BaytyAI → Compliance
When your program spans five countries, six regulators, and three data protection laws — compliance cannot be generic.
BaytyAI's compliance architecture is designed for the regulatory reality of global mega-project delivery. Specific regulation citations. Documented obligations. Implemented controls — with roadmap items labelled honestly, not dressed up as done.
Regulatory Coverage
Every major data protection law your program operates under.
United Arab Emirates
Federal Decree-Law No. 45/2021 — Personal Data Protection Law (PDPL)
- ✓ Data controller registration with TDRA — maintained for controller activities
- ✓ Explicit consent management — per-category consent with timestamp storage
- ✓ Right to erasure within 30 days — automated deletion workflow on account closure
- ✓ 72-hour breach notification to TDRA — documented incident-response plan
European Union
Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR)
- ✓ Lawful basis documented per category (contract performance, legitimate interest)
- ✓ Standard Contractual Clauses (SCCs) for transfers outside the EEA — available on request
- ✓ Right to data portability — structured data export on written request
- ✓ EU representative designated for EU data-subject correspondence
United Kingdom
UK GDPR + Data Protection Act 2018
- ✓ UK adequacy framework applied — transfers governed by UK SCCs (IDTA) where required
- ✓ ICO registration maintained for controller activities involving UK data subjects
- ✓ Data-subject rights (access, rectification, erasure, portability) via enterprise@baytyai.com
- ✓ Privacy notices reviewed for UK-specific disclosure requirements
Kingdom of Saudi Arabia
Personal Data Protection Law — Royal Decree M/19 (PDPL)
- ✓ Saudi PDPL compliance assessment for KSA market entry (2027 Q2)
- ✓ Data residency planning for KSA programs — AWS Riyadh (2027 Q3)
- ✓ NDMO (National Data Management Office) framework incorporated
- ✓ Arabic-language privacy notices and consent forms for KSA onboarding
Singapore
Personal Data Protection Act 2012 (PDPA) — as amended 2020
- ✓ Mandatory data-breach notification — within 3 days of assessment
- ✓ Do Not Call provisions — no unsolicited marketing to Singapore numbers
- ✓ Data Protection Officer designated for Singapore operations
- ✓ PDPA advisory guidelines reviewed for construction-sector data categories
International Programs
Cross-jurisdictional frameworks for multi-national delivery programs
- ✓ Data Processing Agreement (DPA) in English and Arabic for all enterprise programs
- ✓ Sub-processor disclosure list maintained and updated quarterly
- ✓ Jurisdiction-specific consent flows configurable per program deployment
- ✓ Legal transfer mechanisms documented for all cross-border data flows
Data Processing Agreement
The legal framework for how BaytyAI processes your program's data.
BaytyAI acts in two distinct legal roles depending on the data type. For user account data and identity verification data, BaytyAI is the Data Controller. For project records, approval histories, and commercial documents created by enterprise clients, BaytyAI is the Data Processor — acting on the client's instructions as Controller.
When BaytyAI is Data Controller
- • User registration and account-management data
- • Identity verification documents (Emirates IDs, trade licences)
- • Platform usage analytics (anonymised)
- • Billing and subscription metadata
BaytyAI's Privacy Policy governs this processing. Data-subject rights are exercisable directly with BaytyAI.
When BaytyAI is Data Processor
- • Project records created by your organisation
- • Approval histories and decision records
- • Commercial documents, RFQs, and award records
- • Contractor and stakeholder data input by your team
A Data Processing Agreement is required. BaytyAI processes under your instructions as Controller. The DPA includes sub-processor disclosure and audit rights.
Audit Trail
Every decision, documented. Every record, permanent.
On mega-projects, the compliance requirement is not just that the right process was followed — it is that you can prove it. BaytyAI's audit trail is the compliance infrastructure that makes your program's decision history defensible to regulators, auditors, arbitration panels, and government oversight bodies.
Approval records
Every approval, rejection, and escalation is recorded with approving-party identity, timestamp, decision basis, and the version of documentation reviewed. Immutable.
Access history
Every access to sensitive workflows, verification documents, and restricted data is logged with user identity, organisation, timestamp, and access method.
Document version history
Every upload, revision, and supersession is recorded with uploader identity, version number, and timestamp. Current version and full history are always accessible.
Award and procurement records
Every RFQ, submission, evaluation, and award decision is recorded — with evaluation criteria, commercial values, and award rationale.
Variation and claims records
Every variation instruction, scope change, and claims submission is recorded with originating instruction, scope description, commercial value, and approval history.
Admin and access management
Every invitation, permission change, role assignment, and deactivation is logged — a complete record of who had access to what, and when.
All audit records are retained for a minimum of 7 years. Corporate-tier clients can configure extended retention to 15 years for programs with long-term liability tails. Audit records are exported in JSON and PDF formats on request.
Authority Matrix Governance
Who is authorised to decide what — enforced by the platform, not by policy.
The most common compliance failure on mega-projects is not that the wrong person made a decision — it is that the wrong person could, without the system preventing or recording it. BaytyAI enforces approval rights at the workflow level: if a party lacks authority for an action, the workflow does not offer it. Authority is explicitly configured and enforced, not assumed from role.
Payment certificate approval
Only parties with explicit payment authority in the programme's authority matrix can approve payment certificates. Approval by an unauthorised party is technically impossible — not just against policy. Every payment approval carries the approver's verified identity and the authority basis.
Variation order instruction
Only designated authority levels can formally instruct a variation order. Verbal instructions that bypass the authority matrix produce no binding record — the formal instruction must be issued through BaytyAI to trigger the variation workflow. This eliminates the 'oral instruction' dispute category.
Contractor verification approval
Verification decisions — approving or rejecting an organisation's participation — are restricted to designated verification-authority roles. No contractor, consultant, or supplier can self-approve their participation. Every decision is recorded with the approver's identity and basis.
GDPR — EU and International Programs
GDPR compliance for programs with EU-resident participants.
Many mega-programs in the GCC and internationally include EU-resident architects, engineers, and consultants. Where BaytyAI processes EU data subjects' personal data, GDPR Article 3 territorial scope applies — regardless of BaytyAI's UAE headquarters.
Lawful basis documented
Processing of EU data subjects' account and project-participation data is on the basis of contract performance (Article 6(1)(b)). Marketing communications require explicit consent (Article 6(1)(a)).
Data-subject rights mechanism
EU data subjects can exercise access, rectification, erasure, restriction, portability, and objection rights via enterprise@baytyai.com. Requests are responded to within 30 days per GDPR Article 12.
International transfer safeguards
Transfers from the EU/EEA to the UAE are governed by Standard Contractual Clauses where required. EU data is currently processed in AWS Frankfurt (EEA) — no transfer is currently required for EU users.
EU representative
An EU-based GDPR representative is designated for correspondence from EU supervisory authorities and EU data subjects. Contact details are available in the Privacy Policy.
Sub-Processors
Every third-party service that processes program data — named.
GDPR Article 28 and equivalent laws require sub-processor disclosure. The services below process BaytyAI customer data. Stripe is listed as planned — it processes data only once payment processing is activated for a program.
| Sub-processor | Purpose | Data processed | Location | Status |
|---|---|---|---|---|
| Supabase | Database, storage, authentication | All platform data | EU Frankfurt / Global | Active |
| Vercel | Hosting, CDN, edge delivery | Request metadata | Global edge / US | Active |
| Resend | Transactional email | Email addresses, notification content | US | Active |
| Anthropic | AI capabilities | Project data queries (org-scoped, not retained for training) | US | Active |
| Stripe | Payment processing | Payment data only | US / Global | Planned |
BaytyAI will notify enterprise clients of any material sub-processor change a minimum of 30 days before it takes effect, allowing clients to object or terminate per their DPA rights. A full sub-processor list with data types, locations, and legal basis is available on request.
Compliance FAQ
What legal and procurement teams ask — answered with citations.
BaytyAI is designed to comply with UAE Federal Decree-Law No. 45/2021 on Personal Data Protection. Controls include per-category consent management with timestamp storage, an automated right-to-erasure workflow (30-day deletion on account closure), and a documented 72-hour breach-notification protocol to TDRA. Data-controller registration and full compliance documentation are available to enterprise clients under NDA.
BaytyAI processes EU data subjects' personal data under GDPR Article 3 territorial scope for programs with EU-resident participants. Controls include documented lawful basis per processing category, Standard Contractual Clauses for international transfers where applicable, an EU data-subject rights mechanism (30-day response), and an EU-based representative. Current EU user data is processed in an AWS Frankfurt (EEA) region, so no cross-border transfer is currently required.
Yes. BaytyAI provides a standard Data Processing Agreement covering the controller-processor relationship, sub-processor disclosure, security measures, audit rights, breach-notification timelines, and data return/deletion on contract termination. DPAs are available in English and Arabic. Request via enterprise@baytyai.com with subject line 'DPA Request'.
Platform data is stored with our managed database provider in an AWS EU (Frankfurt) region within the EEA by default. UAE data residency (AWS Bahrain) is planned for Month 12, and Saudi Arabia data residency (AWS Riyadh) for 2027 Q3. Custom residency configurations for programs requiring single-jurisdiction isolation are available through enterprise implementation planning.
BaytyAI maintains a documented incident-response plan reviewed quarterly. On confirmation of a personal-data breach: UAE TDRA notification within 72 hours; affected enterprise clients notified within 24 hours; affected data subjects notified within 10 business days where required. Breach records are retained for 5 years.
BaytyAI is assessing full Saudi PDPL (Royal Decree M/19) compliance for KSA market entry in 2027 Q2, with Saudi data residency (AWS Riyadh) planned for 2027 Q3 to meet NDMO data-localisation preferences for government programs. Enterprise clients requiring KSA government deployment should contact enterprise@baytyai.com to discuss the implementation timeline and interim compliance arrangements.
Data subjects whose personal data BaytyAI processes have the right to access their data (copy within 30 days), correction of inaccurate data (within 15 days), erasure on account closure (within 30 days), data portability (structured export on request), and restriction of processing (within 10 days). Requests should be submitted to enterprise@baytyai.com.
Platform audit logs and verification-document access logs are retained for a minimum of 7 years from creation. Financial and transaction records are retained for 5 years in line with UAE tax-law requirements. Corporate-tier clients can configure extended retention to 15 years for programs with long-term liability tails. Personal data, as distinct from audit metadata, is deleted per the applicable retention schedule on account closure.
Your legal team has requirements. We have documentation.
BaytyAI provides Data Processing Agreements, sub-processor lists, compliance questionnaire responses, and jurisdiction-specific compliance assessments to qualified enterprise and government programs.