Skip to content
Qalaama Enterprise Communication Platform
PDPL Compliance Policy

PDPL Compliance Policy

Our architecture and operational measures ensuring strict compliance with Saudi Arabia's Personal Data Protection Law.

Last updated: July 2026

Quick Summary

  • Local Databases: Absolute local residency - zero transfer of Saudi user data outside KSA without regulatory authorization.
  • Purpose Limitation: Data is collected strictly for messaging routing and authentication purposes.
  • Audit Logging: Robust internal audit trails tracking access to database logs.
  • SDAIA Aligned: Operations aligned with the rules set out by the Saudi Data and AI Authority (SDAIA).

1. The Saudi PDPL Compliance Framework

The Personal Data Protection Law (PDPL), issued by Royal Decree No. M/147, governs the processing of personal data inside the Kingdom of Saudi Arabia. Qalaama, under the regulatory oversight of the Saudi Data and AI Authority (SDAIA), strictly implements the required technical and administrative safeguards to protect data subjects.

We act as a Processor for all messaging payload and recipient phone metadata generated by our clients, and as a Controller for account registration details. In both capacities, we ensure that the core data protection principles are enforced.

2. Data Residency and Cloud Architecture

To safeguard national digital sovereignty, Qalaama maintains an isolated hosting cluster in Riyadh:

All personal databases, SAMA-compliant audit records, transaction logs, and WhatsApp API session caches are hosted on localized secure servers inside KSA.

We do not route local Saudi traffic or customer profiles through regional or international data centers. No data is transferred across KSA borders except under explicit conditions approved by SDAIA.

4. Technical Security Safeguards

Qalaama enforces advanced security protocols to protect data from unauthorized access, alteration, or disclosure:

  • Encryption: All API transmissions utilize HTTPS TLS 1.3 encryption. Internal data fields are encrypted at rest with AES-256.
  • Access Control: Multi-Factor Authentication (MFA) and Role-Based Access Control (RBAC) are strictly enforced for Qalaama administrators.
  • Vulnerability Assessment: Regular third-party penetration testing and compliance audits are executed to maintain secure network boundaries.

5. Compliance Office Contact Information

For inquiries regarding our compliance status, privacy impact assessments, or to file data subject requests under PDPL, please reach out to our dedicated compliance bureau:

Compliance Office: compliance@qalaama.com

Qalaama Data Residency & Protection Office, Riyadh, Saudi Arabia.