Mastriva
Regulatory & Sovereign Policy

Enterprise Privacy Policy

Jurisdiction: Kingdom of Saudi Arabia (KSA) • Regulator: SDAIA (Saudi Data & AI Authority) • Standard: SOM-1:2026

Public website scope

This public marketing website is hosted in Singapore. It is separate from customer-controlled enterprise deployments described below. Hosting is not evidence of Saudi data residency for this website.

Inquiry forms prepare drafts locally in your browser; they do not submit, store, or confirm receipt of your details. Sending a draft uses your chosen email provider. Please do not enter sensitive or confidential information. The illustrative demo and readiness assessment run locally and are not connected to customer systems.

Fonts, icons, and website scripts are served locally. No analytics, advertising trackers, or account cookies are configured. Web-server operational logs may record connection metadata such as IP address and requested URL; inquiry fields are not included.

1. Purpose and Sovereign Commitment

Mastriva (coordinating client relationship and commercial interfaces) in operational partnership with Aliph Solutions (providing sovereign technology platforms, IP, and specialist delivery) is committed to upholding the highest standards of data privacy, regulatory compliance, and sovereign information architecture.

This policy defines how personal data and enterprise information are processed, governed, and protected under the Personal Data Protection Law (PDPL) enacted by Royal Decree No. M/19 (dated 09/02/1443H) as amended by Royal Decree No. M/148 (dated 05/09/1444H), its Implementing Regulations, and the guidelines issued by the Saudi Data & Artificial Intelligence Authority (SDAIA).

2. Zero-Raw PII Sovereign Architecture

Unlike conventional SaaS or public generative AI platforms, Mastriva and Aliph Solutions operate on a strict Zero-Raw PII Sovereign Boundary principle:

Aliph Guard Heuristic Gateway

Prior to any agentic reasoning, prompt analysis, or multi-ERP semantic indexing, data streams pass through an automated privacy gateway. National identification numbers, bank account IBANs, telephone numbers, and designated sensitive financial metrics are dynamically pseudonymized or masked within the customer-approved boundary.

3. Categories of Personal & Corporate Data Processed

We process only data strictly necessary for enterprise commercial engagements and contracted platform delivery:

  • Commercial & Professional Contact Data: Names, corporate email addresses, enterprise titles, phone numbers, and institutional affiliations submitted via discovery or RFP requests.
  • Technical Telemetry & Security Logs: Authentication metadata, role-based access timestamps, model query tokens, and administrative change logs forwarded directly to your customer SIEM/SOC.
  • Corporate Knowledge & ERP Data: Governed financial, operational, and supply-chain records indexed exclusively within your designated private on-premises or sovereign cloud instance (e.g. Oracle Riyadh, Azure KSA region).

4. Legal Grounds for Processing Under KSA PDPL

In accordance with Article 5 and Article 6 of the KSA PDPL, we collect and process data on the following lawful bases:

Contractual Necessity (Art. 6): Processing required to coordinate commercial interfaces, execute discovery sessions, and deliver contracted platform services.
Statutory Compliance (Art. 6): Adherence to SAMA Cybersecurity Framework, National Cybersecurity Authority (NCA) directives, and tax/commercial laws.

5. Prohibition of Unauthorized Cross-Border Transfers

Under Article 29 of the KSA PDPL and the Regulation on Personal Data Transfer Outside the Geographical Boundaries of the Kingdom, Mastriva and Aliph Solutions enforce 100% In-Kingdom Data Residency by default.

Zero customer confidential data, citizen personal data, or underlying enterprise ledger records are transferred, cached, or ingested by servers outside the Kingdom of Saudi Arabia without explicit statutory approval, valid Standard Contractual Clauses (SCC), and written client executive authorization.

6. Data Subject Rights Under KSA PDPL

Individuals whose personal data is processed by Mastriva possess explicit statutory rights under Chapter IV of the PDPL:

Right to Know & Access: The right to be informed of the legal basis, purpose, and recipients of data, and to request a copy of held records.
Right to Correction & Destruction: The right to request rectification of inaccurate records or cryptographic erasure when data is no longer necessary.
Right to Revoke Consent: The right to withdraw consent for voluntary communications at any time.

7. Retention, Security & Cryptographic Lineage

All records are stored using AES-256 encryption at rest and TLS 1.3 in transit. In accordance with the SOM-1:2026 Organizational Memory Standard, enterprise decisions, model gate approvals, and audit workpapers maintain immutable cryptographic hashes (SHA-256) ensuring non-repudiation and complete source-to-report lineage.

8. Data Protection & CISO Contacts

For inquiries, data subject access requests (DSARs), or regulatory audits regarding KSA PDPL or SDAIA compliance:

Data Protection & CISO: Office of Data Protection & Information Security
Corporate Address: Riyadh, Kingdom of Saudi Arabia