Privacy policy

Nabrah.ai

Legal — Last updated: 20-05-2026 — Reading time: ~15 min

On this page

  1. Who is Nabrah and what does this Policy cover?

  2. What personal data we collect

  3. Voice and biometric data

  4. How and why we use your data

  5. How our AI processes voice and call data

  6. Legal basis for processing

  7. Who we share data with

  8. Data storage and international transfers

  9. Data retention

  10. Data security and breach notification

  11. Your rights

  12. Cookies and tracking

  13. Children's data

  14. Limitation of liability and disclaimers

  15. Policy changes

  16. Contact us


1. Who is Nabrah and what does this Policy cover? <a id="1-who-is-nabrah-and-what-does-this-policy-cover"></a>

Nabrah.ai and the Nabrah AI platform (collectively, the 'Services') are operated by Deep Scan Technologies, a company incorporated under the laws of the Kingdom of Saudi Arabia, with registered address at Al Abbas Ibn Abd Al Mouttaleb, At Taawun, Riyadh 12476 and Commercial Registration No. 1010801178 ('Nabrah', 'we', 'us', or 'our').

Nabrah provides AI-powered speech and communication tools, including Text-to-Speech (TTS), voice cloning and custom voices, AI voice agents for inbound and outbound calls and IVR flows, developer APIs and SDKs, and related analytical features such as call transcription, summarization, sentiment analysis, and conversation intelligence.

We take your personal data and privacy seriously. This Privacy Policy (the 'Policy') explains our practices regarding the collection, use, protection, and disclosure of Personal Data. It is designed to comply with the Kingdom of Saudi Arabia's Personal Data Protection Law (PDPL) and other applicable data protection laws and standards.

This Policy applies to the Personal Data we process from three main groups of individuals:

Website Visitors: Individuals who visit or interact with our public-facing websites (e.g., nabrah.ai).

Customers: Authorized users representing an organization that has entered into an agreement with Nabrah to use our Services.

End-Users: Individuals whose voice, recordings, or communications are processed through our Services by our Customers (for example, a person who speaks with one of our Customer's AI voice agents, or whose voice is uploaded to create a custom voice).

A critical distinction is whether Nabrah acts as a 'Data Controller' or a 'Data Processor'. For Website Visitors and Customers, Nabrah acts as the Data Controller, meaning we determine the purposes and means of processing. For End-User data that we process through our Services on behalf of our Customers (including voice recordings, generated voices, call audio, transcripts, and metadata), our Customer is the Data Controller and Nabrah acts as the Data Processor, processing such data only on the documented instructions of our Customer. The legal responsibility for obtaining a valid legal basis to process End-User data (including consent for voice biometrics, voice cloning, call recording, and AI-generated voice disclosures) rests solely with our Customers.

Please read this Policy carefully. By accessing our websites or using our Services, you acknowledge that you have read, understood, and agree to the practices described here. If you do not agree with this Policy, you must not use our websites or Services.


2. What personal data do we collect about you and how do we collect it? <a id="2-what-personal-data-we-collect"></a>

We collect Personal Data through various means to provide and improve our Services. The types of data we collect depend on your relationship with us, as detailed below. This approach adheres to the PDPL principle of data minimization.

Data You Provide Directly to Us

Account and Contact Information: When you register for an account, request a demo, or contact us for support, we collect information such as your full name, business email address, phone number, company name, job title, and billing or physical address.

Payment Information: For paying Customers, we collect billing details and payment information, which are processed securely by our third-party payment processors (e.g., Stripe or local KSA gateways). We do not store full card numbers on our systems.

Communications and Support Data: If you contact us via email, support tickets, feedback forms, or other channels, we collect the information contained in your correspondence, including any attachments.

Uploaded Voice and Audio: When you (or your authorized representatives) upload voice recordings to train a custom voice, clone a voice, generate speech, or test the Services, we collect those recordings together with any associated metadata you provide (such as labels, language, and consent records).

Data We Collect Automatically

Usage and Log Data: Information about your interactions with our Services, such as the features you use, the pages you visit, the API endpoints you call, the dates and times of access, and performance statistics.

Device and Connection Information: IP address, browser type and version, operating system, device identifiers, and approximate location derived from your IP address.

Cookies and Other Tracking Technologies: We use cookies and similar technologies to operate and administer our websites, gather usage data, and support our marketing efforts. For details, see Section 12.

Data We Process on Behalf of Our Customers (as a Data Processor)

When our Customers use our Services to deploy voice agents, generate synthetic speech, clone voices, or analyze calls, we process the data they submit to our platform. Nabrah has no direct relationship with the End-Users whose data is processed in this context. The collection of this data is managed by our Customers, who are the Data Controllers. This data includes:

Voice Inputs and Outputs: Audio uploaded to create or clone voices, generated synthetic speech, and any associated configuration.

Interaction Content: Audio from phone calls (inbound and outbound), recordings, and the resulting transcripts generated by our speech-to-text engine. This content may contain Personal Data and, potentially, Sensitive Personal Data of End-Users, depending on the nature of the conversation.

Interaction Metadata: Phone numbers of the calling and receiving parties, the start time and duration of the call, call direction (inbound/outbound), routing data, and other technical details associated with the interaction.

CRM and Integration Data: If a Customer integrates our Services with a third-party application such as a CRM (e.g., Salesforce, HubSpot), telephony provider, or any other system, we may access and process data from that system as directed by the Customer.


3. Voice and biometric data <a id="3-voice-and-biometric-data"></a>

Voice characteristics used for identification may constitute biometric data — a special category of Personal Data under the Saudi PDPL and similar laws. This Section explains how that data is handled and where responsibility lies.

3.1 Nature of Voice Data

Voice recordings, voice prints, embeddings derived from voice, cloned voices, and generated synthetic voices may be processed by the Services. Depending on context and purpose, some of this data may qualify as biometric data and is treated with additional safeguards.

Where you (as a Customer) upload audio to clone or create a custom voice, you are solely responsible for obtaining and documenting explicit, informed, and revocable consent from the person whose voice is used, in line with PDPL and any other applicable laws. This includes consent to record the voice, upload it to Nabrah, use it for speech synthesis or cloning, and use the resulting synthetic voice for your chosen purposes. You must honor any withdrawal of consent and instruct us to delete the relevant data where required by law.

3.3 AI-Generated Voice Disclosures

You are also responsible for any disclosures required by law or industry practice (for example, telling the other party in a call that they are speaking to an AI-generated voice, or that the call is being recorded or transcribed). Please see Section 10 of our Terms of Service for the full list of telephony, calling, and recording obligations.

3.4 Nabrah's Role

When you upload voice data through the Services, Nabrah acts as your Data Processor in respect of that data. Nabrah does not use uploaded End-User voices to identify, profile, or contact End-Users on its own behalf, and does not sell voice data. Subject to your plan and contract, we may use voice data to operate, maintain, secure, and improve the Services as described in Section 4.


4. How and why do we use your personal data? <a id="4-how-and-why-we-use-your-data"></a>

We follow the PDPL principle of purpose limitation. We only use your Personal Data for specific, explicit, and legitimate purposes that we have disclosed to you, and we do not process your data for purposes that are incompatible with those original intentions.

As a Data Controller (For our own business purposes)

To Provide Services and Manage Your Account: We use your Account and Contact Information to create and maintain your account, process payments, provide you with access to our Services, and send essential service-related communications (e.g., billing notices, security alerts).

To Provide Customer Support: We use your communications data and account information to investigate and respond to your inquiries, troubleshoot technical issues, and provide other support services.

For Marketing and Communications: With your consent where required by law, we may use your Contact Information to send you newsletters, promotional materials, and other information about our products and services. You can opt out at any time using the unsubscribe link in any marketing email or by contacting us at info@nabrah.ai.

To Improve Our Services and Websites: We analyze Usage and Log Data to understand how users interact with our platform, improve functionality, enhance the user experience, and develop new features.

For Security, Fraud Prevention, and Legal Compliance: We use your Personal Data to maintain the security and integrity of our platform, detect and prevent fraud and abuse, enforce our legal agreements (such as our Terms of Service), and comply with our legal obligations.

As a Data Processor (On behalf of our Customers)

When we process End-User data on behalf of our Customers, our role is strictly limited to providing the Services as instructed by the Customer in our contractual agreement. Our purposes for processing this data are:

To Deliver the Core Services: We process voice inputs and outputs, Interaction Content, Interaction Metadata, and CRM Integration Data to perform the functions contracted by our Customer. This includes generating synthetic speech, training custom voices, routing calls, creating recordings and transcripts, generating analytical reports, and displaying relevant information within the Customer's Nabrah account. The legal basis for this processing is the contract between Nabrah and the Customer.


5. How does Nabrah's Artificial Intelligence process voice and call data? <a id="5-how-our-ai-processes-voice-and-call-data"></a>

The core value of Nabrah's platform is its ability to apply advanced AI to voice and conversational data. This section explains how our AI systems work and the safeguards we apply.

Core AI Functionality

Text-to-Speech and Voice Generation: Our AI synthesizes natural-sounding speech from text in multiple languages and dialects.

Voice Cloning and Custom Voices: Our AI can train a voice model on audio you upload (with appropriate consent) so that a synthetic voice can be generated based on that model.

AI Voice Agents: Our AI can carry on live conversations over the phone, handle inbound and outbound calls, run IVR flows, and integrate with business systems.

Speech-to-Text Transcription: Our AI automatically converts call audio into searchable text.

Summarization, Sentiment, and Topic Analysis: Our AI generates concise summaries, sentiment scores, and topic/keyword analytics from conversations, to help our Customers understand and improve their operations.

AI Model Training and Improvement

To keep our AI models accurate and effective, they require continuous training and refinement. Using Customer data for model improvement is a separate processing activity from delivering the Services and is subject to additional controls.

Data Protection Safeguards: Before any data is used for training purposes, we apply technical measures to anonymize or pseudonymize it to the greatest extent possible, including removing or obscuring direct personal identifiers.

Customer Control and Consent: Customers can opt out of having their data used to train Nabrah's AI models via their account settings or their contract. Unless a Customer provides explicit consent (or their plan permits training by default), their data is used solely to provide the Services to them.


Under PDPL and similar laws, all processing of Personal Data must be justified by a legal basis. The bases we rely on are:

Performance of a Contract: When processing is necessary to fulfill our contractual obligations to you (e.g., providing the Services you have subscribed to).

Consent: When you have given us your explicit and informed permission to process your Personal Data for a specific purpose (e.g., for sending marketing materials, for voice cloning, or for AI model training).

Legitimate Interest: When we have a legitimate business interest in processing your data (for example, security, fraud prevention, or service improvement), and that interest is not overridden by your fundamental rights and freedoms. We do not rely on legitimate interest as a basis for processing sensitive or biometric data.

Legal Obligation: When we are required to process your Personal Data to comply with a law or a binding legal order.


7. Who do we share your personal data with? <a id="7-who-we-share-data-with"></a>

We do not sell your Personal Data. We share Personal Data only in the limited circumstances described below, and only after taking steps to ensure that any third party with whom we share data provides an adequate level of protection.

Sub-processors and Service Providers: We engage third-party companies and individuals to perform services on our behalf, including cloud hosting, payment processing (e.g., Stripe), telephony and SMS providers, AI model providers, identity providers, data analytics, and customer support. We share the minimum data necessary, and we put binding Data Processing Agreements in place requiring sub-processors to protect the data and process it only on our instructions.

Third-Party Integrations Chosen by the Customer: When a Customer chooses to connect our Services to a third-party application (e.g., a CRM, telephony provider, or any other system), we will share data with that service as directed by the Customer. We are not responsible for the privacy practices of these third-party services, and we encourage our Customers to review their privacy policies.

Legal and Regulatory Bodies: We may disclose Personal Data in response to a lawful request by public authorities, such as to comply with a court order, a legal proceeding, or national security or law-enforcement requirements. We will only disclose what is required by law and will notify the relevant Customer before disclosure where we are not legally prohibited from doing so.

Business Transfers: In the event of a merger, acquisition, bankruptcy, or other sale of all or part of our assets, your Personal Data may be transferred to the acquiring entity. We will notify you of any such change in ownership or control of your Personal Data.


8. Where is your data stored and is it transferred internationally? <a id="8-data-storage-and-international-transfers"></a>

The location and transfer of Personal Data are subject to strict legal requirements under the Saudi PDPL. We have designed our infrastructure and policies to respect data residency and to ensure that all cross-border data transfers are lawful.

Primary Data Storage Location: Customer data, including voice inputs, generated voices, Interaction Content, and Metadata, is primarily stored on secure servers within the Kingdom of Saudi Arabia, to help Customers meet their data localization and compliance obligations.

International Data Transfers: In certain circumstances (such as 24/7 support, specialized AI sub-processors located outside the Kingdom, or globally distributed infrastructure), it may be necessary to transfer Personal Data internationally. We will only conduct such transfers in strict compliance with PDPL and other applicable laws.

Legal Safeguards for Transfers: Any transfer of Personal Data outside Saudi Arabia will be protected by appropriate legal safeguards as mandated by PDPL, which may include: (a) transferring to countries deemed by the Saudi Data & Artificial Intelligence Authority (SDAIA) to provide an adequate level of protection; (b) using approved Standard Contractual Clauses or Binding Corporate Rules where adequacy is not available; and (c) conducting a documented risk assessment for the transfer.


9. How long do we keep your personal data? <a id="9-data-retention"></a>

We adhere to the PDPL principle of storage limitation: we do not retain Personal Data for longer than is necessary to fulfill the purposes for which it was collected or to comply with our legal and contractual obligations.

Customer-Controlled Data: The retention period for voice inputs, generated voices, Interaction Content, and Metadata processed on behalf of our Customers is configured and controlled by the Customer. Our platform provides Customers with retention controls to meet their industry, legal, and business requirements.

Data Deletion Upon Contract Termination: When a Customer terminates their contract with us, all data associated with their account, including voice models, voice inputs, generated voices, and Interaction Content, will be permanently deleted from our production systems after a brief grace period (typically up to 90 days) to allow for account reactivation, unless we are legally required to retain it.

Account and Billing Data: We retain Account and Billing data for the duration of the customer relationship and for the period required to comply with tax, accounting, and other legal obligations.

Marketing Data: Personal Data used for marketing purposes is retained until you withdraw your consent by unsubscribing from our communications.


10. How do we secure your data and respond to incidents? <a id="10-data-security-and-breach-notification"></a>

10.1 Security Measures

We implement technical and organizational measures designed to protect Personal Data against unauthorized access, alteration, disclosure, loss, or destruction. These measures include encryption in transit and (where appropriate) at rest, access controls and least-privilege permissions, network and infrastructure security controls, secure development practices, logging and monitoring, periodic vulnerability assessments, and employee training.

10.2 No Guarantee of Absolute Security

Although we use reasonable measures to protect Personal Data, no method of transmission over the internet, no method of electronic storage, and no AI/ML system is 100% secure. We cannot and do not guarantee absolute security. You are responsible for keeping your account credentials, API keys, and integration secrets confidential, and for using strong, unique passwords.

10.3 Breach Notification

If we become aware of a Personal Data breach that is likely to cause significant harm, we will notify the competent supervisory authority and, where required by PDPL or other applicable law, affected Customers and individuals without undue delay. Customers are responsible for notifying their End-Users where required.


11. What are your rights regarding your personal data? <a id="11-your-rights"></a>

We respect your right to control your Personal Data. In accordance with PDPL and other applicable data protection laws, you have the following rights:

The Right to be Informed: You have the right to be informed about the collection and use of your Personal Data, which is the purpose of this Policy.

The Right of Access: You have the right to request a copy of the Personal Data we hold about you.

The Right to Correction (Rectification): You have the right to request that we correct any inaccurate or incomplete Personal Data we hold about you.

The Right to Destruction (Erasure): You have the right to request the deletion of your Personal Data when it is no longer necessary for the purpose for which it was collected, or when you withdraw your consent.

The Right to Withdraw Consent: Where we process your Personal Data based on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

The Right Regarding Automated Decision-Making: Where applicable, you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects concerning you, except as permitted by law.

How to Exercise Your Rights

If you are a Customer or Website Visitor and wish to exercise any of these rights, please contact us at info@nabrah.ai (see Section 16 below). We will respond to your request in a timely manner, in accordance with applicable law. We may need to verify your identity before responding.

If you are an End-User who has interacted with one of our Customers, please note that Nabrah processes your data as a Data Processor on behalf of that Customer. Therefore, to exercise your rights, you must direct your request to the relevant Customer (the organization that contacted you or whose AI voice agent spoke with you). We are legally and contractually obligated to act only on the documented instructions of our Customers regarding the data they control.


12. How do we use cookies and other tracking technologies? <a id="12-cookies-and-tracking"></a>

We use cookies and similar tracking technologies on our websites to provide and improve our services, analyze usage, and for marketing purposes.

What are Cookies? A cookie is a small text file that a website stores on your computer or mobile device when you visit the site. It enables the website to remember your actions and preferences over a period of time.

How We Use Cookies: We use different categories of cookies:

Strictly Necessary Cookies: Essential for you to browse the website and use its features, such as accessing secure areas.

Performance and Analytical Cookies: These cookies collect aggregated, anonymized information about how you use our website (such as pages visited and links clicked) to help us improve how our website works.

Functional Cookies: These cookies allow our website to remember past choices, such as your preferred language or region.

Marketing and Targeting Cookies: These cookies track your online activity to help advertisers deliver more relevant advertising or to limit how many times you see an ad.

Managing Your Preferences: When you first visit our website, you will be presented with a cookie consent banner that allows you to accept or reject different categories of non-essential cookies. You can also control and manage cookies through your browser settings. Disabling certain cookies may affect the functionality of our website.


13. What is our policy regarding children's data? <a id="13-childrens-data"></a>

Our Services are intended for business use and are not directed at individuals under the age of 18. We do not knowingly collect Personal Data from children. If we become aware that we have inadvertently collected Personal Data from a child without verification of parental consent, we will take steps to delete that information from our servers as quickly as possible. If you believe we may have collected information from a child, please contact us at info@nabrah.ai.


14. Limitation of liability and disclaimers <a id="14-limitation-of-liability-and-disclaimers"></a>

14.1 Best-Efforts Security; No Guarantee

We use reasonable technical and organizational measures to protect Personal Data, but no system, network, or AI service is 100% secure. To the maximum extent permitted by applicable law, Nabrah disclaims any warranty, guarantee, or commitment that the Services, our websites, or any of our data-protection measures will be uninterrupted, error-free, fully resistant to attack, or that any Personal Data processed through the Services will be entirely free from risk of unauthorized access, loss, or alteration.

14.2 No Liability for Customer-Controlled Use of the Services

Where Nabrah acts as a Data Processor on behalf of a Customer, the Customer is the Data Controller and is solely responsible for: (a) the legal basis for processing End-User data (including obtaining consent for voice cloning, voice biometrics, call recording, AI-generated voice disclosures, marketing, and any other processing); (b) the accuracy, lawfulness, and content of the data the Customer submits to the Services; (c) responding to data-subject requests from its End-Users; and (d) any consequence of the Customer's configuration, deployment, integration, or use of the Services. To the maximum extent permitted by applicable law, Nabrah shall have no liability whatsoever to any End-User or other third party for any claim arising out of or related to a Customer's use of the Services, and the Customer agrees to indemnify Nabrah for any such claim in accordance with Section 17 of our Terms of Service.

14.3 No Liability for Third-Party Services

Our Services may rely on, integrate with, or be used alongside third-party services chosen by the Customer (including AI / model providers, telephony and SMS providers, payment processors, identity providers, hosting and cloud providers, CRMs, and other vendors). To the maximum extent permitted by applicable law, Nabrah shall have no liability for any act, omission, security incident, data loss, downtime, or breach by any such third-party service, even where data is shared with or received from that service in the course of providing the Services.

14.4 Relationship to the Terms of Service

This Privacy Policy is part of, and is governed by, our Terms of Service. The disclaimers, exclusions, limitations of liability, indemnification, governing law, and dispute resolution provisions of the Terms of Service (including without limitation Sections 14 through 19) apply to this Policy and to any claim arising out of or related to our processing of Personal Data, to the maximum extent permitted by applicable law. In the event of any conflict between this Policy and the Terms of Service, the Terms of Service shall prevail unless the conflict relates to a matter of mandatory data-protection law, in which case the relevant data-protection law shall control.

14.5 Mandatory Carve-Outs

Nothing in this Policy excludes or limits any liability that cannot lawfully be excluded or limited under applicable law (for example, mandatory liability under PDPL for the obligations of a Data Controller or Data Processor, or under KSA law for fraud, willful misconduct, or gross negligence).


15. How will you be notified of changes to this policy? <a id="15-policy-changes"></a>

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make changes, we will update the 'Last updated' date at the top of this Policy. If we make a material change, we will provide you with notice — for example, by sending an email to the address associated with your account or by posting a prominent notice on our website — before the change becomes effective. We encourage you to review this Policy periodically to stay informed.


16. How can you contact us about your privacy? <a id="16-contact-us"></a>

If you have any questions, concerns, or complaints about this Privacy Policy or our data-protection practices, or if you wish to exercise your rights, please contact us:

Email: info@nabrah.ai

Postal Mail: Riyadh, Kingdom of Saudi Arabia

We are committed to working with you in good faith to obtain a fair resolution of any complaint or concern about privacy.