Privacy Policy
Responsible entity: Creative Matrix for Trading — LLC (شركة مصفوفة التقنية التجارية ذات مسؤولية محدودة).
Product: RateHex.
Geographic scope: Riyadh, Kingdom of Saudi Arabia.
1) Who we are, and what this policy covers
This policy applies to our websites and digital channels relating to RateHex, including:
- the ratehex.com website;
- the Portal channels connected to the system for our corporate customers;
- the parent company website matrixai.sa;
- the RateHex Android and iOS applications.
Our sites may contain links to external sites that we do not operate; this policy does not apply to those sites.
2) Legal roles in relation to data
- When processing data about our customers’ employees inside RateHex: the customer (the contracting organisation) is the data controller, and we act as a data processor on their behalf.
- For marketing data and data from the website and its forms: we are the data controller.
- Data Processing Agreement (DPA): available to our customers on request.
3) Categories of user
This policy applies to: HR managers and system administrators, employees, 360° reviewers (peers and managers), account administrators at the customer, and website visitors.
4) The types of data we process
- Identity and contact: such as name, work email address, telephone number, job title and employer.
- Account data: user accounts within the system, roles and permissions, and sign-in methods (local or SSO, according to the customer’s configuration).
- Evaluation and performance data: evaluation forms, objectives and key performance indicators (KPIs), manager and peer feedback, 360° evaluation results, and any attachments uploaded. The customer decides which fields exist and collects them according to its own needs (they are optional as far as the system is concerned, not mandatory).
- Usage and device data: such as IP addresses, browser and operating system type, and sign-in and activity logs.
- Correspondence and support: support tickets, email messages and chat.
- Attachments: files, images and documents that users upload within forms.
- Approximate location data: may be used for security purposes and to improve the service.
- Sensitive data: we do not set out to collect special or sensitive categories of data.
5) How data is collected
- through the customer’s account and the data it enters into the system;
- through your own direct use of the platform;
- through integrations the customer enables with external systems (at its own choice);
- automatically, through usage logs and similar technologies.
6) Purposes of processing, and the legal basis
- Operating the service and administering accounts (performance of the contract with the customer).
- Security and fraud prevention, and managing access and permissions (legitimate interest and/or legal obligation).
- Analytics and service improvement (legitimate interest, respecting privacy settings).
- Technical support and communication (performance of the contract / legitimate interest).
- Permitted marketing communications (on the basis of your consent, which you may withdraw).
- Legal compliance, and responding to lawful requests.
Where we act as a data processor, processing is carried out on the customer’s instructions and under the terms of the DPA between us.
7) Cookies and similar technologies
We may use cookies and similar technologies for essential, functional and analytical purposes, according to your settings and the customer’s settings. You can manage your preferences from your browser settings, or through any consent mechanism available on our sites and applications.
8) Sharing data with service providers
We may share limited data with service providers who help us operate the platform (hosting, email, security, support and analytics, for example), under appropriate contractual obligations of confidentiality and security. We do not sell your data.
A detailed list of providers, and updates to it, is available on request or through our official channels.
9) Locations and data transfers
Data may be processed inside or outside the Kingdom of Saudi Arabia, depending on the data centre locations of the service providers we work with, or those the customer enables for its own integrations. We apply appropriate safeguards for international transfers where required.
10) Security
We apply appropriate technical and organisational controls in line with good practice, including encryption of communications over secure protocols, permission management on a least-privilege basis, access and activity logging, and secure development practices. We also provide account-based sign-in and/or sign-in through identity providers (SSO), according to the customer’s configuration. No method of electronic transmission or storage is 100% secure.
11) Data retention
We retain data for as long as is necessary for the purposes described above and for our legal obligations. For data about our customers’ employees held within the platform, the customer may set its own retention and deletion cycles according to its policies, and we undertake to carry out its instructions in this respect.
Enquiries and requests submitted through the forms on this website (the contact form and the demo request form) are sent to our team by email, and are also stored in the website’s own database so that no request is lost. Only site administrators can see these records, they are not exposed through any public interface, and they are deleted automatically 365 days after they are submitted.
12) Individual rights
Under applicable law (such as the Saudi Personal Data Protection Law (PDPL) and any other applicable framework), you may have rights including: access to your data, correction, deletion, objection to or restriction of processing, portability, and withdrawal of consent without retroactive effect. Where we act as a data processor, we will direct you to the customer as the data controller.
13) Marketing communications
We will not send you marketing messages except as the law requires and, where consent is required, after you have given it. You may unsubscribe at any time.
14) Children’s data
Our services are directed at organisations and adults. We do not set out to collect data from children.
15) Changes to this policy
We may update this policy from time to time. Any change takes effect from the date it is published on our official sites and channels.
16) How to contact us
You can reach us through the contact channels published on our official sites (ratehex.com and matrixai.sa), or through the customer’s own support channels inside the Portal.

