Your data, under your control.
Built on the requirements of the Personal Data Protection Law across every data path — full per-company isolation, access control, and an audit log for every operation.
PDPL-aligned architecture
Every connection is encrypted with TLS 1.3, passwords are hashed and never stored, and integration keys are held sealed.
What does the regulation require?
- Processing personal data on a lawful basis and for a specified purpose.
- Protecting data with appropriate technical and organizational controls.
- Respecting the data subject's rights (informed, access, correction, destruction).
- Meeting the requirements for the place of processing and transfer outside the Kingdom.
How did we implement it?
- Full per-company isolation — each customer has its own secure workspace.
- Password hashing and role-based access control.
- An audit log for every sensitive operation.
- Per-organization isolation enforced by the database itself, sealed storage for credentials and integration keys, and an audit trail for every action. The platform's servers are hosted with Hetzner Online GmbH in Germany — full detail in the Privacy Policy.
The Personal Data Protection Law (PDPL) is issued by the competent authorities in the Kingdom; Devetrust complies with its requirements and is not a regulatory body.
Questions about data protection
How is our organization's data isolated?
Every company gets a secure, isolated workspace; its data is never mixed with another's, and every action is logged for audit — full isolation between customers.
How is the data protected in practice?
In layers, so no single failure exposes anything. The server refuses every incoming connection except the few published ports; everything else is closed by default. Traffic is encrypted with TLS 1.3 and AES-256. Who you are is checked twice on every request — once at the web layer, then again by the service itself, which never trusts the layer in front of it. Permissions are checked against your role before anything runs. Each organization's data is walled off by the database itself, so even a flawed query cannot reach another organization's records. Every change is written to an audit trail. And if a security check cannot run for any reason, the request is refused rather than let through.
What are my rights under the law?
You have the right to be informed of processing, access your data, request correction or destruction, and withdraw consent — see the Privacy Policy.
How do you protect passwords?
Passwords are stored hashed with a secure one-way algorithm — never reversibly encrypted — with role-based access and granular permissions.
How long is our data kept?
We state the windows as they are: raw position fixes from the device are kept for 90 days, then deleted automatically. What is derived from them lasts longer — trip records are not on an automatic deletion schedule, geofence events are kept 24 months, WASL submission logs 365 days, and the audit trail 36 months. That is what matters in practice: in a regulatory dispute or an insurance claim months later, what is needed is the trip record and the audit trail, not the raw fix.
Your fleet deserves this clarity.
Start with a demo on real data from the platform itself — we reply within one business day.
