Privacy Notice — Madar Platform
مسودة — تتطلب مراجعة مستشار قانوني مرخّص في المملكة (Draft — requires review by a lawyer licensed in the Kingdom of Saudi Arabia)
Item Value Version 2026-09-25.1Date 2026-09-25 Counterpart privacy-notice.ar.md— the Arabic text prevails in case of conflictLegal basis Personal Data Protection Law (Royal Decree M/19 dated 9/2/1443H, as amended by M/148 dated 5/9/1444H), its Implementing Regulations and the Regulation on Personal Data Transfer outside the Kingdom Fields in
[...]are completed by the client before publication. ⚠️ marks an item requiring counsel confirmation.
1. Who we are (Controller)
Madar is operated by:
| Field | Value |
|---|---|
| Legal name | Lemonada Core [full legal name as per CR] |
| Commercial Registration No. | [__________] |
| Unified No. (700) | [__________] |
| National Address | [building no., street, district, city, postal code, additional no.] |
| Privacy email | privacy@[domain] |
| Data Protection Officer | [name] — dpo@[domain] — [phone] |
| National Data Governance Platform registration | [added after SDAIA registration] |
We are the controller of your personal data under the Personal Data Protection Law ("PDPL").
2. Scope
This notice covers landing-page visitors (including conversations with the "Madar Guide"), applicants and trainees (CV upload, voice interview, admission, job simulation), and partner-company representatives and reviewers (account data only).
Madar is for users aged 18 or over. We do not accept applications from minors and delete any such data without delay once identified.
3. Data we collect
| Category | Examples | Source | Sensitive? |
|---|---|---|---|
| Account & contact | display name, email, mobile, preferred language | you | no |
| Application | chosen track, education, requested seat | you | no |
| CV | PDF/DOCX file and extracted text | you | not by default — may contain sensitive data you volunteer (3.1) |
| AI analysis results | skills summary, track-fit indicators, generated interview questions | us (automated) | no |
| Voice | your voice during the interview or guide conversation (processed in real time, not stored) and the resulting transcript | you | treated as sensitive (3.2) |
| Interview evaluation & recommendation | rubric scores, evidence quotes, non-binding recommendation | us (automated + human reviewer) | no |
| Admission decision | admitted / waitlisted / not admitted, short reason | human reviewer | no |
| Simulation data | in-game decisions, messages to characters, deliverables, skill indicators, readiness report | you and us | no |
| Technical | IP address, device/browser, security logs, reCAPTCHA score | automated | no |
| Consent log | purpose, version, timestamp, grant/withdrawal | automated | no |
3.1 Sensitive data that may appear in a CV
We never ask for ethnic or tribal origin, religion, health, marital status, exact age, gender, nationality or criminal record, and recommend you remove them before uploading. If present, our system pseudonymizes your name and identity markers before analysis and blocks such attributes from analysis, scoring and recommendations.
3.2 Why we treat voice as sensitive
A voice can identify a person and may technically be used as biometric data. We do not use it to identify you, but as a precaution we apply sensitive-data standards: separate explicit consent, no storage of raw audio, transcripts only.
4. Purposes and legal bases
| # | Purpose | Data | Legal basis | Consent id |
|---|---|---|---|---|
| 1 | Account and application management | account, application | performance of a contract you are party to (Terms) | — |
| 2 | Receiving and storing your CV | CV | consent | cv_processing |
| 3 | AI analysis of the CV and generation of interview questions | CV, application | explicit consent (automated processing supporting a significant decision) ⚠️ | ai_analysis |
| 4 | Voice interview with the virtual guide and transcript evaluation | voice (real time), transcript | explicit consent (data treated as sensitive) | voice_interview |
| 5 | Processing by providers outside the Kingdom | see §7 | consent + statutory safeguards (PDPL Art. 29, Transfer Regulation) | cross_border |
| 6 | Sharing your profile and readiness report with the partner offering the seat | application summary, evaluation, readiness report | consent | share_with_partner |
| 7 | Running the simulation and issuing the readiness report | simulation data | performance of contract | — |
| 8 | Security, abuse and fraud prevention | technical | legitimate interest / legal obligation ⚠️ | — |
| 9 | Service improvement using aggregated, de-identified statistics | aggregated | legitimate interest (after de-identification) | — |
We do not sell your data, do not use it for marketing without separate consent, and do not allow AI providers to train their models on it.
5. AI and human decision-making
- We use Google Gemini models to analyse CVs, conduct the interview and evaluate transcripts against pre-published rubrics.
- The "Madar Guide" is an AI-generated character, not a human, disclosed by a persistent on-screen badge and a spoken statement at the start of each conversation.
- Evaluation runs twice independently; material divergence is escalated to a human.
- AI recommends, it does not decide. The recommendation contains no accept/reject field; a human reviewer makes the admission decision, sees the evidence and may overrule the recommendation.
- Initial review is performed on a pseudonymized profile (no name).
- You may at any time request an explanation of the evaluation logic, object to the outcome, and request a full fresh human review (§9).
- A text alternative to the voice interview is always available, with no effect on your chances.
6. Recipients
| Recipient | Data | Role | Condition |
|---|---|---|---|
| Authorized Madar staff | need-to-know by role | bound by confidentiality | RBAC + audit log |
| Partner company offering the seat | application summary, evaluation result, readiness report — raw CV file or full transcript only if the consent says so | independent controller ⚠️ | only with your explicit share_with_partner consent, per partner |
| Google Cloud (Google LLC and affiliates) | hosting, database, storage, Gemini, speech-to-text, text-to-speech, reCAPTCHA, identity | processor | DPA + contractual clauses |
| HeyGen, Inc. (avatar fallback) | the guide's generated text/audio for face animation — does not receive your voice in the approved mode | processor | enabled only if primary provider fails |
| LiveKit, Inc. (audio transport fallback) | real-time audio stream | processor | not enabled for real cohorts until assessment is complete |
| Competent authorities | as legally required | — | legal obligation or court order |
7. Transfers outside the Kingdom
At this stage the platform is hosted in the United States (Google Cloud us-central1, Iowa); real-time audio is processed by Google in the same region.
Safeguards: (1) SDAIA Standard Contractual Clauses (controller-to-processor) or equivalent per the Transfer Regulation ⚠️; (2) a written pre-transfer risk assessment (cross-border-assessment.md); (3) data minimization — name pseudonymized before analysis, no raw audio stored; (4) TLS in transit and encryption at rest (CMEK for CVs); (5) model-training use disabled and provider-side input retention minimized; (6) a plan to move to an in-Kingdom region (Google Cloud Dammam me-central2, operated via CNTXT) before any real trainee cohort, or a documented legal justification to continue.
You may withdraw cross_border consent at any time; services that depend on offshore processing may then be unavailable until migration.
8. Retention
| Data | Period | Then |
|---|---|---|
| Raw audio (interview and guide) | not stored — in-memory real-time processing only | — |
| Landing-page guide transcripts | 30 days | automatic deletion |
| CV (file and extracted text) | 180 days from upload | automatic deletion |
| Interview (transcript, evaluation, recommendation) and admission decision | admission cycle + 6 months | deletion or de-identification |
| Simulation sessions and readiness reports | 12 months from last activity | automatic deletion |
| Account data | while the account is active | deleted on closure |
| Consent log and audit logs | [period] ⚠️ to demonstrate compliance | secure deletion |
| Aggregated de-identified statistics | indefinite | not personal data |
9. Your rights
- To be informed (this notice).
- Access and a copy of your data in a readable, clear format.
- Correction, completion or update.
- Destruction (deletion) when no longer needed or consent is withdrawn, unless retention is legally required.
- Withdraw consent at any time, per purpose, as easily as it was given (Privacy page in your account); withdrawal does not affect prior lawful processing.
- Object to automated decision-making and obtain human review: although admission decisions are human, you may request a fresh review by a different reviewer and an explanation of the criteria and evidence.
How: "My privacy" page in your account or privacy@[domain]. We verify your identity and respond within 30 days (extendable as permitted by the Regulations, with reasons) ⚠️. Free of charge.
10. Security
Encryption in transit and at rest; secrets in Secret Manager; role-based access and MFA for admin/reviewer accounts; audit trail for access to CVs and evaluations; time-limited partner demo links; no CV contents or personal data in system logs.
11. Breach notification
We notify the Saudi Data & AI Authority (SDAIA) within 72 hours of becoming aware of a breach that may harm the data or data subjects, and notify you without undue delay where the breach may harm you, explaining what happened, what we did and what you can do.
12. Complaints
Contact our DPO first at dpo@[domain]. You may lodge a complaint with SDAIA, the competent authority, via its online portal within the period set by the Implementing Regulations ⚠️ (secondary sources cite 90 days from the incident — to be verified).
13. Changes
We display the version and date at the top, notify you before material changes, and request fresh consent where a consent-based purpose changes.
References
- PDPL and Implementing Regulations — SDAIA: https://sdaia.gov.sa/ar/SDAIA/about/Pages/RegulationsAndPolicies.aspx
- SDAIA Guide to the PDPL for controllers/processors (sensitive data incl. biometrics used for identification; explicit consent IR Art. 11): https://dgp.sdaia.gov.sa/wps/wcm/connect/f579bc32-fda8-47bd-bc6f-66b8cb77985c/ENG-Guide+to+the+saudi+PDP+law+for+controllersprocessors.pdf?MOD=AJPERES
- National Data Governance Platform: https://dgp.sdaia.gov.sa
- SDAIA Standard Contractual Clauses: https://dgp.sdaia.gov.sa/wps/portal/pdp/knowledgecenter/details/StandardContractualClauses/
- Transfer Regulation overview (Securiti): https://securiti.ai/regulation-on-personal-data-transfer-outside-the-kingdom/
- 72-hour breach notification (Baker McKenzie): https://connectontech.bakermckenzie.com/saudi-arabia-publishes-guidance-on-data-breach-notification/
- Data subject request timing: https://www.lexology.com/library/detail.aspx?g=8a6b6775-f652-4d5f-a8cd-af7676e4718b
- Vertex AI data governance: https://cloud.google.com/vertex-ai/generative-ai/docs/vertex-ai-zero-data-retention
Items for counsel ⚠️
- Partner status (independent vs joint controller) and the data-sharing agreement.
- Legal basis for purpose 8 (security).
- Retention for consent and audit logs.
- Exact complaint deadline and response-extension period.
- Whether explicit consent is strictly required for automated processing where the final decision is human (we took the conservative approach).