Būlum Privacy Policy
Last updated: July 21, 2026
Platform name: Būlum
Company / operating entity: Būlum Company / شركة بولوم, or any legal entity operating, owning, or licensed to manage the platform, as announced within the app or the official website.
Official email for app management, privacy & support: support@bulumplatform.com
Company email: notifications@bulumplatform.com
Article 1: Introduction and the legal nature of the policy
1. The Būlum platform is keen to protect the privacy of its users and their personal data, and undertakes to process data in accordance with the laws, regulations, and instructions in force in the Kingdom of Saudi Arabia, and in a way that achieves the legitimate balance between:
- Protecting the user's privacy and legal rights.
- Enabling the platform to operate, develop, and improve its services.
- Managing accounts, services, bookings, payments, and settlements.
- Protecting users, service providers, and the platform from fraud, misuse, and circumvention.
- Managing reports, disputes, and conflicts.
- Complying with regulatory, security, and supervisory requirements.
- Preserving rights and proving operations within the platform.
2. This policy is a binding regulatory document governing the manner of collecting, using, retaining, processing, sharing, and protecting the personal, operational, financial, and technical data associated with using the Būlum app, its website, its services, and its official channels.
3. This policy is an integral part of the platform's adopted regulatory framework, which includes, without limitation:
- The Terms of Use.
- The Financial & Regulatory Policy.
- The Service Provider Agreement.
- The Code of Conduct.
- The Advertising Policy where it exists.
- The Reports & Disputes Policy.
- Any operational, financial, or technical policies, instructions, or annexes the platform adopts and announces to users.
4. By using the app, creating an account, browsing services, providing a service, requesting a service, making a booking, paying, communicating, uploading content, submitting a report or dispute, or using any feature within the platform, the user acknowledges that they have read, understood, and agreed to this policy, without prejudice to any rights established for them by law.
5. If the user does not agree to this policy, they must stop using the app and must not create an account or carry out any transaction through the platform.
6. This policy does not diminish any right established for the user under the laws in force in the Kingdom of Saudi Arabia, and it is interpreted so as to achieve data protection, regulatory compliance, and the stability of the platform's operation.
Article 2: Definitions
For the purposes of this policy, the following words and phrases have the meanings set out beside each of them, unless the context requires otherwise:
- Būlum: the Būlum electronic app and platform, including the app, the website, the technical systems, the interfaces, the services, and its associated channels.
- The platform / the app: all current or future Būlum interfaces, systems, and services, whether via the mobile app, the website, or any digital channel adopted by the platform.
- The company / operating entity: the entity owning, operating, or licensed to manage and operate the Būlum platform, per the details announced within the app or the official website.
- The user: every natural or legal person who uses the platform in any capacity, including the service seeker, service provider, visitor, browser, account holder, content publisher, advertiser, or any party interacting with the platform.
- The service seeker: the user who books, requests, or pays for a service, appointment, interaction, or experience through the platform.
- The service provider: the user who offers their services, appointments, interactions, or paid or free content through the platform in an independent service-provider capacity.
- Personal data: any data, whatever its source or form, that leads to identifying the user directly or indirectly, such as the name, mobile number, email, account data, identity data upon verification, limited payment data, location data, device identifiers, and usage records.
- Sensitive data: any data of a special or sensitive nature per the regulations, such as health, religious, political, biometric, or other data enjoying special legal protection, which the platform collects only where there is a clear legal justification or a specific operational necessity and to the extent needed.
- Processing: any operation carried out on data, including collection, recording, retention, organization, modification, use, analysis, disclosure, transfer, deletion, concealment, anonymization, or any other action relating to data.
- Controller: the entity that determines the purposes and means of processing personal data within the Būlum platform.
- Processor: any external party that processes data on behalf of and for the account of the platform, such as the payment, hosting, messaging, notifications, analytics, protection, video or voice communication, technical support provider, or any other operational or technical provider.
- Content: everything a user creates, uploads, sends, or displays within the platform, including texts, images, videos, audio clips, descriptions, appointments, prices, ratings, reports, messages, comments, posts, or any other digital material.
- Services: all the services available within Būlum, including voice appointments, video appointments, direct text chats, full-day in-person meetings, travel trips, audio clips, video clips, handwritten cards, and any subsequent services the platform adds.
- Operational data: the data necessary to manage operations within the platform, such as the booking state, booking time, service start, service end, session duration, acceptance, rejection, reason for rejection, payment, refund, dispute, report, rating, and support records.
- Limited financial data: the data relating to payments, collection, and settlements, such as the transaction amount, payment state, transaction reference, platform fees, service or booking fee, settlement data, and the service provider's IBAN data when needed, without this meaning that full sensitive card data is stored with the platform whenever the payment provider processes it directly.
- Anonymized or aggregated data: data processed so that it cannot reasonably be linked to a specific user, used for analysis, service improvement, internal reports, and general metrics.
- Payment provider: any payment gateway, payment processor, bank, or financial or technical entity the platform adopts to process payments, collection, settlement, or financial verification.
- The adopted policies: the Terms of Use, the Financial & Regulatory Policy, the Service Provider Agreement, the Code of Conduct, this policy, and any policies, instructions, or notices the platform adopts.
Article 3: Scope of the policy
1. This policy applies to all Būlum users, whether they are:
- Service providers.
- Service seekers.
- Registered users.
- Visitors or browsers.
- Users interacting with the platform via the app, the website, email, support, or any official channel.
- Advertisers or users of the platform's promotion services where available.
- Any party using any current or future service belonging to Būlum.
2. This policy covers the data collected or processed upon:
- Creating an account.
- Logging in.
- Setting up the profile.
- Offering services or appointments.
- Making bookings.
- Accepting or rejecting full-day in-person meeting or travel-trip requests.
- Starting or ending the service.
- Making a payment, refund, or settlement.
- Submitting a report, dispute, or complaint.
- Contacting support.
- Using messages, calls, video, or text chat within the platform.
- Using the advertising, promotion, or visibility features within the platform.
- Uploading, publishing, or sharing any content.
- Using any current or future service belonging to Būlum.
3. This policy does not apply to external websites, apps, or services not belonging to the platform, even if referenced or accessed through links within the app; their use is governed by their own privacy policies.
4. Būlum bears no responsibility for the privacy practices or data protection of any external party outside its control, while the platform remains committed to exercising appropriate care when selecting the providers necessary for its operation.
Article 4: The platform's capacity and its role in processing data
1. Būlum operates as a technology platform and an organized services marketplace that enables users to offer, request, and book services, interactions, and appointments per the adopted controls.
2. The platform processes data to the extent necessary to operate the platform, manage relationships between users, and provide the means of booking, payment, communication, reports, disputes, and settlements.
3. The platform's processing of data does not mean it is a direct party to the quality of the service provided between users, except within the limits of its role as a technical, organizing, and facilitating intermediary for payment and communication per the Terms of Use and the Financial & Regulatory Policy.
4. The platform reserves the right to process the data necessary to protect the platform's operational system, prevent fraud, verify compliance, manage disputes, and fulfill regulatory requirements.
5. In the platform's relationship with service providers, Būlum processes the data necessary to manage the service provider's account, verify, display services, receive bookings, process payments, settle entitlements, review reports, and apply the Service Provider Agreement.
6. In the platform's relationship with service seekers, Būlum processes the data necessary to create the account, browse services, book appointments, complete payment, communicate within the platform, submit reports or disputes, and protect the service seeker's rights.
7. The user acknowledges that data processing within Būlum is carried out to achieve operational, organizational, financial, security, and regulatory purposes necessary for the nature of the platform.
Article 5: The data the platform collects
Depending on the nature of the user's use of the platform, Būlum may collect the following types of data, without this meaning that all of this data is collected from all users:
First: Account and registration data
- The name or display name.
- The mobile number.
- The email.
- The password or access keys in an encrypted or secured form.
- Date of birth, age, or age group.
- Gender upon an operational, regulatory, or permitted advertising need.
- The account photo or profile photo when uploaded.
- The general city, country, or geographic region.
- The user's language and account settings.
- The account creation date and last login.
- The account status.
- The account-data update log.
Second: Identity and verification data
1. The platform may request additional verification data from some users or service providers, especially when activating trust, verification, or badge features, receiving payments, or protecting the platform from fraud.
2. Verification data may include:
- The legal name.
- The ID, residency, or another verification document number when needed.
- Date of birth.
- A photo or verification document when needed.
- Bank-account matching data.
- Registration or legal-capacity data whenever the user represents an entity.
- Any data necessary to verify the account holder or the service provider's eligibility.
3. The platform requests additional verification data only upon an operational, security, financial, or regulatory need, to prevent fraud, or to protect users.
Third: Profile and service-provider data
- The personal or professional description.
- Areas of expertise or interest.
- The offered services.
- The prices.
- The available appointments.
- The service duration.
- The type of service.
- The images, videos, or samples the service provider uploads.
- The cities or scope of availability.
- Users' ratings.
- The account, verification, distinction, or badge status.
- The service or appointment modification log.
- The service provider's visibility state or ranking within the platform.
- The data necessary to manage the Service Provider Agreement.
Fourth: Booking and service data
- The type of booked service.
- The booking date and time.
- The appointment date and time.
- The service duration.
- The price.
- The booking state.
- The payment state.
- The acceptance or rejection state of the request in the full-day in-person meeting or travel trip.
- The reason for rejection if the request was rejected.
- The time communication was opened.
- The service start time.
- The service end time.
- The party that started the service.
- The party that ended the service.
- Any delay in starting or ending.
- The reports or disputes associated with the booking.
- The review, refund, or settlement decisions.
- The dispute-window data after the service ends per what the Financial & Regulatory Policy adopts.
- Any operational data necessary to prove the course of the transaction and protect the parties' rights.
- Records of the service state and whether it is complete, cancelled, suspended, or under review.
Fifth: Payment and financial-transaction data
- The transaction amount.
- The platform fees.
- The service, booking, cancellation, or any announced regulatory fee.
- The payment state.
- The transaction reference number.
- The transaction time.
- The general payment method, without storing full sensitive card data with the platform whenever the payment provider processes it directly.
- Refund, cancellation, or bank chargeback data.
- Financial settlement data.
- The service provider's share data.
- The platform's share data.
- The service provider's bank account or IBAN data when needed for settlement or verification.
- The bank name or account holder's name when needed.
- The result of bank-account verification or the matching status.
- The relevant financial-correspondence records.
- Any data necessary for financial or accounting compliance or fraud prevention.
Sixth: In-platform communication data
1. Operational messages between users.
2. Direct text chats when using the chat service.
3. Voice or video call data such as:
- The call time.
- Its duration.
- The call state.
- The technical call quality.
- The disconnection or technical failure.
- The technical session identifier.
4. The platform does not use the content of private sessions for advertising purposes.
5. There is no human review of the content of private messages or sessions except within the limits of operational, security, or regulatory necessity, such as the existence of a report, dispute, suspicion of fraud or violation, or a request from a competent authority.
Seventh: Report, complaint, and dispute data
- The type of report.
- The description of the report.
- The reporting party and the party reported against.
- The booking or service associated with the report.
- The attached documents, images, or evidence.
- The log of correspondence with support.
- The review decisions.
- The report state.
- The measures taken.
- Any data necessary to protect rights, prevent misuse, or prove the incident.
- The log of prior reports associated with the account whenever necessary for assessment or protection.
Eighth: Rating and review data
- The numerical or written rating.
- The rating time.
- The service or appointment being rated.
- The visibility or concealment state of the rating.
- The reports associated with the rating.
- The platform's decisions regarding the rating if it breaches the terms or the Code of Conduct.
- Any operational data necessary to prevent fake, malicious, or abusive ratings.
Ninth: Technical and automatic data
- The IP address.
- The device type.
- The operating system and its version.
- The browser type when using the website.
- Device or app identifiers to the extent the operating systems allow.
- The session identifier.
- Log files.
- Login and logout times.
- The pages or screens used.
- Errors and malfunctions.
- Performance logs.
- Network data.
- Security data and login attempts.
- The language and time zone.
- The access or referral source when available.
- Technical data necessary to detect malfunctions, improve performance, or protect the platform.
Tenth: Geolocation data
- The platform may collect general or approximate geolocation data when needed to provide services related to location, region, advertising, or improving the user experience.
- Precise location is only collected when the user activates a feature requiring it, or upon a clear operational need, and per the permissions the user grants from their device.
- The user can control location permissions from their device settings, knowing that disabling them may affect some services or the accuracy of results, advertising, or nearby services.
- The user may not rely on the location data within the platform as an accurate or final guarantee unless the service expressly requires that and per what the platform makes available.
Eleventh: Advertising and personalization data
1. The platform may process limited data for the purpose of displaying internal advertisements or promotional campaigns within the platform.
2. Permitted targeting data may include:
- The age group.
- Gender where available.
- The city or region.
- General interests within the platform.
- The type of services the user interacts with.
- The advertising settings the advertiser chooses within the platform.
3. The platform does not sell personal data to advertisers.
4. Advertisers do not obtain the users' personal identity except where the user agrees, interacts with them of their own will, or where necessary to provide a service they requested.
Twelfth: Third-party registration or login data
- When the user chooses to log in via Apple, Google, or any external login provider, the platform may receive limited data such as the name, email, or external account identifier, depending on the user's settings and the external party's policies.
- The user's account with the external party is subject to that party's policy.
- The platform undertakes to protect the data it receives from those parties within this policy.
- The platform bears no responsibility for any glitch, restriction, or change in the external login services beyond its reasonable control.
Article 6: Data the platform does not intend to collect
1. Būlum does not aim to collect sensitive or excessive data not necessary to operate the service, protect users, or comply with the regulations.
2. The user must not upload or send sensitive data, excessive personal information, or data belonging to others without a legal justification or valid consent from the relevant person.
3. If the user sends sensitive or unnecessary data via messages, reports, content, or support, the platform may be compelled to process it to the minimum extent necessary to handle the request, report, dispute, or regulatory compliance.
4. The platform may delete, block, or restrict any data or content containing sensitive, non-compliant, or unnecessary information or that violates others' privacy.
5. The user bears responsibility for any sensitive data or data belonging to others that they enter, send, or publish without justification.
Article 7: Sources of data collection
The platform collects data from the following sources:
- The data the user provides directly upon registering or using the account.
- The data the user creates when offering a service, creating an appointment, or uploading content.
- The data resulting from bookings, payments, settlements, and disputes.
- The data resulting from communication within the platform.
- The data the system collects automatically for technical, security, and operational purposes.
- The data received from payment, verification, communication, or technical-service providers.
- The data another user provides in a report, rating, complaint, or dispute.
- The data received from official or competent authorities within the limits of the law.
- The data announced or available within the platform per the user's settings.
- The data resulting from the user's use of notifications, support, the official email, or any adopted channel.
Article 8: Legal bases for processing data
Būlum processes personal data based on one or more of the following legal or operational bases, according to the nature of the processing:
- Performing the contractual relationship between the user and the platform.
- Performing the booking, service, payment, or settlement.
- The user's express or implied consent where consent is required.
- Complying with a legal, judicial, or regulatory obligation.
- Protecting the legitimate interests of the platform or users, without prejudice to the user's fundamental rights.
- Preventing fraud and misuse and protecting the platform's security.
- Handling reports, complaints, and disputes.
- Protecting rights or proving transactions.
- Improving, developing, and analyzing the performance of the service.
- Fulfilling digital-safety requirements and protecting the community within the platform.
- Managing operational, financial, and technical risks.
- Protecting service seekers and service providers from circumvention, abuse, or non-compliant use.
Article 9: Purposes of using data
Būlum uses data for the following purposes:
- Creating and managing the account.
- Enabling the user to access the platform.
- Displaying profiles, services, and appointments.
- Enabling service providers to offer their services, prices, and appointments.
- Enabling service seekers to browse and book services.
- Managing instant bookings for voice, video, and direct text chat services.
- Managing full-day in-person meeting and travel-trip requests that require acceptance or rejection by the service provider.
- Sending acceptance, rejection, reminder, update, payment, or dispute notifications.
- Processing payments, refunds, and settlements.
- Implementing the dispute window after the service ends.
- Enabling communication within the platform before, during, or after the service per the adopted controls.
- Verifying the start, end, and duration of the service.
- Managing reports, complaints, and disputes.
- Protecting the platform from fraud, fake accounts, and non-compliant use.
- Verifying the identity of the user or service provider when needed.
- Customer support and responding to inquiries.
- Improving the user experience, interfaces, and features.
- Analyzing performance, malfunctions, and technical testing.
- Developing new features.
- Displaying more relevant advertisements, recommendations, or results within the platform.
- Protecting the rights of the platform and its users.
- Complying with the regulations and official requests.
- Retaining the records necessary to prove transactions.
- Conducting internal and statistical analyses.
- Preventing conduct in breach of the Code of Conduct.
- Applying penalties, restrictions, suspension, or bans upon a violation.
- Enabling badges, verification, or trust levels.
- Managing official communication with users.
- Managing the Service Provider Agreement and applying its obligations.
- Managing the Financial & Regulatory Policy relating to bookings, entitlements, and settlement.
- Preventing circumvention or moving the dealing outside the platform.
- Improving the safety of the operational environment within Būlum.
Article 10: Data visible to others within the platform
1. The user acknowledges that some data they add to their account, profile, or services may appear to others within the platform, according to the nature of the service and the visibility settings.
2. Data such as the following may appear to service seekers or users:
- The display name.
- The account photo.
- The personal or professional description.
- The offered services.
- The prices.
- The available appointments.
- The ratings.
- The city or scope of availability.
- The verification or badge status.
- The public content the user uploads.
- Any data the user chooses to make visible by the nature of the feature.
3. Limited data about the service seeker may appear to the service provider upon booking or requesting, such as:
- The display name.
- The booking data.
- The type of service.
- The date and time of the request.
- The payment or booking-confirmation state to the extent needed.
- Any data necessary to accept or reject the request or deliver the service.
4. No user may exploit the data visible within the platform to communicate outside the platform, harass, market without authorization, or violate others' privacy.
5. The user's sharing of their data within their public profile, via messages, or within the services is at their responsibility, while the platform retains the right to restrict or remove any data in breach of the law, the policy, or the Code of Conduct.
6. The service provider or service seeker may not copy, retain, or reuse the other party's data outside the scope of the service, booking, report, or legitimate right.
Article 11: Privacy of messages, calls, and sessions
1. The platform provides internal means of communication between users according to the type of service, such as messages, text chats, voice calls, video calls, or any other communication means the platform adopts.
2. The user may not use the platform's communication means except for the purposes of the service, booking, legitimate coordination, or performing the relationship associated with Būlum's services.
3. The platform does not review the content of private messages or sessions by humans in a general or random manner.
4. The platform may conduct a human or automated review or processing of communication content or data in cases that warrant it, including without limitation:
- The existence of a report from one of the parties.
- The existence of a financial or operational dispute.
- The existence of suspicion of fraud or misuse.
- The existence of an attempt at circumvention or moving the dealing outside the platform.
- The existence of content in breach of the laws, public decorum, or the Code of Conduct.
- Protecting a user or a third party from potential harm.
- The existence of a legal request from a competent authority.
- A limited, justified security test or internal investigation.
- Fixing a technical glitch or providing technical support requiring limited processing.
- Protecting the rights of the platform, users, or service providers.
5. The platform may use automated tools to detect patterns of risk, fraud, abuse, and circumvention, without this meaning direct human reading of every content or session.
6. The platform does not use the content of private messages or sessions for targeted advertising purposes in a manner that reveals the substance of the private communication between users.
7. The user may not record, photograph, publish, or reuse any session, conversation, or private content belonging to another party without their express consent and without breaching the laws or adopted policies.
8. Any user is prohibited from using messages, calls, sessions, or conversations to exchange external means of communication, payment links, bank accounts, or any means intended to bypass the platform or deal outside it.
9. The user acknowledges that communication records and session data may be used when needed to prove the service state, examine reports or disputes, prevent fraud, or protect rights.
10. The platform reserves the right to take action against any user who violates another user's privacy, including restriction, suspension, banning, withholding entitlements, or taking any other measure per the adopted terms and policies.
Article 12: Privacy of full-day in-person meeting and travel-trip services
1. Given the nature of full-day in-person meeting and travel-trip services, these services may require processing additional data associated with the appointment, day, trip, city, time range, request details, or the acceptance, rejection, payment, or communication state.
2. The service seeker uses the data available about the service provider to choose the suitable appointment, trip, or experience per the data visible within the platform.
3. When sending a full-day in-person meeting or travel-trip request, limited data about the service seeker and the request may reach the service provider — enough to review the request and accept or reject it per the platform's mechanism.
4. If the service provider rejects the request, the reason for rejection may be processed and displayed or sent to the service seeker to the extent needed to clarify the request state and manage the operational relationship.
5. The reason for rejection must be decent and must not contain any unnecessary personal data or abusive, discriminatory, or non-compliant phrases in breach of the laws, values, or adopted policies.
6. The platform may open a communication channel between the two parties after the booking is confirmed, before the appointment, or during the service duration, according to the type of service and the app's mechanism, for coordination and delivery purposes only.
7. No party may use the other party's data outside the scope of delivering the service, booking, or legitimate communication within the platform.
8. The service provider or service seeker may not retain, copy, publish, or reuse the other party's data or the meeting, trip, conversation, or private-arrangement details outside the platform without a legal justification or valid consent.
9. The platform bears no responsibility for any optional disclosure the user makes of their personal data to the other party outside the app or outside the adopted official channels.
10. The platform retains records of full-day in-person meeting and travel-trip services for the purposes of proving the booking, protecting rights, reviewing reports, managing financial settlements, preventing misuse, and complying with the regulations.
11. The user acknowledges that the nature of in-person meetings and travel trips may require a higher degree of personal responsibility, and that sharing any additional data between the parties is at the responsibility of the one who discloses it outside the scope of what the platform requests.
Article 13: Privacy of clips, cards, and interactive-content services
1. The platform may provide interactive services such as:
- An audio clip.
- A video clip.
- A handwritten card.
- Any custom content or output the service provider provides to the service seeker.
2. The user acknowledges that custom content may include personal data, names, phrases, occasions, or details the service seeker provides voluntarily for the purpose of delivering the service.
3. The service seeker must not provide the service provider with sensitive data, data belonging to others, or excessive information the service does not require, unless they have a legal justification or the consent of the relevant person.
4. The service provider remains responsible for not misusing any data, phrases, images, or materials that reach them from the service seeker for the purpose of delivering the interactive service.
5. The service provider may not use the custom content of the service seeker in marketing, publishing, public display, or reuse beyond the limits of fulfilling the request, except with the service seeker's express consent and in a manner not in breach of the laws and adopted policies.
6. The service provider may not include in the interactive output any data, images, phrases, or materials belonging to a third party without right, consent, or legitimate justification.
7. The platform may review the content or its data upon a report, violation, dispute, legal request, or suspicion of misuse or an infringement of privacy, intellectual property, or general values.
8. The user acknowledges that delivering the interactive content, retaining its records, or reviewing it upon a report is not an independent commercial use by the platform; rather, it is processing necessary to operate the service and protect rights.
9. The platform reserves the right to delete, restrict, or block any interactive content that breaches the laws, values, privacy, others' rights, or the platform's policies.
Article 14: Sharing data with technical and financial service providers
1. Būlum may share limited data with external service providers when needed to operate, improve, or protect the platform or to fulfill its obligations.
2. The parties with whom data may be shared include, without limitation:
- Electronic payment providers.
- Banks or settlement entities.
- Verification providers.
- Hosting and cloud-computing providers.
- SMS providers.
- Email and notification providers.
- Voice and video communication providers.
- Analytics and performance-monitoring providers.
- Cybersecurity and protection providers.
- Technical support providers.
- Legal, financial, or accounting advisors when needed.
- Any operational or technical provider necessary to provide or protect the service.
3. Data sharing with these parties is only to the extent necessary to fulfill the specific purpose, and in proportion to the nature of the service, transaction, report, or regulatory requirement.
4. The platform undertakes, as far as possible and according to the nature of the relationship, to bind service providers to the following:
- Maintaining confidentiality.
- Protecting data with appropriate measures.
- Not using the data for purposes independent of the agreed purpose.
- Not selling the data.
- Not re-disclosing except with permission or a legal justification.
- Restricting access to data as needed.
- Applying appropriate security measures.
- Deleting, returning, or restricting the data when the purpose ends, where possible and appropriate.
5. Sharing data with operating providers is not a sale of data; rather, it is processing necessary to provide the platform's services and operate payments, communication, verification, protection, and support.
6. Būlum bears no responsibility for any glitch, delay, or restriction from an external provider beyond its reasonable control, while remaining committed to exercising appropriate care in selecting and dealing with providers.
Article 15: No sale of personal data
1. Būlum does not sell users' personal data.
2. Būlum does not rent, trade in, or grant personal data to advertisers or external parties as an independent product.
3. The platform does not grant any advertiser or commercial party a direct right to access the user's personal identity, mobile number, email, or private data merely because that party advertises within the platform.
4. Advertisers do not obtain direct personal data about users except in cases the law permits, where the user interacts with them of their own will or consent, or where there is a clear operational justification associated with a service the user requested.
5. The platform may use anonymized, aggregated, or statistical data that does not identify the user for purposes of analysis, reports, service improvement, performance measurement, or general marketing of the platform.
6. Anonymized or aggregated data is not personal data whenever it cannot reasonably be linked to a specific user.
Article 16: Legal disclosure and the competent authorities
1. The platform may disclose the user's data if that is required or permitted by law.
2. Cases of legal disclosure include, without limitation:
- The existence of a court order.
- The existence of a request from a competent authority.
- The existence of a legal or supervisory obligation.
- Investigating fraud, abuse, threats, or a violation.
- Protecting the rights of the platform, its users, or others.
- Preventing actual or potential harm.
- Enforcing the adopted policies or terms.
- Combating money laundering, fraud, or prohibited activities where applicable.
- Complying with any financial, security, or regulatory requirements.
3. Disclosure is, where possible, to the extent needed and connected to the legal, operational, or security purpose.
4. Disclosure to the competent authorities, advisors, or service providers when needed is not a breach of data confidentiality or a violation of this policy.
5. The platform may be unable to notify the user of the disclosure if notification is legally prohibited, conflicts with the investigation, causes harm, or breaches the requirements of a competent authority.
6. The platform reserves the right to document any legal disclosure, official request, or compliance procedure per its internal records.
Article 17: Using data for advertising and marketing within the platform
1. Būlum may display advertisements, promotional content, or introductory campaigns within the app, the website, or the official channels.
2. The platform may use limited data to improve the relevance of the advertisement or promotional content, such as:
- The city or region.
- The age group.
- Gender where available and where there is an appropriate justification.
- The language.
- General interests within the platform.
- The type of services the user interacts with.
- The non-sensitive interaction log.
- Preference settings where the platform makes them available.
3. The advertiser is not provided with a list of users' names, numbers, email, or their direct personal data merely for advertising.
4. The advertiser may obtain general or aggregated statistics, such as the number of impressions, clicks, general category, or region, without enabling them to identify an individual user.
5. The platform does not use sensitive data for advertising purposes unless the law permits and with express consent when needed.
6. The user may manage some advertising preferences through the device or app settings where these options are available.
7. Advertisements or promotional content within the platform are not a disclosure of users' personal data to advertisers, unless the user agrees, interacts with the advertiser of their own will, or there is a legitimate justification.
Article 18: Notifications and operational messages
1. The platform sends the user important operational notifications and messages associated with their use of the app, their account, and their services.
2. Operational notifications and messages include, without limitation:
- The verification code.
- Account-creation confirmation.
- Booking confirmation.
- Payment notification.
- Request acceptance or rejection notification.
- An appointment reminder.
- Service start or end notification.
- Report or dispute notification.
- Refund, settlement, or payment-state notification.
- Policy or terms change notification.
- A security or administrative alert.
- A verification or authentication notification.
- A notification relating to restricting, suspending, or deactivating the account.
- Any notification necessary for operation or protecting rights.
3. Operational messages are a core part of the service, and the user may not be able to disable them entirely without affecting the use of the platform or some of its features.
4. The platform may send marketing, introductory, or promotional messages, and the user may unsubscribe from marketing messages where available, without affecting the necessary operational messages.
5. Sending notifications to the contact data registered for the user, or publishing them within the app or the notifications tab, is a sufficient means of notification whenever the platform adopts that.
6. The user undertakes to update their contact data, and the platform bears no responsibility for the non-delivery of a notification due to an error in the data, device settings, the service provider, spam, or any reason beyond its reasonable control.
Article 19: Cookies and similar technologies
1. The platform may use cookies or similar technologies when using the website, the associated interfaces, or some app features, for operational, technical, analytical, and security purposes.
2. These technologies are used, as needed, for purposes such as:
- Logging in.
- Saving preferences.
- Improving performance.
- Analysis.
- Security.
- Measuring advertisements or interaction.
- Preventing fraud.
- Improving the user experience.
- Detecting malfunctions.
- Protecting sessions.
3. The user can control some of these technologies from the browser or device settings where they are controllable by them.
4. Disabling some cookies or technical identifiers may disable some platform features, reduce the quality of the experience, or affect security or login.
5. The platform does not use these technologies to sell the user's identity or grant it to advertisers as an independent product.
Article 20: Data protection and security measures
1. Būlum takes appropriate technical, organizational, and administrative measures to protect personal data from unauthorized access, loss, damage, leakage, modification, or unlawful use.
2. These measures include, according to need, capabilities, and the nature of the data:
- Encrypting communication.
- Protecting passwords.
- Restricting permissions.
- Separating permissions by role.
- Access monitoring.
- Access logs.
- Periodic security review.
- Backups.
- Protecting operating environments.
- Monitoring malfunctions and breaches.
- Training or guiding staff and service providers when needed.
- Contractual controls with processors.
- Security-incident management.
- Continuously testing and improving the security procedures.
- Restricting internal access to data as needed.
- Using technical tools to detect abnormal login attempts or high-risk patterns.
3. The user acknowledges that the internet and technical systems cannot have their security absolutely guaranteed, and that the platform does not provide an absolute guarantee against any security incident, but undertakes to take reasonable and appropriate measures per the regulations.
4. The platform bears no responsibility for any leak, loss, or data damage resulting from:
- The user disclosing the password or verification code.
- Using a compromised or insecure device.
- Sharing the account with others.
- Using insecure public networks.
- Communicating outside the platform.
- The user uploading sensitive data or data belonging to others without justification.
- Errors or acts beyond the platform's reasonable control.
- Force majeure or general attacks that cannot be fully prevented, within the limits the law permits.
5. The user undertakes to notify the platform immediately upon suspicion of a breach of their account, a leak of their login data, or unauthorized use of their account.
6. The platform reserves the right to take the necessary measures to protect accounts and data, including requesting verification, changing login data, suspending the account, or restricting certain features upon a security danger or legitimate suspicion.
Article 21: Internal data-access controls
1. Būlum adopts the need-to-know principle in granting permissions to access users' data.
2. No employee, contractor, supervisor, or technical-service provider is granted general or absolute access to users' data; rather, access is restricted according to the operational, technical, security, or regulatory need.
3. Data-access permissions are determined based on criteria that include, without limitation:
- The nature of the role.
- The operational need.
- The type of data.
- The sensitivity of the data.
- The duration of the task.
- The level of risk.
- Security and compliance requirements.
- The nature of the report, request, dispute, or financial operation being processed.
4. The platform may grant limited, temporary permissions to some of its staff, service providers, or advisors when needed to handle a report, technical support, financial review, security investigation, or a legal obligation.
5. The platform may log access, processing, modification, export, or review operations for purposes of accountability, security, internal investigation, and compliance.
6. Any person authorized to access data is prohibited from using it outside the scope of the specified purpose, or disclosing, copying, or sharing it without authorization.
7. Any unauthorized access or non-compliant use of data is a serious violation warranting the appropriate legal, contractual, or operational measures.
8. The platform is not obliged to disclose to the user the details of its internal permissions, the names of authorized persons, or the internal investigation mechanisms, whenever disclosure could harm security or privacy or reveal the protection or fraud-prevention mechanisms.
Article 22: Record of processing operations
1. The platform may maintain an internal record of personal-data processing operations, for purposes of governance, compliance, review, and protecting rights.
2. The processing record may include, as needed:
- The type of data.
- The purpose of processing.
- The basis for processing.
- The category of users.
- The parties with whom data is shared.
- The retention period.
- The protection measures.
- Data transfer outside the Kingdom where it exists.
- The relevant incidents or reports.
- Any information necessary to prove compliance or improve data management.
3. The processing record is used for internal purposes including:
- Compliance review.
- Risk management.
- Responding to the competent authorities.
- Improving data-protection procedures.
- Documenting processing procedures.
- Security-incident management.
- Protecting the rights of the platform and users.
4. The processing record is not a public document available to users, and it may not be accessed except within the limits the law or the competent authorities determine.
5. The platform's maintenance of an internal processing record does not prevent the user from exercising their rights relating to their data per this policy and the applicable laws.
Article 23: Managing consents and acceptance records
1. The platform documents the user's acceptance of the relevant policies, terms, and agreements, whenever acceptance is required or necessary to prove the operational or legal relationship.
2. The documents and policies the platform may document the user's acceptance of include, without limitation:
- The Privacy Policy.
- The Terms of Use.
- The Financial & Regulatory Policy.
- The Service Provider Agreement where applicable.
- The Code of Conduct.
- Any subsequent material update.
- Any special consent associated with a particular service, feature, or processing.
3. Acceptance records may include:
- The date and time of acceptance.
- The version of the accepted policy or document.
- The method of acceptance within the app.
- The IP address when available.
- The device or session identifier when available.
- The account status at the time of acceptance.
- The language or interface used upon acceptance.
- Any technical or operational record necessary to prove acceptance.
4. These records are used to prove consent, manage the relationship with the user, comply, protect rights, respond to disputes, and prove obligations within the platform.
5. The user may withdraw consent in cases where consent is the sole legal basis for processing, knowing that withdrawing consent may lead to disabling some services, closing the account, or the inability to continue providing the service or performing some obligations.
6. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal, and does not prevent the platform from continuing to process data whenever there is another legal, contractual, or operational basis, such as retaining financial records, handling disputes, complying with the regulations, or protecting rights.
Article 24: The user's rights relating to their data
Subject to the legal and operational limits and the protection of others' rights, the user may exercise the following rights relating to their personal data:
- The right to know how their data is collected and used and the purpose of that.
- The right to access their personal data available with the platform through the means the platform provides or via an official request.
- The right to request the correction, completion, or updating of their data if it is incorrect, incomplete, or outdated.
- The right to request the deletion or destruction of their data when its purpose ends, unless there is a legal, contractual, or operational justification to retain it.
- The right to withdraw consent where consent is the sole basis for processing.
- The right to object to some types of processing where that is established by law.
- The right to request the restriction of some processing where that is possible, established by law, and does not conflict with operating the service or protecting rights.
- The right to submit a complaint or a privacy-related request through the adopted official channels.
- The right to approach the competent authority per the regulations if they believe their data-related rights were not observed.
- These rights are exercised in a way that does not lead to:
- Disabling existing financial or operational obligations.
- Concealing a violation, fraud, or misuse.
- Harming another user's rights.
- Breaching legal or supervisory obligations.
- Deleting records necessary to prove transactions or protect rights.
- Disabling the platform's ability to manage reports, disputes, or conflicts.
Article 25: The mechanism for exercising the user's rights
1. The user can exercise their data-related rights through:
- The account settings within the app where the feature is available.
- The adopted official channels within the app.
- The official email for app management, privacy, and support: support@bulumplatform.com
2. The request must include sufficient information to verify the requester's identity and identify the data or action requested.
3. The platform may request additional information to verify the user's identity before executing the request, to protect the data and prevent impersonation or unauthorized access.
4. The request is handled within a reasonable legal or operational period, according to the nature and complexity of the request, the account status, and the existence of any obligations, disputes, reports, or regulatory requirements.
5. The platform may refuse, restrict, or postpone the request in the following cases:
- The inability to verify the requester's identity.
- The request conflicting with a legal obligation.
- The existence of an ongoing dispute, claim, or report.
- The request conflicting with another user's rights.
- The request being repeated, malicious, or unspecified.
- The need to retain the data to prevent fraud, prove transactions, or comply.
- The data being associated with an ongoing financial operation, booking, settlement, or dispute.
- The existence of a legitimate security or operational reason.
- Any other case the law permits.
6. Deleting some data does not lead to deleting anonymized or aggregated records, temporary backups, or records that must be retained by law or operationally.
7. If the request relates to data visible in the user's account, profile, or services, the platform may ask the user to modify it directly from within the account where the feature is available.
8. The platform is not obliged to execute any request submitted through an unofficial channel or by a person who does not prove their capacity or authority to represent the user.
Article 26: Deleting and closing the account
1. The user may request the deletion or closure of their account per the mechanism the platform provides or through the adopted official channels.
2. Deleting the app from the user's device does not delete the account or the data from the platform's systems.
3. Upon a request to delete the account, the platform may, according to the case, do the following:
- Deactivate the account.
- Prevent access.
- Hide the public profile.
- Stop the display of services.
- Delete or anonymize unnecessary data.
- Retain the records necessary for the legal or operational periods.
- Restrict access to some data instead of deleting it if that is necessary to protect rights or comply.
4. The account may not be deleted in a way that leads to concealing fraud, misuse, evading financial obligations, or an ongoing dispute, report, violation, or entitlements under review.
5. If the user has active bookings, entitlements, disputes, reports, or existing obligations, the platform may postpone deleting some data until the necessary purpose ends.
6. If the user is a service provider, the platform may retain additional data necessary to prove services, bookings, entitlements, settlements, reports, and the obligations associated with the Service Provider Agreement.
7. Some data may remain in secured backups until the backup cycle ends, then it is deleted, replaced, or restricted per the adopted operational procedures.
8. Deleting the account does not forfeit any prior right of the platform or users or any financial, legal, or operational obligation existing before the deletion.
9. The platform may retain limited data about the deleted account to prevent fraud, abusive re-registration, or circumventing ban or suspension decisions.
Article 27: Data retention periods
1. The platform retains data as long as that is necessary to achieve the purposes for which it was collected, or to comply with the regulations, protect rights, prove transactions, or manage disputes.
2. The retention period varies according to the type of data, the nature of its use, and the legal or operational basis for retaining it.
3. The general retention periods are, by way of guidance, as follows:
- Active account data: for the duration of the account's activity.
- Account data after deletion: for the period necessary to execute the deletion or anonymization, while retaining what is legally or operationally necessary.
- Booking and service data: for the period necessary to prove transactions, manage disputes, comply, and protect rights.
- Payment and settlement data: per the necessary legal, accounting, and financial periods.
- Report and dispute data: until the report or dispute ends and for the period necessary to protect rights and prevent misuse.
- Security and login logs: for the period necessary for protection, analysis, and fraud prevention.
- Technical support data: for the period necessary to handle the request, improve the service, and protect rights.
- Marketing data: until unsubscription or the end of the purpose, unless there is another justification for retention.
- Anonymized and aggregated data: may be retained without a specified period whenever it no longer identifies the user.
- Backups: per secure operational cycles the platform determines.
- Verification and authentication data: for the period necessary to prove verification, prevent fraud, and comply.
- Service providers' financial and bank data: for the period necessary for settlement, compliance, and protecting rights.
4. After the retention purpose ends, the platform deletes, anonymizes, isolates, or restricts access to the data in an appropriate manner.
5. The user may not demand the deletion of data that must be retained by law, or to protect the rights of the platform or users, prove transactions, review reports, or prevent fraud.
6. The platform reserves the right to extend the retention period upon a dispute, report, investigation, claim, request from a competent authority, or a legitimate reason to protect rights.
Article 28: Anonymized and aggregated data
1. The platform may use data after anonymizing or aggregating it so that it is no longer reasonably associated with a specific user.
2. Anonymized or aggregated data is used for purposes including, without limitation:
- Statistical analysis.
- Service improvement.
- Performance measurement.
- Understanding usage trends.
- Preparing internal reports.
- Product development.
- General marketing of the platform without revealing the user's identity.
- Attracting partners, investors, or advertisers via general, non-personal metrics.
- Assessing the performance of categories and services.
- Improving safety and combating fraud.
- Studying market and usage metrics within the platform.
3. Anonymized or aggregated data is not personal data whenever it cannot reasonably be linked to a specific user.
4. The user may not object to the use of anonymized or aggregated data that does not lead to identifying them directly or indirectly.
5. The platform undertakes not to attempt to re-identify the user from anonymized or aggregated data except where that is legally or security-necessary or to protect rights and as the regulations permit.
Article 29: Transferring data outside the Kingdom of Saudi Arabia
1. Some of Būlum's services or its technical providers may require processing, storing, or transferring data outside the Kingdom of Saudi Arabia.
2. Data is only transferred outside the Kingdom upon an operational, technical, contractual, or regulatory need, and in accordance with the applicable regulatory controls.
3. External transfer may include, when needed:
- Cloud hosting.
- Payment providers.
- Voice or video communication providers.
- Messaging or email providers.
- Analytics or performance-monitoring tools.
- Technical support or cybersecurity.
- Verification or compliance providers.
- Any operational or technical provider necessary to provide or protect the service.
4. The platform undertakes, as far as possible and according to the nature of the relationship, to apply appropriate safeguards when transferring data, such as:
- Contracting with trusted providers.
- Restricting the purpose of processing.
- Restricting access.
- Confidentiality.
- Appropriate security measures.
- Compliance with the relevant Saudi regulations.
- Minimizing the transferred data to what is necessary.
- Monitoring the providers' level of compliance where appropriate and possible.
5. Transferring data outside the Kingdom does not mean waiving its confidentiality or granting the external party the right to use it for its independent purposes.
6. The user acknowledges that some technical, financial, or communication services may not work efficiently or may be unavailable if external providers cannot be used or data transferred to the extent necessary for operation.
Article 30: Sub-processors
1. The platform may use sub-processors to carry out some technical, operational, financial, or security functions.
2. Sub-processors may include, without limitation:
- Hosting providers.
- Messaging and notification providers.
- Payment providers.
- Verification providers.
- Voice and video communication providers.
- Cybersecurity and protection providers.
- Analytics providers.
- Technical support providers.
- Advisors or professional entities necessary for operation or compliance.
3. Sub-processors undertake, where possible and according to the nature of the contract, to:
- Process the data only based on the platform's instructions or per the specified purpose.
- Not use the data for unauthorized independent purposes.
- Not sell or share the data without permission or justification.
- Protect the data with appropriate measures.
- Report the relevant security incidents when needed.
- Delete, return, or restrict the data when the relationship ends where possible.
- Maintain confidentiality.
- Restrict access to the data as needed.
4. The platform remains keen to select service providers with an appropriate level of security and reliability, without this meaning an absolute guarantee of the actions of external parties beyond the platform's reasonable control.
5. Using sub-processors is not a sale of data or an abandonment of the platform's commitment to protect users' data per this policy.
Article 31: Security incidents and data leaks
1. If the platform becomes aware of a security incident that may affect users' personal data, Būlum takes the appropriate measures according to the nature, scope, and severity of the incident.
2. The measures the platform may take upon a security incident include, without limitation:
- Documenting the incident.
- Containing the impact.
- Identifying the scope of the affected data.
- Assessing the severity level.
- Addressing the technical or operational cause where possible.
- Taking corrective measures.
- Reviewing the relevant permissions or systems.
- Notifying the competent authorities when necessary per the regulations.
- Notifying the affected users when that is legally required or necessary to protect them.
- Taking any measure necessary to reduce the impact of the incident and prevent its recurrence.
3. Notifying the user or the competent authority of a security incident is not an automatic admission by the platform of legal liability, unless liability is established per the applicable laws.
4. The user undertakes to notify the platform immediately upon suspicion of:
- A breach of their account.
- Unauthorized use of their account.
- A leak of the password.
- A leak of the verification code.
- An unauthorized party accessing their account.
- The existence of an operation, booking, payment, or message unknown to them.
- Any abnormal activity relating to their account or data.
5. The user acknowledges that their delay in reporting any incident or security suspicion may increase the harm or make it impossible to fully address, and the user bears responsibility for any effect resulting from their negligence, delay, or disclosure of their login data.
6. Upon an incident or security suspicion, the platform may take precautionary measures including, without limitation:
- Temporarily suspending the account.
- Requesting re-verification.
- Changing the password.
- Disabling some features.
- Suspending bookings or payments.
- Restricting access.
- Blocking active sessions.
- Notifying the user or the competent authorities when needed.
7. The platform bears no responsibility for incidents arising from the user's breach of this policy or the Terms of Use, or from their negligence in protecting their account, device, or login data, within the limits the law permits.
Article 32: The user's obligations to protect their privacy
The user undertakes to:
- Provide correct, up-to-date, and non-misleading data.
- Not use others' data, impersonate them, or create an account with a name or capacity they do not have.
- Maintain the confidentiality of the password, verification codes, and access keys.
- Not share the account with any other party.
- Not enable any unauthorized person to use their account.
- Not send sensitive or excessive data without an operational need or a legitimate justification.
- Not publish, send, or upload personal data belonging to others without consent or a legal justification.
- Not photograph, record, or publish conversations, sessions, or private data belonging to another party without valid consent and without breaching the laws.
- Not move communication or dealing outside the platform in breach of the Terms of Use and the Financial & Regulatory Policy.
- Not use users' data for commercial, marketing, nuisance, or non-compliant purposes.
- Not use users' data for pressure, extortion, threats, defamation, or harming reputation.
- Notify the platform upon suspicion of any unauthorized use, breach, or leak.
- Comply with the Code of Conduct.
- Use the platform in a lawful and secure manner.
- Update their contact data, including the mobile number and email when they change.
- Not use insecure devices, networks, or apps in a way that exposes their account, their data, or others' data to danger.
- Not attempt to access data, accounts, or records they have no authority to access.
- Not use any tools or technical means to extract, copy, or collect users' or the platform's data without authorization.
- The user bears responsibility for any damage, claim, or violation arising from their breach of their obligations relating to protecting privacy or data.
- The platform may take the appropriate measures upon the user's breach of any of the obligations set out in this Article.
Article 33: Minors' privacy and age eligibility
1. Use of the Būlum platform is not permitted for anyone under thirteen (13) calendar years of age.
2. Those aged thirteen and above may use the platform per the controls the platform adopts, taking into account the relevant regulations and the rights of the guardian or custodian where necessary.
3. If the user is a minor per the applicable regulations, their use of the platform is under the responsibility of their guardian or legal custodian where necessary.
4. The platform may restrict some services or features from minor users or younger age groups, especially services that may require:
- A financial dealing.
- Direct communication.
- In-person meetings.
- Travel trips.
- Custom content.
- Sharing additional data.
- Any service the platform deems to need age controls or additional protection.
5. The minor user undertakes to obtain the guardian's consent whenever that is legally or operationally required.
6. The guardian or custodian, whenever they permit the minor to use the platform, acknowledges that they are responsible for monitoring the minor's use of the app and for any data they provide, transactions they carry out, or communication they conduct within the platform, within the limits the law permits.
7. If the platform finds that an account was created in breach of the permitted age or with incorrect data, it may take any appropriate measure, including:
- Suspending the account.
- Restricting the service.
- Deleting the account.
- Cancelling or freezing some transactions.
- Requesting additional verification.
- Preventing the use of some features.
- Taking any appropriate measure to protect the user and the platform.
8. The platform does not intend to collect data from those under the permitted age, and if it becomes aware of that, it will take the appropriate measure per the regulations and adopted policies.
9. No user may exploit the presence of a minor user within the platform, attempt to obtain their data, or communicate with them in a manner in breach of the laws, values, or the platform's policies.
10. The platform may adopt additional age controls, modify the eligibility limits, or restrict some features as it deems appropriate to protect users and comply with the regulations.
Article 34: Third-party data
1. The user may not enter, upload, send, or publish data belonging to a third party unless they have a legal justification or valid consent from the data owner.
2. If the user provides the platform with third-party data, they acknowledge that they are authorized to do so and bear full responsibility for the accuracy of this acknowledgment.
3. Third-party data includes, without limitation:
- Names.
- Mobile numbers.
- Email.
- Images.
- Audio or video clips.
- Identity data.
- Location data.
- Conversations.
- Any personal, private, or sensitive information relating to another person.
4. The user may not use Būlum's services to send third-party data to a service provider, service seeker, or the platform without an actual need, consent, or legitimate justification.
5. If the user's content, report, or request includes third-party data, this data must be limited, necessary, and proportionate to the legitimate purpose.
6. The platform may delete, restrict, or block any third-party data if it appears to have been sent without justification or to include a privacy violation or a breach of the laws or policies.
7. The user bears any claim, damage, or liability arising from their entering, publishing, or sending third-party data without right.
8. Būlum bears no responsibility for any third-party data the user uploads or sends on their own initiative, while the platform retains the right to process it to the extent necessary to handle the report, service, request, violation, or compliance.
Article 35: Public content and private content
1. Public content means all content the user publishes of their own will to appear to others within the platform or that is visible by the nature of the feature used.
2. Public content includes, without limitation:
- The profile.
- The account photo.
- The personal or professional description.
- The service descriptions.
- The service images.
- Public videos.
- The prices.
- The available appointments.
- Public ratings and reviews.
- The posts or materials the user chooses to make visible.
3. Private content means all content the user does not intend to publish to the public, such as:
- Messages.
- Reports.
- Private booking details.
- Payment data.
- Documents sent to support.
- Verification data.
- Conversations associated with the service.
- Any content that by its nature appears to specific parties only.
4. The system handles each type of content according to its nature, its visibility settings, and its purpose.
5. The user's publishing of public content within the platform means their consent to displaying it within the platform per its features, without this meaning the transfer of its ownership to the platform.
6. The user may not consider everything they place in their public profile, service, or rating to be confidential if it is visible by the nature of the feature.
7. No user may copy, republish, or exploit the public or private content of another user outside the platform in a manner in breach of the laws, policies, intellectual property rights, or privacy.
8. The platform reserves the right to restrict, delete, or hide any public or private content if it breaches the laws, values, privacy, others' rights, or the platform's policies.
Article 36: License to use user content for operational purposes
1. The user retains their ownership of the content they create, upload, publish, or send within the platform, whenever they own this content or have the right to use it.
2. Upon the user uploading, publishing, sending, or making available any content within Būlum, they grant the platform a non-exclusive, non-ownership-transferring, worldwide license, usable for using, storing, processing, displaying, technically copying, formatting, and technically adapting, to the extent necessary to operate the platform, provide its services, protect its rights, and improve it.
3. The content-use license includes the following purposes, without limitation:
- Operating the platform.
- Displaying the content per the user's settings and the nature of the feature.
- Displaying services and profiles.
- Enabling booking or delivering the service.
- Sending the content to the intended party upon the service.
- Retaining the necessary records.
- Handling reports and disputes.
- Protecting rights.
- Improving performance.
- Internal analysis.
- Preventing fraud and circumvention.
- Complying with the law.
- Arranging results, recommendations, and visibility within the platform.
- Testing and improving technical features.
- Featuring public content within the platform's interfaces, pages, or services.
4. For public content published within the platform or intended for public display — such as the profile, service descriptions, service images, public videos, ratings, and public content — the platform may use, display, re-feature, arrange, or embed it within the platform's interfaces or its introductory, marketing, or promotional materials associated with the platform, without any independent financial consideration for the user, unless expressly agreed otherwise.
5. For private content, such as messages, reports, documents, verification data, and payment data, the platform's use of it is limited to operational, security, financial, and regulatory purposes, such as delivering the service, handling reports, protecting users, complying with the regulations, and improving safety.
6. This license does not mean:
- Transferring ownership of the content to the platform.
- Selling the user's content as an independent product.
- Using private content in an independent external advertisement without justification or consent where required.
- Revealing private content to the public contrary to the platform's settings or the law.
- Forfeiting the user's legal rights relating to their data and content.
7. The platform may make the technical modifications necessary to the content to conform to display, storage, formatting, and operation requirements, such as changing the size, format, quality, or manner of display, without this being a distortion or a violation of the user's ownership.
8. The user may not upload content they do not own or that includes an infringement of others' privacy, intellectual property, or reputation.
9. The user acknowledges that deleting the account or deleting content may not lead to deleting all technical copies, records, backups, or data necessary for compliance, protecting rights, handling disputes, or preventing fraud.
10. The user bears any claim, damage, or liability arising from their content or from the platform's use of that content per the license granted by this policy.
Article 37: Ratings, reports, and disputes
1. The platform processes rating, report, and dispute data as a core part of protecting the quality of the platform's operational environment and managing trust between users.
2. Rating, report, and dispute data may include:
- The name or identifier of the reporter or rater.
- The other party associated with the report or rating.
- The type of service or booking.
- The service time.
- The description of the incident.
- The attached documents or evidence.
- The communication log associated with the service.
- The platform's decisions or measures.
- Any operational, financial, or technical data necessary to examine the case.
3. A limited part of the report or dispute may be shared with the other party to the extent necessary to respond, investigate, or settle, without disclosing unnecessary data.
4. The platform may hide, delete, or restrict the rating, report, or any associated content if it is:
- Abusive.
- Malicious.
- Containing unnecessary personal data.
- Containing insults, slander, or defamation.
- In breach of the Code of Conduct.
- In breach of the laws or public decorum.
- Unrelated to the service.
- Containing an attempt at extortion, pressure, or circumvention.
- Containing confidential information or third-party data without justification.
5. The platform is not obliged to disclose the full details of the internal review procedures if that would harm security or privacy, reveal fraud-prevention mechanisms, or harm the rights of another party.
6. The platform may retain report and dispute records even after the account is deleted, if they are necessary to protect rights, prove transactions, prevent recurrence, or comply.
7. The platform's retention of report and dispute data is not a breach of the right to deletion whenever the retention is necessary to protect rights, comply, or manage disputes.
8. The user is prohibited from filing malicious or fabricated reports or using reports and ratings to harm others, circumvent, or obtain an undeserved benefit.
Article 38: Automated decisions and technical analyses
1. The platform may use automated, algorithmic, or analytical tools for operational, security, and improvement purposes.
2. The uses of automated tools and technical analyses include, without limitation:
- Arranging results.
- Recommendations.
- Fraud detection.
- Security monitoring.
- Performance measurement.
- Improving the user experience.
- Detecting conduct in breach.
- Preventing fake accounts or abusive use.
- Analyzing service quality.
- Detecting attempts at circumvention or off-platform dealing.
- Identifying operational or financial risks.
- Improving advertising and personalization within the platform.
3. Using automated tools does not always mean making final decisions without human review, especially in cases that have a material effect on the user, whenever the law or the platform's policy requires that.
4. The user may contact the platform to object to a decision affecting their account, entitlements, or services, per the report, support, and adopted official channels.
5. The platform is not obliged to disclose its technical secrets, algorithms, fraud-prevention mechanisms, or detailed risk criteria in a way that would weaken its security or facilitate circumvention.
6. The results of analysis, ranking, or recommendation are not a guarantee of a service provider's quality, a service's suitability, or a specific outcome; rather, they are operational tools to improve and organize the platform experience.
Article 39: Privacy by design and by operation
1. The platform observes the principle of privacy by design and by default settings, to the extent appropriate to the nature of the platform, its resources, its services, and the operation requirements.
2. Observing privacy in design and operation includes, without limitation:
- Minimizing the collection of unnecessary data.
- Restricting access to data.
- Designing permissions according to need.
- Protecting data during operation stages.
- Testing new features from a privacy angle.
- Reviewing risks when adding new services.
- Restricting the use of sensitive data.
- Controlling data sharing with service providers.
- Enabling the user to manage some of their data where the feature is available.
- Retaining the records necessary to protect rights without unnecessary expansion.
3. When adding features with a higher privacy impact, the platform may update the policy, add notices, or request additional consents according to need and the regulations.
4. The privacy-by-design principle does not mean the platform collects only the absolute minimum of data; rather, it collects and processes what is necessary to operate its service, financial, security, and regulatory model and to protect users.
5. The platform undertakes to review its practices when needed in line with the development of services, regulations, and risks.
Article 40: Risk management and impact assessment
1. Būlum may conduct internal assessments of privacy and data-protection risks, especially upon changes, services, or operations with a higher data impact.
2. The cases that may warrant an internal risk assessment include, without limitation:
- Launching a new service.
- Adding a new technical provider.
- Processing sensitive data.
- Expanding advertising or analytics.
- A material change in payment or communication flows.
- Transferring data outside the Kingdom.
- The occurrence of a security incident.
- Adding new verification or authentication mechanisms.
- Launching in-person meeting, travel-trip, or extended services with a higher impact.
- A material change in the report, dispute, or settlement mechanisms.
3. Risk assessments aim to:
- Reduce risks.
- Improve compliance.
- Protect users.
- Protect the platform.
- Improve security measures.
- Control access and sharing.
- Determine corrective measures.
- Improve the design of services.
4. Internal risk assessments are not public documents or available to users, unless the law requires otherwise.
5. Not publishing the risk assessments does not prevent the platform's commitment to protecting data or cooperating with the competent authorities per the applicable regulations.
6. The platform may modify its procedures based on the results of the risk assessment, including restricting some features, modifying the manner of data collection, changing a service provider, or updating this policy.
Article 41: The service provider's responsibility for service seekers' data
1. The service provider undertakes to maintain the confidentiality of any data or information about the service seeker that reaches them through the platform or by reason of a service, booking, request, or communication that arose via Būlum.
2. The service seeker's data the service provider undertakes to protect includes, without limitation:
- The name or display name.
- The mobile number when it appears or reaches them lawfully.
- The email when it appears or reaches them lawfully.
- The booking data.
- The service details.
- The request details.
- Conversations.
- The images, files, or clips the service seeker sends.
- Location, city, or trip data when necessary for the service.
- Any personal or private information the service provider becomes aware of while delivering the service.
3. The service provider may not:
- Copy the service seeker's data beyond the scope of need.
- Retain it after the legitimate purpose ends.
- Share it with any third party.
- Use it to communicate outside the platform.
- Use it for marketing or re-targeting.
- Use it for nuisance or harassment.
- Publish or defame it.
- Exploit it financially, personally, or socially.
- Use it for pressure, threats, or extortion.
- Use it for any purpose unrelated to the booking or service within Būlum.
4. The service provider undertakes to use the service seeker's data only within the limits of delivering the booked service within the platform and per the Terms of Use, the Service Provider Agreement, and the adopted policies.
5. If the service provider needs additional data from the service seeker to deliver the service, the requested data must be necessary and proportionate to the nature of the service and not in breach of the laws or privacy.
6. The service provider may not request sensitive or excessive data from the service seeker except upon a clear necessity, a legitimate justification, and valid consent where required.
7. The service provider remains responsible for any misuse of the service seekers' data that reaches them by reason of using the platform.
8. The service provider's obligation of confidentiality and protecting the service seekers' data continues even after the service ends, the account is closed or suspended, or the service-provider status is ended.
9. The platform may suspend or ban the service provider, hold or deduct their entitlements, or take any appropriate measure if they breach the confidentiality or privacy obligation, per the Terms of Use, the Financial & Regulatory Policy, and the Service Provider Agreement.
10. The service provider bears full responsibility for any claim, damage, penalty, or obligation arising from their disclosure, misuse, or unlawful retention of the service seekers' data.
Article 42: The service seeker's responsibility for the service provider's data
1. The service seeker undertakes not to misuse the service provider's data, appointments, prices, content, images, clips, or information visible within the platform.
2. The service seeker may not use the service provider's data except within the limits of browsing, booking, or delivering the service, submitting a report, or exercising a legitimate right within the platform.
3. The service seeker is prohibited from:
- Harassing the service provider.
- Publishing the service provider's data outside the platform.
- Attempting to communicate with them outside the platform in breach of the terms.
- Photographing or recording the service without legitimate authorization or valid consent.
- Republishing their content without right.
- Using their images, clips, or description for commercial or abusive purposes.
- Extorting, threatening, or defaming them.
- Using their data for an unlawful purpose.
- Attempting to access information not visible or not intended for them.
- Using the service provider's information to circumvent the platform or deal outside it.
4. The service seeker may not copy, retain, share, or reuse the service provider's data or content except to the extent the laws, policies, and the nature of the service permit.
5. If the service seeker obtains data or information about the service provider during an in-person meeting, travel trip, conversation, voice or video appointment, or interactive service, they must use it only for the purpose of the service and not exploit it after it ends.
6. The platform may take the appropriate measures upon the service seeker's breach of this Article, including restricting or suspending the account, deleting the content, banning the user, or taking any appropriate operational or legal measure.
7. The service seeker bears any claim, damage, or liability arising from their misuse of the service provider's data, content, or information.
Article 43: External links and services
1. The platform may contain external links, integrations, or services necessary for or supporting the operation of some features or the provision of some services.
2. External links or services include, without limitation:
- Payment gateways.
- Third-party login services.
- Map or location services.
- Voice or video communication services.
- Messaging or email services.
- Informational or operational links.
- Support, verification, or protection tools.
- Any external technical, financial, or operational service the platform adopts.
3. Būlum bears no responsibility for the privacy policies or data-protection practices of external websites, apps, or services not belonging to it.
4. The user is responsible for reading the privacy policies and terms of any external service they use or move to.
5. The existence of a link or integration within the platform does not mean a full endorsement of the external party's privacy practices, unless the platform expressly states that.
6. When using an external provider necessary to operate a service within Būlum, limited data may be shared with them per this policy and to the extent necessary to provide the service.
7. Būlum bears no responsibility for any data the user provides directly to an external party outside the platform's channels or outside the adopted operational purpose.
8. If the user chooses to leave the platform or deal with an external party outside Būlum, that is at their personal responsibility, and that processing is not subject to this policy except within the limits the platform controls.
Article 44: Payment methods and card-data protection
1. Payments are processed via licensed or adopted payment providers, banks, and financial entities as the platform adopts.
2. The platform does not usually retain full sensitive card data if the payment provider processes it directly.
3. The platform may retain limited financial data necessary for operation, such as:
- The transaction reference.
- The transaction amount.
- The transaction state.
- The general payment method.
- The payment time.
- The payment result.
- The refund state.
- The bank-chargeback state.
- Settlement data.
- The fees or deductions associated with the transaction.
- Any operational data necessary to prove or process the transaction.
4. The use of payment methods is subject to the payment provider's terms and the relevant financial regulations.
5. The user undertakes not to use a payment method they do not own or have no right to use.
6. The user may not use payment methods in a fraudulent, unlawful manner or in breach of the regulations or the platform's policies.
7. The platform may share limited financial data with the payment provider, the bank, the settlement entity, or the competent authorities to the extent necessary to process the payment, refund, dispute, settlement, compliance, or fraud prevention.
8. The platform bears no responsibility for any glitch, rejection, delay, or restriction from the payment provider, the bank, or the financial entity beyond its reasonable control.
9. The user acknowledges that some payment, refund, or settlement operations may be subject to reviews, restrictions, or time periods imposed by the payment provider, the bank, or the regulations.
10. The platform retains payment records to the extent necessary to prove transactions, protect rights, and comply financially, accounting-wise, and legally.
Article 45: The service provider's bank-account data
1. The platform may request the service provider to provide bank-account or IBAN data or any financial data necessary to receive entitlements, verify, or comply.
2. The service provider's bank-account data is used for the following purposes:
- Verification.
- Settlement.
- Transferring entitlements.
- Handling financial errors.
- Matching the account holder's name.
- Complying with regulatory or financial requirements.
- Preventing fraud or misuse.
- Handling financial reports, disputes, or conflicts.
3. The bank data the platform may request includes, without limitation:
- The IBAN.
- The bank name.
- The account holder's name.
- The identity or registration data associated with the account.
- The verification or matching status.
- Any other data the payment provider, bank, or compliance requirements request.
4. The service provider bears responsibility for the accuracy, currency, and matching of their bank data.
5. The platform bears no responsibility for the delay, error, or failure of the transfer resulting from providing incorrect, incomplete, or mismatched bank data.
6. The platform may share this data with payment providers, banks, or financial entities to the extent necessary for execution, verification, or compliance.
7. The platform may suspend the entitlements, delay the settlement, or request additional verification if it finds incorrect, incomplete, suspicious, or mismatched bank data.
8. The service provider may not use a bank account that does not belong to them or that they have no right to use to receive entitlements, unless the platform expressly permits that per the controls it adopts.
9. The platform retains bank-account data and settlement records to the extent necessary for financial and accounting compliance, protecting rights, and proving operations.
Article 46: The limits of the platform's privacy-related liability
1. Būlum undertakes to exercise reasonable and professional care to protect data per the regulations and the standards appropriate to the nature of the platform, its services, its resources, and the processing risks.
2. The platform does not provide an absolute guarantee against any error, breach, glitch, technical incident, or unauthorized access, given the nature of the internet, technical systems, and external service providers.
3. The platform, within the limits the law permits, bears no responsibility for any damage, loss, disclosure, leak, or misuse of data arising from:
- The user's errors.
- The user sharing their data outside the platform.
- The user using an insecure device.
- The user disclosing access codes or the password.
- Sharing the account with others.
- The actions of other users beyond the platform's control.
- Malfunctions or errors of external service providers.
- General cyberattacks or force majeure.
- The user's breach of this policy, the Terms of Use, or the adopted policies.
- Communication, payment, or agreement outside the platform.
- The user uploading sensitive data or data belonging to others without justification.
- Using public networks, apps, or insecure tools.
4. This Article does not prejudice any liability established against the platform under a ruling or an applicable law.
5. The platform's taking of a security, operational, or precautionary measure is not an admission by it of responsibility for the origin of the incident.
6. The platform bears no responsibility for the data the user chooses to make public within their profile, service, or public content, whenever its appearance is a result of their choice or the nature of the feature used.
7. The user bears responsibility for their decisions relating to sharing their data with other users inside or outside the platform.
Article 47: Confidentiality of the platform's internal mechanisms
1. The platform is not obliged to disclose to the user its internal mechanisms or the details of its systems or technical tools whenever disclosure could harm the security of the platform or users or facilitate circumvention or misuse.
2. The internal mechanisms and information the platform is not obliged to disclose include, without limitation:
- The details of the anti-fraud systems.
- The internal risk rules.
- The algorithmic ranking criteria.
- The internal investigation procedures.
- The internal access logs.
- The detailed security mechanisms.
- The risk assessments.
- The analysis or classification models.
- The mechanisms for detecting circumvention or off-platform dealing.
- The technical-monitoring settings.
- The details of the technical or security infrastructure.
- The confidential verification procedures or suspicion indicators.
3. This restriction aims to protect the security of the platform and users, prevent circumvention, and preserve the integrity of the systems.
4. This does not prevent the user from exercising their legal rights relating to their data per this policy and the regulations.
5. The platform may provide the user with general or appropriate information about decisions affecting them, without being obliged to reveal technical, security, or operational details that could harm the platform or others.
6. The user may not object to the platform's non-disclosure of its technical secrets or internal mechanisms whenever the non-disclosure is justified by protecting security, privacy, rights, or preventing misuse.
Article 48: The effect of suspension, banning, or ending the relationship
1. Suspending the account, banning it, deleting the app, ending the relationship, or the user stopping using the platform does not lead to deleting all data immediately.
2. The platform may retain limited or necessary data after suspension, banning, deletion, or ending for purposes including, without limitation:
- Establishing violations.
- Preventing the return of abusive accounts.
- Protecting users.
- Protecting the platform's rights.
- Handling disputes.
- Retaining financial records.
- Complying with the regulations.
- Preventing fraud.
- Managing reports and disputes.
- Proving bookings, payments, or settlements.
- Preventing circumvention of ban or suspension decisions.
- Cooperating with the competent authorities when needed.
3. Some data may be anonymized or access to it restricted instead of fully deleting it, if that is more appropriate to protect rights, comply, and reduce risks.
4. If the suspended or banned account belongs to a service provider, the platform may retain additional data necessary to prove the services, entitlements, bookings, reports, and the service provider's obligations.
5. The user may not use a deletion or account-closure request to conceal a violation, evade a financial obligation, or prevent the review of an ongoing report, dispute, or claim.
6. The effect of the obligations relating to confidentiality, data protection, and not misusing others' data continues after suspension, banning, or ending.
Article 49: Cooperation with supervisory and regulatory authorities
1. Būlum undertakes to cooperate with the competent authorities within the Kingdom of Saudi Arabia in accordance with the laws, regulations, and instructions in force.
2. The requested data or information is provided to the competent authorities to the extent necessary and within the scope of the legal request, supervisory requirement, or legal obligation.
3. Cooperation with the competent authorities is not a breach of this policy or a violation of data confidentiality.
4. Cooperation with the competent authorities may include, without limitation:
- Responding to official requests.
- Providing certain records upon a legal request.
- Cooperating in cases of fraud, abuse, threats, or cybercrime.
- Cooperating in financial, tax, or regulatory requirements.
- Executing orders or decisions issued by a competent authority.
- Retaining or preventing the deletion of certain data upon a legal request.
- Providing what is necessary to protect users, rights, or public order.
5. The platform maintains appropriate records to prove compliance and legal cooperation when needed.
6. The platform may be unable to notify the user of the cooperation or disclosure if notification is legally prohibited, harms the investigation, or conflicts with the request of the competent authority.
Article 50: Priority of the documents and their integration
1. This policy is interpreted in integration with the Terms of Use, the Financial & Regulatory Policy, the Service Provider Agreement, the Code of Conduct, and any other adopted policies.
2. If the text relates to data privacy, its protection, its processing, and the user's related rights, this policy is the primary reference, unless another document provides higher protection or a more specific detail that does not conflict with the regulations.
3. If the text relates to payment, fees, refund, settlement, entitlements, the dispute window, or financial holds, the Financial & Regulatory Policy applies.
4. If the text relates to the service provider's obligations or their responsibility for service seekers' data, their services, or their entitlements, the Service Provider Agreement applies alongside this policy.
5. If the text relates to users' conduct, content, violations, communication etiquette, or preventing abuse or circumvention, the Terms of Use and the Code of Conduct apply alongside this policy.
6. If there is an apparent conflict between the documents, the texts are interpreted so as to achieve:
- Protecting personal data.
- Preserving users' rights.
- Protecting the platform.
- Preventing misuse.
- Preventing circumvention and off-platform dealing.
- Complying with the Saudi regulations.
- The stability of financial and operational operations.
- Not making Būlum responsible for delivering the service or its quality beyond the limits of its role as an organized technology platform.
7. In all cases, the binding laws and regulations in force in the Kingdom of Saudi Arabia prevail where there is an irreconcilable conflict.
Article 51: Priority of the Arabic language
1. The Arabic version of this policy is the original and authoritative version.
2. Any translation of this policy into another language is for facilitation purposes only.
3. Where there is a difference in interpretation between the Arabic version and any translation, the Arabic version prevails.
4. No translation, summary, or explanation of this policy is treated as a substitute for the adopted Arabic text, unless Būlum expressly declares otherwise.
Article 52: Severability
1. If any provision of this policy is found invalid or unenforceable, that does not affect the remaining provisions.
2. The invalid or unenforceable provision is replaced with a valid provision that achieves the nearest possible legal and operational purpose to its original intent.
3. The remaining provisions of this policy remain effective and binding to the maximum extent permitted by the regulations.
4. The invalidity or unenforceability of any provision does not disable the rights of the platform or users or the other obligations set out in this policy or the adopted policies.
Article 53: No waiver of rights
1. Būlum's failure to exercise any right or power under this policy is not a waiver of that right or power.
2. The platform's delay in taking action against a violation, incident, request, content, or processing is not an acceptance of it or a waiver of its right to take subsequent action.
3. Any waiver of a platform right is valid only if it is written, express, and issued by an authorized entity.
4. The platform retains the right to exercise its rights at any time, unless there is a legal impediment.
Article 54: Amendments to the Privacy Policy
1. Būlum may amend or update this policy from time to time in line with the regulations, operation requirements, data protection, and the development of the platform's services.
2. The reasons for amendment or update may include, without limitation:
- Regulatory changes.
- Technical changes.
- Adding new services.
- Improving privacy procedures.
- Requirements of the competent authorities.
- Changes to operation, payment, or communication.
- Adding new service providers.
- Developing report or dispute mechanisms.
- Modifying the types of data being processed.
- Improving security or governance measures.
- Updating the relationship with the other policies.
3. Users are notified of material amendments via the app, the notifications tab, email, or any appropriate channel the platform adopts.
4. Publishing the updated policy within the app, the website, or the platform's official channels is sufficient to prove its availability to users, unless the law or the nature of the amendment requires express acceptance.
5. Continued use of the platform after the update or notice is published is deemed acceptance of the updated policy, without prejudice to the user's legal rights.
6. The platform may request a new acceptance upon a material amendment requiring express consent.
7. If the user does not agree to the updates, they must stop using the platform and request the closure of the account per the adopted mechanism, while the obligations and records that must be retained legally or operationally remain.
Article 55: Contact regarding privacy
1. For any inquiry, request, or complaint relating to privacy, personal data, the app, the account, services, reports, or support, contact us through the adopted official channels within the app or the following email:
Official email for app management, privacy & support
Company email
2. The user's request must include sufficient information to enable the platform to understand the request, verify the requester's identity, and handle it correctly.
3. The platform may request additional information to verify the requester's identity, capacity, or authority before processing the request.
4. The platform undertakes to handle requests seriously and within an appropriate period according to the nature of the request and its legal and operational requirements.
5. The platform is not obliged to execute any request received through an unadopted channel or from a person who does not prove their capacity or authority to represent the user.
6. The channels published within the app, the official website, or this policy are the adopted channels for communication, and the platform may update them whenever needed.
Article 56: Final acknowledgment
The user acknowledges that they:
- Have read this policy in full.
- Understood its content and its legal and operational effects.
- Are aware of the types of data the platform may collect or process according to the nature of their use.
- Are aware of the purposes of processing data, including operating the platform, managing accounts, bookings, payments, communication, reports, disputes, settlements, protection, and compliance.
- Are aware of their rights relating to their data and the mechanism for exercising them through the adopted official channels.
- Agreed to the processing of their data per this policy and the supplementary terms and policies.
- Undertake to provide correct and up-to-date data and not to use others' data or violate their privacy.
- Undertake not to use the platform in a manner that violates others' privacy, data, or content.
- Are aware that some of their data may appear to others within the platform according to the nature of the account, service, booking, content, or visibility settings.
- Are aware that their continued use of the platform after any update to this policy is published or they are notified of it is deemed acceptance of the updated policy.
- Are aware that this policy does not diminish any right established for them under the laws in force in the Kingdom of Saudi Arabia.
- Are aware that the platform reserves the right to protect its systems, users, and rights per the terms, policies, and regulations.
- Are aware that deleting the account or stopping use of the app does not necessarily lead to deleting all data immediately whenever retaining some of it is necessary for compliance, protecting rights, proving transactions, handling disputes, or preventing fraud.
- Acknowledge that Būlum is an organized technology platform, and that processing data within it does not mean the platform is responsible for the quality of the services users provide or their results, except within the limits the regulations and adopted policies determine.
- Acknowledge that their use of the platform is per this policy, the Terms of Use, the Financial & Regulatory Policy, the Service Provider Agreement where applicable, the Code of Conduct, and all the adopted policies.
End of the Privacy Policy