RASEELX / PRIVACY
This notice explains how the website's actual services process personal data.
Effective 30 August 2026
RaseelX empowering intelligent solutions, Commercial Registration 7051821127, is the controller where it determines why and how this website processes personal data. Privacy, consent-withdrawal and data-rights requests may be sent to info@raseelx.com.
Depending on the route you choose, we collect the fields marked as required and any optional details you provide: name, organisation, email, phone, location, preferred contact route, enquiry or consultation content, RFP/project information, supplier details, career information, CVs and supporting documents. We also keep the reference, consent, workflow, delivery, security and audit evidence needed to operate and protect the service.
We process user-submitted General Enquiries, Intelligent Enquiries, consultation requests, RFP/project submissions, supplier registrations and career applications on documented consent so that we can receive, assess and respond to the selected request. Consent is recorded with its purpose, timestamp, language and notice version, and may be withdrawn for future processing. Marketing is not bundled with these purposes and remains disabled unless separately offered and accepted. Security, fraud prevention, rate limiting, audit logging and network or information protection may rely on a documented legitimate interest where applicable; this basis is not used for Sensitive Data.
Intelligent Enquiry is optional and presents a specific consent before use. The server sends only the content needed to analyse and structure the request to the dedicated OpenAI API project with store=false. OpenAI does not make binding engineering, commercial, recruitment or supplier decisions. Do not submit national ID or passport data, banking or credit information, health information, biometric information or other unnecessary Sensitive Data. Career CVs and supplier documents are not sent to OpenAI by default. A non-AI Contact or Consultation route remains available.
Uploaded files are privately stored in Microsoft Azure under generated names and remain quarantined until security scanning returns an acceptable verdict. A supplier registration creates a review record and is not supplier approval. A job or career application creates no employment entitlement. A general career introduction enters a 12-month talent pool only when the applicant separately opts in. National ID is not requested in the normal career process.
The current website does not intentionally use advertising or behavioural tracking. Essential browser storage may preserve a consultation the user chooses to resume and essential preferences. Azure hosting, authentication and security systems process limited request, device, browser, network, availability and diagnostic data for security, reliability and troubleshooting. Application Insights operational telemetry is configured for 30 days.
Actual production services include Microsoft Azure for the website, API, PostgreSQL, private Blob Storage, Key Vault, Defender and monitoring; Microsoft Entra ID for administrator authentication; Microsoft Graph and Exchange Online for service email; and OpenAI for consented Intelligent Enquiry processing. Access is restricted by role, managed identity and mailbox scope. We do not sell personal data. Service providers receive only the data needed for their approved purpose and are governed by applicable contractual and data-protection terms.
The production website, API, database and private document storage are deployed in Microsoft Azure UAE North. Microsoft 365/Graph processing geography is not asserted where it has not been technically verified. The OpenAI production project uses a global API endpoint; RaseelX does not claim Saudi-only or UAE-only OpenAI processing. RaseelX maintains a transfer register and risk assessment and applies data minimisation, encryption, access controls, private storage, managed identities, security scanning and applicable contractual safeguards. No destination is described as formally adequate unless an applicable SDAIA decision is positively verified.
General Enquiries and consultation requests are retained for 12 months after closure. Unconverted Intelligent Enquiries are retained for 90 days after last activity; converted enquiries follow the relevant enquiry or RFP lifecycle. RFP/project requests are retained for 24 months after closure or final decision. Unsuccessful or inactive supplier registrations are retained for 12 months after final decision; approved supplier onboarding/contact records remain for the active relationship plus 24 months. Unsuccessful career applications remain for 6 months after final decision; separately consented talent-pool records remain for 12 months; a hired-candidate website copy is deleted within 90 days after confirmed transfer to the appropriate HR record.
Detailed security and administrator audit records are retained for 12 months. A malicious quarantine payload is removed within 24 hours after final verdict and evidence capture where operationally possible; Blob soft-delete remains for 30 days, and minimal malware verdict evidence remains for 12 months. Minimal consent and rights-request evidence follows a 24-month operational period after closure unless another lawful requirement applies. Records of Processing Activities are maintained throughout processing and for five years after the relevant processing activity ends. Contract, accounting and tax records follow their separate applicable statutory requirements.
At expiry, and where no legal hold or statutory requirement applies, RaseelX securely deletes or anonymises the record, removes active copies and associated files as configured, applies backup and soft-delete lifecycles, notifies processors or recipients where required, and keeps only non-identifying or minimum lawful evidence. Destruction requests are assessed under Article 18 of the Saudi Personal Data Protection Law and its Implementing Regulations; no simple interface action can bypass a hold or mandatory retention check.
Subject to applicable law, you may request information about processing, access to your personal data, a readable copy, correction, completion or update, destruction where applicable, or withdrawal of consent. Send the request to info@raseelx.com. We verify identity proportionately and do not routinely request copies of government identity documents. We target a response within 30 days; where a permitted extension is necessary, it may be extended by up to 30 additional days and we will explain the reason before the first period ends.
Controls include HTTPS, security headers, explicit origin and host allowlists, rate limits, server-side validation, private storage, malware scanning, managed identities, Key Vault, Entra MFA and RBAC, mailbox-scoped email authorization, monitoring, backups and audit evidence. If a Personal Data Breach may cause harm or conflict with a Data Subject's rights or interests, RaseelX prepares notification to the competent authority within 72 hours of awareness and notifies affected Data Subjects without undue delay where the applicable harm threshold is met.
Questions, privacy complaints and requests may be sent to info@raseelx.com. Include enough information for us to identify the relevant workflow and request, but do not email unnecessary Sensitive Data or identity-document copies.