Privacy

Privacy Policy

Last updated:

This policy explains what personal data the ARETION booking platform (platform.aretion.org), its WhatsApp assistant and its emails collect, why, who receives it and what rights you have. It replaces the Privacy Notice of February 2026 for this platform.

1. Who we are

The platform is operated by ARETION Consulting, the trading name of Arkan Alray Company LLC, registered in the Kingdom of Saudi Arabia. We are the data controller for the personal data described here, under the Personal Data Protection Law (Royal Decree No. M/19, 1443H, as amended) and its Executive Regulations (the "PDPL").

  • Registered office: Innovation Boulevard, Al Aqeeq, King Abdullah Financial District (KAFD), Building 7229, Riyadh 13519, Saudi Arabia
  • Commercial registration: 7050596217
  • SDAIA registration: 3260006675
  • Data Protection Officer: dpo@aretion.org

Where you use the platform from another GCC country, that country's data protection law may also apply to you.

2. The personal data we collect

We collect only what the platform needs to work:

  • Account: your name, email address and password (stored only as a one-way hash), and, if you give them, your WhatsApp number, time zone and a referral code.
  • Bookings and payments: the advisor, format, date, time, length and price of each booking, any coupon or credit used, and the payment status and reference numbers returned by our payment provider. We never receive or store your card number.
  • What you share for your consultation: messages you send your advisor, documents you upload for a document review (up to 10 MB each) and anything you say in a session.
  • Care plans: for psychology consultations, your advisor may keep a care plan (goals, focus, interventions and a safety plan).
  • Ratings and feedback you give about a session.
  • Session attendance: the name and email shown in the Zoom meeting and the times participants joined and left.
  • Invoices: the buyer's name, email and phone, and the amounts.
  • Enquiries and support: what you send through the corporate enquiry form, appointment requests, support tickets, messages to our team and blog comments.
  • Our WhatsApp assistant: the messages you send to it and its replies.
  • Advisors: profile, qualifications, availability, photo and the bank details needed to pay them.
  • Technical data: your IP address, used only to limit repeated requests for verification codes; a random identifier that counts how many people are viewing an advisor's profile, deleted within 90 seconds; and visit statistics from our own cookie-free analytics, which do not identify you.

3. Health information

Some of what you share with your advisor — in messages, documents, sessions or a care plan — may be health information, which the PDPL treats as sensitive personal data. We process it only to provide the consultation you booked, with the consent you give when you book. You can withdraw that consent at any time by writing to dpo@aretion.org; we will then stop processing it, except where the law requires us to keep it.

Your advisor can see what you share with them. ARETION staff cannot read your chat with your advisor through the platform. Authorised ARETION staff can see a summary of a care plan where this is needed to support you or to keep you safe. Care plans and the written comments in ratings are encrypted when stored.

4. Why we use your data, and our legal basis

  • To create your account, take your bookings, run your sessions and deliver document reviews — to perform our agreement with you.
  • To take payment, issue invoices and keep tax records — to meet our legal obligations, including VAT law.
  • To send booking confirmations, reminders, meeting links and invoices by email and WhatsApp — to perform our agreement with you.
  • To process health information you share — with your explicit consent.
  • To keep the platform secure and prevent misuse — our legitimate interest.
  • To understand how the site is used, from aggregate statistics only — our legitimate interest.
  • To send you marketing — only with your consent, which you can withdraw at any time.

5. Who receives your data

We do not sell personal data. We share it only with:

  • Your advisor: your name, email, booking details and what you share for the consultation.
  • HyperPay: payment processing. You enter your card details directly with HyperPay; we receive only the result.
  • Zoom Video Communications: online sessions. The meeting title contains your name and your advisor's. Sessions are not recorded, and each meeting is deleted after the session.
  • Resend and our email host (Titan): booking emails and calendar invitations.
  • Pabbly: WhatsApp notifications such as reminders, meeting links and invoice links.
  • Groq: the AI model that drafts answers in our WhatsApp assistant receives the text of your question.
  • Emergent: storage of documents you upload and of images on our blog.
  • netcup: the servers that host the platform and its database, in Nuremberg, Germany.
  • Google Fonts: your browser loads the site's fonts from Google, which sees your IP address.
  • Public authorities, where the law requires it.

Each provider receives only what its service needs.

6. Transfers outside Saudi Arabia

The platform's database is hosted in Germany, and some of the providers above process data in other countries, including the United States. We transfer personal data outside the Kingdom only in line with the PDPL and SDAIA's Regulation on Personal Data Transfer Outside the Kingdom, and only where at least one of these applies:

  • the destination provides an adequate level of protection, as recognised by SDAIA;
  • appropriate safeguards are in place, such as SDAIA's standard contractual clauses;
  • the transfer is necessary to perform our agreement with you; or
  • you have consented to it.

7. Cookies and browser storage

We do not use advertising or tracking cookies, and our analytics set no cookies. The platform stores only what it needs to work:

  • access_token and refresh_token cookies keep you signed in (24 hours and 30 days). They are secure and cannot be read by scripts.
  • Your browser's local storage keeps your sign-in token and role, your language choice (aretion_lang) and the random identifier used to count live viewers of an advisor profile (aretion_viewer_sid).
  • When ARETION staff help you by signing in to your account, additional session cookies mark that session.

Clearing your browser's cookies and site data signs you out and resets these settings.

8. How long we keep it

  • Your account data: while your account is open, and until you ask us to delete it.
  • Booking, payment and invoice records: for as long as Saudi tax and accounting law requires, even after your account is closed.
  • Zoom meetings: deleted after each session. Sessions are not recorded.
  • Verification codes: expire after 10 minutes.
  • Live-viewer identifiers: deleted within 90 seconds.
  • Database backups: kept for 14 days, then overwritten.
  • Documents you upload: for as long as needed for the review and our records, unless you ask us to delete them.

9. Your rights

Subject to the conditions in the PDPL and its Executive Regulations, you have the right to:

  • be informed about how your data is used (this policy);
  • access your personal data and receive a copy of it;
  • have inaccurate or incomplete data corrected;
  • have your data deleted when it is no longer needed;
  • withdraw your consent at any time; and
  • complain to the Saudi Data and AI Authority (SDAIA).

To use any of these rights, or to close your account, write to dpo@aretion.org from the email address on your account. We reply within the period the PDPL sets. Account deletion is handled by our team; it is not yet available as a button in the platform.

10. How we protect your data

  • Passwords are stored only as bcrypt hashes.
  • Care plans and rating comments are encrypted when stored.
  • All traffic is encrypted (HTTPS, with HSTS).
  • Sign-in is locked after repeated failed attempts, and two-factor authentication is available.
  • Access is limited by role, and our team's administrative actions are logged.

If a personal data breach occurs, we will notify SDAIA within 72 hours of becoming aware of it and inform affected people where the law requires.

11. Children

Accounts are for adults. Where a consultation concerns a child, a parent or legal guardian makes the booking, provides the child's information and is responsible for it.

12. Changes and contact

We will update this policy when the platform changes and show the date of the latest version at the top of this page.

Questions or requests: dpo@aretion.org. If you are not satisfied with our answer, you can complain to SDAIA (sdaia.gov.sa).

ARETION
Aretion