David Sánchez de Groeve
Regulatory Compliance · KSA PDPL

Privacy Policy

Personal Data Protection Notice issued in accordance with the Kingdom of Saudi Arabia Personal Data Protection Law (PDPL, Royal Decree No. M/19) and the regulations of the Saudi Data and AI Authority (SDAIA).

1. Data Controller Statement

1. Legal Framework & Controller Status

This Privacy Policy governs the processing of personal data collected through davidgroeve.com. The platform is operated by David Sánchez de Groeve in a personal and professional capacity as an independent Director of IT Operations & Infrastructure and Technology Consultant based in Riyadh, Kingdom of Saudi Arabia. All processing strictly adheres to the Saudi Personal Data Protection Law (PDPL) issued under Royal Decree No. M/19, its Executive Regulations enforced by SDAIA, and applicable guidelines from CST and DGA.

2. Zero-Tracking & Cookie Governance

2. Cookie Policy & Privacy-by-Design (Zero Third-Party Trackers)

In accordance with PDPL Article 21 and international privacy-by-design standards:

  • No Advertising Trackers: This website does not deploy third-party advertising cookies, behavioral tracking pixels, or cross-site analytics scripts.
  • Strictly Necessary Storage: We use minimal local storage purely for essential functions (such as authenticated portal sessions and transmission buffering).
  • No Commercial Monetization of Data: Personal details submitted via the portal or "Tell me something" transmission are never sold, rented, or shared with third-party data brokers.
3. Data Collection & Processing

3. Categories of Personal Data Collected

We process only data strictly necessary for professional consultation, executive inquiries, and portal access:

  • Inbound Inquiries: Voluntary contact details (email address, phone number, note content) transmitted via the direct communication channels.
  • Portal Credentials: Authenticated account data secured via encrypted tokenization (Supabase Infrastructure).
  • Security & Diagnostics: Anonymized server access logs for cybersecurity auditing and denial-of-service protection.
4. Data Sovereignty & Cross-Border Transfers

4. Sovereign Localization & SDAIA Transfer Rules

In alignment with national cloud security standards (NCA ECC-1:2018) and SAMA cybersecurity principles, primary data storage adheres to in-Kingdom residency. Any auxiliary global routing adheres strictly to the SDAIA Regulation on Personal Data Transfers Outside the Kingdom and Standard Contractual Clauses (SCCs).

5. Rights of Data Subjects

5. Your Rights under KSA PDPL

Under Article 4 of the Saudi PDPL, data subjects hold the following enforceable rights:

  • Right to Know: To be informed of the purpose and legal basis for processing.
  • Right of Access: To request a copy of personal information held in our records.
  • Right to Rectification: To update or correct inaccurate or incomplete data.
  • Right to Destruction (Erasure): To request deletion of stored inquiries or account records.
  • Right to Withdraw Consent: To withdraw processing consent at any time without retroactive penalty.
6. Cybersecurity Standards

6. Technical Safeguards (NCA ECC Baseline)

We maintain technical safeguards aligned with NCA Essential Cybersecurity Controls (ECC-1:2018), including TLS 1.3 in transit, AES-256 at rest, strict least-privilege access control, and automated cryptographic erasure when data retention periods expire.

7. Data Protection Point of Contact

7. Data Subject Requests & Inquiries

To exercise your statutory PDPL rights or submit a data protection inquiry, please contact:

Direct Inquiries: director@davidgroeve.com
Location: Riyadh, Kingdom of Saudi Arabia