Who this policy is for
ConnectX builds AI voice agents for business and clinical AI for healthcare teams. This policy explains our public website, demo enquiries and privacy requests. It also explains how to find the right contact when your information is part of a customer's ConnectX workspace.
ConnectX is operated in Saudi Arabia by شركة كونيكت آي, a Simplified Joint Stock Company. Our registered address is Imam Mohammed bin Saud bin Abdulaziz Road, Al-Nakheel, Riyadh 12381. Contact us at support@connectai.sa about this policy or a data request.
For website enquiries and our own business contacts, ConnectX determines why and how the information is used. When a business or healthcare provider uses ConnectX to serve its customers or patients, that organization normally determines the purposes of its records. ConnectX processes those records on its behalf under the applicable service agreement and instructions. The organization's privacy notice explains that relationship in more detail.
Information you give us
Demo enquiries. The form asks for your name, work email, organization and a short description of the workflow you want to explore. Your product selection helps us route the enquiry. Phone number, preferred language, connected systems, call volume and clinical setting are optional. We use this information to respond, understand your requirements and arrange the relevant conversation. Without the required contact and workflow details, we cannot handle the request through that form.
Privacy requests. We ask for a reply email and the kind of request you want to make. A name, the relevant organization and a brief explanation can help us locate the right record. If you act for someone else, we may need to establish your authority before providing information or making a change.
Correspondence. If you email us, we receive the address and information you include, together with the conversation that follows. Share only what is needed for the purpose. Please do not put patient records, scan images, identity documents, passwords or payment information in a public website form.
Website operation and cookies
The website uses information needed to deliver pages and protect the service, such as the requested page, time of access, IP address and browser information. Security and hosting records help diagnose failures and investigate abuse.
This website does not use advertising trackers. Our product demonstrations use fictional information; interacting with an example does not create a customer or patient record. A demo enquiry does not subscribe you to a marketing list. Any future marketing subscription will offer a separate choice and a way to withdraw it.
Links to the signed-in product, WhatsApp or another website open a separate service. Its own information practices and notices apply to that service. A video played directly on this website is served as a website asset rather than an embedded social-media player.
Why information is processed
We use enquiry details for the response you request. Where consent is the basis for that use, you can withdraw it by contacting us. Information necessary to perform an agreement is processed for that agreement. We also handle information needed to meet applicable legal duties, including responding to data-rights requests.
Necessary website security processing supports our legitimate interest in operating a dependable service, subject to the safeguards required by applicable law. This does not create a basis for unrelated use of sensitive clinical information. The business or healthcare provider responsible for a customer workspace establishes the basis for its own processing and gives the relevant notices to individuals.
Customer conversations and clinical records
Depending on the services an organization uses, its workspace can contain contact details, conversations and transcripts, shared customer or patient context, documents, clinical notes, imaging and lab information, follow-up tasks and billing preparation. These are service records, not information requested by our public demo form.
The organization's configuration and authorized workflows determine how those records are used. For example, a call can inform a later WhatsApp interaction, and a consultation can develop into documentation for clinician review. Access follows organization, role and relevant clinical restrictions. Read about these controls on our Trust page.
If your request concerns a clinic's patient record or another business's service record, contact that organization first where possible. If you contact ConnectX, we can help identify the responsible organization and coordinate the request. We cannot disclose another organization's records simply because someone asks for them.
Sharing and location
ConnectX is hosted in Saudi Arabia. Authorized personnel and service providers involved in hosting, communications, security or delivering the requested service may process relevant information for those purposes. Customer-enabled integrations can pass information to the business systems or communication services selected for the workflow.
Saudi hosting does not by itself mean that every connected service processes all information in the same country. The applicable service arrangement should identify relevant providers, processing locations and any safeguards required for a transfer outside the Kingdom. Contact us for the data-handling details of a proposed deployment.
Information may also be disclosed where required by applicable law or a lawful request. Access and disclosure should be limited to the purpose and the information needed for it.
Retention and deletion
Enquiry information is kept for the period needed to respond and manage the resulting business relationship. Security records are kept for the operational and investigation purposes they support. Privacy-request correspondence is retained as needed to handle and document the request and meet applicable obligations.
Customer workspace records follow the applicable service arrangement, the organization's instructions and legal retention requirements. Clinical, billing or dispute-related records may need to be retained after an individual asks for deletion. When information is no longer required and no retention obligation applies, it should be securely deleted or irreversibly anonymized. A deletion request is reviewed against these requirements; it is not a promise of immediate removal from every system and backup.
Your rights and your next step
Under Saudi Arabia's Personal Data Protection Law, rights include understanding how information is used, accessing it, obtaining a readable copy, correcting or completing it, and requesting its destruction where the law allows. You can withdraw consent for processing that relies on consent. Rights are subject to the law's conditions and protections for other people.
Visit User data requests to choose a request and understand the process, or email support@connectai.sa. We may need proportionate identity or authority verification before acting. You can also raise a complaint with the Saudi Data & AI Authority through its data governance platform.
Changes to this policy
We will update this page when the information practices it describes change and identify the current version. Where a change requires a further notice or consent, updating this page alone does not replace that requirement.
Questions about a particular record can start with our data-request page. Questions about a proposed business deployment can start with a data-handling enquiry.