Privacy Policy
Last updated: 1 August 2026
This policy describes how Heard collects, uses, shares, and protects personal data across our website and our platform, including conversations handled on WhatsApp and other channels.
1. Who we are
Heard, a Yasmina company (“Heard”, “we”, “us”) is a Yasmina company operating in the Kingdom of Saudi Arabia and across the MENA region. We provide an AI-powered customer service platform that answers, resolves, and acts on customer conversations across channels including voice, WhatsApp, web chat, email, SMS, and social messaging, in Arabic and English.
This policy explains how we handle personal data across our website and our platform. Where we process the personal data contained in conversations our business customers handle through Heard, we act as a processor on their documented instructions — the business is the controller, and its own privacy notice governs that data. Where we process data about our own account holders, website visitors, and prospects, we act as the controller, and this policy applies directly.
2. The law that applies
We handle personal data in accordance with the Saudi Personal Data Protection Law (PDPL), issued under Royal Decree No. M/19, together with its Implementing Regulations, as supervised by the Saudi Data & AI Authority (SDAIA). Where we serve customers or data subjects in other jurisdictions, we also honour applicable laws such as the EU/UK General Data Protection Regulation (GDPR) and comparable data protection regimes across the MENA region.
3. Information we collect
We collect the following categories of personal data:
- Account and contact data — name, work email, phone number, workspace and role, and authentication identifiers, when you create or are invited to a workspace.
- Customer conversation data — the content of conversations processed through the platform on behalf of our business customers: messages, transcripts and recordings of calls, attachments, and the contact identifiers (such as phone numbers or email addresses) of the people in those conversations. We process this on our customers’ documented instructions.
- Channel metadata — information provided by the messaging channels you connect, such as message and delivery status, timestamps, and sender identifiers.
- Usage and device data — log data, IP address, browser and device type, and interactions with the dashboard, collected to operate and secure the service.
- Cookies and similar technologies — used to keep you signed in and to understand aggregate usage. See the Cookies section below.
4. WhatsApp and third-party messaging channels
When a business connects WhatsApp, Heard receives and sends messages through the Meta WhatsApp Business Platform (Cloud API). Inbound messages from customers are delivered to Heard via a secure webhook and appear in the business’s inbox, where the AI agent or a human agent can respond within the messaging window permitted by WhatsApp.
Data received through WhatsApp — including the customer’s WhatsApp phone number, profile name, and message content — is used solely to deliver the customer-service conversation the customer initiated, and to enable the connected business to respond. We do not use WhatsApp data for advertising, we do not sell it, and we do not share it except with the sub-processors listed below that are necessary to operate the service. Our use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies, including limits on use, retention, and onward transfer.
The same principles apply to the other channels a business may connect (voice telephony, email, SMS, web chat, and social messaging): data is used to operate the conversation and is handled under this policy and the customer’s data processing agreement.
5. How we use personal data and our legal basis
Under the PDPL we process personal data on a lawful basis — including performance of a contract, compliance with a legal obligation, your consent where required, and our legitimate interests in operating and securing the service where those interests are not overridden by your rights. We use personal data to:
- Provide, operate, and secure the platform, including routing conversations, generating AI responses, and taking the actions a business has configured (such as looking up an order or opening a ticket).
- Authenticate users and manage workspaces, roles, and permissions.
- Provide support, respond to enquiries, and communicate service and security notices.
- Monitor, debug, and improve the reliability, quality, and safety of the service.
- Comply with legal and regulatory obligations in the Kingdom and other jurisdictions where we operate.
6. AI and model training
Customer conversations and documents are used to serve that customer’s own agents and for no other purpose. We do not use customer conversation content to train foundation models — ours or any third party’s — and our AI providers are contractually bound not to train their models on data submitted through our service.
8. Cross-border transfers
Heard runs on secure, enterprise-grade cloud infrastructure. Some of our sub-processors may process personal data outside the Kingdom of Saudi Arabia. Where personal data is transferred outside the Kingdom, we do so in accordance with the PDPL’s provisions on transfer of personal data outside the Kingdom and any conditions or guidance issued by SDAIA, applying appropriate safeguards — such as contractual protections equivalent to those recognised under applicable law — to protect the data. For data subjects in the EU/UK, we rely on transfer mechanisms recognised under the GDPR, such as standard contractual clauses.
9. Data retention
We retain personal data only for as long as necessary to provide the service and for the periods agreed with our business customers in their data processing agreement, after which it is deleted or anonymised. Account and website data is retained while your account is active and for a reasonable period afterward to meet legal, accounting, or regulatory requirements. Deletion requests are honoured within the timeframe set out in the applicable agreement or required by law.
10. Security
We protect personal data with technical and organisational measures appropriate to the risk, including encryption in transit and at rest, network isolation, least-privilege access controls, signed and verified webhooks, and audit logging. No method of transmission or storage is perfectly secure, but we work continuously to safeguard the information entrusted to us and to meet the security expectations of the PDPL.
11. Your rights
Subject to applicable law, and in particular under the Saudi PDPL, you have the right to be informed of how your personal data is processed, to access your personal data, to request its correction, and to request its destruction. Where the GDPR or another framework applies to you, you may also have rights to portability, to object to or restrict certain processing, and to withdraw consent.
Where Heard acts as a processor, please direct your request to the business that operates the conversation; we will assist them in responding. Where Heard is the controller, contact us at hello@getheard.tech and we will respond within the timeframes required by law. In the Kingdom of Saudi Arabia, you also have the right to raise a complaint with the Saudi Data & AI Authority (SDAIA); elsewhere, with your competent data protection authority.
13. Children’s privacy
Heard is a business-to-business service and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Language
This policy is published in English. An Arabic version is available on request and, in the event of any inconsistency for data subjects in the Kingdom of Saudi Arabia, the Arabic version prevails.
15. Changes to this policy
We may update this policy from time to time. When we do, we will revise the “last updated” date above and, where changes are material, provide additional notice. Continued use of the service after an update constitutes acceptance of the revised policy.
16. Governing law
This policy is governed by the laws of the Kingdom of Saudi Arabia, without prejudice to any mandatory data protection rights you may have under the laws of your own country of residence.
17. Contact us
For any question about this policy or to exercise your rights, contact us at hello@getheard.tech. You can also write to Heard, a Yasmina company.
Heard, a Yasmina company · https://getheard.tech