Privacy Policy for “Moazez” Platform
Last updated: [DD/MM/YYYY]
Owner/Operator: [Legal company name] (“we”/“Moazez”)
Scope: This policy applies to the Moazez platform, its apps and services (Student App, Parent App, Teacher App, School Dashboard, our website, and customer support).
1) Introduction
Moazez is committed to protecting the privacy of its users’ data and applying best-in-class security and organizational practices to provide a safe and reliable digital education environment. This policy explains how we collect, use, share, and protect your data, and the rights you may have regarding your personal data under applicable laws in the Kingdom of Saudi Arabia, including the Personal Data Protection Law (PDPL) and its implementing regulations as applicable and as updated.
2) Key Definitions
- Personal Data: Any data that identifies you directly or indirectly (e.g., name, ID number, phone number...).
- Sensitive Data: Data that requires a higher level of protection such as biometric data, health data, precise location data, or any data classified as sensitive under applicable law.
- Data Controller: The entity that determines the purposes and means of processing (typically the school/educational institution).
- Data Processor: The entity that processes data on behalf of the controller (typically Moazez when providing services to schools).
- User: Student / Parent / Teacher / Administrative staff / Website visitor.
Important: In most cases, the school is the data controller and Moazez acts as a data processor under the service agreement, unless stated otherwise.
3) Who does this notice apply to?
- Students enrolled in schools using Moazez.
- Parents/guardians.
- Teachers, supervisors, counselors, and school administration.
- Visitors to the Moazez website or anyone contacting support.
4) What data do we collect?
We collect data only to the extent necessary to provide and improve the service and to meet legal and regulatory obligations. This may include:
(A) Identity and account data
Name, class/section, school, national ID/residency number or student identifier (as provided by the school). Mobile number, email, login credentials, device identifiers. Profile photo (if enabled by the school or permitted by role).
(B) Support and communications data
Messages and inquiries submitted to support. Chat/call records for quality and documentation purposes (where notice is provided).
(C) Usage and interaction data
Attendance, recorded behaviors, points/rewards, tasks/achievements, in-app activities. System logs (Logs) such as login times, visited pages, and performed actions.
(D) Location data (Location)
We may use approximate or precise location data only when the school enables features that require it (e.g., pickup/callout workflows or presence verification). Device permission is requested when needed.
(E) Biometric data (Biometric) — if enabled
Such as face/fingerprint identifiers used for identity verification. Our principle: we do not collect/process biometrics unless clearly needed + supported by a valid legal basis/consent where required + minimized to the least scope possible + protected with strict safeguards.
(F) Financial / payments data — if applicable
If there is a wallet/points/rewards or subscriptions, billing and transaction data may be processed. We typically do not store full payment card details when payments are handled by an approved payment provider.
(G) Device and technical data
Device type and OS, app identifiers, IP address, website cookies (Cookies), and advertising identifiers (if any).
5) How do we collect data?
- From the school (student information / administrative systems) during integration or import.
- Directly from the user when registering/updating details or contacting support.
- Automatically through use of the platform (Logs/Analytics).
- From trusted third parties (e.g., notification, hosting, or payment providers) as necessary to deliver the service.
6) Why do we use your data? (Purposes of processing)
We use data for the following purposes:
- To provide and operate core services (accounts, roles, behavior records, points, reports...).
- To enable security features (verification, pickup/callout, preventing unauthorized access).
- To improve the experience and service quality (performance measurement, troubleshooting, feature development).
- To send communications and notifications (parent alerts, administrative notices, system messages).
- To comply with laws and regulatory requirements or official/court orders.
- To generate reports and analytics for the school (KPIs/BI, behavioral and operational indicators).
- AI and advanced analytics (if enabled): to analyze behavioral patterns and predict risks/needs to support administrators and counselors, with data minimization and bias-reduction safeguards where possible.
7) Legal bases for processing
Depending on the context, we rely on one or more of the following legal bases:
- Performance of the service agreement with the school.
- Compliance with a legal obligation.
- Explicit consent where required (especially for sensitive data such as biometrics/precise location, or where user consent is needed).
- Legitimate interests (such as platform security and fraud prevention) balanced against individuals’ rights.
In school contexts, the primary basis is typically the service agreement + legal obligations + school-authorized permissions/consents as applicable.
8) Data sharing: who do we share your data with?
We do not sell your personal data. We may share data only when necessary and with trusted parties, such as:
- The school/educational institution (data controller) within authorized roles.
- Service providers (sub-processors) such as hosting, messaging/notifications providers, analytics providers, technical support, and payment gateways.
- Competent authorities where legally required or pursuant to an official order.
- Auditors/consultants under strict confidentiality.
A list of sub-processors may be provided upon request or published on a dedicated page.
9) Cross-border data transfers
Some services may require hosting or processing with providers operating outside the Kingdom. In such cases:
- We comply with applicable cross-border transfer requirements.
- We apply contractual and security safeguards, assess risks, and minimize transfers where possible.
- Certain data may be kept within the Kingdom based on regulatory requirements or school contracts.
10) Data retention
- We retain data as long as necessary to provide the service, comply with legal obligations, resolve disputes, and enforce agreements.
- When the school relationship ends or a deletion/disposal request applies, deletion/disposal is implemented within an agreed period (e.g., 30 days) unless longer retention is required by law.
- Backup copies may be retained for a limited time for disaster recovery and then rotated/deleted automatically.
11) Information security
We apply appropriate technical and organizational measures, such as:
- Encryption in transit (TLS) and at rest where appropriate.
- Role-based access control (RBAC) and access logging.
- Password controls and multi-factor authentication (where enabled).
- Environment separation, monitoring, and anomaly detection.
- Periodic security testing, updates, and vulnerability remediation.
However, no internet system is 100% secure. We use reasonable efforts to protect data and will notify relevant parties where required in the event of a material security incident.
12) Children and minors’ data
- Moazez is designed for educational environments and may process minors’ data.
- Student data is processed under the school’s framework and permissions and in accordance with applicable laws.
- Access to student data is restricted by role (parent/teacher/administration).
- Features requiring sensitive data (e.g., precise location/biometrics) must be formally enabled with appropriate safeguards and a valid legal basis.
13) Cookies and tracking technologies
When using our website, we may use:
- Essential cookies to operate the site.
- Cookies to improve performance and measure usage (Analytics).
- Preferences may be managed via browser settings or a consent banner (where provided).
14) External links and third-party services
Our website/platform may include links to external services. We are not responsible for the privacy practices of those third parties, and we recommend reviewing their policies before providing any data.
15) Your rights
Under applicable laws, you may have rights including:
- Access to your data.
- Request a copy of your data (portability where applicable).
- Correction of inaccurate data.
- Deletion/disposal (where conditions apply and within the school’s controller framework).
- Withdraw consent where processing is based on consent.
- Object/restrict processing in certain cases.
- Lodge a complaint with the competent authority where applicable.
Note: if the school is the data controller, fulfilling certain requests may require the school’s authorization or direction under the agreement and applicable laws.
16) How to exercise your rights
You can submit a request via the following channels:
- Or through the school dashboard (for administrators).
- Verification information we may request: name, ID/student identifier, mobile number, school, and other reasonable verification details.
- Expected response time: in accordance with applicable law and without prejudice to contractual/legal obligations.
17) AI privacy and predictive analytics (if applicable)
- We may use AI/analytics models to provide supportive indicators (e.g., risk of recurring behavior, need for counseling intervention).
- These indicators are supportive, not final judgments, and disciplinary decisions should not be made based solely on them without human review.
- We work to reduce bias and improve accuracy and apply access controls and auditability.
18) Changes to this policy
We may update this policy from time to time. The updated version will be published on the website with an updated “Last updated” date. If changes are material, we may notify the school/users via official channels.
19) Contact information
Privacy/Data Protection Officer: [Name/Title]
Address: [Company address]
Commercial registration/Tax ID: [---]