Standard contractual safeguards for your data.
Last Updated: June 1, 2026
Standard SDAIA SCCs fully integrated.
Compliant for international operations.
Defines key terms including 'Personal Data', 'Processing', 'Controller', 'Processor', and 'Sub-processor' in alignment with Saudi PDPL and GDPR.
Specifies that Altaius processes data solely to provide the Altaius OS platform and SI services as instructed by the Client.
Altaius commits to strict confidentiality, security measures, and assistance with Data Subject Requests (DSRs).
Detailed description of encryption, access controls, audit logging, and vulnerability management implemented by Altaius.
Rules for engaging third-party providers, including the requirement for back-to-back contractual protections.
Standard contractual clauses and safeguards for transfers outside the Kingdom of Saudi Arabia, ensuring legal compliance.
Commitment to notify the Client of any confirmed personal data breach without undue delay (typically within 24-72 hours).
Mechanisms for the Client to verify Altaius compliance through reports, certifications, or independent audits.
Allocation of risk and responsibility between parties in the event of non-compliance or data protection incidents.
Procedures for the secure return or certified deletion of all Client data upon termination of the service agreement.
We understand that large enterprises and public-sector organizations may require specific riders or variations.
Contact Data Privacy Officer
Inquiries or complaints regarding data processing may be directed to SDAIA or your local authority.
Aligned with Saudi PDPL, designed with NCA ECC controls in mind, and respects international frameworks (GDPR/CPRA).