Data protection

Privacy Policy

What Elbi collects, what it does with it, and how quickly it is destroyed. Written under the Saudi Personal Data Protection Law (PDPL) and the SDAIA Implementing Regulations.

Version 1.0Controller: Elbetron Technologies, Dammam

The short version

  • Nothing is processed until you say yes. The server refuses chat, buttons and uploads without a recorded consent.
  • Every message is destroyed within 24 hours — usually as soon as the conversation ends. An hourly sweep enforces the ceiling even if anything else fails.
  • Voice audio and uploaded files are never stored at all.
  • Encrypted with authenticated encryption before it reaches the database, on a full-disk-encrypted server inside the Kingdom.
  • No external AI service ever sees your data — the model, speech and OCR all run on our own hardware.
  • You can download or delete everything yourself, from inside the widget, at any moment.
  • We never sell data and never use your conversations to train models.

1. Who is responsible for your data

Elbi is an AI assistant built and operated by Elbetron Technologies, a company established in Dammam, Kingdom of Saudi Arabia. For everything described in this policy, Elbetron is the data controller under the Saudi Personal Data Protection Law (PDPL, Royal Decree M/19 of 1443H, as amended) and its Implementing Regulations, supervised by the Saudi Data & AI Authority (SDAIA).

ControllerElbetron Technologies
AddressDammam, Kingdom of Saudi Arabia
Contact for data mattersglobal.business@elbetron.com
Phone+966 54 030 5667
Data Protection OfficerNot appointed. Assessed against Article 30 and the Implementing Regulations and found not mandatory at our current scale; the contact above handles all data requests and is monitored.

If you use Elbi as a customer's assistant embedded on their website, that customer is the controller for their own conversations and Elbetron acts as their processor under a written agreement. This policy then describes what we do on their instructions.

2. What we collect

Only what the assistant needs to answer you. We do not build profiles, we do not track you across other sites, and we do not sell anything to anyone.

DataWhere it comes fromWhy
Message content — what you type or say, and what Elbi repliesYou, during a conversationTo answer your question
Voice audioYour microphone, only if you press the micConverted to text, then discarded
Uploaded file contentOnly files you choose to attachTo answer a question about that file
A random conversation id (client_id)Generated in your browserSo a conversation holds together across messages. It is not your name and is not linked to any identity
IP address and user-agentYour connectionSecurity, abuse prevention and rate limiting
Consent recordYour acceptance of the noticeProof that you agreed, as PDPL requires us to keep
Derived, non-identifying metrics — language, sentiment band, response time, whether the question was resolvedComputed from the conversationService quality reporting

We do not ask for and do not want your national ID, bank or card numbers, passwords, health information or any other sensitive category. The assistant is instructed never to request them, and the widget warns you before you send something that looks like one. If you send such data anyway, it is redacted where we can detect it and destroyed with the rest of the conversation.

3. What we use it for, and our lawful basis

PurposeLawful basis (PDPL Art. 5–6)
Answering your questions in the assistantYour consent
Transcribing your voice so it can be answeredYour consent
Reading a file you attached, to answer a question about itYour consent
Connecting you to a human agent when you askYour consent
Keeping a record that you consentedLegal obligation — PDPL accountability
Security, abuse prevention, rate limiting, incident investigationLegitimate interest
Anonymised service-quality reportingLegitimate interest, on data that no longer identifies anyone

No automated decision is made about you. Elbi answers questions; it does not decide anything that produces a legal or similarly significant effect on you.

We do not use your conversations to train models. The language model Elbi runs is a fixed open-weights model hosted on our own hardware. It is not fine-tuned on your messages, and no message is sent to any third-party AI service.

5. How long we keep it — message content destroyed within 24 hours

This is the part most policies leave vague. Ours is a fixed number, enforced by a job that runs every hour.

WhatKept forThen
Message content (yours and Elbi's)Up to 24 hours, usually far less — normally destroyed as soon as the conversation closesIrreversibly destroyed. A backstop sweep runs hourly and deletes anything past 24 hours even if the normal path failed, so nothing can quietly survive
Voice audioNot kept at allThe temporary file is deleted the moment transcription finishes, success or failure
Uploaded filesNot kept at allProcessed in memory. The file is never written to our disks
Live-agent conversationsUp to 24 hours after the chat closesDestroyed by a separate hourly sweep
Consent recordsThe consent relationship + 24 monthsDeleted
Technical and security logsUp to 12 monthsDeleted
Anonymised metrics (no content, no identifiers)IndefinitelyKept — they cannot be traced back to you

What “destroyed” means here: the stored text is overwritten in the database, not flagged as hidden. Once it is gone we cannot recover it. Encrypted backup copies taken before that point age out on their own cycle — seven days locally and thirty days off-site — after which no copy of the message remains anywhere.

6. How it is protected

  • Encrypted at rest with authenticated encryption. Message content is encrypted before it touches the database, with a key held outside it.
  • Full-disk encryption on the server that holds the data.
  • TLS 1.2 / 1.3 for everything in transit.
  • Identifiers stripped before storage and before the model sees them. Patterns such as card numbers, national IDs, emails and phone numbers are redacted at capture.
  • Everything runs inside the Kingdom, on our own hardware. There is no OpenAI, Anthropic, Google or other external AI service in the path — the language model, speech-to-text, text-to-speech and document OCR are all self-hosted.
  • Access control on the staff dashboard: individual accounts, role-based permissions, two-factor authentication, and an audit log.
  • Encrypted nightly backups, restricted to the same environment.
  • Rate limiting, abuse blocking and malware scanning on uploads.

No system is perfect and we do not claim otherwise. We are not ISO 27001 certified — the controls are implemented, the certificate is not yet issued, and we would rather say so than imply it.

7. Who else can see it

Nobody buys it, and nobody uses it for their own purposes. The complete list of third parties involved in the service:

WhoWhat they seeWhyAgreement
Edge network providerTraffic while it is in transit to usSecure ingress and protection against attackData processing agreement on file
Transactional mail relayStaff email addresses and one-time login codes only — never conversation contentSending staff sign-in codesData processing agreement on file

Our own staff can see the analytics dashboard, which shows counts and quality scores, never message content. A live agent sees a conversation only when you ask to be connected to one, and only while it is open.

We may disclose data if a competent Saudi authority lawfully requires it. Given the 24-hour retention, in most cases there is simply nothing left to disclose.

8. Leaving the Kingdom

Your conversation content does not leave Saudi Arabia. It is processed and stored on servers in the Kingdom and destroyed there.

Two narrow exceptions, both disclosed for completeness:

  • Traffic passes through the edge network's global edge on its way to us, which can mean a routing hop outside the Kingdom while in transit. It is encrypted throughout and is not stored there.
  • Staff sign-in codes and invitations are sent through an email relay hosted outside the Kingdom. These contain a staff email address and a code — never any conversation data.

Both are covered by written data processing agreements, consistent with PDPL Articles 29 and the transfer conditions in the Implementing Regulations.

9. Your rights, and the buttons that exercise them

Under PDPL Articles 4 and 21 you have the rights below. Most policies ask you to email someone and wait. In Elbi, three of them are buttons inside the widget and take effect immediately.

RightHow to use it
Be informed — know what is collected and whyThis page, plus the notice shown before you start
Access and obtain a copy of your data⬇ Download my data in the widget's settings menu — a JSON file, produced on demand and not stored
Erasure — have your data destroyed🗑 Delete this conversation or 🗑 Delete all my data in the same menu. Immediate and irreversible
Withdraw consentThe same settings menu. Processing stops
Correction of inaccurate dataEmail us — though with a 24-hour lifetime there is rarely anything to correct
Object or restrict processingEmail us
ComplainTo us first, at the address below. You may also complain directly to SDAIA, the supervisory authority, at sdaia.gov.sa

We answer requests sent by email within 30 days, as the Regulations require, and normally much sooner. We may ask you for the conversation id shown in the widget so we can find the right data — we have no other way to identify you, by design.

10. Children

Elbi is a business assistant and is not directed at children under 18. We do not knowingly collect their data. If you believe a child has used the assistant and you would like the record removed, contact us — although in practice it will already have been destroyed within 24 hours.

11. Cookies and analytics

Two different things happen here, and they are worth separating.

  • The assistant uses your browser's local storage to hold the random conversation id and your language choice, so a page refresh does not lose your place. That is functional, not tracking, and no cookie is involved.
  • This website uses Google Analytics 4 to count visits and see which pages are read. It sets Google's _ga cookies in your browser and sends usage data — including your IP address — to Google, which processes it outside the Kingdom.
  • We run it in its most restricted configuration: advertising signals off, ad personalisation off, IP anonymisation on. We do not run Google Ads, we do not build remarketing audiences, and we do not sell or share this data.
  • No advertising cookies and no cross-site ad profiling. Analytics is the only third-party script on this site.
  • The staff dashboard uses a secure, HTTP-only session cookie for sign-in.
  • To opt out: block cookies for this site in your browser, use its Do Not Track or tracking-protection setting, or install Google's Analytics opt-out add-on. Nothing on this site stops working if you do.
  • Clearing your browser storage ends any assistant conversation and orphans anything already sent, which is then destroyed on the normal 24-hour schedule.

12. Changes to this policy

If we change how we handle data, we publish the new version here with a new version number and date, and — where the change is material — ask for consent again before continuing. The version you accepted is recorded with your consent, so it is always clear which terms applied.

13. Contact

Questions, requests or complaints about data:

Emailglobal.business@elbetron.com
Phone+966 54 030 5667
PostElbetron Technologies, Dammam, Kingdom of Saudi Arabia
Supervisory authoritySaudi Data & AI Authority (SDAIA) — sdaia.gov.sa

This policy describes the system as built and verified. It is written to be read, not to be impenetrable. It is not legal advice.