Privacy Policy — Da'wati | دعوتي
1. Introduction
Welcome to Da'wati | دعوتي ("Da'wati," "we," "us," or "our").
Da'wati is a digital event and invitation management platform that enables users to create and manage events, prepare and send invitations, manage guest lists, communicate with guests, manage attendance and entry, use QR codes or barcodes where applicable, share event-related photographs and media, and access other event-management features offered through our mobile applications, websites, dashboards, and related services (collectively, the "Services").
Your privacy is important to us. This Privacy Policy explains how we collect, use, store, disclose, transfer, protect, and otherwise process Personal Data when you use Da'wati or when another user provides your information to Da'wati in connection with an event.
This Privacy Policy applies to:
- registered Da'wati users;
- event organizers and hosts;
- guests and invitees;
- event administrators and authorized team members;
- individuals appearing in photographs or media uploaded through the Services;
- visitors to our websites;
- individuals who communicate with us; and
- any other individual whose Personal Data is processed through Da'wati.
Da'wati is operated by:
Legal Entity: Mind Flow
Commercial Registration: 7054536391
Country: Kingdom of Saudi Arabia
Registered Address: Jeddah, Saudi Arabia
Privacy Contact: abdullah@mindflow.sa
General Support: abdullah@mindflow.sa
2. Applicable Data Protection Framework
Where applicable, we process Personal Data in accordance with the laws and regulations of the Kingdom of Saudi Arabia, including the Personal Data Protection Law ("PDPL"), its Implementing Regulations, and applicable regulations governing transfers of Personal Data outside the Kingdom.
Nothing in this Privacy Policy is intended to reduce any rights granted to individuals under applicable law.
3. What Personal Data We May Collect
Depending on how you interact with Da'wati, we may collect the following categories of Personal Data.
3.1 Account Information
When you create or manage a Da'wati account, we may collect:
- full name;
- mobile number;
- email address;
- profile information;
- city or country;
- account identifiers;
- authentication information;
- preferred language;
- profile image;
- account type; and
- other information you voluntarily provide.
We do not intentionally store your plain-text password. Authentication credentials are processed using appropriate authentication and security mechanisms.
3.2 Event Information
If you create or manage an event, we may process:
- event name;
- event type;
- event date and time;
- venue and location;
- event description;
- invitation design;
- event images and branding;
- host information;
- event instructions;
- seating information;
- attendance rules;
- event schedules; and
- other information entered when configuring an event.
3.3 Guest and Invitee Information
Event organizers may upload or enter information concerning guests, including:
- guest name;
- mobile number;
- email address;
- guest category;
- invitation status;
- number of accompanying guests;
- table or seating information;
- RSVP status;
- attendance status;
- check-in and check-out information;
- QR code, barcode, or invitation identifier;
- communication and delivery status;
- guest notes; and
- other event-related information supplied by the organizer.
A guest does not necessarily need to have a Da'wati account for us to process this information.
3.4 Information Provided by Other Users
In some circumstances, we receive Personal Data about you from an event organizer rather than directly from you.
For example, an organizer may provide your name and mobile number to send you an invitation.
The organizer is responsible for ensuring that they have an appropriate legal basis, permission, authority, or other lawful justification required under applicable law to provide your information to Da'wati and use it for the relevant event.
Where Da'wati processes guest information solely on behalf of an organizer and according to their instructions, our role may be that of a data processor. For other processing activities, including operating Da'wati accounts, security, fraud prevention, platform administration, and compliance obligations, Da'wati may act as a data controller.
3.5 RSVP and Attendance Information
We may collect information about your interaction with an invitation, including whether:
- the invitation was delivered;
- a link was opened;
- you accepted or declined an invitation;
- you indicated the number of attendees;
- you checked into an event;
- your invitation code was scanned;
- the invitation was previously used; and
- the organizer recorded your attendance.
3.6 QR Codes and Barcodes
For events that use controlled entry, Da'wati may create a unique QR code, barcode, token, or identifier associated with an invitation or guest.
Scanning this identifier may record information such as:
- guest identity;
- invitation status;
- scan time;
- entry status;
- number of permitted attendees;
- previous scans; and
- event-related verification information.
The identifier should not be shared with unauthorized persons.
3.7 Messages and Communications
Where messaging features are enabled, we may process communications associated with:
- invitations;
- event updates;
- reminders;
- confirmations;
- RSVP requests;
- thank-you messages;
- customer support;
- WhatsApp communications;
- SMS messages;
- email;
- push notifications; and
- other supported communication channels.
Delivery information may include message status, time sent, delivery confirmation, failure information, and similar technical metadata.
3.8 Photographs, Videos and Event Media
Where Da'wati provides photo-sharing, gallery, album, or media functionality, we may process:
- photographs;
- videos;
- profile pictures;
- uploaded event media;
- media metadata; and
- information associated with the person uploading or accessing the content.
Photographs and videos may constitute Personal Data when individuals can be identified from them.
Event organizers and users uploading photographs or videos are responsible for ensuring they have any permissions or lawful basis required to upload, share, publish, or otherwise process that content.
Da'wati does not grant an organizer permission to use a person's image merely because Da'wati provides photo-sharing functionality.
3.9 Payment Information
If paid Services are purchased, we may process:
- transaction amount;
- currency;
- payment status;
- transaction identifier;
- invoice information;
- subscription or package information;
- billing contact details; and
- limited payment-related metadata.
Payment card information may be collected and processed directly by an authorized third-party payment service provider.
Da'wati does not intend to store full payment card numbers, CVV/security codes, or similar payment credentials unless expressly stated otherwise and lawfully implemented.
3.10 Device and Technical Information
When you use Da'wati, we may automatically receive technical information such as:
- IP address;
- operating system;
- application version;
- browser type;
- device type;
- device identifiers;
- language settings;
- time zone;
- crash information;
- diagnostic information;
- log information;
- session information; and
- security-related events.
3.11 Location
We may process location information where required for a particular feature, such as displaying an event venue, opening directions, or providing location-dependent functionality.
Precise device location will only be accessed where appropriate permissions have been granted and the feature requires it.
3.12 Customer Support
If you contact Da'wati, we may process:
- your name;
- contact details;
- account information;
- correspondence;
- screenshots;
- technical logs;
- complaint information; and
- any information you voluntarily provide to resolve your request.
4. Why We Process Personal Data
We may process Personal Data for purposes including:
Providing the Services
To:
- create and manage accounts;
- create events;
- generate invitations;
- manage guest lists;
- facilitate RSVP responses;
- provide QR/barcode entry functionality;
- manage event attendance;
- provide event galleries;
- deliver invitations and notifications;
- process purchases;
- maintain user preferences; and
- provide customer support.
Communications
To send:
- invitations;
- event updates;
- reminders;
- RSVP communications;
- attendance information;
- transaction notifications;
- account notices;
- security alerts; and
- service-related communications.
Security and Fraud Prevention
To:
- authenticate users;
- detect unauthorized account access;
- prevent invitation abuse;
- prevent duplicate or unauthorized QR-code use;
- investigate fraud;
- protect accounts;
- detect security incidents;
- prevent spam and misuse; and
- maintain the integrity of the Services.
Service Improvement
We may analyze usage and technical information to:
- identify bugs;
- monitor performance;
- improve interfaces;
- understand feature usage;
- optimize application stability;
- develop new features; and
- improve user experience.
Where reasonably possible, we use aggregated or anonymized information for analytics.
Legal and Regulatory Compliance
We may process or retain Personal Data where reasonably necessary to:
- comply with applicable law;
- comply with lawful governmental or regulatory requests;
- establish or defend legal claims;
- maintain accounting and transaction records;
- investigate suspected unlawful activity; or
- satisfy regulatory obligations.
5. Legal Basis for Processing
Depending on the processing activity and applicable law, we process Personal Data based on one or more appropriate legal bases, which may include:
- your consent;
- performance of a contract with you;
- taking requested steps before entering into a contract;
- compliance with a legal obligation;
- protecting legitimate interests where permitted by applicable law and where the required conditions have been satisfied;
- protecting an individual's vital interests where applicable; or
- another legal basis permitted under applicable Saudi law.
Where processing relies on consent, you may withdraw that consent in accordance with applicable law.
Withdrawal does not necessarily affect processing that was lawful before consent was withdrawn or processing that is permitted under another legal basis.
6. Event Organizers and Guest Data
Da'wati allows organizers to provide Personal Data relating to third-party guests.
By uploading, importing, entering, synchronizing, or otherwise providing guest information, the organizer represents that:
- the information was obtained lawfully;
- the organizer has the legal authority or appropriate basis to provide it to Da'wati;
- the information will only be used for lawful event-related purposes;
- guests will not be subjected to unlawful spam, harassment, or unauthorized marketing;
- the organizer will comply with applicable privacy, communications, advertising, and anti-spam rules; and
- where required, appropriate notice or consent has been provided or obtained.
Da'wati may suspend an account, event, campaign, or communication functionality where we reasonably believe guest data is being used unlawfully or in violation of our Terms.
7. WhatsApp, SMS, Email and Other Communications
Da'wati may integrate with third-party communication providers.
Messages may therefore be processed by third-party platforms such as telecommunications providers, messaging platforms, email providers, WhatsApp Business Platform providers, or other service providers involved in delivering the communication.
Business-initiated marketing or promotional communications will be handled in accordance with applicable laws and platform requirements.
Where available, recipients may opt out of non-essential marketing communications.
Transactional and service communications—such as authentication messages, security notices, invitations you have requested, or important event updates—may operate differently from marketing communications.
8. When We Share Personal Data
We do not sell Personal Data to advertisers.
We may disclose Personal Data where reasonably necessary to the following categories of recipients.
Service Providers
Including providers supporting:
- cloud hosting;
- databases;
- application infrastructure;
- authentication;
- messaging;
- email;
- SMS;
- WhatsApp;
- push notifications;
- analytics;
- security;
- customer support;
- payment processing;
- media storage; and
- technical operations.
Such providers are permitted to process information only as necessary for the applicable service and subject to appropriate contractual or legal safeguards.
Event Organizers
Guest information, RSVP responses, attendance data, and other event-related information may be accessible to the organizer and authorized event administrators.
Event Staff
Where organizers designate reception staff, check-in staff, photographers, coordinators, or other team members, those individuals may be granted controlled access to information necessary for their role.
Legal Authorities
We may disclose information if required by applicable law, regulation, court order, or valid request from a competent authority.
Corporate Transactions
If Da'wati or its operating entity is involved in a merger, acquisition, restructuring, financing, sale of assets, or similar transaction, information may be transferred as part of that transaction subject to applicable legal requirements.
9. International Data Transfers
Some of the infrastructure, service providers, communications providers, analytics providers, or technology partners used by Da'wati may process Personal Data outside the Kingdom of Saudi Arabia.
Where Personal Data is transferred outside Saudi Arabia, Da'wati will take measures required under applicable Saudi data-protection laws and regulations, which may include:
- confirming that the transfer has an appropriate legal basis;
- assessing the destination and recipient where required;
- applying contractual safeguards;
- applying approved standard contractual clauses where applicable;
- limiting transferred data to what is necessary;
- conducting transfer risk assessments where required; and
- implementing appropriate organizational and technical controls.
10. Data Retention
We retain Personal Data only for as long as reasonably necessary to achieve the purposes for which it was collected and to comply with applicable legal, contractual, accounting, security, and regulatory requirements.
Retention periods may vary depending on the category of information.
For example:
- account information may be retained while the account remains active;
- event information may remain available for the period configured for event history or archival functionality;
- guest information may be retained for the relevant event and an appropriate period thereafter;
- financial records may be retained for legally required accounting or tax periods;
- security logs may be retained for fraud prevention and security investigation purposes;
- backups may contain deleted information for a limited period before being securely overwritten; and
- information subject to a legal dispute or investigation may be retained until the matter is resolved.
When Personal Data is no longer required, we will delete, destroy, anonymize, or otherwise handle it in accordance with applicable requirements.
11. Security
We use reasonable administrative, organizational, and technical measures designed to protect Personal Data against:
- unauthorized access;
- accidental disclosure;
- unlawful processing;
- alteration;
- loss;
- misuse;
- destruction; and
- unauthorized acquisition.
These measures may include, where appropriate:
- encryption in transit;
- encryption at rest;
- authentication controls;
- role-based access;
- access logging;
- restricted administrative privileges;
- database security controls;
- monitoring;
- backups;
- software updates;
- secure development practices; and
- incident-response procedures.
No internet-connected system can be guaranteed to be completely secure. Users are responsible for protecting their account credentials, devices, invitation codes, and access links.
12. Personal Data Breaches
If Da'wati becomes aware of a Personal Data breach, we will investigate and respond in accordance with applicable law.
Where a breach meets applicable notification requirements, we will notify the competent authority within the legally required period and will notify affected individuals where required.
We may also take measures including:
- disabling compromised credentials;
- blocking unauthorized sessions;
- rotating access keys;
- investigating affected systems;
- restoring information;
- contacting affected providers; and
- implementing corrective security measures.
13. Your Privacy Rights
Subject to applicable law and any legally permitted limitations, you may have rights including:
- the right to be informed about how and why your Personal Data is processed;
- the right to access Personal Data held about you;
- the right to obtain a copy of your Personal Data in a clear and readable form;
- the right to request correction, completion, or updating of inaccurate Personal Data;
- the right to request destruction/deletion of Personal Data where applicable; and
- the right to withdraw consent where processing is based on consent.
To exercise a right, contact abdullah@mindflow.sa.
We may need to verify your identity before fulfilling a request.
Where information was provided to us by an event organizer, we may need to coordinate with that organizer to process the request, depending on our respective roles under applicable law.
Certain information may be retained where retention is required or permitted by law.
14. Account Deletion
Where account-deletion functionality is provided, you may request deletion from within the application or through our designated support/privacy channel.
Deleting your account may result in loss of access to:
- events;
- guest lists;
- invitations;
- designs;
- photographs;
- subscriptions;
- purchase history; and
- other associated content.
Account deletion does not necessarily require immediate deletion of every record. We may retain information where required for legal compliance, fraud prevention, security, dispute resolution, accounting, backup integrity, or other lawful purposes.
15. Photos and Event Galleries
Photos shared through an event gallery may contain Personal Data belonging to attendees.
Users must not upload:
- unlawful photographs;
- private or intimate content without authorization;
- content that violates another person's privacy;
- content they do not have permission to distribute;
- defamatory or abusive content; or
- content that infringes intellectual-property rights.
If you believe an image of you has been uploaded improperly, contact abdullah@mindflow.sa with sufficient information to identify the applicable event or image.
We may restrict access to or remove content while reviewing a legitimate privacy or legal complaint.
16. Children and Minors
Da'wati is not intended to allow children to independently enter legally binding commercial agreements.
Where Personal Data relating to a minor is processed in connection with an event, the organizer must ensure that any authorization or consent required from a parent, guardian, or other authorized person has been obtained.
We may remove information relating to a minor where we determine that it was collected or provided improperly.
17. Marketing
We may send marketing communications where permitted by applicable law.
Where consent is legally required, we will seek that consent before sending the relevant communication.
You may withdraw from marketing communications through available unsubscribe or opt-out mechanisms or by contacting us.
Opting out of marketing will not necessarily prevent us from sending essential operational messages, transaction confirmations, security notifications, or other non-marketing communications.
18. Cookies and Similar Technologies
Our websites or web-based Services may use cookies, local storage, SDKs, or similar technologies for purposes such as:
- authentication;
- security;
- maintaining sessions;
- remembering preferences;
- measuring performance;
- analytics; and
- improving functionality.
Where legally required, we will request appropriate permission before using non-essential tracking technologies.
19. Third-Party Services
Da'wati may contain links to, integrations with, or functionality supplied by third parties.
Examples may include:
- map providers;
- messaging providers;
- payment gateways;
- social platforms;
- cloud providers; and
- external websites.
Their processing of Personal Data may be governed by their own privacy policies.
Da'wati is not responsible for the independent privacy practices of third parties where they act as separate data controllers.
20. Complaints
If you have concerns regarding our handling of Personal Data, please contact us first at abdullah@mindflow.sa.
We will review your concern in accordance with applicable requirements.
You may also have the right to lodge a complaint with the competent Saudi data-protection authority through the channels it makes available.
21. Changes to this Privacy Policy
We may update this Privacy Policy to reflect:
- new features;
- regulatory changes;
- changes to service providers;
- changes to our processing practices; or
- security or operational developments.
When material changes occur, we may notify you through the application, our website, email, or another reasonable communication method.
The effective date displayed at the beginning of the Privacy Policy identifies the latest version.
22. Contact Us
For privacy questions, requests, or complaints:
Da'wati | دعوتي
Operated by: Mind Flow
CR No.: 7054536391
Address: Jeddah, Saudi Arabia
Privacy Email: abdullah@mindflow.sa
Support Email: abdullah@mindflow.sa
Website: dawati.io
© 2026 Mind Flow. All rights reserved.