Legal
Privacy policy
This policy explains what the public site processes, what a self-hosted Nool installation processes, and who controls each kind of data.
Last updated: 21 September 2026
Who we are and scope
Nool is developed in Riyadh, Saudi Arabia. The Nool team operates noolbase.com and controls information sent directly to this website. For privacy matters, email [email protected].
This policy covers the public website and the Nool product. The product is normally installed on infrastructure chosen by the customer. The customer therefore controls workspace content, and its own privacy notice and relationship with its users govern that content. The Nool team does not automatically receive workspace content merely because the product is used.
What we process and why
- Access requests: your name, email, message and consent, to answer the request and send you a copy.
- Security and operations: network address, browser type and request time in Cloudflare logs, to detect abuse and operate the site.
- Device preference: the selected theme stays in local browser storage and is not sent to us.
- Inside Nool: session, locale, active-project and sidebar cookies are necessary to sign in and render the workspace as selected.
We use no visitor analytics, advertising pixels or behavioural tracking, and we do not sell personal data.
Legal basis
We rely on your consent for information submitted through the access form. Essential security logs and technical storage support operation and protection of the service, and legitimate interests where permitted without overriding your rights. Product data processing is governed by the customer's agreement and legal responsibilities.
Marketing consent is never a condition of access. We do not send direct marketing without separate, withdrawable consent.
Processors and international transfers
Cloudflare hosts and protects the website and provides Turnstile when you use the form. Resend delivers the request and confirmation emails. Each receives only what its service needs.
These providers may process data outside Saudi Arabia. Transfers must follow PDPL and its regulations, be limited to what is necessary, and use appropriate contractual and technical safeguards.
Retention and deletion
We keep an access request for twelve months after the last contact, then delete it unless a customer relationship begins or law requires longer retention. Cloudflare security logs follow its configured retention. Workspace data in a Nool installation follows the customer's settings and obligations, not this website's retention period.
Your rights
You may ask to be informed of the basis and purpose, access your data and obtain a clear copy, correct or complete it, request destruction when no lawful need remains, and withdraw consent without affecting processing that occurred before withdrawal.
To exercise a right or complain, email [email protected]. You may also complain to the competent Saudi data-protection authority if the matter is unresolved.
Children and changes
The site and product are intended for professional teams, not children's services. If we learn that a child's information reached us without a lawful basis, we will take steps to delete it.
We change the date on this page when the policy changes and, where required, explain a material change before it takes effect.