Trust

Trust and compliance

Two laws touch a Saudi customer sending personal data to Ghaym: Jordan's, because that is where the data rests and where we operate, and Saudi Arabia's, because that is where the data comes from. This page says what each one puts on whom, and hands you the documents rather than summarising them.

2 September 2026

Jordan — where your data actually is

Ghaym operates from Jordan, so Jordan's Personal Data Protection Law No. 24 of 2023 governs our processing regardless of where you sit. Ghaym accounts and what customers put in the Service are stored and processed in Jordan, and do not leave the country for hosting. Whoever runs the infrastructure beneath them is named in the data processing agreement below.

Customer secrets and environment variables are sealed at rest with AES-256-GCM under a master key held by the platform, traffic is encrypted in transit with TLS, and administrative access to the servers is limited to the people who run the platform.

For your account with us — your name, your email and your billing — we are the controller. We decide what is collected and why, and Jordan's law puts those duties on us. For what you deploy on Ghaym Cloud — your application, your database, the personal data of your users inside them — you are the controller and we are the processor. You decide what is collected and why; we run the infrastructure it sits on. That split is written down: the data processing agreement below sets it out clause by clause, and the privacy policy on this site states it to your users as well as to you.

Saudi Arabia — what you have to do before sending data here

If Saudi Arabia's Personal Data Protection Law applies to you, sending personal data to a processor outside the Kingdom is your decision to justify, not ours. The law puts the duty on the controller: you need a lawful route for the transfer, and under the transfer regulation you have to assess the risk before the data moves. We cannot do either for you.

What we can do is make the assessment possible. The data processing agreement below carries the official SDAIA Standard Contractual Clauses — the Second Template, controller to processor — attached unmodified, because the clauses themselves may not be edited. Appendix 1 is completed on signature, the Controller writes the description of its data in Appendix 2, and the security-measures appendix is complete in the agreement. Schedule 3 names the one sub-processor the data passes through and where it processes.

Workloads you run on the Service may not contain personal data of residents of the Kingdom of Saudi Arabia, and keeping that data off the Service is your responsibility, because we do not inspect what you store. Hosting in a Saudi region is available on request at info@ghaym.me.

The documents

Markdown, so you can diff it against the next revision and see exactly what moved. The Arabic text is the authoritative one; the English is a translation of it.

  • Data processing agreement

    The Jordan-law processor agreement, plus the Saudi annex carrying the SDAIA Standard Contractual Clauses and their three appendices, and the security-measures schedule describing what runs. It is governed by the laws of the Hashemite Kingdom of Jordan, and the competent civil courts of Amman have exclusive jurisdiction over disputes arising from it. This is the authoritative text.

    MarkdownArabic

    Read the document
  • Data processing agreement — English translation

    An English translation of the agreement, clause for clause. Where the two texts differ, the Arabic text governs.

    MarkdownEnglish

    Read the document

Questions, or a document you need in a different form

Write to info@ghaym.me. If you need the agreement as a PDF, ask for it. Our data protection contact is the same address, and Ghaym is registered in the registry established under Article 18(D) of the Personal Data Protection Law.