Skip to content
FarqadFARQADFarqad
  1. Home
  2. Privacy Policy(current page)
Version 2026.09 · in force since 28 August 2026

Privacy policy of Farqad Platform

This policy sets out what data Farqad collects, why, who processes it and where, how long it is kept, and your rights over it — clearly and without generalities.

This is an earlier version

You are reading version 2026.09, which version 2026.11 has replaced. It stays published because whoever accepted a version has the right to read what they accepted.

Read the version in force

Farqad is a school self-evaluation platform that processes data about schools, their staff and students, and about its own users and visitors. This policy was drawn up under the Personal Data Protection Law and its Implementing Regulations, and forms part of the Terms of Use.

If you are a teacher, student or parent whose school collects your data through the Platform, your school is the controller of that data and we process it on its behalf; clause 2 explains what that means for you.

Related documents Terms of Use All documents and versions

Contents

  1. 1 Who we are and how to reach us
  2. 2 Scope and roles
  3. 3 The data we collect
  4. 4 Where the data comes from
  5. 5 Why we process data, and on what legal basis
  6. 6 Artificial intelligence
  7. 7 Who processes data with us
  8. 8 Processing outside the Kingdom
  9. 9 How we protect data
  10. 10 How long we keep data
  11. 11 Cookies and similar technologies
  12. 12 Notifications and marketing
  13. 13 Students' and minors' data
  14. 14 Your rights
  15. 15 Data security incidents
  16. 16 Updates to this policy
  17. 17 Contact
1

Who we are and how to reach us

The provider responsible for the Platform — controller of account and visitor data, and processor of schools' data:

Legal name
Smart Innovations Business Solutions Co.
Entity
Limited liability company
Commercial register no.
1011154843
Unified national number
7037387433
Tax identification number (ZATCA)
3119365012
Website
sibs.sa
Contact channel
Official contact form
Reporting channel
The violation reporting page
  • For data protection requests (access, a copy, correction, destruction, objection) and questions: send your request through the official contact form above with “Data protection” in the subject field, and the reply reaches your email.
  • We verify the requester's identity before acting, to protect your data, and reply within thirty days of receiving the request, extendable by a further thirty days for a complex request, in which case we tell you.
2

Scope and roles

  • We are the controller of user-account data (registration, sign-in and preferences), website-visitor data, data of people who write to us or request the platform guide, and subscription and payment data.
  • We are the processor of what a school collects through the Platform about its staff, students and parents: evidence, surveys and their responses, classroom and environment observations, minutes, decisions and certificates. The school decides the purpose and the means; we process on its instructions under the school data clause of the Terms of Use.
  • Where to send your request If you are a school's staff member, student or parent, send your request to your school first; it is the party entitled to decide it and we help it carry it out. If that is not possible, write to us and we will refer it and follow up.
3

The data we collect

We collect only what is needed to deliver and secure the service:

Category What it includes Why
Account data Name (first, father's, grandfather's and family name), mobile number, email address, WhatsApp number if you enable it, profile photo if you upload one, interface language Creating the account and signing in with a verification code, and showing your name to your school's team and in the documents you take part in
National ID number Entered in the profile when it is needed Verifying the signer's identity in the minutes, decisions and certificates the school issues
School data The school's name and identifying details, its members and their roles, and its official stamp if uploaded Organising the evaluation team's work and issuing the school's documents
Evaluation content Uploaded evidence and files, the school's surveys and their responses, classroom and school-environment observations with their photos, minutes, decisions, assignments and certificates, and community posts The core of the service: documenting the evaluation cycle and generating reports and improvement plans
Electronic signature An image of your signature (encrypted) and a record of each signing: its time, IP address and browser Approving documents within the school and proving who signed and when
Security and sign-in data IP address, browser, operating system and device type, a technical device fingerprint (an encrypted digest that cannot be traced back to your data), approximate country and city, and a log of sign-in attempts Detecting suspicious sign-ins and alerting you, and protecting the account from abuse
Subscription and payment data Plan, amount and date, the transfer reference, and any discount code used Executing and evidencing the purchase and reconciling payments against the bank account; no card details are collected
Preferences and communication Notification settings and channels, support requests and your correspondence with us Sending the notifications you enabled and answering your requests
Visitor and prospect data What you enter in the guide-request form (name, email, school, position) and the browsing data described in the cookies clause Sending the guide and replying to you, and improving the site
4

Where the data comes from

  • From you directly when you register, fill in your profile and use the Platform.
  • From your school when it adds you to its team, records you in its documents, or honours you with a certificate.
  • From respondents to the school's surveys and observation instruments; a response may be anonymous depending on the survey's settings.
  • Automatically from your browser and device when you use the Platform, and from the Cloudflare network that protects the site and supplies us with the approximate country and city of your address.
  • From the transfer receipt you send us when you buy a subscription, to match the payment to your order.
5

Why we process data, and on what legal basis

Purpose Legal basis
Delivering the service: account creation, sign-in, evaluation tools, reports and documents Performance of the contract with you or your school
Security: detecting suspicious sign-ins, preventing abuse, keeping audit logs Legitimate interest in protecting the Platform and its users, and what the regulations require
Subscription, payment and invoicing Performance of the contract and statutory financial obligations
Operational notifications (verification codes, assignments, reminders, security alerts) Performance of the contract; your preferences govern the non-essential channels
Technical support and answering your requests Performance of the contract and legitimate interest
Marketing: sending the platform guide and news to those who asked for it Your consent, which you may withdraw at any time
Improving the service through aggregated, anonymised statistics Legitimate interest; nothing identifies a person or a school
Compliance with the regulations and responding to competent authorities Legal obligation

We do not make the service conditional on your consent to processing that is not directly connected with it.

6

Artificial intelligence

  • Some plans include text generation and analysis features (drafting minutes, certificate wording, summarising evidence and observations, SWOT analysis, interview questions) that run on language models at external providers.
  • When such a feature is used we send the model provider only what the feature needs: the school's name and the text being worked on (such as an evidence description or a classroom observation), which may include the names of meeting participants or certificate honourees.
  • The possible providers and their locations are listed in the sub-processor table; the school administrator chooses the actual provider from those we offer, or the default provider is used.
  • We do not use school data to train any model, and we work only through paid programming interfaces whose terms prohibit using inputs for training; a provider may keep a transient operational log of the request (up to 30 days) for security and abuse prevention, after which it is deleted.
  • The school administrator may disable all AI features at any time, after which nothing is sent.
  • Outputs assist with drafting; no decision with legal or professional effect on an individual is taken on them alone, and you may object to your school about processing concerning you through these features.
7

Who processes data with us

We do not sell, rent or share schools' or users' data for marketing. Within the stated purpose, the following sub-processors — which we bind by contract to confidentiality and security — have access to it:

Provider Purpose
Hosting provider Running the servers and the database, and storing schools' files, backups and operational logs
Cloudflare Protecting and accelerating the site, and verifying that a visitor is not a bot (Turnstile) at sign-in and on the support form
Microsoft Clarity Site usage analytics: recording browsing and click activity and heat maps, with sensitive input fields masked (production only, and after your consent)
Resend Sending the Platform's outgoing email from its own farq.ai domain, including verification codes and notifications
Taqnyat Sending SMS messages and verification codes
Meta (WhatsApp Business) WhatsApp messages for those who enable them — once the service is offered
AI model providers: Ollama, Anthropic, OpenAI, Google AI features, according to the school administrator's choice
Google, Apple and Mozilla (push services) Delivering browser notifications to those who enable them

We may also disclose specific data when the law requires it or a competent authority requests it within its powers, and only to the extent of the request; and to whoever takes over the Platform if its ownership changes, with this policy remaining binding on them. This list is updated on every change, and school administrators are notified.

8

Processing outside the Kingdom

  • Some processing may take place at sub-processors outside the Kingdom, in accordance with the Personal Data Protection Law and the Regulation on Personal Data Transfer outside the Kingdom, under data processing agreements that bind each processor to a level of protection no lower than the regulations require.
  • A school subject to particular requirements on where its data is processed (such as government bodies) should check that this is compatible with its obligations before use, and may write to us to discuss alternatives.
  • Any material change to the processing arrangements is announced in this policy and school administrators are notified.
9

How we protect data

We apply organisational and technical measures proportionate to the sensitivity of the data, including:

  • Full encryption of the connection (TLS with HSTS), so nothing travels between your browser and the Platform unencrypted.
  • Passwordless sign-in with one-time verification codes, so there are no passwords to leak, with a temporary lock after repeated failed attempts.
  • Encryption of signature images and school stamps at rest with keys held separately from the database, and operational secrets kept in an encrypted store.
  • Layered permissions on three levels (system role, account role in the school, and access level on each record), so a member sees only what concerns their school and role.
  • Detection of sign-ins from an unfamiliar device or country with an alert to the account holder, rate limiting on sign-in and forms, and bot verification.
  • An activity log for every school recording who did what and when.
  • Hourly database backups with periodic restore tests, and a mandatory backup before every deployment.
  • The provider's staff access production data only within the narrowest operational scope and on a documented exceptional basis.
  • A responsible disclosure programme for security vulnerabilities through the official contact form, with [SECURITY] in the subject field.

No method of transmission or storage is one hundred percent secure; we therefore review and improve these measures continuously, and the data security incidents clause sets out what we do if the unwanted happens.

10

How long we keep data

We keep data for as long as the purpose of processing it stands, then destroy or anonymise it, as follows:

Data Period
School data and evaluation content For the subscription, then 90 days after it ends to allow renewal and export, then destroyed within 30 days from the live systems and then from the backups according to their cycle; the school's identifying record (its name and its members' memberships) stays with the subscription and billing records for the period the regulations prescribe
Your personal account data While your account exists; when you ask to close it, it is destroyed or anonymised within 30 days, while your name remains in your school's documents you took part in as part of its record
Sign-in log and security events 12 months from when they occur
Expired sign-in sessions Deleted within a day of expiring
Audit and school activity logs With the school's data
Subscription and payment data The period the tax and commercial regulations prescribe for keeping transaction records
Support requests and correspondence 24 months from the request being closed
Guide-request and marketing data Until you withdraw consent, and at most 12 months from the last contact
Read notifications Archived after 90 days
Operational logs and backups A short rolling cycle for security and recovery, and used for nothing else
11

Cookies and similar technologies

We use cookies and local storage in your browser for the following purposes:

Name or source Type Purpose and duration
Platform session Essential Identifying your session after sign-in and protecting forms from forgery; ends with the session
Cloudflare / Turnstile Essential Protecting the site from abuse and verifying that a visitor is not a bot; short durations
theme Functional Remembering your choice of light or dark mode; one year
op_limit and local storage Functional Interface preferences and operational limits; until you clear them
analytics_consent Functional Remembering your answer to the analytics consent bar (accept or decline); one year
Microsoft Clarity Analytical Understanding how the site is used in order to improve it: recording browsing and click activity without sensitive input fields; loaded only after you accept on the consent bar, production only, durations set by Microsoft (up to one year)

Analytics cookies run only if you accept them on the bar shown on your first visit, and you can change your answer by deleting the analytics_consent cookie from your browser so the bar appears again. You can delete or block cookies from your browser settings; this does not affect the Platform except for the essential cookies. If you enable browser notifications, that is recorded with your permission and you can withdraw it from the browser at any time.

12

Notifications and marketing

  • We send operational notifications the service needs (verification codes, assignments, reminders, security alerts) by email, SMS, in-Platform or browser notification, and WhatsApp for those who have explicitly enabled it.
  • You control the channels, categories and timing of notifications from your account settings, and notification emails carry a one-click unsubscribe link; security messages and verification codes cannot be switched off while the account exists.
  • We send marketing only to those who asked for it (such as a request for the platform guide), and you can withdraw consent at any time by writing to us, whereupon we stop and delete your marketing data.
  • Schools that use messaging credits are responsible for the content they send to their staff and parents and for its recipients, under the Terms of Use.
13

Students' and minors' data

  • No one under eighteen may create an account on the Platform. Schools may, however, collect data about students under that age through surveys and observation instruments, and school-environment observation photos may include students.
  • The school is the controller of this data and must obtain a guardian's consent wherever the Personal Data Protection Law and its regulations require it, limit what it collects to what the evaluation purpose needs, and prefer anonymous responses.
  • We process students' data only as a processor on the school's behalf, use it for no other purpose, and show it only to those the school has authorised.
  • A guardian may exercise their child's rights through the school, or through us if that is not possible.
14

Your rights

Under the Personal Data Protection Law you have the right:

  • To be informed: to know what we collect about you, why and how — which is what this policy sets out.
  • To access and obtain a copy: to ask to see your data and receive a copy of it in a clear, readable format.
  • To correction: to ask for your data to be corrected, completed or updated; you can edit your profile details directly from your account.
  • To destruction: to ask for your data to be destroyed when its purpose has ended, subject to what the regulations require to be kept and what belongs to your school's record.
  • To withdraw consent and object: to withdraw, at any time, consent on which processing was based, and to object to processing based on a legitimate interest.
  • To complain: to lodge a complaint with the competent personal-data-protection authority in the Kingdom if you believe we have not handled your request properly.

To exercise any of these rights, send your request through the official contact form named in clause 1. We verify your identity and reply within thirty days, extendable by a further thirty days for a complex request, telling you the reason. If your data is controlled by your school, send your request to it first and we will help it carry the request out.

15

Data security incidents

  • If an incident affects the confidentiality, integrity or availability of your data, we contain it and assess its impact immediately.
  • We notify affected schools, as controllers, without undue delay and within 72 hours of confirming the incident, so they can meet their own obligations, and we notify the competent authority and data subjects as the law requires.
  • The notification describes the nature of the incident, the data affected, the likely consequences, what we have done and what we recommend.
16

Updates to this policy

  • Every version of this policy carries a version number and an effective date shown at the top of the page, with a note of what changed.
  • We notify users and school administrators of material changes thirty days before they take effect, through the registered contact channel or within the Platform; clarifications and corrections take effect on publication.
  • A change of sub-processors or of hosting location counts as a change that requires notification.
17

Contact

For any question about this policy or your data, write to us through the official contact form named in clause 1 with “Data protection” in the subject field.

What changed in version 2026.09

  • The payment provider is removed from the list of sub-processors: payment is by bank transfer and no card details reach us.
  • The subscription and payment data row now records the transfer reference in place of the card brand and last four digits, and the payment provider is no longer a source of data about you.

Earlier versions: 2026.10, 2026.09, 2026.08

Farqad Platform

Farqad Platform

As constant as Farqad

Documented evaluation, in clear steps

Follow us

Platform

  • About
  • The framework
  • Pricing
  • Status

Support

  • Help
  • FAQ
  • Contact
  • Report

Terms & privacy

  • Terms
  • Privacy

© 2026 Farqad Platform — all rights reserved to Smart Innovations for Business Solutions

Commercial register 1011154843 · Unified number 7037387433 · Contact us

Analytics cookies

They help us understand how the pages are used and improve them. Details