Legal · Pro Max Gulf
Privacy Policy
Last updated:
This Privacy Policy explains how Pro Max Gulf Company ("Pro Max Gulf", "we", "us") handles personal data across its website and its software platforms, including ZIJ and its social publishing feature. It sets out what we process, on whose behalf, why, how long we keep it, and how you can exercise your rights under the Saudi Personal Data Protection Law ("PDPL").
The entity responsible for this policy
- Legal name
- Pro Max Gulf Company
- Legal name (Arabic)
- شركة برو ماكس جلف
- Entity type
- Limited Liability Company
- Commercial Registration (CR)
- 7050606222
- VAT registration number
- 313103592700003
- Country
- Kingdom of Saudi Arabia
- info@promaxgulf.com
- Website
- https://tech.promaxgulf.com
1. What this policy covers
This policy applies to the Pro Max Gulf website at tech.promaxgulf.com, to ZIJ and its social publishing feature, and to the enquiries and support requests we receive. Where a specific product is governed by its own policy — for example the Managed ZATCA Compliance Platform — that product's policy applies to it, and this one applies to everything else.
Where Pro Max Gulf and a customer have signed a separate agreement covering data processing, that agreement governs the relationship and this policy explains it; it does not override the agreement.
2. Our role: when we are a Controller and when we are a Processor
Pro Max Gulf does not have a single role for all data. The role follows the processing activity, because the platform is multi-tenant: each customer organisation is a separate tenant with its own users, its own configuration, its own connected accounts and its own records.
We act as a Processor — processing on the customer's documented instructions, within that customer's tenant — for:
- the accounts and profiles of the customer's own users of the platform, including their names, sign-in identities, roles and permissions;
- business data the customer connects to the platform, including data drawn from the customer's ERP and other connected systems, knowledge base content, and the questions and answers exchanged inside the customer's workspace;
- the customer's connected social accounts — the authorisation held for the customer's own pages and accounts, and the metadata describing them;
- content the customer's users submit for publishing, including post text, images and scheduling; and
- the audit and governance records generated by activity inside the customer's workspace.
We act as a Controller — determining the purposes and means ourselves — for:
- our own business records: sales enquiries, the website contact form, quotations, contracts, invoices and correspondence with customers and prospects;
- support requests made to us directly, and the contact details of the individuals who make them;
- platform-level security, availability and abuse-prevention logging that we keep to operate the service safely and to meet our own legal obligations; and
- Pro Max Gulf's own social media accounts and any publishing we carry out for ourselves, where the company — not a customer — decides what is published.
A single record can sit under both roles at different moments. An audit entry recording that a customer's approver released a post is processed for the customer as Processor; the same infrastructure logging that keeps the service secure and available is ours as Controller. Where we are a Processor, requests from individuals are directed to the customer, and we support the customer in answering them.
3. Personal data we process
Depending on how you interact with us, the following categories may be processed:
- Identity and contact data — name, business email address, telephone number, employer and job role.
- Account and authorisation data — sign-in identity, workspace membership, assigned roles and per-user permissions, and the record of who granted them.
- Connected social account data — see section 4.
- Content data — text, images and attachments submitted to the platform, including content submitted for publishing and the approval decisions taken on it.
- Usage and technical data — pages visited, actions performed, device and browser information, IP address, timestamps, and error and performance telemetry.
- Audit and governance data — a record of who did what and when: creation, submission, approval, rejection, scheduling, publication and failure events, with the acting user, the time, the decision and a hash of the content decided upon.
- Commercial data — enquiries, contract and billing records, and correspondence.
We do not seek to collect sensitive personal data through the platform, and we ask that it is not submitted through the website contact form.
4. Connected social accounts and publishing
The social publishing feature lets an organisation connect its own company pages and accounts on LinkedIn, Facebook, Instagram and X, and publish to them through a governed workflow. This section describes that feature specifically, because it is the part of the platform that touches third-party platform data.
Connecting an account. A connection is made by an administrator of the organisation completing that platform's own consent screen while signed in to the platform. Pro Max Gulf never asks for, receives or stores a user's password for any social platform. Authorisation is granted by the platform itself and can be withdrawn at any time — see our Data Deletion page.
What the platform requests. We request the narrowest set of permissions the publishing workflow needs on each platform:
- LinkedIn — openid, profile, email, w_organization_social, r_organization_social, rw_organization_admin.
- Meta (Facebook and Instagram, through one connection) — pages_show_list, pages_read_engagement, pages_manage_posts, business_management, instagram_basic, instagram_content_publish.
- X — tweet.read, tweet.write, users.read, offline.access, media.write.
What we store. For each connection we hold an access token, a refresh token where the platform issues one, the token's expiry, and the set of permissions actually granted. These credentials are held in an encrypted secret store, encrypted at rest, keyed to that connection and segregated by tenant. They are never displayed again after they are stored, and they are never written into configuration files, source code, support tickets or messages. Alongside them we store non-credential metadata describing the destination: the platform, the page or account identifier and display name, the destination type, the connection's status and health, and the identity of the administrator who authorised it.
What we do with it. The authorisation is used only to discover the pages and accounts you are entitled to publish to, to confirm the connection is still valid, and to publish the content your organisation approves. We do not use it to read private messages, to harvest audience or follower lists for our own purposes, to publish anything your workflow has not approved, or to build advertising or profiling products. Content you publish is sent to the platform you selected, and from that point it is governed by that platform's own terms and privacy policy.
Governance records. Because publishing under a company identity is a controlled act, the platform records who drafted a post, who submitted it, who approved or rejected it, when, and a hash of the exact content approved, together with the reference the platform returned for the published post. These records exist so an organisation can demonstrate that a post under its name was authorised. They are retained as described in section 8.
5. Purposes and legal bases
Under the PDPL we process personal data on the following bases:
- Performance of a contract or in preparation for one — to provide the platform, administer accounts, deliver support, and manage the commercial relationship.
- Compliance with a legal obligation — to meet tax, accounting, commercial-registration and other statutory requirements in the Kingdom.
- Legitimate interests, where these are not overridden by the rights of the individual and no sensitive data is involved — to keep the service secure and available, to prevent abuse, to maintain audit and governance records, and to improve reliability.
- Consent — where consent is the appropriate basis, such as marketing communications you opt in to, and the authorisation you grant on a social platform's own consent screen. Consent can be withdrawn at any time, without affecting processing already carried out.
Where we act as a Processor, the legal basis for processing the customer's data is determined by that customer as Controller, and we process on their instructions.
6. Sharing and third parties
We share personal data only as follows:
- Social platforms — where your organisation publishes to a connected account, the content and the authorisation are sent to LinkedIn, Meta (Facebook and Instagram) or X, as applicable. Each operates as an independent controller of what it receives.
- Infrastructure and hosting providers — who host the platform and its data on our instructions.
- AI model providers — the platform can be configured to use a hosted model provider or a self-hosted model gateway. Which is used is a deployment and customer configuration choice. Where a hosted provider is configured, content submitted to the assistant is sent to that provider for processing; where a self-hosted gateway is configured, it is not.
- Professional advisers and authorities — where we are required to disclose by law or to establish or defend legal claims.
We do not sell personal data, and we do not share it for third-party advertising.
7. Processing outside the Kingdom
Some of the third parties described above operate outside the Kingdom of Saudi Arabia. The social platforms are located outside the Kingdom, so content published to a connected account is necessarily transferred to them. Where a hosted AI model provider is configured, processing may also take place outside the Kingdom; where a self-hosted model gateway is configured instead, that processing remains within the deployment.
Where personal data is transferred outside the Kingdom we do so in accordance with the PDPL and its implementing regulations, limiting the transfer to what the purpose requires. Customers who need processing to remain within a defined boundary should raise this with us before configuration, as the platform supports self-hosted model deployment.
8. Retention
We keep personal data only as long as it is needed for the purpose it was collected for, or as long as the law requires. Several retention horizons in the platform are configurable per deployment rather than fixed by us, and we state them as such rather than quoting a figure that may not apply to your installation:
- Social authorisation credentials — held for the life of the connection. When a connection is revoked they are destroyed as part of the revocation; see our Data Deletion page.
- Connected destination metadata — held for the life of the connection; on revocation a bounded, non-credential record of the revocation is kept, capped in number and holding no tokens.
- Audit and governance records — retained to the horizon configured for the deployment. Where no horizon is configured, the sweep that trims them does not run and records are kept.
- Approval records — an approval is single-use and expires if not acted on, by default after 72 hours, after which the post returns to draft.
- Workflow and scheduled-job history — 30 days by default.
- Dashboard caches — 14 days by default.
- Generated artefacts, such as exported reports — retained by default until deleted, unless a retention period is configured.
- Commercial records — retained for the period required by Saudi tax and commercial law.
Content that has already been published to a social platform is held by that platform under its own retention rules. Deleting a record in our platform does not remove a post from LinkedIn, Facebook, Instagram or X — that must be done on the platform itself.
9. Security
Authorisation credentials for connected social accounts are encrypted at rest in a dedicated secret store, segregated by tenant, and are not retrievable for display once stored. Access to the platform is governed by per-user roles and permissions, and the permissions that allow publishing and approving are opt-in rather than granted by default.
The publishing workflow enforces a separation of duties: the person who submits a post cannot approve their own post. Publication runs through a single governed path that consumes a single-use approval bound to a hash of the approved content, so approved content cannot be altered before it goes out.
No system can be guaranteed absolutely secure. If a personal data breach occurs we will assess it and notify the competent authority, and affected individuals or customers, as the PDPL and its implementing regulations require.
10. Your rights
Subject to the conditions and exceptions in the PDPL, you have the right to be informed about how your personal data is processed, to access it, to obtain a copy of it in a readable format, to request that it be corrected, completed or updated, and to request that it be destroyed where it is no longer needed for the purpose it was collected for. Where processing rests on consent, you may withdraw that consent.
To exercise a right, write to us at the address in the contact block below. We may need to verify your identity before acting, and we will respond to a verified request without undue delay and in any event within 30 days.
If your data is held inside a customer's workspace, Pro Max Gulf is acting as a Processor for that customer. In that case please direct your request to that organisation; if you contact us, we will refer you to them and support them in responding.
If you believe your rights under the PDPL have not been respected, you may lodge a complaint with the competent supervisory authority in the Kingdom of Saudi Arabia.
11. Children
The platform is a business product intended for use by organisations and their employees. It is not directed at children, and we do not knowingly collect personal data from them.
12. Changes to this policy
We may update this policy as the product and the applicable regulations develop. The date at the top records the most recent change. Where a change materially affects how personal data is handled, we will take reasonable steps to make it known.
13. Language
This policy is published in English and Arabic. If there is any inconsistency between the two versions, the English version governs.