Skip to content
GloviaGlovia.
LEGAL++++

Last updated 24 August 2026

Version 1.0 · Effective 24 August 2026

Privacy
notice.

How Glovia processes personal data on glovia.ai, structured for Saudi PDPL readiness. Counsel review still required before relying on this as final legal text.

LEGAL

This notice describes how Glovia (“we”, “us”) processes personal data when you visit glovia.ai, submit a contact or demo request, or otherwise interact with our public website. It is intended to support compliance with the Kingdom of Saudi Arabia Personal Data Protection Law (PDPL) and related Implementing Regulations. Enterprise platform processing for contracted customers is addressed separately below and in the customer agreement.

01

Controller identity

The controller for website personal data is Glovia, trading as Glovia from Riyadh, Saudi Arabia. Formal commercial registration details will be published when confirmed by counsel. Until then, Glovia is the trading name used in this notice. Privacy contact: hello@glovia.ai.

02

Data categories and sources

We process: (1) Form fields you submit — typically full name, work email, company/organization, and optional message (and any other fields shown on the form at the time). (2) Technical logs — IP address, user-agent/browser and device indicators, timestamps, and request metadata generated when you use the site or submit a form, used for security, abuse prevention, and reliability. (3) Cookies and similar technologies — see the cookies inventory; we do not currently run third-party marketing analytics pixels on the site. (4) Correspondence — emails or messages you send to our published addresses, and related replies. Sources are you (direct), your device/browser (technical), and our systems when you use the site.

03

Purposes and legal bases

We process personal data to: respond to inquiries and demo requests; operate, secure, and improve the website (including rate-limiting and spam controls); and meet applicable legal obligations. Required form fields (for example name, work email, company) are needed to handle your request; the message field is optional. Legal bases under PDPL (as applicable) include: processing necessary to take steps at your request before a contract or to respond to your inquiry; legitimate operational and security needs for running a public website; and compliance with law. Where consent is required for a specific optional technology, we will seek it. We do not sell personal data.

04

Recipients and processors

We use service providers only as needed to run the site and handle inquiries: website hosting and delivery (currently Vercel); email delivery of contact-form and related messages via SMTP to our configured mail infrastructure; and, if you choose to book via our published scheduling link, the scheduling provider (currently Calendly) processes the data you provide to them under their terms. We do not sell personal data. We may disclose data if required by Saudi or other applicable law, or to protect rights, safety, or security. Providers are instructed to process data only for the services they perform for us.

05

International transfers

Our public website is hosted on Vercel’s infrastructure, which may process technical and form-related data in regions outside Saudi Arabia depending on routing and provider operations. SMTP delivery may likewise involve servers outside the Kingdom depending on the configured mail host. When you use Calendly, that provider may process data in accordance with its own locations and safeguards. Where a transfer outside Saudi Arabia occurs, we rely on appropriate safeguards available under PDPL and its regulations (including contractual and organizational measures with providers) and will update this section as counsel confirms transfer mechanisms for our stack. We do not transfer website inquiry data for sale or unrelated marketing lists.

06

Retention by category

Inquiry and demo-request records (form contents and related email copies): retained while we handle the request and for a reasonable follow-up period, then deleted or anonymized unless a longer period is required for legal claims, audits, or regulatory duty — typically up to 24 months absent an ongoing relationship or legal hold. Technical/security logs: retained for short operational windows (generally up to 90 days, or longer if needed to investigate abuse or security incidents). Correspondence with privacy or general inboxes: retained as needed to complete the matter and meet record-keeping duties. Cookies: as set out in the cookies inventory / browser controls. Enterprise customer data retention is governed by the customer agreement, not this website notice.

07

Rights under Saudi PDPL

Subject to PDPL conditions and exceptions, you may request access to your personal data, correction of inaccurate data, and destruction of data when the purpose ends or the law so requires, and exercise other rights available under PDPL and its regulations. To submit a request or complaint about website processing, contact hello@glovia.ai. We may need to verify your identity before acting. You may also lodge a complaint with the Saudi Data and AI Authority (SDAIA) or the competent authority under PDPL where applicable. We will respond within the timeframes required by law.

08

Cookies inventory

Necessary: NEXT_LOCALE (or equivalent) — stores your language preference so the site can serve English or Arabic; typically a first-party cookie set by our edge/proxy. Strictly needed for locale continuity. Analytics: we do not currently load third-party analytics or advertising cookies on glovia.ai. If that changes, this inventory will be updated before or when those technologies are enabled. How to control: use your browser settings to block or delete cookies; blocking the locale cookie may reset language preference on later visits. Third-party sites you open from our links (for example Calendly) set their own cookies under their policies.

09

Automated decisions

We do not use automated decision-making, including profiling that produces legal or similarly significant effects, to accept, reject, or rank website inquiries or demo requests. Form submissions are reviewed by people on our team. Spam and rate-limit checks may filter abusive traffic automatically; that is security hygiene, not a decision about your eligibility for services.

10

Enterprise customer data

Personal and business data processed inside a contracted Glovia deployment for an enterprise customer is separate from website-visitor data described above. That processing is governed by the customer’s order, master agreement, and related data-processing terms — not solely by this public notice. Hosting and residency (for example private cloud, on-premise, or Saudi-based or other hosting options agreed in writing) are as specified in the deployment agreement. We do not claim that every deployment is an unqualified “sovereign cloud”; residency and controls follow what the contract defines. Tenant data is not shared across customers for unrelated purposes.

11

Document control

Version 1.0. Effective date: 24 August 2026. This notice is published in English and Saudi Arabic (ar-SA) with intended parity of substance. Until counsel directs otherwise, the English text is the controlling language if a conflict of interpretation arises between language versions. We may update this notice as our stack, practices, or the law change; the version and effective date above will be revised accordingly. Material changes will be reflected on this page. This structure is prepared for launch review; final legal approval by counsel remains required.