Legal document
Privacy Policy
This policy explains what data RITM collects, why, where it is kept, who can reach it, and what rights you have over it.
Last updated: August 4, 2026
This is a good-faith initial version describing the platform as it actually is today. It is pending final legal review for alignment with Saudi Arabia's Personal Data Protection Law.
To be completed before final adoption
- Legal name of the data controller and commercial registration number.
- Data protection officer or designated contact for requests.
- Final retention periods, after legal review.
1. What we collect
Only what running the service requires:
- Account data: name, email address, and role within the company.
- Work data you enter: projects, tasks, clients, financial entries, goals.
- Files you upload: attachments, CVs, provider documents, payment proofs.
- Meeting transcripts, when entered or captured through the platform.
- Operational logs: what happened, when, and who did it — for audit and security.
2. Why we collect it
Each kind has a specific purpose:
- To run the service you subscribed to.
- To verify identity and permissions and prevent unauthorised access.
- To issue invoices and manage the subscription.
- To improve the product using aggregate measures that identify no individual.
- To send necessary operational mail, such as inviting a new member or notifying a task.
3. Where data is kept
The database and files are held with Supabase on servers in the European Union; the application runs on Vercel.
Traffic between your browser and the platform is encrypted in transit, and data is encrypted at rest by the hosting provider.
4. Who can access it
Inside your company: the owner sets each member's permissions. An employee sees their own scope, a manager their department, the owner the company.
RITM staff: see account, subscription and billing data only. They cannot view your projects, clients or financial figures — enforced in the database, not in the interface.
No RITM staff member can impersonate a user or sign in as them.
5. Sub-processors
We rely on external providers to run parts of the service:
- Supabase — database, storage and authentication (servers in the European Union).
- Vercel — application hosting and delivery.
- Anthropic — language-model processing of free-text requests and meeting minutes.
- LiveKit — video meeting rooms.
- Resend — operational email (invitations and notifications).
- Moyasar — payment processing, once enabled.
6. AI and meeting transcripts
When minutes are requested, that meeting's transcript is sent to the language-model provider to extract the summary, decisions and action items; the result is stored inside your company's workspace.
Your data is not used to train models, and nothing outside the requester's own permissions is sent to the model.
Most requests in the platform are resolved in code without sending anything to a language model at all.
7. What we do not do
Stated plainly:
- We do not sell your data, your employees' data, or your clients' data.
- We do not rent or share it for advertising.
- We do not use your work content to train models.
8. Marketing messages
Operational mail — a member invitation, a task notification, a billing alert — is part of the service and continues while your account exists.
Marketing messages are sent only with your consent, and you can withdraw that consent at any time without affecting the service.
9. Retention
We keep your company's data while your subscription is active. After termination there is a reasonable window to export, after which work data is deleted.
Limited records may be kept longer where the law requires it, such as accounting records.
10. Your rights
Under the Personal Data Protection Law you may:
- Know what data we hold about you.
- Request a copy of it.
- Correct anything inaccurate.
- Request deletion, to the extent the law allows.
- Withdraw consent to marketing messages.
11. Security incidents
If an incident affects personal data, we act on it immediately and notify those affected and the competent authority as the law requires.
12. Changes to this policy
We may update this policy. The last-updated date appears at the top of this page, and we give notice of material changes.
Exercising your rights
Write to no-reply@riitmos.com describing your request and we will handle it within the statutory period.