1. Introduction & Scope
This Privacy Policy explains how LNQ Teams collects, uses, stores, protects, and discloses personal information when you utilize our website, collaborative team formation tools, application processing systems, and associated services.
We respect your privacy and are committed to complete transparency regarding data processing operations in compliance with the principles and provisions of the Personal Data Protection Law (PDPL) of the Kingdom of Saudi Arabia and its implementing regulations.
2. Platform Operator & Contact
LNQ Teams operates as a dedicated collaborative team formation platform in the Kingdom of Saudi Arabia. For questions, notices, or requests regarding personal data processing, please contact our privacy channel at: lnq@wesalclub.com.
3. Regulatory Alignment with Saudi PDPL
This policy and our underlying system architecture are structured around key statutory data protection tenets under Saudi law:
- Lawfulness & Fairness: Personal data is collected and processed solely for specified, explicit, and legitimate platform purposes.
- Data Minimization: Data collection is strictly limited to the minimum necessary categories required for team assembly and role applications.
- Data Quality & Accuracy: Mechanisms exist for users to review, update, and maintain accurate records.
- Storage Limitation: Personal data is not preserved longer than necessary to achieve the operational or statutory compliance purposes.
- Security & Confidentiality: Appropriate technical, organizational, and logical safeguards protect data against unauthorized disclosure or loss.
4. Actual Personal Data Categories Collected
LNQ Teams collects only actual, functional data categories required for operating the collaborative platform:
a. Account & Identity Information:
Full name, email address, one-way cryptographically hashed password, preferred UI locale (Arabic or English), and account creation timestamps.
b. Profile & Background Details:
Professional headline, university or company affiliation, academic major or field, biography statement, skill tags, city and country, and external portfolio links (LinkedIn, GitHub, personal portfolio URL).
c. Team & Role Listings:
Team title, URL slug, description, category/industry, avatar image, member capacity ceiling, open role titles and descriptions, vacancy caps, and private post-acceptance onboarding notes.
d. Applications & Role Inquiries:
Application motivation statement, custom role question answers, evaluation statuses (Pending, In Review, Accepted, Rejected), and active team membership records.
e. Invitations & System Communications:
Recipient email addresses, secure single-use invitation tokens, in-app notification records, read/unread states, and notification channel preferences.
f. Moderation, Safety & Audit Records:
User violation reports, evidence snapshots, moderation outcomes, administrative audit log entries, email dispatch statuses, IP addresses, and User Agent strings captured during authenticated interactions.
5. Custom Application Questions & Answers
Team Owners may specify custom qualification questions for an Open Role:
- A historical snapshot of the question text and field type is preserved upon publication to protect candidate record integrity.
- Applicant responses are categorized as Restricted / Private Data and are never exposed on public directory surfaces.
- Access to submitted answers is strictly restricted to the authorized Team Owner and reviewers evaluating that specific application.
6. Private Acceptance & Onboarding Messages
Team Owners may formulate private onboarding instructions visible only to accepted members:
- These communications are concealed from the general public, applicants under review, and rejected applicants.
- They appear exclusively to a candidate once their application status changes to Accepted.
- External channels linked in acceptance notes (such as WhatsApp groups, Slack channels, or shared drives) are governed independently by those external platforms.
7. Public Information vs. Restricted Data
To avoid accidental exposure, LNQ Teams maintains strict architectural separation between public and private data:
Publicly Visible:
- Display name, profile headline, bio, skills, and portfolio links.
- Published team details and open role listings.
- Public team membership roster as confirmed.
Private & Restricted:
- Email address and account security settings.
- Application motivations and custom question answers.
- Private acceptance notes and secret invite codes.
- Moderation reports, reviewer notes, and audit logs.
8. Password Security & One-Way Hashing
We never store user passwords in readable plain text. Passwords undergo irreversible one-way cryptographic hashing (via Bcrypt/Argon2 algorithms) within Laravel's core authentication subsystem. No employee, developer, or administrator possesses the technical ability to view or decrypt your original plaintext password.
9. Processing Purposes & Legal Grounds
Under the Saudi PDPL, personal data processing is supported by legitimate grounds:
- Contractual Performance (Service Delivery): Creating accounts, listing teams, routing applications, sending invitations, and displaying rosters.
- Legitimate Interests & Platform Integrity: Moderation reviews, investigating safety reports, thwarting bot abuse, and maintaining audit logs.
- Legal & Regulatory Compliance: Fulfilling official statutory requests from competent Saudi judicial and governmental bodies.
- Informed Consent: In specific circumstances where consent is requested, with the full right to withdraw consent at any time.
11. International Processing & Cross-Border Data
Certain cloud infrastructure components (such as application server nodes or transactional SMTP delivery relays) may operate across international cloud regions. Where cross-border data processing occurs, LNQ Teams implements safeguards and contractual assurances aligned with cross-border data transfer regulations issued by the Saudi Data & AI Authority (SDAIA) to ensure an adequate standard of protection.
12. Data Retention, Deletion & Audit Integrity
Personal data is retained only for as long as needed to fulfill operational and regulatory requirements:
- Upon deleting your account via profile settings, your public profile is immediately deactivated and memberships are unlinked.
- Soft-deleted records are immediately hidden from public directories, preserving safety against inadvertent deletion.
- Certain administrative records—including security audit logs, moderation case history, and transactional email dispatch records—are retained for appropriate governance periods to ensure cybersecurity, prevent repeat fraud, and fulfill statutory compliance obligations.
14. Technical Safeguards & Security
Our infrastructure incorporates multi-layered technical and organizational safeguards:
- Enforced HTTPS/TLS encryption across all production network endpoints.
- Granular role-based access controls restricting administrative dashboard capabilities.
- Strict rate-limiting on authentication and invitation claiming routes to prevent automated brute-force attacks.
- Server-side input sanitization and parameterized queries protecting against SQL injection and cross-site scripting (XSS).
15. Data Subject Rights Under Saudi Law
Under the Saudi Personal Data Protection Law, you are entitled to several fundamental rights, subject to legal limitations:
- Right to be Informed: To know what personal data is processed, why, and on what legal grounds.
- Right of Access: To request access to your personal data held by the platform.
- Right to Obtain a Copy: To receive your data in a clear, readable digital format.
- Right to Rectification: To request correction, completion, or updating of inaccurate data.
- Right to Destruction / Erasure: To request destruction of personal data when no longer needed, except where legal or audit retention is required.
- Right to Withdraw Consent: To withdraw previously provided consent at any time where consent was the processing basis.
16. How to Exercise Privacy Rights
You can directly view and edit your profile information or delete your account through your account settings. For formal data access or destruction requests, please email our privacy channel. We may request reasonable identity verification before processing requests to prevent unauthorized data exposure.
17. Policy Updates & Revision History
We may update this Privacy Policy periodically to reflect technological changes or evolving legal regulations. When material modifications occur, we will update the "Last Updated" date at the top of this page and issue appropriate notices within the application or via email.
18. Privacy Contact & Inquiries
If you have any questions, concerns, or requests regarding the processing of your personal data under Saudi regulations, please contact our privacy channel: