Smart accounting for Saudi businesses
Englishالعربية
جَبرJabr
Home
Features
All Jabr featuresAI accountingE-invoicingFiling Center and QawaemPayroll and GOSIBank reconciliationSolutions for your business
See how it worksPricingAcademyAbout
جَبرJabr

Navigate

Home
Features
All Jabr featuresAI accountingE-invoicingFiling Center and QawaemPayroll and GOSIBank reconciliationSolutions for your business
See how it worksPricingAcademyAbout

Legal Documents

Terms of ServicePrivacy PolicyData Processing AgreementCookie PolicyAcceptable Use PolicySecurity

Privacy Policy

Arabic is the legally binding version per Saudi law.

Effective date and last reviewed: 12 September 2026 / ١٢ سبتمبر ٢٠٢٦

This policy explains how Asas Albahth Commercial Limited Company ("Jabr") processes personal data under the Saudi Personal Data Protection Law and its regulations.

1. Data We Process

  • Account and contact data: name, email, mobile number, language, and authentication data.
  • Business data: name, registration and tax numbers, address, activity, legal form, and ownership information entered by the user.
  • Workspace content: entries, invoices, documents, customers, suppliers, employees, payroll, bank statements, inventory, assets, reports, migration data, and integration data.
  • Technical and usage data: IP address, browser and session information, requests, errors, audit events, and a device identifier derived from browser type, language, and screen dimensions for abuse prevention. It is not a unique cryptographic hash.

2. Roles

Jabr is a controller for account, billing, security, and service-operation data. For personal data a business places in its books, the business is normally the controller and Jabr acts as processor under the Data Processing Agreement. The business must have a lawful basis for employee, customer, and supplier data.

3. Purposes and Legal Bases

  • Contract: account creation, accounting services, support, billing, export, and requested synchronization.
  • Legal obligation: record retention, competent-authority requests, and applicable tax and regulatory duties.
  • Permitted legitimate interests: network security and fraud or abuse prevention, after balancing rights and excluding sensitive-data processing on this basis.
  • Consent: built-in AI and speech processing where consent is required. Withdrawal does not invalidate earlier lawful processing.

4. Jabr Team and Support Access

Internal dashboards ordinarily show account, company, status, and aggregate usage data. Authorized personnel may access company records through merchant-granted, time-limited support, or for a security incident, dispute, or legal obligation. These paths are purpose- and permission-limited, and sensitive actions are logged. Tenant controls prevent one company's users from accessing another company.

5. AI and Speech

After the user accepts the built-in assistant disclosure and uses it, Jabr sends the message, context, and records needed for the answer to external AI services; audio or response text is sent to speech services when voice is used. Processing may occur outside Saudi Arabia. This path does not run before acceptance, and Jabr does not use customer books to train models it owns. With the user's MCP client, the external client's request determines what reaches the user's provider under that provider's terms.

6. Integrations, API, and Apps

When a user connects a store, bank, payment gateway, OAuth app, or API key, Jabr and the selected service exchange data allowed by the granted scopes. The user controls and can revoke the connection. A connected provider may be an independent controller under its own terms and privacy policy. Provider secrets are not exposed in the admin UI.

7. Service Providers and Disclosures

  • Google Cloud and Firebase: hosting, compute, database, file storage, authentication, and application protection.
  • Jabr's configured email provider: operational email and account support.
  • AI and speech services: the features described above or limited operational verification of subscription receipts.
  • User-connected services: stores, banks, payment gateways, apps, and external AI providers according to granted scopes.
  • Data may be disclosed in response to binding legal process, to protect rights and security, or in a lawful corporate transaction with appropriate safeguards.

8. Location and International Transfers

The current authoritative accounting database is in Saudi Arabia. Other components—including compute, authentication, security, email, AI, speech, and user-selected connectors—may process data outside the Kingdom. For transfers it makes, Jabr applies the PDPL and the Regulation on Personal Data Transfer Outside the Kingdom and presents separate consent when consent is the applicable basis.

9. Security

Jabr uses HTTPS/TLS in transit, cloud-provider encryption at rest, company-scoped access rules, roles, protection for sensitive keys, audit logging for sensitive operations, and operational backup and recovery controls. These measures do not guarantee that an incident can never occur.

10. Retention and Deletion

  • Account, support, and security data is retained as needed to operate the service, protect rights, and meet obligations, then deleted or de-identified under operational policy and law.
  • The Commercial Books Law requires specified books, correspondence, and supporting documents to be retained for at least 10 years. The period runs from the date specified by law, not automatically from cancellation of Jabr.
  • VAT records are generally retained for 6 years; movable capital-asset records extend to 11 years and immovable capital-asset records to 15 years under current ZATCA requirements.
  • The longer applicable period controls. Deletion may be requested, subject to mandatory retention and legal-claims needs.

11. Rights

Data subjects may request information, access, a copy, correction, destruction, withdrawal of consent, objection, or restriction where provided by law. Identity verification may be required, and retention duties or others' rights may limit a request. Contact info@jabrhq.com. Data subjects may complain to the competent authority.

12. Incidents and Changes

Jabr assesses personal-data incidents and notifies the competent authority within 72 hours when the statutory harm threshold is met. It notifies affected data subjects without undue delay when the law requires. Material policy changes will be announced, and a new consent may be requested when a consent-based purpose changes.

Official Legal References

The following official sources were reviewed on 12 September 2026. The official source controls if the law changes.

  • Saudi Personal Data Protection Law
  • PDPL Implementing Regulations
  • Regulation on Personal Data Transfer Outside the Kingdom
  • Commercial Books Law
  • ZATCA VAT Implementing Regulations
  • Electronic Transactions Law
  • E-Commerce Law
View in:|
جَبرJABR

Smart accounting for Saudi businesses

Product

HomePricingInteractive demoAll Jabr featuresE-invoicingBusiness solutionsIntegrationsTools

Resources

AcademySaudi accounting guidesFree calculatorsDeveloper API

Company

AboutContact UsSecurity

Legal

Terms of ServicePrivacy PolicyData Processing AgreementCookie PolicyAcceptable Use
QR code for National Personal Data Protection Register entryPersonal Data ProtectionRegistration No.: 3260007545QR code for the Saudi Business Center E-CertificateSaudi Business Center E-CertificateAuthentication No.: 0000324313
Encrypted at restDesigned for PDPLISO 27001 · 27017 · 27018

Asas Albahth© 2026 Jabr is a registered trademark owned and operated by Asas Albahth Commercial Limited Company 7033481131. All rights reserved.