Barada Privacy Policy

Last Updated: March 2025

This Privacy Policy describes how Barada Inc., operating the Barada platform ("Barada," "we," "us," or "our"), collects, uses, stores, shares, and protects your personal information when you access or use our web and mobile platform (the "Platform"). Your privacy is important to us. By accessing or using the Platform, your personal data will be processed in accordance with this Privacy Policy and the applicable lawful bases described herein. Where processing is based on your consent, you may withdraw such consent at any time. If you do not agree with our policies and practices, please do not use the Platform. This Privacy Policy is incorporated into and is subject to the Barada Terms & Conditions of Service.

1. Information We Collect

We collect various types of information to provide and improve our Services to you.

1.1. Information You Provide to Us Directly

For compliance with financial, regulatory, and anti-fraud obligations, we may collect personal information such as your name, email address, password, phone number, national ID numbers, commercial registration documents, licenses, and related verification materials. This data is treated as personal data under applicable laws and is: • Processed strictly for regulatory compliance, • Subject to restricted internal access, • Encrypted in storage and transit, • Retained only for legally mandated periods, • Not used for marketing or profiling purposes. Certain identity verification data, including national ID numbers and government-issued documents, may constitute sensitive personal data under applicable laws. Such data is subject to enhanced safeguards, restricted access controls, and limited retention periods in accordance with regulatory requirements.

Profile Information

  • For Brands: Company name, contact information, commercial registration, VAT registration, billing address, payment information, marketing objectives, industry, target demographics, campaign budgets, social media handles and links, bio, profile picture, demographic information (e.g., age, gender, location, interests), content niches, past campaign experience, expected rates, audience demographics, performance metrics and other information relevant to campaign creation.
  • For Agencies: Agency name, client brand information, team member details, billing arrangements, and all brands information under the agency as mentioned under the "For Brands" section.
  • For Content Creators: Social media handles and links, bio, profile picture, demographic information (e.g., age, gender, location, interests), content niches, past campaign experience, expected rates, audience demographics, performance metrics, and banking details for payments. You authorize us to obtain certain public, and authorized personal information from your linked social media accounts as per your platform settings and our Privacy Policy. In the case the content creator is located in a licensed market, Barada Inc. requires the license.

Campaign Data

Information related to campaigns you create or participate in, including campaign briefs, AI-generated recommendations, proposals, agreements, deliverables, communications between Brands and Content Creators, content submissions, approval workflows, and feedback.

Payment Information

When you make or receive payments through the Platform's escrow system, we collect payment details such as bank account details, BenefitPay information, and other local payment method details. This information is processed by our third-party payment processors including Stripe and regional payment gateways, and we do not directly store sensitive payment card data.

Communications

Records of your communications with us, including customer support inquiries, feedback, and survey responses. This also includes information you provide when you communicate with other users through the Platform.

Identity Verification

For compliance with regional regulations, we will collect national ID numbers, commercial registration documents, or other verification documents including but not limited to licenses.

Data Minimization: We collect only personal data that is necessary, proportionate, and relevant.

1.2. Information We Collect Automatically

When you access and use the Platform, we may automatically collect certain information about your device and usage patterns:

  • Usage Data: Information on how you access and use the Platform, such as the pages you visit, the features you use, AI recommendations you interact with, the links you click, the searches you conduct, and the time and date of your activities.
  • Device Information: Details about your device, including your IP address, device type, operating system, browser type, and mobile network information.
  • Location Information: With your consent, we may collect information about your location to provide region-specific services and ensure compliance with local regulations.
  • Log Data: Server logs may include your IP address, browser type, referring/exit pages, and timestamps.
  • Cookies and Similar Technologies: We use cookies and similar tracking technologies to collect information about your browsing activity and preferences, such as your language preferences (Arabic/English), login details, and website traffic.
  • AI Interaction Data: Information about how you interact with our AI-powered features, including search queries, matching preferences, and content optimization choices.

1.3. Information We Collect from Third Parties

  • Social Media: If you connect your social media accounts to the Platform, we collect information from those accounts, such as your profile information, public posts, follower counts, engagement metrics, and content performance data.
  • Third-Party Services: We will collect information about you from third-party services including payment processors, analytics providers, fraud detection services, and identity verification providers.
  • Client's Agencies Integration: When applicable, we may receive information about content creation services provided through the client's designated agencies.
  • Publicly Available Data: We will collect information from publicly available sources to enhance your profile and provide relevant AI-powered recommendations.

We collect only personal data that is necessary, proportionate, and relevant to the purposes described in this Privacy Policy. We do not collect excessive or unrelated data.

2. Our Role as Data Controller and Processor

Barada acts as a Data Controller for the personal information we collect directly from you for the purpose of providing and managing your access to the Platform, processing subscriptions, facilitating escrow payments, and for our own marketing and operational purposes. When Brands or Agencies use the Barada Platform to collect or manage personal information about Content Creators (or other individuals), Barada acts as a Data Processor on behalf of the Brand or Agency. In such cases, the Brand or Agency is the Data Controller, and Barada processes such data strictly according to their instructions and our agreements with them. Brands and Agencies are responsible for complying with any regulations or laws that require providing notice, disclosure, and/or obtaining consent prior to transferring data to Barada for processing purposes. In certain circumstances, Barada and Brands or Agencies may act as independent or joint controllers where both parties determine the purposes and means of processing (for example, platform analytics or AI system improvement).

3. How We Use Your Information

We use the information we collect for various purposes, including:

  • To Provide and Improve the Platform: To operate, maintain, and improve the Platform, including personalizing your experience through AI algorithms, providing relevant content and recommendations, and developing new features.
  • To Facilitate AI-Powered Collaborations: • Use Campaign AI to match campaigns with suitable creators based on performance metrics. • Apply Performance AI to predict campaign success and ROI. • Utilize Creative AI to suggest content improvements and optimization. • Implement Scheduling AI to determine optimal posting times. • Deploy Cultural AI to ensure content appropriateness for GCC markets.
  • To Manage Escrow Payments: To securely hold funds in escrow, release payments upon campaign completion, process refunds when necessary, and maintain transaction records for compliance.
  • To Communicate with You: To send service-related notifications, campaign updates, payment confirmations, security alerts, and support messages. With your consent, we may send marketing communications about new features and promotions.
  • For Analytics and Research: To analyze trends, usage patterns, and user demographics to improve the Platform. This includes creating AI-powered profiles about Content Creators based on their reach, audience context, and performance metrics to help Brands find suitable partners.
  • To Ensure Compliance: To comply with regional regulations, including data localization requirements, content moderation standards, and financial regulations.
  • To Protect Our Rights: To protect our rights, property, and interests, prevent fraud and abuse, and enforce our Terms of Service.
  • For Marketing and Promotion: As stated in our Terms & Conditions, we use Brand details, Content Creator details, and Campaign Content to promote and market the Platform and its Services.

3.1 Legal Bases for Processing

We process personal data under the following lawful bases: • Contractual Necessity – To create and manage accounts, facilitate campaigns, process escrow payments, and provide Platform functionality. • Legal Obligation – To comply with anti-money laundering (AML), tax, identity verification, financial regulations, and regional data localization requirements. • Legitimate Interests – To prevent fraud, ensure platform security, improve services, conduct analytics, and develop AI-powered features, provided such interests are not overridden by your rights. • Consent – For marketing communications, optional AI profiling features, location services, and international transfers where required by law.

4. How We Share Your Information

We may share your information with third parties in the following circumstances:

  • Between Platform Users: Information necessary for campaign collaboration is shared between relevant Brands, Agencies, and Content Creators on the Platform. This includes profiles, proposals, campaign briefs, and performance metrics.
  • With Service Providers: We share information with trusted third-party service providers including: • Payment processors (Stripe) • Cloud hosting providers • Analytics providers • Identity verification services • Customer support tools • Barada's Channels (offline & online) Payment processors who act either as independent data controllers or processors depending on the transaction context. Payment data may be transferred cross-border subject to appropriate safeguards including contractual protections and encryption.
  • With Affiliates: We may share your information with our affiliates and subsidiaries for business and operational purposes consistent with this Privacy Policy.
  • With Legal Authorities: We may disclose your information if required by law, legal process, or governmental request, including compliance with regional authorities.
  • Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction.
  • With Your Consent: We may share your information with third parties when we have your explicit consent.
  • Aggregated Data: We may share aggregated and de-identified information that cannot reasonably be used to identify you for research and industry insights.

Barada does not sell personal data to third parties.

5. International Data Transfers and Regional Storage

Data Localization

  • Saudi Arabia: Data of Saudi residents is stored within Saudi Arabia in compliance with local regulations. Where required under the Kingdom of Saudi Arabia Personal Data Protection Law (KSA PDPL), personal data of Saudi residents will be stored and processed within the Kingdom. If cross-border transfers are necessary, such transfers will occur only: • With explicit user consent where required, • Pursuant to regulatory approvals where applicable, • Subject to appropriate safeguards including encryption and contractual protections.
  • Bahrain: Primary data center for regional operations.
  • Other GCC Countries: Data stored regionally with appropriate safeguards.

Your information may be transferred to and processed in countries other than your country of residence. We implement appropriate safeguards including Standard Contractual Clauses (SCCs) and encryption to ensure compliance with applicable laws. Where required by applicable law, we conduct transfer impact assessments to evaluate risks associated with cross-border transfers and implement supplementary safeguards where necessary.

6. Your Choices and Rights

The availability and scope of these rights may vary depending on your country of residence and applicable data protection laws. You have certain rights regarding your personal information:

  • Account Management: Update your account information at any time through your account settings.
  • Communication Preferences: Opt-out of promotional emails through unsubscribe links or account settings.
  • Data Access and Portability: Request access to your personal information in a portable format.
  • Erasure: Request deletion of your personal data, subject to legal obligations (e.g., financial records, completed campaigns).
  • Correction: Request correction of inaccurate personal information.
  • Objection: Object to processing based on legitimate interest or for direct marketing.
  • Restriction: Request restriction of processing in specific circumstances.
  • Withdraw Consent: Withdraw consent for processing where we rely on consent as the legal basis.
  • AI Decisions: Request human review of automated AI-powered decisions affecting you.
  • Complaint: Lodge a complaint with relevant data protection authorities.

To exercise these rights, contact us at Support@barada.io. We will respond in accordance with applicable laws.

7. Data Security

Barada maintains internal policies, access controls, and data protection governance procedures to ensure ongoing compliance with applicable data protection laws. Employees and contractors with access to personal data are subject to confidentiality obligations and receive appropriate data protection training. We implement industry-standard security measures including: • 256-bit SSL encryption for data transmission • Encrypted storage of sensitive information • Regular security audits and assessments • Access controls and multi-factor authentication • Secure escrow payment processing • Incident response procedures While we strive to protect your information, no method of transmission or storage is completely secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and relevant regulatory authorities in accordance with applicable laws.

8. Data Retention

We retain your information for as long as necessary to: • Maintain active accounts • Complete ongoing campaigns • Comply with legal obligations (financial records, tax requirements) • Resolve disputes • Enforce agreements Barada retains all data that is public on the platform and has been uploaded and shared by the users. Publicly shared content will remain visible during the account lifecycle. Upon account closure, such content will be deleted, anonymized, or retained only where legally required or necessary for dispute resolution. Account data is retained for the duration of the account relationship and for a period thereafter to comply with legal, financial, and dispute resolution obligations. Shared data may remain visible for the duration of your account. Upon account closure, such content will either: • Be deleted within a reasonable timeframe, • Be anonymized for analytics purposes, or • Be retained only where legally required. We do not retain personal data indefinitely without lawful justification.

9. Third-Party Links and Services

The Platform may contain links to third-party websites or services. We are not responsible for their privacy practices. We encourage you to review their privacy policies.

10. Children's Privacy

The Barada Platform is not intended for individuals under 16. We do not knowingly collect personal information from anyone under 16. If we discover such a collection, we will promptly delete the information.

11. Regulatory Compliance

Barada is committed to complying with applicable data protection laws in the jurisdictions in which it operates, including: Kingdom of Bahrain Compliance with Bahrain Personal Data Protection Law (Law No. 30 of 2018) and all regulations. Kingdom of Saudi Arabia Compliance with the KSA Personal Data Protection Law (PDPL), including data localization and cross-border transfer requirements. United Arab Emirates Compliance with UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection, and where applicable, DIFC and ADGM data protection regulations. Users may contact the relevant supervisory authority in their jurisdiction for complaints. This Privacy Policy shall be governed by and interpreted in accordance with the laws of Bahrain, without prejudice to mandatory data protection rights under applicable local laws.

12. AI and Automated Decision-Making

Our AI systems process your data to: • Match creators with campaigns • Predict campaign performance & ROI • Optimize content and scheduling • Ensure cultural appropriateness • Create and manage content • Suggest campaign budgets Our AI systems provide assistive recommendations and do not independently produce legal or similarly significant effects without human oversight. We implement: • Human review mechanisms, • Bias monitoring procedures, • Periodic AI system evaluations, • Safeguards to reduce discriminatory or culturally inappropriate outputs. Users may request clarification regarding key inputs influencing AI-driven recommendations. AI-generated recommendations are based on statistical analysis of engagement metrics, audience demographics, content performance, and campaign objectives. These systems do not make autonomous contractual or financial decisions without human review. Where profiling is used, it is limited to professional platform performance evaluation and does not involve sensitive personal characteristics. AI outputs are subject to periodic review and refinement to ensure accuracy and fairness.

13. Changes to This Privacy Policy

We may update this Privacy Policy periodically. We will notify you of material changes by posting the new Privacy Policy and updating the "Effective Date." Continued use after changes constitutes acceptance.

Data Protection Contact

If you have questions about this Privacy Policy or our data practices, you may contact us at: Support@barada.io