Security and privacy

Your leads stay yours

The people your team meets are your company's most valuable list. This page says, without adjectives, how SEL XP keeps that list apart from everyone else's, where it is stored, who handles it and what is still to come.

Last updated 5 October 2026

What is in place

Six things that protect your data

  • Each customer is kept apart by the database itself

    Every table that holds customer data carries the workspace it belongs to, and row-level security is forced on all of them. The application cannot read across workspaces even if its own code has a fault.

    • The service connects with a role that cannot bypass these rules
    • Automated tests fail the build if a new table lacks them
    • Looking across workspaces is limited to exact matches: one email at sign-in, one token for a public page
  • Inside your company, people see what they should

    A rep sees their own leads. A manager sees their teams', an admin their company's or branch's, and owners see everything. The server decides this for every list, export, report and sync, so the app cannot show more than a person is allowed.

    • Every admin change is written to an audit log
    • Handovers and exports are audited too
    • An admin can switch a person off at once
  • What stays on the phone is encrypted

    For offline use the app keeps a copy of a person's leads, tasks and check-ins on their device, with anything waiting to be sent. Each record is sealed with AES-GCM encryption, and the copy is forgotten when they sign out.

    • Card photos and voice notes waiting to send are sealed too
    • The store apps will keep the key in the phone's own secure storage
    • Remote wipe for a lost phone is planned, not built
  • Sign-in without passwords

    People sign in with a six-digit code sent to their work email. There are no passwords to reuse, leak or reset. People join by an admin's invitation only.

    • Sign-in attempts are limited for each address
    • Sessions are signed and expire
    • Single sign-on is planned
  • AI that keeps nothing, and decides nothing

    Card reading, voice transcription and note drafts use AI providers set to zero data retention: nothing is kept after the answer comes back. What the AI returns is treated as untrusted. Our own checks run on it, and a person approves it before anything is saved.

    • Text on a card or in a note is data, never an instruction to the AI
    • Card photos and recordings are private, and removed after 90 days by default
    • We count how often AI is used, never what was said
  • Your CRM's key is kept in a secret store

    The API key for your CRM lives in a secret vault. It is never stored in our tables, written to a log, audited or sent back by the API. A CRM address must be https and may not point at a private network.

    • A refused key pauses the connection and tells your admins
    • Nothing is sent to the CRM twice
    • Disconnecting removes the key

Where it goes

Where your data is stored, and who handles it

Neither of our hosting providers has a region in the Gulf yet, so we use the nearest one. If your company must keep data in its own country, tell us before you buy: a self-hosted deployment in your own environment is the option for that.

WhatProviderWhereNote
Database and filesSupabaseMumbai, IndiaLeads, tasks, check-ins, card photos, voice recordings
The app and its APIVercelMumbai, IndiaServes the app and answers its requests
EmailResendOutside the GulfSign-in codes, follow-up emails, reminders
Card reading and note draftsAnthropic, through Vercel's AI GatewayOutside the GulfZero data retention
Voice transcriptionMicrosoft, through Vercel's AI GatewayOutside the GulfZero data retention

This list changes as the product does. The date at the top of the page says when it was last correct. The card reader in particular is being tested against others and may change.

The law where you sell

Data protection law in the Gulf

Your company decides why it collects a visitor's details, and is responsible for that. We process the data for you. This is a summary, not legal advice.

Saudi Arabia

Personal Data Protection Law (Royal Decree M/19 of 2021, amended by M/148 of 2023)

In force since 14 September 2023, with compliance required from 14 September 2024. The regulator is SDAIA. Sending personal data outside the Kingdom is allowed only on set conditions.

United Arab Emirates

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data

In force since 2 January 2022. The financial free zones, DIFC and ADGM, have data protection laws of their own.

Qatar, Bahrain, Oman, Kuwait

Each has its own law or regulation

Qatar's Law No. 13 of 2016, Bahrain's Law No. 30 of 2018 and Oman's Royal Decree 6/2022 are general data protection laws. Kuwait regulates through its communications authority.

What the product does to help

  • Each lead records why you may contact that person.
  • A visitor who shares their details from a card does so with the consent wording your company chose.
  • Someone who asked not to be contacted gets no follow-up and no reminder is raised about them.
  • Your privacy notice is linked on every page a visitor can open.
  • Card photos and voice recordings are removed after a set period.

For our data processing terms, or a question from your security team, write to hello@lucidarc.ae.

Questions

What security teams ask

Where is our data stored?

SEL XP stores its database and files in Mumbai, India, which is the nearest region our hosting providers offer to the Gulf. If your company's policy requires data to stay in your own country, tell us before you buy: a self-hosted deployment in your own environment is the option for that case.

Can other customers see our leads?

No. Each company has its own workspace, and the separation is enforced by the database itself, with row-level security on every table, not only by the application. The service connects with a role that cannot bypass it.

Who inside our company can see a lead?

A rep sees their own leads. A manager sees their teams' leads, a company or branch admin sees that unit's, and owners see everything. The server works this out for every list, export and report, so the app cannot show more than a person is allowed.

Is data on the phone protected?

Yes. What the app keeps on the phone for offline use, including leads, tasks and anything waiting to be sent, is sealed with AES-GCM encryption. It is forgotten when the person signs out.

Does the AI keep our business cards?

No. Card reading, voice transcription and note drafts go through AI providers set to zero data retention, so nothing is kept after the answer comes back. A person approves what the AI read or wrote before it is saved.

How do people sign in?

With a six-digit code sent to their work email, so there are no passwords to leak or reuse. People are invited by an admin, and an admin can switch a person off at once.

Is SEL XP ISO 27001 or SOC 2 certified?

Not today. SEL XP is a new product and holds no security certification yet. This page sets out what is in place instead: database-level separation of customers, encrypted storage on the phone, sign-in by emailed code, an audit log and AI providers set to keep nothing.

Can we get our data out?

Yes. Managers and admins can export leads as a spreadsheet at any time, and with a CRM connected your leads are already there with their history. Card photos are removed after 90 days by default; what was read from them stays with the lead.

See it with your team

Bring your security team to the demo.

We will show them the separation between customers, the audit log and exactly what reaches each provider.

  1. What happens next
  2. Day 0You send the form. We reply within one working day.
  3. 30 minA call on your screen: capture, follow-up, CRM and what your managers see.
  4. Set-upWe build your workspace with you: companies, teams, products, wording.