DATA PROTECTION
Your data is not our business model
How Nathan Digital protects the personal and organizational data entrusted to us by enterprises across 50+ countries.
Published and effective on: 2 June 2026
HR systems hold the most sensitive data in any organization — salaries, personal IDs, medical records, performance reviews. We treat every byte with the seriousness it deserves.
SECURITY
How we protect your data.
Encryption everywhere
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Database backups are encrypted with customer-specific keys.
Access controls
Role-based access control (RBAC) across all systems. Multi-factor authentication enforced for all internal access. Principle of least privilege.
Data residency
Choose where your data lives. We offer hosting in UAE, EU, US, and Singapore regions to meet local data sovereignty requirements.
Audit logging
Every access, modification, and export is logged with immutable audit trails. Full visibility into who accessed what and when.
Regular assessments
Annual penetration testing by independent third parties. Continuous vulnerability scanning. SOC 2 Type II aligned controls.
Employee training
All staff complete mandatory data protection training at onboarding and annually. Security awareness is embedded in our culture.
COMPLIANCE
Regulatory frameworks we support.
UAE PDPL
Fully compliant with the UAE Personal Data Protection Law (Federal Decree-Law No. 45/2021) governing the processing of personal data within the UAE.
GDPR
Compliant with the EU General Data Protection Regulation for clients operating in or serving individuals in the European Economic Area.
KSA PDPL
Adherent to the Saudi Arabia Personal Data Protection Law for organizations processing personal data within the Kingdom.
DIFC Data Protection
Compliant with DIFC Data Protection Law No. 5 of 2020 for clients operating within the Dubai International Financial Centre.
ADGM Data Protection
Adherent to the Abu Dhabi Global Market Data Protection Regulations 2021 for ADGM-based entities.
ISO 27001 (aligned)
Our information security management system is aligned with ISO 27001 controls. Formal certification in progress.
YOUR RIGHTS
Data subject rights.
Request a copy of the personal data we process about you or your employees.
Request correction of inaccurate or incomplete personal data.
Request deletion of personal data when it is no longer necessary for its original purpose.
Request that we limit how we process your data in certain circumstances.
Receive your data in a structured, machine-readable format for transfer to another provider.
Object to processing based on legitimate interests or for direct marketing purposes.