Data Protection & Residency — Qatar (PDPPL)
The prepare-once, reuse-per-deal answer to the questions Qatar enterprise procurement asks. Written against Law No. 13 of 2016 (Personal Data Privacy Protection Law, PDPPL) and Qatar's Cloud Policy Framework, and against what the product actually does — every claim below is verifiable in the codebase or the infrastructure.
This page is an operational summary prepared by PMFriend, not legal advice. For a specific engagement we'll support your counsel and, where required, the competent authority's (NCSA) notification/approval process.
Roles
| Party | Role under PDPPL |
|---|---|
| The agency / FM company (you) | Data controller — you decide why tenant/owner data is processed |
| PMFriend | Data processor — we process it on your documented instructions |
What personal data PMFriend processes
| Category | Examples | Why |
|---|---|---|
| Tenant contact data | name, email, mobile | matching reports to tenants; notices |
| Maintenance content | report text, photos, WhatsApp messages | triage + dispatch — the product's job |
| Lease terms | dates, rent amount, deposit tasks | compliance countdowns, arrears context |
| Owner contact data | name, email, mobile | digests and approvals you initiate |
| Contractor business data | business name, CR/ABN, insurance dates | dispatch + insurance tracking |
Not collected: payment card data, QID/passport numbers, bank details, trust-accounting records (those stay in your systems of record).
Where data is processed
| Component | Region / provider | Notes |
|---|---|---|
| Application + database (primary) | AWS eu-central-1 (Frankfurt) | GDPR-grade EU region; encrypted at rest; 14-day point-in-time recovery |
| Inbound email intake (raw messages) | AWS ap-southeast-2 (Sydney) | S3 + SES |
| AI processing | Anthropic (US) | minimised fields only — see table below; no training on customer data per commercial terms |
| Outbound email delivery | Resend (US) | message content in transit for delivery |
There is no in-country (Qatar) hosting today. Under the PDPPL and Qatar's Cloud Policy Framework this is a workable position for ordinary commercial sectors: the law restricts cross-border transfers to destinations with adequate protection and expects documented safeguards — it does not impose a blanket data-residency mandate outside specially regulated sectors (finance, health). For an engagement that requires it, we support the NCSA notification/approval route with this document as the transfer-impact input; in-country/GCC hosting is a scale-stage decision we'll cost on request.
AI data minimisation — what each feature actually sends
These are enforced as documented privacy contracts in the codebase, per port:
| Feature | Sent to the AI | Explicitly NOT sent |
|---|---|---|
| Maintenance triage | report text + photo, property context | tenant name, contact, history |
| Inbound email/WhatsApp classification | subject + message body | sender address book, other messages |
| Worker task translation | the job scope text only | tenant/owner identity, addresses beyond the scope text |
| Arrears / entry notices | tenant name + property address (required for a legally addressable notice), amounts, dates | email, mobile, lease id, payment history |
| Case / dispute packs | chronology + tenant name + address | tenant email/mobile, lease ids, contractor contacts |
No customer data is used to train models. AI calls fail closed to non-AI fallbacks — a provider outage never blocks operations.
Security safeguards (the questionnaire answers)
- Tenant isolation: PostgreSQL
FORCE ROW LEVEL SECURITYper agency — cross-tenant reads are impossible at the database layer, not just the app layer. - Encryption: TLS in transit; AWS-managed encryption at rest (RDS, S3).
- Database credentials: short-lived IAM tokens — no static DB password exists that could leak.
- Contractor access: single-work-order magic links, SHA-256-hashed at rest, 14-day expiry, no persistent accounts.
- Webhooks: cryptographically verified (SNS signature; WhatsApp HMAC-SHA256) and fail-closed when unconfigured.
- Abuse controls: per-IP and per-user rate limits on every public and AI-spending endpoint.
- No trackers: no advertising or third-party analytics scripts.
Data-subject rights, retention, breach
- Access / correction / deletion: requests flow through the controller (the agency); we execute within 30 days. Statutory retention (e.g. records needed for RDSC proceedings) is honoured; everything else is deleted.
- Exit: full CSV export within 7 business days of cancellation; data deleted 30 days after.
- Breach: we notify the agency within 72 hours of confirming a breach, and support your notification obligations to individuals and authorities.
What we provide per deal
- This transfer-impact summary (current version, dated).
- A Data Processing Agreement naming subprocessors (AWS, Anthropic, Resend).
- Completed security questionnaires on your template.
- Support for the NCSA approval/notification route where your counsel deems it required.
- At scale-commitment stage: a costed option for GCC/in-country hosting.
See also
- Qatar Market Roadmap — where the residency decision sits
- Qatar — Compliance Defaults — the property-side rule-set