Our architecture and operational measures ensuring strict compliance with Saudi Arabia's Personal Data Protection Law.
The Personal Data Protection Law (PDPL), issued by Royal Decree No. M/147, governs the processing of personal data inside the Kingdom of Saudi Arabia. Qalaama, under the regulatory oversight of the Saudi Data and AI Authority (SDAIA), strictly implements the required technical and administrative safeguards to protect data subjects.
We act as a Processor for all messaging payload and recipient phone metadata generated by our clients, and as a Controller for account registration details. In both capacities, we ensure that the core data protection principles are enforced.
To safeguard national digital sovereignty, Qalaama maintains an isolated hosting cluster in Riyadh:
All personal databases, SAMA-compliant audit records, transaction logs, and WhatsApp API session caches are hosted on localized secure servers inside KSA.
We do not route local Saudi traffic or customer profiles through regional or international data centers. No data is transferred across KSA borders except under explicit conditions approved by SDAIA.
We adhere strictly to the data minimization principle. We only collect the minimal personal data required to register accounts, verify business identities, and route communications.
Consent is obtained explicitly at the time of collection (such as when registering via our sign-up form). Users retain the right to withdraw consent at any time, except where processing is required under CITC messaging rules or statutory financial records compliance.
Qalaama enforces advanced security protocols to protect data from unauthorized access, alteration, or disclosure:
For inquiries regarding our compliance status, privacy impact assessments, or to file data subject requests under PDPL, please reach out to our dedicated compliance bureau:
Compliance Office: compliance@qalaama.com
Qalaama Data Residency & Protection Office, Riyadh, Saudi Arabia.