Projex Labs Products are coming "very soon"
← Back to home
Privacy & Data Protection

We treat your data like we treat our code — with care, and in the open.

This notice explains what data we collect, why we collect it, how long we keep it, who we share it with, and the rights you hold under Saudi Arabia's Personal Data Protection Law (PDPL, Royal Decree M/149). Effective date: 2026-06-02 (covers the projexlabs.com marketing site, the me.projexlabs.com identity surface, and the federated sign-in flows that route through Keycloak).

In one paragraph

We are the data controller for projexlabs.com. We collect only what we need to respond to an inquiry (name, email, the message you send) plus a single language-preference cookie. We don't sell data, we don't share with advertisers, we don't transfer Saudi personal data across borders without your consent. You can access, correct, or erase your data by emailing hi@projexlabs.com. If you think we've got something wrong, you can complain to the Saudi Data & AI Authority (SDAIA).

1. Who we are (Data Controller)

Projex Labs is the data controller for projexlabs.com and all personal data processed through this site. Contact: hi@projexlabs.com. Office: Riyadh, Saudi Arabia. If you need to reach the person responsible for data protection requests, email the address above with subject line "Privacy request" and we route it internally.

2. What personal data we collect

We collect three narrow categories. (a) Inquiry data: when you email us or click an email-me CTA, we receive your name (if provided), email address, and the contents of your message. (b) Technical data: a single language-preference cookie (pxl_lang) stored on your device to remember whether you prefer the English or Arabic edition; standard server request logs (IP address, user agent, requested URL, timestamp) generated by the hosting infrastructure and retained only for security and diagnostics. (c) Account data — explained in §2a immediately below — only collected if you create a Projex Labs account or sign in to one of our products. We do not use marketing cookies, advertising pixels, session replay, heatmaps, or third-party analytics.

2a. Account data (sign-in & profile)

If you create a Projex Labs account at me.projexlabs.com or sign in to a Projex Labs ecosystem product (Skyline, Omnideck, Trellis, Academy, Atelier, Lab), we additionally collect: (i) your email address — which acts as your username — and a short-lived 6-digit sign-in code we deliver via email (we never ask for or store passwords, the sign-in is always code-by-email); (ii) optional profile fields you choose to provide (name, headline, bio, avatar URL, location, industry, languages, pronouns, birthday, timezone); (iii) federated identity claims we receive from any third-party sign-in provider you choose (Google, Apple, GitHub) — typically your name, email address, and the provider's opaque user identifier (e.g. Google sub-ID), used solely to verify the link between your Projex Labs account and that third-party account; (iv) connected-account verification metadata — for accounts you choose to link (GitHub username, LinkedIn URL, your website) we store the URL plus a small verification proof (a rel="me" link, a DNS TXT record value, or a short token you display on your site) to confirm the account is yours; (v) the products you have signed in to, plus the tier/subscription state for each. We do not collect your contacts, calendars, files, browsing history, location beyond what you self-declare in your profile, or anything from outside the Projex Labs surface area.

3. Why we process it (Lawful basis)

Inquiry data is processed on the lawful basis of taking steps at your request before entering into a potential business relationship (PDPL Article 6) and, where applicable, your explicit consent (sending us an email is itself a signal of consent to reply). Technical data — the language-preference cookie and server logs — is processed on the lawful basis of our legitimate interest in operating a reliable, bilingual, secure website, weighed against your privacy interests.

4. How long we keep it (Retention)

Inquiry emails are retained for as long as the potential or active partnership conversation is live, plus up to 24 months after the last interaction to support follow-ups and legal record-keeping, after which they are deleted or anonymized. The pxl_lang cookie has a 180-day max-age on your device; you can clear it at any time from your browser settings. Server request logs are retained for up to 90 days for security purposes and then discarded or rotated out. Account data — your Projex Labs profile, federated identity links, and product tier state — is retained for as long as your account is active. When you request deletion (see §7), we close your account, then permanently delete the associated personal data within 30 calendar days, except for the minimal records we are legally required to retain (e.g. financial-transaction logs for the statutory period applicable to billing, where billing was activated). Sign-in codes (the 6-digit OTP) are valid for ~10 minutes and discarded immediately after use or expiry.

5. Who we share it with (Recipients)

We do not sell personal data and we do not share it with advertisers. Your data passes through the following processors strictly to deliver the service you requested: (a) email-delivery processor (Resend) for the sign-in code emails, welcome emails, and any account-related notifications we send to you; (b) authentication processor (Keycloak, self-hosted by us on Saudi-resident infrastructure) which manages the account, the sign-in flow, and the federated identity links; (c) Saudi-resident infrastructure hosting and CDN providers, which operate the website, the auth backend, and edge caching; (d) federated identity providers you choose to sign in with (Google, Apple, GitHub) — these are independent data controllers for the data they hold about you on their own platforms, and we only receive the limited claims described in §2a when you actively choose to use them. Each processor under our direction is bound to process your data only on our documented instructions and with confidentiality obligations. Independent controllers (the federated identity providers) operate under their own privacy notices, which we link from the sign-in page.

6. Cross-border transfers

Our production hosting, primary data residency, and account database are in Saudi Arabia (Oracle Cloud Riyadh region for our Core auth backend; CDN edge for the public marketing site). Certain operational systems may involve transfer outside the Kingdom: the email-delivery processor (Resend) operates from European and US regions, so the contents of transactional emails we send you (sign-in codes, welcome messages) transit through their infrastructure; the federated identity providers you choose to sign in with (Google, Apple, GitHub) operate globally. Where any transfer of Saudi personal data outside Saudi Arabia occurs, we only do so (a) where the destination country is recognized as providing an adequate level of protection under PDPL, or (b) where appropriate contractual safeguards (standard contractual clauses or equivalent) are in place, or (c) where you have given explicit consent — choosing to sign in with a federated identity provider constitutes that consent for the limited claims described in §2a. We never transfer personal data for advertising, profiling, or secondary purposes.

7. Your rights under PDPL

As a data subject under PDPL you have the right to: (a) be informed about how your data is processed — this notice; (b) access your data — request a copy; (c) rectify inaccurate data; (d) erase data where we no longer have a lawful basis to keep it; (e) restrict processing in specific cases; (f) object to processing based on legitimate interest; (g) withdraw consent where consent is the lawful basis; (h) not be subject to a decision based solely on automated processing that produces legal effects (we do not make such decisions on this site). For account-related requests you can also use the self-service controls inside your account at me.projexlabs.com: update your profile, unlink a federated identity provider, disconnect a verified social account, or initiate account deletion. For everything else — and for any account-related request you would rather route by email — write to hi@projexlabs.com. We respond within 30 calendar days; routine self-service requests are typically instant.

8. How to complain

If you believe we have violated your rights under PDPL, you can file a complaint with the Saudi Data & AI Authority (SDAIA) through sdaia.gov.sa or the National Data Management Office (NDMO). You retain all rights under Saudi law to seek judicial redress. We also welcome complaints directly at hi@projexlabs.com — we'd rather hear about it and fix it than have it go to the authority first.

9. Security

We apply technical and organizational measures proportionate to the nature of the data we handle: TLS 1.3 for all traffic, least-privilege access controls for the inbound inquiry channel, encrypted storage at rest on managed infrastructure, routine patching, and internal review of any change that could affect personal-data handling. We align our broader security posture with the National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC) and Cloud Cybersecurity Controls (CCC) where applicable. No system is risk-free, but we take our obligation seriously.

10. Children's data

This site is intended for partnership, research, and professional audiences. We do not knowingly collect personal data from children under 13. If you believe a child has provided data, contact hi@projexlabs.com and we will delete it.

11. Changes to this notice

We may update this notice to reflect changes to the law, our practices, or the site itself. The effective date at the top will change. Material changes (new data collection, new purposes, new recipients, new cross-border transfers) are called out explicitly when they happen.

12. Contact

Questions, requests, or complaints — email hi@projexlabs.com with subject "Privacy request" and your preferred language (EN/AR). We respond within 30 calendar days; routine requests within 48 hours.

How we map to Saudi PDPL — at a glance.

Each PDPL obligation mapped to the specific control or disclosure on this site. This is the same matrix we share with partners who ask for documented compliance.

PDPL ObligationHow projexlabs.com compliesReference
Privacy notice (Art. 4, 5)This page — plain-English + formal sections 1–12§1–§12 above
Identity of data controllerProjex Labs, Riyadh, Saudi Arabia — hi@projexlabs.com§1
Lawful basis for processingPre-contractual steps at your request (Art. 6); legitimate interest for technical data§3
Purpose specificationInquiry response + bilingual operation of the site — nothing else§2, §3
Data minimizationNo forms, no fingerprinting, no third-party trackers; inquiry is name/email/message only§2
Consent managementEmail-me-to-reply is the consent signal; pxl_lang cookie set only after language detection + user can clear§3, §4
RetentionInquiries: duration of conversation + 24 months; cookie: 180 days; logs: 90 days§4
Recipients / processorsEmail hosting + Saudi-resident infra; no advertisers, no data sale§5
Cross-border transfer rulesPrimary residency in Saudi; any transfer only with adequacy/SCC/consent§6
Data subject rights (all eight)Access, rectification, erasure, restriction, objection, portability, consent withdrawal, automated-decision opt-out§7
Right to complain to SDAIADisclosed with link pathway to sdaia.gov.sa and NDMO§8
Security measuresTLS 1.3, least-privilege access, encrypted at rest, NCA ECC/CCC alignment§9
Children's dataNot knowingly collected; deletion on notification§10
Breach notification readinessInternal runbook aligned to the 72-hour window; contact route definedSeparate operational runbook, available to partners on request
Automated decision-makingNone on this site. No profiling, no scoring, no algorithmic decisions affecting users§7(h)

References above point to numbered sections on this page. For the full operational runbook (breach handling, DPIA template, processor register, data residency map), partners can request it at hi@projexlabs.com.

Exercise your rights.

All privacy-related requests — access, correction, deletion, withdrawal of consent, complaint — route through one address. Please include "Privacy request" in the subject line so we triage correctly.