Skip to content
ProjectFlow
Legal Terms DPA Sub-processors
Legal Terms DPA Sub-processors
Back to the site
Back to the site

On this page

  1. 1. The short version
  2. 2. Two different roles
  3. 3. Who we are
  4. 4. What we collect
  5. 5. Why, and on what basis
  6. 6. Cookies and tracking
  7. 7. Who else can see it
  8. 8. Where your data is stored
  9. 9. How long we keep it
  10. 10. Your rights
  11. 11. Security
  12. 12. Automated decisions and AI
  13. 13. Children
  14. 14. Changes
  15. 15. Contact and complaints

Privacy Notice

Effective 12 September 2026 Version 1.2 SMR Future Technologies

This notice explains what personal data we hold, why we hold it, and what you can do about it. It is written to be read. Where the honest answer is less flattering than the one you might expect — such as where your data physically sits today — we have said the honest one.

1. The short version

  • We collect the minimum needed to run your account and the Service: who you are, what company you work for, what you did in the product, and what you paid.
  • We do not sell your data. We do not share it with advertisers, and we do not use it to train AI models.
  • We load no third-party analytics or advertising scripts on this website or in the product today.
  • You can export everything and delete your workspace yourself, from inside the product, without asking us.
  • Our infrastructure currently runs in the AWS US East (N. Virginia) region — see section 8, which explains what that means and what we are doing about it.

2. Two different roles

We handle personal data in two capacities, and it matters which one applies, because the rights and the responsible party differ.

DataExampleOur roleGoverned by
Account Data Your administrator's name and email, your company registration details, billing records, support tickets Controller — we decide why and how it is processed This notice
Customer Data Personal data inside your projects: a subcontractor's contact, a site engineer named on a purchase order, a signatory on a contract Processor — we act on your instructions only The DPA; your own privacy notice governs those individuals

If you are an employee of one of our customers and you want to know what your employer holds about you in ProjectFlow, ask your employer — they are the controller of that data, not us. We will support them in answering you.

3. Who we are

The controller of Account Data is SMR Future Technologies, a business established in India. Our registration details and registered address are available on request.

We are not established in Saudi Arabia. The Saudi PDPL still applies to us, because it reaches the processing of personal data of people in the Kingdom wherever the processor sits, and this notice is written to it. Indian data protection law applies to us as well, as the country we are established in.

For any privacy question, contact us at info@smrfuturetechnologies.com.

4. What we collect

4.1 When you create a workspace

  • About you: first name, last name, work email address, and a password (stored only as a salted hash — we never see or store the password itself).
  • About your company: legal company name, the workspace subdomain you choose, commercial registration number, VAT registration number, your role, and your team size.
  • Your plan choice and the trial start and end dates.

4.2 When you use the Service

  • Authentication and session records: sign-in events, two-factor enrolment status, session and recovery tokens (stored hashed), and IP address and user agent at sign-in.
  • An operational audit log: what action was taken, by which account, against which record, and when. This exists so that a disputed change to a commercial figure can be traced, and it is also what protects you if an account is misused.
  • Consent records: what you have consented to and when, including withdrawals — we are required to be able to demonstrate this.

4.3 Billing

  • Subscription tier, billing cycle, status, renewal dates, plan changes, and invoice history.
  • An identifier issued by our payment provider that links your subscription to their record.

We do not receive or store your full card number. Card details are entered directly with our payment provider and never reach our systems.

4.4 Support and communications

  • Support tickets and their correspondence, including anything you choose to put in them.
  • Any feedback you submit.
  • Emails we send you about your account, and whether they were delivered.

4.5 Self-hosted deployments

If you run ProjectFlow on your own servers under a licence, the licensing service receives periodic check-ins confirming entitlement — the licence identifier, the version in use and basic operational counters. These check-ins do not carry your Customer Data.

5. Why, and on what basis

We process personal data under the Saudi Personal Data Protection Law (PDPL) and its implementing regulations.

PurposeData usedBasis
Providing the Service you signed up forAccount, company, authenticationPerformance of the contract with you
Billing and collecting paymentBilling, company registration, VAT numberPerformance of the contract; legal obligation for tax records
Security, fraud prevention and abuse detectionSign-in records, IP address, audit logLegitimate interests — keeping accounts and other customers safe
SupportTickets, contact detailsPerformance of the contract
Service emails (security alerts, billing, changes to terms)Contact detailsPerformance of the contract; legal obligation
Marketing emails about the productContact detailsConsent — withdrawable at any time, with no effect on your service
Improving the productAggregated, non-identifying usage informationLegitimate interests
Complying with law and defending legal claimsAs requiredLegal obligation; legitimate interests

Work still outstanding, stated rather than implied. Where we rely on legitimate interests, the PDPL expects a documented assessment weighing that interest against your rights. We have not yet completed and recorded those assessments. We are saying so here instead of writing a sentence that implies we have — and we will update this notice when they exist.

6. Cookies and tracking

This marketing website sets no cookies and loads nothing from a third party. There is no analytics script, no advertising pixel, no embedded font from an external CDN, and no tracker. The only thing stored in your browser here is any preference you set on the page itself.

In the product, we use one category of cookie and no other:

  • Strictly necessary cookies — to keep you signed in and to protect against cross-site request forgery. These cannot be turned off, because the Service does not work without them, and they require no consent.
  • Nothing optional — no analytics cookie, no advertising cookie, no conversion pixel, no third-party tag manager. There is no optional category to accept or reject, so we do not ask you to.

We removed a consent banner that asked for nothing real. An earlier version of this notice recorded that our banner offered "Analytics" and "Marketing" toggles while no such technology was loaded, and that we would remove them. They are removed. In their place is a one-off notice saying that only strictly necessary cookies are in use; dismissing it stores nothing but the fact that you saw it. Nowhere are you asked to accept or reject an optional category, because there is not one. If we ever introduce optional technology we will name the provider here and on the sub-processor page, with at least 30 days' notice before it is switched on, and it will not load unless you have actively consented — with a way to withdraw that consent as easily as you gave it.

7. Who else can see it

We share personal data only with:

  • Sub-processors who help us run the Service — hosting, email delivery, payment processing. The current list, what each does and where each is located, is published at /legal/subprocessors/.
  • Professional advisers — lawyers, accountants, auditors — under confidentiality, where needed.
  • Authorities, where we are legally required to. We will tell you first unless we are legally prohibited from doing so.
  • A successor, if the business is sold or merged. You will be told before your data is transferred, and this notice continues to apply until you are given a new one.

We do not sell personal data, and we never have. We do not share it with advertising networks or data brokers.

8. Where your data is stored

Today, our infrastructure runs in the Amazon Web Services US East (N. Virginia) region, in the United States, and our transactional email is sent from the same region. Separately, our own team is in India, and administers and supports the Service from there. Both are transfers of personal data outside the Kingdom of Saudi Arabia, and you should treat them as two distinct ones when assessing us.

We are stating this plainly because it matters to a Saudi buyer and because the honest answer differs from what you might assume from a product built for this market. Moving the platform to a Saudi region is on our roadmap; it has not happened yet, and we will not describe it as done before it is.

Under the PDPL and the Data Transfer Regulations, a transfer of this kind needs a recognised basis — an adequacy determination covering the destination, or an approved safeguard such as the standard contractual clauses issued by SDAIA — together with a documented transfer risk assessment, and minimisation of what is sent.

We have not completed that yet, and we are not going to pretend otherwise. We have not executed SDAIA standard contractual clauses with our hosting provider, and we have not written the transfer risk assessment. Our hosting contract carries the provider's standard European clauses, which are not a PDPL transfer mechanism.

This is the single largest open item on our compliance list and it is being worked on. If you are evaluating us and cross-border transfer is material to you — for most Saudi contractors it should be — ask us where this stands before you subscribe, and treat this paragraph as the honest answer rather than the marketing one.

If cross-border transfer is unacceptable for your organisation, tell us before you sign up. A self-hosted deployment, where your Customer Data stays on infrastructure you control, is the route that actually solves it, and we would rather discuss that with you than have you discover this section afterwards.

9. How long we keep it

DataRetention
Workspace and Customer DataFor as long as your subscription is active. On account deletion: a 30-day recoverable suspension, then the site is torn down. Where a subscription lapses through non-payment instead, that window is 60 days.
The torn-down site itselfArchived, not erased, at teardown. Reclaiming the storage is a separate operator step, so an archived copy exists for a period afterwards. This is deliberate, so that a teardown caused by our own billing error stays recoverable.
Account recordNot deleted as a row — the personal data in it is anonymised, because invoices must remain attached to it for tax audit.
Billing and tax recordsRetained for the period Saudi tax and commercial-books law requires, even after your workspace is gone. We cannot delete these on request.
Operational audit logRetained for security and legal-compliance purposes. When a user is deleted the actor reference is cleared, but the record still contains the action, the target record reference and a timestamp — so it is pseudonymised, not anonymised. We are stating that precisely because the difference matters under the PDPL.
Consent recordsRetained while we need to demonstrate the consent, and for a reasonable period after withdrawal.
Support ticketsRetained under a defined sweep and deleted when it expires.
BackupsRolling, overwritten in the ordinary course. A deletion runs against live systems immediately and works through backups as they cycle.

10. Your rights

Under the PDPL you have the right to:

  • Be informed — of what we collect and why. That is what this notice is for.
  • Access — ask what personal data we hold about you.
  • Obtain a copy — of your personal data, in a readable and clear format.
  • Correct — have inaccurate or incomplete data put right.
  • Request destruction — where we no longer need it, or where you withdraw the consent it depended on. Some records we must keep by law, and we will say which.
  • Withdraw consent — at any time, where consent is the basis. Withdrawing marketing consent never affects your service.

Three of these you can exercise yourself, immediately, without contacting us. The Privacy page inside the product lets you export a complete archive of your workspace (delivered as a signed download link valid for 24 hours), start the deletion flow, and see your consent record with controls to grant or withdraw each consent.

For anything else, email info@smrfuturetechnologies.com. We will respond within 30 days of receiving your request. If it is complex, or if you have made repeated requests, we may extend that once and will tell you within the first 30 days that we have done so and why. We do not charge for a reasonable request. We may need to verify your identity first — that is a protection for you, not an obstacle.

11. Security

Measures we actually have in place:

  • Encryption in transit (TLS) on every public endpoint, with HTTP redirected to HTTPS.
  • Encryption at rest on stored data and backups.
  • Passwords stored only as salted hashes; session and recovery tokens stored hashed.
  • Optional two-factor authentication, with recovery codes.
  • Server-side permission enforcement — the interface never decides what you may see; where a figure cannot be shown to a user it is shown as unavailable rather than as a zero.
  • Tenant isolation: each customer's workspace is a separate tenant.
  • Rate limiting on authentication and one-time-password endpoints.
  • An operational audit log of changes.
  • Administrative access limited to the people who need it, with sensitive operations requiring a second approver.
  • Automated secret scanning in our development process to keep credentials out of source code.

No system is perfectly secure. If a personal data breach occurs, we will notify the competent authority within the period required by law — 72 hours of becoming aware, under the current rules — and will notify affected individuals without undue delay where the breach is likely to cause them serious harm. Where we act as your processor, we will notify you without undue delay so that you can meet your own obligations.

We hold no third-party security certification. We are not ISO 27001 certified and have not completed a SOC 2 audit. We would rather say so than imply otherwise. If your procurement process requires one, tell us and we will be straight with you about the timeline.

12. Automated decisions and AI

We do not make decisions producing legal or similarly significant effects about you by automated means alone.

The Service already suggests links between BoQ lines using rule-based matching, for a person to accept or ignore. The AI features we are developing will generate suggestions too — a form field read from a scanned document, a rate, a search result, lines matched by meaning — and none of them is available yet. They will be grounded in your own workspace, search answers will cite the documents they drew from, and any suggestion may be wrong. We do not use your data to train AI models, and where we engage a model provider we will contract for the same.

13. Children

ProjectFlow is business software and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe we have, tell us and we will delete it.

14. Changes

We will update this notice when our practices change. The effective date at the top always reflects the current version. For a change that materially affects your rights we will notify workspace administrators by email at least 30 days in advance, and we keep prior versions available on request.

15. Contact and complaints

SMR Future Technologies, India
Email: info@smrfuturetechnologies.com
Registered address and registration numbers: on request.

Please raise a concern with us first — we would rather fix it than have you escalate. If you are not satisfied with our response, you have the right to complain to the Saudi Data & Artificial Intelligence Authority (SDAIA), the competent supervisory authority for personal data in the Kingdom.

Related documents: Terms of Service · Data Processing Addendum · Sub-processors

© 2026 SMR Future Technologies. All rights reserved. Terms · Privacy · DPA · Sub-processors