Custom systems
Compliance is built into the system, not added after
Data protection is not a privacy page copied from another site. It is a set of technical decisions taken at build time: where the data is stored, who reaches it, how long it stays, and when it is genuinely deleted.
Implementation
What we apply inside the system itself
Technical measures, not legal wording.
Storage and access
- Hosting inside the country where required
- Encryption in storage and in transit
- Permissions at field level, not screen level
- An access log of who opened what, and when
- Test data kept separate from production data
Retention and rights
- A defined retention period per data type
- Genuine deletion afterwards, not just hiding
- Export of an individual’s data on request
- A record of consents and their dates
- A documented procedure for handling a breach
Handover
A technical file ready for your legal adviser
We implement the technical requirements and document what was built in one ordered file, so your adviser reviews it and forms an opinion on what is actually in place rather than a general description.
What the documentation file covers
Assessment
What we examine in an existing system
Three categories, in a report ordered by severity.
Who reaches what
Accounts holding wider permissions than their role needs, and accounts of people who left and were never closed.
Where the data lives
Copies sitting in files and on devices outside the system, the thing most often forgotten in any review.
What leaves to third parties
Every connected tool or service and what data it can see, because the obligation extends to whoever you share with.
Questions
About data protection
Must hosting be inside Saudi Arabia?
Do you write the privacy policy?
What about the systems we already run?
Start here
Tell us about your project
Send us two lines about what you need on WhatsApp. We reply, book a short scoping call, then send a written plan with cost and timeline before you commit to anything.