Privacy Policy
This Privacy Policy explains how Adraa Labs collects, uses, and protects personal data in connection with Adraa Mail. We process data in the Kingdom of Saudi Arabia in alignment with the Personal Data Protection Law (PDPL) issued by Royal Decree M/19 of 1443H and its Implementing Regulations.
1.Who we are
Adraa Labs(“Adraa”, “we”, “us”) is a company registered in Riyadh, Kingdom of Saudi Arabia, and is the controller of personal data processed for the purpose of providing accounts, billing, and support for Adraa Mail.
For mailbox contents and other Customer Data submitted by Subscribers through the Service, Adraa acts as a processor on behalf of the Subscriber (controller). The Subscriber is responsible for the lawful basis of its own processing and for responding to the rights requests of its own Users.
You can reach our privacy team at privacy@adraa.ai.
2.Scope
This Policy applies to the Adraa Mail web application, mailbox access protocols (SMTP, IMAP, JMAP), administrative dashboards, marketing pages on adraa.ai, and related setup and support communications.
It does not apply to third-party services that you choose to connect to Adraa Mail (e.g. DNS providers, identity providers, mobile mail clients). Those services have their own privacy notices.
3.Categories of personal data we process
3.1 Account and billing data
Names, work email addresses, phone numbers, organisation name, billing address, VAT number, and payment-instrument metadata (last four digits, brand, expiry — full card numbers are handled by our payment processor and never reach our servers).
3.2 Authentication data
Hashed passwords, multi-factor authentication settings, session identifiers, single-sign-on assertions, and audit logs of sign-in events (timestamp, IP address, user agent, country).
3.3 Mailbox content (processed as processor on the Subscriber’s behalf)
The bodies, headers, attachments, contacts, calendars, and folder structures that Users send, receive, or store through the Service. We do not access this content except as set out in section 5 (Purposes).
3.4 Mail metadata and operational logs
SMTP envelope information (sender, recipient, message size, timestamps), delivery status, SPF / DKIM / DMARC verdicts, anti-spam scores, and infrastructure logs needed to operate and secure the Service.
3.5 Domain and DNS configuration
The mail domains a Subscriber configures, the DNS records we publish or recommend, and verification states.
3.6 Support and communication data
The contents of messages you send to support, sales, billing, or legal addresses, and any attachments or screenshots you choose to include.
3.7 Website and product analytics
On the public marketing site we may process aggregated, de-identified usage data (page views, referrer, country, device class) using first-party tooling. The mailbox application itself does not embed third-party trackers.
4.Sources of data
We obtain personal data from:
- you and your Users, directly, when you sign up, configure the Service, or contact us;
- your authorised administrators, when they provision or manage Users on your behalf;
- third parties acting on your behalf, such as your DNS provider or identity provider;
- automatic collection by the Service (logs, mail metadata, security telemetry);
- publicly available sources, such as WHOIS or public DNS, when verifying domain ownership.
5.Purposes and legal bases
We process personal data for the following purposes:
- Providing the Service — accepting, delivering, and storing mail; maintaining mailboxes; running the web client. Basis: performance of the contract with the Subscriber.
- Account administration and billing — creating accounts, invoicing, collecting payments. Basis: performance of contract; compliance with tax law.
- Security and abuse prevention — anti-spam, anti-malware, abuse detection, rate limiting, intrusion detection. Basis: legitimate interest in protecting the Service and other Subscribers.
- Support — diagnosing and resolving issues you report. Basis: performance of contract.
- Compliance with law — responding to lawful requests from competent authorities and complying with our own legal obligations. Basis: legal obligation.
- Product improvement — aggregated, de-identified usage analysis. Basis: legitimate interest.
- Marketing — sending occasional product updates to administrative contacts. Basis: legitimate interest, with an opt-out in every message.
6.Data residency
Adraa Mail is operated from data centres in the Kingdom of Saudi Arabia. Live mailbox data, backups, and operational logs are stored in-Kingdom. We do not replicate Customer Data outside Saudi Arabia.
A limited set of operational telemetry (for example, exception traces from the administrative dashboard) may be processed by sub-processors outside Saudi Arabia under appropriate safeguards described in section 7. We will obtain explicit consent before any cross-border transfer of Customer Data, in accordance with PDPL Article 29.
7.Sub-processors
We engage a small number of sub-processors to support the Service (for example, payment processing, transactional email for setup notifications, infrastructure monitoring). A current list of sub-processors, their location, and the type of processing they perform is available on request from privacy@adraa.ai.
Each sub-processor is bound by a written agreement that imposes data protection obligations no less protective than those in this Policy, and is permitted to process personal data only on documented instructions from Adraa.
8.Sharing and disclosure
We share personal data only as follows:
- with sub-processors as described in section 7;
- with the Subscriber to whom a User belongs (Users should direct privacy requests to their administrator first);
- with competent Saudi authorities where required by law, regulation, or a binding order. We assess each request for validity and, where lawful, notify the affected Subscriber;
- with professional advisers, auditors, and prospective acquirers under appropriate confidentiality obligations, in the context of corporate transactions;
- with your consent.
We do not sell personal data, and we do not share it with advertisers.
9.Retention
We retain personal data only for as long as needed for the purposes set out above, then delete or anonymise it on the following schedule:
- Mailbox content — for the duration of the subscription, plus thirty (30) days after termination to support migration or reinstatement, after which it is permanently removed from live and backup systems within ninety (90) days.
- Account and billing records — for as long as the account is active, and up to ten (10) years after termination where required to meet Saudi tax, accounting, and audit obligations.
- Authentication and security logs — typically ninety (90) days for session logs and up to twelve (12) months for security audit logs.
- Support correspondence — up to thirty-six (36) months from the date of the last related interaction.
- Marketing contacts — until you unsubscribe, after which we retain a suppression record indefinitely so we do not contact you again.
10.Security
We implement technical and organisational measures appropriate to the risk of processing, including:
- encryption in transit (TLS 1.2 or above) and at rest;
- strong password hashing and support for multi-factor authentication;
- least-privilege access controls and tamper-evident audit logs for administrative actions;
- network segmentation, intrusion detection, and DDoS protection;
- scheduled backups stored in-Kingdom with documented restore procedures;
- vetting of personnel with access to systems, and security awareness training;
- vulnerability management, regular penetration testing, and an incident response process.
No method of transmission or storage is perfectly secure. If we become aware of a personal data breach affecting your data, we will notify the affected Subscribers and, where required, the Saudi Data & Artificial Intelligence Authority (SDAIA) without undue delay and in accordance with the PDPL Implementing Regulations.
11.Your rights under the PDPL
Subject to applicable exemptions, you have the following rights:
- To be informed about how your personal data is processed;
- Access to your personal data held by us;
- Correction of inaccurate or incomplete data;
- Destruction of personal data that is no longer required;
- Withdrawal of consent, where processing is based on consent;
- Restriction of processing, in defined circumstances;
- Objection to processing based on legitimate interest, including direct marketing;
- Lodge a complaintwith the Saudi Data & Artificial Intelligence Authority (SDAIA), the competent supervisory authority.
Where Adraa processes personal data as a processor on behalf of a Subscriber, please direct rights requests to your administrator. We will assist Subscribers in responding to such requests as required by the PDPL.
12.How to exercise your rights
Write to privacy@adraa.ai with a description of your request and the email address associated with your account. We may need to verify your identity before acting on a request. We aim to respond within thirty (30) days, and will tell you if we need additional time.
13.Cookies and similar technologies
The mailbox application uses a small number of first-party cookies and local-storage keys that are strictly necessary to authenticate sessions, remember interface preferences (such as theme and locale), and operate features like offline drafts. No third-party advertising or cross-site tracking technologies are loaded inside the authenticated mailbox.
The public marketing site may set first-party cookies to measure aggregate traffic and to remember if you have accepted a cookie notice. You can disable cookies in your browser, but the Service may not function correctly without the strictly necessary ones.
14.Children
The Service is intended for use by businesses and is not directed at children under the age of eighteen (18). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact privacy@adraa.ai so we can delete it.
15.Automated decision-making
We do not use Customer Data to make decisions producing legal or similarly significant effects about individual Users by purely automated means. Automated systems we operate (such as anti-spam classification) act on messages, not on individual people, and their decisions are subject to human review on request via support@adraa.ai.
16.Changes to this Policy
We may update this Policy from time to time. The version in force is the one published at adraa.ai/privacy on the date of access. We will notify Subscribers of material changes by email to the registered administrative contact and by posting a notice in the administrative dashboard at least fourteen (14) days before the changes take effect.
17.Contact and complaints
For any privacy question, request, or complaint, write to privacy@adraa.ai. We take complaints seriously and will work in good faith to resolve them.
If you are not satisfied with our response, you have the right to lodge a complaint with the Saudi Data & Artificial Intelligence Authority (SDAIA), which can be reached via sdaia.gov.sa.