Operating in the Kingdom of Saudi Arabia
24/7 Emergency: +966 56 147 3672
HomeAbout
Services
Why VeltrixairIndustriesCoverageStandardsCareersRequest a QuoteCall our 24/7 deskDownload Brochure
Compliance Statement

Conformance with the Personal Data Protection Law

This is the formal PDPL conformity statement for the Veltrixair Industries BU. It maps PDPL articles to what the BU actually does with data, documents the notices we give at the point of collection, sets out how we respond to a breach, and describes how the programme is governed. It's written for legal and compliance teams to review. If you want the plain-language version, that's the Privacy Notice. Together, the two documents cover what Saudi law requires us to disclose.

Statement of Conformity

The Industries BU operates in conformance with the Saudi PDPL

The Veltrixair Industries Business Unit follows the Saudi Personal Data Protection Law, issued under Royal Decree No. M/19, along with its Implementing Regulations from the Saudi Data and Artificial Intelligence Authority (SDAIA) and any further SDAIA guidance. This document is the BU's formal compliance statement, issued by the VP — Data Protection function.

We only process personal data on a documented legal basis, keep it no longer than set out in Section 9, only send it outside the Kingdom under the legal conditions in Section 8, and honour the rights described in Section 7. If this document and the Privacy Notice ever seem to differ, the Privacy Notice is what applies to you — this document is our internal compliance reference.

We review this statement every year, and any time something meaningful changes. The version number at the top updates with every revision, and we keep a change log available on request.

KK
Khalid Khan VP — Data Protection & InfoSec Advisory
PDPL Articles at a Glance

Four articles. The structural anchors

Four parts of Saudi data protection law do most of the heavy lifting in this document: your rights, the legal bases we rely on, how we handle sensitive data, and our obligation to be transparent. Each is explained in the sections below.

04
PDPL Art. 04

Data Subject Rights

Eight rights granted to individuals — access, correction, erasure, restriction, object, portability, withdraw consent, be informed. 30-day response window.

05
PDPL Art. 05

Lawful Basis

Permitted bases for processing personal data — consent, contractual necessity, legal obligation, legitimate interests, vital interests, and prescribed purposes.

06
PDPL Art. 06

Sensitive Data

Special category data — health, biometric, ethnic origin, religious belief, political opinion, criminal record. Explicit consent required for processing.

14
PDPL Art. 14

Transparency Obligation

Requirement to inform data subjects at point of collection of identity, purpose, basis, recipients, retention, rights, complaint route. Layered notices below.

Data controller & DPO function

Veltrixair Industries, based in Riyadh, is the Data Controller for the Industries business — meaning we decide why and how personal data is processed, as described here and in the Privacy Notice.

Tarique Ahmad, who's also our Chairman and CFO, holds the role of Data Protection Officer. This function reports directly to the Chairman rather than through the commercial side of the business, which keeps it independent when handling rights requests, breach reviews, and refusals.

Operational Note

The DPO function is contactable at privacy@veltrixair.com for data subject rights requests, regulator correspondence, and any matter falling within Articles 4 and 14. Substantive correspondence is reviewed by the function personally; routine administrative correspondence may be delegated.

Regulatory framework stack

We operate under several overlapping Saudi regulations. PDPL is the main one — the others either build on it, reference it, or add related obligations on the same data.

  • PDPL — Personal Data Protection Law · Royal Decree No. M/19. The primary instrument.
  • PDPL Implementing Regulations · issued by SDAIA. Operational specifics on consent, retention, breach notification, cross-border transfers.
  • SDAIA Guidance Notes · supplementary regulatory guidance issued from time to time on specific PDPL matters.
  • ZATCA Fatoora Phase 2 · e-invoicing regulations, governing the financial data category.
  • Saudi Labour Law · workforce records, end-of-service gratuity, and employment data retention obligations.
  • HCIS site access protocols · access logs and permit-to-work records on petrochemical complex sites.
  • NCA Essential Cybersecurity Controls (ECC) · adopted as the supplementary security control framework over personal data.
  • ISO/IEC 27001 · adopted as a best-practice baseline for the information security management system supporting personal data processing.

Where two regulations overlap — for example PDPL's retention rules and ZATCA's mandatory record-keeping period — we follow whichever requires the longer retention, while still limiting who can access the data to only those who need it for its original purpose.

Lawful basis map

Saudi data protection law sets out the legal grounds for processing personal data. The table below matches each of our activities to its legal basis — nothing we do is undocumented.

Processing Activity
Lawful Basis
Notes
Quote & enquiry processing
Contractual
Pre-contractual steps under Article 5 — necessary to respond to the data subject's request for a quote.
Engagement delivery
Contractual
AMC contracts, project delivery, site visit coordination — necessary for performance of the contract with the client.
Inspection certificates
Legal Obligation
SASO inspection certificate retention requirements; ISO 9927 thorough examination records.
Workforce records
Legal Obligation
Saudi Labour Law payroll, Iqama, end-of-service gratuity audit defence, GOSI obligations.
Site access logs
Legitimate Int.
HCIS-mandated where applicable; otherwise legitimate interest in HSE, with balancing test documented.
ZATCA e-invoicing
Legal Obligation
Fatoora Phase 2 e-invoicing requirements. Retention per ZATCA regulatory minimum.
Newsletter subscriptions
Consent
Article 5 consent — granular, freely given, withdrawable. One-click unsubscribe in every issue.
HSE incident processing
Vital Interest
Where processing health information may be necessary to protect life. Narrow application; documented per incident.
Web analytics (pseudonymised)
Consent
Cookie consent banner. Pseudonymised IP, browser, referrer; never tied to identifiable individuals.

Sensitive data handling

Saudi law sets extra requirements for sensitive personal data — things like health information, biometric data, ethnicity, religion, political views, union membership, or criminal record. We can only process this kind of data with explicit consent, or under another basis specifically allowed by the regulations.

We don't normally process sensitive personal data. Our everyday work — quotes, engagement records, site photos, financial records, workforce admin — doesn't need it. Where an exception comes up, it's handled the way described below.

  • HSE incident health information · Where a workplace incident or near-miss requires processing of health-related information, the data is collected on the explicit basis of vital interests under PDPL Article 5, retained under elevated controls (encrypted, role-restricted access), and is the subject of a documented incident-specific processing record.
  • CCHI medical insurance administration · Workforce health insurance administration is handled by the CCHI-licensed insurer as a separate Controller under their own Article 6 basis. Veltrixair Industries acts only as a transmission point for enrolment data.
  • Biometric site access · Where a client site (Aramco, SABIC, HCIS-regulated complex) operates biometric access, the client is the Controller for that processing. Veltrixair Industries’ role is limited to facilitating its workforce's enrolment under the client's framework.

We never process the other categories of sensitive data — ethnicity, religion, political views, union membership, or criminal record — under any circumstance.

Transparency obligation

Saudi law requires us to be upfront at the moment we collect your data — who we are, why we're collecting it, our legal basis, who might see it, how long we'll keep it, your rights, and how to complain if needed.

We do this in layers: the full legal detail sits here, the plain-language version is the Privacy Notice, and short notices appear right at the point of collection — on forms, in confirmation emails, and spoken aloud during site visits where photos are taken.

Layered Notice Architecture

These three layers work together — this document and the Privacy Notice are always accessible from the footer, the shorter notices appear right when you're submitting something, and confirmations are sent after. Each layer links to the others, and each one gives you enough information on its own.

Layered notice — point of collection

The cards below show, in short form, exactly what you're told when you submit each of our main forms. Each one gives you everything you need without reading the full Privacy Notice — though the link to it is always there.

Quote Form · VTX-RFQ
Request a quote
Controller
Veltrixair Industries, Riyadh KSA
Purpose
Process your enquiry, prepare a quote, route to the assigned engineering lead.
Basis
Contractual necessity (PDPL Art 5).
Retention
12 months unless an engagement results, in which case engagement-record retention applies.
Recipients
Internal engineering & commercial teams; no third parties.
DPO
privacy@veltrixair.com
Site Visit Form · VTX-VST
Request a site visit
Controller
Veltrixair Industries, Riyadh KSA
Purpose
Co-ordinate the site visit, schedule the engineer, prepare the assessment.
Basis
Contractual necessity (PDPL Art 5).
Retention
12 months for the visit record; site imagery retained 5+ years for asset history.
Recipients
Internal engineering team; client site as required for access coordination.
DPO
privacy@veltrixair.com
Careers Form · VTX-HR
Career application
Controller
Veltrixair Industries, Riyadh KSA
Purpose
Assess the application, route to the recruitment lead, maintain a candidate pipeline.
Basis
Pre-contractual / consent (PDPL Art 5).
Retention
12 months for unsuccessful or pipeline candidates; converted on hire to workforce records.
Recipients
Internal HR team and the hiring manager for the relevant track.
DPO
privacy@veltrixair.com
Newsletter · Quarterly
Newsletter subscription
Controller
Veltrixair Industries, Riyadh KSA
Purpose
Send the quarterly newsletter (max four emails per year). Nothing else.
Basis
Consent (PDPL Art 5) — granular, freely given, withdrawable.
Retention
Until you unsubscribe. One-click unsubscribe in every issue.
Recipients
Email service provider only — bound by data processing agreement.
DPO
privacy@veltrixair.com
Site visit imagery — verbal notice

When we capture data on site — photos of equipment condition, occasional videos of faults — the lead engineer tells you verbally at the start of the visit, and it's confirmed in writing afterward. If anyone appears in the shot by accident, we blur them out before using it externally.

Data subject rights workflow

Saudi law gives you eight rights over your personal data. The Privacy Notice explains them in plain terms. This section documents how we actually process a request internally — so these rights are real, not just words on a page.

  • T+5 working days · Acknowledgement. Receipt of the request is acknowledged with a reference number routed to the requesting data subject. Initial routing to the DPO function is automatic.
  • T+12 days · Identity verification. Where the request relates to specific personal data, the requester's identity is verified through proportionate means (existing relationship reference, ID document, secondary contact channel).
  • T+30 days · Substantive response. Per Article 4, substantive response is delivered within thirty days of verified receipt. Complex requests may invoke a documented extension under the Implementing Regulations, with notification to the requester.
  • Refusal grounds. Where a request is refused — for example, retention obligations under Saudi Labour Law preventing erasure — the refusal is documented with reference to the lawful basis. The DPO function reviews refusals before issue.
  • External escalation. Every response includes the route to escalate to SDAIA as the Competent Authority, where the requester is dissatisfied with the BU's response.

Send requests to privacy@veltrixair.com. Standard requests are free; only clearly unreasonable or excessive requests might carry a fee, as allowed under the regulations.

Cross-border transfers

Saudi law governs how we can send personal data outside the Kingdom. Our default is to keep data inside Saudi Arabia — Saudi-based cloud infrastructure, Saudi-based servers, and Saudi-based processing wherever possible.

When data does need to leave — for example, routing technical support through a European vendor, or overflow cloud capacity — that transfer is documented in an assessment maintained by our Data Protection Officer.

  • Lawful basis. Each transfer is mapped to a permitted basis under Article 29 — adequacy where SDAIA-recognised, contractual necessity for engagement-critical transfers, or explicit consent for non-essential transfers.
  • Recipient assessment. Recipient jurisdiction's data protection regime is assessed. Where adequacy is not established, additional contractual safeguards are imposed via DPA.
  • Technical safeguards. Transit encryption (TLS), at-rest encryption (AES-256), access controls (role-based), audit logging (centralised). Personal data in transit is never sent unencrypted.
  • India operations bilateral. Veltrixair Industries operations in India support the Industries BU's back-office functions. Transfers India-bound are governed by both PDPL Art 29 and the India Digital Personal Data Protection Act 2023, with the bilateral DPA framework documented and reviewed annually.

If data needs to move again after it's already left the Kingdom — from one foreign country to another — that requires separate approval. It's not allowed by default.

Retention schedule

Saudi law says we can only keep personal data as long as we actually need it. Our full retention schedule is in the Privacy Notice. This section explains the process behind it.

  • Quarterly retention review. The DPO function reviews the retention schedule quarterly. Records past their retention period are flagged for the responsible function (HR for workforce, Finance for ZATCA, BU Operations for engagement records) for action.
  • Documented destruction. Records reaching end-of-retention are destroyed via documented destruction workflows. Destruction certificates are retained for audit trail purposes; the certificates themselves are not personal data.
  • Anonymisation alternative. Where data has continued analytical value but no continuing personal-data purpose, irreversible anonymisation is preferred over deletion. Anonymised aggregates are retained outside the personal-data control regime.
  • Statutory minimums prevail. Where Saudi statutory law mandates a minimum retention period (Saudi Labour Law for workforce, ZATCA for invoicing, SASO for inspection certificates), the statutory minimum prevails over the BU's operational preference for shorter retention.

Breach response framework

Saudi regulations require us to notify the data protection authority within 72 hours of discovering a breach likely to cause harm. Our internal process is built to catch breaches early, contain them fast, assess them properly, and notify on time.

T+0 hr
Detection & internal notification

Detection by any source — internal monitoring, employee report, vendor notification, regulator inquiry. CISO and DPO function notified within one hour.

T+1 hr
Initial classification

Preliminary assessment of severity, scope, and the lawful processing affected. Triage decision: contained incident vs reportable breach.

T+4 hr
Containment actions

Containment measures applied — credential rotation, system isolation, access revocation, log preservation. Preliminary incident report logged.

T+24 hr
Severity assessment finalised

Severity assessment finalised; data subjects affected identified and counted; notification threshold under the IR evaluated; communications plan drafted.

T+72 hr
SDAIA notification

Where the breach meets the notification threshold, SDAIA is notified within the 72-hour window per the Implementing Regulations. Notification is comprehensive — nature, scope, mitigation, contact.

T+30 days
Affected data subject notification

Where individual notification is required, affected data subjects are notified directly with a description of the breach, the data affected, the remedial actions taken, and their rights.

+14 days
Post-incident review

Within 14 days of full resolution, the DPO function leads a documented post-incident review — root cause, control gaps, remediation actions, lessons learned, and updates to this notice if material.

Programme governance

A privacy programme that only exists on paper doesn't actually meet the requirements. Ours runs on six real, ongoing practices, each with a schedule, an owner, and a clear output.

1
Privacy Impact Assessments

Annual review of existing processing activities. PIA on every new processing activity before go-live. Outputs are version-controlled documents in the BU's governance library.

2
Internal audit cadence

Quarterly internal audit of the BU's PDPL conformity, conducted by the Privacy Advisory practice acting as second-line. Findings are tracked to closure.

3
Workforce training

Mandatory PDPL training on hire; annual refresh thereafter. Completion is tracked at individual level. Engineers handling site imagery receive additional contextual training.

4
Vendor DPAs

Every processor handling personal data on the BU's behalf is bound by a Data Processing Agreement. DPAs are reviewed annually; new vendors are onboarded only with DPA in place.

5
DPO independence

The DPO function reports directly to the Chairman, outside the commercial chain. Refusals of data subject rights requests are reviewed by the function before issue. Independence preserved structurally.

6
Continuous improvement

Material findings from audits or incidents trigger review of this notice and the Privacy Notice. Material updates are communicated; minor corrections are tracked in the change log.

Document control & updates

This document is version-controlled. Material changes — to processing activities, to the regulatory framework, to the lawful basis map, to the breach response framework — trigger a new version. The version reference at the top of this document is incremented; a change log is maintained internally and made available on legitimate request.

Document control register

Reference
VTX-PDPL-001
Version
v1.0 · Q1 2026
Issue date
Q1 2026
Issuing authority
VP — Data Protection & InfoSec Advisory
Approval
Khalid Khan, Chairman & CFO + VP DP
Review cycle
Annual + on material change
Languages
English (authoritative) · Arabic available on request
Change log
Maintained internally · available on legitimate request to the DPO function

If the Arabic and English versions ever differ, the English version is the one that applies — that's our standard operating language for governance documents. If you spot a translation issue, let our Data Protection team know.