Privacy Policy

Chapter One: Privacy Policy and Personal Data Protection

We value your privacy and are committed to protecting your data. This Chapter explains how personal data is collected, used, and protected on the TrendX platform (the website, the mobile applications, and all related services).

1. Personal Data We Collect

1.1 Account Data (collected directly from the user)

  • Full name or username.
  • Email address.
  • Mobile number.
  • Password (stored in hashed form) — applicable only where a direct account is created.
  • Profile image (optional).
  • Date of birth, for age-verification purposes.

1.2 Usage and Interaction Data (collected automatically)

  • In-app activity logs (trends viewed, posts, comments, votes).
  • Session data (session start and end times and duration of use).
  • Device data (device type, operating system, application version, device identifier).
  • Internet Protocol (IP) address and approximate geographic location.
  • Preferred language and application settings.

1.3 Cookies and Tracking Data

  • Functional cookies necessary for the operation of the Application.
  • Performance and analytics data or an equivalent service.
  • Push notification tokens.

Users may control cookie settings through their browser or device settings.

1.4 Sensitive Data

The TrendX application does not collect any sensitive data (such as health, biometric, religious, or ethnic data) except with prior explicit consent, and in accordance with the special provisions set out in Article (Six) of the Law and Article (Six) of the Implementing Regulations.

1.5 Sign-In via Third-Party Accounts

When signing in through an external authentication service, we may collect the user's name, email address, profile image, and public profile information. We do not collect passwords or sensitive authentication credentials belonging to those services. By signing in, the user is also subject to the privacy policies of those providers:

  • Google: https://policies.google.com/privacy
  • Apple: https://www.apple.com/sa/legal/privacy/en-ww/
  • X (Twitter): https://twitter.com/privacy
  • LinkedIn: https://www.linkedin.com/legal/privacy-policy
  • Facebook: https://www.facebook.com/policy.php

2. Methods and Purposes of Data Collection

2.1 Direct Collection

Data is collected directly from the user through registration forms, the user profile, and account settings, for the purposes of creating the account, verifying identity, providing the Application's services, personalizing the user experience, and communicating in relation to the account.

2.2 Indirect Collection

Certain data is collected automatically during use of the Application from the following sources: analytics technologies and cookies or their equivalents; device and network data collected automatically; and interoperability with social platforms where the user elects to sign in through them.

2.3 Principal Purposes of Processing

  • Providing, operating, and maintaining the services of the TrendX application.
  • Authenticating sign-in and creating the user profile.
  • Personalizing content and trends according to the user's interests.
  • Improving the performance of the Application and the user experience through general, anonymized, or aggregated analytics.
  • Sending notifications and alerts relating to the account and the service.
  • Detecting fraud, preventing misuse, and protecting account security and data integrity.
  • Complying with statutory, judicial, and regulatory requirements.
  • Communicating with users regarding updates and changes to the service.

3. Legal Bases for Processing Personal Data

Pursuant to Articles (Five) and (Six) of the Personal Data Protection Law and the related provisions of the Implementing Regulations, the Company relies on the following legal bases:

z1

 

4. Disclosure and Sharing of Data

TrendX does not sell or rent personal data to any third party under any circumstances. Data is disclosed only in the following cases:

4.1 Service Providers

The Company may share specific data with service providers acting on its behalf (such as cloud computing providers and analytics and notification services), under contracts that ensure compliance with the provisions of the Law and the preservation of data confidentiality.

4.2 Legal and Judicial Requirements

In response to requests from competent judicial or governmental authorities in accordance with the laws in force, or to give effect to a judicial ruling or investigation order.

4.3 Protection of Rights and Safety

Data may be shared where necessary to protect the rights of the Company or the rights, safety, or property of users, or to prevent or report a crime.

4.4 Transfer of Data Outside the Kingdom

Where operational necessity requires the transfer of any data outside the Kingdom of Saudi Arabia, such transfer shall be carried out in accordance with the controls of Article (Twenty-Nine) of the Law and the related provisions of the Implementing Regulations, after obtaining the necessary approvals from SDAIA, and subject to ensuring an adequate level of protection in the receiving country.

5. Data Storage, Retention, and Destruction

5.1 Storage and Protection Measures

Personal data is stored on secure servers using approved encryption technologies, in accordance with the controls issued by the National Cybersecurity Authority (NCA), with the application of role-based access controls (RBAC) and the ISO/IEC 27001:2022 information security management standard.

5.2 Retention Periods

z2

5.3 Data Destruction

Upon fulfilment of the purpose of the data or expiry of the retention period, data is destroyed by secure means that prevent its recovery, using secure erasure and digital destruction techniques in accordance with approved international standards (ISO/IEC 27001:2022), and in accordance with the Fifth Principle of the Personal Data Protection Policy of the National Data Management Office.

5.4 Technical Security and Protection

  • Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256).
  • Measures to prevent unauthorized access and to monitor suspicious activity.
  • Periodic penetration testing and annual information security reviews.
  • Isolation of development and testing environments from the production environment.
  • Application of the principle of least privilege to all employees.

6. Child Safety (CSAE)

TrendX application is committed to preventing any form of Child Sexual Abuse and Exploitation (CSAE), and is fully committed to providing a safe digital environment and protecting minors from any harmful or unlawful content.

6.1 Strictly Prohibited Content

  • Any content that exploits or endangers children in any manner.
  • Any sexual content involving minors (under 18 years of age) in any form.
  • Any activity or conduct related to child abuse or sexual exploitation.
  • Any communication or content that contributes to the recruitment of children or exposes them to harm.

6.2 Monitoring and Reporting Mechanism

The Application employs automated and human moderation systems to detect violations and remove them immediately, and to report them to the competent authorities where appropriate, including the National Center for Missing & Exploited Children (NCMEC). Users may report any suspected violations via info@trendx.co or through the in-app reporting tool.

6.3 Legal Basis

This commitment is grounded in the Anti-Cyber Crime Law promulgated by Royal Decree No. (M/17) of 1428H; the Child Protection Law promulgated by Royal Decree No. (M/14) of 1436H and its Implementing Regulations; and the child protection provisions of the Google Play Developer Program Policy and the Apple App Store Review Guidelines.

7. Rights of the Data Subject

Under Article (Four) of the Personal Data Protection Law and the related provisions of the Implementing Regulations, you are entitled to exercise the following rights:

z3

 

To exercise any of these rights, please contact info@trendx.co. No fees are charged for the exercise of these rights.

8. Notification of Personal Data Breaches

In the event of a personal data breach that may cause harm to data subjects, the Company undertakes the following in accordance with Article (Twenty-Four) of the Implementing Regulations:

  • Notifying the Saudi Data and Artificial Intelligence Authority (SDAIA) within 72 hours of becoming aware of the incident.
  • Notifying affected data subjects without undue delay, with a clear description of the incident and the measures taken in response.
  • Documenting the incident and the corrective measures taken, and retaining records thereof for regulatory review.
  • Taking all necessary measures to mitigate the effects of the incident and prevent its recurrence.

Chapter Two: Professional Community Standards

TrendX aspires to reflect the best version of professional dialogue: a space built on responsible opinion, informed analysis, and data derived from genuine engagement. Here we engage with respect, we disagree professionally, and we contribute content that adds value. A user's presence on TrendX signifies their commitment to building a safe, trustworthy, and professional environment.

9. Be Safe — Make Your Contributions a Safe Environment for Everyone

TrendX is a space for constructive professional discussion, not an arena for attacks or abuse. The publication of any content involving the following is not permitted:

  • Harassment, bullying, or personal targeting.
  • Defamation or the disclosure of private information without permission.
  • Incitement to violence, hatred, or discrimination.
  • Direct or indirect threats.
  • Shocking, disturbing, or indecent content.
  • Any unlawful, dangerous, or harmful activity.

Where you encounter content that violates these standards, please use the reporting tools available within the Application.

10. Be Trustworthy — Your Real Identity Is the Basis of Your Credibility

TrendX is a professional community built on trust. We require users to use correct and accurate information, to provide genuine information about themselves or their organization, not to create fake accounts, not to impersonate other persons or entities, and not to publish misleading or fabricated information.

10.1 Prohibited Practices

  • Manipulating voting or survey results.
  • Creating multiple accounts to influence surveys.
  • Publishing content intended to mislead the community or to unlawfully influence opinion.
  • Failing to disclose sponsored content or paid recommendations.

10.2 Intellectual Property Rights

  • Respecting copyright and refraining from copying articles or studies from other platforms without citing the source or obtaining permission.
  • Attributing credit where due: published opinions and analyses are attributed to their original authors.

11. Be Professional — Discuss Freely Within a Professional Framework

We welcome wide-ranging discussions on work, management, markets, trends, and skills, provided that all contributions remain within a professional framework. The following is not permitted:

  • Hate speech or discrimination.
  • Sexual innuendo or messages of a sexual nature.
  • The use of indecent or insulting language.
  • Turning professional discussions into personal disputes.
  • Publishing purely entertainment content that does not serve the professional context.
  • Spam or unauthorized promotion.

12. Creating Content on TrendX

When creating a survey or a post, you must ensure that the question is clear, avoid misleading or provocative phrasing, refrain from using content to incite division, and refrain from posing questions that violate privacy or target specific individuals. The purpose of content on TrendX is to stimulate thought, measure trends, and enrich dialogue.

12.1 Use of Artificial Intelligence

  • Transparency: disclosure where artificial intelligence is used to generate long-form content or complete studies.
  • Added value: the objective is genuine engagement, not flooding the platform with repetitive automated content.

13. Protection of Trade Secrets and Corporate Confidentiality

  • Refraining from publishing sensitive internal information about current or former employers under the guise of “professional analysis”.
  • Every employee represents themselves personally unless their account is verified as an official spokesperson for the organization.
  • Preserving the integrity of surveys and refraining from using automated tools to vote or to organize influence over results.

14. Reporting and Review

TrendX relies on two complementary systems to detect violating content:

  • User reports: via the reporting option within the post.
  • Automated systems: including keyword filters and artificial intelligence for detecting violations.

Following review, content may be restricted in visibility, flagged for review, or permanently removed.

15. Exceptions of Educational or Newsworthy Value

Certain content that might otherwise breach these standards may be permitted to remain in specific cases where it: has clear educational value; forms part of legitimate professional analysis; or relates to a news event of professional relevance. In such cases, an appropriate warning may be displayed before viewing.

Chapter Three: Trust & Safety System

TrendX applies an integrated system of automated and human mechanisms to protect the safety of the community and the reliability of survey data. The system operates across two distinct domains: content safety for posts and events, and data quality for survey responses. Both domains are governed by a single configurable enforcement engine that records strikes against user accounts and escalates penalties automatically.

16. Content Safety

16.1 Layer One: Keyword Blocking

Before any content reaches the artificial intelligence model, it passes through an internal keyword filter. This is a deterministic, high-speed check that requires no external service. The filter is applied to post titles, answer options, and event titles.

Upon detection of a match, the system responds immediately, before the content is created or stored: the post or event is not created; a notification is sent to the author stating the reason for removal; a strike is added to their account; and the penalty engine evaluates the new strike balance and applies the appropriate penalty.

16.2 Layer Two: AI Classification

Content that passes the keyword filter is submitted to an intelligent classification model that returns a risk score from 0 to 100, on the basis of which the applicable action is determined:

z6

 

The 40–90 range is deliberately broad so that ambiguous content is routed to human review rather than decided automatically under uncertainty, which reduces false positives for legitimate users while maintaining control over clear violations.

17. Survey Fraud Control

The integrity of surveys is a cornerstone of TrendX's value. The system uses behavioural signals — not assumptions — to identify users who are not responding in good faith. Devices and IP addresses serve solely as sensing instruments; strikes and penalties are recorded and applied exclusively at the account level, in order to protect users in shared environments (households, universities, and offices).

17.1 Signal One: Speeding Detection

This signal detects users who complete surveys at a speed that does not allow the questions to be read and considered. The expected duration is calculated in one of two ways: automatically according to the type of each question (each type having a configured minimum time), or by a manual override set by the survey creator or the administrator. A strike is recorded where a survey is submitted in less than the configured proportion of the expected duration.

Fraud resistance: the timer uses server time (changes to the device clock have no effect); reloading the page does not reset the timer; and a strike is recorded only after a successful submission, not upon abandoning the survey.

17.2 Signal Two: Device Reuse Detection

This signal identifies coordinated abuse in which multiple accounts are operated from a single device to inflate survey completions. A cluster is flagged where the number of distinct accounts on a single device reaches a configured threshold and where a configured proportion of them have completed surveys on that device. Where both conditions are met, every eligible account in the cluster receives a strike.

18. Strike & Penalty Engine

Each strike source has an independent enforcement plan that tracks its own strike counter and applies penalties on that basis alone. This means that a user with multiple types of violations is assessed separately for each source.

18.1 What Generates a Strike

z7

 

No other action generates a strike. Reports, automatic hiding, wallet usage, and refund operations do not create strikes.

18.2 Penalty Ladder (structural example)

z8

z9

 

Administrators may modify the number of strikes at each level, the action applied at each level, and the sources associated with the plan, through the administration panel. Modifications apply only to subsequent strikes and do not operate retroactively.

19. Account States and Access Control

z10

 

The account state is enforced at the backend level before every action — it cannot be circumvented through the user interface.

20. Administrative Controls and Appeals

20.1 Administrative Powers

  • Mark Safe: restoring the post, removing the flag, and notifying the author. No strike is recorded.
  • Delete + warn: permanent removal, recording of a strike, triggering of the penalty engine, and notification of the author.
  • Sending a customized warning to the user without changing the account state.
  • Suspension for a period determined by the administrator (1 / 3 / 7 days).
  • Permanent ban: the user is signed out immediately.
  • Reactivation: restoring the account to active status and resetting the running counter to zero.

20.2 Audit Trail

Every administrative action is logged with the administrator's identifier, timestamp, reason, and the affected user or content. Deletion reasons are retained internally and are not displayed to the user. The logs are available for any compliance review.

20.3 Appeals Mechanism

A user is entitled to submit an appeal against any enforcement action via info@trendx.co within 15 days of the action, and the appeal will be answered within 15 business days. Where the user remains dissatisfied, they are entitled to escalate the matter to the Saudi Data and Artificial Intelligence Authority (SDAIA).

Chapter Four: Complaints, Updates, and References

21. Complaints and Appeals Mechanism

21.1 Direct Contact with TrendX

A detailed complaint should be sent to info@trendx.co and will be answered within 15 business days of receipt in complete form.

21.2 Escalation to the Competent Authority

Where the user is dissatisfied with the handling of the complaint or does not receive a response within the specified period, they are entitled to submit a complaint to:

z11

 

22. Updates to the Guide

The Company reserves the right to update this Guide periodically in response to regulatory or operational developments. Where material amendments are made, users will be notified through:

  • An in-app notification within the TrendX application.
  • A message to the registered email address.
  • An update to the last-reviewed date at the head of the Guide.

The update date shown at the head of the Guide constitutes the official reference for the effectiveness of the current version. Continued use of the Application after notification shall constitute acceptance of the amended version.

23. Version History

z12

 

24. References and Legal Basis

24.1 Saudi Laws and Regulations

  • Personal Data Protection Law — promulgated by Royal Decree No. (M/19) dated 09/02/1443H, as amended by Royal Decree No. (M/148) dated 05/09/1444H — in particular Articles (Four, Five, Six, Twelve, Thirteen, Eighteen, and Twenty-Nine).
  • Implementing Regulations of the Personal Data Protection Law — issued by the Saudi Data and Artificial Intelligence Authority (SDAIA) — in particular Article (Twenty-Four) concerning breach incidents and Article (Thirty-Two) concerning complaints.
  • Guiding Manual for the Preparation and Development of a Privacy Policy — Saudi Data and Artificial Intelligence Authority (SDAIA).
  • Personal Data Protection Policy — National Data Management Office, under the National Data Governance Framework (Version 2.0) — in particular Principles One through Ten.
  • Anti-Cyber Crime Law — promulgated by Royal Decree No. (M/17) of 1428H.
  • Child Protection Law — promulgated by Royal Decree No. (M/14) of 1436H, and its Implementing Regulations.
  • Cybersecurity Controls and Requirements — National Cybersecurity Authority (NCA), including the Essential Cybersecurity Controls (ECC) and the Data Cybersecurity Controls (DCC).
  • E-Commerce Law — promulgated by Royal Decree No. (M/126) of 1440H, and its Implementing Regulations.

24.2 International and Technical References

  • ISO/IEC 27001:2022 — Information Security Management System.
  • ISO/IEC 27701:2019 — Privacy Information Management (an extension of ISO 27001).
  • Google Play Developer Program Policy — data protection, privacy, and child safety.
  • Apple App Store Review Guidelines — privacy and user data protection.
  • National Center for Missing & Exploited Children (NCMEC) standards — CSAE reporting.
  • OWASP Mobile Application Security Verification Standard (MASVS).

24.3 Internal Implementation References

  • The SDAIA Guiding Manual for the Preparation and Development of a Privacy Policy — all ten elements have been applied in full in Chapter One.
  • TrendX Platform Health Strategy — the internal technical document for the Trust & Safety System adopted in Chapter Three.
  • TrendX Professional Community Guide — incorporated in full into Chapter Two.
  • The Privacy Policy page published on the website (Arabic and English versions) — its content has been incorporated into Chapter One of this version.

Acknowledgment and Approval

This Guide takes effect from the date of its publication and supersedes all previous versions of TrendX's separate policies (the Privacy Policy, the Professional Community Guide, and the Platform Health Strategy), including the Privacy Policy page currently published on the website. Any conflict between this Guide and any earlier document shall be resolved in favour of this Guide.

z13

Note: This is an English translation of the Arabic Unified Policy and Privacy Guide. In the event of any discrepancy between the Arabic and English versions, the Arabic version shall prevail.

cross linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram