Last updated: 2026-08-13

Who we are

Barqia (بَرقية) is a WhatsApp CRM & marketing platform for merchants in Saudi Arabia and the Gulf, operated by Murtadha Abdulrahim Al-Haddad Trading Establishment (Unified National Number 7038322678), National Address: 3530 Souq Al Arbiea, Historical Center Al Mubarraz Dist., Al Mubarraz 36361, secondary no. 9098, Kingdom of Saudi Arabia — short address FMAB3530. Privacy contact: support@barqia.net. Site and application at barqia.net.

Our role: processor and controller

For merchant-account data (name, email, mobile, billing) we are the controller. For the merchant's end-customer data processed over WhatsApp, we act as processor on the merchant's behalf and under its instructions; the merchant remains the controller responsible for the lawful basis and for obtaining consent.

WhatsApp data we process

Through Meta's official WhatsApp Cloud API we process, on the merchant's behalf: customers' phone numbers, WhatsApp profile names, message and conversation content, attachments and media, message metadata and delivery/read statuses, and the WhatsApp Business Account (WABA) and phone-number identifiers obtained when an account is connected via Embedded Signup.

Purpose & purpose limitation

WhatsApp data is used solely to enable messaging between a merchant and its customer: the inbox, CRM, automations and reminders, and CSAT. We do not use it to enrich other merchants' customer data, to build profiles, or for resale, in line with Meta's Business & Commerce Policies. We never sell your data.

Lawful basis & consent (PDPL)

We work to Saudi Arabia's Personal Data Protection Law (PDPL) and its implementing regulations, and the «Cross-border transfer & safeguards» section below states plainly which of them are not yet in place. Consent is the default lawful basis, and consent is not bundled as a precondition of the service. Merchants must obtain the customer's opt-in before messaging them over WhatsApp.

Sharing & sub-processors

To run the service we use the sub-processors below. • Meta/WhatsApp — the Cloud API: message content, customer numbers and metadata. • Hostinger — server and database hosting, and the provider-managed periodic backups of that server. • Our AI provider (OpenAI, Google or Anthropic, depending on the configuration in force) — conversation text reaches it in three cases: when you enable the AI assistant, when you ask it to draft a template, and in the analysis of ended conversations (intent and sentiment). With the assistant, your business profile, your custom instructions and a live snapshot of your product catalog are sent too, so it answers with your own information. That analysis runs by default on ended conversations even if you never enable the assistant; you can switch it off on your profile page. • Google — push notifications to the staff app via Firebase Cloud Messaging: the notification title, an excerpt, and the device identifier. • Salla and Zid — when you connect your store: orders, carts and the customer data attached to them. • Sndr — transactional email: recipient address and message content. • Payment providers (Moyasar and Tap) — for online subscription payments; we never store your card details on our systems. • Sentry — technical error reports where enabled, which may incidentally contain technical identifiers. • The storage provider hosting our encrypted off-site backups, where we run them; it will be named here once it is settled. We do not share your data with anyone else except under a legal obligation or with your consent, and we never sell it. We notify merchants before adding a new sub-processor, by updating this list and by an email to the address on the account.

Cross-border transfer & safeguards

Our infrastructure does not currently run on servers inside Saudi Arabia. Where your data sits: the primary server running the platform and its database is hosted with Hostinger outside the Kingdom. The provider-managed periodic backups of that server are stored in the United States — that is what Hostinger's own systems report for them, and it is the one location we can evidence. WhatsApp messages are processed on Meta's infrastructure outside the Kingdom. We have asked Hostinger for written confirmation of the primary server's hosting city and will name it on this page once it is documented — we do not publish a location we have not verified. Legal basis for the transfer: the transfer is necessary to perform the service the merchant has contracted us to provide; the platform does not function without these providers. We do not ask you for a separate consent to the transfer as a condition of using the service. Safeguards in place today: each provider's published data-processing terms, incorporated into our agreement with them; encryption of traffic in transit; encryption of tokens and sensitive data at rest; separation of every account's data from every other: each record is owned by its account, and every query on the read paths a merchant reaches is constrained to it in application code; and access limited to the smallest possible number of staff, with looks at an identified customer's data logged in the inbox and the phonebook. And what is not in place yet, stated plainly: we have not yet executed the Standard Contractual Clauses issued by the Saudi Data & AI Authority (SDAIA), and we have not yet documented a formal cross-border transfer risk assessment. This page will be updated when either is complete. If in-Kingdom data residency is a regulatory requirement for your business, write to us at support@barqia.net before subscribing and we will set out our current position in writing.

Use in the healthcare sector

Barqia is built for administrative messaging: confirming and reminding appointments, general enquiries, and measuring patient satisfaction. Because our infrastructure sits outside the Kingdom (see the section above), we do not offer the platform as a place to hold or exchange health records. We ask healthcare organisations not to send diagnoses, test or lab results, medical reports, prescriptions, or any content from a patient's health record through the platform. A patient's name, mobile number and appointment are administrative information we process; the substance of their medical condition has no place in the conversation. The healthcare organisation, as controller, is responsible for confirming its own compliance with Saudi health-data regulations before using the platform. We are ready to provide a written description of your data flow for your legal adviser: write to us at support@barqia.net.

Retention

We retain data only as long as needed to provide the service and meet legal obligations, then delete or anonymise it. The actual rules: • Contacts, conversations and orders are kept for as long as the merchant's relationship with the customer lasts, and are not auto-deleted with time — deleting them would erase the trading history the service exists to hold. They are deleted when a customer asks for erasure, or when the merchant closes their account. • Campaign delivery logs are anonymised after an operator-set period — the customer's name, number and reply text are erased and the record kept so the campaign's statistics stay correct — and no such period is set today. • Verification codes are purged about a day after they expire. Abandoned carts are purged on an operator-set period, as campaign logs are; where no period is set they remain until a customer requests erasure or the merchant closes their account. • Two windows are fixed and set by nobody: the raw inbound payloads from Meta — a verbatim copy of the message text — are purged seven days after processing, and the per-number send counter is purged after thirty days. • Opt-out lists and the consent audit trail are not erased on an erasure request: deleting the record of someone who asked not to be messaged would put them back on the sending list, which is the opposite of what they asked for. Meta provides no archive of message content, so the copy that counts is ours — and the rules above are what govern it.

Your rights & data deletion

Under the PDPL you have the right to access, correct, erase, and port your data, and to withdraw consent at any time. We respond within about 30 days. To request deletion via the dedicated path see barqia.net/data-deletion, or contact support@barqia.net. You also have the right to lodge a complaint with the Saudi Data & AI Authority (SDAIA) regarding the processing of your data.

Opt-in & opt-out

Merchants must obtain the customer's consent before messaging. We honour the customer's choice automatically: anyone who sends "إيقاف"/STOP is immediately opted out, and "اشتراك"/START re-subscribes them. It is enforced on every merchant-initiated message. One exception is deliberate: someone who opted out of marketing alone through WhatsApp's own setting still receives what is not marketing — their order confirmation, their shipping update, and a reminder for an appointment they have. Anyone who sends «إيقاف»/STOP is stopped from everything.

Sensitive data we do not collect through conversations

We do not solicit full payment-card numbers, IBANs, or national-ID numbers over WhatsApp, and we advise merchants not to collect them through conversations. What we do ask the merchant for, to verify the business and to pay them, is set out in the next section.

Business verification (KYB) and payout data

To verify your business before enabling certain capabilities we may ask you to upload: your commercial registration, your VAT certificate, and a copy of the owner's or authorised representative's ID. For participants in the referral programme we store an IBAN in order to pay commission. We are the controller of this data — not the processor — because it is yours rather than your customers'. It is stored with restricted access and is only looked at for the purpose it was collected for: reviewing the verification, making a payout, or meeting a legal obligation. None of it enters any measurement or advertising tool, and none of it is shared with the AI provider.

Security & breach notification

Access tokens and sensitive data are stored encrypted, every record is owned by its account and every query on the read paths a merchant reaches is constrained to it, and opening a customer's conversation or their phonebook card is logged against whoever opened it. To authenticate inbound messages from Meta we rely on a phone_number_id anti-spoof gate as the enforced control, with X-Hub-Signature-256 (HMAC) verification as defense-in-depth that is logged on mismatch. In the event of a breach affecting personal data we notify the affected merchant without undue delay and within 48 hours of becoming aware of it at the latest, and we notify the Saudi Data & AI Authority (SDAIA) and data subjects as the law requires.

Website measurement & advertising tools

On our marketing site (barqia.net) we count page views to learn which pages actually help merchants. The core measurement runs on our own servers: the visit record itself stores no IP address and no browser fingerprint (routine technical server logs are kept for operations and security, and rotated). If you accept full measurement we store a random identifier in your browser that links your visits together for signup-funnel measurement only — it is not derived from anything about you, is never joined to an account, and you can erase it at any time. With your consent, advertising measurement tools from Google, Meta, Snapchat and TikTok may also load; none of them loads before you consent. Choosing "Essential only" keeps the visit counted anonymously with no identifier and no third-party tool. To change your choice at any time use "Privacy choices" in the page footer. This section does not apply to WhatsApp conversations or to merchants' customer data — those are governed by the sections above and never enter any advertising tool.

Updates & contact

We may update this policy and will post the updated date at the top of the page. For any privacy question or to exercise your rights: support@barqia.net.

Measurement choices

You can review or withdraw your choice at any time — it does not affect your use of the platform.

بَرقية Barqia

A shared WhatsApp inbox, automation, an AI assistant, campaigns, catalog and forms for Saudi and Gulf merchants — over Meta's official API.

صندوق الواردلوحة المتابعة (كانبان)تدفقات الأتمتةروبوت واتسابالمساعد الذكينماذج واتسابالحملاتالبث المجدولقوالب الرسائلكتالوج المنتجاتالطلباتبرنامج الولاءالتحليلات والتقاريرودجت الدردشة للموقع
متجر إلكترونيمتجر / بيع بالتجزئةمطعم / مقهىعيادة / مركز طبيخدمات / مزوّد خدمةتعليم / تدريبعقاراتمنتجع / استراحةصالون / حلاقة / سبا
© Barqia — all rights reservedMeta official API · PDPL-compliant · mada & Apple Pay
مدعوم بـبَرقية