Fursah policies

Privacy Policy

Version 2.0 · Effective 19 August 2026 · Last updated 19 August 2026

This policy explains what personal data Fursah collects, why we are permitted to process it, who receives it, how long we keep it, and the rights you can exercise over it. It is written to meet the Personal Data Protection Law of the Kingdom of Saudi Arabia (Royal Decree M/19, as amended by M/148) and its Implementing Regulations.

1. Who is responsible for your data

The data controller is Fursah AI (“Fursah”, “we”, “us”), Riyadh, Kingdom of Saudi Arabia. We determine the purposes and means of processing personal data on this platform and are accountable for it under the Personal Data Protection Law (“PDPL”).

Privacy enquiries, rights requests, and complaints may be sent to info@fursah.org. We aim to acknowledge within five working days and to resolve within thirty days, which is the period the Implementing Regulations allow for responding to a data-subject request.

Where a university or employer uses Fursah to manage its own recruitment or advising process, that institution acts as an independent controller for the decisions it makes. Fursah remains controller for the platform, the scoring engine, and the records described in this policy.

2. Personal data we collect

We collect only what is needed to operate the readiness, matching, verification, and institutional-reporting functions of the platform. Categories are:

  • Account data: your name, email address, assigned role (student, employer, university, or administrator), account status, and the date the account was created.
  • Student profile data: your target career, degree, institution, and an optional short biography that you write yourself.
  • Competence data: the skills you list and the proficiency level you claim for each (a 1–5 scale), certifications, work and volunteer experience with duration, and projects.
  • Evidence files: documents you upload to support a certification, project, or experience, including the original filename, file type, size, and the outcome of automated file checks and human review.
  • Activity data: applications you submit and their status, jobs you bookmark, employers and career tracks you follow, and the roadmap items generated for you or added by you.
  • Governance records: your purpose-specific consent choices and their version, appeals you raise, data requests you make, support tickets you open, and notifications sent to you.
  • Outcome data: structured feedback an employer records after a placement, across technical skill, communication, teamwork, problem-solving, adaptability, and an overall rating.
  • Technical data: an authentication session cookie, and server logs generated in the ordinary course of operating a web service.

3. Personal data we deliberately do not collect

Fursah does not collect your national identity number, date of birth, gender, nationality, tribal or family affiliation, marital status, health or disability information, religious affiliation, or political opinion. No field for any of these exists in our data model.

This is a design commitment, not merely a current state. Because these attributes are never collected, they cannot enter a readiness score or a match ranking, and they cannot be inferred back out of a score we did not build from them. Any proposal to collect a special-category attribute would require a documented lawful basis and a Data Protection Impact Assessment before a field is added.

We do not collect Grade Point Average. Screening on institution prestige or grade average is one of the specific harms the platform exists to reduce.

4. Why we process your data, and our lawful basis

Under the PDPL we must have a lawful basis for each purpose. Ours are:

  • To provide the service you asked for: calculating your readiness score, showing your gaps, matching you to opportunities, and carrying your applications to employers. Basis: performance of the service you have requested.
  • To verify evidence you submit, so that a claimed skill or certification means something to an employer. Basis: performance of the service, and our legitimate interest in the integrity of the platform.
  • To share approved evidence with an employer reviewing your application. Basis: your consent, given per purpose and withdrawable at any time.
  • To send you notifications about opportunities matching employers and career tracks you follow. Basis: your consent.
  • To improve the recommendation logic using de-identified employment outcomes. Basis: your consent.
  • To produce aggregate, non-identifying reporting for universities and for national workforce planning. Basis: legitimate interest, exercised only on data that has been aggregated and suppressed as described in clause 7.
  • To keep security, audit, and accountability records, and to respond to rights requests and appeals. Basis: compliance with our legal obligations under the PDPL.

5. Consent, and what happens when you withdraw it

Consent on Fursah is specific rather than bundled. Three purposes are separately controlled from your privacy settings: sharing verified evidence with employers, using anonymised outcomes to improve recommendations, and personalised opportunity notifications. Each is recorded with its own timestamp and policy version.

You may withdraw any consent at any time, and withdrawal is as easy as giving it: a single control in the same screen. Withdrawal takes effect immediately for future processing. It does not make past lawful processing unlawful, and it does not retract a document an employer has already lawfully viewed.

Refusing or withdrawing consent does not disable your account, your readiness score, or your ability to apply for opportunities. Consent-based purposes are additional to the core service, never a condition of it. We do not use pre-ticked boxes, and we do not treat silence or inactivity as consent.

6. Who receives your data

We do not sell personal data. We do not disclose personal data for advertising, and we do not permit any third party to use data obtained through Fursah to profile you for advertising purposes.

Your data is disclosed only in these circumstances:

  • To an employer, when you apply to their opportunity: your profile, your match score, and the explanation behind it. Supporting evidence is included only if you have granted the employer-evidence consent.
  • To a holder of a sharing link you created yourself. Passport links are time-limited, carry an expiry date you set, and can be revoked by you at any moment, which invalidates the link immediately.
  • To your university, only in aggregate form and subject to the suppression rule in clause 7. A university does not receive named student records or per-student scores through institutional reporting.
  • To service providers who process data on our instructions under written agreement: Google Firebase Authentication for sign-in, Cloudflare R2 for encrypted storage of evidence files, Cloudflare Workers AI for the language-model processing described in clause 6a, and Vercel for application hosting. They may not use your data for their own purposes.
  • To a competent authority where we are legally required to disclose, and to the extent required.

6a. Language-model processing

Two features send personal data to a language model, and we describe them specifically rather than under a general reference to “AI processing”.

  • Evidence extraction: when you upload a certificate, project, or experience document, its contents are sent for structured extraction. This includes the document type, title, issuer, recipient name, dates, supported skills, confidence values, and supporting text. The result is a proposal for a human reviewer. It is never an automatic approval.
  • The in-platform assistant: when you ask it a question, it receives a prepared set of facts scoped to your own role, together with your question and up to six previous turns of that conversation.

6b. Limits on that processing

The model does not compute your readiness score or your match score. Those remain deterministic and rule-based, exactly as published in the Responsible AI Policy, so that every number affecting you stays reconstructible. The model extracts, summarises, and explains; it does not rank people.

The facts supplied to the assistant are scoped by role before they leave our systems. A university's assistant receives only aggregate, suppression-filtered data and cannot be given an individual student's record, and this boundary is enforced by an automated check that runs against the context builder rather than by instruction to the model alone.

We use Cloudflare Workers AI. Your data is processed to answer your request and is not used by us or by the provider to train models.

Language models can be wrong. Extracted details are a proposal you and a human reviewer can correct, and assistant answers are explanatory rather than authoritative. Where an extraction is wrong, correcting it is a data-correction right under clause 11, not a support request.

7. Aggregate reporting and the suppression threshold

Universities and national-planning views receive statistics, not students. Aggregate reporting excludes names, email addresses, and per-person scores by construction.

Aggregation alone is not anonymity. A “readiness band distribution” across three students identifies all three. Fursah therefore enforces a minimum cohort size of five: where fewer than five students fall within a reporting group, the platform suppresses the figures entirely and states that the cohort is too small to report, rather than publishing a re-identifying statistic.

8. Evidence files and their handling

Evidence documents are stored in private object storage, are not publicly addressable, and are served only to users authorised to see them. Uploads are limited to 25 MB and to a defined list of document, image, and media formats; executable and macro-enabled file types are rejected.

Automated checks screen an upload before a human reviewer sees it. These checks flag a file for closer inspection; they do not by themselves approve or reject your evidence. Approval or rejection of evidence is always a human decision, recorded with the reviewer's identity and the time of review.

9. International transfer

Fursah is designed to be operated from a hosting region inside the Kingdom, consistent with national data-classification and cloud-hosting rules and with the Regulations on Personal Data Transfers outside the Kingdom.

We state plainly that the current prototype deployment uses infrastructure providers whose storage and hosting regions are not yet pinned to the Kingdom. This is a known limitation of the prototype and is disclosed here rather than omitted. Before the platform processes real student records at any scale, hosting and storage will be bound to a compliant in-Kingdom region, and any residual transfer will be assessed and documented as the Regulations require.

The same rule applies to the language-model processing in clause 6a. Inference runs on the provider's distributed network rather than in a region that we currently select. Evidence documents are the platform's most sensitive data, so this is the first transfer planned for localisation within the Kingdom. Until then, an institution may disable extraction. Evidence is then reviewed by a person without a machine-generated proposal.

10. Retention

We keep personal data only as long as the purpose it was collected for requires.

  • Profile, competence, and evidence data: retained while your account is active, and deleted or de-identified when you close your account or a deletion request is completed.
  • Applications and their outcomes: retained while the application is live and for a limited period afterwards so that appeals remain reviewable.
  • Authentication sessions: the session cookie expires thirty days after it is issued.
  • Audit, consent, appeal, and data-request records: retained for the period we must be able to demonstrate accountability, because deleting the record of a decision would defeat the purpose of logging it. These records are minimised and are not used to build a profile of you.

11. Your rights

The PDPL gives you rights over your personal data, and the platform implements them as working features rather than as an email address to write to. From your data-rights screen you may:

  • Be informed: this policy, and the explanation shown with every automated result.
  • Access: request confirmation of what we hold about you.
  • Obtain a copy: request your data in a readable, portable form.
  • Request correction: ask us to rectify data that is inaccurate, incomplete, or out of date.
  • Request deletion: ask us to erase your personal data where we have no overriding legal reason to retain it.
  • Withdraw consent: for any purpose you previously allowed.
  • Object to a solely automated decision, and require human review, as set out in the Responsible AI Policy.

12. Complaints

If you believe we have handled your personal data unlawfully, contact us first at info@fursah.org so that we can investigate. You also have the right to lodge a complaint directly with the Saudi Data & Artificial Intelligence Authority (SDAIA) as the competent supervisory authority, and doing so does not require you to come to us first.

13. Security

We apply role-based access control, encrypted transport, private storage for evidence files, and audit logging of consequential actions. Access to personal data within Fursah is restricted to the role that needs it for a defined purpose.

No system is perfectly secure. If a personal-data breach occurs that is likely to cause harm, we will notify SDAIA and affected individuals in accordance with the notification periods set out in the Implementing Regulations.

14. Children

Fursah is built for university-level students and adult professionals and is not directed at children. We do not knowingly create accounts for individuals below the age of majority without the verified consent of a guardian. If we learn that we hold such an account without proper authority, we will delete it.

15. Changes to this policy

We version this policy and record the version against your consent choices, so that it is always possible to establish which text you agreed to. Where a change materially affects how we use your data, we will notify you and, where the change requires it, ask for fresh consent rather than relying on the old one.

16. Prototype status

Fursah is currently a prototype. Parts of the platform run on demonstration data, and some figures displayed in the interface are illustrative rather than measured. This policy describes how we handle real personal data wherever the platform processes it, and we have not softened any statement on the basis that the system is a prototype.