Legal
Privacy Policy
AccrePro Technologies | Kingdom of Saudi Arabia
Version 1.0 | Publication effective date: 9 October 2026
This consolidated draft retains the substance of AccrePro’s existing 12-section website policy and adds Saudi Personal Data Protection Law (PDPL) transparency elements. Operational verification items are isolated in the final publication checklist and must be completed before adoption.
1. Introduction and Scope
AccrePro Technologies ("AccrePro", "we", "us", or "our") respects privacy and is committed to handling personal data lawfully, fairly and transparently. This Privacy Policy describes how we collect, use, disclose, store, protect and destroy personal data when you visit accrepro.com, request demonstrations, contact us, or use AccrePro software and learning services. It is made available before or at collection, as applicable. Use of the website does not, by itself, constitute consent to every type of processing: where consent is legally required, we will request it separately. Other processing may rely on an applicable lawful basis. This policy does not replace any client contract or Data Processing Agreement (DPA).
2. Identity, Roles and Contact
The controller for personal data collected for AccrePro’s own website, marketing, sales, account administration, security and support purposes is AccrePro Technologies, subject to confirmation of its registered legal name. Address: Building No. 7503, King Abdulaziz Road, Al Arid District, Riyadh 13332, Saudi Arabia. Email: business.dev@accrepro.com. Phone (as currently published): +966 50 113 774 [VERIFY NUMBER]. Where customer organizations decide the purposes and means of processing healthcare or employee data inside the platform, they are generally controllers and AccrePro generally acts as processor under documented instructions and its DPA; actual roles depend on the specific processing operation. If a data protection officer is legally required and appointed, their contact details will be published here.
3. Personal Data We Collect
Depending on your interaction, we may collect: (a) contact and organizational information such as names, work emails, phone numbers, titles and organization names; (b) account information such as username, role, authorized facility and authentication records (passwords should be stored as protected credentials, not plain text); (c) technical and usage data such as IP address, device/browser details, log and event data, approximate location and cookies; (d) emails, inquiries, demo requests, support correspondence and files you voluntarily submit; (e) billing/contract contact details; and (f) customer-controlled content, which may include personal or sensitive healthcare information where permitted under contract. We seek to minimize data and do not require patient-identifiable information for a routine website inquiry. Sensitive personal data receives additional safeguards.
4. Collection Methods and Whether Data Is Required
We collect data directly when you complete a web form, register, purchase services, communicate with us or upload authorized platform content. We may collect data indirectly through essential site logs, cookies and approved analytics, through authorized customer account administrators, or from referrals and professional contacts, where lawful. Fields marked as required are necessary to respond to your inquiry, create or secure an account, or fulfill a requested service; other fields are optional. Failure to provide required information may prevent us from completing that specific request or service. We will provide any additional point-of-collection notice required by law.
5. Purposes and Lawful Bases
We process only the minimum personal data reasonably necessary for specified purposes. These include: responding to requests and managing customer relationships (pre-contractual or contractual necessity where applicable, consent or permitted legitimate interests); operating accounts and services (contractual necessity and/or other lawful basis); protecting systems, detecting abuse and maintaining audit logs (applicable legitimate interests and legal obligations, with no reliance on legitimate interests for sensitive data); complying with statutory, regulatory and judicial requirements (legal obligation); and sending optional promotional messages (consent or another lawful basis where permitted, with an opt-out). Where information is processed on a customer’s behalf, the customer determines the applicable lawful basis and AccrePro processes it according to the DPA and lawful instructions. If an additional incompatible purpose is proposed, we will first assess its legality and provide a further notice or obtain consent where necessary.
6. Cookies and Similar Technologies
We may use strictly necessary cookies for website operation and security and, where enabled, preference and analytics cookies. Non-essential cookies and marketing technologies will be activated only when the applicable consent or other legal requirements are met. Visitors may manage available cookie preferences and browser controls; blocking essential cookies may reduce functionality. Before publication, the actual cookie categories, providers, durations and controls must be listed in a separate cookie notice or on this page.
7. Healthcare Data and Customer-Controlled Content
Our products may host or process information uploaded by authorized healthcare organizations, including patient, staff or other sensitive personal data. Clients are responsible for establishing lawful grounds for upload and configuring user access; AccrePro remains responsible for its own legally applicable processor and security obligations. We restrict access to authorized personnel, use access-control and confidentiality measures, and process content for contracted service delivery, troubleshooting, security and other documented customer instructions. We do not treat a customer’s upload as unrestricted permission to repurpose patient data.
8. AI-Enabled Features
Certain AccrePro modules may offer AI-assisted analysis, classification, summarization, suggestions or related capabilities. Where an AI feature processes customer content, the processing is limited to the relevant service purpose, authorized configuration and contract terms. Depending on the deployed feature, approved technology providers or subprocessors may be involved. AccrePro does not make a blanket claim that all AI inference takes place inside Saudi Arabia or that no external AI service receives personal data; these facts must be verified for each feature. Customer content will not be used for general model training unless this is specifically authorized, lawful and transparently disclosed. Customers should avoid entering unnecessary identifiable patient data into AI tools, and AI-generated outputs should be reviewed by qualified personnel before operational or clinical reliance.
9. Disclosure and Recipient Categories
We do not sell personal data. We may disclose necessary data, for the relevant purposes, to contracted infrastructure/hosting, email, technical support, analytics and approved AI service providers; professional legal/accounting advisers; regulators, courts or authorities where legally required; and successor entities in a lawful corporate transaction. We apply suitable confidentiality, security and contractual protections and disclose only what is necessary. A list or notice of material subprocessors and processing locations should be available to enterprise customers through the DPA or a linked subprocessor notice. Disclosure may be occasional (for legal requirements) or recurring (for contracted service providers).
10. Storage Locations and Transfers Outside Saudi Arabia
AccrePro primarily operates for customers in Saudi Arabia and intends to use authorized infrastructure appropriate for their contractual and sector-specific obligations. Personal data may be stored or processed in locations determined by the applicable service configuration, including by approved service providers. Any transfer or disclosure of personal data outside Saudi Arabia must meet the Saudi PDPL and its transfer regulations, including any required safeguards, limitations and assessments. Before publication, AccrePro must identify and disclose verified website-hosting, production, backup, support and AI-processing geographies; a generic claim that all data remains in the Kingdom must not be used unless technically validated.
11. Storage, Retention and Secure Destruction
We retain personal data for documented periods appropriate to the category, purpose, applicable laws and contractual requirements, then securely delete, anonymize or irreversibly destroy it when no longer required, subject to lawful preservation duties. Website contact inquiries, account and security records, service communications, contract records and customer-controlled platform content may have different retention periods. For platform data, deletion or return following contract termination is governed by the DPA and applicable law, including backup deletion cycles. The category-specific schedule and backup timelines in the publication checklist must be verified and published or explicitly described by objective criteria; no unsupported fixed retention promise is made in this draft.
12. Security and Personal Data Incidents
We maintain risk-based administrative, organizational and technical safeguards such as role-based access, authentication controls, encryption where appropriate, logging, employee confidentiality, backup protections and incident response. These controls are reviewed against applicable Saudi requirements and contractual obligations. No system can guarantee absolute security. Where an incident is reportable, AccrePro will cooperate with the relevant controller and make or support legally required notifications to regulators and affected individuals within applicable deadlines.
13. Your Rights Under Saudi PDPL
Subject to statutory exceptions and the nature of our role, you may have the right: to be informed of processing and its lawful basis; to access your personal data; to obtain a copy in an appropriate readable format; to request correction, completion or updating; to request destruction where legally permitted; and to withdraw consent where processing relies on consent (without invalidating earlier lawful processing). Additional rights or restrictions may arise under applicable laws. Requests about personal data controlled by a hospital or other customer may need to be submitted to that controller, while AccrePro provides reasonable processor assistance.
14. How to Exercise Rights and Submit Complaints
Send requests and privacy complaints to business.dev@accrepro.com with the subject “Privacy Request” (a dedicated privacy mailbox may replace this address once designated). Please describe your request without emailing unnecessary sensitive health records. We may verify identity and authority before disclosure. We will respond within the period required under Saudi law; where the implementing rules require a response within 30 days, that timeframe applies, subject to lawful extensions and exceptions. If dissatisfied, you may escalate through the Saudi Data & AI Authority (SDAIA) or other competent authority using its official channels, subject to applicable complaint procedures.
15. Children’s Privacy
Our general website and enterprise services are intended for organizations and professionals, not children. We do not intentionally solicit personal data from children through public marketing forms. The prior policy’s “under 16” threshold is not a universal replacement for the Saudi legal rules regarding minors and guardians. Where an authorized healthcare customer processes minors’ data through the platform, the customer and AccrePro will comply with applicable legal and contractual protections.
16. Third-Party Links
Our website may link to websites or services not operated by AccrePro. Their independent privacy practices are governed by their own policies. We encourage users to review them; nothing in this clause limits legal responsibility AccrePro may have for its own data disclosures.
17. Changes and Language
We may update this policy to reflect operational or legal developments. We will update the effective/revision date and provide additional notice or obtain consent where legally required. Continued use alone does not replace legally required notice or consent. English and Arabic versions are provided for accessibility; any interpretation or prevailing-language provision should be validated by legal counsel and should not diminish statutory rights.
18. Regulatory References
This policy is drafted with reference to the Saudi Personal Data Protection Law (PDPL), its Implementing Regulations, applicable transfer regulations and SDAIA guidance. Guidance documents inform the drafting, but the Law and Regulations govern. Current references: https://dgp.sdaia.gov.sa/ and https://sdaia.gov.sa/.