Privacy Policy
This policy covers everything we operate under the Tsleem name: the website at tsleemksa.com, the web application at app.tsleemksa.com, and the Tsleem mobile app for Android and iOS. It explains what personal data we collect, why, where it is kept, who it is shared with, how long we keep it, how it is destroyed, and what you can require of us.
Last updated: 21 September 2026
- Who we are
- Who is responsible for your data
- What we collect, and why
- How we collect it
- Billing and payment data
- Cookies on this website
- Who your data is shared with
- Where it is stored and how it is protected
- How long we keep it, and how it is destroyed
- Your rights, and how to exercise them
- Complaints
- Children
- Changes to this policy
Who we are
Tsleem is a field-operations platform operated by Allama Almuhtarifa Company for Business Solutions (trading as Protag), a company registered in the Kingdom of Saudi Arabia.
| Company | Allama Almuhtarifa Company for Business Solutions |
|---|---|
| Commercial Registration | 7038411810 |
| VAT registration | 312076116700003 |
| Registered address | King Abdulaziz Rd, Alyasmin, Riyadh 13326, Saudi Arabia |
| privacy@tsleemksa.com | |
| Telephone | +966 50 795 6034 |
Who is responsible for your data
This depends on which relationship you have with us, and it changes who decides what happens to your data.
If you are a customer of ours
When your organisation buys Tsleem, we are the data controller for the account and billing data of the people who deal with us — the contacts who sign the agreement, receive invoices and administer the account. We decide what we collect and why.
If you are a user inside a customer's account
Your employer — the organisation that issued your account — decides what operational data is collected and why. They are the data controller. We operate Tsleem on their behalf as the data processor, and do not use their data for any purpose of our own. This matters for your rights: requests to access, correct or delete work records are decided by your employer, and we will pass your request to them and support them in answering it.
If you are a visitor to this website
We are the controller for the limited data described under Cookies on this website.
What we collect, and why
| Data | Purpose | Required? |
|---|---|---|
| Name, work email address, telephone, job title, account ID | To create and secure your account, to sign you in, and to attribute each completed checklist, approval or rejection to the person who did it. | Yes — the service cannot function without it |
| Organisation name, address, CR and VAT details | To contract with your organisation and to issue a compliant tax invoice. | Yes, for customers |
| Device identifier and push token | To deliver notifications about work assigned to you and to keep your session secure. | Yes, in the mobile app |
| Photographs taken in the app | Photographic evidence attached to a checklist answer, stored in your employer's work-order records. The app uses the camera only — it cannot browse or read your photo gallery. | Only where a checklist question asks for a photo |
| Precise location | To record where an inspection took place and to confirm the work was done at the right site. | No — you may decline; checklists can still be submitted |
| Operational records you create | Checklists, work orders, tickets, approvals, remarks and the audit trail of who did what and when. This is the substance of the service. | Yes |
| Billing records | Invoices, payment status and payment references. See Billing and payment data. | Yes, for customers |
| Crash reports, diagnostics and server logs | To find and fix faults, and to investigate security incidents. | Yes |
We do not collect contacts, calendar, messages, call logs, browsing history, audio, health data, or an advertising identifier. We do not profile you for advertising, and we make no automated decision that produces a legal effect about you without a person involved.
Automated photo checks
If your organisation has enabled it, a photo you attach may be assessed automatically to judge whether it matches the question being answered. The photo and the question text are sent to Anthropic for that assessment and are not used to train any model. The resulting verdict is stored with the checklist and is visible to your supervisor. A verdict is advisory: a person always makes the final decision.
How we collect it
- Directly from you — when you fill in a checklist, take a photo, raise a ticket, or email us.
- From your employer — accounts are created by your organisation's administrator. There is no public sign-up to the application.
- Automatically — device and session information, server logs, crash diagnostics, and, on this website only, analytics cookies if you accept them.
Billing and payment data
Tsleem is sold to organisations, not to consumers, and there is no online checkout. A plan is agreed with our sales team, we issue an invoice or a secure payment link, and the customer pays against it. The commercial terms are set out on our pricing page.
We never see or store your full card number. Card details are entered directly on the hosted payment page of a payment service provider licensed by the Saudi Central Bank (SAMA), which is responsible for processing them under the PCI DSS standard. What we receive back and retain is limited to the payment reference, the last four digits and card brand, the amount, the currency and whether the payment succeeded.
We keep invoices, credit notes and payment records for as long as Saudi tax and commercial law requires us to, which is longer than the life of your account. This is a legal obligation and is not affected by a deletion request.
Cookies on this website
This website sets no cookies at all unless you accept analytics. There is no advertising, no tracking pixel, no third-party embed, and nothing is sold or shared. Declining costs you nothing — every page works identically.
| Cookie | Purpose | Retention | Consent |
|---|---|---|---|
tsleem_consent |
Remembers whether you accepted or declined analytics. | 6 months | Not required — it exists only to honour your choice |
_ga, _ga_* |
Google Analytics 4: anonymous, aggregated measurement of how the site is used. | Up to 24 months | Only set if you accept |
If you accept, analytics records the pages you viewed and roughly how long for, your approximate location at city level derived from a truncated IP address, your device type, browser and language, and the site that referred you. IP anonymisation is enabled and Google advertising signals are switched off, so this data is not used for ad targeting or combined with advertising profiles. If you decline, no Google script is loaded and no request is made to Google at all.
The application at app.tsleemksa.com uses strictly-necessary cookies to keep you signed in. These are required for it to function and are not used for tracking.
Who your data is shared with
Your data is visible to authorised people within your own organisation. It is not sold, rented, or shared with advertisers or data brokers. It is handled by these service providers on our behalf, under contract:
| Provider | What they do |
|---|---|
| Google Cloud Platform | Hosting, database and file storage |
| Google Firebase | Push notifications and crash reporting |
| Anthropic | Automated photo checks, where your organisation has enabled that feature |
| Our payment service provider | Card processing for subscription invoices |
We may also disclose data where we are required to by Saudi law, a court order, or a competent authority.
Where it is stored and how it is protected
Operational data is stored on Google Cloud infrastructure in the Middle East (Dammam, Saudi Arabia) region. All traffic between the applications and our servers is encrypted with HTTPS/TLS. Sign-in tokens are held in the device's encrypted storage. Access within our team is limited to the people who need it to operate and support the service, and administrative access is logged.
Two categories of processing involve a transfer outside the Kingdom: automated photo checks, which are sent to Anthropic, and push notification delivery and crash reporting through Google Firebase. Both are carried out under contract and are limited to the purposes described above.
How long we keep it, and how it is destroyed
- Operational records — retained for as long as your organisation's account remains active, and deleted when they instruct us to delete them or when the account closes.
- Account and contact data — deleted when the account closes, except where we must keep it for a legal reason.
- Invoices and payment records — retained for the period Saudi tax and commercial law requires.
- Server logs and crash diagnostics — retained for a rolling operational window and then overwritten.
- Analytics — up to 24 months, and only if you accepted.
When data reaches the end of its retention period it is deleted from live systems and removed from backups as those backups age out on their normal cycle. Where deletion is not technically possible, we anonymise the record so that it can no longer identify a person.
Your rights, and how to exercise them
Under Saudi Arabia's Personal Data Protection Law (PDPL) — and the GDPR if you are in the EU or UK — you may:
- ask to be informed of the legal basis and purpose for collecting your personal data;
- ask what personal data we hold about you and request access to it;
- request a copy of it in a readable format;
- ask for it to be corrected, completed or updated;
- ask for it to be destroyed where it is no longer needed;
- withdraw consent, where we relied on your consent.
To exercise any of these, write to privacy@tsleemksa.com from your work address, or contact your organisation's Tsleem administrator. We action verified requests within 30 days.
Accounts cannot be created inside the application, and for the same reason they cannot be deleted inside it — your account belongs to your employer. See the account deletion page for the full procedure. Note that completed inspection records may be retained by your employer as a business record even after your personal account is removed, where they are required to keep them.
Where we act as processor for your employer, we will pass your request to them and support them in answering it.
Complaints
If you are unhappy with how we have handled your personal data, write to privacy@tsleemksa.com with the word "Complaint" in the subject line. We acknowledge every complaint within 3 working days and aim to resolve it within 30 days, telling you what we found and what we did.
If you are not satisfied with our response, you may escalate to the Saudi Data & AI Authority (SDAIA), which supervises the PDPL. Complaints about a purchase may also be raised with the Ministry of Commerce.
Children
Tsleem is a workplace tool intended for adults in employment. It is not directed at children and we do not knowingly collect data from anyone under 18.
Changes to this policy
If we change how we handle personal data we will update this page and revise the date above. Material changes will also be announced to the administrators of every active organisation.
A separate, more detailed policy covers the mobile app specifically, as required by the app stores: Tsleem mobile app privacy policy. Where the two differ on a point of detail about the app, that page governs.