Privacy policy
Draft — pending legal review by the owner. Not yet a binding document.
Last updated: 2026-10-06
1. Who we are
Gurdx ("we", "us") provides a fraud-prevention and user-intelligence API and the website and dashboard around it. This policy explains what personal data we process and why. It is written with the Saudi Personal Data Protection Law (PDPL) in mind and is intended to be reviewed against it before the service is offered publicly.
2. Data we process
Account data: name, email address, company, password hash and sign-in metadata of the people who register.
API data: the values you send for analysis (for example IP addresses, email addresses, phone numbers, transaction details, card BIN and last four digits) and our results. Full card numbers are never stored; we keep the BIN, the last four digits and a keyed one-way hash so that repeated use of a card can be detected.
Technical data: request logs, timestamps, error codes and security events needed to run and protect the service.
3. Why we process it
To provide, secure and bill the service; to detect and prevent fraud and abuse; to support our customers; and to meet legal obligations. Where we act on your behalf for the data you send, you are the controller and we are the processor.
4. Retention and deletion
Raw request logs are kept for a limited period (90 days by default) and aggregated counters for as long as your account exists. You can delete the data related to a given end user at any time with the user-deletion endpoint, and request deletion of your account.
5. Sharing and transfers
We do not sell personal data. We use service providers (hosting, email delivery, payment processing) bound by confidentiality and security obligations. Where data is transferred outside the Kingdom, we apply the safeguards required by applicable law.
6. Your rights
Subject to law you may ask to access, correct, delete or receive a copy of your personal data, and object to certain processing. Contact us using the details on the contact page.
7. Security
Traffic is encrypted in transit, secrets are stored encrypted or hashed, access to the platform requires two-factor authentication for administrators, and API keys can be restricted to authorised hosts.
8. Contact
Questions about this policy: see the contact page.