Legal · Managed ZATCA Compliance Platform
Privacy Policy
Last updated:
This Privacy Policy explains how Pro Max Gulf ("Pro Max Gulf", "we", "us") handles data in connection with the Managed ZATCA Compliance Platform for Microsoft Dynamics 365 Business Central (the "Platform"). It covers the data the Platform processes on behalf of our customers, the data we collect directly, how long it is kept, and how you can exercise your rights.
1. Who this policy applies to
This policy applies to organisations that license the Platform ("Customers"), to the individual users those Customers authorise to use it, and to anyone who contacts us about the Platform.
For invoice and transaction data held inside a Customer's Business Central environment, the Customer is the data controller and Pro Max Gulf acts as a data processor, following the Customer's documented instructions and the terms of the applicable service agreement. For data we collect directly — such as sales enquiries, support tickets, and billing records — Pro Max Gulf is the controller.
2. Data the Platform processes
The Platform operates inside the Customer's Business Central environment and exchanges data with ZATCA's Fatoora platform in order to generate, clear, and report e-invoices. In doing so it processes:
- Invoice and credit/debit note data — invoice numbers, dates, line items, quantities, prices, tax amounts, and totals.
- Seller and buyer identifiers — legal name, VAT registration number, commercial registration number, address, and (where the transaction requires it) buyer contact details.
- Cryptographic and compliance artefacts — CSRs, cryptographic stamp identifiers (CSIDs), certificates, private key references, invoice hashes, UUIDs, QR codes, and the signed XML of each document.
- ZATCA exchange records — request and response payloads, clearance and reporting status, warnings, validation errors, and timestamps returned by the Fatoora APIs.
- Operational telemetry — job queue status, retry attempts, error logs, environment and version identifiers, and performance metrics used for monitoring and support.
- User account data — the Business Central user identity that performed an action, used for audit trails and troubleshooting.
3. Data we collect directly
Separately from the Platform, we collect information you give us: your name, work email, phone number, company name, and the content of your message when you use our contact form or write to us; and the records we need to administer licences, subscriptions, invoicing, and support.
Our website collects only what is needed to serve the page. We do not use advertising or cross-site tracking cookies on this site.
4. Why we process this data
- To deliver the Platform — generating, signing, clearing, and reporting e-invoices to ZATCA as required by the KSA E-Invoicing Regulation and its implementing resolutions.
- To manage the certificate lifecycle — onboarding, renewal, and revocation of compliance and production CSIDs.
- To monitor reliability — detecting failed submissions, retrying automatically, and alerting our team and yours before a compliance gap opens.
- To provide support — investigating tickets, reproducing issues, and applying fixes.
- To maintain compliance — keeping the audit records that KSA tax law requires of the taxpayer and that our own regulatory obligations require of us.
- To run our business — licensing, billing, service communications, and improving the Platform.
5. Legal basis
We process data on the basis of the contract between Pro Max Gulf and the Customer, our and the Customer's compliance with Saudi tax and e-invoicing law, and our legitimate interest in operating, securing, and improving the Platform. Where consent is required — for example for marketing communications — we ask for it and you may withdraw it at any time.
6. Where data is stored
Invoice data generated by the Platform is stored in the Customer's own Business Central environment — Microsoft's cloud tenancy for online deployments, or the Customer's own infrastructure for on-premises deployments. Pro Max Gulf does not maintain a separate copy of a Customer's invoice ledger.
Records required for e-invoicing are stored and retained inside the Kingdom of Saudi Arabia in line with ZATCA's requirements. Where an on-premises deployment is used, ensuring the hosting location meets those requirements is the Customer's responsibility, and we will advise on the configuration needed.
Support and monitoring data — logs, diagnostics, and tickets you send us — is held on our systems and access is restricted to the personnel who need it.
7. Sharing and sub-processors
We share data only where it is necessary to deliver the Platform:
- ZATCA — invoice documents and compliance artefacts are transmitted to the Fatoora platform because the law requires it.
- Microsoft — where the Customer runs Business Central online, the data resides in the Customer's Microsoft tenancy under Microsoft's terms.
- Service providers — vetted providers for hosting, monitoring, and communications, bound by confidentiality and processing terms consistent with this policy.
- Authorities — where we are legally required to disclose information to a competent Saudi authority.
We do not sell personal data, and we do not share it for third-party advertising.
8. Retention
E-invoices and their supporting compliance artefacts must be retained under KSA VAT and e-invoicing rules — currently a minimum of six years from the end of the tax period concerned, and longer for certain assets. Those records live in the Customer's environment and are retained by the Customer accordingly.
Operational logs and monitoring data are retained for up to 24 months, which is long enough to investigate incidents and support a tax audit trail. Support tickets and business correspondence are kept for the life of the commercial relationship plus the period required by law. Sales enquiries that do not lead to a contract are deleted within 24 months.
9. Security
The Platform signs every document with the Customer's cryptographic stamp and transmits it over encrypted channels. Private key material is held in the Customer's environment and is never transmitted to Pro Max Gulf in plaintext. Access to Customer environments by our support personnel is granted only when authorised, is limited to what the task requires, and is logged.
We apply role-based access control, least-privilege administration, encrypted transport, patching and vulnerability management, and periodic review of our controls. No system can be guaranteed absolutely secure, but if a breach affects your data we will notify you and the relevant authorities without undue delay.
10. Your rights
Under the Saudi Personal Data Protection Law you may request access to the personal data we hold about you, ask for it to be corrected or deleted, object to or restrict certain processing, request a copy in a portable format, and withdraw consent where processing relies on it.
If your data sits inside a Customer's Business Central environment, direct your request to that Customer — we will support them in responding. For data we hold as controller, contact us using the details below and we will respond within the period required by law. You also have the right to complain to the Saudi Data & AI Authority (SDAIA).
11. Changes to this policy
We may update this policy as the Platform or the regulatory requirements change. The revision date at the top of this page always reflects the current version, and we will notify Customers directly of any change that materially affects how their data is processed.
12. Contact
For privacy questions, data requests, or to reach our data protection contact: