PINAVIAAI governance and execution
Back to Pinavia

Compliance

Compliance

GCC and Pakistan regulatory frameworks, where your data lives, and the processing commitments Pinavia makes to every pilot workspace.

Effective 2026-08-06Draft — under legal review

This statement is a complete draft prepared for legal review. It describes the frameworks, residency and commitments Pinavia operates under today. If your procurement process requires a counsel-approved compliance statement or a signed DPA before onboarding, request them at hello@pinavia.io.

Pakistan — Personal Data Protection Law (PDPL) 2023

Pinavia processes personal data under the authority of the data controller (the pilot workspace owner). All customer data is encrypted at rest (AES-256-GCM) and in transit (TLS 1.3). Data is hosted on Neon Postgres (ap-southeast-1, Singapore) with Cloudflare R2 for file storage.

Cross-border transfer is supported because the data controller is based in Pakistan and processing infrastructure is in Singapore, a jurisdiction with adequate data protection standards under PDPL.

United Arab Emirates — Federal Decree-Law No. 45 of 2021 (PDPL)

Pinavia FZCO is a Dubai-registered entity. Data processing complies with UAE PDPL requirements for consent, purpose limitation, and data subject rights. The platform supports data localisation through regional Neon deployment.

Controller-processor relationship: the pilot workspace owner is the controller; Pinavia is the processor. A Data Processing Agreement template is available for signed pilot contracts.

Kingdom of Saudi Arabia — SAMA Cybersecurity Framework / NCA Essential Cybersecurity Controls

For KSA-regulated financial institutions, Pinavia supports evidence-bounded governance workflows that align with SAMA's cybersecurity maturity model and NCA-ECC controls. The audit trail, approval chain enforcement, and evidence provenance match regulatory expectations for board-level technology governance.

Pinavia does not hold a SAMA licence and does not provide regulated financial services. It is a governance technology platform used by licensed entities under their own regulatory umbrella.

Processing commitments

What Pinavia commits to for every pilot workspace:

  • Data residency — all customer data is hosted on Neon Postgres in Singapore (ap-southeast-1); file storage uses Cloudflare R2. No customer data is stored in the United States or European Union unless explicitly configured.
  • Retention and deletion — workspace owners control retention. Evidence and agent outputs can be deleted at any time. On workspace closure, all data is permanently deleted within 30 days; backups are retained for 30 days (Neon point-in-time recovery).
  • Breach response — affected workspace owners are notified within 72 hours of a confirmed breach, with a detailed incident report covering root cause, affected data, and remediation.
  • Subprocessors — Neon (database), Cloudflare (R2 storage, CDN), Clerk (identity), Anthropic and DeepSeek (language models), Sentry (error monitoring), Plausible (analytics), Resend (email). No customer data is used to train third-party models.
  • Data Processing Agreement — a DPA template is available for signed pilot contracts, covering controller-processor roles, data categories, processing purposes, subprocessor notification, data subject rights, and cross-border transfer safeguards.

Contact

For compliance enquiries and DPA requests write to hello@pinavia.io. For security disclosures write to security@pinavia.io. Pinavia FZCO, Dubai, UAE.

Compliance | Pinavia