Subprocessors
The categories of third party that process data on our behalf, what each receives and why, the standards we hold them to, and how to obtain the current named list.
Effective date: 9 August 2026 · Last updated: 9 August 2026
1. What a subprocessor is
A subprocessor is a third party that processes data on our behalf so that we can deliver the service — hosting the platform, storing files, generating AI output, taking a payment.
This is different from a platform you connect yourself. When you link an advertising or social account, that platform is not our subprocessor: it is your own provider, and you granted it your data directly. We only exchange with it what your instructions require.
2. Categories we engage
We publish categories here, and maintain the named list separately. That is deliberate: infrastructure and provider arrangements change, and a policy page that names vendors becomes inaccurate the moment one is replaced. An inaccurate disclosure is worse than a general one.
- Platform hosting — Runs the application and its interface. Processes all data that passes through the service, in transit and at rest.
- Database — Stores accounts, workspaces, campaigns, connection records and encrypted tokens.
- File storage and delivery — Stores and serves uploaded and generated media — images, video, audio.
- AI generation — Receives the prompt and any material attached to it, returns the generated output. Contractually prohibited from training general-purpose models on it.
- Payments — Processes subscription payments. Card details go directly to the payment provider and are never stored on SAIMA's systems.
- Email delivery — Sends transactional messages — verification, password reset, billing and security notices.
3. What we require of them
Every subprocessor is engaged under a written agreement that binds it to process data only on our documented instructions, to apply security measures appropriate to the data, to restrict access to personnel who need it, to notify us without undue delay of a security incident, and to delete or return data when the engagement ends.
AI providers carry an additional obligation: they may not use customer content to train, fine-tune or improve general-purpose models. Where a provider offers a zero-retention or no-training configuration, we select it.
Before engaging a subprocessor we assess its security posture, its data handling, and whether the arrangement is compatible with the commitments in our Privacy Policy.
4. Processing outside the Kingdom
Some subprocessors operate infrastructure outside the Kingdom of Saudi Arabia. Where personal data is transferred outside the Kingdom, we rely on the bases permitted by the Personal Data Protection Law and its implementing regulations, and impose contractual safeguards on the receiving party.
Customers with data-residency requirements should raise them before contracting so that we can confirm in writing whether we can meet them.
5. Obtaining the current list
The named list of subprocessors, with the function of each and the processing location, is available on request to any customer, and is provided as standard to enterprise customers during procurement.
Write to privacy@saimahub.ai. We do not require a confidentiality agreement to disclose it.
6. Changes
We notify customers before adding or replacing a subprocessor that processes personal data, so that there is time to raise an objection.
Where a customer has a signed Data Processing Agreement, the notice period and objection mechanism in that agreement prevail over this section.
Related documents
