Enterprise Privacy Policy
Public website scope
This public marketing website is hosted in Singapore. It is separate from customer-controlled enterprise deployments described below. Hosting is not evidence of Saudi data residency for this website.
Inquiry forms prepare drafts locally in your browser; they do not submit, store, or confirm receipt of your details. Sending a draft uses your chosen email provider. Please do not enter sensitive or confidential information. The illustrative demo and readiness assessment run locally and are not connected to customer systems.
Fonts, icons, and website scripts are served locally. No analytics, advertising trackers, or account cookies are configured. Web-server operational logs may record connection metadata such as IP address and requested URL; inquiry fields are not included.
1. Purpose and Sovereign Commitment
Mastriva (coordinating client relationship and commercial interfaces) in operational partnership with Aliph Solutions (providing sovereign technology platforms, IP, and specialist delivery) is committed to upholding the highest standards of data privacy, regulatory compliance, and sovereign information architecture.
This policy defines how personal data and enterprise information are processed, governed, and protected under the Personal Data Protection Law (PDPL) enacted by Royal Decree No. M/19 (dated 09/02/1443H) as amended by Royal Decree No. M/148 (dated 05/09/1444H), its Implementing Regulations, and the guidelines issued by the Saudi Data & Artificial Intelligence Authority (SDAIA).
2. Zero-Raw PII Sovereign Architecture
Unlike conventional SaaS or public generative AI platforms, Mastriva and Aliph Solutions operate on a strict Zero-Raw PII Sovereign Boundary principle:
Prior to any agentic reasoning, prompt analysis, or multi-ERP semantic indexing, data streams pass through an automated privacy gateway. National identification numbers, bank account IBANs, telephone numbers, and designated sensitive financial metrics are dynamically pseudonymized or masked within the customer-approved boundary.
3. Categories of Personal & Corporate Data Processed
We process only data strictly necessary for enterprise commercial engagements and contracted platform delivery:
- Commercial & Professional Contact Data: Names, corporate email addresses, enterprise titles, phone numbers, and institutional affiliations submitted via discovery or RFP requests.
- Technical Telemetry & Security Logs: Authentication metadata, role-based access timestamps, model query tokens, and administrative change logs forwarded directly to your customer SIEM/SOC.
- Corporate Knowledge & ERP Data: Governed financial, operational, and supply-chain records indexed exclusively within your designated private on-premises or sovereign cloud instance (e.g. Oracle Riyadh, Azure KSA region).
4. Legal Grounds for Processing Under KSA PDPL
In accordance with Article 5 and Article 6 of the KSA PDPL, we collect and process data on the following lawful bases:
5. Prohibition of Unauthorized Cross-Border Transfers
Under Article 29 of the KSA PDPL and the Regulation on Personal Data Transfer Outside the Geographical Boundaries of the Kingdom, Mastriva and Aliph Solutions enforce 100% In-Kingdom Data Residency by default.
Zero customer confidential data, citizen personal data, or underlying enterprise ledger records are transferred, cached, or ingested by servers outside the Kingdom of Saudi Arabia without explicit statutory approval, valid Standard Contractual Clauses (SCC), and written client executive authorization.
6. Data Subject Rights Under KSA PDPL
Individuals whose personal data is processed by Mastriva possess explicit statutory rights under Chapter IV of the PDPL:
7. Retention, Security & Cryptographic Lineage
All records are stored using AES-256 encryption at rest and TLS 1.3 in transit. In accordance with the SOM-1:2026 Organizational Memory Standard, enterprise decisions, model gate approvals, and audit workpapers maintain immutable cryptographic hashes (SHA-256) ensuring non-repudiation and complete source-to-report lineage.
8. Data Protection & CISO Contacts
For inquiries, data subject access requests (DSARs), or regulatory audits regarding KSA PDPL or SDAIA compliance: