PINAVIAPinaviaAI governance and execution

Compliance

GCC and Pakistan regulatory frameworks, data residency, and processing commitments.

Regional Frameworks

PakistanPersonal Data Protection Law (PDPL) 2023

Pinavia processes personal data under the authority of the data controller (the pilot workspace owner). All customer data is encrypted at rest (AES-256-GCM) and in transit (TLS 1.3). Data is hosted on Neon Postgres (ap-southeast-1, Singapore) with Cloudflare R2 for file storage.

Cross-border transfer is supported because the data controller is based in Pakistan and processing infrastructure is in Singapore — a jurisdiction with adequate data protection standards under PDPL.

United Arab EmiratesFederal Decree-Law No. 45 of 2021 (PDPL)

Pinavia FZCO is a Dubai-registered entity. Data processing complies with UAE PDPL requirements for consent, purpose limitation, and data subject rights. The platform supports data localization through regional Neon deployment.

Controller-processor relationship: the pilot workspace owner is the controller; Pinavia is the processor. A Data Processing Agreement template is available for signed pilot contracts.

Kingdom of Saudi ArabiaSAMA Cybersecurity Framework / NCA Essential Cybersecurity Controls

For KSA-regulated financial institutions, Pinavia supports evidence-bounded governance workflows that align with SAMA's cybersecurity maturity model and NCA-ECC controls. The platform's audit trail, approval chain enforcement, and evidence provenance match regulatory expectations for board-level technology governance.

Pinavia does not hold a SAMA license and does not provide regulated financial services. It is a governance technology platform used by licensed entities under their own regulatory umbrella.

Processing Commitments

Data Residency

All customer data is hosted on Neon Postgres in Singapore (ap-southeast-1). File storage uses Cloudflare R2. No customer data is stored in the United States or European Union unless explicitly configured.

Retention & Deletion

Workspace owners control data retention. Evidence and agent outputs can be deleted at any time. On workspace closure, all data is permanently deleted within 30 days. Backups are retained for 30 days (Neon point-in-time recovery).

Breach Response

In the event of a data breach, Pinavia will notify affected workspace owners within 72 hours of confirmation. A detailed incident report will be provided including root cause, affected data, and remediation steps. Contact security@nexusai.io for security disclosures.

Subprocessors

Pinavia uses the following subprocessors: Neon (database), Cloudflare (R2 storage, CDN), Clerk (identity), Anthropic/DeepSeek (LLM), Sentry (error monitoring), Plausible (analytics), Resend (email). No customer data is used to train third-party models.

Data Processing Agreement

A DPA template is available for signed pilot contracts. It covers controller-processor roles, data categories, processing purposes, subprocessor notification, data subject rights, and cross-border transfer safeguards. Contact hello@pinavia.io for a copy.

For compliance inquiries, DPA requests, or security disclosures: security@nexusai.io

Pinavia FZCO · Dubai, UAE · Last updated August 2026

Compliance — Pinavia