Privacy Policy
Last updated: May 2026
We take your privacy seriously. This policy explains what we collect, why, how we protect it, and what you can do to control your data. It applies to all users of the Ashkoo platform.
§ 1Data we collect
Data you provide directly at sign-up (name, email, hashed password, optional phone, account type: personal or business), the content of cases and comments you submit, and their attachments. We also collect limited operational data (IP address, browser type, timestamps, pages visited) for platform security and performance improvement.
§ 2Why we collect
Exclusive purposes: (a) operating the service (relaying your case to the company, sending notifications); (b) content moderation and compliance with these terms; (c) security (fraud and abuse prevention); (d) anonymized service improvement. No marketing use without separate, explicit consent.
§ 3Legal basis
(a) Your explicit consent at sign-up; (b) contract (provision of the requested service); (c) legitimate interest (security, anti-fraud); (d) legal obligations when competent authorities request through proper process.
§ 4Data sharing
We do not sell your data. We share with: (a) the company named in a case — your displayed name, email (for in-case communication), phone if you chose to share it; (b) infrastructure providers (see section 9 for full list) under strict data-protection agreements; (c) competent judicial authorities upon valid request.
§ 5Location and security
Data is stored in data centers with AES-256 encryption at rest and TLS 1.3 in transit. Strict access controls: a limited number of staff can access data, only for operational necessity with full audit log.
§ 6Retention
Account data: kept while the account is active. Case data: retained 5 years after closure for dispute resolution and historical record. Login logs and IPs: 90 days then deleted. You may request deletion at any time (section 11).
§ 7Cookies
We use only cookies necessary for site operation and login sessions. No ad-tracking cookies or third-party analytics at this stage. You can manage cookies through your browser settings.
§ 8Automated processing and AI
We may use automated systems and AI tools to process user content before publishing: masking sensitive personal data (names, numbers, addresses), readability improvement, translation between supported languages, offensive-language mitigation, and preliminary moderation. These systems do not alter the essential meaning of content and do not constitute a final decision — a human reviews the output before any action that has a significant effect on your account or content.
§ 9Sub-processors
To operate the platform we work with the following sub-processors under Data Processing Agreements: Supabase (database and auth, EU/US); Vercel (hosting, US); Cloudflare (CDN and security, global); Resend (email sending, EU/US). All are certified to ISO 27001 and SOC 2. The list may be updated; material changes are communicated in advance.
§ 10Children
Platform for adults (18+) only. We do not knowingly collect minors’ data. Minor accounts discovered are deleted. Parents who suspect underage signup may contact us.
§ 11Your rights
Rights: (a) access to stored data; (b) rectification; (c) erasure; (d) portability (JSON); (e) withdraw consent; (f) lodge a complaint with the authority in your country. To exercise: email info@ashkoo.com with subject "Privacy".
§ 12Breach notification
In the event of a breach affecting your data, we will notify you within 72 hours of discovery, and notify the competent authority (Saudi Data & AI Authority, UAE Data Office, CNDP Morocco, and equivalent regulators) within the timeframes set by local law.
§ 13International transfers
Some providers (see section 9) may be outside your country. We apply contractual and technical safeguards equivalent to EU Standard Contractual Clauses to protect your data during any international transfer. All sensitive data (case content, attachments) is encrypted in transit.
§ 14No solely-automated decisions with legal effect
No decisions with legal or similarly significant effect on you are taken solely based on automated processing. Decisions about public posting, content removal, or account suspension involve human review. You retain the right to request human intervention and contest any decision regarding your data.
§ 15Updates
This policy may be updated to reflect technical or legal changes. Material changes are notified by email 30 days before they take effect.
§ 16Contact
All privacy-related inquiries to: info@ashkoo.com (subject "Privacy"). Response within 5 business days, legitimate requests fulfilled within 30 days.