1.Who is responsible for your data
The controller of your personal data on the عطاء platform at ataa.ai is شركة فكرة بلس للبحث والتطوير في مجال تقنيات التعليم ذ.م.م ش.ش.و — a company registered in Dubai, United Arab Emirates. That company owns and operates the platform and is your counterparty under the terms and conditions. The name above is its registered legal name as written on its UAE trade licence, set here in Arabic because the licence carries no English rendering; “عطاء” and ataa.ai are trade names it operates under and do not denote a separate entity.
For any privacy question, or to exercise any of your rights, write to support@ataa.ai, use the contact page under the privacy topic, or reach legal@ataa.ai for formal matters. Data requests are handled within thirty days at the outside.
2.Scope and the regimes behind it
This policy covers everything you do on the ataa.ai website, its apps, its email and its streaming, and applies equally to learners, teachers and visitors who never sign up. It is drafted to the shape of the GCC personal-data regimes — the Saudi Personal Data Protection Law and its regulations, and the UAE personal-data-protection law — and to the GDPR for visitors reaching us from inside the European Union.
It does not cover other websites you reach from a link inside a course, third-party tools a teacher uses in their teaching, or the meeting platforms live sessions are held on — each of those has its own policy.
3.What we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address and whether it is verified, password stored hashed and unreadable, preferred language and currency, profile picture if you upload one | You enter it |
| Sign-in and security data | Active sessions and their devices, your Google account identifier if you sign in that way, sign-in attempt times with the network address and its country, security events such as a password change or two-factor setup | Captured on sign-in |
| Order and payment data | Courses bought, amount, currency, country of purchase, invoice number, the payment provider’s reference, card brand and last four digits, the terms version and your marketing-consent state at the moment of purchase | Created by the purchase |
| Learning data | Enrolments, your progress per lesson, counted watch minutes and last position, quiz results, certificates issued and their verification serial | Your use of the player |
| What you post | Reviews, questions and answers, direct messages with a teacher, support tickets, reports you file | You post it |
| Teacher data | Public profile details, identity-verification documents, IBAN and beneficiary name both encrypted, payout and balance history | The teacher provides it |
| Technical data | Browser and operating system, connection country, request identifier, error traces and response times | Captured on each visit |
| Measurement and advertising data | Visit and campaign identifiers for the ad that brought you — none of which is written, and no pixel loaded, before you consent | Only after your consent |
- We never receive or store your full card number or security code. Your card is entered in the payment provider’s own fields, and what returns to us is an encrypted token and a short description of the card, useless outside their system.
- We never ask for a postal or billing address at any stage — the product is digital, nothing ships, and our schema has no address table at all.
- We do not collect your phone number to sign you in: there are no phone codes on this platform. The one case where your name and number are requested is choosing to pay in instalments, where available, because the instalment provider needs them to assess the order.
- We do not ask for special-category data — health, religion, ethnicity — do not infer it, and have nowhere to put it.
4.Why we process it, and on what lawful basis
| Purpose | Lawful basis |
|---|---|
| Creating your account, securing sign-in, keeping your sessions | Performance of our contract |
| Completing a purchase, issuing the invoice, handling refunds | Contract and legal obligation |
| Saving your course progress and issuing and verifying your certificate | Performance of our contract |
| Sending transactional mail: receipt, payout decision, session reminder | Performance of our contract |
| Counting watch minutes to distribute the teachers’ share of subscription revenue | Our contract with the teacher |
| Detecting fraud, preventing account sharing, protecting content from copying | Legitimate interest |
| Monitoring faults, measuring performance, improving the product in aggregate | Legitimate interest |
| Measuring campaign performance and site traffic | Your consent, withdrawable at any time |
| Marketing email, offers and periodic digests | Your consent, explicitly given and never pre-ticked |
| Keeping accounting, tax and audit records | Legal obligation |
We make no solely automated decisions with legal effect on you. Fraud detection and account-sharing signals raise a case to a member of staff; refund decisions, account suspensions and payout approvals are made by a person and recorded. You may ask for any such decision to be reviewed and explained to you.
6.Where your data is stored, and transfers abroad
Our primary database — accounts, orders, progress — is hosted in Frankfurt, Germany. The site itself runs on Vercel’s distributed network, so requests are handled at the data centre nearest you to keep responses fast, and files and invoices sit in a private cloud store with Cloudflare.
- Every transfer outside your country happens under a processing agreement carrying standard contractual safeguards, and we do not work with a provider that lacks encryption in transit and at rest.
- IBANs and beneficiary names are stored encrypted at field level, and identity-verification documents live in a private store with no public access, downloaded over short-lived links after an entitlement check.
- Access to payment or identity data inside our team is limited to as few people as possible, requires the staff member to re-verify their identity at every sensitive action, and is written to an append-only audit log.
7.How long we keep it
| Data | Retention |
|---|---|
| An active account’s data | For as long as the account is open |
| Sessions and sign-in records | Thirty days after the session ends |
| Financial records, invoices and credit notes | Ten years — the longest period GCC rules impose |
| Administrative audit logs | Seven years |
| Security events | Twelve months |
| Email delivery logs | Twelve months, after which the address is hashed and no longer readable |
| Payment-provider webhook payloads | Ninety days |
| Watch and progress data | Twenty-four months after your last activity in the course |
| Advertising measurement events sent with your consent | Ninety days |
| Teacher identity-verification documents | For the contractual relationship and the statutory period after it |
| Uploads that never completed | Thirty days, then deleted automatically |
8.How we protect it
- Encryption in transit is mandatory on every request, and encryption at rest applies at the database and storage layer.
- Passwords are stored hashed with a modern algorithm built for the purpose; nobody here can read or recover them.
- IBANs and beneficiary names carry additional field-level encryption, with the key held as a separate secret and a version column that allows it to be rotated.
- Sensitive operations — approving a payout, exporting the payout file that contains full IBANs, and suspending a teacher’s account — require the staff member to re-verify their identity there and then, and all of them are logged.
- Rate limits guard every sensitive path, and a human-verification check runs on sign-up, sign-in and password reset.
- Error traces are scrubbed of email addresses, IBANs and session headers before they reach the monitoring system.
- Incident response: if a breach affects your personal data we notify you and the competent authority within seventy-two hours of becoming aware of it, setting out what happened, what we did and what we advise you to do.
9.Your rights, and how to use them
| Right | How it works today |
|---|---|
| Access and portability | A “Download my data” button in your account settings gives you a single JSON file containing your account, orders, enrolments, progress, certificates and what you posted. It is open to every signed-in account, and support remains available if you cannot use it. |
| Correction | Edit your details straight from account settings, or through support for anything you cannot change yourself |
| Erasure | A learner deletes their own account from account settings: it anonymises your identity and revokes every session in the same moment. Teacher and admin accounts are reviewed by hand, by writing to support, because payouts, identity files and enrolled students have to be unwound first |
| Objection and restriction | Object to any processing resting on legitimate interest, or ask us to restrict it while your objection is examined |
| Withdrawing consent | “Privacy settings” in the footer switches measurement and advertising off as easily as consent was given, and the unsubscribe link in every marketing email stops it at once |
| Complaint | You may complain to the competent data-protection authority where you live — we would rather you gave us the chance to fix it first |
We answer rights requests within thirty days at the outside, and usually within days. We may ask for extra identity verification before an export or a deletion, to protect your account from impersonation. Deleting your account does not refund what you paid — a refund is its own path, within 30 days, under the refund policy.
10.Consent for measurement and advertising
No advertising pixel loads and no marketing or analytics measurement runs before you choose. The one exception is basic page-performance measurement — load timings and the page’s route — which runs for every visitor on the legitimate-interest basis set out in the table above: it writes nothing to your browser and creates no identifier that can follow you between visits or across sites. On your first visit a panel offers two buttons of equal shape and size — “Accept all” and “Reject all” — plus “Customise”, which separates the “Analytics” and “Advertising” categories so you can allow one and refuse the other. A refusal is stored exactly the way an acceptance is, limits nothing about using the platform, and your choice is kept for twelve months.
- The measurement tool runs in consent mode: before your choice, every storage and advertising signal it has is set to denied, and only your own choice changes that.
- Advertising pixels do not load before your consent, and click identifiers are not written before it.
- We record your consent state on the order itself at the moment of purchase, and no purchase event is sent to an advertising platform unless that consent is on record — a condition re-checked immediately before sending, not once at checkout.
- Every cookie is listed by name, purpose and lifetime in the cookie policy.
11.Children’s privacy
The platform is not directed at anyone under thirteen and we do not knowingly collect their data. If we learn of an account belonging to a child under that age, we delete it and its data. Between thirteen and eighteen, the platform is used with a guardian’s consent and through their account, and the guardian may ask to see or delete the minor’s data.
12.Changes to this policy
We update this policy whenever we add a service, change a processor, or switch on one marked “not yet enabled” above. Material changes — a new processing purpose, or a new processor with access to payment or identity data — are notified by email and in-product thirty days before they take effect, and the “last updated” date at the top is refreshed in every case.