This Privacy Policy explains how Sigmix (“Sigmix,” “we,” “us,” “our”) collects, uses, shares, stores, and protects personal data when you use the Sigmix websites (sigmix.ai, sigmix.sa) and platform. It is written to comply with the Saudi Personal Data Protection Law (PDPL) and its Implementing Regulations, administered by SDAIA.
Registered address: 7229 Innovation Boulevard, 3004 Al Aqeeq District, 13519 Riyadh, Kingdom of Saudi Arabia.
Our two roles: controller and processor
Sigmix handles personal data in two different capacities, and your rights and our duties differ depending on which applies:
As a controller, we decide why and how data is processed. We are the controller for: your account, profile, and login data; billing, payment, and tax data; support and communications; security, fraud-prevention, and audit data; and our own website and marketing analytics. This Privacy Policy governs that processing.
As a processor, we process data on your instructions, on your behalf, where you decide the purpose. We are the processor for the content you put into the modules and the personal data of the third parties you process through them — for example, your prompts and uploads, your email recipient lists, your survey respondents, your meeting participants, your chatbot contacts, and the visitors to websites you build with us. For that data, you are the controller, you are responsible for the lawful basis and for notifying those individuals, and our handling is governed by our Data Processing Agreement (DPA), not this Policy.
Personal data we collect (as controller)
- Account & profile: name, email, phone, company/organisation, role, workspace and user IDs, preferences.
- Billing & tax: billing name and address, billing type (Individual / Freelancer / Company / Government), VAT number (business customers), plan and credit records, invoices, and an encrypted payment token (we do not store full card numbers — see §6).
- Usage & device: modules and features used, credits consumed, session and log data, IP address, browser and device type, and similar telemetry.
- Support & communications: your messages to us, tickets, and feedback.
- Website & marketing analytics: cookies and similar technologies on our marketing site and in-product analytics (see §7 and the Cookie Policy).
- Information from third parties: where lawful, limited data from our payment, identity, or anti-fraud providers.
Note on content you submit: prompts, uploads, and module content may contain personal data. We process that as your processor under the DPA (§1); you must not submit third-party or sensitive personal data without a lawful basis (see the AUP).
Why we process it, and our lawful basis (as controller)
| Purpose | Lawful basis (PDPL) |
|---|---|
| Create and operate your account; provide the Services | Performance of a contract |
| Process subscriptions, credits, top-ups, payments | Contract + legal obligation |
| Issue tax invoices and meet tax/accounting duties | Legal obligation |
| Security, fraud prevention, authentication (incl. OTP/MFA), abuse detection | Legitimate interest / legal obligation |
| Customer support | Performance of a contract |
| Service analytics and improvement (aggregated/de-identified where possible) | Legitimate interest |
| Marketing communications about features and offers | Consent (opt-in; withdraw anytime) |
| Non-essential cookies and tracking | Consent (see Cookie Policy) |
| Comply with law, respond to lawful requests, enforce our terms | Legal obligation / legitimate interest |
We do not use your content or personal data to train AI models.
Marketing and your consent
We send marketing only with your opt-in consent. Every marketing message carries an easy, free unsubscribe, and you can withdraw consent at any time — withdrawal is as easy as giving it and does not affect the lawfulness of prior processing. Email and SMS consents are handled separately.
Data storage, residency, retention, and cross-border transfers
Residency. Our core platform and customer data are hosted in the Kingdom of Saudi Arabia (Oracle Cloud Infrastructure, Riyadh region) by default. Some features and sub-processors necessarily process data outside the Kingdom — these are listed in §8 and flagged below.
Cross-border transfers. Where personal data is processed outside KSA (for example, certain global AI inference, the email-delivery provider's EU region, global meetings, and WhatsApp/Meta), we do so only as permitted by the PDPL and its transfer rules, applying appropriate safeguards (such as SDAIA-approved standard contractual clauses) and, where required, a transfer risk assessment. KSA-sovereign and KSA-only options are available for several modules where in-Kingdom processing is required.
Retention. We keep personal data only as long as needed for the purposes above or as required by law:
| Data | Retention |
|---|---|
| Account & profile | While active; deleted or anonymised within 90 days of account closure |
| Billing, invoices & tax records | 6 years (ZATCA/tax law — overrides deletion requests) |
| Usage logs & telemetry | 12 months, then anonymised |
| Prompts & AI outputs (where we hold them) | While active; deleted within 90 days of account deletion; processed at AI providers for inference only, never used for training |
| Meeting recordings/transcripts (opt-in) | Customer-controlled (we are processor); deleted on account deletion |
| Support tickets | 24 months after resolution |
| Marketing consent & suppression records | Kept as long as needed to honour your preference / opt-out |
| Cookie consent logs | 18 months |
| Records of processing / breach records | 5 years (PDPL) |
Backups are deleted on a rolling cycle; where deletion is requested, residual backup copies are purged or anonymised within the normal backup cycle.
Payments and card data
Card and wallet payments (mada, Visa, Mastercard, Apple Pay, Google Pay) are processed by licensed third-party payment providers through their secure hosted fields. Sigmix never receives or stores your full card number — we hold only an encrypted token used for recurring billing. Card-present transactions use 3-D Secure.
Who we share data with (sub-processors and recipients)
We do not sell your personal data. We share it only with:
(a) Service providers / sub-processors who process data on our behalf under contracts requiring confidentiality, security, and PDPL compliance. Our current sub-processors, by category, include:
| Category | Provider(s) | Location / transfer |
|---|---|---|
| Hosting, database & storage | Oracle Cloud Infrastructure (Riyadh); self-hosted object storage | In-Kingdom |
| Payments | Paymob (and gateway swappable per partner) | In-Kingdom processing; card networks as applicable |
| E-invoicing (ZATCA) | Qoyod | In-Kingdom |
| Email delivery | Amazon SES | Cross-border (EU region) |
| AI inference (global) | Amazon Bedrock; Azure/OpenAI; Google; xAI | Cross-border (inference only; no training) |
| AI inference (KSA-sovereign) | Groq (Dammam); in-Kingdom GPU servers on Oracle, Google Cloud (Dammam), SCCC and Huawei | In-Kingdom |
| Real-time meetings (global) | Cloudflare Realtime | Cross-border |
| Messaging | WhatsApp / Meta | Cross-border |
| Website & product analytics | Google Analytics 4 (Google); Sigmix first-party analytics (self-hosted) | GA4: cross-border; first-party: In-Kingdom |
A current, versioned sub-processor list is maintained at sigmix.ai/legal/subprocessors. We update it as providers change and, where required, give notice.
(b) Legal, safety, and regulatory recipients — courts, regulators, or authorities where required by law or to protect rights, safety, or our Services.
(c) Corporate transactions — a successor in a merger, acquisition, or asset sale, subject to continued protection and notice where required.
Your rights under the PDPL
For data where we are the controller, you have the right to: be informed about processing; access your data; obtain a copy in a readable format; rectify inaccurate or incomplete data; request destruction/erasure where data is no longer needed or where consent is withdrawn and no other basis applies; and withdraw consent to consent-based processing.
How to exercise your rights: submit a request at sigmix.ai/privacy-request or email dpo@sigmix.sa. We will verify your identity to protect your data and respond within 30 days (extendable once with notice). There is no fee for a reasonable request.
If your request concerns data we process as a processor on a customer's behalf (for example, you are a recipient on someone's email list, a survey respondent, or a meeting participant), we will refer you to, or forward your request to, the relevant customer (the controller), who is responsible for handling it. You may lodge a complaint with SDAIA if you are unsatisfied with how we handle your data.
Security
We apply organisational, administrative, and technical measures appropriate to the risk, including:
- encryption in transit and at rest;
- tenant isolation at database (row-level security) and application layers;
- separation of personal data into a dedicated, erasable user store (so a person can be deleted without breaking immutable tax records, which carry only opaque IDs);
- access controls and least-privilege;
- authentication options including OTP/MFA;
- logging and monitoring; and
- staff confidentiality obligations.
No system is perfectly secure; you are responsible for safeguarding your credentials and devices.
Personal-data breaches
If a personal-data breach occurs that may harm you or your rights, we will notify SDAIA within 72 hours of becoming aware, and notify affected individuals without undue delay where required. (Where a separate notification to the Ministry of Commerce applies, we will also comply with that.)
Children
The Services are intended for users 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact dpo@sigmix.sa and we will delete it.
Changes to this Policy
We may update this Privacy Policy. For material changes we will give notice by email, in-product notice, or website posting. Continued use after the effective date is acceptance. We keep version history.
Contact
Questions, requests, or complaints: Data Protection Officer — dpo@sigmix.sa · Requests: sigmix.ai/privacy-request · Post: 7229 Innovation Boulevard, 3004 Al Aqeeq District, 13519 Riyadh, Kingdom of Saudi Arabia.
Language
This Privacy Policy may be provided in English and Arabic. In case of any conflict, the Arabic version prevails.