Legal

Privacy Policy

What personal data Strategia collects, why, how long it is kept, and the rights you have over it.

Note This is the first published edition of the Strategia Privacy Policy. It is a good-faith draft prepared for the platform and must be reviewed by qualified legal counsel and, where required, registered with the relevant data protection authority before it is relied upon in production. Nothing here is legal advice.

1. Scope

This Privacy Policy explains how Nudom Systems ("we", "us"), operator of the Strategia strategy and performance management platform, handles personal data.

It is written with the Kingdom of Bahrain's Personal Data Protection Law (Law No. 30 of 2018, "PDPL") in mind, and follows the structure of the EU General Data Protection Regulation (GDPR) so that customers subject to it can map their own obligations onto ours.

2. Controller and processor roles

Strategia is a multi-tenant platform sold to organisations, so there are two distinct relationships:

Data Who is the controller Who is the processor
Data your organisation puts into its workspace (users, goals, KPIs, check-ins, comments, files) Your organisation Nudom Systems
Data we hold to run the platform itself (billing contacts, support tickets, security logs) Nudom Systems

Where we act as a processor, we act on your organisation's documented instructions. If you want your data corrected or deleted, contact your organisation's administrator first — they control it. We will help them action your request.

3. Personal data we process

3.1 Account and profile data

Name, work email address, staff or employee ID, job position, department, organisational reporting line, account status, profile photo, preferred language, and notification preferences.

3.2 Authentication and security data

Hashed password (we never store passwords in readable form), password reset tokens, multi-factor authentication secrets and recovery codes, trusted-device records, sign-in timestamps, and the IP address and browser user-agent of sign-in attempts.

3.3 Usage and activity data

An append-only, hash-chained activity log of significant actions — records created, changed or deleted, approvals, workflow transitions, permission changes — including who acted, when, and from what IP address. This log exists for security, accountability and audit, and by design it cannot be edited after the fact.

3.4 Content you create

Goals, KPIs, metric readings, check-in commentary, comments and mentions, risk entries and treatments, report definitions, and any file you upload. This content is under your organisation's control and may contain personal data if your users put personal data into it.

When you accept the Terms and Conditions or this Privacy Policy, we record which document version you accepted, the date and time, your IP address and the interface language you accepted in.

3.6 Technical and diagnostic data

Application and error logs, and — where enabled — error reports sent to our monitoring provider (Sentry). Error reports may include the URL you were on, your user ID and, where the customer has enabled it, your name and email address so that support can follow up on a specific failure.

3.7 What we do not collect

We do not collect payment card numbers through the Platform, we do not run advertising or third-party marketing trackers in the application, and we do not use Customer Data to train machine-learning models.

Purpose Legal basis
Providing the Platform to your organisation Performance of a contract; our legitimate interest in running the service
Authenticating you and keeping accounts secure Legal obligation; legitimate interest in security
Keeping an audit trail of significant actions Legitimate interest in accountability; our customers' compliance obligations
Sending operational notifications (assignments, approvals, overdue KPIs, alerts) Performance of a contract
Diagnosing errors and improving reliability Legitimate interest in a working service
Recording acceptance of these legal documents Legal obligation; establishing consent
Responding to support requests Performance of a contract

Where we rely on consent — for example, optional analytics — you can withdraw it at any time without affecting your ability to use the Platform for its core purpose.

5. Who we share it with

We share personal data only with:

  • your own organisation — administrators and colleagues, as governed by the roles and permissions your organisation configures;
  • infrastructure and service providers acting as our sub-processors, under written contract, only as needed to run the Platform: hosting and database services, transactional email delivery, and error monitoring (Sentry);
  • professional advisers (auditors, lawyers) under a duty of confidentiality; and
  • authorities, where we are legally compelled — in which case we will notify the affected customer unless the law forbids it.

We do not sell personal data, and we do not share it for anyone else's marketing.

6. International transfers

Our primary hosting is in the region agreed with each customer. Where a sub-processor stores or accesses data outside the Kingdom of Bahrain, we rely on a lawful transfer mechanism — an adequacy finding, standard contractual clauses, or the data subject's explicit consent — and we assess the recipient's safeguards before the transfer begins.

A current list of sub-processors and their locations is available from [email protected] on request.

7. How long we keep it

Category Retention
Account and profile data For the life of the account; deleted or anonymised within 90 days of the account being permanently removed
Customer Data (goals, KPIs, content) For the subscription term, plus a 30-day export window after termination
Activity and audit logs 7 years, to serve customers' audit and compliance obligations
Consent records 7 years after the account closes, since they evidence what was agreed
Authentication and security logs 12 months
Error and diagnostic reports 90 days
Backups Rotated on a rolling schedule; deleted data disappears from backups as the rotation completes

Where we are required by law to keep something longer, we keep it only for as long as that requirement lasts.

8. How we protect it

  • Traffic is encrypted in transit with TLS; passwords are hashed with a modern, salted algorithm.
  • Each customer's data lives in a separate tenant database, not a shared table with a tenant column.
  • Access is governed by role-based permissions, with least-privilege defaults.
  • Multi-factor authentication is available to every account and can be mandated organisation-wide.
  • Administrative access by our staff is restricted, logged, and granted only when needed to operate or support the Platform.
  • Security headers, rate limiting and account lockouts defend against automated attacks.
  • The audit log is append-only and hash-chained, so tampering is detectable.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the affected customer without undue delay and within 72 hours of becoming aware of it, and will support them in notifying the relevant authority and affected individuals.

9. Your rights

Subject to the PDPL, and to the GDPR where it applies, you have the right to:

  • be informed about how your data is used — that is what this document is for;
  • access the personal data we hold about you;
  • rectify data that is inaccurate or incomplete;
  • erase data, where there is no overriding legal or contractual reason to keep it;
  • restrict or object to certain processing;
  • portability — receive your data in a structured, machine-readable format;
  • withdraw consent, where processing is based on consent; and
  • complain to the competent data protection authority.

Because most personal data on the Platform is controlled by your organisation, please start with your organisation's administrator. If you cannot reach them, or your request concerns data we control ourselves, write to [email protected]. We will respond within 30 days, and will tell you if we need longer and why.

10. Cookies and similar technologies

Strategia uses only what it needs to function:

  • a session cookie that keeps you signed in;
  • a CSRF token that protects forms from cross-site request forgery;
  • an optional "remember me" cookie and trusted-device cookie, set only when you ask for them; and
  • browser local storage for interface preferences such as your theme, language and sidebar state.

There are no advertising cookies and no third-party marketing trackers. Blocking the session or CSRF cookie will stop the Platform working.

11. Children

Strategia is a workplace tool. It is not directed at children and we do not knowingly collect personal data from anyone under 18. If you believe a child's data has reached the Platform, contact [email protected] and we will work with the relevant customer to remove it.

12. Automated decision-making

The Platform calculates achievement percentages, statuses, forecasts and narrative insights from the data you enter. These are decision-support outputs presented to a human, not automated decisions producing legal or similarly significant effects without human involvement. A person in your organisation remains responsible for any decision taken.

13. Changes to this policy

We may update this Privacy Policy. When we make a material change we will increase the version number of this document and ask you to review and accept the new version the next time you sign in. The current version and its effective date are shown at the top of this page.

14. Contact

Nudom Systems Kingdom of Bahrain Privacy enquiries: [email protected] General legal: [email protected] Web: nudomsystems.com

Version 1.0 · Effective 2026-07-26