PINAVIAAI governance and execution
Back to Pinavia

Compliance

Compliance

GCC and Pakistan regulatory frameworks and the processing commitments Pinavia makes to every pilot workspace.

Effective 2026-08-06Draft — under legal review

This statement is a complete draft prepared for legal review. It describes the frameworks and commitments Pinavia operates under today. If your procurement process requires a counsel-approved compliance statement or a signed DPA before onboarding, request them at hello@pinavia.io.

Pakistan — Personal Data Protection Law (PDPL) 2023

Pinavia processes personal data under the authority of the data controller (the pilot workspace owner). Traffic is served over TLS. Workspace data and original files are encrypted at rest by the managed database and object storage platforms. Connector credentials are additionally encrypted by Pinavia (AES-256-GCM) before they are stored.

Where personal data is transferred across borders, the safeguards that apply are set out in the data processing agreement for the workspace.

United Arab Emirates — Federal Decree-Law No. 45 of 2021 (PDPL)

Pinavia FZCO is a Dubai-registered entity. Data processing complies with UAE PDPL requirements for consent, purpose limitation, and data subject rights.

Controller-processor relationship: the pilot workspace owner is the controller; Pinavia is the processor. A Data Processing Agreement template is available for signed pilot contracts.

Kingdom of Saudi Arabia — SAMA Cybersecurity Framework / NCA Essential Cybersecurity Controls

For KSA-regulated financial institutions, Pinavia supports evidence-bounded governance workflows that align with SAMA's cybersecurity maturity model and NCA-ECC controls. The audit trail, approval chain enforcement, and evidence provenance match regulatory expectations for board-level technology governance.

Pinavia does not hold a SAMA licence and does not provide regulated financial services. It is a governance technology platform used by licensed entities under their own regulatory umbrella.

Processing commitments

What Pinavia commits to for every pilot workspace:

  • Hosting locations — listed with the subprocessor list, which is provided with our data processing agreement on request.
  • Retention and deletion — workspace owners control retention. Evidence and agent outputs can be deleted at any time. On workspace closure or written request, workspace records are deleted from the production database within 30 days. Original files are held in object storage under a fixed retention lock and are removed when that period ends. Backup copies are never edited by Pinavia and are retained under the backup bucket's retention settings. Audit records needed to evidence that a deletion took place are kept in a minimised form with no customer content.
  • Breach response — affected workspace owners are notified within 72 hours of a confirmed breach, with a detailed incident report covering root cause, affected data, and remediation.
  • Subprocessors — a full subprocessor list is provided with our data processing agreement on request. No customer data is used to train third-party models.
  • Data Processing Agreement — a DPA template is available for signed pilot contracts, covering controller-processor roles, data categories, processing purposes, subprocessor notification, data subject rights, and cross-border transfer safeguards.

Contact

For compliance enquiries and DPA requests write to hello@pinavia.io. For security disclosures write to security@pinavia.io. Pinavia FZCO, Dubai, UAE.

Compliance | Pinavia