Privacy Notice
Effective / last reviewed: 9 August 2026 · Beta policy baseline; formal legal review remains required before unrestricted public launch.
1. Who controls your personal data
Execivon is a product and brand of Urban Solutions Valley Ltd.. This notice describes personal-data processing for the Execivon website and application. For privacy requests use the form below.
2. What we collect
Depending on how you use Execivon, we may process account and contact data, authentication/security records, subscription and payment metadata, user preferences, support communications, uploaded content, generated artifacts, workflow/execution records, integration configuration, consent records, and limited website preview analytics. Execivon is designed to avoid collecting personal data that is not necessary for a defined purpose.
3. Why we process it
4. Consent and marketing
Where consent is used, Execivon records the choice and its context. Marketing consent is separate from the acceptance needed to create/use the service. Users may withdraw marketing consent using the unsubscribe mechanism or privacy request process. Withdrawal should be as easy as giving consent.
5. AI and connected providers
Execivon may send the minimum task context needed to configured AI or infrastructure providers to perform requested functions. Public product pages describe the Execivon AI Engine at a functional level; internal model-routing, system prompts, cost logic and proprietary orchestration are not public. The actual provider/subprocessor register must be maintained by the Product Owner and updated before production use.
6. Sharing, processors and international transfers
Personal data may be processed by service providers needed to operate Execivon, subject to applicable agreements and safeguards. Where personal data is transferred outside Saudi Arabia, the Product Owner must assess and document the applicable PDPL transfer requirements and safeguards before enabling that processing path. Execivon does not claim that every future integration is approved for every jurisdiction.
7. Retention and deletion
Data is retained for defined operational, contractual, legal, security and backup purposes. Retention periods must be documented in the internal retention schedule and enforced by deletion/archival jobs. Account deletion does not automatically override records that must lawfully be retained.
8. Your rights
Subject to applicable law and verification, individuals may request access, correction, deletion/destruction, a copy/export, withdrawal of consent, or raise another privacy concern. Execivon must verify requests before disclosing or altering personal data.
9. Security
Execivon is designed around authenticated access, role/tenant isolation, encrypted transport, protected credentials, auditability, controlled external actions, backup/recovery and secure development practices. Security controls are described as implemented/readiness measures; Execivon does not claim certifications or regulatory approval unless formally achieved.
10. Submit a privacy request
Saudi regulatory baseline used for readiness
Product implementation should be assessed against the Saudi Personal Data Protection Law and Implementing Regulation, including purpose-specific/free consent, consent records and withdrawal, direct-marketing requirements, data minimization, data-subject rights and transfer requirements. These references guide readiness; they are not a certification statement.