1. Introduction and scope
This privacy policy explains how Qaymeni handles personal and operational data entered, created or processed within its cloud system. Qaymeni provides technology for collecting customer feedback, following complaints, analyzing satisfaction and managing digital reputation through a cloud dashboard and periodic reports. Because the service relies on data businesses provide about their end customers, this policy distinguishes Qaymeni’s responsibilities as a cloud service provider from those of the business customer that decides to collect and use data. The policy applies to business account owners, authorized staff and end users who receive review links, messages or complaint forms. It covers data collected through the dashboard, review links, WhatsApp, email, QR codes and other technical channels connected in the future. It explains the data collected, its purposes and processing, responsibility for legally required consent, and the limits of Qaymeni’s responsibility for improper or unauthorized use by a business customer, its staff or third parties.
2. Parties and roles
“Platform” or “Qaymeni” means the cloud system owned or operated by Qaymeni’s owning entity that provides feedback, complaint, reporting and analytics services. “Customer” or “business customer” means a business, company, establishment or individual subscribing to the service to request reviews, manage complaints or analyze satisfaction. An “end user” is a natural person who deals with that business and receives a review request or submits a rating, complaint or comment through connected channels. The business customer generally acts as the data controller: it decides which end-user data to enter, the reason and channel for contact, and whether to send a review link, WhatsApp message or email. Qaymeni generally acts as a data processor, providing technical processing according to the business customer’s instructions rather than independently deciding to collect data or send messages. The business customer is primarily responsible for lawful collection, consent and compliance with data protection, communications and anti-spam requirements. Qaymeni undertakes to provide an appropriate technical environment, take reasonable security measures and process data for the agreed purpose, without assuming responsibility for unlawfully entered data or contact made without the data subject’s consent.
3. Data that may be processed
Data may include names, mobile numbers, email addresses, branch and business names, order or invoice numbers and business account user information. Feedback data may include star ratings, submission time, rating type, comments, issue categories, complaint text and status, and actions taken. Operational and analytical data may include review volumes, average satisfaction, branch performance, recurring issues, links sent, clicks on external links, dashboard usage and account activity. Technical data may include IP addresses, device and browser type, access times, security logs and error data used to operate, protect and improve the service. Qaymeni does not seek sensitive data, but a business may enter it in comments, complaints or text fields. Businesses must not enter sensitive or unnecessary information, including detailed health information, financial data or identity numbers, without a clear legal basis and the data subject’s explicit consent, and unless necessary and proportionate to the processing purpose.
4. Data sources and consent
Data mainly comes from the business customer or the end user interacting with a review link or message. When staff enter a mobile number, upload a customer list or send a review link through WhatsApp or email, the business represents that it has the legal right and necessary consent to use that data. The business is fully responsible for ensuring lawful collection, informing people of the purpose and ensuring that contact for feedback, service improvement or complaints does not breach applicable requirements, policies or prior commitments. Qaymeni is not responsible for messages to unauthorized numbers, lists obtained without consent, or messages considered unwanted, spam or unlawful. The business is solely responsible for related disputes, claims or penalties and must indemnify Qaymeni for resulting harm, claims or costs.
5. Purposes of processing
Qaymeni uses data to operate the service and enable feedback collection and analysis, complaint management and experience improvement. This includes creating review requests, sending links at the business’s request, recording ratings, classifying complaints, presenting performance indicators, generating daily, weekly or monthly reports and identifying branches, services or products needing improvement. Data may also support customer assistance, troubleshooting, service quality, security, feature development, abuse prevention and compliance with the terms. Qaymeni does not use end-user data for its own independent marketing without separate, clear and legally valid consent. Aggregated or anonymized data that cannot identify individuals may be used for general analysis, product development and usage research; it is not linked to a particular end user or used to make an individual decision about them.
6. Third-party sharing
The service may rely on cloud hosting, messaging, email, WhatsApp APIs, technical analytics and external review providers such as Google Reviews or Google Maps. Data is shared only as needed to operate the service or carry out the business customer’s request. Qaymeni does not sell, rent or trade customer or end-user data. External channels are subject to their own terms and policies; Qaymeni does not control their decisions, systems, outages, changes, restrictions, blocking or message and review policies. If a business directs an end user to an external platform, information entered after leaving Qaymeni is governed by that provider’s privacy policy and terms. Qaymeni is not responsible for that provider’s processing, deletion, retention or use of data.
7. Storage, processing locations and international transfers
As a cloud service, Qaymeni may process or store data on servers inside or outside Saudi Arabia, depending on the infrastructure and provider used. Processing or transfers outside Saudi Arabia must meet applicable requirements in light of the service, purpose and available safeguards. Businesses must not use the platform in breach of transfer rules or sector-specific restrictions. Businesses in regulated sectors, including health, finance or government, must disclose special data-location or storage requirements to Qaymeni in writing before subscribing or entering data and confirm that the selected plan, settings and infrastructure meet their obligations. Qaymeni is not responsible for undisclosed or unagreed sector requirements. Local hosting, data segregation, customized encryption, special audit logs or additional compliance commitments require written agreement under an Enterprise arrangement or a separate contract.
8. Security measures
Qaymeni takes reasonable security measures appropriate to a cloud system. These may include encryption in transit, access management, secure login, activity logs, backups, error monitoring and limiting access to people or systems that need data to operate the service. The measures aim to reduce unauthorized access, loss, alteration or disclosure. No internet-connected system can be guaranteed absolutely secure. Qaymeni does not guarantee immunity from all attacks, breaches, outages, user mistakes or provider issues. Its responsibility is limited to reasonable professional measures within the service and subscription and does not extend to the consequences of customer, employee or third-party errors. Businesses must protect accounts, use trusted staff, avoid sharing credentials, review permissions, disable departed employees’ accounts and monitor unusual use. Actions through a business account or its users are attributed to that business unless a direct Qaymeni technical defect is established.
9. Retention and deletion
Data is retained during an active subscription or as long as needed to provide the service, unless the business requests deletion or a different period is agreed. After expiry or cancellation, access may be disabled and data may be deleted, archived or retained in temporary backups for a limited period for security, accounting or legal purposes. Deletion requests are handled within a reasonable period according to available technical capabilities. Some backups and technical logs may remain temporarily until backup rotation or the end of a legal need. End users seeking correction or deletion should contact the business that requested their feedback, as it has the direct relationship and acts as controller. Qaymeni may assist the business where feasible and included in the service.
10. Data subject rights
Depending on applicable law, individuals may have rights to access, correct or delete data, object to certain processing or request restrictions. Because Qaymeni generally acts as processor, rights are ordinarily exercised through the business customer as controller. The business must provide an appropriate channel for requests and respond within legally required periods. If Qaymeni receives a direct request concerning a business’s data, it may refer the person to that business or notify it, without taking responsibility for deciding the request’s validity, acceptance or rejection. Qaymeni is not obliged to perform deletion or modification that could affect the business’s rights or legal obligations except on the business’s instructions, a legal ruling or an official request from a competent authority.
11. Security incident notifications
If Qaymeni becomes aware of a confirmed security incident materially affecting the confidentiality, integrity or availability of customer data in the platform, it will take reasonable steps to investigate, contain and mitigate the incident and notify the business where required or appropriate to the incident and affected data. Qaymeni is not responsible for incidents caused by weak passwords, shared credentials, compromised customer devices, staff errors, external integrations or unapproved tools. In such cases the business remains responsible for legally required notifications to individuals or authorities. Additional support for investigations, incident reports or compliance may require fees or a separate agreement, especially for extensive technical work outside the basic subscription.