PDPL notice.
This page summarizes how MIQAS complies with the Kingdom of Saudi Arabia's Personal Data Protection Law (PDPL, Royal Decree M/19/1443) and its Implementing Regulation.
Data controller
Ensign Establishment for Advertising · Commercial Registration on file · Riyadh, Saudi Arabia · contact@ensignksa.com.
Lawful basis for processing
We rely on the following PDPL lawful bases:
- Contract — to provide the MIQAS Service to your workspace under our Terms.
- Legitimate interest— for fraud prevention, security, and aggregate product analytics that don't involve advertising.
- Consent — for non-essential cookies and any optional analytics features. You can withdraw consent at any time.
- Legal obligation — to comply with KSA tax, financial reporting, and law-enforcement requirements where applicable.
Cross-border transfers
Workspace data is currently stored on Supabase infrastructure in the EU-Central (Frankfurt) region, and some processors (Vercel, Resend, Paymob) operate outside the Kingdom. Because SDAIA has not yet published a list of countries with an "adequate level of protection," we rely on the appropriate-safeguards route under Article 29 of the PDPL and the Regulation on Personal Data Transfer Outside the Kingdom: SDAIA-approved Standard Contractual Clauses (or Binding Common Rules for intra-group transfers), a transfer-risk assessment for continuous or large-scale processing, and a purpose that serves the operation of the Service you subscribe to. We only transfer the personal data needed to run MIQAS, and never to a standard lower than the PDPL requires.
Data subject rights
KSA residents whose personal data is processed by MIQAS have the following rights under PDPL Article 4:
- Right to be informed
- Right of access
- Right to request correction, completion, or updating
- Right to request destruction (subject to retention obligations)
- Right to obtain a copy of your data in a readable and clear format
Two of these are self-serve inside the dashboard: from Settings → Privacy & your data you can download a full copy of your workspace data and request its permanent deletion. For any other request, write to contact@ensignksa.com identifying which workspace it relates to. We respond within the 30-day window required by PDPL (extendable by a further 30 days for complex requests).
Personal data breach notification
If a personal-data breach occurs, we notify SDAIA through the National Data Governance Platform within 72 hours of becoming aware of it, and we notify affected data subjects without undue delay where the breach may cause harm to their data or interests. PDPL applies no size threshold, so breaches are assessed and reported regardless of scale.
Direct marketing
We only send you marketing or awareness messages with your prior consent, and every such message carries an easy opt-out, as required by PDPL Article 25 and the CST Anti-Spam Regulation. Transactional emails (billing, security, and the reports you switch on) are part of the Service and are not marketing.
Complaints
If you believe your rights under PDPL have not been respected, you may lodge a complaint with the Saudi Data & AI Authority (SDAIA).
Cookies and tracking
MIQAS uses strictly necessary cookies for session management. Optional analytics cookies are off by default and only enabled if you accept via the cookie consent banner. We do not use third-party advertising cookies on the MIQAS domain.
Updates
This Notice is reviewed at least annually and whenever there is a material change to our processing activities.