Legal

PACE Align: Privacy Policy

Effective Date: 01/04/2026Jurisdiction: Kingdom of Saudi Arabia (KSA)

1. Introduction and Regulatory Alignment

Welcome to PACE Align. We are committed to protecting your privacy and ensuring the highest standards of data governance. This Privacy Policy outlines how we collect, use, and protect information across our corporate website and our enterprise Patient Support Program (PSP) infrastructure.

PACE Align is architected to strictly comply with the Personal Data Protection Law (PDPL) enacted by Royal Decree No. (M/19) and the regulations set forth by the Saudi Data & Artificial Intelligence Authority (SDAIA) and the Saudi Food and Drug Authority (SFDA).

2. Data Localization & Sovereignty

All data processed by the PACE Align ecosystem, including website inquiries and platform infrastructure, is 100% locally hosted within the Kingdom of Saudi Arabia on Tier-1, compliance-certified sovereign cloud infrastructure. We enforce a strict, system-level prohibition on the cross-border transfer of sensitive health data.

3. Information We Collect

A. Corporate Website Visitors (B2B Leads)

When you interact with our website, request a demo, or use our financial modeling tools, we collect corporate contact information including: Full Name, Corporate Email, Job Title, Organization Name, and IP address.

B. Platform End-Users (Patients)

Patient data is collected exclusively via our secure, encrypted omnichannel mobile gateway following explicit, verifiable opt-in consent during the onboarding phase. This data is strictly limited to information necessary for therapeutic adherence (e.g., automated dosing schedules, masked identification tokens).

4. How We Use and Mask Data

We apply strict Role-Based Access Control (RBAC) and advanced data separation protocols:

  • For Pharmaceutical Sponsors: PACE Align utilizes K-Anonymity protocols and threshold-based cryptographic masking (e.g., Rule of 3 boundaries). Pharmaceutical executives receive Zero-PII (No Personally Identifiable Information). Dashboards display strictly aggregated market intelligence, ensuring absolute compliance with the SFDA Code of Pharmaceutical Ethics and local data governance mandates.
  • For PSP Agencies: Third-party nurses operate under strict Row-Level Security. They can only access PII for patients explicitly assigned to their specific agency.
  • Corporate Inquiries: B2B contact data is used solely to provide executive demonstrations, deliver customized business cases, and communicate platform updates.

5. Data Security Protocols

PACE Align employs enterprise-grade security, including:

  • Advanced Encryption Standards: Applied to all data at rest and in transit across our ecosystem.
  • Structured Data Capture: We minimize free-text entry in our clinical workflows, utilizing highly structured data models and strict interface controls to prevent accidental PII leakage or unregulated data capture.

6. Your Rights Under the PDPL

Under Saudi Law, you possess the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request the correction of inaccurate or incomplete data.
  • Destruction: Request the deletion of your personal data when it is no longer necessary for the purposes collected.
  • Withdraw Consent: Withdraw your consent for data processing at any time (which may impact your ability to use the PACE Align platform).

To exercise these rights, contact our Data Privacy Officer at: Partnerships@mypacehub.com