العربية

Privacy

How Anseraf handles personal data across its three products, and who is responsible for what.

Last updated

Who we are

This site and the products described on it are operated by شركة انصراف سريع, a Saudi limited liability company registered under commercial registration number 4650267933, with its registered address in Madinah, Kingdom of Saudi Arabia.

You can reach us about anything in this document at [email protected].

Who is responsible for school data

Almost all of the personal data our products touch belongs to a school: its students, their guardians, and its staff. In that relationship the school is the data controller — it decides what is collected and why — and we act as a processor, handling that data only on the school's documented instructions and only to provide the service it subscribed to.

This matters in practice. We do not decide which students are enrolled, who may collect a child, or what a school records about its staff. If you are a parent or an employee and you want something changed or removed, the school is the right place to ask, and we will help the school act on it.

A small amount of data is ours as controller: the contact details of the people who administer a subscription, billing records, support correspondence, and the security logs we keep to run the service safely.

What each product handles

The three products are sold separately and hold different data. Each has its own page with the detail:

  • Anseraf — parent and staff engagement: guardian identities, student–guardian relationships, dismissal and attendance events, notifications.
  • Sijillak — the school system of record: students, staff, classes, and school documents. No guardian accounts exist in it at all.
  • Sadaak — paging and bells: audio zones, devices, bell timetables, announcements. Very little personal data, and no student records.

What we never do

  • We do not sell personal data, and we never have.
  • We do not use student, guardian or staff data to target advertising, and the products carry no advertising.
  • We do not use school data to train machine-learning models.
  • We do not share school data with another school, or with any third party, except the infrastructure providers needed to run the service and where the law requires it.

Where data is held

Our production servers are currently located in Germany, operated on infrastructure we manage ourselves rather than on a third-party school-software platform. Some supporting services — email delivery, DNS and content delivery — may process data in other countries.

Because this places personal data outside the Kingdom, it is a cross-border transfer under the Personal Data Protection Law. We rely on the transfer being necessary to perform the agreement with the school, and we apply contractual and technical safeguards to it. If you require data residency inside the Kingdom, tell us before you subscribe: it is a deployment question, not a policy one.

Your rights

Under the Personal Data Protection Law you may ask to be told what personal data is held about you, to obtain a copy of it, to have it corrected, and in defined circumstances to have it destroyed. You may also withdraw a consent you previously gave.

For anything held on behalf of a school — a student record, an attendance or dismissal event, a guardian relationship — the school is the controller and decides. Send those requests to the school; we will support the school in answering them. For data we hold in our own right, such as an enquiry you emailed us, write to us directly and we will respond.

Children

Our products are used in schools, so much of the data concerns children. Children do not hold accounts in any of the three products. A student never signs in; the people who sign in are guardians and school staff. Data about a child is entered and controlled by the school under its own lawful basis and its arrangements with the family.

How long data is kept

While a school's subscription is active, its data is retained so the service can function. When a subscription ends, the school may request an export, and we delete or irreversibly anonymise the data after an agreed wind-down period unless a longer period is required by law. Backups age out on their own schedule and are deleted with the media they sit on.

Security

  • Sign-in uses a one-time code sent to a phone number. There are no passwords to be reused or leaked.
  • Every request is authorised against the specific school it concerns, so one school cannot reach another's records.
  • Traffic is encrypted in transit.
  • Access to production systems is limited to the people who operate them, and administrative actions are logged.

Changes to this document

When this document changes materially we will update the date at the top and, where the change affects schools, tell subscribing schools directly.

Back to home