Skip to content

Privacy Policy

Effective date: 7 October 2026 · Version 1.1

This policy explains what personal data Ranen collects through ranen.ai, why we collect it, who we share it with, how long we keep it and the rights you have over it. It is written to meet the requirements of the Kingdom of Saudi Arabia’s Personal Data Protection Law (PDPL) issued by Royal Decree No. (M/19) dated 9/2/1443H, as amended, and its Implementing Regulations.

In short
  • We only collect what you send us in the demo form, plus minimal technical data needed to keep the site secure.
  • We use it to answer your request and arrange your demo. We do not sell it or use it for advertising.
  • The voice demo on our homepage uses your microphone only when you press it. Your browser converts your speech to text; we do not record or store your audio or what you say.
  • You can access, correct, obtain a copy of or delete your data, or withdraw consent, at any time by emailing [email protected].

1. Who is responsible for your data

ranen.ai is operated by Insejam Technology Contracting Company (انسجام التقنية للمقاولات), a limited liability company registered in the Kingdom of Saudi Arabia under Commercial Registration No. 1010611445, headquartered in Riyadh (“Ranen”, “we”, “us”), the controller of the personal data collected through it. Questions about this policy or about your data can be sent to our privacy contact at [email protected].

2. Scope of this policy

This policy covers visitors to ranen.ai and people who request a demo or contact us through it.

It does not cover calls handled by the Ranen platform on behalf of our business clients. For those calls, the client is the controller and Ranen processes the data as a processor under a written agreement with that client, as described in the dedicated section below. Callers should refer to the privacy policy of the organisation they called.

3. Data we collect

Data you give us when you request a demo:

  • Name and company name
  • Work email address
  • Mobile number and preferred contact method (call, WhatsApp or email)
  • Approximate monthly call volume, the topics you want to explore and your message (optional)
  • The savings estimate from our calculator, if you used it before submitting
  • The language of the page and a record of your consent with its date and time

Data collected automatically:

  • Your IP address, converted to a one-way hash and held for one hour only to block repeated or automated submissions
  • Standard server logs kept by our hosting provider (IP address, browser type, pages requested and time) for security and troubleshooting

The interactive voice demo accesses your microphone only after you press the microphone button and your browser asks for and receives your permission. While you speak, your browser converts your speech to text using its own built-in speech recognition service, which may be provided by the browser maker (for example Google in Chrome or Apple in Safari) under its own privacy terms. The resulting text is matched to a sample reply inside your browser. Ranen does not record, receive or store your audio or the text of what you say. You can also type a request or pick a sample sentence instead of using the microphone.

We do not ask for sensitive personal data (such as health, religious or financial account data). Please do not include it in your message.

4. Why we use your data and on what basis

  • To respond to your demo request, arrange the demo and follow up on it: based on the consent you give in the form and on taking steps at your request before a possible contract.
  • To send you information about Ranen services related to your request: based on your consent, which you can withdraw at any time.
  • To protect the site against abuse, spam and attacks: based on our legitimate interest in keeping the service secure.
  • To comply with legal obligations and requests from competent authorities: where the law requires it.

We do not sell your data, use it for third-party advertising or make decisions about you based solely on automated processing.

5. Who we share it with

We share personal data only with service providers that process it on our behalf and under our instructions, and only as far as needed for the purposes above:

  • Website hosting and infrastructure provider
  • Email delivery provider used to send and receive messages about your request
  • Customer relationship management (CRM) provider used by our sales team

Each provider is bound by a written agreement that requires confidentiality and appropriate security. We may also disclose data to competent authorities when the law requires it. We never rent or sell personal data.

6. Transfers outside the Kingdom

Some of our service providers may store or process data outside the Kingdom of Saudi Arabia. Any such transfer is made only in accordance with the PDPL and the Regulation on Personal Data Transfer outside the Kingdom, including adequate safeguards such as standard contractual clauses where required, and is limited to the minimum data necessary.

7. How long we keep it

  • Demo request data: up to 24 months from our last contact with you, after which it is deleted or anonymised, unless you become a client (then the client agreement applies) or the law requires a longer period.
  • Hashed IP address used for abuse prevention: one hour.
  • Server logs: for the short period our hosting provider needs for security and troubleshooting.

8. How we protect it

We apply administrative, technical and physical measures appropriate to the nature of the data, including encryption in transit (HTTPS/TLS), restricted and logged administrative access, and careful selection of service providers.

If a personal data breach occurs that is likely to harm you, we will notify the Saudi Data and AI Authority (SDAIA) within 72 hours of becoming aware of it and inform you without undue delay where required.

9. Your rights

Under the PDPL you have the right to:

  • Be informed about how your personal data is collected and used (this policy)
  • Access your personal data held by us
  • Obtain a copy of your data in a clear, readable format
  • Request correction, completion or updating of your data
  • Request destruction of your data when it is no longer needed
  • Withdraw your consent at any time, without affecting processing carried out before withdrawal

To exercise any of these rights, email [email protected] from the address you used with us, or tell us how to verify your identity. We respond within 30 days, free of charge. If we need more time as permitted by law, we will tell you why.

10. Complaints

If you are not satisfied with how we handled your data, please contact us first so we can resolve it. You also have the right to lodge a complaint with the competent authority, the Saudi Data and AI Authority (SDAIA), through sdaia.gov.sa.

11. Cookies and similar technologies

ranen.ai does not use advertising or cross-site tracking cookies, and fonts and assets are served from our own server. Only cookies that are strictly necessary for the site to function and remain secure may be set (for example for signed-in administrators). If we introduce analytics, we will update this policy first and ask for your consent where required.

12. Children

Our website and services are intended for businesses and are not directed at anyone under 18. We do not knowingly collect data from children; if you believe a child has sent us data, contact us and we will delete it.

13. Changes to this policy

We may update this policy to reflect changes in the law or in our services. The effective date at the top shows when it was last revised, and material changes will be announced on this page.

14. Contact us

For any question or request about your personal data, email [email protected]. Please write “Privacy request” in the subject line so it reaches the right team quickly.

15. Data we process for our clients

When we provide the service to our business clients, we process caller data as a processor, under a data processing agreement with each client, with these commitments:

  • Calls, recordings and transcripts hosted in data centres inside the Kingdom of Saudi Arabia
  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Card and ID numbers automatically masked in transcripts and recordings
  • An audit log of every access and action, and fine-grained permissions per team
  • No use of client data to train models that serve other clients, and deletion on the client’s request or at the end of the subscription

The client informs callers, provides the lawful basis for processing and receives their rights requests; we help the client fulfil them.