Skip to content

Privacy policy

This policy explains in plain language what data we collect from you, why we collect it, which of our providers sees it and where it is stored, how long we keep it, and the rights you hold over it and how to exercise them.

Last updated12 September 2026

1.Who is responsible for your data

The controller of your personal data on the عطاء platform at ataa.ai is شركة فكرة بلس للبحث والتطوير في مجال تقنيات التعليم ذ.م.م ش.ش.و — a company registered in Dubai, United Arab Emirates. That company owns and operates the platform and is your counterparty under the terms and conditions. The name above is its registered legal name as written on its UAE trade licence, set here in Arabic because the licence carries no English rendering; “عطاء” and ataa.ai are trade names it operates under and do not denote a separate entity.

For any privacy question, or to exercise any of your rights, write to support@ataa.ai, use the contact page under the privacy topic, or reach legal@ataa.ai for formal matters. Data requests are handled within thirty days at the outside.

Two of these rights you exercise yourself from account settings, with no human decision in the way: downloading your data as a single file, and — if you are a learner — deleting your account. Everything else you ask support for, and all of them are described under “Your rights”.

2.Scope and the regimes behind it

This policy covers everything you do on the ataa.ai website, its apps, its email and its streaming, and applies equally to learners, teachers and visitors who never sign up. It is drafted to the shape of the GCC personal-data regimes — the Saudi Personal Data Protection Law and its regulations, and the UAE personal-data-protection law — and to the GDPR for visitors reaching us from inside the European Union.

It does not cover other websites you reach from a link inside a course, third-party tools a teacher uses in their teaching, or the meeting platforms live sessions are held on — each of those has its own policy.

3.What we collect

CategoryExamplesSource
Account dataName, email address and whether it is verified, password stored hashed and unreadable, preferred language and currency, profile picture if you upload oneYou enter it
Sign-in and security dataActive sessions and their devices, your Google account identifier if you sign in that way, sign-in attempt times with the network address and its country, security events such as a password change or two-factor setupCaptured on sign-in
Order and payment dataCourses bought, amount, currency, country of purchase, invoice number, the payment provider’s reference, card brand and last four digits, the terms version and your marketing-consent state at the moment of purchaseCreated by the purchase
Learning dataEnrolments, your progress per lesson, counted watch minutes and last position, quiz results, certificates issued and their verification serialYour use of the player
What you postReviews, questions and answers, direct messages with a teacher, support tickets, reports you fileYou post it
Teacher dataPublic profile details, identity-verification documents, IBAN and beneficiary name both encrypted, payout and balance historyThe teacher provides it
Technical dataBrowser and operating system, connection country, request identifier, error traces and response timesCaptured on each visit
Measurement and advertising dataVisit and campaign identifiers for the ad that brought you — none of which is written, and no pixel loaded, before you consentOnly after your consent
  • We never receive or store your full card number or security code. Your card is entered in the payment provider’s own fields, and what returns to us is an encrypted token and a short description of the card, useless outside their system.
  • We never ask for a postal or billing address at any stage — the product is digital, nothing ships, and our schema has no address table at all.
  • We do not collect your phone number to sign you in: there are no phone codes on this platform. The one case where your name and number are requested is choosing to pay in instalments, where available, because the instalment provider needs them to assess the order.
  • We do not ask for special-category data — health, religion, ethnicity — do not infer it, and have nowhere to put it.

4.Why we process it, and on what lawful basis

PurposeLawful basis
Creating your account, securing sign-in, keeping your sessionsPerformance of our contract
Completing a purchase, issuing the invoice, handling refundsContract and legal obligation
Saving your course progress and issuing and verifying your certificatePerformance of our contract
Sending transactional mail: receipt, payout decision, session reminderPerformance of our contract
Counting watch minutes to distribute the teachers’ share of subscription revenueOur contract with the teacher
Detecting fraud, preventing account sharing, protecting content from copyingLegitimate interest
Monitoring faults, measuring performance, improving the product in aggregateLegitimate interest
Measuring campaign performance and site trafficYour consent, withdrawable at any time
Marketing email, offers and periodic digestsYour consent, explicitly given and never pre-ticked
Keeping accounting, tax and audit recordsLegal obligation

We make no solely automated decisions with legal effect on you. Fraud detection and account-sharing signals raise a case to a member of staff; refund decisions, account suspensions and payout approvals are made by a person and recorded. You may ask for any such decision to be reviewed and explained to you.

5.Who we share it with

We do not sell or rent your data to anyone, and we do not use it to train anyone else’s AI systems. We share it only with providers acting on our instructions under data-processing agreements, and this is the list as it stands today:

ProviderPurposeWhat it seesStatus
VercelHosting the platform and its delivery network, and measuring page performanceSite requests, the address of the page requested, network address and its country, load timingsLive
Vercel — visitor analyticsCounting visits, pages and the referring siteThe page you open, the site that referred you, and the visit counted — only after you allow the “Analytics” categoryConsent only
CloudflareDomain management, storage of files and invoices, and abuse protection (Turnstile)Uploaded files and stored invoices, and your network address when we check you are not a robotLive
Amazon Web Services (AWS)The primary database — accounts, orders, progress, everything the platform readsEverything in the table above except files and videoLive — servers in Frankfurt, Germany
StripeCollecting card, Apple Pay and Google Pay payments and issuing refundsYour email, the amount and currency, and the card details you enter with them directlyLive
SentryFault monitoringTechnical error traces, scrubbed of email addresses, IBANs and session headersLive
Bunny StreamTranscoding and streaming video over signed linksA temporary playback identifier, network address, playback-quality signalsLive
ResendSending transactional mail and the mail you consented toYour email, your name, the message content and its delivery stateLive
PayPalAn alternative payment method charged in dollars or eurosYour email, the amount and its referenceNot yet enabled
Google Analytics 4Measuring traffic and page performanceA visit identifier and navigation path — only after you allow the “Analytics” categoryNot yet enabled
Meta and SnapMeasuring advertising performanceAn ad-click identifier, your email address and our account id for you — both hashed and unreadable — your browser type, and the purchase event with its value — only after you allow the “Advertising” categoryConsent only
The teacher whose course you tookFollowing their students, answering them, issuing their certificatesYour display name, your progress in their own courses, your questions and messages to them — never your payment data and never your email addressIndependent party
The payout bankPaying teachersThe beneficiary teacher’s name, IBAN and payout amountTeachers only

We may disclose data where a competent judicial or regulatory authority requires it by lawful order, or to defend our rights in a live dispute or to submit evidence in a chargeback, and only as narrowly as the request compels. If ownership of the platform or part of it transfers, data transfers with it on condition the buyer honours this policy, and we tell you beforehand.

6.Where your data is stored, and transfers abroad

Our primary database — accounts, orders, progress — is hosted in Frankfurt, Germany. The site itself runs on Vercel’s distributed network, so requests are handled at the data centre nearest you to keep responses fast, and files and invoices sit in a private cloud store with Cloudflare.

  • Every transfer outside your country happens under a processing agreement carrying standard contractual safeguards, and we do not work with a provider that lacks encryption in transit and at rest.
  • IBANs and beneficiary names are stored encrypted at field level, and identity-verification documents live in a private store with no public access, downloaded over short-lived links after an entitlement check.
  • Access to payment or identity data inside our team is limited to as few people as possible, requires the staff member to re-verify their identity at every sensitive action, and is written to an append-only audit log.

7.How long we keep it

DataRetention
An active account’s dataFor as long as the account is open
Sessions and sign-in recordsThirty days after the session ends
Financial records, invoices and credit notesTen years — the longest period GCC rules impose
Administrative audit logsSeven years
Security eventsTwelve months
Email delivery logsTwelve months, after which the address is hashed and no longer readable
Payment-provider webhook payloadsNinety days
Watch and progress dataTwenty-four months after your last activity in the course
Advertising measurement events sent with your consentNinety days
Teacher identity-verification documentsFor the contractual relationship and the statutory period after it
Uploads that never completedThirty days, then deleted automatically
Backups expire on the same clock, so a deletion from the database is not quietly undone by a backup that lives forever.

8.How we protect it

  • Encryption in transit is mandatory on every request, and encryption at rest applies at the database and storage layer.
  • Passwords are stored hashed with a modern algorithm built for the purpose; nobody here can read or recover them.
  • IBANs and beneficiary names carry additional field-level encryption, with the key held as a separate secret and a version column that allows it to be rotated.
  • Sensitive operations — approving a payout, exporting the payout file that contains full IBANs, and suspending a teacher’s account — require the staff member to re-verify their identity there and then, and all of them are logged.
  • Rate limits guard every sensitive path, and a human-verification check runs on sign-up, sign-in and password reset.
  • Error traces are scrubbed of email addresses, IBANs and session headers before they reach the monitoring system.
  • Incident response: if a breach affects your personal data we notify you and the competent authority within seventy-two hours of becoming aware of it, setting out what happened, what we did and what we advise you to do.

9.Your rights, and how to use them

RightHow it works today
Access and portabilityA “Download my data” button in your account settings gives you a single JSON file containing your account, orders, enrolments, progress, certificates and what you posted. It is open to every signed-in account, and support remains available if you cannot use it.
CorrectionEdit your details straight from account settings, or through support for anything you cannot change yourself
ErasureA learner deletes their own account from account settings: it anonymises your identity and revokes every session in the same moment. Teacher and admin accounts are reviewed by hand, by writing to support, because payouts, identity files and enrolled students have to be unwound first
Objection and restrictionObject to any processing resting on legitimate interest, or ask us to restrict it while your objection is examined
Withdrawing consent“Privacy settings” in the footer switches measurement and advertising off as easily as consent was given, and the unsubscribe link in every marketing email stops it at once
ComplaintYou may complain to the competent data-protection authority where you live — we would rather you gave us the chance to fix it first
Exactly what deleting your account covers: your personal details are removed from the account — name, email, phone, password, picture and two-factor secret — every one of your sessions is revoked at the same moment, and anything you had posted shows as “deleted user” instead of your name. Your learning record (enrolments, progress, attempts, certificates) and your financial record (accounting entries, invoices and credit notes) remain once severed from your identity and are not deleted by this request: the financial record is required by tax and commercial rules, and the learning record feeds what teachers are paid. You can always ask us what we still hold about you after deletion.

We answer rights requests within thirty days at the outside, and usually within days. We may ask for extra identity verification before an export or a deletion, to protect your account from impersonation. Deleting your account does not refund what you paid — a refund is its own path, within 30 days, under the refund policy.

11.Children’s privacy

The platform is not directed at anyone under thirteen and we do not knowingly collect their data. If we learn of an account belonging to a child under that age, we delete it and its data. Between thirteen and eighteen, the platform is used with a guardian’s consent and through their account, and the guardian may ask to see or delete the minor’s data.

12.Changes to this policy

We update this policy whenever we add a service, change a processor, or switch on one marked “not yet enabled” above. Material changes — a new processing purpose, or a new processor with access to payment or identity data — are notified by email and in-product thirty days before they take effect, and the “last updated” date at the top is refreshed in every case.

Related documents

A question about this document?

Our support team answers questions about terms, privacy and refunds within one working day.