Legal document

Privacy Policy

This policy explains what data RITM collects, why, where it is kept, who can reach it, and what rights you have over it.

Last updated: August 4, 2026

This is a good-faith initial version describing the platform as it actually is today. It is pending final legal review for alignment with Saudi Arabia's Personal Data Protection Law.

To be completed before final adoption

  • Legal name of the data controller and commercial registration number.
  • Data protection officer or designated contact for requests.
  • Final retention periods, after legal review.

1. What we collect

Only what running the service requires:

  • Account data: name, email address, and role within the company.
  • Work data you enter: projects, tasks, clients, financial entries, goals.
  • Files you upload: attachments, CVs, provider documents, payment proofs.
  • Meeting transcripts, when entered or captured through the platform.
  • Operational logs: what happened, when, and who did it — for audit and security.

2. Why we collect it

Each kind has a specific purpose:

  • To run the service you subscribed to.
  • To verify identity and permissions and prevent unauthorised access.
  • To issue invoices and manage the subscription.
  • To improve the product using aggregate measures that identify no individual.
  • To send necessary operational mail, such as inviting a new member or notifying a task.

3. Where data is kept

The database and files are held with Supabase on servers in the European Union; the application runs on Vercel.

Traffic between your browser and the platform is encrypted in transit, and data is encrypted at rest by the hosting provider.

4. Who can access it

Inside your company: the owner sets each member's permissions. An employee sees their own scope, a manager their department, the owner the company.

RITM staff: see account, subscription and billing data only. They cannot view your projects, clients or financial figures — enforced in the database, not in the interface.

No RITM staff member can impersonate a user or sign in as them.

5. Sub-processors

We rely on external providers to run parts of the service:

  • Supabase — database, storage and authentication (servers in the European Union).
  • Vercel — application hosting and delivery.
  • Anthropic — language-model processing of free-text requests and meeting minutes.
  • LiveKit — video meeting rooms.
  • Resend — operational email (invitations and notifications).
  • Moyasar — payment processing, once enabled.

6. AI and meeting transcripts

When minutes are requested, that meeting's transcript is sent to the language-model provider to extract the summary, decisions and action items; the result is stored inside your company's workspace.

Your data is not used to train models, and nothing outside the requester's own permissions is sent to the model.

Most requests in the platform are resolved in code without sending anything to a language model at all.

7. What we do not do

Stated plainly:

  • We do not sell your data, your employees' data, or your clients' data.
  • We do not rent or share it for advertising.
  • We do not use your work content to train models.

8. Marketing messages

Operational mail — a member invitation, a task notification, a billing alert — is part of the service and continues while your account exists.

Marketing messages are sent only with your consent, and you can withdraw that consent at any time without affecting the service.

9. Retention

We keep your company's data while your subscription is active. After termination there is a reasonable window to export, after which work data is deleted.

Limited records may be kept longer where the law requires it, such as accounting records.

10. Your rights

Under the Personal Data Protection Law you may:

  • Know what data we hold about you.
  • Request a copy of it.
  • Correct anything inaccurate.
  • Request deletion, to the extent the law allows.
  • Withdraw consent to marketing messages.

11. Security incidents

If an incident affects personal data, we act on it immediately and notify those affected and the competent authority as the law requires.

12. Changes to this policy

We may update this policy. The last-updated date appears at the top of this page, and we give notice of material changes.

Exercising your rights

Write to no-reply@riitmos.com describing your request and we will handle it within the statutory period.