1. ABOUT THIS POLICY
Vivid Algorithms W.L.L. ("Vivid", "we", "us") is a company registered in the Kingdom of Bahrain (Commercial Registration No. 191837-1) providing a predictive customer retention analytics platform.
This Policy explains how we handle personal data. It is important to understand that we handle personal data in two distinct capacities, and different rules apply to each.
1.1 Our Two Roles
(a) As Data Processor — for our Clients' end-customer data.
When a business ("Client") uses our platform, the personal data of that Client's customers, patients, or prospects ("End Users") is processed on the Client's instructions and on the Client's behalf. The Client is the Data Controller; we are the Data Processor. We do not decide why or how that data is used. Our obligations are set out in the Data Processing Addendum forming Schedule C to our Terms of Service.
If you are an End User of one of our Clients, this Policy describes our role, but your rights are exercised against that Client — not against us. See Section 9.
(b) As Data Controller — for our own business data.
We are the Data Controller for: personal data of our Clients' staff and authorised users, collected to administer accounts, provide support, secure the platform, and bill; visitors to vividsystems.co; prospective clients and marketing contacts; and job applicants. Sections 3, 4, 5, and 10 apply.
1.2 Governing Law
This Policy is written to comply with Law No. 30 of 2018 of the Kingdom of Bahrain with respect to Personal Data Protection (the "PDPL"), together with its implementing resolutions and orders. The PDPL is supervised by the Personal Data Protection Authority, whose functions are discharged by the Ministry of Justice, Islamic Affairs and Waqf.
2. DATA WE PROCESS AS DATA PROCESSOR (CLIENT END-USER DATA)
2.1 Categories
Clients configure what they submit. Typically this includes:
- Identifiers: name, mobile number, email address, internal customer or patient reference
- Appointment and transaction data: booking history, attendance, cancellations, no-shows, service or treatment category, transaction history, payment timing
- Behavioural data: visit frequency and recency, spend patterns, lifecycle stage, engagement metrics
- Communication metadata: message delivery, open, and response status, channel, timestamps. We do not process message content unless a Client expressly authorises it in writing.
- Derived data: churn risk scores, segment assignments, confidence values, and other outputs generated by our models
2.2 Sensitive Personal Data
Our platform is not designed for sensitive personal data, and Clients are contractually prohibited from submitting it by default.
Where a Client's business necessarily involves health-related information — for example a medical, dental, or aesthetic clinic where appointment or department categories are themselves health-related — such data may be processed only where all of the following are in place:
- the Client is expressly designated as a Health Data client in its Service Agreement or a signed Addendum, with the specific categories identified;
- the Client has obtained explicit consent from each End User, or established another lawful basis available under PDPL Article 5 for sensitive personal data;
- the Client has obtained, and provided us with evidence of, any prior written authorisation of the Authority required under PDPL Article 15 for automatic processing of sensitive personal data; and
- the enhanced technical controls in Annex 2 to Schedule C of our Terms are in force.
Absent these conditions, we may delete or quarantine such data and suspend the affected service.
We do not process biometric identifiers, payment card or banking data, government identity numbers, criminal records, or data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership.
2.3 Who Processes It
We process this data solely on the relevant Client's documented instructions. We do not use it for our own purposes, do not sell it, and do not share it between Clients.
3. DATA WE PROCESS AS DATA CONTROLLER
3.1 Client Personnel and Account Data
Name, business email, business phone, job title, account credentials and authentication factors, support correspondence, and billing contact details. Used to provide and administer the account, authenticate users, deliver support, secure the platform, invoice, and communicate service notices.
3.2 Website Visitors
IP address, browser and device type, user agent, referring URL, pages viewed, approximate geographic location derived from IP, and cookie identifiers.
3.3 Platform Telemetry
Authentication events, API request logs and performance metrics, dashboard usage and feature interaction analytics, error and diagnostic logs, and security event data.
3.4 Marketing and Recruitment
Contact details of prospective clients who enquire or subscribe, and information submitted by job applicants.
3.5 Cookies
We currently use only strictly necessary cookies for authentication, session continuity, and security. We do not use advertising or cross-site tracking cookies. If we introduce optional analytics cookies, we will request consent before setting them and provide a way to withdraw that consent.
4. PURPOSES AND LAWFUL BASES
4.1 As Data Processor
We do not independently determine purposes. We process End User data to: generate churn predictions using models trained on that Client's data; dispatch automated interventions the Client has configured and approved; populate that Client's dashboards; operate integrations with that Client's systems; and support, troubleshoot, secure, and maintain the service.
The lawful basis for processing End User data is established by the Client as Data Controller — ordinarily explicit consent, contractual necessity, or legitimate interest under the PDPL. It is the Client's responsibility to establish, document, and evidence it.
4.2 As Data Controller
| Purpose | Lawful basis |
|---|---|
| Providing and administering Client accounts | Contractual necessity |
| Authentication and access control | Contractual necessity; legitimate interest in security |
| Platform security, fraud and abuse prevention, anomaly detection | Legitimate interest in protecting our systems, our Clients, and End Users |
| Service performance monitoring and diagnostics | Legitimate interest in maintaining a reliable service |
| Billing, collections, and accounting records | Contractual necessity; legal obligation |
| Responding to support requests | Contractual necessity |
| Service notices and security announcements | Contractual necessity; legal obligation |
| Marketing to business contacts | Consent, withdrawable at any time |
| Analytics cookies | Consent |
| Responding to the Authority, regulators, courts, and law enforcement | Legal obligation |
5. MACHINE LEARNING AND MODEL TRAINING
This section describes exactly what we do and do not do with data in connection with machine learning. It is deliberately specific because vague language here is the most common cause of failed enterprise reviews.
5.1 Client-Specific Models — What We Do
We train, retrain, and evaluate models using each Client's data, exclusively to serve that Client. These models are logically segregated. No data, output, model weight, learned parameter, or feature value derived from one Client's data is used to serve, inform, or improve the service delivered to any other Client.
This is an inherent and inseparable part of delivering the service. A Client's instruction to provide the service is its instruction to perform this processing.
5.2 Multi-Tenant and Cross-Client Models — What We Do Not Do
We do not use Client data, outputs, or derivatives of either to train, retrain, fine-tune, benchmark, or improve:
- any multi-tenant or shared model serving more than one Client;
- any publicly available or third-party AI model; or
- any general-purpose or foundation model,
unless the Client has given prior specific written authorisation. This is opt-in. It is not implied by use of the service, and it may be withdrawn on thirty (30) days' notice.
5.3 Third-Party AI Services
We do not transmit Client data to any third-party generative AI or machine learning service that reserves rights to train on submitted data. Any third-party AI processor we use is listed as a sub-processor and is contractually bound to a zero-retention, no-training commitment.
5.4 Aggregated Data
We may derive aggregated statistics for capacity planning, security analytics, and internal reporting. "Aggregated" means stripped of all direct and indirect identifiers of the Client, its End Users, and its business, combined with other sources, and not reasonably re-identifiable. We do not publish or disclose aggregated data in any form that identifies a Client or an End User. Where a Client's Addendum prohibits the creation of aggregated data, that prohibition prevails.
5.5 Human Oversight
PDPL Article 22 gives a data subject the right, where a decision is based solely on automated processing intended to assess them in respect of performance at work, financial standing, credit-worthiness, reliability, or conduct, to request that the decision be reconsidered by means that are not solely automated, free of charge.
Our outputs assess End Users in respect of matters including conduct and reliability. Accordingly, our Terms prohibit Clients from using outputs as the sole basis for any decision producing a legal or similarly significant effect on an End User — including refusal of service, denial or withdrawal of care, differential pricing, or account termination. Clients must maintain meaningful human review and handle Article 22 requests as Data Controller. We provide technical assistance.
6. WHAT WE DO NOT DO
- We do not sell, rent, or trade personal data.
- We do not share one Client's data with another Client.
- We do not use Client data to train multi-tenant or public AI models without prior specific written authorisation.
- We do not contact a Client's End Users on our own initiative or for our own purposes. All messaging is configured, approved, and dispatched under the Client's control and in the Client's name.
- We do not make final business decisions about End Users.
- We do not process message content unless expressly authorised in writing by the Client.
- We do not transmit Client data to third-party AI services that train on submitted data.
6.1 Our Access to Client Data — Stated Accurately
We access Client data only where necessary, and only in these circumstances:
(a) to deliver the service (automated processing, which is continuous);
(b) to investigate and resolve a support request raised by the Client;
(c) to investigate a security incident, suspected abuse, or platform fault;
(d) to perform maintenance, migration, or recovery where automated means are insufficient; or
(e) where required by law or by a lawful demand of the Authority, a regulator, or a court.
Human access under (b)–(d) is limited to named authorised personnel, granted on a least-privilege basis, logged, and — other than under (e), or where notification would compromise a security investigation — notified to or requested by the Client.
7. SHARING AND SUB-PROCESSORS
7.1 Categories
We disclose personal data only to: our authorised personnel on a need-to-know basis; sub-processors listed in Annex 3 to Schedule C of our Terms; professional advisers under confidentiality; the Authority, regulators, courts, or law enforcement where legally required; and an acquirer in connection with a merger, acquisition, or sale of assets, subject to confidentiality and to notice to affected Clients.
7.2 Named Sub-Processor List
Our current named sub-processors are listed in Annex 3 to Schedule C of our Terms of Service. We give at least thirty (30) days' notice before adding or replacing a sub-processor. Clients may request the current list or subscribe to change notices by emailing support@vividsystems.co, and may object on reasonable data-protection grounds.
Where a Client's Addendum requires prior express written consent to third-party disclosure, we obtain that consent by way of a countersigned sub-processor annex before processing begins, and obtain fresh written consent before engaging any additional sub-processor for that Client's data.
7.3 Government and Law Enforcement Requests
We disclose personal data to public authorities only where we have a legal obligation. We assess each request for validity and scope, disclose the minimum required, and notify the affected Client before disclosure unless legally prohibited or where doing so would prejudice an investigation.
8. INTERNATIONAL TRANSFERS
PDPL Article 12 prohibits the transfer of personal data outside the Kingdom of Bahrain without the specific consent of the data subject, unless the destination is on a whitelist specified by ministerial decision, or a special authorisation has been issued by the Ministry of Justice, Islamic Affairs and Waqf.
Our current data locations: primary platform processing and database storage are hosted on Vivid-managed Hostinger infrastructure in France. Messaging, email, calendar, and optional AI features may involve the providers and locations listed in Annex 3 to Schedule C of our Terms.
Transfer mechanism: France and the United States are included in the list of countries and territories recognised under Bahrain Order No. 42 of 2022 as providing adequate protection. For any destination outside that list, we and the Client document and apply an available PDPL mechanism before transfer, including Authority authorisation or a statutory exception where applicable.
For each Client, the applicable lawful transfer mechanism is confirmed in the Service Agreement. As Data Controller, the Client is responsible for establishing it — including obtaining End User consent where that is the basis relied on. We protect transfers in transit, bind recipients contractually where appropriate, and provide Clients with the information they need to support an assessment or authorisation application.
Any alternative data-residency arrangement must be expressly documented in a signed Service Agreement and is subject to technical availability and applicable fees.
9. RIGHTS OF END USERS (DATA SUBJECTS)
Under the PDPL, individuals have the right to: be informed about processing; access their personal data and obtain a copy; have inaccurate or incomplete data rectified; have data blocked or erased where processing breaches the law; object to processing, including for direct marketing; withdraw consent; obtain data portability; and, under Article 22, request that a decision based solely on automated processing be reconsidered by non-automated means, free of charge.
9.1 How to Exercise Them
If you are an End User of one of our Clients, please contact that Client directly. The Client is the Data Controller. It holds the relationship with you, controls the lawful basis, and is responsible for responding. We are not permitted to respond substantively on their behalf.
If you contact us, we will forward your request to the relevant Client without undue delay and direct you to them. Where we can identify the Client from the information you provide, we will tell you who they are.
9.2 Our Assistance to Clients
We acknowledge a Client's request for assistance within one (1) business day and provide substantive assistance within five (5) business days, so that the Client can meet its own statutory deadline.
9.3 Complaints
If you are dissatisfied, you may complain to the Personal Data Protection Authority, Ministry of Justice, Islamic Affairs and Waqf, Kingdom of Bahrain.
9.4 Where We Are the Controller
If you are a Client's authorised user, a website visitor, a marketing contact, or a job applicant, contact support@vividsystems.co. We respond within the statutory period.
10. RETENTION
| Data | Retention |
|---|---|
| Client end-user data (as processor) | For the subscription term. Deleted from production within 10 business days of termination or expiry of the export window |
| Client-specific models | Decommissioned on termination, within the same window |
| Encrypted backups | Rolling expiry not exceeding 90 days, then permanently deleted. Logically isolated from production and not accessible for processing |
| Account and authorised user data | Subscription term plus 5 years |
| Billing and accounting records | 10 years, or longer where required by Bahraini law |
| Security and audit logs | Up to 12 months, unless longer retention is required for an investigation or by law |
| Support correspondence | 5 years after closure |
| Website analytics | We do not currently use optional analytics cookies; server security logs are retained as stated above |
| Marketing contacts | Until consent withdrawn, plus suppression-list retention |
| Job applications | 12 months unless consent is given to retain them longer |
Certificate of destruction: on termination we issue a written certificate within ten (10) business days of completing production deletion, stating the categories deleted, the deletion date, and the residual backup expiry date.
11. SECURITY
We maintain administrative, technical, and organisational safeguards appropriate to the nature of the data and the risks of processing. These include:
- unique user accounts and role-based, least-privilege access controls;
- logical tenant segregation enforced at the application and database-query layers;
- TLS encryption for data in transit and protected credentials and secrets;
- authenticated APIs, input validation, parameterised database access, rate limiting, and dependency review;
- separate development, staging, and production environments;
- security, authentication, administrative-action, and application logs retained according to Section 10;
- automated backups and documented recovery procedures; and
- incident-response procedures and access revocation when access is no longer required.
Additional controls, including multi-factor authentication, dedicated infrastructure, field-level encryption, or enhanced audit reporting, apply only where enabled or agreed in a Client's Service Agreement or signed Addendum.
No system is completely secure. Clients are responsible for safeguarding their credentials, API keys, and access tokens and for promptly revoking access that is no longer required.
12. DATA BREACHES
We maintain a documented incident response plan. Where a personal data breach affects Client data, we notify the affected Client in writing within twenty-four (24) hours of discovery, with the nature of the breach, the categories and approximate volumes affected, likely consequences, measures taken, and a contact point — supplemented without undue delay as more becomes known.
This is designed to give Clients sufficient time to meet their own obligation, as Data Controller, to notify the Authority within seventy-two (72) hours.
We do not notify the Authority or any data subject of a breach affecting Client data without the Client's prior written consent, unless required by law, in which case we notify the Client first where lawful to do so.
Where we are the Data Controller, we notify the Authority and affected individuals as required by the PDPL.
13. CLIENT RESPONSIBILITIES
Clients are Data Controllers and are responsible for: establishing and documenting a lawful basis for all processing they instruct; providing End Users with the information required under PDPL Articles 17 and 18, including that automated behavioural processing is carried out and that a processor is engaged; obtaining explicit consent where required, including for sensitive data and for transfers outside Bahrain under Article 12; submitting any notification required under Article 14 and obtaining any prior authorisation required under Article 15; obtaining documented opt-in consent for automated messaging on each channel and honouring opt-outs; handling all data subject and Article 22 requests; maintaining meaningful human review of any consequential decision; securing their own credentials and enforcing MFA; not submitting prohibited data; and notifying us within twenty-four (24) hours of any unlawful upload or security incident.
14. CHILDREN
Our services are business-to-business and are not directed at children. Where a Client's business necessarily involves End Users under eighteen — including paediatric, dental, and family practices — the Client must declare this, confirm guardian consent under the PDPL, and ensure no automated intervention is sent directly to a minor rather than to their guardian. If we discover data of minors processed without a lawful basis, we will require immediate removal and may suspend the service.
15. OUR RIGHTS
We may: update, restrict, or discontinue features in accordance with our Terms; suspend or deny access for breach of our Terms or Acceptable Use Policy; suspend processing we reasonably believe infringes the PDPL; and generate and use aggregated data strictly as defined in Section 5.4.
16. CHANGES TO THIS POLICY
We may update this Policy. Changes are posted at vividsystems.co with a revised "Last Updated" date, and active Clients are notified by email at least thirty (30) days before material changes take effect. Earlier versions are available on request from support@vividsystems.co. Continued use after the effective date constitutes acceptance.
17. CONTACT
Vivid Algorithms W.L.L.
Commercial Registration: CR 191837-1
Building No. 1913, Road No. 2124, Block No. 321, Al Gudaibiya, Kingdom of Bahrain
| Purpose | Contact |
|---|---|
| Data protection and privacy | support@vividsystems.co |
| Security incidents and vulnerability reports | support@vividsystems.co |
| Abuse reports | support@vividsystems.co |
| Legal notices | support@vividsystems.co |
| General support | support@vividsystems.co |
Supervisory authority: Personal Data Protection Authority, Ministry of Justice, Islamic Affairs and Waqf, Kingdom of Bahrain.
END OF PRIVACY POLICY
