Privacy overview for the current DataSitr service, including routing, retained operational data, and handling of higher-risk inputs.
In a typical deployment, the customer acts as the data controller and DataSitr acts as a processor for the service workflow. Requests are handled on Saudi-hosted infrastructure. The live pilot stores limited operational state, including encrypted token mappings and compliance metadata, on Saudi-hosted operational systems.
Your data flow is automatically segmented:
Identified PII is stored as AES-256-GCM encrypted token mappings for rehydration during the request workflow. On the live pilot, shared operational state runs on Saudi-hosted operational systems. Token mappings are time-limited, and compliance metadata may be retained to support audit and customer operations.
We provide APIs that help the Data Controller carry out supported data-subject workflows, including export, deletion, and rectification of vaulted subject data and related records. Availability of any specific workflow depends on the deployed configuration and the customer's own legal process.
This page was last updated on 2026-05-14.