Custom systems

Compliance is built into the system, not added after

Data protection is not a privacy page copied from another site. It is a set of technical decisions taken at build time: where the data is stored, who reaches it, how long it stays, and when it is genuinely deleted.

Implementation

What we apply inside the system itself

Technical measures, not legal wording.

Storage and access

  • Hosting inside the country where required
  • Encryption in storage and in transit
  • Permissions at field level, not screen level
  • An access log of who opened what, and when
  • Test data kept separate from production data

Retention and rights

  • A defined retention period per data type
  • Genuine deletion afterwards, not just hiding
  • Export of an individual’s data on request
  • A record of consents and their dates
  • A documented procedure for handling a breach

Handover

A technical file ready for your legal adviser

We implement the technical requirements and document what was built in one ordered file, so your adviser reviews it and forms an opinion on what is actually in place rather than a general description.

What the documentation file covers

A description of the data types stored
The hosting location and its provider
The permission matrix as implemented
The retention periods actually applied
A list of connected third parties
The procedure for individual data requests

Assessment

What we examine in an existing system

Three categories, in a report ordered by severity.

Who reaches what

Accounts holding wider permissions than their role needs, and accounts of people who left and were never closed.

Where the data lives

Copies sitting in files and on devices outside the system, the thing most often forgotten in any review.

What leaves to third parties

Every connected tool or service and what data it can see, because the obligation extends to whoever you share with.

Questions

About data protection

Must hosting be inside Saudi Arabia?
It depends on the data type and your regulator. We design the system so the hosting location can change without a rebuild, so the decision is not final from day one.
Do you write the privacy policy?
We write the precise technical description of what the system actually does, and your adviser turns it into legal wording. The worst privacy policies are the copied ones describing somebody else’s system.
What about the systems we already run?
We review them and produce a gap list ordered by severity, implement what can be fixed within the current platform, and set out plainly what needs a deeper change.

Start here

Tell us about your project

Send us two lines about what you need on WhatsApp. We reply, book a short scoping call, then send a written plan with cost and timeline before you commit to anything.