Privacy Policy
What we see, and what we keep.
Written to be read once, by whoever has to sign it off.
Last updated 13 September 20261. Who we are
Proof Manager is a product of AI Manager Company, registered in Riyadh, Saudi Arabia.
For personal data processed through the product we act as a processor on behalf of the restaurant group that operates the branch. That group is the controller: it decides which stations are recorded, who receives alerts, and how long records are kept. For our own website, sales and support records we are the controller.
2. What we process
Two separate things, kept separate:
3. What we do not do
4. Why we process it
Branch data is processed to perform our contract with the restaurant group, on that group’s instructions. Business contact data is processed on the basis of our legitimate interest in responding to you, which Article 16 of the Implementing Regulations allows where it does not affect your rights.
Where consent is the basis for any processing, it can be withdrawn at any time under Article 12. Our appointment as processor is governed by Article 17, which requires the controller to choose a processor that gives sufficient guarantees, and to set the purpose, the categories of data, the term and breach notification in writing. We collect only the minimum the purpose needs (Article 19) and disclose only the minimum necessary (Article 20).
5. How long we keep it
Retention is not fixed by us. It is agreed with each customer and set per branch in the contract, and it expires automatically at the end of that period. One group may agree thirty days; another may agree longer. Nothing is kept beyond the agreed period, and early deletion can be requested at any time.
Business contact data is kept only for as long as it is needed to answer you and to keep our commercial records, and it is deleted on request.
6. Security
We apply technical and organisational measures appropriate to the risk, as Article 23 of the Implementing Regulations requires, with access limited to named staff. The measures that apply to a particular deployment are set out in the agreement with that customer.
7. Where it is processed
Deployments differ. Some groups require every frame to stay inside the Kingdom, some run partly on equipment inside the branch, and others are entirely in the cloud. Where processing takes place is agreed with each customer and set out in the agreement. Any transfer of personal data outside the Kingdom happens only on the conditions the Personal Data Protection Law sets for transfers, and on the terms agreed with the controller. Our records of processing activities are kept as Article 33 of the Implementing Regulations requires.
Formspree, a service provider, receives website enquiries, delivers them to our inbox, and stores a copy in its submission archive. The name, company, work email, mobile and message you submit may be processed outside Saudi Arabia for that purpose. This does not include branch video or order data. To honour a deletion request, we delete the submission from Formspree, the corresponding email from hello@proofmanager.co, and any related commercial records we hold.
8. Your rights
The Implementing Regulations give a data subject the right to be informed about processing (Article 4), to access their personal data (Article 5), to obtain a copy of it (Article 6), to have it corrected (Article 7), and to have it destroyed when it is no longer needed for the purpose it was collected for (Article 8). Consent, where it applies, can be withdrawn (Article 12).
If the data sits inside a customer’s branch deployment, the request goes to that restaurant group as controller, and we support them in answering it. For anything we hold as controller, write to us directly.
9. Personal data breaches
Where a breach causes harm to personal data or to a data subject, the competent authority — the Saudi Data and Artificial Intelligence Authority — is notified within 72 hours, the deadline set by Article 24 of the Implementing Regulations, together with the affected individuals and the steps taken.
10. Changes
When this policy changes materially we will say so here and update the date at the top.
Rights requests are answered within 30 days, the maximum set by Article 3 of the Implementing Regulations. Send them to hello@proofmanager.co.
Privacy Policy
What we see, and what we keep.
Written to be read once, by whoever has to sign it off.
Last updated 13 September 20261. Who we are
Proof Manager is a product of AI Manager Company, registered in Riyadh, Saudi Arabia.
For personal data processed through the product we act as a processor on behalf of the restaurant group that operates the branch. That group is the controller: it decides which stations are recorded, who receives alerts, and how long records are kept. For our own website, sales and support records we are the controller.
2. What we process
Two separate things, kept separate:
3. What we do not do
4. Why we process it
Branch data is processed to perform our contract with the restaurant group, on that group’s instructions. Business contact data is processed on the basis of our legitimate interest in responding to you, which Article 16 of the Implementing Regulations allows where it does not affect your rights.
Where consent is the basis for any processing, it can be withdrawn at any time under Article 12. Our appointment as processor is governed by Article 17, which requires the controller to choose a processor that gives sufficient guarantees, and to set the purpose, the categories of data, the term and breach notification in writing. We collect only the minimum the purpose needs (Article 19) and disclose only the minimum necessary (Article 20).
5. How long we keep it
Retention is not fixed by us. It is agreed with each customer and set per branch in the contract, and it expires automatically at the end of that period. One group may agree thirty days; another may agree longer. Nothing is kept beyond the agreed period, and early deletion can be requested at any time.
Business contact data is kept only for as long as it is needed to answer you and to keep our commercial records, and it is deleted on request.
6. Security
We apply technical and organisational measures appropriate to the risk, as Article 23 of the Implementing Regulations requires, with access limited to named staff. The measures that apply to a particular deployment are set out in the agreement with that customer.
7. Where it is processed
Deployments differ. Some groups require every frame to stay inside the Kingdom, some run partly on equipment inside the branch, and others are entirely in the cloud. Where processing takes place is agreed with each customer and set out in the agreement. Any transfer of personal data outside the Kingdom happens only on the conditions the Personal Data Protection Law sets for transfers, and on the terms agreed with the controller. Our records of processing activities are kept as Article 33 of the Implementing Regulations requires.
Formspree, a service provider, receives website enquiries, delivers them to our inbox, and stores a copy in its submission archive. The name, company, work email, mobile and message you submit may be processed outside Saudi Arabia for that purpose. This does not include branch video or order data. To honour a deletion request, we delete the submission from Formspree, the corresponding email from hello@proofmanager.co, and any related commercial records we hold.
8. Your rights
The Implementing Regulations give a data subject the right to be informed about processing (Article 4), to access their personal data (Article 5), to obtain a copy of it (Article 6), to have it corrected (Article 7), and to have it destroyed when it is no longer needed for the purpose it was collected for (Article 8). Consent, where it applies, can be withdrawn (Article 12).
If the data sits inside a customer’s branch deployment, the request goes to that restaurant group as controller, and we support them in answering it. For anything we hold as controller, write to us directly.
9. Personal data breaches
Where a breach causes harm to personal data or to a data subject, the competent authority — the Saudi Data and Artificial Intelligence Authority — is notified within 72 hours, the deadline set by Article 24 of the Implementing Regulations, together with the affected individuals and the steps taken.
10. Changes
When this policy changes materially we will say so here and update the date at the top.
Rights requests are answered within 30 days, the maximum set by Article 3 of the Implementing Regulations. Send them to hello@proofmanager.co.