Legal / Data Protection

Data Protection Policy.

OAT's data protection program is engineered for sovereign AI workloads — combining KSA residency, regulator-aligned governance, and enterprise security controls.

Framework
PDPL + ISO
Residency
KSA
Crypto
AES-256 / TLS 1.3
Notification
72 hours
Controls

Our data protection controls.

01

PDPL Alignment

Processing aligned with the Saudi Personal Data Protection Law and SDAIA executive regulations.

PDPLSDAIA
02

Sovereign Residency

Personal and enterprise data is hosted within KSA, on infrastructure under Saudi jurisdiction.

KSA Hosted
03

Encryption

AES-256 at rest and TLS 1.3 in transit across all OAT services, with HSM-backed key management.

AES-256TLS 1.3
04

Identity & Access

Zero-trust identity, least-privilege RBAC, MFA enforcement, and continuous session attestation.

Zero TrustMFA
05

Audit Logging

Immutable, tamper-evident logs covering all data access and administrative actions.

Audit
06

Sub-Processors

Strict vetting, contractual safeguards, and ongoing monitoring of every sub-processor in the chain.

DPA
07

Breach Response

Defined incident severity matrix and 72-hour regulator notification commitment for qualifying incidents.

72h
08

Data Subject Rights

Standardized intake for access, correction, deletion, and portability requests with SLA timelines.

DSR
Contact

Data Protection Office.

For data protection inquiries, DSR requests, or breach notifications, contact our Data Protection Office: