Privacy Policy
How Formeets collects, uses, and protects your data — and the choices and rights you have under the Saudi Personal Data Protection Law (PDPL).
In short
We run ForMeets, a platform that schedules meetings, records and transcribes them, and uses AI to draft notes, summaries, and action items. This policy explains what we collect and why, your choices, and your rights under the Saudi Personal Data Protection Law (PDPL). We do not sell your data, we do not use it to train AI models, and we host all data in Saudi Arabia.
1. Who controls your data
For meeting content (recordings, transcripts, notes, tasks), the organisation that uses ForMeets is the controller and NGN only processes it on that organisation’s instructions (see our DPA). For account, billing, and website data, NGN is the controller. If you are a meeting participant or guest, contact the host organisation to exercise your rights over meeting content.
2. What we collect
- Account: name, work email, password (hashed), role, language, organisation/workspace.
- Meeting content: audio and (if enabled) video recordings, transcripts, speaker labels, notes, summaries, agendas, tasks, attendance, and files.
- Voice data: because we transcribe speech and label speakers, we process voices. This may count as sensitive data, so we handle it with extra care.
- Usage and technical: IP address, device/browser, app activity, and logs.
- Audit: security and governance logs (who did what, when, and from which IP).
- Billing: plan and invoice details for paid, self-serve customers (card data is handled by our payment provider).
3. Why we use it
To provide and secure the Service, sync your devices, send notifications, support you, handle billing, improve the product (using aggregated or de-identified data), and meet legal duties. Our legal bases under the PDPL are mainly performance of a contract, your or your organisation’s consent, our legitimate interests, and legal obligations.
4. AI and recording
- AI drafts only. AI writes drafts of minutes, summaries, and action items. A person must review and approve them before they are final. AI can make mistakes, so check it.
- No AI training on your data. We do not use your content (recordings, transcripts, or anything else) to train, retrain, or fine-tune AI models. Our AI providers are contractually banned from using it to train their models. An organisation can also turn AI features off.
- Recording consent is the organiser’s job. The customer and the meeting organiser are responsible for recording lawfully. Before recording, the organiser must tell all participants that the meeting is recorded, transcribed, and processed by AI, and get their consent — including from external guests. A recording indicator is shown when recording is on.
5. Where your data is hosted
We host all Customer Data in the Kingdom of Saudi Arabia, in the Riyadh region of Huawei Cloud (Middle East). We do not transfer personal data outside the Kingdom. If a customer’s specific requirements need a service that must run outside the Kingdom, we will do so only on that customer’s instructions and in line with the PDPL and the Regulation on Personal Data Transfer Outside the Kingdom.
6. Who we share it with
Only with: service providers that help us run ForMeets (hosting, AI, email) under confidentiality terms; identity and integration providers you connect (Google, Microsoft, Zoom, Jira); and authorities where the law requires. We do not sell your data or use it for advertising. Our sub-processor list is in the DPA.
7. How long we keep it
- Meeting records: as long as your organisation’s settings say. Cancelled or deleted meetings sit in Trash for 30 days, then are deleted.
- Audit logs: at least 180 days (configurable).
- Account data: we delete or anonymise your personal account data within 30 to 90 days after your account closes, unless the law requires us to keep it longer.
8. Your rights
Under the PDPL you can: be informed, access and get a copy of your data, correct it, ask us to delete it, withdraw consent, and object to certain uses. ForMeets also lets you export or delete your account data in your profile. To use these rights, email support@formeets.com (for account data) or the host organisation (for meeting content). You can also complain to SDAIA.
9. Security
We protect data with encryption in transit and at rest, role-based access, password hashing and account lockout, tenant isolation, and tamper-resistant audit logs. No system is perfectly secure, but we work to recognised standards.
10. Breaches
If a reportable breach happens, we will notify SDAIA within 72 hours where required, tell affected organisations without undue delay, and inform individuals if there is a risk of serious harm.
11. Children
ForMeets is for organisations and their adult staff and guests. It is not for children, and you must be at least 18 to use it.
12. Changes and contact
We may update this policy and will post the new date; we’ll give extra notice for major changes. Questions: support@formeets.com.