Skip to main content

Data Protection & Residency — Qatar (PDPPL)

The prepare-once, reuse-per-deal answer to the questions Qatar enterprise procurement asks. Written against Law No. 13 of 2016 (Personal Data Privacy Protection Law, PDPPL) and Qatar's Cloud Policy Framework, and against what the product actually does — every claim below is verifiable in the codebase or the infrastructure.

warning

This page is an operational summary prepared by PMFriend, not legal advice. For a specific engagement we'll support your counsel and, where required, the competent authority's (NCSA) notification/approval process.

Roles

PartyRole under PDPPL
The agency / FM company (you)Data controller — you decide why tenant/owner data is processed
PMFriendData processor — we process it on your documented instructions

What personal data PMFriend processes

CategoryExamplesWhy
Tenant contact dataname, email, mobilematching reports to tenants; notices
Maintenance contentreport text, photos, WhatsApp messagestriage + dispatch — the product's job
Lease termsdates, rent amount, deposit taskscompliance countdowns, arrears context
Owner contact dataname, email, mobiledigests and approvals you initiate
Contractor business databusiness name, CR/ABN, insurance datesdispatch + insurance tracking

Not collected: payment card data, QID/passport numbers, bank details, trust-accounting records (those stay in your systems of record).

Where data is processed

ComponentRegion / providerNotes
Application + database (primary)AWS eu-central-1 (Frankfurt)GDPR-grade EU region; encrypted at rest; 14-day point-in-time recovery
Inbound email intake (raw messages)AWS ap-southeast-2 (Sydney)S3 + SES
AI processingAnthropic (US)minimised fields only — see table below; no training on customer data per commercial terms
Outbound email deliveryResend (US)message content in transit for delivery

There is no in-country (Qatar) hosting today. Under the PDPPL and Qatar's Cloud Policy Framework this is a workable position for ordinary commercial sectors: the law restricts cross-border transfers to destinations with adequate protection and expects documented safeguards — it does not impose a blanket data-residency mandate outside specially regulated sectors (finance, health). For an engagement that requires it, we support the NCSA notification/approval route with this document as the transfer-impact input; in-country/GCC hosting is a scale-stage decision we'll cost on request.

AI data minimisation — what each feature actually sends

These are enforced as documented privacy contracts in the codebase, per port:

FeatureSent to the AIExplicitly NOT sent
Maintenance triagereport text + photo, property contexttenant name, contact, history
Inbound email/WhatsApp classificationsubject + message bodysender address book, other messages
Worker task translationthe job scope text onlytenant/owner identity, addresses beyond the scope text
Arrears / entry noticestenant name + property address (required for a legally addressable notice), amounts, datesemail, mobile, lease id, payment history
Case / dispute packschronology + tenant name + addresstenant email/mobile, lease ids, contractor contacts

No customer data is used to train models. AI calls fail closed to non-AI fallbacks — a provider outage never blocks operations.

Security safeguards (the questionnaire answers)

  • Tenant isolation: PostgreSQL FORCE ROW LEVEL SECURITY per agency — cross-tenant reads are impossible at the database layer, not just the app layer.
  • Encryption: TLS in transit; AWS-managed encryption at rest (RDS, S3).
  • Database credentials: short-lived IAM tokens — no static DB password exists that could leak.
  • Contractor access: single-work-order magic links, SHA-256-hashed at rest, 14-day expiry, no persistent accounts.
  • Webhooks: cryptographically verified (SNS signature; WhatsApp HMAC-SHA256) and fail-closed when unconfigured.
  • Abuse controls: per-IP and per-user rate limits on every public and AI-spending endpoint.
  • No trackers: no advertising or third-party analytics scripts.

Data-subject rights, retention, breach

  • Access / correction / deletion: requests flow through the controller (the agency); we execute within 30 days. Statutory retention (e.g. records needed for RDSC proceedings) is honoured; everything else is deleted.
  • Exit: full CSV export within 7 business days of cancellation; data deleted 30 days after.
  • Breach: we notify the agency within 72 hours of confirming a breach, and support your notification obligations to individuals and authorities.

What we provide per deal

  1. This transfer-impact summary (current version, dated).
  2. A Data Processing Agreement naming subprocessors (AWS, Anthropic, Resend).
  3. Completed security questionnaires on your template.
  4. Support for the NCSA approval/notification route where your counsel deems it required.
  5. At scale-commitment stage: a costed option for GCC/in-country hosting.

See also