Sign in

Trust · Security

PDPL compliance

The Personal Data Protection Law sets the rules for how personal data is collected, processed and stored. Edrak is designed so that work done on the platform stays inside those rules, wherever you operate.

Compliance cannot be a document you write after the fact. On Edrak, residency, purpose limits, masking and audit are properties of the platform, applied to every mission as it runs.

Obligation, met in the platform.

How the law's core requirements map to controls that are already part of how Edrak runs.

  1. 01

    Residency

    Data and inference run on infrastructure in the jurisdiction you designate. Transfers outside it happen only where the law permits and you approve.

  2. 02

    Purpose limitation

    Missions carry a defined objective. Retrieval and processing stay scoped to it, so personal data collected for one purpose is not quietly reused for another.

  3. 03

    Minimization & masking

    Masking applies before a model sees the data. People and agents retrieve only what their permissions allow, and only what the task needs.

  4. 04

    Data subject rights

    Access, correction and deletion requests need to find the data first. Foundry's indexed, permissioned record makes personal data locatable and actionable.

  5. 05

    Retention

    Retention windows are set per source and per classification. What expires is removed from retrieval, not just hidden from view.

  6. 06

    Accountability

    The immutable audit log records what was accessed, by whom, under which authority. When the regulator asks, the evidence is the record of the work itself.

Where it runs

Deployment options per engagement

In-jurisdiction infrastructure
Processing stays on infrastructure inside the jurisdiction you designate, for engagements that require it.
In-boundary models
Open-weight models run inside your boundary, so restricted personal data never reaches an external API.
Sovereign & air-gapped
Fully isolated deployment for government and regulated environments, on request.

Edrak provides the controls described here; legal responsibility for PDPL compliance rests with each organization as controller of its data. Alignment details are confirmed per engagement with your compliance team.

Bring your compliance team. We'll bring the evidence.