Skip to content

Legal

Privacy policy

How we handle personal data across the KLEDHR platform and this website — where it lives, who can reach it, and what you can ask us to do with it.

Template pending legal review

This document is a working draft written to be a sensible starting point for a UAE SaaS company. It has not been reviewed by counsel and should not be published as-is. Last updated 17 August 2026.

1. Who we are

Kled AI (“Kled”, “we”) is a company based in Dubai, United Arab Emirates. We build KLEDHR, a multi-tenant HR, payroll and compliance platform for the UAE market.

This policy is written against the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and its executive regulations.

2. Two different roles

The distinction below decides who is accountable for what, and it matters more than anything else in this document.

When you visit this website

We are the controller. We decide what is collected and why — essentially, the contact details you submit and basic technical data described in section 3.

When your employer uses KLEDHR

We are a processor. Your employer is the controller of the employee data held in their tenant, and they determine how it is used. We process it on their documented instructions under a data-processing agreement. If you are an employee and want your record corrected or erased, please raise it with your employer’s HR team first — we are generally not permitted to act on it directly.

3. What we collect

Website

  • Details you submit in the demo or contact forms: name, work email, company, headcount range, and anything you write in the message field.
  • Standard server logs — IP address, user agent, requested path and timestamp — retained for security and troubleshooting.

This site does not use advertising cookies, cross-site trackers or third-party analytics profiling. If that changes, this section and a consent mechanism will change with it.

Platform

Within a customer tenant, KLEDHR processes the employee data that customer uploads or generates — identity and contract details, Emirates ID and visa records, attendance, leave, payroll and end-of-service calculations, documents, and recruitment records including CVs. The scope is set by the customer, not by us.

4. Why we process it

PurposeBasis
Responding to a demo or contact requestSteps taken at your request before entering a contract
Providing the platform to a customerPerformance of our contract with that customer
Securing the service and investigating incidentsLegitimate interest in operating a safe service
Meeting statutory record-keeping obligationsLegal obligation

5. Where the data lives

Customer data is hosted in Azure UAE North (Dubai). Each customer tenant has its own isolated PostgreSQL database rather than shared tables filtered by a tenant column. Data at rest does not leave the UAE.

Traffic reaches us through a security edge providing TLS termination, CDN, WAF and DDoS protection, and is re-encrypted to origin. Edge processing may involve transient handling of request metadata outside the UAE; content at rest is not stored there.

6. AI processing

KLEDHR includes AI features. Three commitments govern them:

  • Personal data is routed only to inference providers covered by a data-processing agreement that prohibits training on customer data.
  • Every AI action is written to an audit log with the inputs it used, and any action that changes a record requires explicit human confirmation first.
  • Generative AI is excluded from grievance and disciplinary workflows by design.

Named providers and their serving regions are set out in the architecture pack available to customers and prospects under NDA. A self-hosted deployment path exists for organisations that require no external inference calls at all.

7. Sharing

We do not sell personal data. We share it only with sub-processors that support the service — cloud hosting, the security edge, identity, error monitoring, email delivery and AI inference — each under contract and assessed before onboarding. A current sub-processor list is available on request, and customers are notified before a new one is added.

We may also disclose data where required by law or competent authority.

8. Retention

  • Website enquiries: kept for up to 24 months from last contact, then deleted.
  • Customer tenant data: kept for the life of the contract, then deleted or returned within 90 days of termination unless a longer statutory period applies.
  • Backups: rolled off on the standard backup cycle; deletion requests are honoured in live systems immediately and in backups as they expire.

9. Your rights

Subject to the PDPL and to the controller/processor distinction in section 2, you may request access to your data, correction of inaccurate data, erasure, restriction of processing, a portable copy, or object to certain processing. You may also withdraw consent where consent is the basis.

Write to hello@kledhr.com. We respond within 30 days. If you are dissatisfied, you may complain to the UAE Data Office.

10. Security

  • Encryption in transit throughout, and at rest for personal data.
  • Per-tenant database isolation; access scoped at the service layer.
  • Enterprise identity with MFA on privileged roles, and per-tenant SAML/OIDC single sign-on.
  • Audit logging of security-relevant and AI events.
  • Daily automated backups, with point-in-time recovery on enterprise tiers.

11. Children

The service is sold to businesses and is not directed at children. We do not knowingly collect data from anyone under 18 other than where an employer lawfully records a dependant’s details as part of an employee’s file.

12. Changes

We will update this page when our practices change and revise the date below. Material changes affecting customers are notified directly.

Last updated 17 August 2026. Questions: hello@kledhr.com. See also our terms of use.