Privacy & Data Processing Policy.
This policy explains how SHIFTFM handles personal data and operational data processed through the website and platform.
Policy Scope
This policy explains how SHIFTFM handles personal data and operational data processed when the website or the platform is used.
The policy applies to data submitted through public website forms as well as operational data entered into the SHIFTFM environment by customers and their users.
Types of Data
Depending on use of the service, processed data may include the following categories.
SHIFTFM does not ask the customer to enter sensitive personal data as part of the normal use of the platform.
- Organization and facility data.
- User names.
- Business contact details.
- Job titles and permissions.
- Login and usage records.
- Tickets, tasks, incidents, and work orders.
- Vendor and contractor information entered by the customer.
- Images and attachments.
- Operational logs and related metadata needed to operate and support the service.
Sources and Collection
SHIFTFM collects data that a visitor or customer provides directly, including through contact and demo-request forms, onboarding communications, user creation, and operational records entered into the platform.
Operational and technical records may also be generated during use for authentication, support, service protection, and activity tracing.
How Data Is Used
SHIFTFM uses data to provide the service, respond to inquiries, arrange demos, configure customer environments, support users, secure the platform, investigate misuse, maintain records, and meet applicable legal obligations.
Aggregated and De-identified Statistics
SHIFTFM may generate and use aggregated or de-identified statistics derived from use of the platform for service improvement, capacity planning, performance measurement, analysis, general metrics, and publication of overall platform-usage statistics.
Such statistics must not identify a customer, its users or facilities in a reasonably identifiable manner, must not disclose customer-specific confidential operational data, and must not reasonably enable re-identification of individuals or organizations from the published information.
SHIFTFM will not use a customer's name, logo, or customer-specific statistics in public or marketing materials without that customer's permission.
The creation or use of aggregated and de-identified statistics does not affect the customer's ownership of its underlying customer data.
Roles by Processing Context
Depending on the processing context, the customer may act as the controller or equivalent responsible party for the data it collects and enters into SHIFTFM, while SHIFTFM may act as a processor or service provider when handling that data to provide the service.
Where SHIFTFM determines processing purposes or means for its own business, support, security, or regulatory needs, SHIFTFM may act in a different role as permitted by applicable law.
Cross-Border Processing
Some technical components may require processing or storage through infrastructure outside the Kingdom of Saudi Arabia. In those cases, SHIFTFM manages that processing according to the legal requirements applicable to international transfer and cross-border processing in light of the data, the recipient, and the relevant legal basis.
Customer Data Isolation
Each customer’s data is managed through its assigned operating environment together with logical, permission, and organizational separation measures designed to limit unauthorized access and cross-customer overlap.
Access to each organization’s data is restricted according to the user’s relationship to that organization and the permissions granted to that user. Access to another organization’s data is not made available except under an appropriate legal and technical authorization.
Data Protection Measures
SHIFTFM applies technical and organizational measures proportionate to the nature of the service, the data involved, and the relevant risks. These measures include access management, customer isolation, session protection, connection security, and service-continuity practices aligned to the operating architecture.
Security Incidents
When a data-related incident is discovered, SHIFTFM works to assess, contain, investigate, and mitigate it.
Reports and notifications are handled according to applicable laws and regulations. Any 72-hour notification requirement applies where the statutory conditions for that type of notification are met.
Retention During Subscription
SHIFTFM retains the data needed to provide the service during the subscription period while applying data-minimization principles and avoiding retention of personal data for longer than necessary for a legitimate or regulatory purpose.
Retention After Expiry
When a paid subscription ends without renewal, SHIFTFM may archive operational data in a compressed and isolated form for up to three years for legitimate purposes such as possible account restoration, dispute handling, evidence of transactions and contractual obligations, and record continuity where needed.
The three-year period does not mean that all personal data must be retained for the full period.
Personal data for which there is no longer a legitimate purpose or legal retention requirement is deleted or anonymized.
After the archival period ends, data is permanently deleted or anonymized unless the law requires part of it to be retained longer.
Rights Requests
Rights requests are handled in accordance with the Personal Data Protection Law and related regulations.
If the data was entered by a customer organization and that organization is the controller for the relevant processing, the request may be referred to the customer or handled in coordination with it.
No Sale of Data
SHIFTFM does not sell customer operational data or personal data contained within a customer environment to third parties.
Policy Updates
SHIFTFM may update this policy from time to time without obtaining a new individual approval from every customer or user where the change is non-material. Non-material changes may include, without limitation, clarifications of wording, formatting or structural updates, contact-information updates, correction of errors, clarification of an existing process, operational or technical descriptions that do not materially reduce rights or materially increase obligations, and changes needed to reflect existing platform functionality without materially changing the legal relationship.
Non-material updates become effective when the updated policy is published, and the Last updated date on this page is revised accordingly. If a change is material and materially affects customer rights, user rights, data-processing practices, material customer obligations, material service restrictions, payment or subscription obligations, or another substantial element of the legal relationship, SHIFTFM will provide notice through the platform and/or another appropriate communication channel.
Where applicable law or the nature of the change requires renewed acceptance, SHIFTFM may require the affected customer or user to accept the updated policy before continuing normal use. For changes that do not legally require renewed explicit acceptance, continued use of the service after the effective date may constitute acceptance of the updated policy, subject always to the laws and regulations applicable in the Kingdom of Saudi Arabia.
Contact
Questions about this policy may be sent to info@shiftfm.net or by phone at 0534801690.
Location: Riyadh, Saudi Arabia.