Privacy Policy
How Quality Stability Co. collects, uses, and protects personal data in the QSCO platform.
Clause 1: Introduction
Quality Stability Co. ("QSCO", "we") operates a compliance platform for food establishments in the Kingdom of Saudi Arabia, and is the controller of the personal data described here. This policy explains what personal data we process, why we process it, how long we keep it, and what rights you have under the Saudi Personal Data Protection Law (PDPL). It applies to the QSCO platform, to its establishment, inspector, and administrator portals, and to this website.
Clause 2: Personal data we collect
We collect only what the platform needs in order to operate. The categories below reflect what the system actually stores.
- Account and identity
- Your name, email address, and mobile number, together with your role and the time you last signed in. We never store passwords — only an irreversible bcrypt hash.
- Establishment details
- Your establishment's name, commercial registration number, tax number, city, and contact email and phone number.
- Inspector identity (KYC)
- For inspectors only: national ID number, date of birth, national ID expiry date, and municipality health certificate expiry date, along with a copy of the national ID and a personal photograph. The national ID number is encrypted at rest, and is additionally stored as an irreversible keyed hash so that the same ID cannot be registered twice.
- Location during visits
- For inspectors only, and only while a visit is in progress: your device reports its GPS position roughly every 30 seconds, along with the accuracy of that reading and whether you were inside the branch geofence. If any reading falls outside the geofence, the visit is flagged as having a location deviation. Each evidence photograph is also tagged with the position at which it was captured. Clause 5 describes this in full.
- Payment details
- Card numbers and security codes never reach our systems — they are entered directly with our payment provider. We store only an encrypted payment token for renewals, plus the card brand, its last four digits, and its expiry month and year.
- Documents and photographs
- Files you upload — commercial registration certificates, establishment logos, identity documents — and the photographic evidence captured during visits.
- Messages and notes
- Free text written inside the platform: the subject and replies of visit tickets, notes an inspector adds when submitting a visit, and notes an administrator adds to a visit, which the assigned inspector can read. Ticket replies form part of the visit record and are not deleted once posted.
- Technical records
- When you accept a subscription contract electronically, we record your IP address and browser user-agent as evidence of that acceptance. We also keep an audit log of actions taken within the platform; where a request is refused because of insufficient permissions or your establishment's status, that log entry includes the IP address the request came from. Unsuccessful sign-in attempts are recorded against the email address that was tried.
Clause 3: How we use personal data
We use personal data for the following purposes, and no others.
- Running your account
- To create and operate your account, authenticate you, and apply the permissions attached to your role.
- Delivering visits
- To schedule, carry out, and report on field visits — including confirming that an inspector was physically present at the branch.
- Billing
- To process subscriptions, take payment, renew, and issue contracts and receipts.
- Measuring quality and reliability
- To measure how reliably visits are carried out and how establishments perform against compliance criteria. Clause 6 sets out what we measure about individuals.
- Protecting the platform
- To rate-limit requests, detect abuse, and investigate security incidents. IP addresses used for rate limiting are held in memory only and are not written to the database.
- Meeting our obligations
- To comply with legal, regulatory, tax, and record-keeping requirements.
Clause 4: Legal basis for processing
We process personal data to perform our contract with you, to comply with our legal obligations, for our legitimate interests in operating and securing the platform, and — where the law requires it — with your consent. The two forms of processing that bear most directly on individuals, inspector location tracking and inspector performance measurement, are described separately in clauses 5 and 6.
Clause 5: Location tracking (inspectors)
Because it is the most intrusive processing we carry out, we set it out separately. While an inspector has a visit in progress — and only while a visit is in progress — the device reports its position roughly every 30 seconds. Your browser samples position continuously for accuracy while the visit screen is open, but a reading is transmitted to us only on that interval. Each reading is compared against the branch geofence and stored with the result; if any reading falls outside it, the visit itself is marked as having a location deviation, which platform administrators can see. This is used to confirm attendance at the branch, to verify that evidence was captured on site, and to produce the visit report. It is not used to track inspectors outside an active visit, and location capture stops when the visit ends.
Location history is deleted 12 months after the visit it belongs to, and is deleted immediately if the inspector's personal data is erased at their request. See clause 10.
Clause 6: Performance measurement (inspectors)
The platform measures how reliably individual inspectors work. We set this out openly because it concerns named people.
- Reliability score
- Each inspector has a monthly reliability score. It begins at 100 and falls by 10 points for each visit that expires without being carried out, giving a band of Reliable, Watch, At Risk, or Probation. Missed visits are the only input; nothing else affects it. The score is calculated from the record each time it is shown rather than stored, and the deduction is reversed if the visit is subsequently rescheduled.
- Activity measures
- For each inspector we can show the number of visits completed, expired, and cancelled, the average time taken to carry out a visit, and the time of last sign-in.
- Establishment compliance score
- Each branch carries a compliance score with a full history of every change and its cause. This measures the establishment rather than a person, but where a branch has a single assigned manager it will in practice reflect that manager's work.
These measures are visible to QSCO platform administrators, who can sort and filter inspectors by reliability band and see a monthly list of the lowest-scoring inspectors. Each inspector can see their own score and the events behind it. Scores are not shown to establishments or to other customers. No decision is taken automatically from a score — in particular, a score never blocks an inspector from being assigned work; it informs decisions that a person makes. If you disagree with a measure recorded about you, contact us using clause 18 and a person will review it.
Clause 7: Payments
Payments are processed by Moyasar, a licensed Saudi payment provider. Card details are entered directly with Moyasar and never pass through our servers, and our card-entry pages run under a strict content security policy. Where you enable automatic renewal, we store a payment token — never your card number — encrypted at rest, and use it solely to charge the renewals you have authorised.
Clause 8: Who we share data with
We do not sell personal data. We share it only with the service providers below, and only to the extent each needs in order to perform its function.
- Moyasar
- Payment processing. Receives the payment amount, its description, and transaction metadata, and receives your card details directly from your browser.
- Microsoft Azure Blob Storage
- Stores documents, photographs, contracts, and receipts.
- OpenRouteService
- Provides driving directions and address search. Receives the coordinates involved and the text you type when searching for a place. We call it from our own servers, so your IP address is not disclosed to it.
- OpenStreetMap
- Supplies map imagery. Your browser contacts it directly whenever a map is displayed, which reveals your IP address and the area you are viewing to that service. It is the only third party your browser contacts when a map is shown.
We may also disclose personal data where required to do so by law or by a competent authority.
Clause 9: Transfers outside the Kingdom
The QSCO platform's application servers, its database, and its backups are all hosted inside the Kingdom of Saudi Arabia. Three of the providers in clause 8 process data outside it: Microsoft Azure Blob Storage, which holds uploaded documents, photographs, contracts, and receipts; OpenRouteService, which receives coordinates and place-search text; and OpenStreetMap, which your browser contacts directly for map imagery and which therefore receives your IP address. Where personal data is transferred outside the Kingdom we do so in accordance with the PDPL and its implementing regulations, under contractual terms that require the recipient to protect it to an equivalent standard and to process it only on our instructions.
Clause 10: How long we keep data
We keep personal data for as long as it is needed for the purpose it was collected for, and thereafter for any period the law requires. The periods below are the ones we apply.
- Account data
- Kept while your account is active. On erasure, your name, email address, phone number, and stored password are replaced with anonymous values. The account record itself is retained as a marker, so that records which must survive — contracts, receipts, audit history — remain internally consistent without identifying you.
- Inspector identity data
- The national ID number, date of birth, expiry dates, identity document scans, and personal photograph are deleted outright — not anonymised — when the inspector's personal data is erased. Identity documents left without an owner are removed by an automated purge.
- Location history
- Deleted 12 months after the visit it belongs to, and immediately on erasure of the inspector's personal data.
- Visit evidence photographs
- Deleted 24 months after the visit they belong to.
- Audit records
- Kept for 5 years, in line with commercial record-keeping obligations, then deleted. These include the IP addresses described in clause 2.
- Contracts and receipts
- Kept for as long as the law requires, because they are financial and evidentiary records.
- Abandoned registrations
- Documents uploaded during a registration that was never completed expire after 24 hours and are removed by a purge that runs every hour, so they are deleted shortly after that point.
Some records cannot be deleted on request because the law requires us to keep them: contracts, receipts, and audit history. These are retained, but reference the anonymised account described above rather than identifying you. Messages posted in visit tickets also remain part of the visit record and are attributed to that anonymised account.
Clause 11: How we protect data
We apply the following measures, among others.
- Encryption at rest
- National ID numbers and payment tokens are encrypted under separate, isolated encryption purposes, so that a key able to read one cannot read the other.
- Passwords
- Stored only as irreversible bcrypt hashes, which can never be read back — not even by us.
- Payment pages
- Card entry runs under a strict, nonce-based content security policy, so no third-party script can execute on a payment page.
- Tenant isolation
- Each establishment's data is isolated at the database level, so one establishment cannot read another's records.
- Access control
- Access is permission-based and denied by default, and every action is re-checked on the server — never in the browser alone.
Clause 12: Your rights
Under the PDPL you have the following rights in respect of your personal data.
- To be informed and to access
- To be told what personal data we hold about you, and to request a copy of it.
- To correct
- To have inaccurate or incomplete data corrected.
- To erase
- To request erasure of your personal data where we are not required to keep it.
- To withdraw consent
- To withdraw your consent at any time, where our processing relies on it.
- To object or restrict
- To object to processing, or ask us to restrict it, in the cases the law allows — including the performance measurement described in clause 6.
- To complain
- To lodge a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA), the competent supervisory authority in the Kingdom.
To exercise any of these rights, contact us using the details in clause 18. We will respond within 30 days. Some records — contracts, receipts, and audit history — must be kept by law even after erasure; in those cases we anonymise them rather than delete them, as described in clause 10.
Clause 14: Data breach notification
We maintain procedures to detect, investigate, and respond to personal data breaches. Where a breach occurs, we will notify the Saudi Data and Artificial Intelligence Authority (SDAIA) without undue delay and within the period the PDPL and its implementing regulations require, and we will notify affected individuals directly where the breach is likely to cause them serious harm.
Clause 15: Children
The platform is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18 years of age.
Clause 16: Confidentiality and intellectual property
The QSCO platform and everything delivered through it are the property of Quality Stability Co. and are protected under the applicable laws and regulations of the Kingdom of Saudi Arabia. This clause sets out the confidentiality and intellectual property terms that apply to your establishment and to anyone acting on its behalf. They are in addition to, and do not replace, the terms of your subscription contract.
- Ownership of the platform
- All systems, platforms, dashboards, reports, templates, methodologies, software, databases, designs, indicators, and operating manuals that Quality Stability Co. develops or provides — including the QSCO Score — are its exclusive property and are protected under the laws of the Kingdom.
- Restrictions on use
- You may not copy, photograph, record, reproduce, distribute, publish, transfer, disclose, or otherwise make available any part of the QSCO platform, its dashboard, the QSCO Score, or any report, template, or document provided as part of the service, without our prior written consent.
- Access credentials
- You must keep every username, password, and other means of access to the platform confidential, and you are responsible for the activity carried out through your accounts. Tell us immediately if you believe a credential has been compromised.
- No competing use
- Neither you nor anyone acting on your behalf may use the information, documents, reports, templates, or working methods obtained through the service to create, develop, imitate, or provide a similar or competing service, whether directly or indirectly.
- Internal use only
- The reports, findings, indicators, analyses, and dashboards we deliver are for your establishment's own internal use. They may not be resold, redistributed, published, or commercially exploited without our prior written approval.
- Intellectual property rights
- All intellectual property rights in the platform — software, databases, user interfaces, designs, reports, the QSCO Score, trade marks and trade names, documentation, and every future update or enhancement — remain exclusively ours. Your subscription grants a right to use the platform for the duration of that subscription, and transfers no ownership of any kind.
- Confidential information
- You must keep confidential the technical, commercial, financial, operational, and business information you learn while the service is provided, both during your subscription and after it ends.
Where this clause is breached, Quality Stability Co. may take the steps available to it under the laws of the Kingdom, including claiming compensation for the damage actually suffered and terminating the subscription where the breach materially affects its rights or interests. Nothing in this clause limits your rights over your own personal data set out in clause 12, or your establishment's ownership of the data it enters into the platform.
Clause 17: Changes to this policy
We may update this policy from time to time. The version and effective date shown at the top of this page always identify the text currently in force, and we will give notice of any material change through the platform.
Clause 18: Contact us
For any privacy question, or to exercise the rights set out in clause 12, contact Quality Stability Co. at info@qsco.sa and we will respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA).