Compliance
Compliance
GCC and Pakistan regulatory frameworks, where your data lives, and the processing commitments Pinavia makes to every pilot workspace.
This statement is a complete draft prepared for legal review. It describes the frameworks, residency and commitments Pinavia operates under today. If your procurement process requires a counsel-approved compliance statement or a signed DPA before onboarding, request them at hello@pinavia.io.
Pakistan — Personal Data Protection Law (PDPL) 2023
Pinavia processes personal data under the authority of the data controller (the pilot workspace owner). All customer data is encrypted at rest (AES-256-GCM) and in transit (TLS 1.3). Data is hosted on Neon Postgres (ap-southeast-1, Singapore) with Cloudflare R2 for file storage.
Cross-border transfer is supported because the data controller is based in Pakistan and processing infrastructure is in Singapore, a jurisdiction with adequate data protection standards under PDPL.
United Arab Emirates — Federal Decree-Law No. 45 of 2021 (PDPL)
Pinavia FZCO is a Dubai-registered entity. Data processing complies with UAE PDPL requirements for consent, purpose limitation, and data subject rights. The platform supports data localisation through regional Neon deployment.
Controller-processor relationship: the pilot workspace owner is the controller; Pinavia is the processor. A Data Processing Agreement template is available for signed pilot contracts.
Kingdom of Saudi Arabia — SAMA Cybersecurity Framework / NCA Essential Cybersecurity Controls
For KSA-regulated financial institutions, Pinavia supports evidence-bounded governance workflows that align with SAMA's cybersecurity maturity model and NCA-ECC controls. The audit trail, approval chain enforcement, and evidence provenance match regulatory expectations for board-level technology governance.
Pinavia does not hold a SAMA licence and does not provide regulated financial services. It is a governance technology platform used by licensed entities under their own regulatory umbrella.
Processing commitments
What Pinavia commits to for every pilot workspace:
- Data residency — all customer data is hosted on Neon Postgres in Singapore (ap-southeast-1); file storage uses Cloudflare R2. No customer data is stored in the United States or European Union unless explicitly configured.
- Retention and deletion — workspace owners control retention. Evidence and agent outputs can be deleted at any time. On workspace closure, all data is permanently deleted within 30 days; backups are retained for 30 days (Neon point-in-time recovery).
- Breach response — affected workspace owners are notified within 72 hours of a confirmed breach, with a detailed incident report covering root cause, affected data, and remediation.
- Subprocessors — Neon (database), Cloudflare (R2 storage, CDN), Clerk (identity), Anthropic and DeepSeek (language models), Sentry (error monitoring), Plausible (analytics), Resend (email). No customer data is used to train third-party models.
- Data Processing Agreement — a DPA template is available for signed pilot contracts, covering controller-processor roles, data categories, processing purposes, subprocessor notification, data subject rights, and cross-border transfer safeguards.
Contact
For compliance enquiries and DPA requests write to hello@pinavia.io. For security disclosures write to security@pinavia.io. Pinavia FZCO, Dubai, UAE.