LEGAL
Privacy Policy
How stageOS by Safira handles personal data across stagePassport, stageEvents, stageVendors and matchmaking — under the Saudi PDPL first, and under the GDPR, UK GDPR and US state privacy laws where they apply.
LAST UPDATED 12 AUGUST 2026
01Who we are and how to reach us
stageOS by Safira operates stagePassport, stageEvents, stageVendors and the matchmaking engine described on this site. In this policy "we", "us" and "stageOS" mean stageOS by Safira.
For personal data processed through our own website and our own commercial relationships we act as the controller. When we run an event platform for a client — an organiser, ministry, authority or venue — that client is the controller and we act as their processor, under a written agreement that limits us to their documented instructions.
Privacy questions, access requests and complaints: hello@stageos.ai. We answer every request from the same address, whether it reaches us under the PDPL, the GDPR or another regime.
02The data we collect
We collect only what a matching decision, an access decision or a commercial conversation actually requires. Categories differ by surface.
- Delegate and attendee data (stagePassport): name, organisation, role, sector, languages, objectives for the event, meeting availability, and the meetings you accept or decline.
- Organiser and vendor data (stageEvents, stageVendors): contact details of named staff, company registration and trade details, service categories, commercial terms and delivery records.
- Matchmaking inputs: the structured profile fields above, plus the verification state of a profile and the outcome of each proposed meeting. Free-text objectives are used as written; we do not infer sensitive characteristics from them.
- Website data: pages requested, referring page, approximate location derived from IP, device and browser type, and language preference.
- Contact form data: name, work email, organisation, role and the brief you send us.
03Why we process it, and on what legal basis
Under the PDPL we rely on your consent, on the performance of a contract to which you are party, on our legitimate interests where the PDPL permits them, and on compliance with a legal obligation. Where the GDPR or UK GDPR applies we rely on the equivalent bases in Article 6.
- Running the event you registered for, issuing your passport and admitting you on site — performance of a contract.
- Proposing meetings and producing a match set — performance of a contract with the organiser, and your consent where the organiser's programme is optional.
- Verifying an organisation or a vendor before it is proposed to a counterparty — legitimate interests in preventing fraud and misrepresentation.
- Measuring outcomes of a programme (meetings held, deals reported, SME participation) — legitimate interests, reported to the organiser in aggregate.
- Answering a message you send us and following up commercially — consent and legitimate interests.
- Security, audit logging, tax and statutory record-keeping — legal obligation.
04Data & PDPL: residency, transfers and sovereignty
Saudi Personal Data Protection Law (Royal Decree M/19 of 1443H, as amended) and its Implementing Regulations govern personal data collected in the Kingdom. Residency is a build requirement for us, not a deployment afterthought: personal data from Saudi programmes is hosted in KSA-sovereign regions, and where residency, retention or access cannot be satisfied, the feature does not ship.
Transfers outside the Kingdom happen only where the PDPL permits them and only for a defined purpose, under the transfer conditions and risk assessment required by the Implementing Regulations. We do not transfer Saudi delegate data to a third country to make a general-purpose model work.
Where a matching decision requires a model, it operates on the structured fields described above inside the same sovereign boundary. Personal data is never used to train third-party foundation models, and free-text objectives are not sent to third-party model providers for training.
For delegates and clients outside the Kingdom, transfers into KSA or between our regions are covered by the appropriate safeguards under the GDPR or UK GDPR — standard contractual clauses, the UK addendum, and a transfer risk assessment — available on request.
SDAIA is the competent supervisory authority in the Kingdom. You may complain to SDAIA at any time; we would ask you to raise it with us first at hello@stageos.ai so we can fix it faster.
05Retention
We keep personal data only for as long as the purpose it was collected for is live, plus any period a law or a client contract requires.
- Event and passport data: for the duration of the event programme and up to 12 months after it closes, unless the organiser's contract specifies a shorter period.
- Matchmaking inputs and meeting outcomes: up to 24 months, so year-on-year programme measurement is possible; profiles are pseudonymised at the end of that period.
- Contact-form and commercial correspondence: up to 24 months from the last contact.
- Records we must keep for tax, accounting or statutory audit: for the period set by the applicable law.
- When a client relationship ends we return or delete the personal data we processed on their behalf, at their election, subject to those statutory retention periods.
07Your rights
Under the PDPL you have the right to be informed, the right to access your data, the right to request a copy in a readable format, the right to correct or complete it, and the right to request its destruction. Where the processing rests on consent, you may withdraw that consent at any time without affecting processing already carried out.
Under the GDPR and UK GDPR you additionally have rights to erasure, restriction, portability, objection — including to processing based on legitimate interests — and the right not to be subject to a decision based solely on automated processing that produces a legal or similarly significant effect.
Residents of California and other US states with comprehensive privacy laws may request access, correction, deletion and portability, and may opt out of sale or sharing. We do not sell or share personal data as those terms are defined.
To exercise any right, email hello@stageos.ai. We respond within 30 days and will tell you if we need to verify your identity first. Exercising a right never costs you anything and never degrades the service you receive.
08Matchmaking and automated decision-making
Matchmaking is deterministic and auditable. A proposed meeting is the output of a scored objective function with hard constraints — language, verification state, competitive exclusion and stated availability — applied as gates, not preferences. Every proposal can be explained in terms of the inputs that produced it.
No automated output admits you to an event, denies you entry, prices anything or makes any other decision with a legal or similarly significant effect on you. Organiser staff review and can override any proposed match, and you can decline any meeting without giving a reason.
If you want the reasoning behind a specific proposal, ask us and we will provide it.
10Security
Access to personal data is role-scoped and least-privilege, authenticated per user, and logged. Data is encrypted in transit and at rest by the platform layer. Production access is limited to named engineers and reviewed periodically.
No system is beyond compromise. If a personal data breach occurs we notify SDAIA and, where required, affected individuals, within the periods set by the PDPL Implementing Regulations, and we notify our clients without undue delay so they can meet their own obligations. To report a suspected vulnerability or incident, email hello@stageos.ai.
11Children
Our platforms are built for professional event programmes and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child's data has reached us, tell us and we will delete it.
12Changes to this policy
We update this policy when the platform changes or the law does. The date at the top of the page always reflects the current version. Where a change materially affects how we handle your personal data, we notify you directly or through the event platform before it takes effect.
Questions about this document, or a request relating to your data: hello@stageos.ai. This document is provided for transparency and is not legal advice; it is reviewed periodically and updated as the platform and applicable law change.
