

  • Dispatch drivers to pickup and drop-off locations
  • Provide real-time delivery tracking
  • Generate proof of delivery and route logs
  • Optimize delivery routes

Location collection stops when the driver clocks out of their shift.

c. IP-based approximate location IP addresses are collected as part of standard security and access logging and may be used to derive approximate city-level location for fraud prevention and security purposes.

Location data sharing: Driver GPS data is accessible to the subscribing business (the employer) and may be shared with logistics integration partners (e.g., Mrsool) solely to fulfill deliveries. Location data is never sold to third parties or used for advertising.

User control: Drivers can revoke precise GPS permission at any time through their device's location settings. Doing so will disable dispatching and real-time tracking features. Delivery addresses can be corrected or deleted by the business account administrator.

1.4 Device & Usage Data

  • Device type, operating system, app or browser version
  • Log data: timestamps, features accessed, error reports
  • Session duration and interaction patterns (used to improve the platform)

1.5 Payment Reference Data

We store payment reference numbers and transaction IDs only. We do not store full card numbers, CVV codes, or bank account details. Payment processing is handled by licensed third-party processors.

1.6 Sensitive Information

We do not routinely collect sensitive personal data (health, biometric, or religious data). Official identity documents (e.g., Saudi National ID / Iqama) are collected only where required by law or strictly necessary for identity verification and are securely deleted once the purpose ends.

2. How We Use Your Data

Purpose Data Used Legal Basis
Providing and operating the OSS platform Account data, operational data Performance of contract
Order fulfillment and delivery routing Delivery addresses, GPS data Performance of contract
Driver dispatching and route optimization GPS location, activity logs Performance of contract; legitimate interests
Platform security and fraud prevention IP address, device data, logs Legitimate interests
Customer support Account data, support logs Performance of contract
Product improvement Usage data (anonymized) Legitimate interests
Direct marketing Email address Consent (opt-in required)
Legal compliance As required Legal obligation

3. Data Sharing

We do not sell your personal data.

We share data only with:

  • Google Cloud Platform (KSA region): Infrastructure hosting. All data is stored within the Kingdom of Saudi Arabia. No cross-border transfers occur.
  • Logistics partners (e.g., Mrsool): Order and delivery data shared only as necessary to fulfill deliveries, and only under your instruction as the subscribing business.
  • Payment processors: Transaction references only; full card data is never passed to us.
  • Competent authorities: Where required by Saudi law or a valid legal order.

4. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this policy and to meet legal, regulatory, accounting, or reporting obligations.

On termination of your subscription:

  • Your data remains accessible for 30 days for export
  • Personal data is then deleted from active systems
  • Backup copies are deleted when no longer needed for security or continuity purposes

5. Data Storage & International Transfers

All data is stored on Google Cloud Platform infrastructure in the Kingdom of Saudi Arabia. No personal data is transferred outside KSA.

If a cross-border transfer ever becomes necessary, we will seek your prior written authorization, implement a PDPL-compliant transfer mechanism, and perform a transfer risk assessment before any transfer occurs.

6. Your Rights Under PDPL

Under Saudi Arabia's Personal Data Protection Law (PDPL), you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request deletion of your personal data (subject to legal retention requirements)
  • Restrict or object to certain processing
  • Data portability — receive your data in a structured format
  • Withdraw consent at any time where processing is based on consent

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

7. Security

We implement technical and organizational measures including:

  • Encryption in transit (TLS) and at rest
  • Role-based access control with least-privilege principles
  • Multi-factor authentication for administrative access
  • Regular security monitoring and vulnerability management
  • Secure software development practices aligned with NCA baselines

In the event of a personal data breach affecting your data, we will notify you without undue delay and, where required by PDPL, notify the competent authority within 72 hours.

8. Children's Privacy

OSS is a business platform intended for use by organizations and their authorized employees. We do not knowingly collect personal data from individuals under the age of 18.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you by email and post the updated policy at this URL. The effective date at the top of this page will be updated accordingly.

10. Contact Us

CyberAgora (شركة التجمع الرقمي)

Get in touch

Got questions? Our team can help you map the right modules, integration path, and rollout plan.

What tools make the most sense for your business

How to integrate easily with your current setup

Transparent pricing that scales with you

No pressure, just a practical first step toward smarter operations.

Postal address

Address: JEKA3237, Building Number 3237, Sari Branch Road, Secondary Number 8878, Al Khalidiyah District, Postal Code 23423, Jeddah, Saudi Arabia

Phone number
920013624