Privacy Policy
Last updated: October 2026
Introduction
This policy explains the data we collect when you use the saudicon.app website and the SaudiCon app for Android and iOS, why we use it, who processes it on our behalf, how long we keep it, and how you can exercise your rights. The website and the app are operated by Knight Solutions Company, Commercial Registration No. 7051291826, Riyadh, Kingdom of Saudi Arabia, which is the party responsible for your data. The website and the app are independent and not affiliated with any government entity.
Data we collect
- Account data: the email address you sign in with, your name if you add it yourself, your language, and the device type and browser identifier (User-Agent) when the account is created.
- Sign-in code: a six-digit code we email to you at each sign-in, valid for ten minutes and deleted once used.
- Your choices in the service: the events you save, the events you ask to be reminded about, the sectors you turn alerts on for, your newsletter subscription, and the read state of your notifications.
- Push token: when you allow notifications on your device, we record its push token with the platform, the app language and the app version, for at most five devices per account.
- Consent register: when you accept the Terms and this policy, and when you turn any notification on or off, we record the consent type, the wording version, your decision and its time, with the IP address and browser identifier of the request, to document consent as the Personal Data Protection Law requires.
- Technical data: for each request our server records the IP address, the requested address including search words, the browser identifier, the country and the time, to protect the service and diagnose faults.
- Diagnostic data from the app, as described under “Crash reports and diagnostics”.
- On the website only: the pages you visit, through cookies and Google Analytics.
The only device permission the app requests is notifications: it does not request location permission and does not access your contacts, photos, files or advertising identifier. When you add an event to your device calendar, the app opens the operating system’s calendar form for you to confirm; it does not read your appointments or send anything from them to us.
How we use your data
- Running your account, signing you in, and syncing your saved events between the app and the website.
- Sending the reminders you ask for a month, a week and a day before an event, by email, in the in-app notifications and as device notifications, once you turn on “Reminder before the event”.
- Alerting you to new and upcoming events in the sectors you choose, in the app and as device notifications.
- Sending the weekly newsletter if you subscribe to it.
- Protecting the service from abuse, for example by limiting sign-in attempts, and diagnosing and fixing faults.
- Documenting your consent and its withdrawal, and proving an account deletion when needed.
Device notifications and emails for reminders and alerts stay off until you turn them on in Account, and you can turn them off at any time in the same place or in your device settings.
Crash reports and diagnostics
When an error occurs in the app, it sends our server a diagnostic signal carrying where the error happened, its type, the app version and a random install identifier created on your device, which is renewed when you sign out or reinstall and is not linked to your account. The Android version also sends crash reports to Firebase Crashlytics, a Google service; they include the error type, its place in the code, the app version, the device model, the operating-system version and an installation identifier created by the service. We remove the error message before sending, because it could contain personal data, and we send neither your account identifier nor your email. Google Analytics for Firebase is permanently disabled in the app.
Service providers that process your data
We rely on the following providers to run the service; each processes data on our behalf and within its role:
- Contabo GmbH: hosting of the server that runs the database, the website and the app’s API. We run search (Meilisearch) and the newsletter system (Listmonk) ourselves on the same server.
- Cloudflare, Inc.: content delivery and protection of the connection between your device and our server; the technical data of every request, including the IP address, passes through it.
- Resend, Inc.: sending email, including sign-in codes and reminder emails.
- Expo (650 Industries, Inc.): delivery of device notifications and app updates; push tokens and notification text pass through it, and the IP address and device type when the app checks for updates.
- Google LLC: notification delivery on Android (Firebase Cloud Messaging), crash reports (Firebase Crashlytics), and website visit measurement (Google Analytics).
- Apple Inc.: notification delivery on iOS.
- Backblaze, Inc.: storage of encrypted database backups.
When you open an event’s registration page, an organiser’s website or a maps app from the app, you move to a service governed by that party’s own privacy policy.
Sharing data with third parties
We do not sell or rent your personal data, and we do not share it with anyone for their own purposes. Only the service providers listed above have access to it, and event organisers receive no data about you.
Where data is stored, and transfers outside the Kingdom
Your data is stored on a server located in France, and the providers listed above also process it outside the Kingdom of Saudi Arabia. We tell you this at the point of collection, as the Personal Data Protection Law requires, and the safeguards in this policy apply wherever your data is processed.
How long we keep data
- Account data, saved events, reminders, sector alerts and preferences: for as long as your account exists; deleted when it is deleted.
- Sign-in code: ten minutes; deleted once used or one hour after it expires.
- App sign-in session: 180 days; erased from your device when you sign out and invalidated on every device when the account is deleted.
- Push tokens: revoked when you sign out of that device or delete the account; revoked tokens are deleted after 90 days.
- In-app notifications: read ones are deleted 12 months after being read.
- Notification send log: 24 months.
- Diagnostic data sent to our server: 13 months.
- Server technical logs: 14 days.
- Crash reports in Firebase Crashlytics: 90 days, per Google’s retention period.
- Consent register: while your account exists; on deletion your identity is removed, and the anonymised record is kept for five years as proof of consent, then deleted.
- Database backups: copies on our server kept for 14 days, and encrypted copies at Backblaze kept for at most six months; deleted data may remain in them until that period lapses.
Deleting your account
You can delete your account inside the app under Account, then “Delete account”. It is deleted immediately together with your saved events, reminders, sector alerts, notifications, push tokens and newsletter subscription, and your sessions stop on every device. If you no longer have the app, you can request deletion on the Delete account page. After deletion we keep the consent register without any personal identifier, a record proving the deletion that holds a keyed hash of the email from which the email cannot be recovered, diagnostic data that was never linked to your account, and, if you contacted us as an organiser, sponsor, media representative or speaker, that professional contact record until you ask us to delete it.
Cookies
The website uses cookies to remember your preferences and keep you signed in, and Google Analytics to measure visits. You can control cookies in your browser settings. The app uses neither cookies nor Google Analytics.
Data protection
We take appropriate security measures to protect your personal data from unauthorized access, alteration, disclosure or destruction: all traffic between your device and our server is encrypted, your session token is kept in your device’s secure store, and database access is limited to the people who operate the service.
Your rights
Under the Personal Data Protection Law you have the right to:
- Be informed of what we collect and why, which this policy explains.
- Access the personal data we hold about you and obtain a copy in a clear format.
- Request the correction, completion or deletion of your data.
- Withdraw your consent to any notification at any time under Account in the app, or through the unsubscribe link in the newsletter.
- Lodge a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA).
To exercise any of these rights, write to [email protected] from the email registered to your account. We reply within 30 days of receiving the request at most.
Changes to this policy
We may update this policy from time to time. When a change affects your rights, we show you the Terms and this policy again inside the app for your acceptance before you continue, and we announce the change on this page with an updated date.
Contact us
If you have any questions about this policy or your data, email us at [email protected] (write to us)