Privacy Policy

What we see, and what we keep.

Written to be read once, by whoever has to sign it off.

Last updated 13 September 2026

1. Who we are

Proof Manager is a product of AI Manager Company, registered in Riyadh, Saudi Arabia.

For personal data processed through the product we act as a processor on behalf of the restaurant group that operates the branch. That group is the controller: it decides which stations are recorded, who receives alerts, and how long records are kept. For our own website, sales and support records we are the controller.

2. What we process

Two separate things, kept separate:

Branch video and order data. Frames from cameras the customer already owns, plus the order record from the POS or the aggregator. Cameras are framed on process — the packing station, the shelf, the drawer, the lane.
Business contact data. Name, company, work email, mobile, and the branch you asked about, when you contact us or ask for a demo.

3. What we do not do

No face recognition, and no biometric identification.
No identity matching between an exception and a named employee. Who was on shift is the customer’s record, not ours.
No sale of personal data, and no sharing with advertisers.
Branch footage is processed only on the controller’s instructions, and for no purpose of our own.

4. Why we process it

Branch data is processed to perform our contract with the restaurant group, on that group’s instructions. Business contact data is processed on the basis of our legitimate interest in responding to you, which Article 16 of the Implementing Regulations allows where it does not affect your rights.

Where consent is the basis for any processing, it can be withdrawn at any time under Article 12. Our appointment as processor is governed by Article 17, which requires the controller to choose a processor that gives sufficient guarantees, and to set the purpose, the categories of data, the term and breach notification in writing. We collect only the minimum the purpose needs (Article 19) and disclose only the minimum necessary (Article 20).

5. How long we keep it

Retention is not fixed by us. It is agreed with each customer and set per branch in the contract, and it expires automatically at the end of that period. One group may agree thirty days; another may agree longer. Nothing is kept beyond the agreed period, and early deletion can be requested at any time.

Business contact data is kept only for as long as it is needed to answer you and to keep our commercial records, and it is deleted on request.

6. Security

We apply technical and organisational measures appropriate to the risk, as Article 23 of the Implementing Regulations requires, with access limited to named staff. The measures that apply to a particular deployment are set out in the agreement with that customer.

7. Where it is processed

Deployments differ. Some groups require every frame to stay inside the Kingdom, some run partly on equipment inside the branch, and others are entirely in the cloud. Where processing takes place is agreed with each customer and set out in the agreement. Any transfer of personal data outside the Kingdom happens only on the conditions the Personal Data Protection Law sets for transfers, and on the terms agreed with the controller. Our records of processing activities are kept as Article 33 of the Implementing Regulations requires.

Formspree, a service provider, receives website enquiries, delivers them to our inbox, and stores a copy in its submission archive. The name, company, work email, mobile and message you submit may be processed outside Saudi Arabia for that purpose. This does not include branch video or order data. To honour a deletion request, we delete the submission from Formspree, the corresponding email from hello@proofmanager.co, and any related commercial records we hold.

8. Your rights

The Implementing Regulations give a data subject the right to be informed about processing (Article 4), to access their personal data (Article 5), to obtain a copy of it (Article 6), to have it corrected (Article 7), and to have it destroyed when it is no longer needed for the purpose it was collected for (Article 8). Consent, where it applies, can be withdrawn (Article 12).

If the data sits inside a customer’s branch deployment, the request goes to that restaurant group as controller, and we support them in answering it. For anything we hold as controller, write to us directly.

9. Personal data breaches

Where a breach causes harm to personal data or to a data subject, the competent authority — the Saudi Data and Artificial Intelligence Authority — is notified within 72 hours, the deadline set by Article 24 of the Implementing Regulations, together with the affected individuals and the steps taken.

10. Changes

When this policy changes materially we will say so here and update the date at the top.

QUESTIONS

Rights requests are answered within 30 days, the maximum set by Article 3 of the Implementing Regulations. Send them to hello@proofmanager.co.

Privacy Policy

What we see, and what we keep.

Written to be read once, by whoever has to sign it off.

Last updated 13 September 2026

1. Who we are

Proof Manager is a product of AI Manager Company, registered in Riyadh, Saudi Arabia.

For personal data processed through the product we act as a processor on behalf of the restaurant group that operates the branch. That group is the controller: it decides which stations are recorded, who receives alerts, and how long records are kept. For our own website, sales and support records we are the controller.

2. What we process

Two separate things, kept separate:

Branch video and order data. Frames from cameras the customer already owns, plus the order record from the POS or the aggregator. Cameras are framed on process — the packing station, the shelf, the drawer, the lane.
Business contact data. Name, company, work email, mobile, and the branch you asked about, when you contact us or ask for a demo.

3. What we do not do

No face recognition, and no biometric identification.
No identity matching between an exception and a named employee. Who was on shift is the customer’s record, not ours.
No sale of personal data, and no sharing with advertisers.
Branch footage is processed only on the controller’s instructions, and for no purpose of our own.

4. Why we process it

Branch data is processed to perform our contract with the restaurant group, on that group’s instructions. Business contact data is processed on the basis of our legitimate interest in responding to you, which Article 16 of the Implementing Regulations allows where it does not affect your rights.

Where consent is the basis for any processing, it can be withdrawn at any time under Article 12. Our appointment as processor is governed by Article 17, which requires the controller to choose a processor that gives sufficient guarantees, and to set the purpose, the categories of data, the term and breach notification in writing. We collect only the minimum the purpose needs (Article 19) and disclose only the minimum necessary (Article 20).

5. How long we keep it

Retention is not fixed by us. It is agreed with each customer and set per branch in the contract, and it expires automatically at the end of that period. One group may agree thirty days; another may agree longer. Nothing is kept beyond the agreed period, and early deletion can be requested at any time.

Business contact data is kept only for as long as it is needed to answer you and to keep our commercial records, and it is deleted on request.

6. Security

We apply technical and organisational measures appropriate to the risk, as Article 23 of the Implementing Regulations requires, with access limited to named staff. The measures that apply to a particular deployment are set out in the agreement with that customer.

7. Where it is processed

Deployments differ. Some groups require every frame to stay inside the Kingdom, some run partly on equipment inside the branch, and others are entirely in the cloud. Where processing takes place is agreed with each customer and set out in the agreement. Any transfer of personal data outside the Kingdom happens only on the conditions the Personal Data Protection Law sets for transfers, and on the terms agreed with the controller. Our records of processing activities are kept as Article 33 of the Implementing Regulations requires.

Formspree, a service provider, receives website enquiries, delivers them to our inbox, and stores a copy in its submission archive. The name, company, work email, mobile and message you submit may be processed outside Saudi Arabia for that purpose. This does not include branch video or order data. To honour a deletion request, we delete the submission from Formspree, the corresponding email from hello@proofmanager.co, and any related commercial records we hold.

8. Your rights

The Implementing Regulations give a data subject the right to be informed about processing (Article 4), to access their personal data (Article 5), to obtain a copy of it (Article 6), to have it corrected (Article 7), and to have it destroyed when it is no longer needed for the purpose it was collected for (Article 8). Consent, where it applies, can be withdrawn (Article 12).

If the data sits inside a customer’s branch deployment, the request goes to that restaurant group as controller, and we support them in answering it. For anything we hold as controller, write to us directly.

9. Personal data breaches

Where a breach causes harm to personal data or to a data subject, the competent authority — the Saudi Data and Artificial Intelligence Authority — is notified within 72 hours, the deadline set by Article 24 of the Implementing Regulations, together with the affected individuals and the steps taken.

10. Changes

When this policy changes materially we will say so here and update the date at the top.

QUESTIONS

Rights requests are answered within 30 days, the maximum set by Article 3 of the Implementing Regulations. Send them to hello@proofmanager.co.