Privacy Policy
This Privacy Policy explains how MeandRobo Artificial Intelligence Solutions W.L.L. ("MeandRobo", "we", "us") handles personal data in connection with Qiyada (the "Service"), our website at qiyada.meandrobo.com.qa, and our sales and support activities. It is written to meet the requirements of Qatar's Law No. 13 of 2016 on the Protection of Personal Data Privacy and takes into account other data protection laws that may apply to our customers, including the laws of other Gulf states, the EU and UK General Data Protection Regulations, and applicable US laws.
In short. Qiyada is a business tool. Your organisation controls the data it puts into its workspace; we process that data only to run the Service. We never sell personal data, never use your data to train AI models, and never send an email on your behalf without your confirmation. You can export or delete your data, and you can contact us about your rights at info@meandrobo.com.qa.
1. Who we are and our two roles
Controller for our own data. MeandRobo is the controller of the personal data we collect to run our business: account and sign-in details, billing records, website enquiries and demo requests, support conversations, and security logs.
Processor for our customers' data. When an organisation ("Customer") uses Qiyada, the information it uploads, enters or connects — financial statements, documents, contracts, business cards, mailbox and calendar content, and conversations with the AI assistant — is "Customer Data". The Customer is the controller of personal data within Customer Data and decides why it is processed; we process it on the Customer's behalf and on its instructions, under our Data Processing Addendum. If your personal data is in a Customer's workspace (for example, you are an employee, a correspondent or a business-card contact), please contact that organisation first; we will help them respond.
Contact. MeandRobo Artificial Intelligence Solutions W.L.L., Doha, State of Qatar, State of Qatar. Privacy enquiries: info@meandrobo.com.qa.
2. The personal data we handle
| Category | Examples | Where it comes from |
|---|---|---|
| Account data | Name, work email, username, organisation name, country, phone (optional), role, hashed password, two-factor secret (encrypted), sign-in history | You, when you sign up or are invited by your administrator |
| Enquiry data | Name, company, work email, phone, message, preferred contact method; a one-way hash of your IP address for abuse prevention | You, via our contact and demo-request forms |
| Billing data | Plan, subscription ID and status, amounts, dates, PayPal payer name and email, country | You and PayPal. We never receive card or bank details |
| Consent and legal records | Acceptance of Terms, business-use declaration, auto-renewal consent, marketing preference, with date and version | You |
| Usage and security data | Pages and features used, AI request counts, audit-log entries (who did what, when), device and browser type, IP address in server logs, error logs | Your use of the Service |
| Customer Data (processed for the Customer) | Financial statements and documents, contracts, letters, business-card images and contact details, notes, AI conversations, calendar entries, and — if connected — mailbox messages | The Customer and its users, and services they connect |
| Voice | Spoken requests to Mona are converted to text by your browser's built-in speech-recognition service. Depending on your browser, the audio may be sent to the browser maker (for example Google for Chrome, Microsoft for Edge, Apple for Safari) and processed under its own terms; we do not receive or store the audio, only the resulting text. If natural voice is switched on, Mona's replies are generated as audio by our AI provider (Google) | You |
| Notification data | Push-notification subscription for your device, notification preferences | Your browser, when you allow notifications |
We do not intentionally collect special categories of personal data (such as health, religion or biometric data), and our Terms ask customers not to upload them unless genuinely necessary. The Service is for adults acting for a business and is not directed at anyone under 18.
3. Why we use personal data, and our legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Create and run your account and workspace, sign you in securely, provide features and support | Account, usage, Customer Data | Performance of our contract with you or your organisation; our legitimate interest in providing the Service to the organisation you work for |
| Process subscriptions, payments and invoices; keep accounting and tax records | Billing, consent records | Contract; legal obligation |
| Keep the Service secure, prevent fraud and abuse, keep audit logs | Account, usage, security data, hashed IP | Legitimate interests (security); legal obligation where applicable |
| Respond to demo requests and enquiries | Enquiry data | Steps at your request before a contract; legitimate interests |
| Send service messages (security alerts, billing, changes to terms) | Account data | Contract; legal obligation |
| Send marketing about Qiyada | Name, email | Your consent only — which you can withdraw at any time; we do not send marketing without it |
| Improve the Service using aggregated, de-identified usage statistics | Usage data | Legitimate interests |
| Comply with the law and respond to lawful requests; establish or defend legal claims | Any relevant data | Legal obligation; legitimate interests |
| Process Customer Data to provide the Service | Customer Data | On the Customer's instructions (the Customer determines its own legal basis) |
You must give us your name, work email and organisation details, and accept our Terms, to create an account; without them we cannot provide the Service. Billing data is needed to process a paid subscription. Other information (phone number, marketing preferences, integrations, voice) is optional.
Under Qatar's law, we process personal data with your consent or where necessary for the lawful purposes described above. We do not make decisions about individuals based solely on automated processing that produce legal or similarly significant effects.
4. Artificial intelligence
- Which features use AI. The analyst, the AI Secretary, contract review and generation, market intelligence and the voice assistant Mona use AI models. Mona is an AI assistant, not a human, and the Service says so.
- Our AI provider. We use Google's Gemini API as a sub-processor. The relevant content (for example, the figures you ask about or the document you want reviewed) is sent to it to generate the answer. We use Google's paid service, under which Google does not use your prompts or responses to improve its products or train its models. Google keeps prompts and responses for up to 55 days solely to detect abuse and comply with the law, and authorised Google staff may review flagged content for that purpose only. Market-intelligence features use Google's "Grounding with Google Search": the request (the company's name, sector, country and latest revenue figure, and any focus you type — but not your uploaded documents) is processed by Gemini, which runs Google searches to find current public information. For these requests Google also stores the prompt and output for 30 days to produce the search results and may use them to debug and test its grounding systems, under its data processing terms. The resulting briefing, with its sources, is saved in the workspace for the users who have access to that company.
- No training by us. We do not use Customer Data or AI output to train any AI model.
- You stay in charge. AI output can be wrong. Emails and letters drafted by AI are sent only after a user confirms them, from the user's own mailbox.
5. Connected mailboxes and calendars
These integrations are optional and switched on by a user.
- Microsoft 365. If you connect Outlook mail or calendar, you sign in with Microsoft and approve specific permissions: sign-in and basic profile, offline access, read mail, send mail, and read calendar. Your organisation's Microsoft 365 administrator may need to approve the connection. We store the resulting refresh token encrypted and use it only to show you your messages and meetings, flag urgent emails, prepare briefings and send emails you confirm.
- Other mailboxes (including Gmail) via IMAP/SMTP. If you connect a mailbox with an app password, we store the password encrypted and use it only for the same purposes.
- Calendar links. If you add a private calendar address (for example from Google Calendar), we read the events it publishes to show them in the Service.
- Limits. We read only what is needed for the features you use, we do not use mailbox or calendar content for advertising or to train AI models, and our staff do not read it except at your request for support, for security, or where the law requires. You can disconnect at any time in the app, and you can also revoke access in your Microsoft or email account; we then stop accessing it and delete the stored credentials and any stored copies of messages or events from that account.
6. Who we share personal data with
We do not sell personal data and do not share it for advertising. We share it only with:
- Sub-processors that help us run the Service, under their data processing terms, which require them to protect it and use it only on our instructions: hosting (Hostinger International Ltd., [to be completed: hosting country]) and Google (Gemini API). The current list is on our Sub-processors page.
- Services you connect — Microsoft, your email provider, your calendar provider — which receive requests from us on your behalf and process data under their own terms.
- PayPal, which processes payments as an independent controller under its own privacy statement.
- Services outside our control that deliver features in your browser: browser push services (for example those run by Google, Apple and Mozilla) deliver notifications to your devices if you enable them — notifications are encrypted in transit to your device and contain short alerts, not document content; and your browser's speech-recognition service (see section 2).
- Your organisation's administrators, who can see the users, activity and data in their workspace.
- Professional advisers (lawyers, accountants, auditors) under confidentiality.
- Authorities, where the law requires it or to protect rights, safety and security; we will tell the affected customer where the law allows.
- A buyer or successor if our business is reorganised, merged or sold, under equivalent protections, and we will tell you.
7. International transfers
We are based in Qatar. Our servers and their backups are located in [to be completed: hosting country], and our AI provider may process data in the United States and other countries where Google operates. Personal data may therefore be transferred outside the country where you are.
We transfer personal data only where the law allows and with appropriate safeguards: for example, the European Commission's Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement) for transfers from the EEA and UK; the Standard Contractual Clauses issued by the Saudi Data & AI Authority for transfers from Saudi Arabia; Google's data processing terms, which incorporate the Standard Contractual Clauses (Google LLC is also certified under the EU–US Data Privacy Framework); and any consent or permit required by local law. You can ask us for a copy of the safeguards at info@meandrobo.com.qa.
8. How long we keep personal data
| Data | How long |
|---|---|
| Account data | While the account is active. After a workspace is closed: 30 days to allow export, then deleted |
| Customer Data | Controlled by the Customer. On workspace closure: 30-day retrieval period, then deleted |
| Encrypted backups | Overwritten in the normal cycle, within 60 days after deletion from the live system |
| Mailbox, calendar credentials and cached content | Until disconnected; credentials are deleted on disconnect |
| AI provider logs (Google) | Up to 55 days, for abuse monitoring only |
| Market-intelligence requests grounded with Google Search (Google) | 30 days, to produce search results and debug and test Google's systems |
| Server, error and usage logs (including IP addresses) | 90 days, then deleted or aggregated; aggregated statistics are kept without personal data |
| Enquiries that do not become customers | 24 months after the last contact |
| Hashed IP addresses from forms | 90 days |
| Audit and security logs | Up to 24 months |
| Sign-in sessions | End after 24 hours of inactivity (or when you sign out) and are then deleted |
| Users removed from a workspace | Sign-in data deleted within 30 days; their past activity stays in that workspace's audit log |
| Billing, payment and tax records | 10 years, as required by accounting and tax law |
| Consent records (terms, auto-renewal, marketing) | For the life of the account and 3 years after it ends (longer only while needed for a legal claim) |
| Marketing opt-out list | Kept (email only) so that we can continue to respect your choice |
9. How we protect personal data
- Encryption in transit (HTTPS/TLS) for all connections.
- Passwords stored only as one-way hashes; two-factor secrets, mailbox credentials and access tokens stored encrypted (AES-256-GCM).
- Two-factor sign-in, session expiry, and company- and module-level access control inside each workspace.
- Each customer workspace is kept in a separate database schema.
- Audit logging of sign-ins, changes and administrative actions.
- Encrypted daily backups that are regularly restore-tested.
- Least-privilege access for our staff, and a documented incident-response process.
No system is perfectly secure. If a personal-data breach affects data in a customer's workspace, we notify that customer without undue delay and in any event within 48 hours of becoming aware of it, and help the customer meet its own obligations to notify authorities and individuals. If a breach affects personal data for which we are the controller (such as account or billing data) and it is likely to cause harm, we notify the competent authority and, where required, the individuals concerned without undue delay and, where the law requires, within 72 hours of becoming aware of it.
10. Your rights
Depending on where you are, you may have the right to:
- be informed about how your data is processed (this Policy) and be told about processing and about any inaccurate disclosure of your data;
- access your data and receive a copy;
- correct inaccurate or incomplete data;
- delete your data, or have its processing restricted;
- object to processing based on our legitimate interests, and object at any time to direct marketing;
- withdraw consent at any time, without affecting earlier processing;
- data portability — receive your data in a structured, machine-readable format;
- not be subject to decisions based solely on automated processing with significant effects;
- complain to us and to a data-protection authority.
How to exercise them. Many rights can be exercised directly in the app (edit your profile, export data under Organisation → Your data, disconnect integrations, close a workspace). Otherwise email info@meandrobo.com.qa. We may need to verify your identity. We acknowledge requests within 10 business days and answer within 30 days; if a request is complex we may extend this where the law allows, and we will tell you why. We do not charge for requests unless they are manifestly unfounded or excessive, where the law allows a fee. Requests about Customer Data are passed to the Customer that controls it, and we help them respond.
Complaints. We handle privacy complaints through our internal procedure: email info@meandrobo.com.qa and we will acknowledge your complaint within 30 days (usually much sooner) and respond without undue delay. You can also complain to the authority responsible for data protection where you live or work — in Qatar, the National Cyber Security Agency; in Saudi Arabia, the Saudi Data & AI Authority; in the EU, your national supervisory authority; in the UK, the Information Commissioner's Office.
United States. We do not sell or "share" personal information for cross-context behavioural advertising, and we do not use sensitive personal information to infer characteristics. Residents of US states with privacy laws may exercise the rights those laws give them by contacting us.
11. Cookies and similar technologies
We use only what is strictly necessary for the Service to work: a sign-in token and your preferences (such as language and export settings) stored in your browser's local storage. We do not use advertising or cross-site tracking cookies, and we do not respond to "Do Not Track" signals because we use no tracking technologies to which they would apply. PayPal may set its own cookies when you use its checkout. Details are in our Cookie & Storage Notice.
12. Marketing
We send marketing emails only to people who have opted in. Every marketing email identifies us, says that it is marketing, includes our postal address, and contains a simple way to unsubscribe, which we act on within 2 business days. Service messages about your account, security, billing or changes to our terms are not marketing and are sent regardless.
13. Changes to this Policy
We may update this Policy. We will post the new version with its effective date and, for material changes, notify account holders by email or in the app at least 30 days before they take effect, unless a change is required sooner by law.
14. Contact
MeandRobo Artificial Intelligence Solutions W.L.L. · Doha, State of Qatar, State of Qatar · Commercial registration no. 237749, registered with the Ministry of Commerce and Industry, State of Qatar Privacy: info@meandrobo.com.qa
This Policy is published in English and Arabic.
