Farqad is a school self-evaluation platform that processes data about schools, their staff and students, and about its own users and visitors. This policy was drawn up under the Personal Data Protection Law and its Implementing Regulations, and forms part of the Terms of Use.
If you are a teacher, student or parent whose school collects your data through the Platform, your school is the controller of that data and we process it on its behalf; clause 2 explains what that means for you.
Who we are and how to reach us
The provider responsible for the Platform — controller of account and visitor data, and processor of schools' data:
- Legal name
- Smart Innovations Business Solutions Co.
- Entity
- Limited liability company
- Commercial register no.
- 1011154843
- Unified national number
- 7037387433
- Tax identification number (ZATCA)
- 3119365012
- Website
- sibs.sa
- Contact channel
- Official contact form
- Reporting channel
- The violation reporting page
- For data protection requests (access, a copy, correction, destruction, objection) and questions: send your request through the official contact form above, choosing “Data protection request” as the kind of message, and the reply reaches your email.
- We verify the requester's identity before acting, to protect your data, and reply within thirty days of receiving the request, extendable by a further thirty days for a complex request, in which case we tell you.
Scope and roles
- We are the controller of user-account data (registration, sign-in and preferences), website-visitor data, data of people who write to us or request the platform guide, and subscription and payment data.
- We are the processor of what a school collects through the Platform about its staff, students and parents: evidence, surveys and their responses, classroom and environment observations, minutes, decisions and certificates. The school decides the purpose and the means; we process on its instructions under the school data clause of the Terms of Use.
- Where to send your request If you are a school's staff member, student or parent, send your request to your school first; it is the party entitled to decide it and we help it carry it out. If that is not possible, write to us and we will refer it and follow up.
The data we collect
We collect only what is needed to deliver and secure the service:
| Category | What it includes | Why |
|---|---|---|
| Account data | Name (first, father's, grandfather's and family name), mobile number, email address, WhatsApp number if you enable it, profile photo if you upload one, interface language | Creating the account and signing in with a verification code, and showing your name to your school's team and in the documents you take part in |
| National ID number | Entered in the profile when it is needed | Verifying the signer's identity in the minutes, decisions and certificates the school issues |
| School data | The school's name and identifying details, its members and their roles, and its official stamp if uploaded | Organising the evaluation team's work and issuing the school's documents |
| Evaluation content | Uploaded evidence and files, the school's surveys and their responses, classroom and school-environment observations with their photos, minutes, decisions, assignments and certificates, and community posts | The core of the service: documenting the evaluation cycle and generating reports and improvement plans |
| Electronic signature | An image of your signature (encrypted) and a record of each signing: its time, IP address and browser | Approving documents within the school and proving who signed and when |
| Security and sign-in data | IP address, browser, operating system and device type, a technical device fingerprint (an encrypted digest that cannot be traced back to your data), approximate country and city, and a log of sign-in attempts | Detecting suspicious sign-ins and alerting you, and protecting the account from abuse |
| Subscription and payment data | Plan, amount and date, the transfer reference, and any discount code used | Executing and evidencing the purchase and reconciling payments against the bank account; no card details are collected |
| Preferences and communication | Notification settings and channels, support requests and your correspondence with us | Sending the notifications you enabled and answering your requests |
| Visitor and prospect data | What you enter in the guide-request form (name, email, school, position) and the browsing data described in the cookies clause | Sending the guide and replying to you, and improving the site |
The most sensitive data
Four of the things we collect are more sensitive than the rest, and are handled specially on top of the general measures in the security clause:
| Data | How it is handled |
|---|---|
| National ID number | Encrypted at rest with a key held separately from the database, filtered out of operational logs, asked for only from someone signing a document the school issues, and shown to nobody but its owner and those the school authorises |
| Signature image | Encrypted at rest, displayed only within the document it signed, and never sent to any sub-processor |
| The school's official stamp | Encrypted at rest, and used only on the documents of the school that uploaded it |
| School-environment observation photos | May show students who are minors, so they are school data processed on its behalf alone: never sent to AI features, seen only by those the school authorises, and destroyed with the school's data |
We do not collect health, religious, security or affiliation data, nor biometric data (such as a fingerprint or face scan); a signature here is an image its owner uploads, not a biometric measurement. Schools should not place data of those kinds in the Platform, and should prefer anonymous responses wherever that still serves the purpose of the evaluation.
Where the data comes from
- From you directly when you register, fill in your profile and use the Platform.
- From your school when it adds you to its team, records you in its documents, or honours you with a certificate.
- From respondents to the school's surveys and observation instruments; a response may be anonymous depending on the survey's settings.
- Automatically from your browser and device when you use the Platform, and from the Cloudflare network that protects the site and supplies us with the approximate country and city of your address.
- From the transfer receipt you send us when you buy a subscription, to match the payment to your order.
What you must provide, and what you need not
Not everything we collect is required of you. This is what follows from withholding each kind:
| Data | Required? | If you withhold it |
|---|---|---|
| Name and mobile number | Required | No account can be created or signed into: sign-in works by a verification code sent to your mobile, and your name is what identifies you to your school's team |
| Email address | Required | Backup verification codes, account notifications and replies to your requests cannot reach you |
| National ID number | When needed | It does not stop you using the Platform, but no signed document can be issued in your name where the school requires its signer's identity to be verified |
| Signature image | When needed | You cannot approve minutes, decisions and certificates electronically; any other means of approval your school accepts remains open to you |
| WhatsApp number, profile photo, interface language | Optional | No effect on the service: the channel is simply not enabled, and your initials are shown instead of a photo |
| Bank transfer details | Required to purchase | The subscription cannot be approved: without the transfer reference the payment cannot be matched to your order |
| Guide-request form data | Optional | Nothing stops you using the site or buying a subscription; only the guide does not reach you |
| Consent to analytics cookies | Optional | No effect whatsoever: the Platform works in full if you decline, and no analytics file is loaded |
For what your school collects about you as controller — survey responses, performance observations — whether it is required is its decision and not ours, and whoever asks you for it there should tell you.
Why we process data, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Delivering the service: account creation, sign-in, evaluation tools, reports and documents | Performance of the contract with you or your school |
| Security: detecting suspicious sign-ins, preventing abuse, keeping audit logs | Legitimate interest in protecting the Platform and its users, and what the regulations require |
| Subscription, payment and invoicing | Performance of the contract and statutory financial obligations |
| Operational notifications (verification codes, assignments, reminders, security alerts) | Performance of the contract; your preferences govern the non-essential channels |
| Technical support and answering your requests | Performance of the contract and legitimate interest |
| Marketing: sending the platform guide and news to those who asked for it | Your consent, which you may withdraw at any time |
| Improving the service through aggregated, anonymised statistics | Legitimate interest; nothing identifies a person or a school |
| Compliance with the regulations and responding to competent authorities | Legal obligation |
We do not make the service conditional on your consent to processing that is not directly connected with it.
Artificial intelligence
- Some plans include text generation and analysis features (drafting minutes, certificate wording, summarising evidence and observations, SWOT analysis, interview questions) that run on language models at external providers.
- When such a feature is used we send the model provider only what the feature needs: the school's name and the text being worked on (such as an evidence description or a classroom observation), which may include the names of meeting participants or certificate honourees.
- The possible providers and their locations are listed in the sub-processor table; the school administrator chooses the actual provider from those we offer, or the default provider is used.
- We do not use school data to train any model, and we work only through paid programming interfaces whose terms prohibit using inputs for training; a provider may keep a transient operational log of the request (up to 30 days) for security and abuse prevention, after which it is deleted.
- The school administrator may disable all AI features at any time, after which nothing is sent.
- Outputs assist with drafting; no decision with legal or professional effect on an individual is taken on them alone, and you may object to your school about processing concerning you through these features.
Automated processing and decisions
- The Platform automatically computes indicators, scores, completion rates and performance levels from the evaluation data the school enters, and shows them in dashboards and reports. This is arithmetic from formulas published in the evaluation instruments themselves, not inference by a model.
- Some features run on language models, as the previous clause explains; their output is text shown to whoever asked for it, to accept, edit or discard.
- The Platform takes no decision about you with legal or professional effect on automated processing alone: any decision concerning an individual — a performance evaluation, an assignment, an honour, an end of membership — is taken by whoever the school authorises, after considering the output, and they are answerable for it.
- You may ask for human review of any automated output concerning you, ask what data it was built on, and object to it. Send the request to your school as controller of the evaluation data; we help it act on the request, and handle it ourselves for what we control.
Links to third-party sites
- The Platform and its website carry links to sites we do not run: the company's own site, the competent authorities' sources for the evaluation framework, and whatever links a school itself adds to its evidence, documents and posts.
- Once you leave the Platform through such a link, you are on a site governed by its own privacy policy; we neither control what it collects nor answer for it, so read its policy before entrusting it with your data.
- We place no advertising and no third-party tracking tags in the Platform, and what loads from outside sources is limited to what the sub-processors clause and the cookies clause set out.
Processing outside the Kingdom
- Some processing may take place at sub-processors outside the Kingdom, in accordance with the Personal Data Protection Law and the Regulation on Personal Data Transfer outside the Kingdom, under data processing agreements that bind each processor to a level of protection no lower than the regulations require.
- A school subject to particular requirements on where its data is processed (such as government bodies) should check that this is compatible with its obligations before use, and may write to us to discuss alternatives.
- Any material change to the processing arrangements is announced in this policy and school administrators are notified.
How we protect data
We apply organisational and technical measures proportionate to the sensitivity of the data, including:
- Full encryption of the connection (TLS with HSTS), so nothing travels between your browser and the Platform unencrypted.
- Passwordless sign-in with one-time verification codes, so there are no passwords to leak, with a temporary lock after repeated failed attempts.
- Encryption of signature images and school stamps at rest with keys held separately from the database, and operational secrets kept in an encrypted store.
- Layered permissions on three levels (system role, account role in the school, and access level on each record), so a member sees only what concerns their school and role.
- Detection of sign-ins from an unfamiliar device or country with an alert to the account holder, rate limiting on sign-in and forms, and bot verification.
- An activity log for every school recording who did what and when.
- Hourly database backups with periodic restore tests, and a mandatory backup before every deployment.
- The provider's staff access production data only within the narrowest operational scope and on a documented exceptional basis.
- A responsible disclosure programme for security vulnerabilities through the reporting page, which routes a report to whoever acts on it without depending on what the reporter typed into the subject field.
No method of transmission or storage is one hundred percent secure; we therefore review and improve these measures continuously, and the data security incidents clause sets out what we do if the unwanted happens.
How long we keep data
We keep data for as long as the purpose of processing it stands, then destroy or anonymise it, as follows:
| Data | Period |
|---|---|
| School data and evaluation content | For the subscription, then 90 days after it ends to allow renewal and export, then destroyed within 30 days from the live systems; after that it remains in the backups alone until their cycle — set out at the end of this table — runs out, where it is neither read nor used except to recover from a failure. The school's identifying record (its name and its members' memberships) stays with the subscription and billing records for the period set out below |
| Your personal account data | While your account exists; when you ask to close it, it is destroyed or anonymised within 30 days, while your name remains in your school's documents you took part in as part of its record |
| Sign-in log and security events | 12 months from when they occur |
| Expired sign-in sessions | Deleted within a day of expiring |
| Audit and school activity logs | With the school's data |
| Subscription and payment data | Ten years from the end of the financial year of the transaction, the period the commercial and tax regulations prescribe for keeping books and transaction records |
| Support requests and correspondence | 24 months from the request being closed |
| Guide-request and marketing data | Until you withdraw consent, and at most 12 months from the last contact |
| Read notifications | Archived after 90 days |
| Database backups | One copy an hour, kept on a tiered cycle: the last 24 hourly copies, 30 daily, 12 weekly, 12 monthly and 5 yearly — so the oldest copy held may be up to five years old. They are read only to recover from a failure or to run a restore drill, are used for no other purpose, and whatever was destroyed from the live systems falls out of them tier by tier as each tier ages out |
| Operational logs | A rolling cycle governed by file size rather than age, the oldest displaced as it fills — a few days in practice. They are filtered before writing of mobile number, national ID, WhatsApp number, signature and stamp, and are used only for security and fault tracing |
Notifications and marketing
- We send operational notifications the service needs (verification codes, assignments, reminders, security alerts) by email, SMS, in-Platform or browser notification, and WhatsApp for those who have explicitly enabled it.
- You control the channels, categories and timing of notifications from your account settings, and notification emails carry a one-click unsubscribe link; security messages and verification codes cannot be switched off while the account exists.
- We send marketing only to those who asked for it (such as a request for the platform guide), and you can withdraw consent at any time by writing to us, whereupon we stop and delete your marketing data.
- Schools that use messaging credits are responsible for the content they send to their staff and parents and for its recipients, under the Terms of Use.
Students' and minors' data
- No one under eighteen may create an account on the Platform. Schools may, however, collect data about students under that age through surveys and observation instruments, and school-environment observation photos may include students.
- The school is the controller of this data and must obtain a guardian's consent wherever the Personal Data Protection Law and its regulations require it, limit what it collects to what the evaluation purpose needs, and prefer anonymous responses.
- We process students' data only as a processor on the school's behalf, use it for no other purpose, and show it only to those the school has authorised.
- A guardian may exercise their child's rights through the school, or through us if that is not possible.
Your rights
Under the Personal Data Protection Law you have the right:
- To be informed: to know what we collect about you, why and how — which is what this policy sets out.
- To access and obtain a copy: to ask to see your data and receive a copy of it in a clear, readable format.
- To correction: to ask for your data to be corrected, completed or updated; you can edit your profile details directly from your account.
- To destruction: to ask for your data to be destroyed when its purpose has ended, subject to what the regulations require to be kept and what belongs to your school's record.
- To withdraw consent and object: to withdraw, at any time, consent on which processing was based, and to object to processing based on a legitimate interest.
- To complain: to lodge a complaint with the Saudi Data and AI Authority (SDAIA), the authority competent for the Personal Data Protection Law in the Kingdom, if you believe we have not handled your request properly.
To exercise any of these rights, send your request through the official contact form named in clause 1, choosing “Data protection request” as the kind of message. We verify your identity and reply within thirty days, extendable by a further thirty days for a complex request, telling you the reason. If your data is controlled by your school, send your request to it first and we will help it carry the request out.
Data security incidents
- If an incident affects the confidentiality, integrity or availability of your data, we contain it and assess its impact immediately.
- We notify affected schools, as controllers, without undue delay and within 72 hours of confirming the incident, so they can meet their own obligations, and we notify the Saudi Data and AI Authority (SDAIA) and data subjects as the law requires.
- The notification describes the nature of the incident, the data affected, the likely consequences, what we have done and what we recommend.
Updates to this policy
- Every version of this policy carries a version number and an effective date shown at the top of the page, with a note of what changed.
- We notify users and school administrators of material changes thirty days before they take effect, through the registered contact channel or within the Platform; clarifications and corrections take effect on publication.
- A change of sub-processors or of hosting location counts as a change that requires notification.
Contact
For any question about this policy or your data, write to us through the official contact form named in clause 1, choosing “Data protection request” as the kind of message.
What changed in version 2026.11
- Reporting a security vulnerability has moved to the reporting page, and the requirement to type [SECURITY] into the subject field is gone — the routing is the platform's job now, not the reporter's.
- Data protection requests are sent by choosing “Data protection request” as the kind of message on the form, in place of typing a phrase into the subject field.
- The contact clause and the rights clause name the same choice, so the policy no longer offers two routes for one request.
- The data protection authority is now named — the Saudi Data and AI Authority (SDAIA) — in your rights and in the data security incidents clause, where it used to read “the competent authority” with no name.
- Backup retention corrected. The policy described backups as “a short rolling cycle”, which understates them: the cycle is tiered and reaches five years at its yearly tier. The retention table now sets out all five tiers with their figures, and the school-data row says plainly that what is destroyed from the live systems stays in the backups until its tier ages out. Nothing about what we do has changed — what we say about it has.
- New clause “The most sensitive data”: the national ID number, the signature image, the school stamp and the school-environment photos, how each is handled, and what we do not collect at all.
- New clause “What you must provide, and what you need not”: a table separating the required from the optional and setting out what follows from withholding each.
- New clause “Automated processing and decisions”: what is computed automatically, that a decision about any individual is taken by a person, and your right to human review and to object.
- New clause “Links to third-party sites”: what takes you off the Platform is governed by its owner's policy, and we place no advertising or third-party tracking tags.
- Retention of subscription and payment records is now stated as a figure: ten years from the end of the transaction's financial year, in place of “the period the regulations prescribe”.
- Operational logs were separated from backups in the table, and described accurately: their cycle is governed by file size, not age.