1. Introduction
This Privacy Policy describes how Laeq365 ("we", "us", "our") collects, uses, and shares information about you when you use our website, mobile applications, and related services (collectively, the "Service").
We are committed to handling personal data responsibly and transparently, in line with applicable data-protection laws including Saudi Arabia's PDPL and, where relevant, the EU GDPR.
2. Data We Collect
Depending on how you interact with the Service, we may collect the following categories of data:
- Account data — name, email, phone number, role, company, and billing details.
- Usage data — log data, device identifiers, browser type, IP address, and pages visited.
- Content you submit — checklists, tasks, reports, signatures, uploaded files, and inspection records.
- Communication data — messages you send through support channels or in-app forms.
3. How We Use Your Data
We use your data only for the following purposes:
- Providing, maintaining, and improving the Service.
- Authenticating accounts and protecting against fraud or abuse.
- Processing payments and issuing invoices.
- Sending essential service notifications and, when permitted, product updates.
6. Third-Party Service Providers (Subprocessors)
To run Laeq365 reliably we rely on a small number of carefully vetted third-party providers. These providers act as data processors on our behalf, are contractually bound by data-protection obligations, and may only use your data for the specific purpose listed below.
All data exchanged with these providers is transmitted over encrypted (TLS) channels, and sensitive fields (such as phone numbers) are stored in encrypted form. Payment card details never reach our servers — they are submitted directly to our PCI-DSS compliant payment provider.
- Google Cloud Storage — secure cloud storage for uploaded files such as inspection PDFs, signature images and report attachments.
Provider region: Global (Google LLC). Encryption: at-rest and in-transit by default. - Tap Payments — processing of subscription and one-time payments. Card data is tokenized and handled directly by Tap; we receive only a transaction reference.
Provider region: Saudi Arabia / MENA (Tap Payments). PCI-DSS Level 1 certified. - Google OAuth (Sign-in with Google) — optional sign-in via your Google account. We receive only your name, email and Google profile ID — never your Google password.
Provider region: Global (Google LLC). Authentication is performed end-to-end over HTTPS. - Google Workspace (Gmail SMTP) — delivery of transactional emails such as welcome messages, invoices and account notifications.
Provider region: Global (Google LLC). All messages are sent over authenticated TLS.
We review this list periodically and will update it before adding any new subprocessor that handles personal data.
7. Data Security
We apply industry-standard technical and organizational measures to protect your data. This includes TLS encryption for all data in transit, AES-based encryption for sensitive fields at rest (such as phone numbers and credentials), hashed and salted passwords, role-based access control, single-session enforcement, and regular security audits. While we follow these best practices, no method of transmission or storage is 100% secure.
8. Your Rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of your data, subject to our legal retention obligations.
- Withdraw consent or object to certain processing activities.
9. Data Retention
We retain personal data only as long as needed to provide the Service or to meet legal, accounting, or reporting requirements. Once you delete your account, your data is fully removed within 60 days unless you restore the account during that period.
10. Children's Privacy
Laeq365 is not directed to children under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us so we can remove it.
11. International Data Transfers
Your data may be processed and stored on servers located outside your country of residence. When this happens, we take appropriate safeguards to ensure your data continues to receive a level of protection consistent with this policy and applicable law.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and notify you in-app or by email where appropriate.
13. Contact Us
For any privacy-related questions or to exercise your rights, please contact us at info@laeq365.com

