PRIVACY NOTICE / V0.1

Privacy notice

Pre-launch version — 2 September 2026

Required before public launch

SATR is a launch-stage working brand. Before public access, replace this notice with the controller’s full legal name, address, registration details, tax number where applicable and a formal privacy contact.

DATA CONTROLLER

[Operating legal entity — complete before public launch]

1. Data we collect

Talent applications may include identity and contact details, time zone, roles, languages, experience, work links, availability, desired rate and tool-use disclosures. Company inquiries may include contact and company details, website, plan, goals, current state and timeline. Fields marked (*) are necessary to process the request; unmarked fields are optional.

2. Purposes and legal bases

We process talent data to assess applications, communicate, run an assessment where needed, manage the talent network and take contracting steps. Company data is used to respond, diagnose needs, prepare a proposal and manage a relationship if it begins. Depending on the stage, processing relies on consent, pre-contract steps, contract performance, legal obligations and legitimate interests that do not override your rights.

3. Who receives data

Access is limited to authorized operations personnel. Hosting, communications, assessment, contracting, payment and analytics providers may assist where needed. Processors are bound by confidentiality, security, purpose limits and deletion or return duties. We do not sell personal data.

4. Processing outside Saudi Arabia

Some technology or contracting providers may operate outside Saudi Arabia. Before an applicable transfer, we assess the destination, purpose, minimum data, lawful safeguard and transfer risk under Saudi requirements. Foreign contractual clauses are not treated as an automatic substitute for Saudi requirements.

5. Retention

An unselected talent application is retained for no more than 6 months after the decision, then deleted or anonymized unless law requires otherwise. Company inquiries are kept for up to 12 months after the last interaction. If a contract begins, necessary records are kept during the relationship and for applicable legal or claims periods afterward.

6. Automated decisions

Tools may help organize applications, but we do not reject an application solely through an automated decision without human review. If this changes, we will provide a clear notice, a challenge route and meaningful human review before implementation.

7. Time recording

The application form does not collect device-activity data. If a selected project uses time recording, a separate notice will explain the exact data, purpose, retention and correction route. Our launch standard is task-time recording without webcam or keystroke monitoring.

8. Security and incidents

We use need-to-know access, multi-factor authentication where supported, separated client workspaces, confidentiality commitments, provider review and incident response. If a breach reaches a regulatory notification threshold, we follow the applicable authority and individual-notification requirements.

9. Your rights

You may request information, access, a copy, correction, destruction or consent withdrawal where applicable, and may object or complain to the competent authority. We respond within the legally required period and may request reasonable identity verification before acting.

10. Contact and updates

Until a formal privacy channel is approved, use the company request form, choose custom scope and write “Privacy request” in the goals field. We will update this notice when purposes, providers or the operating entity change and will display the new version date.

Submit a privacy request