# 1. EU GDPR Compliance Matrix
Where GDPR applies, processing roles, rights handling, safeguards, and transfer arrangements must be assessed for the customer’s use. Our Privacy Policy and DPA describe the relevant arrangements. Use of the platform is not a certification of the customer’s compliance.
# 2. UAE PDPL (Federal Law No. 45/2021)
UAE personal data protection requirements apply according to their scope and exemptions. Hosting in the UAE does not by itself satisfy all processing or transfer requirements. Breach reporting follows the applicable law and regulator requirements; this page does not substitute a universal 72-hour deadline for those rules.
# 3. Saudi Arabia KSA PDPL & GCC Alignment
Customers subject to Saudi or other regional data protection rules should assess lawful processing, publication, and cross-border transfer requirements before using the service. A UAE business address or hosting region does not establish Saudi data residency or approval by a regulator.
# 4. ISO 27001 & SOC 2 Safeguards
Security frameworks may inform due-diligence discussions. Specific certifications, audited controls, and reports must be confirmed by current documentation rather than inferred from this website. Contact hello@cuspforge.com for the evidence available for your procurement review.