VCOSH — Virtual Center of Occupational Safety and Health Services
Pre-launch draft — legal counsel to finalise

Legal

PDPL data-handling notice

A concise, plain-language summary of how vCosh complies with the Kingdom of Saudi Arabia’s Personal Data Protection Law (PDPL). For the full statement of practices, see our privacy policy.

Last updated: 14 May 2026

Data residency

me-central-1 · Riyadh

Encryption

At rest · In transit

Controller

VCOSH Operations (KSA)

Breach notification

Within 72 hours to SDAIA

1. Scope

This notice applies to all personal data of natural persons resident in the Kingdom of Saudi Arabia processed by the vCosh platform.

2. Lawful bases for processing (PDPL Article 5)

  • Contract — performing the service your employer purchased on your behalf.
  • Legal obligation — NCOSH-mandated occupational safety training records.
  • Consent — for sensitive health-adjacent processing (real-age assessment, wearable sync, AI assistant chat).
  • Vital interests — when a safety risk to you is detected (e.g. extreme assessment score) we may notify you through the platform and surface a specialist hand-off.

3. Data residency and storage

Primary storage is in the KSA-resident me-central-1 AWS region. Backup snapshots are written to an immutable archive in the same region with cross-account isolation. We do not replicate personal data outside the Kingdom.

4. Sub-processors

A small set of supporting services may transiently touch personal data. We have data-processing agreements with each, aligned with PDPL cross-border-transfer requirements:

  • Mux — video transcoding; processes video files only, no PII.
  • LiveKit — real-time video for specialist consults; consults are routed through KSA edge nodes where available.
  • Anthropic — AI assistant inference; prompts are scrubbed of direct identifiers before transmission and content is excluded from model training.
  • Postmark — transactional email delivery (verification links, notifications).
  • Firebase Cloud Messaging / Apple Push Notification service — push notifications to the mobile app.
  • Twilio — SMS for OTP fallback only, in jurisdictions where SMS is permitted.

The current sub-processor list is available on request to privacy@vcosh.sa. We notify Customers 30 days before adding a new sub-processor.

5. Sensitive personal data

Real-age responses, wearable health data, AI assistant transcripts, and specialist-consult notes are treated as sensitive personal data under PDPL §6. They are:

  • Encrypted at the row level in addition to disk-level encryption.
  • Accessible only to you, the specialist you booked (their own session notes), and a tightly scoped vCosh on-call team for incident response (with audit trail).
  • Excluded from all Client-Admin dashboards. Aggregate distributions are reported only at department-or-larger granularity to prevent re-identification.

6. Retention

Retention windows are itemised in our privacy policy §7. Highlights:

  • Training records — 7 years (NCOSH-aligned).
  • Audit logs — 7 years (PDPL §32-aligned).
  • AI assistant transcripts — 12 months, then deleted.
  • Wearable raw data — withdrawn within 30 days of consent revocation.

7. Your rights (PDPL Articles 4 and 16)

You have the right to access, correct, delete, port, restrict, and object to processing of your personal data, plus the right to withdraw consent for sensitive processing at any time. Most rights are self-serve from your Profile; for anything else, write to privacy@vcosh.sa. We respond within 30 days, and at no cost to you.

You may also lodge a complaint with the Saudi Data & AI Authority (SDAIA).

8. Breach notification

In the event of a personal-data breach affecting your information, we notify you and SDAIA within 72 hours of detection, per PDPL §22. Notifications include the nature of the breach, the data affected, the steps we are taking, and recommended actions for you.

9. Contact

Data Protection Officer · VCOSH Operations · Riyadh, KSA · privacy@vcosh.sa