NEW The NOVA engine now understands Saudi dialects with higher accuracy
Legal · Compliance

Compliance Statement

How we approach regulatory expectations: what the platform is designed to support, the evidence we provide to audit teams, and what we do not claim. A statement written to be read in compliance committees as-is: no inflation, no ambiguity.

Last updated: June 2026

Regulatory compliance is your organization's obligation to its regulators: no platform can "grant" you compliance or guarantee it on your behalf. What we commit to is threefold: designing the platform to support your compliance journey, providing your audit teams the evidence they need, and separating clearly what we implement from what we do not claim.

This statement complements the Privacy Policy and the Security Statement; its operational counterparts in the Trust Center are the PDPL page and the Saudi compliance page.

1

Our PDPL stance

The platform's controls are designed to comply with the Saudi Personal Data Protection Law (PDPL) and its regulations: data minimization, purpose limitation, data-subject rights, and security of processing.

  • We provide a data processing agreement to customers, defining each party's role: you control your data; we process it to run the service: along with processing, notification, and deletion obligations.
  • The Privacy Policy explains what we collect, how we use it, and your rights over it: in plain language.
  • The principle-to-control mapping that ties the law's articles to platform controls lives on the PDPL page in the Trust Center: this statement does not duplicate it.

To be precise: "designed to comply" means the controls were built around the law's requirements and support your obligations: it does not replace your own legal assessment.

2 · Data residency

Your data resides in the Kingdom

On NOVA Cloud, customer data resides in Saudi Arabia by default: in Saudi data centers. That is not a passing feature; it is a commitment:

  • We do not change where your data resides on NOVA Cloud without prior notice to you.
  • Any transfer of personal data outside the Kingdom: should it ever be needed: is subject to the transfer provisions of the law and its regulations, and does not happen without a legal basis and clear notice.
  • In private-cloud (VPC) and on-premises deployments, data stays entirely inside your own infrastructure: including air-gapped environments isolated from the internet.

Details of the three deployment paths are on the deployment page.

3

What audit teams can request from us

We support your audit readiness with evidence that can actually be requested: not with generic assurances. Our customers, and the review teams working on their behalf, can request:

  • Control descriptions: documentation of the security model and platform architecture at a depth suited to security reviews: starting from the Security page and going deeper on request.
  • Contractual documents: the data processing agreement, and our infrastructure-provider stance as documented in the Security Statement.
  • Security and compliance questionnaires: we answer assessment questionnaires within a reasonable scope and timeframe.
  • Evidence of your own usage: the in-platform audit trail records who executed what, under which permission: and your teams can export it for internal reviews.
4 · Certifications

What we do not claim

Our rule on certifications and accreditations is explicit: we do not claim certifications we have not earned; when we obtain independent certifications, we will announce them here and in the Trust Center.

  • When we say our controls were "designed with" a standard or framework in mind, we mean its requirements informed the design: not that we hold a formal accreditation, unless we state so in writing.
  • We do not use the logos of regulators or regulatory frameworks in a way that implies an endorsement that was not issued.
  • The platform was built with Saudi regulatory expectations in mind, and we track how they evolve: any future independent certification or assessment will be documented with its date and scope.
5

Cooperation with regulators

We operate from the Kingdom and under its laws, and we deal with competent authorities responsibly:

  • Lawful requests issued by a competent authority are handled in accordance with the law, with the minimum disclosure necessary: consistent with the Privacy Policy.
  • Unless the law prevents it, we seek to notify the customer of requests concerning their data.
  • If your organization undergoes a regulatory review related to its use of the platform, we cooperate by providing the service-related information and evidence within the scope of our agreement.
6

Contact & changes to this statement

For compliance and audit questions, write to [email protected] or contact us. If you are assessing your organization's readiness to adopt AI within Saudi regulatory expectations, start from the Saudi compliance page in the Trust Center.

If we make a material change to this statement, we notify customers before it takes effect, by email or an in-platform notice.