Privacy Policy
Effective date: 22 July 2026
This Privacy Policy explains how Al Sane Group (the "Group", "we", "us", "our") collects, uses, stores, and protects information in connection with ARSG AI (the "Service"), the Group's internal artificial-intelligence assistant platform, available to authorized users at https://chat.arsg.ai and described at https://arsg.ai. Please read this Policy carefully. By signing in to or using the Service, you acknowledge that your use is subject to this Policy and to the ARSG AI Terms of Service published at https://arsg.ai/terms.
1. Who We Are and the Scope of This Policy
ARSG AI is an internal workplace tool operated by the Group for its own personnel. Access is limited to employees, contractors, and other authorized personnel of the Group whose access has been approved by a platform administrator (an "Administrator"). ARSG AI is not a consumer service: there is no self-service public registration, and no one outside the Group's authorized user community is permitted to use the Service.
This Policy applies to all information collected or processed through the Service, including information generated when you sign in, submit content, or receive AI-generated responses. It supplements, and does not replace, any employment agreement, contractor agreement, or internal Group policy that applies to you. This Policy is governed by the laws of the State of Kuwait.
2. Information We Collect
We collect three broad categories of information in connection with the Service.
2.1 Account and identity information
When your account is created, approved, or used, we collect and hold:
- your name and work email address;
- identifiers associated with your Microsoft 365 work account, where you sign in using Microsoft Entra ID single sign-on;
- a profile picture, if one is provided; and
- records relating to the creation, approval, activation, and status of your account.
2.2 Content you submit and receive
The core function of the Service is to accept prompts, documents, and files from you and to return AI-generated responses. In doing so, we collect and store:
- the prompts and messages you type into the Service;
- documents and files you upload;
- your conversation history; and
- the AI-generated outputs returned to you.
This content is stored so that you can return to your conversations and files later. It is retained on Group-controlled systems as described in Sections 6 and 9.
2.3 Technical and usage information
When you access the Service, we automatically record certain technical information, including your IP address, browser and device information, timestamps of activity, and security and access logs. We use this information to keep the Service secure and functioning properly.
3. How We Use Information
We use the information described above to:
- operate the Service — receiving your prompts and files, generating responses, and storing your conversations and uploads so you can revisit them;
- authenticate you and administer your account, including approval and activation of new accounts;
- protect the security and integrity of the Service and of Group systems, including investigating suspected misuse or unauthorized access;
- provide user support and troubleshoot problems;
- meet the Group's compliance obligations and manage the workplace in accordance with applicable law and internal Group policies; and
- maintain records required for the administration of the Service.
We do not use your information for advertising, and we do not sell personal information.
4. AI Processing and Third-Party Model Providers
To generate responses, the Service transmits your prompts and any attached content, on a per-request basis, to the AI model provider selected for that conversation. Depending on the model chosen, this may be:
- Anthropic (Claude models), via Anthropic's commercial API;
- OpenAI, via OpenAI's commercial API;
- Google (Gemini models), via Google's commercial API; or
- internal Group-hosted applications built on the Dify platform, which run on infrastructure operated by the Group.
These providers process the submitted content in order to return a response to your request. Under the applicable API terms of Anthropic, OpenAI, and Google, content submitted through their commercial APIs is not used to train their models.
Only the content associated with the specific request — not your full account or the Service's stored records — is transmitted to the selected provider for processing.
5. Authentication via Microsoft
The Service supports sign-in with your Microsoft 365 work account through Microsoft Entra ID single sign-on. When you use single sign-on, Microsoft processes the authentication under Microsoft's own terms, and we receive identity information associated with your work account, such as your name, work email address, and Microsoft account identifiers.
Administrators may also provision or approve username-and-password accounts. New accounts may require Administrator activation before they can be used, and Administrators may approve, suspend, or remove accounts as described in Section 8.
6. Infrastructure, Cloudflare, and Transfers in Transit
The Service is self-hosted on infrastructure operated and controlled by the Group. Your conversation history, uploaded files, and account records are stored on Group-controlled systems, not in a third-party software-as-a-service database.
Cloudflare, Inc. provides DNS, TLS encryption, content delivery, and secure tunneling between the public internet and the Group's infrastructure. Traffic between your device and the Service therefore passes through Cloudflare's network, encrypted in transit.
When your request is processed by an external AI model provider as described in Section 4, or routed through Cloudflare's network, the associated content may be transmitted to and processed on servers located outside the State of Kuwait. All such traffic is encrypted in transit using HTTPS/TLS.
7. Cookies
The Service uses strictly necessary cookies only — that is, session and authentication cookies required to keep you signed in and to operate the Service securely. We do not use advertising cookies, third-party analytics cookies, or tracking pixels. Because the cookies we use are essential, blocking them in your browser will prevent you from signing in to the Service.
8. Administrator Access and Workplace Monitoring Notice
Please read this section carefully. ARSG AI is a workplace tool provided by the Group, and its contents are accessible to the Group.
Administrators are able to access, review, export, and delete accounts, conversations, and uploaded files. They may do so for security, compliance, user support, and lawful workplace-management purposes, in accordance with applicable law and internal Group policies.
You should have no expectation that content you submit to the Service is private from the Group. Prompts, conversations, uploaded files, and generated outputs may be reviewed by authorized Administrators. Please keep this in mind when deciding what to submit, and follow any internal Group guidance on the handling of confidential or sensitive information.
9. Retention and Deletion
We retain your account information, content, and technical records while your account is active. After your account is closed, information is retained and disposed of in accordance with the Group's internal data-retention practices.
Accounts and their associated content are removed when a user leaves the Group (offboarding) or upon an approved request made to the Administrators, as described in Section 11.
10. Security Measures
We take the security of the Service seriously and apply measures appropriate to an internal enterprise system, including:
- Encryption in transit: all traffic between your device, Cloudflare, the Group's infrastructure, and external AI model providers is encrypted using HTTPS/TLS;
- Access control: access is limited to accounts approved by Administrators, with sign-in through Microsoft Entra ID single sign-on or Administrator-provisioned credentials;
- Group-controlled hosting: the Service runs on infrastructure operated and controlled by the Group, and stored data resides on Group-controlled systems rather than in a third-party SaaS database; and
- Security logging: security and access logs are maintained to help detect and investigate unauthorized activity.
No system can be guaranteed to be completely secure. If you become aware of any suspected security issue affecting the Service, please report it promptly through the Group's internal support channels.
11. Your Choices and Requests
If you wish to access, correct, or delete information held about you on the Service — including your account details, conversations, or uploaded files — please contact your Administrator or use the Group's internal IT support channels. Requests are handled in accordance with applicable law, the Group's internal policies, and the Group's legal and operational obligations, which may require certain records to be retained.
You may also choose which AI model processes a given conversation, where the Service makes more than one model available, and you can limit what information you submit to the Service in the first place.
12. Changes to This Policy
We may update this Policy from time to time, for example to reflect changes to the Service, its providers, or applicable law. When we do, we will post the revised version at https://arsg.ai/privacy and update the effective date shown at the top of this page. Your continued use of the Service after a revised Policy takes effect constitutes your acknowledgment of the revised Policy. We encourage you to review this page periodically.
13. Contact
If you have questions about this Policy or about how your information is handled on the Service, please contact your Administrator or raise a request through the Group's internal IT support channels. Because ARSG AI is an internal service available only to authorized Group personnel, all privacy questions and requests are handled through these internal channels. Your use of the Service is also governed by the ARSG AI Terms of Service at https://arsg.ai/terms.