This is an earlier version
You are reading version 2026.09, which version 2026.11 has replaced. It stays published because whoever accepted a version has the right to read what they accepted.
Read the version in forceFarqad is a school self-evaluation platform that processes data about schools, their staff and students, and about its own users and visitors. This policy was drawn up under the Personal Data Protection Law and its Implementing Regulations, and forms part of the Terms of Use.
If you are a teacher, student or parent whose school collects your data through the Platform, your school is the controller of that data and we process it on its behalf; clause 2 explains what that means for you.
Who we are and how to reach us
The provider responsible for the Platform — controller of account and visitor data, and processor of schools' data:
- Legal name
- Smart Innovations Business Solutions Co.
- Entity
- Limited liability company
- Commercial register no.
- 1011154843
- Unified national number
- 7037387433
- Tax identification number (ZATCA)
- 3119365012
- Website
- sibs.sa
- Contact channel
- Official contact form
- Reporting channel
- The violation reporting page
- For data protection requests (access, a copy, correction, destruction, objection) and questions: send your request through the official contact form above with “Data protection” in the subject field, and the reply reaches your email.
- We verify the requester's identity before acting, to protect your data, and reply within thirty days of receiving the request, extendable by a further thirty days for a complex request, in which case we tell you.
Scope and roles
- We are the controller of user-account data (registration, sign-in and preferences), website-visitor data, data of people who write to us or request the platform guide, and subscription and payment data.
- We are the processor of what a school collects through the Platform about its staff, students and parents: evidence, surveys and their responses, classroom and environment observations, minutes, decisions and certificates. The school decides the purpose and the means; we process on its instructions under the school data clause of the Terms of Use.
- Where to send your request If you are a school's staff member, student or parent, send your request to your school first; it is the party entitled to decide it and we help it carry it out. If that is not possible, write to us and we will refer it and follow up.
The data we collect
We collect only what is needed to deliver and secure the service:
| Category | What it includes | Why |
|---|---|---|
| Account data | Name (first, father's, grandfather's and family name), mobile number, email address, WhatsApp number if you enable it, profile photo if you upload one, interface language | Creating the account and signing in with a verification code, and showing your name to your school's team and in the documents you take part in |
| National ID number | Entered in the profile when it is needed | Verifying the signer's identity in the minutes, decisions and certificates the school issues |
| School data | The school's name and identifying details, its members and their roles, and its official stamp if uploaded | Organising the evaluation team's work and issuing the school's documents |
| Evaluation content | Uploaded evidence and files, the school's surveys and their responses, classroom and school-environment observations with their photos, minutes, decisions, assignments and certificates, and community posts | The core of the service: documenting the evaluation cycle and generating reports and improvement plans |
| Electronic signature | An image of your signature (encrypted) and a record of each signing: its time, IP address and browser | Approving documents within the school and proving who signed and when |
| Security and sign-in data | IP address, browser, operating system and device type, a technical device fingerprint (an encrypted digest that cannot be traced back to your data), approximate country and city, and a log of sign-in attempts | Detecting suspicious sign-ins and alerting you, and protecting the account from abuse |
| Subscription and payment data | Plan, amount and date, the transfer reference, and any discount code used | Executing and evidencing the purchase and reconciling payments against the bank account; no card details are collected |
| Preferences and communication | Notification settings and channels, support requests and your correspondence with us | Sending the notifications you enabled and answering your requests |
| Visitor and prospect data | What you enter in the guide-request form (name, email, school, position) and the browsing data described in the cookies clause | Sending the guide and replying to you, and improving the site |
Where the data comes from
- From you directly when you register, fill in your profile and use the Platform.
- From your school when it adds you to its team, records you in its documents, or honours you with a certificate.
- From respondents to the school's surveys and observation instruments; a response may be anonymous depending on the survey's settings.
- Automatically from your browser and device when you use the Platform, and from the Cloudflare network that protects the site and supplies us with the approximate country and city of your address.
- From the transfer receipt you send us when you buy a subscription, to match the payment to your order.
Why we process data, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Delivering the service: account creation, sign-in, evaluation tools, reports and documents | Performance of the contract with you or your school |
| Security: detecting suspicious sign-ins, preventing abuse, keeping audit logs | Legitimate interest in protecting the Platform and its users, and what the regulations require |
| Subscription, payment and invoicing | Performance of the contract and statutory financial obligations |
| Operational notifications (verification codes, assignments, reminders, security alerts) | Performance of the contract; your preferences govern the non-essential channels |
| Technical support and answering your requests | Performance of the contract and legitimate interest |
| Marketing: sending the platform guide and news to those who asked for it | Your consent, which you may withdraw at any time |
| Improving the service through aggregated, anonymised statistics | Legitimate interest; nothing identifies a person or a school |
| Compliance with the regulations and responding to competent authorities | Legal obligation |
We do not make the service conditional on your consent to processing that is not directly connected with it.
Artificial intelligence
- Some plans include text generation and analysis features (drafting minutes, certificate wording, summarising evidence and observations, SWOT analysis, interview questions) that run on language models at external providers.
- When such a feature is used we send the model provider only what the feature needs: the school's name and the text being worked on (such as an evidence description or a classroom observation), which may include the names of meeting participants or certificate honourees.
- The possible providers and their locations are listed in the sub-processor table; the school administrator chooses the actual provider from those we offer, or the default provider is used.
- We do not use school data to train any model, and we work only through paid programming interfaces whose terms prohibit using inputs for training; a provider may keep a transient operational log of the request (up to 30 days) for security and abuse prevention, after which it is deleted.
- The school administrator may disable all AI features at any time, after which nothing is sent.
- Outputs assist with drafting; no decision with legal or professional effect on an individual is taken on them alone, and you may object to your school about processing concerning you through these features.
Processing outside the Kingdom
- Some processing may take place at sub-processors outside the Kingdom, in accordance with the Personal Data Protection Law and the Regulation on Personal Data Transfer outside the Kingdom, under data processing agreements that bind each processor to a level of protection no lower than the regulations require.
- A school subject to particular requirements on where its data is processed (such as government bodies) should check that this is compatible with its obligations before use, and may write to us to discuss alternatives.
- Any material change to the processing arrangements is announced in this policy and school administrators are notified.
How we protect data
We apply organisational and technical measures proportionate to the sensitivity of the data, including:
- Full encryption of the connection (TLS with HSTS), so nothing travels between your browser and the Platform unencrypted.
- Passwordless sign-in with one-time verification codes, so there are no passwords to leak, with a temporary lock after repeated failed attempts.
- Encryption of signature images and school stamps at rest with keys held separately from the database, and operational secrets kept in an encrypted store.
- Layered permissions on three levels (system role, account role in the school, and access level on each record), so a member sees only what concerns their school and role.
- Detection of sign-ins from an unfamiliar device or country with an alert to the account holder, rate limiting on sign-in and forms, and bot verification.
- An activity log for every school recording who did what and when.
- Hourly database backups with periodic restore tests, and a mandatory backup before every deployment.
- The provider's staff access production data only within the narrowest operational scope and on a documented exceptional basis.
- A responsible disclosure programme for security vulnerabilities through the official contact form, with [SECURITY] in the subject field.
No method of transmission or storage is one hundred percent secure; we therefore review and improve these measures continuously, and the data security incidents clause sets out what we do if the unwanted happens.
How long we keep data
We keep data for as long as the purpose of processing it stands, then destroy or anonymise it, as follows:
| Data | Period |
|---|---|
| School data and evaluation content | For the subscription, then 90 days after it ends to allow renewal and export, then destroyed within 30 days from the live systems and then from the backups according to their cycle; the school's identifying record (its name and its members' memberships) stays with the subscription and billing records for the period the regulations prescribe |
| Your personal account data | While your account exists; when you ask to close it, it is destroyed or anonymised within 30 days, while your name remains in your school's documents you took part in as part of its record |
| Sign-in log and security events | 12 months from when they occur |
| Expired sign-in sessions | Deleted within a day of expiring |
| Audit and school activity logs | With the school's data |
| Subscription and payment data | The period the tax and commercial regulations prescribe for keeping transaction records |
| Support requests and correspondence | 24 months from the request being closed |
| Guide-request and marketing data | Until you withdraw consent, and at most 12 months from the last contact |
| Read notifications | Archived after 90 days |
| Operational logs and backups | A short rolling cycle for security and recovery, and used for nothing else |
Notifications and marketing
- We send operational notifications the service needs (verification codes, assignments, reminders, security alerts) by email, SMS, in-Platform or browser notification, and WhatsApp for those who have explicitly enabled it.
- You control the channels, categories and timing of notifications from your account settings, and notification emails carry a one-click unsubscribe link; security messages and verification codes cannot be switched off while the account exists.
- We send marketing only to those who asked for it (such as a request for the platform guide), and you can withdraw consent at any time by writing to us, whereupon we stop and delete your marketing data.
- Schools that use messaging credits are responsible for the content they send to their staff and parents and for its recipients, under the Terms of Use.
Students' and minors' data
- No one under eighteen may create an account on the Platform. Schools may, however, collect data about students under that age through surveys and observation instruments, and school-environment observation photos may include students.
- The school is the controller of this data and must obtain a guardian's consent wherever the Personal Data Protection Law and its regulations require it, limit what it collects to what the evaluation purpose needs, and prefer anonymous responses.
- We process students' data only as a processor on the school's behalf, use it for no other purpose, and show it only to those the school has authorised.
- A guardian may exercise their child's rights through the school, or through us if that is not possible.
Your rights
Under the Personal Data Protection Law you have the right:
- To be informed: to know what we collect about you, why and how — which is what this policy sets out.
- To access and obtain a copy: to ask to see your data and receive a copy of it in a clear, readable format.
- To correction: to ask for your data to be corrected, completed or updated; you can edit your profile details directly from your account.
- To destruction: to ask for your data to be destroyed when its purpose has ended, subject to what the regulations require to be kept and what belongs to your school's record.
- To withdraw consent and object: to withdraw, at any time, consent on which processing was based, and to object to processing based on a legitimate interest.
- To complain: to lodge a complaint with the competent personal-data-protection authority in the Kingdom if you believe we have not handled your request properly.
To exercise any of these rights, send your request through the official contact form named in clause 1. We verify your identity and reply within thirty days, extendable by a further thirty days for a complex request, telling you the reason. If your data is controlled by your school, send your request to it first and we will help it carry the request out.
Data security incidents
- If an incident affects the confidentiality, integrity or availability of your data, we contain it and assess its impact immediately.
- We notify affected schools, as controllers, without undue delay and within 72 hours of confirming the incident, so they can meet their own obligations, and we notify the competent authority and data subjects as the law requires.
- The notification describes the nature of the incident, the data affected, the likely consequences, what we have done and what we recommend.
Updates to this policy
- Every version of this policy carries a version number and an effective date shown at the top of the page, with a note of what changed.
- We notify users and school administrators of material changes thirty days before they take effect, through the registered contact channel or within the Platform; clarifications and corrections take effect on publication.
- A change of sub-processors or of hosting location counts as a change that requires notification.
Contact
For any question about this policy or your data, write to us through the official contact form named in clause 1 with “Data protection” in the subject field.
What changed in version 2026.09
- The payment provider is removed from the list of sub-processors: payment is by bank transfer and no card details reach us.
- The subscription and payment data row now records the transfer reference in place of the card brand and last four digits, and the payment provider is no longer a source of data about you.