1. Introduction and scope
This Privacy Policy for the Kingdom of Saudi Arabia ("Policy") explains how CAN Mobilities, Inc. and its affiliates ("CAN," "we," "us," or "our") collect, use, disclose, and protect personal data when individuals and organizations in the Kingdom of Saudi Arabia ("KSA" or the "Kingdom") interact with our products and services — including CareOS, our AI-powered healthcare operating system; CAN Companion, our AI care companion; CAN Devices, our connected health hardware; and our websites, applications, and related services (collectively, the "Services").
This Policy is issued in accordance with the Personal Data Protection Law of the Kingdom of Saudi Arabia, promulgated by Royal Decree No. M/19 of 9/2/1443H (16 September 2021), as amended by Royal Decree No. M/148 of 5/9/1444H (27 March 2023), together with its Implementing Regulations and the Regulations on Personal Data Transfer Outside the Kingdom (collectively, the "PDPL"), as supervised by the Saudi Data & Artificial Intelligence Authority ("SDAIA") and any successor competent authority.
If you access the Services from outside the Kingdom, our global Privacy Policy applies. If there is any conflict between this Policy and the global Privacy Policy with respect to personal data processed subject to the PDPL, this Policy prevails to the extent of the conflict.
2. Our roles: controller and processor
CAN acts in two distinct roles under the PDPL, and your rights and our obligations differ depending on the role:
- Controller. When you visit our websites, request a demo, subscribe to communications, or use consumer-facing features of the Services in your personal capacity, CAN determines the purpose and manner of processing and acts as a controller.
- Processor. When CAN provides CareOS, CAN Companion, or CAN Devices to a hospital, healthcare provider, insurer, government entity, or other organization in the Kingdom (each, a "Customer"), CAN processes personal data — including health data — on behalf of and under the documented instructions of that Customer, which acts as the controller. In that case, the Customer's own privacy notice governs, and requests to exercise rights over such data should be directed to the Customer. We support our Customers in responding as required by the PDPL and our contracts.
3. Personal data we collect
Depending on how you interact with the Services, we may collect the following categories of personal data:
- Identity and contact data: name, email address, telephone number, organization, job title, and correspondence you send us.
- Account and usage data: credentials, role and permissions, device identifiers, log data, IP address, browser type, and interactions with the Services.
- Health data (sensitive data): where processed for a Customer or with your explicit consent — clinical records, care plans, vital signs, assessments, medications, and related information. Health data is "sensitive data" under the PDPL and receives heightened protection as described in Section 7.
- Device and sensor data: readings and telemetry generated by CAN Devices, such as activity, falls, location (where enabled), and biometric measurements.
- AI interaction data: prompts, conversations, and responses exchanged with CAN Companion and other AI features.
- Marketing data: preferences, subscriptions, and engagement with our communications.
We collect only the personal data that is adequate, relevant, and limited to what is necessary for the purposes described in this Policy, consistent with the data minimization requirements of the PDPL.
4. Legal bases for processing
The PDPL requires that personal data be processed on a lawful basis. We rely on the following bases:
- Consent: for marketing communications, optional features, and any processing of sensitive data where the PDPL requires explicit consent. Consent is freely given and specific, and you may withdraw it at any time as described in Section 12; withdrawal does not affect processing carried out before withdrawal.
- Actual interest: where processing achieves your actual interest and contacting you is impossible or difficult, as permitted by the PDPL.
- Contract and legal obligation: where processing is necessary to perform an agreement to which you are a party, or to comply with an obligation under the laws of the Kingdom.
- Legitimate interest: for non-sensitive data only, where permitted by the PDPL and its Implementing Regulations, and provided your rights and interests are not prejudiced — for example, securing and improving the Services.
- Health purposes: health data is processed in accordance with the PDPL's specific conditions for health data, under the controllership of our Customers where applicable.
We do not process personal data in ways incompatible with the purposes for which it was collected without a lawful basis for the new purpose.
5. How we use personal data
We use personal data to:
- Provide, operate, secure, and maintain the Services.
- Deliver care coordination, monitoring, alerting, and clinical workflow functionality on behalf of our Customers.
- Respond to demo requests, inquiries, and support tickets.
- Send service communications and, with your consent, marketing communications (you may opt out at any time).
- Improve and develop the Services, using de-identified or aggregated data wherever feasible.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Comply with the laws and regulations of the Kingdom and respond to lawful requests from competent authorities.
6. AI features and CAN Companion
CareOS and CAN Companion use artificial intelligence to support care. In the Kingdom, we design and operate these features consistent with the PDPL, SDAIA's AI Ethics Principles, and applicable guidance of the Saudi health authorities:
- AI outputs are decision-support tools. They do not replace the judgment of licensed healthcare practitioners, and clinical decisions remain with qualified professionals.
- We do not permit third-party foundation-model providers to train their models on personal data or patient data processed through the Services.
- Personal data submitted to AI features is retained only as needed to deliver the feature and is not used for advertising.
- We apply human oversight, testing, and monitoring appropriate to the healthcare context, and we work to identify and mitigate bias in AI features.
7. Health data and sensitive data
Health data is sensitive data under the PDPL and is subject to strict controls:
- Access to health data is restricted to the minimum number of employees and workers necessary to provide the required services, on a need-to-know basis.
- Processing of health data is limited to the minimum extent necessary to provide health services or health insurance programs.
- We implement organizational, administrative, and technical measures required by the PDPL, its Implementing Regulations, and applicable requirements of the Ministry of Health and the Saudi Health Council, including where relevant the national health information exchange policies (NPHIES and related frameworks).
- Where CAN Devices constitute medical devices, they are marketed in the Kingdom in accordance with the requirements of the Saudi Food and Drug Authority ("SFDA").
8. How we disclose personal data
We disclose personal data only as permitted by the PDPL:
- To our Customers (as controllers) and their authorized users in connection with the Services.
- To service providers and processors who process personal data on our behalf under written agreements imposing confidentiality, security, and processing restrictions consistent with the PDPL.
- To our affiliates for the purposes described in this Policy, subject to the transfer rules in Section 9.
- To competent authorities in the Kingdom where disclosure is required by law or requested through lawful process.
- In connection with a corporate transaction (merger, acquisition, reorganization), subject to continued protection of personal data.
We do not sell personal data, and we do not disclose personal data for third-party advertising purposes.
9. Transfers of personal data outside the Kingdom
Some of our infrastructure and personnel are located outside the Kingdom. Where personal data subject to the PDPL is transferred or disclosed outside the Kingdom, we do so only in accordance with the PDPL and the Regulations on Personal Data Transfer Outside the Kingdom, including:
- Transferring to jurisdictions recognized as providing an adequate level of protection, where applicable.
- Implementing appropriate safeguards approved under the Transfer Regulations, such as standard contractual clauses adopted by SDAIA or binding common rules, where adequacy is not available.
- Limiting transfers to the minimum personal data necessary for the stated purpose.
- Conducting risk assessments of transfers where required.
Where applicable law, regulatory requirements, or our agreements with Customers require that specific categories of data — including certain health data of patients in the Kingdom — be hosted within the Kingdom, we support in-Kingdom hosting and processing arrangements in accordance with those requirements.
10. Data retention and destruction
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, unless a longer period is required or permitted by the laws of the Kingdom. When personal data is no longer needed, we destroy it without undue delay or anonymize it in accordance with the PDPL, using methods that prevent reconstruction or re-identification. Personal data processed on behalf of a Customer is returned or destroyed in accordance with our agreement with that Customer.
11. Security
We implement organizational, administrative, and technical measures to protect personal data against unauthorized access, disclosure, alteration, and destruction, informed by the PDPL, the National Cybersecurity Authority's Essential Cybersecurity Controls (ECC), and international standards. Measures include encryption of data in transit and at rest, role-based access controls, audit logging, personnel training and confidentiality undertakings, and documented incident response plans.
If a personal data breach occurs that harms or is likely to harm your data or interests, we will notify the competent authority within the timeframes required by the Implementing Regulations (including notification to SDAIA within 72 hours where required) and will notify affected individuals and Customers as required by the PDPL and our contracts. Report suspected vulnerabilities or incidents to security@can.co.
12. Your rights under the PDPL
Subject to the conditions and exceptions in the PDPL and its Implementing Regulations, you have the right to:
- Be informed about how and why we process your personal data, and the lawful basis for doing so.
- Access your personal data held by us.
- Obtain a copy of your personal data in a clear, readable format.
- Request correction, completion, or updating of your personal data.
- Request destruction of your personal data when it is no longer needed for the purpose it was collected, subject to legal retention obligations.
- Withdraw your consent to processing at any time, where processing is based on consent.
To exercise these rights, email privacy@can.co with the subject line "PDPL Rights Request," or write to the address in Section 17. We will verify your identity before acting on a request and will respond within the timeframes prescribed by the Implementing Regulations (generally within thirty (30) days, extendable as permitted by law). Exercising your rights is free of charge, although the PDPL permits reasonable fees for repetitive or excessive requests.
If your request concerns health records or other personal data that we process on behalf of a Customer, we will refer your request to that Customer and support their response, as described in Section 2.
13. Cookies and similar technologies
Our websites use strictly necessary cookies, preference cookies, and limited first-party analytics cookies, as described in our Cookie Notice. We do not use cross-site advertising trackers. Where the PDPL or its Implementing Regulations require consent for non-essential cookies, we obtain it. You can control cookies through your browser settings.
14. Children and guardianship
Our websites and marketing services are not directed to children, and we do not knowingly collect personal data directly from individuals who lack legal capacity without the consent of their guardian, as required by the PDPL. Pediatric and dependent-care programs deployed by Customers may involve processing the health data of minors or persons under guardianship; in those cases, processing occurs on behalf of the Customer with the consents required by the laws of the Kingdom. If you believe a child has provided us personal data without appropriate guardian consent, contact privacy@can.co and we will take appropriate steps to destroy it.
15. Complaints
If you have a concern about how we handle your personal data, please contact us first at privacy@can.co — we take every complaint seriously and will respond promptly. You also have the right to lodge a complaint with the competent authority in the Kingdom (currently SDAIA) in accordance with the PDPL and its Implementing Regulations.
16. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, the Services, or the laws of the Kingdom. Material changes will be notified by posting the updated Policy on can.co with a new "Last updated" date and, where required by the PDPL, by additional notice or renewed consent.
17. How to contact us
For questions about this Policy or our processing of personal data in the Kingdom, contact:
- Email: privacy@can.co (subject line: "KSA Privacy").
- Post: CAN Mobilities, Inc., Attn: Privacy Office, 530 Lytton Avenue, Palo Alto, CA 94301, United States.
Where the PDPL requires the appointment of a personal data protection officer or a licensed representative in the Kingdom, the contact details of that officer or representative are available upon request at privacy@can.co.
