Skip to main content

Privacy Policy

Last updated: September 15, 2026

This Privacy Policy explains what personal data Salalem collects, what we do with it, who else handles it, how we protect it, and how to have it deleted. It covers the Salalem website, the Salalem platform, and the Salalem apps for Android and iOS.

Who this policy is from

Salalem publishes this policy and provides the Website, the Service and the Salalem mobile apps it covers. Salalem is referred to below as the Company. Write to support@salalem.com with any question about this policy, or about the data we hold on you.

Who decides what happens to your data

Nearly everyone who uses Salalem does so through an employer that bought the Service and created the account. In that arrangement your employer is the controller of your data and the Company processes it on their instructions: they decide who gets an account, what learning is assigned, who sees the results, and how long the account lasts. Questions about those decisions belong with your own administrator. Where you subscribed yourself rather than through an organization, the Company is the controller.

What we collect

Your account holds the identity details you or your administrator provide: name, email address, phone number, and the organizational details your administrator imports, such as job title and department. Your profile can also carry a photo, preferred language, city, country and nationality, year of birth, level of education, and employment status; these are optional and you can change or clear them. The Service records what you do in it — learning assigned and completed, assessment attempts and scores, time spent on an activity, video progress, certificates issued, and sign-in timestamps. What you submit is held with it: evidence you upload to show learning you did outside Salalem, such as a photo of a certificate or a PDF from another provider, and, where your employer has turned the social features on, the posts and images you share with colleagues.

What your device sends

To run and repair the Service, the apps and the website send technical data: device model and operating system, app version, language, IP address, and crash and error reports. If you allow notifications, the app registers a push token with Google's Firebase Cloud Messaging, or with Huawei on Huawei devices, so reminders about your own learning can reach you. The apps carry no advertising SDK. We do not use your data for advertising, we do not sell it, and we do not track you across other companies' apps or websites.

What the apps ask permission for

The mobile apps ask for five things, each at the moment it is needed rather than at sign-in, and each refusable. The camera, to photograph evidence of learning you did outside Salalem and, in a proctored assessment, the identity photos described below. Your photos and files, to attach an image or a PDF you already have instead of taking a new one, and to post an image to colleagues where your employer has turned the social features on. Your location, once, and only at the start of a proctored assessment. Notifications, to remind you about your own learning. Face ID or your fingerprint, only if you choose to unlock the app with it. That one is off until you switch it on, it reopens a session already stored on your phone rather than signing you in, and your face or fingerprint is checked by the phone itself and never reaches Salalem. The apps ask for nothing else: they do not record audio, they do not read your contacts or your calendar, they carry no advertising identifier, and they never read your location in the background. Refusing a permission stops only the thing it was for.

What a proctored assessment collects

Some assessments are proctored, and you are told before the attempt begins. Those attempts ask for a front-camera photo of you and a photo of an identity document, which are uploaded straight into private storage and are seen only by the people at your organization who review attempts, and some assessments ask for a second photo partway through the attempt. The app also takes a single location reading at the moment the attempt starts, to record where it was taken — you can decline and the attempt still begins, and the app never reads your location in the background. While the attempt runs, the app records integrity signals: leaving the app, switching browser tab, a signal that a screenshot was taken on Android or iOS, and whether the device has been jailbroken or rooted.

What we do with it

We use your data to run the Service your organization contracted: to let you in, deliver the learning assigned to you, score assessments, issue certificates, report progress to your administrator, and notify you about your own learning. Technical data is used in aggregate to fix faults and to see which parts of the product get used. We do not sell personal data and we do not share it for advertising.

How we protect it

Traffic between your device and Salalem travels over TLS, and the Android and iOS apps refuse unencrypted HTTP outright. Passwords are stored only as salted hashes, never in readable form. Every record in the platform is scoped to the organization that owns it and every request is checked against that scope, so one organization's data cannot be read from another's account; where your organization connects its own identity provider, joiners and leavers are governed by the directory it already audits. Photos, identity documents, reports and invoices sit in private storage that is not publicly addressable, encrypted at rest by the hosting provider, and reachable only through links that expire within the hour. Images you upload are downscaled and stripped of their embedded metadata, including any GPS coordinates the camera recorded, before they leave your device. On your device the sign-in token is held in the system keystore — the iOS Keychain or the Android Keystore — production builds ship obfuscated, and Android backups of app data are switched off. Course content and your progress are cached on the device so the app keeps working without a connection; uninstalling the app removes that cache. Inside the Company, access to customer data is limited to the staff who need it to run and support the Service.

Where it is stored

The platform runs on Microsoft Azure, and the region your organization's environment sits in is set when that environment is provisioned and confirmed in writing before contracting. Files uploaded to the Service — evidence, identity documents, reports — are held in Amazon S3 in Frankfurt, Germany. One transfer out of that is worth naming plainly: SCORM courses run on SCORM Cloud, which is served from the United States and offers no regional alternative, so a SCORM course's content and the results of taking it are processed there. If your regulator or your own policy requires a particular country, raise it during the evaluation — for SCORM that means a self-hosted runtime rather than a setting, which is a deployment decision we would rather take before contracting than after.

Who else handles it

A short list of providers processes data on our behalf, each for a single job: Microsoft Azure and Amazon Web Services host the platform and its files, and Cloudflare serves the website; SendGrid sends email, and Twilio sends text messages and one-time codes; Google's Firebase Cloud Messaging and Huawei deliver push notifications; Sentry receives crash and error reports, which can name the account and address involved in a failure; SCORM Cloud runs SCORM courses and records their results; PayTabs handles card payments made online; and HubSpot holds inquiries sent through this website so we can reply to them. The knowledge assistant runs on Salalem's own Azure OpenAI deployment in Sweden, reached over a private endpoint rather than the public internet, with Cohere re-ordering search results by relevance at the moment a question is asked. Where a course embeds a video hosted elsewhere — YouTube, Vimeo, Dailymotion or Wistia — playing it contacts that provider directly, so it sees the address you connect from and that a video was played; we send it nothing else about you. None of them may use your data for their own purposes, and no model is trained on your content.

How long we keep it, and how to have it deleted

While an account is active its data stays in the Service, so your record of completions, scores and certificates remains available to you and to your administrator. After an account is closed, the data it holds is retained for technical and analytical reasons. If you want that data deleted, ask us at support@salalem.com and we will remove it. Where the account belongs to an organization we act on that organization's instructions, so we will confirm the request with your administrator before deleting a record they are obliged to keep.

Your rights

We handle personal data in line with GDPR and Saudi PDPL. You can ask what we hold on you, have it corrected, get a copy of it, or have it deleted. Start with your own administrator, who holds the account and can correct much of it in the platform directly. A request to export or erase a record reaches us at support@salalem.com, and we act on it by hand rather than through a self-service button — we would rather tell you that than imply a control the product does not yet have. We will verify who you are first, because these requests concern data we should not hand to the wrong person.

Children's data

Salalem is a workplace learning platform. Accounts are created by employers for people who work for them, and the Service is neither intended for nor directed at children. We do not knowingly collect data from anyone under 16. If you believe a child holds an account, write to support@salalem.com and we will delete it.

Changes to this policy

When this policy changes, the date at the top of this page changes with it, and we tell administrators ahead of any change that materially affects what we collect or who processes it. The version published here is the current one.