Privacy Policy

Last updated: 4 August 2026

This policy is a first-pass draft covering the data Riyada Intelligence collects through its marketing site and platform today. Sections in [brackets] mark details that still need to be filled in with real company information.

1. Who we are

Riyada Intelligence (“Riyada Intelligence”, “we”, “us”) provides a workforce-readiness intelligence platform for learning, compliance and skills teams. This policy explains what personal data we collect through our website and product, why we collect it, who we share it with, and the rights you have over it.

For the purposes of applicable data protection law (including the EU/UK GDPR), the data controller is:

[Company legal name]
[Company registered address]
Company registration number: [Company registration number]
Privacy contact: [Privacy/Data Protection contact email]

2. What data we collect

We collect different data depending on how you interact with us:

  • Demo requests (“Book a demo” form): full name, work email address, company name, and any message you choose to add.
  • Launch promotion form (“25% off our official launch” pop-up): full name, company name, email address, and phone number (with country code).
  • Learner and admin accounts: name, work email, job title, department, role/permission level, password (stored as a salted hash, never in plain text), and platform activity such as course enrollments, progress, completions, assessment results, certifications, skills data and gamification data (XP, streaks, badges).
  • Automatically collected data: IP address, browser and device information, and basic usage/log data needed to operate and secure the platform (e.g. login timestamps, error logs).
  • Cookies: we use a strictly necessary session cookie to keep you signed in. We do not currently set non-essential analytics or marketing cookies. [If/when analytics, advertising, or other non-essential cookies are added, list each tool here (e.g. Google Analytics) and add a cookie consent banner for EU/UK visitors before they are set.]

3. How we use your data

  • To respond to demo requests and sales enquiries, and to follow up with relevant offers.
  • To create and administer learner and admin accounts, and to operate the platform's core features (catalog, enrollment, progress tracking, certifications, reporting).
  • To communicate with you about your account, service updates, and (where you've agreed to be contacted) product or promotional updates.
  • To maintain the security, integrity and performance of the platform, including detecting and preventing fraud or misuse.
  • To comply with our legal obligations, and to establish, exercise or defend legal claims.

5. Who we share data with

We do not sell personal data. We share it only in the following circumstances:

  • Connected learning providers:if your organisation connects a third-party provider (currently GO1; we'll update this list as we connect additional providers) and you enroll in or complete a course through it, we share the minimum data needed to do so — typically your name, work email, and enrollment/completion status — with that provider, so they can grant you access and report progress back to us. Each provider processes that data under its own privacy policy and terms; we encourage you to review them.
  • Service providers (sub-processors): companies that host our infrastructure, send transactional email, or otherwise support the operation of the platform, under contracts that require them to protect your data. [List sub-processors here, e.g. hosting provider, email delivery provider, once finalized.]
  • Legal and safety reasons: where required to comply with the law, a valid legal process, or to protect the rights, property or safety of Riyada Intelligence, our users, or others.
  • Business transfers: if Riyada Intelligence is involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction, subject to this policy.

6. International data transfers

We operate across the Middle East, Europe, Africa, Asia, North America and South America, and our infrastructure or service providers may be located outside your country, including outside the European Economic Area (EEA) or UK. Where we transfer personal data internationally, we use appropriate safeguards required by law, such as Standard Contractual Clauses. [Confirm hosting location(s) and, if data leaves the EEA/UK, the specific transfer mechanism relied on, once infrastructure/vendor decisions are finalized.]

7. Data retention

We retain personal data for as long as needed to provide the platform and for the purposes described in this policy — for example, account and learning-record data for the life of your organisation's account plus a period afterward to meet audit, compliance and legal requirements, and sales-enquiry data for a reasonable period if you don't become a customer. [Define specific retention periods per data category — e.g. account data, learning records, compliance/certification records, sales enquiries — once finalized, since compliance record-keeping needs in particular may require longer statutory minimums.] When data is no longer needed, we delete or anonymise it.

8. Your rights

If GDPR or a similar law applies to you, you have the right to: access the personal data we hold about you; correct inaccurate data; request deletion (“right to be forgotten”); restrict or object to certain processing; receive your data in a portable format; and withdraw consent at any time where we rely on consent. Where your account is administered by your employer or organisation, some requests (e.g. deletion) may need to go through your organisation's administrator.

To exercise any of these rights, contact us at [Privacy/Data Protection contact email]. We will respond within the timeframe required by applicable law. If you're not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.

9. Security

We use technical and organisational measures appropriate to the risk to protect personal data, including encryption of data in transit, access controls, and password hashing. No system is perfectly secure, and we cannot guarantee absolute security, but we work to protect your data and to respond quickly if an issue arises.

10. Children’s privacy

Riyada Intelligence is a workplace learning platform intended for use by working adults through their employer or organisation. It is not directed at, and we do not knowingly collect personal data from, children.

11. Changes to this policy

We may update this policy from time to time, for example as our product, providers, or legal obligations change. We'll update the “Last updated” date above when we do, and where changes are material, we'll take reasonable steps to notify account administrators.

12. Contact us

Questions about this policy or your data can be sent to [Privacy/Data Protection contact email] or by post to [Company registered address].