Privacy Policy

Effective date: April 10, 2026 · Last updated: September 3, 2026

This Privacy Policy explains how Mise ("we", "us", "our"), operated by Mubangizi Moses and accessible at miseapp.app, collects, uses, and protects your personal data. This policy is designed to comply with the Saudi Arabia Personal Data Protection Law (PDPL), enacted by Royal Decree M/19, and its implementing regulations.

1. Data Controller

The data controller for personal data processed through the Service is Mubangizi Moses, contactable at privacy@miseapp.app.

2. Data We Collect

2.1 Account Data

When you register, we collect:

  • Full name
  • Email address
  • Organisation name and type
  • Role within the organisation
  • Phone / WhatsApp number (optional, for supplier communication)

2.2 Operational Data

Data created through normal use of the Service:

  • Procurement requests, approvals, and purchase orders
  • Delivery records and inventory levels
  • Supplier contact details (name, WhatsApp number, email)
  • Delivery note photos (when using OCR feature)
  • Issuance and waste tracking records

2.3 Payment Data

Payment is processed by Dodo Payments, acting as our merchant of record. We store only your subscription plan, billing cycle, and invoice history. We never receive or store card numbers — Dodo handles card data under its own PCI DSS compliance.

2.4 Technical Data

We collect standard web analytics: IP address, browser type, device type, and pages visited. This data is used to maintain security and improve the Service.

3. Purpose and Legal Basis

Under PDPL Article 5, we process personal data for the following purposes:

PurposeLegal Basis (PDPL)
Providing the Service (auth, procurement workflows)Performance of contract (Art. 5.1)
Processing paymentsPerformance of contract (Art. 5.1)
Sending order notifications via WhatsApp/emailPerformance of contract (Art. 5.1)
Security monitoring and abuse preventionLegitimate interest (Art. 5.2)
Product improvement and analyticsLegitimate interest (Art. 5.2)
Marketing communicationsConsent (Art. 5.4) — opt-in only

4. Data Sharing

We share personal data only with the following sub-processors:

  • Supabase (database hosting) — all Service data, stored on AWS infrastructure in Ireland
  • Vercel (application hosting) — processes requests
  • Resend (email delivery) — transactional and notification emails
  • Meta Platforms (WhatsApp Business Cloud API) — supplier order notifications
  • Google Cloud Vision (OCR) — delivery note image processing
  • Groq (AI inference) — parsing inbound supplier messages
  • Upstash (Redis) — rate limiting; briefly holds IP addresses
  • Sentry (error monitoring) — diagnostic data from failed requests

Dodo Payments is our merchant of record. When you subscribe, Dodo is the seller of record and handles your payment details as an independent controller under its own privacy policy. We never receive or store your card details.

We do not sell personal data and we do not share it for advertising purposes. Each sub-processor listed above operates under a data processing agreement, in most cases incorporated into the terms accepted when the account was opened.

5. Cross-Border Transfer

Your data is stored in Ireland (AWS eu-west-1). If you are in the Kingdom of Saudi Arabia, this means your personal data is transferred outside the Kingdom.

PDPL Article 29 permits such a transfer where the recipient country provides an adequate level of protection or appropriate safeguards are in place. Ireland is subject to the EU General Data Protection Regulation, and our sub-processors operate under standard contractual clauses and recognised security certifications (SOC 2, ISO 27001).

6. Data Retention

  • Active accounts — data retained for the duration of the subscription.
  • Cancelled accounts — data retained for 30 days after cancellation, then permanently deleted.
  • Invoices and payment records — retained for 7 years as required by Saudi commercial law.
  • Security logs — retained for 12 months.

7. Your Rights Under PDPL

As a data subject under PDPL, you have the right to:

  • Access — request a copy of your personal data.
  • Correction — request correction of inaccurate data.
  • Deletion — request deletion of your data (subject to legal retention requirements).
  • Restrict processing — request that we limit how we use your data.
  • Data portability — receive your data in a structured, machine-readable format.
  • Object — object to processing based on legitimate interest.
  • Withdraw consent — withdraw consent for marketing communications at any time.

To exercise these rights, contact us at privacy@miseapp.app. We will respond within 30 days.

8. Data Security

We implement appropriate technical and organisational measures including:

  • Row-level security (RLS) — each organisation's data is isolated at the database level.
  • Encryption in transit (TLS 1.3) and at rest (AES-256).
  • Role-based access control enforced via JWT claims.
  • Webhook signature verification for all payment and messaging integrations.
  • Regular security audits.

9. Children's Privacy

The Service is designed for business use and is not directed at individuals under 18. We do not knowingly collect data from minors.

10. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email or in-app notice at least 14 days before they take effect.

11. Complaints

If you believe your data rights have been violated, you may file a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA) at sdaia.gov.sa.

If you are in the European Economic Area or the United Kingdom, you may instead lodge a complaint with your own national supervisory authority. You do not have to come to us first. A current list of EEA authorities is published by the European Data Protection Board at edpb.europa.eu; in the UK the authority is the Information Commissioner's Office at ico.org.uk.

12. Users in the EEA and the UK

Mise is operated from outside the EEA. Where we offer the service to people in the EEA or the UK, we process their personal data in accordance with the UK and EU General Data Protection Regulation in addition to the PDPL. Where the two differ, we apply whichever gives you the stronger protection.

Controller and processor. For the account data of the person who signs up we act as a controller. For the operational data an organisation puts into Mise — its staff, suppliers, requests, purchase orders and prices — the organisation is the controller and we act as its processor, acting only on its documented instructions. Organisations processing personal data of people in the EEA or UK should read our Data Processing Agreement, which takes effect on acceptance of the Terms of Service. For a signed copy, write to legal@miseapp.app.

Your rights. The rights listed in section 7 — access, rectification, erasure, restriction, portability and objection — are the rights available to you under Articles 15 to 21 of the GDPR, and withdrawal of consent under Article 7(3). We respond within 30 days.

Personal data breaches. If a breach affecting your personal data occurs, we will notify the competent supervisory authority within 72 hours of becoming aware of it where the breach is likely to result in a risk to your rights, and we will notify you directly without undue delay where the risk is high. Where we act as a processor, we will notify the controlling organisation without undue delay so that it can meet its own deadline.

No advertising trackers. Mise runs no advertising pixels, no third-party analytics and no cross-site tracking cookies on any of its pages. We do not sell or share personal data with advertising networks, and we never have.

13. Contact

For privacy-related inquiries: privacy@miseapp.app