<link rel="stylesheet" href="assets/vendor/intl-tel-input/css/intlTelInput.css" />

Settings

Settings

Text size
Language
Theme
Sign in

Effective date: September 15, 2026 · Last updated: September 15, 2026

Rawabit Privacy Policy

Introduction

Rawabit ERP respects user privacy and is committed to protecting personal data processed through the Rawabit website, mobile and tablet applications, cloud platform, and related services.

This policy explains what data Rawabit may collect, why it is used, how it may be shared, how long it is retained, and the choices and rights available to users.

Rawabit is developed and operated by Nadeer. “Rawabit,” “we,” “our,” and “us” refer to the Rawabit service and its operator.

Scope

This policy applies to:

Rawabit may act as a data controller when it determines the purpose and means of processing, and as a data processor when it processes employee, customer, or supplier data on behalf of a subscribing organization.

  • The Rawabit Android application.
  • The Rawabit iOS and iPadOS applications.
  • The Rawabit ERP website and platform.
  • Rawabit cloud services and APIs.
  • Related support, notification, and integration services.

Data We May Process

3.1 Account and identity data

3.2 Employment and HR data

3.3 Financial and operational data

3.4 Location data

Rawabit collects approximate and precise location data when a user operates attendance, check-in/check-out, workplace verification, or geofence-dependent features.

With the user’s permission, Rawabit may access location data:

Background location is used to detect entry into and exit from the user’s assigned workplace through geofencing and to perform or support authorized attendance check-in/check-out and related notifications.

Rawabit does not use location data for advertising. Rawabit does not sell, rent, or use location data to track users for marketing purposes.

Background location is accessed only after Rawabit presents a prominent in-app disclosure and the user grants permission through the device’s operating system.

Users may refuse or withdraw location permission at any time through device settings. Disabling location may prevent automatic attendance, workplace verification, and other location-dependent features from working. Other features that do not require location may remain available according to the user’s permissions.

3.5 Device, technical, and usage data

3.6 Camera, photographs, and files

Rawabit may request access to the camera, photographs, or files when users:

Rawabit accesses these resources only after permission is granted or the user selects the relevant file.

3.7 Notifications

Rawabit may request notification permission to provide:

Notifications can be disabled through device settings.

3.8 Biometric authentication

Rawabit may allow users to authenticate through device-provided fingerprint or facial-recognition functionality.

Rawabit does not collect or store copies of fingerprints or facial templates. Biometric verification is performed by the device operating system.

3.9 Communications and support

Rawabit may process messages, support requests, attachments, and feedback supplied to its support, sales, or account-management teams.

  • Name and username.
  • Email address and mobile number.
  • Profile image, when voluntarily provided.
  • Organization, branch, department, and job title.
  • User and employee identifiers.
  • Authentication and session information.
  • Roles, permissions, and login records.
  • Employment and contract details.
  • Attendance, working hours, and check-in/check-out records.
  • Leave, permission, service, and approval requests.
  • Salary, payslip, benefit, and deduction information.
  • Documents provided by the user or organization.
  • Performance, training, task, or timesheet data, when applicable.
  • Invoices, journal entries, payments, and expenses.
  • Purchase and sales information.
  • Inventory, warehouse, and product information.
  • Customer and supplier data.
  • Financial and operational reports.
  • VAT and electronic-invoicing information.
  • Project, task, and working-time information.
  • While the application is in use.
  • While the application is running in the foreground.
  • While the application is running in the background.
  • While the application is closed or not in use, when automatic attendance or workplace-geofence functionality is enabled and background-location permission has been granted.
  • Device type and model.
  • Operating-system and application version.
  • Language and time zone.
  • IP address.
  • Application and device identifiers, where permitted.
  • Session and login records.
  • Performance, diagnostic, and crash information.
  • Security and administrative audit logs.
  • Interactions with application functionality.
  • Add a profile photograph.
  • Capture or attach documents.
  • Scan QR codes or barcodes.
  • Attach receipts, invoices, or documents to requests.
  • Request and approval updates.
  • Attendance notifications.
  • Account and service updates.
  • Security alerts.
  • Relevant task and workflow notifications.

Sources of Data

Data may be obtained from:

  • The user.
  • The subscribing organization.
  • An authorized HR or system administrator.
  • Activity generated while using Rawabit.
  • The user’s device after the required permission is granted.
  • Integrations authorized by the organization.
  • Service providers where legally permitted.

Purposes of Processing

Rawabit processes data to:

  • Create and administer accounts.
  • Authenticate users and manage sessions and permissions.
  • Operate accounting, HR, inventory, procurement, sales, CRM, and project services.
  • Manage attendance and check-in/check-out.
  • Verify presence at an assigned workplace.
  • Operate geofencing and authorized automatic attendance.
  • Process leave, service, and approval requests.
  • Provide payslips and employee self-service.
  • Generate financial and operational reports.
  • Provide customer support.
  • Send service-related notifications.
  • Improve performance, reliability, and user experience.
  • Diagnose crashes and technical problems.
  • Prevent fraud, abuse, and unauthorized access.
  • Meet contractual, legal, and regulatory requirements.
  • Protect Rawabit, subscribing organizations, and users.

Legal Basis

Depending on the relevant circumstances and applicable law, processing may be based on:

  • User consent.
  • Performance of a contract or requested service.
  • Compliance with a legal or regulatory obligation.
  • Platform and user security.
  • Legitimate interests where permitted by law.
  • Processing instructions received from the subscribing organization.

Prominent Background-Location Disclosure

Before requesting background-location permission, Rawabit presents a prominent disclosure substantially stating:

Rawabit collects location data in the background, including when the application is closed or not in use, to detect entry into and exit from your assigned workplace and to perform or support authorized automatic attendance check-in and check-out. Location is used only for attendance and workplace-geofence functionality.

The user can continue to the operating-system permission request or choose “Not now.”

Sharing of Data

Rawabit does not sell personal data.

Data may be shared, where necessary, with:

Service providers are required to process data only for contracted purposes and apply appropriate safeguards.

  • The user’s subscribing organization and authorized administrators.
  • Cloud-hosting and infrastructure providers.
  • Notification, email, and messaging providers.
  • Technical-support, performance-monitoring, and cybersecurity providers.
  • Payment and billing providers where applicable.
  • Government or regulatory authorities where legally required.
  • Professional advisers and auditors where necessary.
  • A lawful successor in connection with a merger or reorganization.

Location Data Is Not Sold

Rawabit does not sell approximate or precise location data, use it for behavioral advertising, or share it with data brokers.

Location may be processed by technical infrastructure and service providers only as necessary to operate attendance and geofencing functionality under appropriate contractual and security controls.

Retention

Rawabit retains data only for as long as necessary to:

Location and geofence records are retained only for as long as necessary to provide attendance functionality and satisfy applicable organizational and legal requirements. When no longer required, data is deleted, destroyed, or anonymized according to the applicable retention policy.

Retention periods for employment and financial records may vary according to the subscribing organization’s instructions and applicable law.

  • Provide the services.
  • Perform the agreement with the subscribing organization.
  • Maintain required attendance and transaction records.
  • Meet legal, regulatory, accounting, and contractual obligations.
  • Prevent fraud and protect platform security.
  • Resolve disputes and enforce rights.

Account and Data Deletion

Users may request account or personal-data deletion through:

https://rawabit.cloud/contact

When an account belongs to an organization, Rawabit may refer the request to that organization because it may be the controller of the employee’s data.

Certain records may be retained where required by law, accounting obligations, contract, security, fraud prevention, or dispute resolution.

Uninstalling the application does not automatically delete the user’s account or server-side records.

Permissions and User Controls

Users can manage the following permissions through device settings:

Withdrawing permission prevents future access to the corresponding device function but does not automatically delete information that was previously processed lawfully.

  • Approximate or precise location.
  • Location while using the application.
  • Background location.
  • Camera.
  • Photographs and files.
  • Notifications.
  • Device biometric authentication.

Security

Rawabit uses technical and organizational measures intended to protect personal data, including:

No electronic transmission or storage system can be guaranteed to be completely secure, but Rawabit applies appropriate controls to reduce risk.

  • Encrypted network communications.
  • Identity and access management.
  • Role-based permissions.
  • Separation of organizational data.
  • Security and administrative audit logs.
  • Monitoring for suspicious access.
  • Backup and recovery controls.
  • Security updates and vulnerability remediation.

International Transfers

Rawabit may use cloud infrastructure or service providers that process data outside Saudi Arabia.

Where personal data is transferred outside Saudi Arabia, Rawabit handles the transfer according to the Saudi Personal Data Protection Law, its implementing regulations, and other applicable requirements.

Data-Subject Rights

Subject to applicable law, users may have the right to:

Rawabit may request information to verify the requester’s identity.

When Rawabit acts as a processor, the request may be referred to or handled in cooperation with the subscribing organization.

  • Be informed about the processing of their data.
  • Access their personal data.
  • Request a copy of their data.
  • Correct or complete inaccurate information.
  • Request deletion or destruction where legally permitted.
  • Withdraw consent where processing relies on consent.
  • Object or submit a complaint where permitted.

Employee Information

Organizations using Rawabit are responsible for having an appropriate legal basis to collect, enter, and process employee information and for providing required notices and obtaining any required consent.

Employees should ordinarily contact their employer’s HR or privacy representative regarding information controlled by their organization.

Children’s Privacy

Rawabit is intended for organizations and their authorized users and is not directed toward children.

Rawabit does not knowingly collect personal data from children for independent use of the application. If such data is identified without an appropriate legal basis, Rawabit will take reasonable steps to delete it.

Cookies

The Rawabit website may use cookies and similar technologies to:

Users can manage cookies through browser settings or available preference controls.

  • Operate the website.
  • Maintain sessions.
  • Remember language and preferences.
  • Improve performance.
  • Analyze use.
  • Enhance security and prevent misuse.

Third-Party Services

Rawabit may contain integrations or links to third-party services. Information submitted directly to an independent third party is governed by that party’s privacy policy.

This policy does not control the practices of independent third parties not controlled by Rawabit.

Security Incidents

If a personal-data security incident occurs, Rawabit will assess it, take appropriate measures to limit its effects, and provide any legally required notifications to authorities or affected data subjects.

Changes to This Policy

Rawabit may update this policy when functionality, processing practices, or legal requirements change.

The updated version and its effective date will be published on the Rawabit website. Material changes may also be communicated through the application or platform where appropriate.

Contact Us

For privacy questions and access, correction, or deletion requests:

Contact page: https://rawabit.cloud/contact

Website: https://rawabit.cloud