Privacy Policy
Last updated: April 5, 2026
WBEX ("we," "our," or "us") operates a managed infrastructure platform registered in Riyadh, Kingdom of Saudi Arabia (Commercial Registration No. 7052047094). This Privacy Policy describes how we collect, use, store, and disclose information in compliance with the Personal Data Protection Law (PDPL) of the Kingdom of Saudi Arabia (Royal Decree M/19 of 1443 AH) and its implementing regulations issued by the Saudi Data and Artificial Intelligence Authority (SDAIA).
IMPORTANT: Unauthorized access, misuse, or unauthorized disclosure of personal data is a criminal offense under Saudi law, punishable by imprisonment of up to two (2) years and/or fines of up to three (3) million Saudi Riyals under the PDPL and related cybercrime legislation (Anti-Cyber Crime Law, Royal Decree M/17 of 1428 AH). This is not merely a breach of contract — it is a violation of law.
By using the Platform, you consent to the practices described in this Privacy Policy. If you do not agree, you must cease use of our services immediately.
1. Data We Collect
1.1 Account Information
When you register for an account, we collect:
- Full legal name and email address
- Phone number (required for identity verification via SMS OTP)
- Company or organization name and Commercial Registration number (if applicable)
- Billing and payment information (processed through Tap Payments; we do not store card numbers)
- Account credentials (passwords are hashed using bcrypt with 12 rounds; never stored in plaintext)
1.2 Server and Infrastructure Data
When you use the Platform, we collect and process:
- Server IP addresses, SSH connection details, and cloud provider credentials
- Server performance metrics collected every 15 seconds (CPU, memory, disk, network traffic)
- Application deployment logs, build logs, and container states
- Domain configuration, DNS records, and SSL certificate data
- Backup metadata (timestamps, sizes, retention status)
1.3 Access Logs and Security Events
We collect detailed access logs that constitute legal evidence under Saudi cybercrime law:
- HTTP access logs from Traefik reverse proxy (request host, path, status, IP address, user agent)
- Authentication events (login attempts, OTP verifications, password changes)
- Security events (failed SSH attempts, blocked IPs, firewall actions)
- API request logs with timestamps and IP addresses
- Deployment actions (who deployed what, when, from which source)
Legal basis: These logs are retained as evidence in compliance with the Anti-Cyber Crime Law (Article 10) which requires preservation of electronic records that may be relevant to criminal investigations.
1.4 Cloudflare Analytics
Through our Cloudflare integration, we collect:
- Visitor IP addresses and geographic location (country level)
- Request volumes, bandwidth usage, and threat data
- Firewall events and security analytics
1.5 AI Chatbot Interactions
When you interact with our AI assistant ("سيف"), we collect:
- Conversation content (messages sent and received)
- Contact information voluntarily provided during chat (name, email, phone)
- Service rating feedback
Chat conversations are processed by Anthropic (Claude AI) under their data processing terms. We do not use chat data for AI model training.
2. How We Use Information
We process personal data only for the following lawful purposes:
- Service delivery: Deploying applications, monitoring servers, managing domains, and providing the Platform's core functionality
- Account management: Creating and managing accounts, processing payments, and issuing invoices
- Security and fraud prevention: Detecting, preventing, and responding to unauthorized access, abuse, and security incidents. This is a legal obligation under Saudi cybercrime law.
- Legal compliance: Fulfilling our obligations under PDPL, Anti-Cyber Crime Law, ZATCA tax regulations, and other applicable Saudi laws
- Technical support: Responding to inquiries and resolving technical issues
- Platform improvement: Analyzing anonymized usage patterns to improve features and performance
3. Data Retention as Legal Evidence
We retain data for specific periods based on legal requirements and operational needs:
- Access logs and security events: Retained for a minimum of 12 months as required by the Anti-Cyber Crime Law for potential use as legal evidence in criminal investigations
- Authentication logs: Retained for 24 months to support forensic investigation of unauthorized access
- Deployment history: Retained for the lifetime of the account plus 6 months after termination
- Billing and financial records: Retained for a minimum of 7 years as required by ZATCA tax regulations and Saudi commercial law
- Account data: Retained for the duration of the account plus 90 days after termination
- AI chatbot conversations: Retained for 24 months for quality assurance and dispute resolution
- Anonymized analytics: May be retained indefinitely in aggregated form
WARNING: Tampering with, destroying, or altering electronic logs or evidence is a criminal offense under Article 5 of the Anti-Cyber Crime Law, punishable by imprisonment of up to four (4) years and/or fines of up to three (3) million Saudi Riyals.
4. Disclosure to Saudi Authorities
We may disclose personal data and access logs to Saudi government authorities in the following circumstances:
- Court orders and legal process: When required by a valid court order issued by a Saudi court of competent jurisdiction
- Criminal investigations: When requested by the Public Prosecution or law enforcement agencies investigating cybercrime under the Anti-Cyber Crime Law
- National security: When required by the National Cybersecurity Authority (NCA) for national security purposes
- SDAIA requests: When required by SDAIA for enforcement of the PDPL
- ZATCA audits: When required by the Zakat, Tax and Customs Authority for tax compliance audits
- Imminent harm: When we reasonably believe disclosure is necessary to prevent imminent physical harm or financial crime
We will notify affected users of government data requests unless legally prohibited from doing so (e.g., by court order imposing non-disclosure).
5. Data Storage and Security
5.1 Storage Location
Primary data storage is on servers located in Europe (Germany). Account data, logs, and metadata are stored on our control plane infrastructure. Server metrics may be processed in the geographic region where your servers are located.
5.2 Security Measures
- Encryption at rest: All sensitive data encrypted using AES-256
- Encryption in transit: All communications encrypted using TLS 1.2+ via Cloudflare
- Password security: Passwords hashed using bcrypt (12 rounds); never stored in plaintext
- Access controls: Role-based access with principle of least privilege
- Firewall protection: Cloudflare WAF with geographic restrictions
- Credential isolation: SSH keys and API credentials stored encrypted in the database
5.3 Breach Notification
In the event of a personal data breach, we will:
- Notify SDAIA within 72 hours of becoming aware of the breach, as required by PDPL
- Notify affected individuals without undue delay if the breach is likely to result in high risk to their rights
- Document the breach, its effects, and remedial actions taken
Legal consequence: Failure to notify of a data breach is a violation of PDPL Article 29, punishable by fines of up to five (5) million Saudi Riyals.
6. Your Rights Under PDPL
Under the Personal Data Protection Law, you have the following legally enforceable rights:
- Right of access (Article 14): You may request a copy of all personal data we hold about you
- Right to correction (Article 15): You may request correction of inaccurate or incomplete personal data
- Right to deletion (Article 16): You may request deletion of your personal data, subject to our legal retention obligations
- Right to data portability (Article 17): You may request an export of your data in a machine-readable format
- Right to restrict processing (Article 18): You may request restriction of processing in certain circumstances
- Right to object (Article 19): You may object to processing of your personal data for direct marketing
- Right to withdraw consent (Article 12): Where processing is based on consent, you may withdraw it at any time
- Right to lodge a complaint: You may file a complaint with SDAIA if you believe your data protection rights have been violated
To exercise these rights, contact us at info@wbex.sa. We will respond within 30 days. Failure to respond to legitimate data subject requests is a violation of PDPL, subject to regulatory sanctions.
7. Third-Party Services
- Cloudflare: DNS, CDN, SSL, and security services — processes visitor IP addresses and traffic data
- Tap Payments: Payment processing — we do not store card numbers
- GitHub: Repository access for deployment — only authorized repositories
- Anthropic (Claude AI): AI chatbot processing — conversations processed under Anthropic's terms
- Authentica: SMS OTP verification — phone numbers shared for verification only
We share only the minimum data necessary. Each provider operates under its own privacy policy and applicable data protection laws.
8. International Data Transfers
Some data may be processed outside the Kingdom of Saudi Arabia, depending on the cloud providers and services used. All international transfers comply with PDPL Chapter 5 (Cross-Border Transfer of Personal Data) and include adequate safeguards as required by SDAIA.
9. Cookies
- Essential cookies: Authentication and session management (required)
- Functional cookies: Language and layout preferences
- Analytics cookies: Aggregated usage patterns via Cloudflare Analytics
10. Children's Privacy
The Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. Processing personal data of children without parental consent is a violation of PDPL Article 21.
11. Changes to This Policy
We may update this Privacy Policy to reflect changes in law, regulation, or our practices. Material changes will be notified by email or Platform notice at least 30 days before taking effect.
12. Contact and Data Protection Officer
For privacy-related inquiries, data subject requests, or complaints:
WBEX Technology
Riyadh, Kingdom of Saudi Arabia
Commercial Registration: 7052047094
Email: info@wbex.sa
Website: wbex.sa
If you are not satisfied with our response, you have the right to file a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA) at sdaia.gov.sa.