Skip to main content
سنوريات SANORIYAT

Privacy Policy

Version 2026-07 · Effective July 2026 · Governing law: Kingdom of Saudi Arabia

How SANORIYAT processes personal data under the Saudi Personal Data Protection Law (PDPL). Data controller: SANORIYAT.

1. Data we collect

  • Account: email, password (via our auth provider), country, language. Email confirmation is required.
  • Profile: display name, city, bio, avatar, phone number and your chosen visibility (show/hide), optional contact links.
  • Cattery: name, public slug, description, breeds, logo/cover images, and contact details you choose to publish.
  • Cats & listings: name, breed, date of birth, colour/EMS code, photos, certificates, registration/microchip, price, status, pedigree, and litters/breeding records.
  • Health records: per-cat health notes and any health documents you upload (stored privately; survive an identity transfer with the cat).
  • Verification: cattery name and the registration/certificate image you upload (stored privately).
  • Interactions: messages, comments, reviews and replies, reservation/inquiry details (incl. name and contact you provide), notifications.
  • Consent & compliance: the terms/privacy version you accepted and when, age confirmation, and moderation/appeal records and an internal audit log.
  • AI usage metadata: counts, model, token usage and cost (operational metering — not the content of your conversations).
  • Technical: device/app and basic security and diagnostic data.

2. How we use it & legal basis (PDPL)

  • Provide and secure the platform — performance of contract / legitimate interests.
  • Accounts, verification, messaging, marketplace discovery — contract.
  • Fraud prevention, abuse moderation, safety, audit — legitimate interests / legal obligation.
  • AI-assisted features — your explicit consent (see §5).
  • Product analytics and reliability/error monitoring — legitimate interests (pseudonymous; no advertising).
  • Service communications — contract / consent.

3. Public vs. private information

Your cat, cattery, and listing content and your Reviewed Breeder status are public. Your phone/contact is shown publicly only if you set visibility to “Show.” Health records and documents, messages, reservations you receive, verification documents, and account data are NOT public; access is restricted by row-level security, and private documents (health and verification) are served only to authorised users via short-lived signed links.

4. Sharing & processors

  • Hosting, database, storage, authentication — our cloud/database provider.
  • AI features — Anthropic and/or OpenAI process documents/photos you submit to AI tools to extract or generate data only; per their terms this data is not used to train their models.
  • Transactional email — an email delivery provider sends account, verification, and notification emails on our behalf (it receives the recipient address and message content).
  • Product analytics — a privacy-first, EU-hosted analytics provider receives only a pseudonymous account id, your role, language, and the page path. It never receives your name, messages, photos, or other content, and uses no advertising cookies. Active only when we enable it.
  • Error monitoring & diagnostics — a provider receives technical error reports (and a pseudonymous id/role/locale tag) so we can keep the service reliable. It does not receive your messages or content. Active only when we enable it.
  • (Future) push notifications — a mobile messaging provider, only if you enable notifications.
  • We do not sell personal data, and we do not use your data for advertising. We disclose data where required by law or to protect rights, safety, and the platform.

5. AI features & international transfers

Some processors (notably the AI providers) operate outside the Kingdom (United States). Where you use AI features, your submitted content is transferred abroad only with your consent, limited to the stated purpose, and subject to appropriate safeguards. You can use manual entry instead of AI.

Other operational providers (hosting, transactional email, diagnostics) may also process limited data outside the Kingdom under appropriate safeguards. Our product analytics provider is hosted in the European Union.

6. Retention

We keep account and profile data while your account is active and as needed for legal, security, and dispute purposes after closure. Verification documents are retained only as long as needed to maintain status. Moderated/removed content is retained in restricted form for audit and safety. Operational logs are kept for limited periods. A detailed retention schedule is available on request.

7. Your rights (PDPL)

Subject to law, you may access, correct, delete, and port your data, withdraw consent, and object to certain processing. Submit a request via admin@sanoriyat.com or the in-app data-request form; we verify your identity and respond within the legally required period. Deletion may be subject to retention for legal or safety reasons.

8. Security

Access controls (row-level security), private storage for sensitive documents, encryption in transit, and least-privilege admin access. No system is perfectly secure; we will notify you and the competent authority of qualifying breaches as required by law.

9. Children

The platform is for users 18 or older. We do not knowingly process children's data and will delete such data on discovery.

10. Changes & contact

We version this Policy; material changes are notified and may require renewed consent. Contact: admin@sanoriyat.com. Data controller: SANORIYAT.