Nasih AI - Privacy Notice
Privacy information for Nasih AI users and data handling practices.
Nasih AI Chatbot - Privacy Notice
*This Privacy Notice supplements the IMPACTIVE Consulting Privacy Policy
and provides specific information about how we collect, process, and
protect your personal data when you use Nasih, our AI-powered
educational chatbot. Please read this notice together with our main
Privacy Policy.*
1. Data Controller
Entity: IMPACTIVE Consulting
Privacy Contact: privacy\@impactiveconsulting.com.sa
2. Data We Collect Through Nasih
2.1 Data You Provide
- Text queries and prompts you submit to Nasih
- Any personal data you voluntarily include in your queries (you are
advised not to share sensitive data)
- Feedback or ratings you provide on Nasih\'s responses (if available)
2.2 Data Collected Automatically
- Session identifiers (randomly generated, not personally identifying)
- Timestamps of interactions
- Conversation history within and across sessions (if persistent
memory is enabled)
- Device and browser information associated with the session
- IP address (anonymized where feasible)
2.3 Data We Do NOT Collect
Nasih is not designed to collect and you should not submit:
- National identification numbers (National ID, Iqama)
- Financial account numbers, credit card details, or banking
credentials
- Passwords or authentication credentials
- Health or medical information
- Biometric data
If you inadvertently submit such data, it will be processed as part of
the conversation but we will take reasonable steps to delete it upon
identification or request.
3. How We Use Your Data
Data collected through Nasih is processed for the following purposes:
- To process your queries and generate educational responses
- To maintain conversation context within a session for coherent
interaction
- To maintain persistent memory across sessions for personalized
experience (if enabled)
- To improve Nasih\'s quality, accuracy, and relevance (using
aggregated, anonymized data)
- To detect and prevent misuse, abuse, or security threats
- To comply with applicable laws and regulations
4. Lawful Basis for Processing
- Consent (PDPL Art. 6): When you voluntarily submit queries to Nasih,
you consent to the processing of data contained in those queries.
- Legitimate Interest: For security monitoring, fraud prevention, and
service improvement (where not overridden by your rights).
- Legal Obligation: Where we are required to retain or disclose data
under Saudi law.
5. Automated Processing and AI Disclosure
In accordance with PDPL Article 29, we provide the following disclosures
about Nasih\'s automated processing:
5.1 Nature of Automated Processing
Nasih uses artificial intelligence (large language models) to
automatically generate responses to your queries. No human reviews or
intervenes in individual conversations in real-time. Nasih\'s responses
are generated algorithmically.
5.2 Agentic Capabilities
Nasih may engage in agentic AI processing, including:
- Tool Access: Nasih may use reference tools, calculators, or data
lookups to enhance responses.
- Persistent Memory: Nasih may retain and recall context from previous
sessions (maximum 90 days).
- Multi-Step Reasoning: Nasih may chain multiple analytical steps to
respond to complex queries.
- Autonomous Reasoning: Nasih independently determines how to approach
and respond to queries within its defined parameters.
5.3 Third-Party AI Processor
Nasih\'s AI capabilities are powered by Anthropic (developer of the
Claude AI model). Your queries are transmitted to Anthropic\'s
infrastructure for processing under a Data Processing Agreement that
ensures:
- Processing is strictly limited to generating responses to your
queries
- Your data is not used for AI model training without separate consent
- Appropriate technical and organizational security measures are
maintained
- Data is processed in compliance with applicable data protection
requirements
5.4 No Significant Automated Decisions
Nasih does not make decisions that produce legal effects or similarly
significantly affect you. Nasih provides educational guidance only. Any
decisions you make based on Nasih\'s outputs are yours alone.
6. Data Retention
Data retention periods for Nasih are as follows:
- Session conversation data: 90 days from the date of interaction
- Persistent memory (if enabled): 90 days from last interaction;
auto-deleted after 90 days of inactivity
- Session technical metadata: 12 months from collection
- Aggregated analytics (anonymized): Retained indefinitely
(non-personal)
You may request deletion of your Nasih data at any time by emailing
privacy\@impactiveconsulting.com.sa. Deletion requests are processed
within thirty (30) days.
7. Data Security
Data processed through Nasih is protected by:
- End-to-end encryption of data in transit (TLS/SSL)
- Encryption of stored conversation data at rest
- Access controls limiting data access to authorized personnel and
systems
- Regular security assessments of Nasih\'s infrastructure
- Contractual security obligations on third-party AI processors
8. Your Rights
Under the PDPL, you have the right to:
- Access your Nasih conversation data
- Request correction of inaccurate data
- Request deletion of your data (including persistent memory)
- Opt out of persistent memory by contacting us
- Request human review of any concern about automated processing
- Withdraw consent at any time (by ceasing use or contacting us)
- Lodge a complaint with the Saudi Data and Artificial Intelligence
Authority (SDAIA)
To exercise your rights, email privacy\@impactiveconsulting.com.sa with
the subject line \"Nasih Data Request - \[Your Request Type\]\".
9. Children\'s Privacy
Nasih is not intended for use by individuals under eighteen (18) years
of age. We do not knowingly process personal data of children through
Nasih.
10. Changes to This Notice
We may update this notice from time to time. Material changes will be
indicated by an updated effective date. Please review this notice
periodically.
11. Contact
IMPACTIVE Consulting - Privacy Team
Email: privacy\@impactiveconsulting.com.sa
Website: impactiveconsulting.com.sa