Skip to content
FarqadFARQADFarqad
  1. Home
  2. Privacy Policy(current page)
Version 2026.11 · in force since 28 August 2026

Privacy policy of Farqad Platform

This policy sets out what data Farqad collects, why, who processes it and where, how long it is kept, and your rights over it — clearly and without generalities.

Farqad is a school self-evaluation platform that processes data about schools, their staff and students, and about its own users and visitors. This policy was drawn up under the Personal Data Protection Law and its Implementing Regulations, and forms part of the Terms of Use.

If you are a teacher, student or parent whose school collects your data through the Platform, your school is the controller of that data and we process it on its behalf; clause 2 explains what that means for you.

Related documents Terms of Use All documents and versions

Contents

  1. 1 Who we are and how to reach us
  2. 2 Scope and roles
  3. 3 The data we collect
  4. 4 The most sensitive data
  5. 5 Where the data comes from
  6. 6 What you must provide, and what you need not
  7. 7 Why we process data, and on what legal basis
  8. 8 Artificial intelligence
  9. 9 Automated processing and decisions
  10. 10 Who processes data with us
  11. 11 Links to third-party sites
  12. 12 Processing outside the Kingdom
  13. 13 How we protect data
  14. 14 How long we keep data
  15. 15 Cookies and similar technologies
  16. 16 Notifications and marketing
  17. 17 Students' and minors' data
  18. 18 Your rights
  19. 19 Data security incidents
  20. 20 Updates to this policy
  21. 21 Contact
1

Who we are and how to reach us

The provider responsible for the Platform — controller of account and visitor data, and processor of schools' data:

Legal name
Smart Innovations Business Solutions Co.
Entity
Limited liability company
Commercial register no.
1011154843
Unified national number
7037387433
Tax identification number (ZATCA)
3119365012
Website
sibs.sa
Contact channel
Official contact form
Reporting channel
The violation reporting page
  • For data protection requests (access, a copy, correction, destruction, objection) and questions: send your request through the official contact form above, choosing “Data protection request” as the kind of message, and the reply reaches your email.
  • We verify the requester's identity before acting, to protect your data, and reply within thirty days of receiving the request, extendable by a further thirty days for a complex request, in which case we tell you.
2

Scope and roles

  • We are the controller of user-account data (registration, sign-in and preferences), website-visitor data, data of people who write to us or request the platform guide, and subscription and payment data.
  • We are the processor of what a school collects through the Platform about its staff, students and parents: evidence, surveys and their responses, classroom and environment observations, minutes, decisions and certificates. The school decides the purpose and the means; we process on its instructions under the school data clause of the Terms of Use.
  • Where to send your request If you are a school's staff member, student or parent, send your request to your school first; it is the party entitled to decide it and we help it carry it out. If that is not possible, write to us and we will refer it and follow up.
3

The data we collect

We collect only what is needed to deliver and secure the service:

Category What it includes Why
Account data Name (first, father's, grandfather's and family name), mobile number, email address, WhatsApp number if you enable it, profile photo if you upload one, interface language Creating the account and signing in with a verification code, and showing your name to your school's team and in the documents you take part in
National ID number Entered in the profile when it is needed Verifying the signer's identity in the minutes, decisions and certificates the school issues
School data The school's name and identifying details, its members and their roles, and its official stamp if uploaded Organising the evaluation team's work and issuing the school's documents
Evaluation content Uploaded evidence and files, the school's surveys and their responses, classroom and school-environment observations with their photos, minutes, decisions, assignments and certificates, and community posts The core of the service: documenting the evaluation cycle and generating reports and improvement plans
Electronic signature An image of your signature (encrypted) and a record of each signing: its time, IP address and browser Approving documents within the school and proving who signed and when
Security and sign-in data IP address, browser, operating system and device type, a technical device fingerprint (an encrypted digest that cannot be traced back to your data), approximate country and city, and a log of sign-in attempts Detecting suspicious sign-ins and alerting you, and protecting the account from abuse
Subscription and payment data Plan, amount and date, the transfer reference, and any discount code used Executing and evidencing the purchase and reconciling payments against the bank account; no card details are collected
Preferences and communication Notification settings and channels, support requests and your correspondence with us Sending the notifications you enabled and answering your requests
Visitor and prospect data What you enter in the guide-request form (name, email, school, position) and the browsing data described in the cookies clause Sending the guide and replying to you, and improving the site
4

The most sensitive data

Four of the things we collect are more sensitive than the rest, and are handled specially on top of the general measures in the security clause:

Data How it is handled
National ID number Encrypted at rest with a key held separately from the database, filtered out of operational logs, asked for only from someone signing a document the school issues, and shown to nobody but its owner and those the school authorises
Signature image Encrypted at rest, displayed only within the document it signed, and never sent to any sub-processor
The school's official stamp Encrypted at rest, and used only on the documents of the school that uploaded it
School-environment observation photos May show students who are minors, so they are school data processed on its behalf alone: never sent to AI features, seen only by those the school authorises, and destroyed with the school's data

We do not collect health, religious, security or affiliation data, nor biometric data (such as a fingerprint or face scan); a signature here is an image its owner uploads, not a biometric measurement. Schools should not place data of those kinds in the Platform, and should prefer anonymous responses wherever that still serves the purpose of the evaluation.

5

Where the data comes from

  • From you directly when you register, fill in your profile and use the Platform.
  • From your school when it adds you to its team, records you in its documents, or honours you with a certificate.
  • From respondents to the school's surveys and observation instruments; a response may be anonymous depending on the survey's settings.
  • Automatically from your browser and device when you use the Platform, and from the Cloudflare network that protects the site and supplies us with the approximate country and city of your address.
  • From the transfer receipt you send us when you buy a subscription, to match the payment to your order.
6

What you must provide, and what you need not

Not everything we collect is required of you. This is what follows from withholding each kind:

Data Required? If you withhold it
Name and mobile number Required No account can be created or signed into: sign-in works by a verification code sent to your mobile, and your name is what identifies you to your school's team
Email address Required Backup verification codes, account notifications and replies to your requests cannot reach you
National ID number When needed It does not stop you using the Platform, but no signed document can be issued in your name where the school requires its signer's identity to be verified
Signature image When needed You cannot approve minutes, decisions and certificates electronically; any other means of approval your school accepts remains open to you
WhatsApp number, profile photo, interface language Optional No effect on the service: the channel is simply not enabled, and your initials are shown instead of a photo
Bank transfer details Required to purchase The subscription cannot be approved: without the transfer reference the payment cannot be matched to your order
Guide-request form data Optional Nothing stops you using the site or buying a subscription; only the guide does not reach you
Consent to analytics cookies Optional No effect whatsoever: the Platform works in full if you decline, and no analytics file is loaded

For what your school collects about you as controller — survey responses, performance observations — whether it is required is its decision and not ours, and whoever asks you for it there should tell you.

7

Why we process data, and on what legal basis

Purpose Legal basis
Delivering the service: account creation, sign-in, evaluation tools, reports and documents Performance of the contract with you or your school
Security: detecting suspicious sign-ins, preventing abuse, keeping audit logs Legitimate interest in protecting the Platform and its users, and what the regulations require
Subscription, payment and invoicing Performance of the contract and statutory financial obligations
Operational notifications (verification codes, assignments, reminders, security alerts) Performance of the contract; your preferences govern the non-essential channels
Technical support and answering your requests Performance of the contract and legitimate interest
Marketing: sending the platform guide and news to those who asked for it Your consent, which you may withdraw at any time
Improving the service through aggregated, anonymised statistics Legitimate interest; nothing identifies a person or a school
Compliance with the regulations and responding to competent authorities Legal obligation

We do not make the service conditional on your consent to processing that is not directly connected with it.

8

Artificial intelligence

  • Some plans include text generation and analysis features (drafting minutes, certificate wording, summarising evidence and observations, SWOT analysis, interview questions) that run on language models at external providers.
  • When such a feature is used we send the model provider only what the feature needs: the school's name and the text being worked on (such as an evidence description or a classroom observation), which may include the names of meeting participants or certificate honourees.
  • The possible providers and their locations are listed in the sub-processor table; the school administrator chooses the actual provider from those we offer, or the default provider is used.
  • We do not use school data to train any model, and we work only through paid programming interfaces whose terms prohibit using inputs for training; a provider may keep a transient operational log of the request (up to 30 days) for security and abuse prevention, after which it is deleted.
  • The school administrator may disable all AI features at any time, after which nothing is sent.
  • Outputs assist with drafting; no decision with legal or professional effect on an individual is taken on them alone, and you may object to your school about processing concerning you through these features.
9

Automated processing and decisions

  • The Platform automatically computes indicators, scores, completion rates and performance levels from the evaluation data the school enters, and shows them in dashboards and reports. This is arithmetic from formulas published in the evaluation instruments themselves, not inference by a model.
  • Some features run on language models, as the previous clause explains; their output is text shown to whoever asked for it, to accept, edit or discard.
  • The Platform takes no decision about you with legal or professional effect on automated processing alone: any decision concerning an individual — a performance evaluation, an assignment, an honour, an end of membership — is taken by whoever the school authorises, after considering the output, and they are answerable for it.
  • You may ask for human review of any automated output concerning you, ask what data it was built on, and object to it. Send the request to your school as controller of the evaluation data; we help it act on the request, and handle it ourselves for what we control.
10

Who processes data with us

We do not sell, rent or share schools' or users' data for marketing. Within the stated purpose, the following sub-processors — which we bind by contract to confidentiality and security — have access to it:

Provider Purpose
Hosting provider Running the servers and the database, and storing schools' files, backups and operational logs
Cloudflare Protecting and accelerating the site, and verifying that a visitor is not a bot (Turnstile) at sign-in and on the support form
Microsoft Clarity Site usage analytics: recording browsing and click activity and heat maps, with sensitive input fields masked (production only, and after your consent)
Resend Sending the Platform's outgoing email from its own farq.ai domain, including verification codes and notifications
Taqnyat Sending SMS messages and verification codes
Meta (WhatsApp Business) WhatsApp messages for those who enable them — once the service is offered
AI model providers: Ollama, Anthropic, OpenAI, Google AI features, according to the school administrator's choice
Google, Apple and Mozilla (push services) Delivering browser notifications to those who enable them

We may also disclose specific data when the law requires it or a competent authority requests it within its powers, and only to the extent of the request; and to whoever takes over the Platform if its ownership changes, with this policy remaining binding on them. This list is updated on every change, and school administrators are notified.

11

Links to third-party sites

  • The Platform and its website carry links to sites we do not run: the company's own site, the competent authorities' sources for the evaluation framework, and whatever links a school itself adds to its evidence, documents and posts.
  • Once you leave the Platform through such a link, you are on a site governed by its own privacy policy; we neither control what it collects nor answer for it, so read its policy before entrusting it with your data.
  • We place no advertising and no third-party tracking tags in the Platform, and what loads from outside sources is limited to what the sub-processors clause and the cookies clause set out.
12

Processing outside the Kingdom

  • Some processing may take place at sub-processors outside the Kingdom, in accordance with the Personal Data Protection Law and the Regulation on Personal Data Transfer outside the Kingdom, under data processing agreements that bind each processor to a level of protection no lower than the regulations require.
  • A school subject to particular requirements on where its data is processed (such as government bodies) should check that this is compatible with its obligations before use, and may write to us to discuss alternatives.
  • Any material change to the processing arrangements is announced in this policy and school administrators are notified.
13

How we protect data

We apply organisational and technical measures proportionate to the sensitivity of the data, including:

  • Full encryption of the connection (TLS with HSTS), so nothing travels between your browser and the Platform unencrypted.
  • Passwordless sign-in with one-time verification codes, so there are no passwords to leak, with a temporary lock after repeated failed attempts.
  • Encryption of signature images and school stamps at rest with keys held separately from the database, and operational secrets kept in an encrypted store.
  • Layered permissions on three levels (system role, account role in the school, and access level on each record), so a member sees only what concerns their school and role.
  • Detection of sign-ins from an unfamiliar device or country with an alert to the account holder, rate limiting on sign-in and forms, and bot verification.
  • An activity log for every school recording who did what and when.
  • Hourly database backups with periodic restore tests, and a mandatory backup before every deployment.
  • The provider's staff access production data only within the narrowest operational scope and on a documented exceptional basis.
  • A responsible disclosure programme for security vulnerabilities through the reporting page, which routes a report to whoever acts on it without depending on what the reporter typed into the subject field.

No method of transmission or storage is one hundred percent secure; we therefore review and improve these measures continuously, and the data security incidents clause sets out what we do if the unwanted happens.

14

How long we keep data

We keep data for as long as the purpose of processing it stands, then destroy or anonymise it, as follows:

Data Period
School data and evaluation content For the subscription, then 90 days after it ends to allow renewal and export, then destroyed within 30 days from the live systems; after that it remains in the backups alone until their cycle — set out at the end of this table — runs out, where it is neither read nor used except to recover from a failure. The school's identifying record (its name and its members' memberships) stays with the subscription and billing records for the period set out below
Your personal account data While your account exists; when you ask to close it, it is destroyed or anonymised within 30 days, while your name remains in your school's documents you took part in as part of its record
Sign-in log and security events 12 months from when they occur
Expired sign-in sessions Deleted within a day of expiring
Audit and school activity logs With the school's data
Subscription and payment data Ten years from the end of the financial year of the transaction, the period the commercial and tax regulations prescribe for keeping books and transaction records
Support requests and correspondence 24 months from the request being closed
Guide-request and marketing data Until you withdraw consent, and at most 12 months from the last contact
Read notifications Archived after 90 days
Database backups One copy an hour, kept on a tiered cycle: the last 24 hourly copies, 30 daily, 12 weekly, 12 monthly and 5 yearly — so the oldest copy held may be up to five years old. They are read only to recover from a failure or to run a restore drill, are used for no other purpose, and whatever was destroyed from the live systems falls out of them tier by tier as each tier ages out
Operational logs A rolling cycle governed by file size rather than age, the oldest displaced as it fills — a few days in practice. They are filtered before writing of mobile number, national ID, WhatsApp number, signature and stamp, and are used only for security and fault tracing
15

Cookies and similar technologies

We use cookies and local storage in your browser for the following purposes:

Name or source Type Purpose and duration
Platform session Essential Identifying your session after sign-in and protecting forms from forgery; ends with the session
Cloudflare / Turnstile Essential Protecting the site from abuse and verifying that a visitor is not a bot; short durations
theme Functional Remembering your choice of light or dark mode; one year
op_limit and local storage Functional Interface preferences and operational limits; until you clear them
analytics_consent Functional Remembering your answer to the analytics consent bar (accept or decline); one year
Microsoft Clarity Analytical Understanding how the site is used in order to improve it: recording browsing and click activity without sensitive input fields; loaded only after you accept on the consent bar, production only, durations set by Microsoft (up to one year)

Analytics cookies run only if you accept them on the bar shown on your first visit, and you can change your answer by deleting the analytics_consent cookie from your browser so the bar appears again. You can delete or block cookies from your browser settings; this does not affect the Platform except for the essential cookies. If you enable browser notifications, that is recorded with your permission and you can withdraw it from the browser at any time.

16

Notifications and marketing

  • We send operational notifications the service needs (verification codes, assignments, reminders, security alerts) by email, SMS, in-Platform or browser notification, and WhatsApp for those who have explicitly enabled it.
  • You control the channels, categories and timing of notifications from your account settings, and notification emails carry a one-click unsubscribe link; security messages and verification codes cannot be switched off while the account exists.
  • We send marketing only to those who asked for it (such as a request for the platform guide), and you can withdraw consent at any time by writing to us, whereupon we stop and delete your marketing data.
  • Schools that use messaging credits are responsible for the content they send to their staff and parents and for its recipients, under the Terms of Use.
17

Students' and minors' data

  • No one under eighteen may create an account on the Platform. Schools may, however, collect data about students under that age through surveys and observation instruments, and school-environment observation photos may include students.
  • The school is the controller of this data and must obtain a guardian's consent wherever the Personal Data Protection Law and its regulations require it, limit what it collects to what the evaluation purpose needs, and prefer anonymous responses.
  • We process students' data only as a processor on the school's behalf, use it for no other purpose, and show it only to those the school has authorised.
  • A guardian may exercise their child's rights through the school, or through us if that is not possible.
18

Your rights

Under the Personal Data Protection Law you have the right:

  • To be informed: to know what we collect about you, why and how — which is what this policy sets out.
  • To access and obtain a copy: to ask to see your data and receive a copy of it in a clear, readable format.
  • To correction: to ask for your data to be corrected, completed or updated; you can edit your profile details directly from your account.
  • To destruction: to ask for your data to be destroyed when its purpose has ended, subject to what the regulations require to be kept and what belongs to your school's record.
  • To withdraw consent and object: to withdraw, at any time, consent on which processing was based, and to object to processing based on a legitimate interest.
  • To complain: to lodge a complaint with the Saudi Data and AI Authority (SDAIA), the authority competent for the Personal Data Protection Law in the Kingdom, if you believe we have not handled your request properly.

To exercise any of these rights, send your request through the official contact form named in clause 1, choosing “Data protection request” as the kind of message. We verify your identity and reply within thirty days, extendable by a further thirty days for a complex request, telling you the reason. If your data is controlled by your school, send your request to it first and we will help it carry the request out.

19

Data security incidents

  • If an incident affects the confidentiality, integrity or availability of your data, we contain it and assess its impact immediately.
  • We notify affected schools, as controllers, without undue delay and within 72 hours of confirming the incident, so they can meet their own obligations, and we notify the Saudi Data and AI Authority (SDAIA) and data subjects as the law requires.
  • The notification describes the nature of the incident, the data affected, the likely consequences, what we have done and what we recommend.
20

Updates to this policy

  • Every version of this policy carries a version number and an effective date shown at the top of the page, with a note of what changed.
  • We notify users and school administrators of material changes thirty days before they take effect, through the registered contact channel or within the Platform; clarifications and corrections take effect on publication.
  • A change of sub-processors or of hosting location counts as a change that requires notification.
21

Contact

For any question about this policy or your data, write to us through the official contact form named in clause 1, choosing “Data protection request” as the kind of message.

What changed in version 2026.11

  • Reporting a security vulnerability has moved to the reporting page, and the requirement to type [SECURITY] into the subject field is gone — the routing is the platform's job now, not the reporter's.
  • Data protection requests are sent by choosing “Data protection request” as the kind of message on the form, in place of typing a phrase into the subject field.
  • The contact clause and the rights clause name the same choice, so the policy no longer offers two routes for one request.
  • The data protection authority is now named — the Saudi Data and AI Authority (SDAIA) — in your rights and in the data security incidents clause, where it used to read “the competent authority” with no name.
  • Backup retention corrected. The policy described backups as “a short rolling cycle”, which understates them: the cycle is tiered and reaches five years at its yearly tier. The retention table now sets out all five tiers with their figures, and the school-data row says plainly that what is destroyed from the live systems stays in the backups until its tier ages out. Nothing about what we do has changed — what we say about it has.
  • New clause “The most sensitive data”: the national ID number, the signature image, the school stamp and the school-environment photos, how each is handled, and what we do not collect at all.
  • New clause “What you must provide, and what you need not”: a table separating the required from the optional and setting out what follows from withholding each.
  • New clause “Automated processing and decisions”: what is computed automatically, that a decision about any individual is taken by a person, and your right to human review and to object.
  • New clause “Links to third-party sites”: what takes you off the Platform is governed by its owner's policy, and we place no advertising or third-party tracking tags.
  • Retention of subscription and payment records is now stated as a figure: ten years from the end of the transaction's financial year, in place of “the period the regulations prescribe”.
  • Operational logs were separated from backups in the table, and described accurately: their cycle is governed by file size, not age.

Earlier versions: 2026.10, 2026.09, 2026.08

Farqad Platform

Farqad Platform

As constant as Farqad

Documented evaluation, in clear steps

Follow us

Platform

  • About
  • The framework
  • Pricing
  • Status

Support

  • Help
  • FAQ
  • Contact
  • Report

Terms & privacy

  • Terms
  • Privacy

© 2026 Farqad Platform — all rights reserved to Smart Innovations for Business Solutions

Commercial register 1011154843 · Unified number 7037387433 · Contact us

Analytics cookies

They help us understand how the pages are used and improve them. Details