Legal
Privacy Policy
How GattAI collects, processes, and protects personal data across our marketing properties, early access waitlist, and enterprise AI HR platform.
Last updated 20 September 2026
1. Scope & Legal Roles (Controller vs. Processor)
Data protection laws distinguish between the entity that determines the purposes and means of processing personal data (the Data Controller) and the entity that processes personal data on behalf of the controller (the Data Processor).
- GattAI as Data Controller: With respect to visitors to our website, individuals who register for our enterprise waitlist, request architecture specifications, or communicate with our sales and support teams, GattAI acts as the Data Controller.
- GattAI as Data Processor: With respect to employee records, candidate applications, compensation structures, performance reviews, and other organizational workforce data uploaded to or processed through the GattAI SaaS platform, our customer organization is the Data Controller, and GattAI operates strictly as a Data Processor bound by a comprehensive Data Processing Agreement (DPA).
2. Information We Collect
We adhere strictly to the principle of data minimization, collecting only information necessary to fulfill clearly stated legitimate business and operational purposes:
A. Website & Waitlist Submissions: When you voluntarily submit forms on our website, we collect:
- Full name, corporate email address, and professional job title.
- Company or organization name, industry sector, and estimated workforce size.
- Jurisdictions of operational interest (e.g., Saudi Arabia, UAE, Egypt, wider GCC).
- Specific functional modules selected (e.g., Payroll Intelligence, AI Recruiter, Performance).
- Evaluation timeline and qualitative notes regarding your HR automation roadmap.
B. Technical Telemetry & Operational Logs: Standard server logs captured for cybersecurity, DDoS defense, and infrastructure reliability:
- Internet Protocol (IP) address and approximate geographic location.
- Browser user agent, operating system, and language preferences.
- Uniform Resource Identifiers (URIs) accessed, request headers, and timestamps.
C. Zero Invasive Tracking & Cookie Policy: This marketing site does not set third-party advertising cookies, does not load tracking pixels, and does not deploy session-recording scripts (such as Hotjar or FullStory). You can inspect all network requests independently via your browser developer tools.
3. Purpose & Legal Bases for Processing
Under the EU General Data Protection Regulation (GDPR Article 6), KSA PDPL, and UAE PDPL, we process your personal data under the following lawful bases:
- Performance of a Contract / Pre-Contractual Steps: Evaluating your enterprise waitlist submission, scheduling product demonstrations, and provisioning early access sandbox environments upon request.
- Legitimate Interests: Protecting the security and integrity of our infrastructure, preventing fraudulent inquiries, and optimizing the performance and usability of our systems.
- Compliance with Legal Obligations: Fulfilling statutory tax, corporate governance, and regulatory reporting requirements.
4. AI Processing & Zero Data Retention Commitments
GattAI’s core mission is to automate enterprise HR workflows with unwavering data privacy. We enforce rigorous safeguards around artificial intelligence operations:
- Strict Training Prohibition: Neither waitlist submissions nor customer tenant workforce data is ever used to train, retrain, or fine-tune public foundation models (including models developed by Anthropic, OpenAI, or other providers).
- Deterministic Pseudonymization: Prior to transmitting any prompt to an external model API, all direct and indirect personal identifiers are replaced with synthetic cryptographic tokens. The identity mapping table is encrypted and never leaves the tenant’s isolated database partition.
- Zero Data Retention (ZDR): Model inferences are executed under contractual Zero Data Retention terms with model providers, ensuring that prompt payloads and completions exist only transiently in provider RAM and are purged immediately upon transmission.
5. Infrastructure & Authorized Sub-Processors
To deliver high-availability cloud services, we partner with verified, enterprise-tier infrastructure providers operating under binding DPAs:
- Cloud Hosting & Database Storage: Enterprise PostgreSQL database and object storage infrastructure hosted via Supabase / AWS / Google Cloud, with dedicated regional cloud data centers available across the GCC (Saudi Arabia and UAE) and the European Union.
- Transactional Email Communications: Resend (used solely for delivering waitlist confirmations and critical security notices; not utilized as a marketing tracking service).
- AI Model Inference Providers: Enterprise API tiers of Anthropic and OpenAI operating under contractual Zero Data Retention agreements.
6. Data Retention & Cryptographic Disposal
We retain personal data only for as long as necessary to achieve the specific purposes for which it was collected:
- Waitlist Submissions: Retained until your organization is onboarded into the platform or until you submit a deletion request.
- Platform Customer Data: Governed by the Master Services Agreement (MSA) and local statutory requirements (e.g., labor laws requiring 5-to-10 year retention of payroll and tax filings in KSA, UAE, and Egypt). Upon contract termination, tenant data is exported securely and irreversibly purged from all active databases following a 30-day grace period.
7. Your Rights as a Data Subject
Regardless of your jurisdiction, you maintain robust rights over your personal data under GDPR, KSA PDPL, and UAE PDPL:
- Right of Access: You have the right to request a copy of the personal data we hold about you.
- Right to Rectification: You may request immediate correction of any inaccurate or incomplete personal information.
- Right to Erasure (“Right to be Forgotten”): You may request the deletion of your personal records where no statutory or contractual retention obligation applies.
- Right to Restriction & Objection: You may object to or request the restriction of specific processing activities.
- Right to Non-Automated Decision Making: Under Article 22 of the GDPR and corresponding GCC privacy standards, you have the right not to be subject to a decision based solely on automated processing. GattAI enforces this right natively through our mandatory, unskippable human approval gates.
To exercise any of these rights, contact our Data Protection Officer at privacy@gattai.ai. We verify requests via the originating corporate email address and respond within thirty (30) days without fee.
8. Contact Information & Regulatory Inquiries
For questions regarding this Privacy Policy, our data processing practices, or to request our standard Data Processing Agreement (DPA), please reach out to our privacy team:
Email: privacy@gattai.ai
Trust & Security Center: https://gattai.ai/trust/security