Who We Are
CyberAgora (شركة التجمع الرقمي) is a technology company incorporated in Jeddah, Kingdom of Saudi Arabia. We develop and operate OSS (Operations Success System), an AI-powered operating system for multi-location businesses, accessible via web platform and mobile applications.
This Privacy Policy explains how CyberAgora collects, uses, stores, and protects personal data when you use the OSS platform.
- CyberAgora (شركة التجمع الرقمي)
- Jeddah, Kingdom of Saudi Arabia
- Email: [email protected]
- Phone: 920013624
1. Data We Collect
1.1 Account & Identity Data
- Full name, job title, and role
- Business email address and phone number
- Organization name and contact details
1.2 Operational Data
Data generated through your use of the platform:
- Order records, inventory entries, and transaction logs
- Product catalog content, pricing, and specifications
- Customer and delivery records entered by your team
- Support tickets and communications
1.3 Location Data
We collect location data in the following contexts:
a. Delivery addresses Delivery addresses entered during order creation (street, city, district) are stored to route and fulfill orders.
b. Real-time GPS — delivery personnel If your organization uses OSS's Logistics & Delivery module, the mobile app collects real-time GPS coordinates from delivery drivers continuously for the duration of their shift, from clock-in to clock-out. This includes background location collection while the app is not in the foreground. This data is used to:
- Dispatch drivers to pickup and drop-off locations
- Provide real-time delivery tracking
- Generate proof of delivery and route logs
- Optimize delivery routes
Location collection stops when the driver clocks out of their shift.
c. IP-based approximate location IP addresses are collected as part of standard security and access logging and may be used to derive approximate city-level location for fraud prevention and security purposes.
Location data sharing: Driver GPS data is accessible to the subscribing business (the employer) and may be shared with logistics integration partners (e.g., Mrsool) solely to fulfill deliveries. Location data is never sold to third parties or used for advertising.
User control: Drivers can revoke precise GPS permission at any time through their device's location settings. Doing so will disable dispatching and real-time tracking features. Delivery addresses can be corrected or deleted by the business account administrator.
1.4 Device & Usage Data
- Device type, operating system, app or browser version
- Log data: timestamps, features accessed, error reports
- Session duration and interaction patterns (used to improve the platform)
1.5 Payment Reference Data
We store payment reference numbers and transaction IDs only. We do not store full card numbers, CVV codes, or bank account details. Payment processing is handled by licensed third-party processors.
1.6 Sensitive Information
We do not routinely collect sensitive personal data (health, biometric, or religious data). Official identity documents (e.g., Saudi National ID / Iqama) are collected only where required by law or strictly necessary for identity verification and are securely deleted once the purpose ends.
2. How We Use Your Data
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Providing and operating the OSS platform | Account data, operational data | Performance of contract |
| Order fulfillment and delivery routing | Delivery addresses, GPS data | Performance of contract |
| Driver dispatching and route optimization | GPS location, activity logs | Performance of contract; legitimate interests |
| Platform security and fraud prevention | IP address, device data, logs | Legitimate interests |
| Customer support | Account data, support logs | Performance of contract |
| Product improvement | Usage data (anonymized) | Legitimate interests |
| Direct marketing | Email address | Consent (opt-in required) |
| Legal compliance | As required | Legal obligation |
3. Data Sharing
We do not sell your personal data.
We share data only with:
- Google Cloud Platform (KSA region): Infrastructure hosting. All data is stored within the Kingdom of Saudi Arabia. No cross-border transfers occur.
- Logistics partners (e.g., Mrsool): Order and delivery data shared only as necessary to fulfill deliveries, and only under your instruction as the subscribing business.
- Payment processors: Transaction references only; full card data is never passed to us.
- Competent authorities: Where required by Saudi law or a valid legal order.
4. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this policy and to meet legal, regulatory, accounting, or reporting obligations.
On termination of your subscription:
- Your data remains accessible for 30 days for export
- Personal data is then deleted from active systems
- Backup copies are deleted when no longer needed for security or continuity purposes
5. Data Storage & International Transfers
All data is stored on Google Cloud Platform infrastructure in the Kingdom of Saudi Arabia. No personal data is transferred outside KSA.
If a cross-border transfer ever becomes necessary, we will seek your prior written authorization, implement a PDPL-compliant transfer mechanism, and perform a transfer risk assessment before any transfer occurs.
6. Your Rights Under PDPL
Under Saudi Arabia's Personal Data Protection Law (PDPL), you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Request deletion of your personal data (subject to legal retention requirements)
- Restrict or object to certain processing
- Data portability — receive your data in a structured format
- Withdraw consent at any time where processing is based on consent
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
7. Security
We implement technical and organizational measures including:
- Encryption in transit (TLS) and at rest
- Role-based access control with least-privilege principles
- Multi-factor authentication for administrative access
- Regular security monitoring and vulnerability management
- Secure software development practices aligned with NCA baselines
In the event of a personal data breach affecting your data, we will notify you without undue delay and, where required by PDPL, notify the competent authority within 72 hours.
8. Children's Privacy
OSS is a business platform intended for use by organizations and their authorized employees. We do not knowingly collect personal data from individuals under the age of 18.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you by email and post the updated policy at this URL. The effective date at the top of this page will be updated accordingly.
10. Contact Us
CyberAgora (شركة التجمع الرقمي)
- Email: [email protected]
- Phone: 920013624
- Jeddah, Kingdom of Saudi Arabia