Document summary
This policy explains provider selection, data a provider might receive, contractual and transfer controls, and how we avoid publishing an assumed list that does not match actual operations.
Actual, not invented, provider list
We do not publish a provider merely because the platform supports connecting it. This version contains no provider list because a publishable operations register has not yet been approved. You may request disclosure relevant to your service through the privacy channel. This page must be updated before a provider appears in the public storage register.
Due diligence
Before connection, we review ownership, location, service, security, privacy, continuity, incidents, subprocessors, deletion, audit rights, and exit plan.
Contract terms
The contract defines party roles, purpose, instructions, categories, location, confidentiality, controls, assistance with rights and incidents, and disposal. A sensitive service does not rely only on linked public terms.
Minimization and access
Providers receive the smallest technical and data scope. Separate service accounts, key rotation, and access logs are used, and administrative accounts are not shared between vendors.
Transfers outside the Kingdom
A transfer assessment records country, purpose, categories, sensitivity, necessity, safeguard, and any applicable exemption. A suitable legal mechanism such as standard contractual clauses or approved safeguard is used where needed.
Provider changes
A new provider is reviewed before activation. We update the list and notice and request new consent if an optional purpose changes or law requires. Exit and deletion plans run on termination.
Monitoring and incidents
We review connection status, errors, permissions, security reports, and renewal. Providers must report incidents without undue delay and provide information needed for assessment and notification.
Rights and deletion
The data map links providers so access or destruction requests reach every system. We verify a deletion certificate or API outcome rather than relying only on account closure.
Official references
References used to prepare this content
Links point to official legal or guidance sources. Applicability depends on the organization, product, and contract.
Versions
Change log
- Version 1.0.0
Published the first operational version with clear scope, responsibilities, rights, and escalation routes.