Privacy policy
Last updated 25 June 2026
This Privacy Policy explains how Shaiban Technology Ltd., trading as Sheba ("Sheba", "we", "us", or "our"), collects, uses, stores, shares, and protects personal data in connection with our website at www.shaiban.co and our products and services. It applies to visitors to our website, enterprise clients and authorized users of our products, and end-users whose data we process on behalf of those clients. Effective 25 June 2026.
On this page
1. Introduction and who we are
Shaiban Technology Ltd., trading as Sheba, is a technology company that provides AI-powered enterprise software and consulting services across the Arab region. Sheba is the commercial brand; Shaiban Technology Ltd. is the contracting legal entity. Our canonical website is www.shaiban.co.
Our products and services include: ChatSheba — an Arabic-native AI customer-support and CRM platform across WhatsApp Business, Telegram, the website chat widget, and mobile-app integration via API; Social Sheba — an AI marketing assistant that works in Arabic and its dialects, English, and most languages; Custom AI Solutions — agentic AI, document processing, and ERP integrations; and Consulting — AI readiness assessments and roadmaps.
If you have questions about this policy or our data practices, contact us at legal@shaiban.space.
2. What data we collect
Website visitors. This website has no account system, no login, and no database of its own. We collect personal data only when you submit one of our forms — a project request on the start page, a contact message, or a Social Sheba waitlist signup. A submission contains your name, the contact channel you chose (a WhatsApp number or a work email), and any optional details you add: your company name, company size, industry, and a short message describing what you want to build. We collect nothing you do not type in. The analytics described in Section 11 collect no personal data.
ChatSheba end-users. Where an enterprise client deploys ChatSheba, we process conversation content (the text of messages across WhatsApp Business, Telegram, the website chat widget, and mobile-app integrations), conversation history and session metadata (timestamps, channel identifiers, and session IDs), customer profile data supplied by the client (such as name, account numbers, and purchase history), and channel API metadata such as delivery-status indicators and phone-number identifiers. Sheba processes this data as a Data Processor on behalf of the enterprise client — see Section 5.
Social Sheba clients. We process brand assets (logos and visual style guides), tone-of-voice materials (copy briefs and editorial guidelines), marketing materials (existing content samples and advertising copy), and authorized-user account data (names and email addresses of client team members).
Custom AI Solution clients. We process business documents (contracts, invoices, and operational reports), ERP and operational data (employee records, supplier data, and financial transactions, to the extent they contain personal data), and any data provided to train or configure the AI system. For sovereign or on-premise deployments, data remains entirely within the client's own infrastructure and Sheba retains no copies after the engagement ends.
Consulting clients. We process internal business data (process documentation, organizational charts, and workflow descriptions) and the contact data of client personnel involved in the engagement (names, job titles, email addresses, and phone numbers).
3. How we collect data
Forms and direct submissions. We receive data through the forms on our website (the start-page project request, the contact message, and the Social Sheba waitlist), through client onboarding and billing exchanges, and through email correspondence you initiate.
Automatic collection. Server logs may record technical data such as an IP address, browser, device type, the pages accessed, HTTP response codes, and timestamps for security and reliability. Our analytics are cookieless and collect no personal data — see Section 11.
Client-provided data. For our products, we receive customer data fed into ChatSheba through the integrations the enterprise client configures, brand materials uploaded to Social Sheba by authorized users, documents submitted to Custom AI systems for configuration or operation, and information shared directly during consulting engagements.
Third-party integrations. When our products connect to channel APIs (such as the WhatsApp Business API), CRM systems, or ERP platforms, we receive the data necessary to provide the contracted service. The scope of that data is determined by the client's configuration.
4. Why we process data (legal bases)
Website forms — Purpose: to read your request, reply to it, and follow up about your project or enquiry. Legal basis: your request to be contacted (expressed by submitting the form) and our legitimate interest in communicating with prospective clients. We use these details for that purpose only — we do not sell your data, share it with advertisers, or use it to build a profile of you.
ChatSheba end-user data — Purpose: to power the conversational AI engine — routing messages, generating responses, and maintaining conversation context. Legal basis (as Processor): contractual obligation under our Data Processing Agreement with the enterprise client, who is the Data Controller.
Social Sheba — Purpose: to generate AI-assisted, brand-aligned marketing outputs. Legal basis (as Processor): contractual performance.
Custom AI Solutions — Purpose: to build, configure, and operate bespoke AI systems as specified in the client agreement. Legal basis (as Processor): contractual performance and documented client instructions.
Consulting — Purpose: to conduct AI readiness assessments and provide strategic recommendations. Legal basis: contractual performance.
Billing and payments — Purpose: to process payments, issue invoices, and maintain financial records. Legal basis: contractual necessity and legal obligation. Financial records are retained for the period required by applicable accounting and tax law.
5. Data Processor vs. Controller distinction
A Data Controller determines the purposes and means of processing personal data. A Data Processor processes personal data on behalf of, and under the instructions of, a Controller.
Sheba is the Data Controller for: data collected through our website (form submissions and cookieless analytics), data about our own employees and contractors, and authorized-user account data for our products.
Sheba is a Data Processor for: ChatSheba end-user conversation data (the enterprise client is the Controller), Social Sheba brand and content materials, Custom AI Solution documents and business data, and internal business data shared during consulting engagements.
Where Sheba acts as a Data Processor, we enter into a written Data Processing Agreement (DPA) with the enterprise client. The DPA covers the scope, nature, and purpose of processing; the categories of data and data subjects; security obligations and technical safeguards; sub-processor notification and approval procedures; data-subject rights-request procedures; breach-notification timelines; and the deletion or return of data on termination. To request a DPA, contact legal@shaiban.space.
Enterprise clients are solely responsible for ensuring a valid legal basis for sharing personal data with Sheba, for providing the required privacy disclosures and obtaining the required consents from their end-users, and for complying with the applicable privacy law in their jurisdiction.
6. Third parties we share data with
We do not sell personal data.
Website sub-processors. For this website specifically, a small set of providers process data on Sheba's behalf, each for one job: Plausible provides cookieless page-view analytics and processes no personal data; Resend sends the team an email notification of your form submission; Telegram sends the team a message notification of your submission; and Vercel hosts and serves the website. Each processes only what is needed to run the site and reach you.
Meta / WhatsApp Business API. ChatSheba routes messages through Meta's WhatsApp Business API; message content and associated metadata are transmitted to Meta's infrastructure as part of service delivery. Enterprise clients should review Meta's data-use policies for WhatsApp Business.
AI model providers. Queries and conversation snippets may be passed to leading third-party AI model providers during inference. Sheba is model-agnostic and selects providers based on client requirements and performance, using API configurations that explicitly prohibit providers from using submitted data to train their models.
Cloud hosting providers. Depending on deployment requirements and client preferences, we use established cloud providers, all bound by data-processing agreements. Region-specific deployment is available to clients with data-residency requirements.
Payment processors. Billing information is transmitted to payment processors for secure processing. We do not store full payment-card details, and our payment infrastructure adheres to PCI-DSS standards.
Legal and regulatory authorities. We may disclose personal data where required by applicable law or court order, or to protect our legal rights and the safety of others.
Professional advisors. Lawyers, accountants, auditors, and insurers are contractually bound to confidentiality and receive only the minimum data necessary.
Business transfers. In a merger, acquisition, or sale of assets, personal data may be transferred as part of the transaction, subject to equivalent privacy protections; affected individuals will be notified as required by law.
7. International data transfers
Data collected through our services may be transferred to and processed in countries outside the country where it was first collected.
To protect data during international transfers, we apply contractual safeguards through our Data Processing Agreements or equivalent standard contractual clauses with sub-processors; we select sub-processors on the basis of recognized security certifications (such as ISO 27001 or SOC 2) and the availability of regional data-residency options; and we offer client-directed data residency on request — contact legal@shaiban.space.
Where any applicable data protection law governs a transfer, we commit to identifying an appropriate legal basis for the processing, honoring the data-subject rights described in Section 10, and implementing appropriate transfer mechanisms for data leaving its jurisdiction of origin.
8. Data retention
We retain personal data only for as long as necessary to fulfill the purposes described in this policy, or as required by applicable law.
Website form data is kept only as long as needed to answer you and keep a record of the engagement, and is removed on request. Server and security logs are retained for up to 12 months. ChatSheba conversation data is retained per the client service agreement, defaulting to 12 months after a conversation ends, then deleted or anonymized. Social Sheba brand and content assets are kept for the duration of the service agreement plus 90 days, then permanently deleted. Custom AI Solution data in cloud deployments is kept for the duration of the service agreement plus 90 days; for sovereign or on-premise deployments, no copy is retained after the engagement. Consulting internal business data is kept for the duration of the engagement plus one year, then deleted or returned to the client. Billing and financial records are retained for the period required by applicable accounting and tax law.
9. Security measures
Technical measures. We use TLS 1.2 or higher for all data in transit and AES-256 encryption for data at rest. Internal systems are protected by role-based access controls and multi-factor authentication. Third-party integrations use authenticated, encrypted API connections. We run periodic vulnerability assessments and risk-prioritized patching.
Organizational measures. We apply data minimization — collecting only what is necessary for the specified purpose — provide privacy and security training to staff with access to personal data, conduct security due diligence on sub-processors with contractual security requirements before onboarding, and maintain a documented breach-response procedure with notification within legally required timelines.
Limitation. No method of electronic storage or transmission is completely secure. While we apply industry-standard safeguards, we cannot guarantee absolute security. If you believe your data has been compromised, contact us immediately at legal@shaiban.space.
10. Your rights
Under applicable data protection law, you have the rights set out below. These rights apply to data for which Sheba is the Data Controller. For data processed through our products where Sheba acts as a Data Processor, please direct your request to the enterprise client, who is the Data Controller.
Right of access — you may request confirmation of whether we hold personal data about you and receive a copy of it. Right to correction — you may request correction of personal data that is inaccurate, incomplete, or out of date. Right to deletion — you may request deletion of your personal data where it is no longer necessary for the purpose collected, where you have withdrawn consent, or where processing has been unlawful, unless continued retention is required by law. Right to withdraw consent — where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal. Right to object — you may object to processing based on our legitimate interests where your particular situation warrants; we will stop unless we can demonstrate compelling legitimate grounds. Right to data portability — you may request your data in a structured, commonly used, machine-readable format where technically feasible and required by applicable law.
Right to complain — you may lodge a complaint with the competent data protection authority in the applicable jurisdiction. We encourage you to contact us first at legal@shaiban.space so we can address your concern directly.
How to submit a request — email legal@shaiban.space with your full name, contact information, the right you wish to exercise, and enough information to identify the personal data concerned. We will acknowledge your request within 3 business days and respond fully within 30 days. For complex requests, we may extend this period by a further 30 days with prior notice.
11. Cookies policy
This website sets no analytics or advertising cookies. Our analytics tool, Plausible, is cookieless: it counts page views and tells us which pages are useful without setting cookies, without collecting personal data, and without tracking you across sites. Because nothing is stored on your device for tracking, this site shows no cookie consent banner — the only consent we collect is the inline acknowledgement on the start-page form.
We store two small preferences on your device — your language choice (English or Arabic) and your light or dark theme — so the site remembers them on your next visit. While you are filling in a form, any marketing reference from the link you arrived on is held in your browser's session storage and cleared the moment you close the tab. This storage stays on your device, is never used to track you, and is never shared.
We do not deploy marketing or retargeting cookies, advertising trackers, social pixels, fingerprinting, or cross-site cookies. You can clear the language and theme preferences at any time through your browser's storage settings for this site; nothing else is stored. Because there is no tracking to opt into, there is no separate Do Not Track mechanism to honor — there is simply nothing that follows you off this site.
12. Children's data
Our products and services are designed exclusively for businesses and adult professionals. We do not knowingly collect personal data from individuals under the age of 18. By submitting a form, you represent that you are at least 18 years of age.
Where ChatSheba is deployed in contexts in which minors may interact with the system, the enterprise client — as the Data Controller — is solely responsible for providing appropriate disclosures, obtaining parental or guardian consent, and ensuring compliance with all applicable child-data-protection laws.
If we become aware that we have inadvertently collected personal data from a minor, we will promptly delete it. Please notify us at legal@shaiban.space if you believe this has occurred.
13. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal obligations, or regulatory requirements. When we make changes, we will update the "Last updated" date on this page and post the revised policy at www.shaiban.co/en/privacy.
Material changes include the collection of a new type of personal data not previously described, sharing data with a new third party not previously disclosed, a change in the legal basis for any processing activity, or a change in retention periods to the detriment of data subjects. Continued use of our website or services after a revised policy is posted constitutes acceptance of the updated terms to the extent permitted by applicable law. A version history is available on request — contact legal@shaiban.space.
14. How to contact us
For any question, concern, or request relating to this Privacy Policy or our data practices, email legal@shaiban.space or write to us via www.shaiban.co. The contracting legal entity is Shaiban Technology Ltd., Yemen.
We will acknowledge your inquiry within 3 business days and aim to resolve it within 30 days, or within any shorter timeframe required by applicable law. If your concern is not resolved to your satisfaction, you may escalate to the competent data protection authority in the applicable jurisdiction.
This policy is governed by the laws of Yemen. Any dispute will first be addressed through good-faith negotiation for at least 30 days; failing resolution, it will be submitted to the competent courts of Yemen, or to arbitration where the parties have agreed to it.