This policy explains what data is collected when you use the OfficeUP.sa website, the OfficeUP app for iOS and Android, and the OfficeUP system installed at an organisation — how that data is used, who can see it, and how it is deleted.
Who we are
OfficeUP is a facility, workplace and meeting-room booking management system, developed and licensed to organisations in the Kingdom of Saudi Arabia.
Who is responsible for your data? — an important distinction
The OfficeUP system is installed on the servers of the organisation that licensed it, or on that organisation's own hosting. This means employee, building, booking and visitor data stays inside that organisation's environment and is not transferred to us. We do not access it and we keep no copy of it.
- If you are an employee or a visitor at an organisation that uses OfficeUP: that organisation (your employer or the host) is the controller of your data and is responsible for it. We are only the software vendor. Any request to access, correct or delete your data goes to the relevant department at that organisation, not to us.
- If you are a visitor to our website, or you contacted us to request a demo: we are responsible for the data you sent us directly, and the sections below apply to it.
We may provide an organisation — at its request and with its permission — technical support that requires temporary access to its system. This is done under an agreement with that organisation, is limited to the task at hand, and is not used for any other purpose.
1. Data collected by the OfficeUP.sa website
What we collect
- "Request a demo" form data: your name, organisation name, email address, phone number (optional), organisation size, and the text of your message. You provide this voluntarily.
- Server logs: like any web server, our server records the IP address, browser and operating system, the page requested and the time of the request. These are used only for site security and fault diagnosis.
- Theme preference: your choice of light or dark mode is stored in your own browser (localStorage). It never reaches us and does not identify you.
What we do not collect
- We show no advertising, do not sell your data, and do not share it for marketing purposes.
- We use no advertising-tracking cookies and no device fingerprinting.
- We never ask for sensitive data on the website: no ID documents, no banking details.
Why we use it
- To respond to your request and present the system to you.
- To contact you about that specific request — not to add you to mailing lists you did not ask for.
- To protect the website and improve its content.
2. The OfficeUP mobile app
The app does not work on its own: it is a front end for the OfficeUP system installed at your organisation, and it connects to that organisation's server. We, the app's developers, operate no server that collects your data — data travels between your device and your organisation's server directly.
What the app processes
- Sign-in data: your work email address and a temporary sign-in code sent to it. The app uses no passwords.
- Work data: your name, department and seat; your meetings and bookings; invitations you sent or received; your meeting check-ins; your planned office days; and visitors you invited. All of this is stored on your organisation's server.
- Device data: device name and type, the push notification token, and your app language and theme preference. These are used to deliver notifications to you and to let your organisation revoke a lost device.
Permissions the app requests, and why
- Camera: to scan the QR code at the meeting-room door for check-in, and to scan the device activation code. No photo is captured, stored or transmitted — the image is read in the moment only to extract the code.
- Notifications: so that meeting invitations, changes and attendee replies reach you. You can turn these off in your device settings at any time.
What the app does not do
- It does not track your location.
- It does not access your contacts, photos or files.
- It shows no advertising and contains no marketing trackers or behavioural analytics.
- It does not sell your data and does not share it with data brokers.
Third parties
We share data only with the services needed to deliver what you asked for:
- Firebase Cloud Messaging (by Google): to deliver push notifications to your device. Only your device token and the notification text pass through it.
- Your organisation's mail server (SMTP): to send sign-in codes and invitations. This server belongs to, or is subscribed to by, your organisation — not us.
- Microsoft 365, Google Workspace or Exchange: if your organisation enables calendar integration, room bookings are synchronised with its calendar on that service, under your organisation's own agreement with that provider.
- Our hosting provider: hosts our marketing website only.
We share data with no other party unless required to do so by law or by a judicial order in the Kingdom of Saudi Arabia.
How data is protected
- Sign-in by temporary codes sent to the official work email, instead of passwords.
- Roles, permissions and a location scope: an administrator sees only what falls within their scope.
- Integration secrets encrypted with AES-256.
- CSRF protection on every form.
- An activity log recording every sensitive administrative action: who performed it, on what, and when.
- Any device registered in the app can be revoked immediately from the admin panel.
That said, no method of electronic transmission or storage is one hundred percent secure. We take reasonable care, but we cannot guarantee absolute security.
Retention periods
- Contact form data: kept as long as it is needed to respond to you and follow up on your request, then deleted — or deleted earlier if you ask us to.
- Server logs: kept for a short period for security and diagnostics, then deleted automatically.
- System and app data: the retention period is set by the organisation that owns the installation, under its own policies and legal obligations — not by us.
Your rights
Under the Personal Data Protection Law of the Kingdom of Saudi Arabia, you have the right to know what data about you is processed, to request a copy of it, to request its correction or deletion, and to withdraw your consent.
- For data you sent us through the website: write to info@officeup.sa and we will respond within thirty days at most.
- For your data inside your organisation's system: address your request to the relevant department at your organisation, as it is the controller of that data. We will assist the organisation technically in carrying out your request if it asks us to.
Account and data deletion
An app account is not something you create: it is your work account inside your organisation's system. To delete it or delete your data:
- Employees of an organisation: ask the relevant department at your organisation to delete your account from the OfficeUP admin panel. This removes your personal data, bookings and invitations from the system, in line with your organisation's retention policy.
- Removing the device only: simply sign out of the app or delete it from your device. The push token is revoked and no further notifications reach you.
- If you contacted us through the website: send a deletion request to info@officeup.sa from the same email address you used to contact us. We will delete your data within thirty days and confirm it to you.
Children
The system and the app are intended for the workplace and are not directed at anyone under eighteen. We do not knowingly collect their data. If we learn that a minor's data has been collected without a lawful basis, we delete it.
Transfers outside the Kingdom
System data stays on your organisation's servers, wherever those are located. The push notification service (Firebase) may process the device token and the notification text on servers outside the Kingdom; this is inherent to the service, and an organisation may disable push notifications entirely if it prefers.
Changes to this policy
We may update this policy whenever the system's features or the legal requirements change. The date of the latest update is stated at the top of this page. If a change is material, we notify the organisations we are contracted with before it takes effect.
Governing law
This policy is governed by the laws of the Kingdom of Saudi Arabia, including the Personal Data Protection Law and its Implementing Regulations. The competent judicial authorities in the Kingdom have jurisdiction over any dispute arising from it.
Contact us
For any privacy question or request:
- Email: info@officeup.sa
- Website: https://officeup.sa