Abtal
Join Abtal

Privacy Policy

Last updated:

Who we are

Abtal Hub and Abtal Business use a shared Abtal identity service. Hub provides professional, learning, opportunity and family journeys. Business is separately deployed and has its own application permissions. Shared sign-on does not give either application unrestricted access to the other application's data.

This notice describes the intended production processing. The Saudi PDPL transfer assessment, processor agreements, retention approval, controller identity and contact verification, and final bilingual legal approval are pending. Admission of personal data to this production deployment remains closed until these approvals are recorded. This version was prepared on 2026-09-05; its effective date will be recorded with approval.

Scope

This notice covers Hub, the shared identity and Profile services, and the common processing described for Business. The separately operated Business deployment must supply an accurate processor and purpose inventory before its own admission. Third-party websites and separately governed clinical center records are outside this notice.

The data we collect

Identity and shared Profile: account identifiers, email verification, authentication and session events, roles, display name, optional birth date, language, avatar reference, consent and provenance, and profile version. Keycloak receives and manages passwords and MFA credentials; Hub and Business application routes do not receive passwords. Application permissions and logout/revocation are checked independently.

Hub family data: family account and profile labels, relationship, age band, interface language, followed conditions, selected needs and priorities, current stage, journeys and recommendation feedback. Guardian and participant access, consent, delegation, ownership transfer, revocation, export and deletion records control access. This may include information about children, disability or support needs.

Professional and opportunity data: professional and organization profiles, qualifications, specialties, experience, CVs, student verification evidence, certificates and training records, job or training applications, event participation, messages and content you submit. Visibility and access depend on the feature and your permissions; submitting a job application shares its relevant content with that employer.

Files: CVs, student evidence, verification documents, certificates, attachments, exports and unreleased media are private objects. Access uses short-lived signed links after server authorization. Approved public images and media are delivered through Cloudflare from a private Wasabi origin; raw bucket endpoints are not public access paths.

Operational data includes necessary technical, security and audit events and email delivery outcomes. Logs must exclude passwords, credentials, tokens, private file contents and unnecessary personal fields. Location for an event check-in is collected only through the specific consent journey when that feature is used.

Sensitive and family information

Family condition, disability and support information is sensitive. Access is restricted to the authorized family or participant context and approved operations. It must not become public professional profile data or advertising targeting data. Clinical center records governed by another product remain separate; that separation does not mean Hub holds no children's data.

Retention, deletion and restore

Active records follow the approved purpose-specific retention schedule. The proposed operational schedule includes 30 days for operational logs, 90 days for security logs and metrics, 14 days for traces, and at least 365 days for minimized identity audit evidence. Backup recovery points have proposed 35-day default, 84-day weekly and 365-day monthly retention, with at least 395 days for erasure ledgers. These periods remain subject to signed retention approval and lawful preservation requirements.

Deletion removes or de-identifies eligible live records and revokes access. Immutable encrypted backups may retain earlier records until their retention expires; they are isolated from ordinary use. Before a restore is returned to service, erasure ledgers and subject aliases are replayed so deleted accounts or data are not reintroduced. Exports and private access must be checked again after restore. Minimal audit or legally required records may remain under the approved schedule.

Your rights

Subject to applicable law, you may request access, correction, a copy or export, deletion, and withdrawal of consent where used. Family and participant requests are checked against the relevant authority and consent rules. Contact the privacy team for requests that cannot be completed in account settings and for information about retention exceptions or transfers. You may complain to the competent data protection authority.

Processors and sharing

The intended production providers include Hetzner for compute and volumes, Wasabi for private application objects and backups, independently administered Backblaze B2 for recovery copies, AWS for protected state and key services and Amazon SES for transactional email, and Cloudflare for edge delivery, security and protected administration. Keycloak is self-hosted identity software, not a separate external recipient. Processor contracts, subprocessors, locations and access arrangements require the approved register before personal data is admitted.

International transfers and data residency

The intended primary processing is in the European Union: compute in Germany, object and independent recovery storage in Germany and the Netherlands as specified in the approved provider register, and AWS Frankfurt (eu-central-1) for state, keys and transactional email services. This is not a claim that every Cloudflare edge, provider support or subprocessor operation is confined to the EU. The exact locations and onward transfers must be documented and assessed before activation.

Transfers from Saudi Arabia require review under the Saudi Personal Data Protection Law and its transfer regulations, with applicable safeguards and risk assessment recorded by the responsible legal team. Owner approval of EU hosting is not legal approval. Signed transfer and processor documentation is pending; no compliance certification is asserted here.

Security

The intended controls include server-side authorization, encrypted transport and storage, least privilege, private origins, minimized audit trails, and independent encrypted recovery copies. Their production operation must be demonstrated before admission. Report suspected unauthorized access through the privacy contact; the incident procedure includes assessment, containment and notifications where required.

Children and guardians

Hub can process children's family profiles and support needs within authorized guardian and participant journeys. The relevant guardian authority, age-appropriate consent and participant control rules must be satisfied. A professional Business account does not automatically grant access to a child's Hub profile. Child and family data must not be exposed through public directories.

Changes to this notice

Material changes to purposes, processors, regions or rights will be reflected in the approved notice and communicated before taking effect as required. The production effective version and approval record remain pending.

Privacy contact

The current published privacy contact is [email protected]. The responsible legal entity, postal address and operational ownership of this contact must be verified and included in the signed approval record before production admission.

See also the other legal pages.