Legal

Privacy policy.

How Noura collects, uses, and protects the personal data of visitors, subscribers, and the team members who work on the desk.

Last updated · 12 September 2026

1. Who this policy is for

This policy applies to anyone who visits nourahub.com, submits an access request, holds a workspace account (Client, Editor, Analyst, Compliance Officer, Senior Advisor, or Admin), or interacts with Noura by email.

By using the platform you agree to how we handle your data as described here. If you disagree with any part of this policy, do not submit personal data through the site.

2. What we collect

Identity: your full name, work email, company, and stated role, taken from access requests, contact forms, and workspace onboarding.

Usage: pages viewed, feature interactions, and the queries you enter into Ask Noura. This is used to improve the product; we do not sell it.

Delivery: your recipient status on regulatory alerts, feasibility engagements, and email digests, so we can prove which clients were notified of what and when.

System logs: standard server and error logs (IP, user agent, timestamps). Retained for security investigations and troubleshooting.

3. What we do not collect

We do not ask for national ID, passport numbers, financial account details, or health information from visitors.

We do not run third-party advertising trackers, and we do not embed pixels from advertising networks.

4. How we use your data

To deliver the service you asked for: intelligence, feasibility studies, alerts, and account communications.

To confirm a request came from a real person (basic anti-abuse), and to route it to the right member of the desk.

To improve the product, using aggregated usage patterns. Individual queries are only reviewed to debug a reported issue or to investigate suspected misuse.

To meet a legal or regulatory obligation in the jurisdictions Noura operates in.

5. How we store your data

Primary data is stored on Supabase (Postgres) hosted in the AWS Middle East (Bahrain) region wherever regional availability allows, otherwise in the closest available region.

Email is delivered by Resend on our behalf. Chat completions and analytical prompts are sent to Anthropic (Claude) and OpenAI, subject to their respective enterprise data-processing terms — inputs are not used to train their public models.

Backups are encrypted at rest. Access to production data is limited to Admin and, when strictly needed, a Senior Advisor.

6. Retention

Access requests are kept for 24 months so the desk can honour follow-ups. After that they are archived or deleted.

Workspace profiles are kept for as long as the account is active. When an account is closed, the profile is demoted (never hard-deleted) so historical audit trails remain intact.

Compliance alerts and feasibility deliverables are kept indefinitely as part of Noura's editorial record.

7. Your rights

You may request a copy of the personal data we hold about you, correct anything wrong, or ask us to erase it, by writing to admin@nourahub.com. We reply within 14 working days.

Where erasure would break a duty-of-care obligation (for example, an alert we already sent you), we will explain what we can and cannot remove.

8. Contact

Questions about this policy, or a request under it, go to admin@nourahub.com. Advisory and partnership queries go to advisory@nourahub.com.