Legal
Privacy policy
How we handle personal data across the KLEDHR platform and this website — where it lives, who can reach it, and what you can ask us to do with it.
Template pending legal review
This document is a working draft written to be a sensible starting point for a UAE SaaS company. It has not been reviewed by counsel and should not be published as-is. Last updated 17 August 2026.
1. Who we are
Kled AI (“Kled”, “we”) is a company based in Dubai, United Arab Emirates. We build KLEDHR, a multi-tenant HR, payroll and compliance platform for the UAE market.
This policy is written against the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and its executive regulations.
2. Two different roles
The distinction below decides who is accountable for what, and it matters more than anything else in this document.
When you visit this website
We are the controller. We decide what is collected and why — essentially, the contact details you submit and basic technical data described in section 3.
When your employer uses KLEDHR
We are a processor. Your employer is the controller of the employee data held in their tenant, and they determine how it is used. We process it on their documented instructions under a data-processing agreement. If you are an employee and want your record corrected or erased, please raise it with your employer’s HR team first — we are generally not permitted to act on it directly.
3. What we collect
Website
- Details you submit in the demo or contact forms: name, work email, company, headcount range, and anything you write in the message field.
- Standard server logs — IP address, user agent, requested path and timestamp — retained for security and troubleshooting.
This site does not use advertising cookies, cross-site trackers or third-party analytics profiling. If that changes, this section and a consent mechanism will change with it.
Platform
Within a customer tenant, KLEDHR processes the employee data that customer uploads or generates — identity and contract details, Emirates ID and visa records, attendance, leave, payroll and end-of-service calculations, documents, and recruitment records including CVs. The scope is set by the customer, not by us.
4. Why we process it
| Purpose | Basis |
|---|---|
| Responding to a demo or contact request | Steps taken at your request before entering a contract |
| Providing the platform to a customer | Performance of our contract with that customer |
| Securing the service and investigating incidents | Legitimate interest in operating a safe service |
| Meeting statutory record-keeping obligations | Legal obligation |
5. Where the data lives
Customer data is hosted in Azure UAE North (Dubai). Each customer tenant has its own isolated PostgreSQL database rather than shared tables filtered by a tenant column. Data at rest does not leave the UAE.
Traffic reaches us through a security edge providing TLS termination, CDN, WAF and DDoS protection, and is re-encrypted to origin. Edge processing may involve transient handling of request metadata outside the UAE; content at rest is not stored there.
6. AI processing
KLEDHR includes AI features. Three commitments govern them:
- Personal data is routed only to inference providers covered by a data-processing agreement that prohibits training on customer data.
- Every AI action is written to an audit log with the inputs it used, and any action that changes a record requires explicit human confirmation first.
- Generative AI is excluded from grievance and disciplinary workflows by design.
Named providers and their serving regions are set out in the architecture pack available to customers and prospects under NDA. A self-hosted deployment path exists for organisations that require no external inference calls at all.
7. Sharing
We do not sell personal data. We share it only with sub-processors that support the service — cloud hosting, the security edge, identity, error monitoring, email delivery and AI inference — each under contract and assessed before onboarding. A current sub-processor list is available on request, and customers are notified before a new one is added.
We may also disclose data where required by law or competent authority.
8. Retention
- Website enquiries: kept for up to 24 months from last contact, then deleted.
- Customer tenant data: kept for the life of the contract, then deleted or returned within 90 days of termination unless a longer statutory period applies.
- Backups: rolled off on the standard backup cycle; deletion requests are honoured in live systems immediately and in backups as they expire.
9. Your rights
Subject to the PDPL and to the controller/processor distinction in section 2, you may request access to your data, correction of inaccurate data, erasure, restriction of processing, a portable copy, or object to certain processing. You may also withdraw consent where consent is the basis.
Write to hello@kledhr.com. We respond within 30 days. If you are dissatisfied, you may complain to the UAE Data Office.
10. Security
- Encryption in transit throughout, and at rest for personal data.
- Per-tenant database isolation; access scoped at the service layer.
- Enterprise identity with MFA on privileged roles, and per-tenant SAML/OIDC single sign-on.
- Audit logging of security-relevant and AI events.
- Daily automated backups, with point-in-time recovery on enterprise tiers.
11. Children
The service is sold to businesses and is not directed at children. We do not knowingly collect data from anyone under 18 other than where an employer lawfully records a dependant’s details as part of an employee’s file.
12. Changes
We will update this page when our practices change and revise the date below. Material changes affecting customers are notified directly.
Last updated 17 August 2026. Questions: hello@kledhr.com. See also our terms of use.