Last updated: 2026/08/23
Raseem ("Raseem", "we", "us") operates a case-management platform ("the Platform") used by subscribing law firms ("the Firm") to manage their cases, sessions, consultations and clients. This policy explains what data we collect, why, and how we protect it, in line with Saudi Arabia's Personal Data Protection Law (PDPL).
Who controls the data
For staff-account data (the Firm's own users), Raseem is the data controller, as the platform operator. For client, opponent and case data the Firm enters, the Firm is the data controller — Raseem acts only as a data processor operating the platform on the Firm's behalf.
What we collect
- Staff account data: name, email, phone, job role.
- Case, execution, legal-service and consultation records the Firm enters.
- Client, contact, opponent and reference-entity records.
- Uploaded documents and files.
- Activity logs — who did what, and when — for audit and security purposes.
- Sign-in metadata (time, success/failure) for account-security purposes only.
Why we collect it
To provide the case-management service the Firm subscribes to — organizing cases, sessions and deadlines, letting the Firm's team collaborate, and protecting the account from unauthorized access.
Who we share it with
- We do not sell or rent any user's or client's data to a third party for marketing.
- We use Google's Gemini API for two optional features: automatic Arabic→English field translation, and the AI legal assistant's document search (when a Firm uses it). Only the relevant text is sent, for that purpose only.
- The Platform is hosted on cloud infrastructure (Railway) with a dedicated database per deployment.
- Subscription billing via a licensed Saudi payment gateway is planned but not active yet — no payment data is processed by the Platform today.
How long we keep it
We retain data for as long as the Firm's account is active. We do not auto-delete records; a Firm may request the erasure of a specific client's data (see below). The activity log itself is kept without deletion even after an erasure, as it is a legal record of what happened.
Your right to erasure
From a client's own file, the Firm can run «محو بيانات الموكل» (erase client data). This overwrites every identifying field — name, ID number, passport, phone, email, birth date — with a placeholder, everywhere that client appears, including on any case they were a party to. The case/session record itself is NOT deleted — only the person's identity is scrubbed, because the underlying matter remains a legal record the Firm must keep.
Your right to data portability
The Firm can export a client's complete file — profile, contacts, matters and attachment list — as JSON, Word, Excel or PDF, directly from that client's page.
Security measures
- Encrypted transport (HTTPS/TLS) between the browser and our servers.
- Two-factor authentication (2FA), enforced on every account.
- A comprehensive audit log of every create/update/delete — enforced append-only at the database level, so it cannot be edited or deleted, including by an administrator.
- Rate limiting on public-facing endpoints against abuse.
- File-upload type and content validation.
- Strict tenant isolation — every database query is scoped to the Firm's own data.
Cookies
We use only the cookies the Platform needs to function: your sign-in session, CSRF protection, and an optional "remember this device" cookie for two-factor authentication (30 days). We do not use marketing or third-party tracking cookies.
Contact us
For any data-protection request or question about this policy, email info@raseem.sa.