PDPL compliance
We comply with the Personal Data Protection Law issued by the Saudi Data and AI Authority (SDAIA).
Last updated: May 10, 2026
The Personal Data Protection Law (PDPL) is Saudi Arabia's legal framework for protecting personal data. This page spells out exactly how HOM complies with each of its provisions.
Data controller
HOM acts as Data Controller for the data we collect directly from you (name, phone, preferences) and as Data Processor for the data you input into the system about your tenants or property owners.
Lawful basis for processing
We process your data based on: (1) your explicit consent at signup, (2) the execution of our contract with you, and (3) compliance with regulatory requirements such as ZATCA and the Central Bank.
Data localization
All customer data is hosted on cloud infrastructure within the borders of the Kingdom of Saudi Arabia. We do not transfer data outside the Kingdom except with your explicit consent and within tightly scoped use cases.
Data protection officer
We've appointed a Data Protection Officer you can reach at dpo@hom.sa for any inquiry or request regarding your data.
Breach reporting
In the event of any potential breach of your data, we will notify you and the competent authority within 72 hours of discovering the incident, with a full explanation of the impact and the measures taken.
Your rights under PDPL
Your rights include: access, correction, deletion, restriction of processing, portability to another provider, and objection to automated processing. All these rights are fulfilled within 30 days of the request.